Commit Graph

6538 Commits

Author SHA1 Message Date
Atomic Red Team doc generator 30a2f6f601 Generated docs from job=generate-docs branch=master [ci skip] 2024-08-03 01:37:27 +00:00
sree siva likhitha kothalanka de8cc181a6 Update T1082.yaml (#2895)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-08-02 20:36:16 -05:00
dependabot[bot] a8cdef7e1b Bump hypothesis from 6.108.2 to 6.108.5 (#2889)
Bumps [hypothesis](https://github.com/HypothesisWorks/hypothesis) from 6.108.2 to 6.108.5.
- [Release notes](https://github.com/HypothesisWorks/hypothesis/releases)
- [Commits](https://github.com/HypothesisWorks/hypothesis/compare/hypothesis-python-6.108.2...hypothesis-python-6.108.5)

---
updated-dependencies:
- dependency-name: hypothesis
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-08-02 20:33:58 -05:00
Atomic Red Team doc generator 1157183f0a Generated docs from job=generate-docs branch=master [ci skip] 2024-08-03 01:32:44 +00:00
Mohana Shankar D f85294b90d Update T1564.003.yaml (#2884)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-08-02 20:31:32 -05:00
Atomic Red Team doc generator 4a087e79e5 Generated docs from job=generate-docs branch=master [ci skip] 2024-08-03 01:30:28 +00:00
abhijose09 a1d2de5f9c Update T1546.yaml (#2883)
New Test Added : Load custom DLL on mstsc execution

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-08-02 20:29:01 -05:00
Atomic Red Team doc generator e580d4420f Generated docs from job=generate-docs branch=master [ci skip] 2024-08-03 01:27:36 +00:00
abhijose09 5182c34b07 New Test : Leverage Virtual Channels to execute custom DLL during successful RDP session (#2882)
* Update T1547.yaml

New Test Added : Leverage Virtual Channels to execute custom DLL during successful RDP session

* Update T1547.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-08-02 20:26:27 -05:00
Atomic Red Team doc generator 16bb157750 Generated docs from job=generate-docs branch=master [ci skip] 2024-08-03 01:25:14 +00:00
amitrrajeshwarkar fba22ab5e3 Update T1574.002.yaml (#2881)
Various threat actors and malware have been found side loading a masqueraded "KeyScramblerIE.dll" through "KeyScrambler.exe", which can load further executables embedded in modified KeyScramblerIE.dll file.

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-08-02 20:24:08 -05:00
Atomic Red Team doc generator e6469976ec Generated docs from job=generate-docs branch=master [ci skip] 2024-08-03 01:17:47 +00:00
abhijose09 d27673ede6 Update T1546.yaml (#2880)
* Update T1546.yaml

New Test Added : Persistence using automatic execution of custom DLL during RDP session

* Update T1546.yaml

* Update T1546.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-08-02 20:16:39 -05:00
Atomic Red Team doc generator aa9410b161 Generated docs from job=generate-docs branch=master [ci skip] 2024-08-02 21:45:08 +00:00
AlbertoPellitteri 8e18cafebb Fix 1046.yaml (#2892)
* Adding the --rm option in the docker run command

* Fix the docker exec command

* Added the dockerfile path as input arg

* Fixing the reference to the dockerfile filepath

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2024-08-02 14:43:58 -07:00
Atomic Red Team doc generator 47a7a1525f Generated docs from job=generate-docs branch=master [ci skip] 2024-08-02 21:39:16 +00:00
AlbertoPellitteri 366ff6f084 Fix T1613.yaml (#2886)
* Fixing several issues on T1613 test

* Undoing the md file fix

* Undoing the md file fix and fixing also test 2

---------

Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2024-08-02 14:38:09 -07:00
Atomic Red Team doc generator d143f79024 Generated docs from job=generate-docs branch=master [ci skip] 2024-08-01 23:51:58 +00:00
AlbertoPellitteri 4a11a17dba Fix T1612.yaml (#2887)
* Adding the docker rm option

* Undoing the md file fix

---------

Co-authored-by: Hare Sudhan <code@0x6c.dev>
Co-authored-by: Bhavin Patel <bhavin.j.patel91@gmail.com>
2024-08-01 16:50:50 -07:00
Atomic Red Team doc generator 67520627ff Generated docs from job=generate-docs branch=master [ci skip] 2024-08-01 23:47:03 +00:00
AlbertoPellitteri 95ef62dd1e Update T1562.008.yaml (#2888)
* Added the AWS platform to test 5

* Undoing the md file fix
2024-08-01 16:45:54 -07:00
dependabot[bot] 422d661a56 Bump pytest from 8.3.1 to 8.3.2 (#2890)
Bumps [pytest](https://github.com/pytest-dev/pytest) from 8.3.1 to 8.3.2.
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/8.3.1...8.3.2)

---
updated-dependencies:
- dependency-name: pytest
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-07-31 23:58:53 -04:00
Atomic Red Team doc generator 88851e2bea Generated docs from job=generate-docs branch=master [ci skip] 2024-08-01 03:53:03 +00:00
nish221b-bs c8926e03c0 Update T1059.004.yaml (#2871)
* Update T1059.004.yaml

