Commit Graph

6615 Commits

Author SHA1 Message Date
Bhavin Patel 59e7e7bbe2 Merge pull request #1803 from esanyaCode/T1562.001-azure-defense-evasion-eventhub-deletion
Updated Azure Eventhub Deletion Scenario
2022-03-14 14:06:15 -07:00
Bhavin Patel 433d8a29e0 Merge branch 'master' into T1562.001-azure-defense-evasion-eventhub-deletion 2022-03-14 14:04:41 -07:00
CircleCI Atomic Red Team doc generator 6b82fe5136 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 18:07:44 +00:00
CircleCI Atomic Red Team GUID generator 3ce01207ea Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 18:07:38 +00:00
Tim Schulz 85ea448d3b Added procedural variation to include PowerShell execution and WMIC (#1801)
* Added procedural variation to include PowerShell execution and WMIC

* Removed empty GUID lines

* Changed wmic to only command_prompt instead of powershell and command_prompt

Co-authored-by: Tim Schulz <tim@scythe.io>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-03-14 12:07:08 -06:00
Araveti Esanya Reddy 9dc726b495 updated as per review commets 2022-03-14 23:32:17 +05:30
CircleCI Atomic Red Team doc generator 052cae4391 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 18:01:13 +00:00
CircleCI Atomic Red Team GUID generator e0a6429a77 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 18:01:07 +00:00
tccontre d83aada893 Disable Windows Features (#1811)
* Update T1112.yaml

* Update T1112.yaml

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-03-14 12:00:25 -06:00
CircleCI Atomic Red Team doc generator de8ceae8a6 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 17:44:57 +00:00
CircleCI Atomic Red Team GUID generator 859404904a Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 17:44:50 +00:00
tccontre 7a4e2abcdb Update T1112.yaml (#1810)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-03-14 11:44:14 -06:00
CircleCI Atomic Red Team doc generator 3947bbc2a5 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 17:41:32 +00:00
Araveti Esanya Reddy f3e3346b1a updated as per review comments 2022-03-14 23:11:29 +05:30
CircleCI Atomic Red Team GUID generator de94c41347 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 17:41:26 +00:00
frack113 d3a53714b4 Add persistance via Recycle bin (#1809)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-03-14 11:41:04 -06:00
CircleCI Atomic Red Team doc generator 042bd99bdd Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 17:38:48 +00:00
CircleCI Atomic Red Team GUID generator 0f87abb865 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 17:38:42 +00:00
frack113 f6a8e78538 pnputil lolbin (#1808)
* pnputil lolbin

* spelling

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-03-14 11:38:08 -06:00
CircleCI Atomic Red Team doc generator 1209d7b0f6 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 17:32:56 +00:00
CircleCI Atomic Red Team GUID generator 5e47dae27b Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 17:32:49 +00:00
Michael Haag 687da9235b AD Enumeration - user/groups, pw policy (#1807)
* More AD

* fix conflict resolution mistake

* add powershell

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-03-14 11:32:18 -06:00
Araveti Esanya Reddy a6e1d47cdd Update T1562.008.yaml 2022-03-14 22:44:03 +05:30
Araveti Esanya Reddy c88221308f updated as per review comments 2022-03-14 22:34:33 +05:30
CircleCI Atomic Red Team doc generator 4c019a8936 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 16:44:03 +00:00
CircleCI Atomic Red Team GUID generator b52281c4cd Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-14 16:43:54 +00:00
Michael Haag d1e3e11730 AD Searching and powerview (#1806)
* ADSI

* new atomics
2022-03-14 10:43:19 -06:00
WojciechLesicki 30af70bef9 Removing md file 2022-03-11 23:59:46 +01:00
WojciechLesicki 8578fc3308 Correct description 2022-03-11 23:52:07 +01:00
Wojciech Lesicki 3c9dfe7e80 Merge branch 'redcanaryco:master' into master 2022-03-11 23:50:15 +01:00
CircleCI Atomic Red Team doc generator 8aedc6cdd9 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-09 21:03:01 +00:00
Carrie Roberts 4e7a2ed599 fix prereq for screenshot test (#1805) 2022-03-09 14:02:31 -07:00
CircleCI Atomic Red Team doc generator 82df99e7c8 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-09 16:16:04 +00:00
CircleCI Atomic Red Team GUID generator 455cd5837e Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-09 16:15:58 +00:00
Leo Verlod 5148b9db57 Adding T1003.007 Test 3 - MimiPenguin Usage (#1804)
Adding T1003.007 Test 3 - Capture Passwords with MimiPenguin. This test is designed to run the MimiPenguin script, which takes advantage of a vulnerability in Ubuntu-based distros, as well as certain versions of GNOME Keyring, in order to capture passwords in cleartext. Upon successful execution, user passwords will be exported to a file and displayed on-screen.
2022-03-09 09:15:17 -07:00
Araveti Esanya Reddy af719c41d2 udpated azure eventhub deletion scenario 2022-03-08 17:57:22 +05:30
CircleCI Atomic Red Team doc generator 6052b5118a Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-08 01:33:09 +00:00
SecWilson 42dd141032 Fixing Blackbyte Cleanup Commands (#1802)
Co-authored-by: Wilson <SWilson@nti.local>
2022-03-07 18:32:31 -07:00
Carrie Roberts 9186e32eb2 Merge branch 'master' into master 2022-03-07 11:35:13 -06:00
CircleCI Atomic Red Team doc generator 682d8d732b Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-07 17:34:07 +00:00
CircleCI Atomic Red Team GUID generator 03c3400af9 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-07 17:34:02 +00:00
SecWilson 43fa5fb8a0 Blackbyte privilege escalation via Powershell (#1796)
Co-authored-by: Wilson <SWilson@nti.local>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-03-07 10:33:31 -07:00
CircleCI Atomic Red Team doc generator 7dd9d481b5 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-07 17:18:44 +00:00
CircleCI Atomic Red Team GUID generator a38b68f067 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-07 17:18:39 +00:00
Leo Verlod 5388982089 Adding T1059.003 Test 4 - BlackByte Print Bombing (#1799)
Adding T1059.003 Test 4, which is designed to emulate the print bombing behavior observed in recent BlackByte ransomware attacks.

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-03-07 10:18:20 -07:00
CircleCI Atomic Red Team doc generator c81858120b Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-07 16:39:15 +00:00
lucasRiley 999d18a36d T1059.005 Fix Cleanup and Prereq (#1798)
Co-authored-by: Riley <lriley@NTI.local>
2022-03-07 09:38:41 -07:00
WojciechLesicki 54f98b9930 Added one more newline :) 2022-03-06 19:15:00 +01:00
WojciechLesicki eb50e5b1e0 Adding new lines 2022-03-06 18:59:52 +01:00
WojciechLesicki 2be981e92d I added another atomic related to adding permission to the application in AzureAD. 2022-03-06 18:54:11 +01:00