Commit Graph

1159 Commits

Author SHA1 Message Date
caseysmithrc 800192a12c update tests 2019-02-14 13:41:54 -07:00
Tony M Lambert f0985c5444 Chain Reaction - Rocke and Roll (#443)
* initial commit

* modified output style

* final url changes

* Update rocke-and-roll-stage-01.sh
2019-01-24 08:22:38 -08:00
CircleCI Atomic Red Team doc generator 805deeee31 Generate docs from job=validate_atomics_generate_docs branch=master 2019-01-21 19:49:11 +00:00
Keep Watcher baba01109e adding SSP mod simulation (#438)
* adding SSP mod simulation

* Update T1101.md
2019-01-21 11:49:01 -08:00
Tony M Lambert da88f2baa2 T1099 Timestomp test with Rocke example (#439) 2019-01-21 11:48:46 -08:00
CircleCI Atomic Red Team doc generator e74554992e Generate docs from job=validate_atomics_generate_docs branch=master 2019-01-16 22:14:59 +00:00
Tony M Lambert 4f5c279c61 T1009 - Adjust test with variable for execution (#418) 2019-01-16 14:14:49 -08:00
CircleCI Atomic Red Team doc generator 37ca7e5fd0 Generate docs from job=validate_atomics_generate_docs branch=master 2019-01-16 17:25:14 +00:00
Ross Wolf 6b6f4beae5 Update flag for cmd.exe (#416) 2019-01-16 09:25:04 -08:00
CircleCI Atomic Red Team doc generator c65ed5d77e Generate docs from job=validate_atomics_generate_docs branch=master 2019-01-16 17:24:56 +00:00
Tony M Lambert d76e946bc2 T1002 - Reorganize tests for better execution with framework (#417) 2019-01-16 09:24:48 -08:00
CircleCI Atomic Red Team doc generator 87bd65c63c Generate docs from job=validate_atomics_generate_docs branch=master 2019-01-16 17:24:38 +00:00
Tony M Lambert 832a907d54 T1174 Password Filter DLL PoSH test (#420) 2019-01-16 09:24:29 -08:00
CircleCI Atomic Red Team doc generator d8510e729b Generate docs from job=validate_atomics_generate_docs branch=master 2019-01-16 17:24:16 +00:00
Tony M Lambert 78bedf0e45 T1107 Fix wbadmin test (#421) 2019-01-16 09:24:09 -08:00
Tony M Lambert dfabc52d64 T1107 File Deletion reorg with variables (#423) 2019-01-16 09:23:55 -08:00
CircleCI Atomic Red Team doc generator bb07c4ac15 Generate docs from job=validate_atomics_generate_docs branch=master 2019-01-16 17:23:40 +00:00
JimmyAstle 61ffc53425 Register-CimProvider Atomic test (#435)
A quick atomic test that utilizes register-cimprovider to execute a dll that pops calc.
2019-01-16 09:23:29 -08:00
CircleCI Atomic Red Team doc generator 7554e9b644 Generate docs from job=validate_atomics_generate_docs branch=master 2019-01-16 16:17:22 +00:00
Keith McCammon 5c3f5b6389 Merge pull request #424 from ForensicITGuy/t1166-setuidgid
T1166 SetUID SetGID add tests with variables
2019-01-16 09:17:12 -07:00
CircleCI Atomic Red Team doc generator 063e489114 Generate docs from job=validate_atomics_generate_docs branch=master 2018-12-13 16:07:16 +00:00
Tony M Lambert 0779b60397 T1010 App Window Discovery with C# (#429) 2018-12-13 08:07:08 -08:00
CircleCI Atomic Red Team doc generator 8243dfedec Generate docs from job=validate_atomics_generate_docs branch=master 2018-12-13 16:06:56 +00:00
Tony M Lambert 4334a8c0b0 T1007 Service Discovery Net Start to File (#428) 2018-12-13 08:06:48 -08:00
CircleCI Atomic Red Team doc generator 07079c9ed7 Generate docs from job=validate_atomics_generate_docs branch=master 2018-12-13 16:06:36 +00:00
Tony M Lambert 0f576dd03f T1004 Winlogon Helper DLLs (#427) 2018-12-13 08:06:28 -08:00
Tony M Lambert 5da497ed1d T1156 .bash_profile .bashrc reorg into separate tests (#426) 2018-12-13 08:06:19 -08:00
Tony M Lambert 15b6f10135 T1009 Binary Padding reorg with variables (#425) 2018-12-13 08:06:12 -08:00
Tony M Lambert a49998432e T1088 Fodhelper UAC Bypass and PoSH tests (#422) 2018-12-13 08:06:02 -08:00
Tony M Lambert 6725795d88 T1166 SetUID SetGID add tests with variables 2018-12-11 00:31:19 -06:00
CircleCI Atomic Red Team doc generator 5bbe2e6403 Generate docs from job=validate_atomics_generate_docs branch=master 2018-12-05 00:53:11 +00:00
Tony M Lambert 9aaa150dcf T1220 XSL Script Processing (#410)
* Remove XSL tests from T1127 Trusted Dev Tools