* Update T1059.004.yaml

* Update T1059.004.yaml

---------

Co-authored-by: Hare Sudhan <code@0x6c.dev>
2024-07-31 23:51:49 -04:00
Atomic Red Team doc generator bee5a4c48f Generated docs from job=generate-docs branch=master [ci skip] 2024-07-24 14:41:19 +00:00
abhijose09 af560d5067 Update T1546.008.yaml (#2878)
New Test Added : Auto-start application on user logon

Existing Test Atbroker.exe (AT) Executes Arbitrary Command via Registry Key added modified for addition of elevated privileges to carry out the required testing

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-24 09:40:14 -05:00
Atomic Red Team doc generator f368a70546 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-24 14:38:05 +00:00
abhijose09 13f7dde9a3 Update T1574.001.yaml (#2877)
New test Added : Phantom Dll Hijacking - WinAppXRT.dll

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-24 09:36:55 -05:00
Atomic Red Team doc generator 83c5d69c55 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-24 14:35:18 +00:00
NeuralGlitch 1c0f195934 Update T1547.yaml (#2875)
adding new atomic realted to pnputil to cover different set of command line arguments for pnputil. pnputil can be abused to install drivers in windows 

Test Name: Driver Installation Using pnputil.exe

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-24 09:34:09 -05:00
Atomic Red Team doc generator 9418990356 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-24 14:32:32 +00:00
sree siva likhitha kothalanka ba841eba7a Update T1217.yaml (#2876)
* Update T1217.yaml

This test will extract Microsoft Edge browser's history of current user

* Update T1217.yaml

* Update T1217.yaml

* remove duplicate test

* Update T1217.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-24 09:31:17 -05:00
Atomic Red Team doc generator 33939648b7 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-24 02:37:54 +00:00
Prakash22-k 5fc2f6dd5f Update T1218.yaml (#2855)
* Update T1218.yaml

* Update T1218.yaml

* Update T1218.yaml

---------

Co-authored-by: Hare Sudhan <code@0x6c.dev>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-23 21:36:46 -05:00
Atomic Red Team doc generator b0f5fc12dd Generated docs from job=generate-docs branch=master [ci skip] 2024-07-24 02:31:35 +00:00
dependabot[bot] c62a30637d Bump pytest from 8.2.2 to 8.3.1 (#2873)
Bumps [pytest](https://github.com/pytest-dev/pytest) from 8.2.2 to 8.3.1.
- [Release notes](https://github.com/pytest-dev/pytest/releases)
- [Changelog](https://github.com/pytest-dev/pytest/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/pytest-dev/pytest/compare/8.2.2...8.3.1)

---
updated-dependencies:
- dependency-name: pytest
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-23 21:30:29 -05:00
abhijose09 19fbe0f994 Update T1112.yaml (#2870)
Added New Test : Adding custom paths for application execution

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-23 21:29:27 -05:00
Atomic Red Team doc generator 444f81d64f Generated docs from job=generate-docs branch=master [ci skip] 2024-07-24 02:28:03 +00:00
Pavan R Patil 7c1d934430 Update T1569.002.yaml (#2869)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-23 21:26:56 -05:00
Atomic Red Team doc generator f1fd271ee0 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-24 02:24:52 +00:00
Badoodish a8585e0e50 Update T1078.003.yaml (#2867)
Added new test "Use PsExec to elevate to NT Authority\SYSTEM account"

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-23 21:23:48 -05:00
Atomic Red Team doc generator e1feb2c7a5 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-24 02:21:57 +00:00
abhijose09 bd13bcbaec Update T1546.yaml (#2865)
New Test : Adding custom debugger for Windows Error Reporting

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-23 21:20:48 -05:00
Atomic Red Team doc generator 2d3c1652a4 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-24 02:17:35 +00:00
abhijose09 3bc01cabb5 3 new tests added (#2863)
3 new Tests added :
Abusing MyComputer Disk Backup Path for Persistence
Abusing MyComputer Disk Cleanup Path for Persistence
Abusing MyComputer Disk Fragmentation Path for Persistence

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-23 21:16:20 -05:00
Atomic Red Team doc generator 162921f9e7 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-23 22:08:10 +00:00
abhijose09 d4aa5c432e New Test - Modify RDP-Tcp Initial Program Registry Entry (#2861)
* Update T1112.yaml

Modify RDP-Tcp Initial Program Registry Entry

* Update T1112.yaml

added cleanup commands

* Update T1112.yaml

* Update T1112.yaml

* Update T1112.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-23 17:06:54 -05:00
Atomic Red Team doc generator 229af9deb5 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-23 21:39:39 +00:00
Badoodish 0a8ad64ee8 Added new test to T1614.001 "Discover System Language by Windows API … (#2857)
* Added new test to T1614.001 "Discover System Language by Windows API Query"

* Fixed indentation on line 139. Added input arguments

* Fixed indentation on line 126

* Added markdown formatting.

* Added C# source code as requested

* Removed input arguments because not arguments are supported.

* Updated exe output

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2024-07-23 16:38:25 -05:00
Atomic Red Team doc generator 2a37d1cae8 Generated docs from job=generate-docs branch=master [ci skip] 2024-07-19 04:22:39 +00:00