* Add T1220 XSL Script Processing
2018-12-04 16:52:57 -08:00
CircleCI Atomic Red Team doc generator 0d9f652cab Generate docs from job=validate_atomics_generate_docs branch=master 2018-12-05 00:38:31 +00:00
Tony M Lambert 9a487bd26a Added test for persistence via BITS (#409) 2018-12-04 16:38:19 -08:00
Tony M Lambert 4c0eab68c4 T1220 WMIC XSL Tests (#411)
* Remove XSL tests from T1127 Trusted Dev Tools

* Add T1220 XSL Script Processing

* Added tests for T1220 WMIC XSL execution

* fixed to pass spec
2018-12-04 16:38:12 -08:00
Tony M Lambert 4d4cc31211 T1222 Added File Perm Modification tests (#412) 2018-12-04 16:38:03 -08:00
Tony M Lambert 943b36db5d T1218 Signed Binary Proxy Execution (#413) 2018-12-04 16:37:48 -08:00
Brian Beyer d2362a0d45 Security updates to gems (#415) 2018-11-28 12:31:18 -08:00
CircleCI Atomic Red Team doc generator 9ab98d2318 Generate docs from job=validate_atomics_generate_docs branch=master 2018-11-17 16:15:14 +00:00
Ross Wolf ae1b07bf4d Update T1042 with cmd /c argument (#408)
The `/c` flag was missing for `cmd.exe`, causing the command to be skipped.
2018-11-17 09:15:06 -07:00
CircleCI Atomic Red Team doc generator 51180df1b1 Generate docs from job=validate_atomics_generate_docs branch=master 2018-11-14 21:38:39 +00:00
Tony M Lambert 64ac0fea1f T1223 Compiled HTML Help (#407)
* T1223 Compiled HTML Help

* Update ATT&CK JSON (#406)

* Generate docs from job=validate_atomics_generate_docs branch=master

* T1223 Compiled HTML Help
2018-11-14 14:38:32 -07:00
CircleCI Atomic Red Team doc generator 6965fc15ef Generate docs from job=validate_atomics_generate_docs branch=master 2018-11-14 20:59:18 +00:00
Tony M Lambert c68c20392b Update ATT&CK JSON (#406) 2018-11-14 13:59:04 -07:00
Keith McCammon 53b39e11fe Merge pull request #401 from redcanaryco/clean-up-csmith
fix-executor
2018-11-11 18:18:48 -07:00
Keith McCammon 7074c68b8d Merge pull request #403 from redcanaryco/t1087-kwm
Clean up T1087 for consistency, platform accuracy
2018-11-11 12:45:34 -07:00
CircleCI Atomic Red Team doc generator bce4f2b833 Generate docs from job=validate_atomics_generate_docs branch=t1087-kwm 2018-11-11 19:43:16 +00:00
Keith McCammon 2cf59e99fa Clean up for consistency, platform accuracy
No new atomic tests were added. One test was broken into two.
2018-11-11 12:41:49 -07:00
CircleCI Atomic Red Team doc generator f48234fc7f Generate docs from job=validate_atomics_generate_docs branch=clean-up-csmith 2018-11-10 22:54:09 +00:00
caseysmithrc 11b85d5596 fix-executor 2018-11-10 15:53:55 -07:00