Commit Graph

2933 Commits

Author SHA1 Message Date
CircleCI Atomic Red Team doc generator 29a063b40b Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:47:14 +00:00
CircleCI Atomic Red Team GUID generator e2cbd60596 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:47:07 +00:00
Adam Mashinchi 12843c96cf Merge pull request #1568 from redcanaryco/T1059.001-obfuscated-powershell
Add obfuscated PowerShell to T1059.001
2021-07-27 07:46:22 -07:00
Adam Mashinchi e6009bdbb3 Merge branch 'master' into T1059.001-obfuscated-powershell 2021-07-27 07:45:02 -07:00
CircleCI Atomic Red Team doc generator 1d8ca6c672 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:44:55 +00:00
CircleCI Atomic Red Team GUID generator 5e1b13f76f Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:44:49 +00:00
Adam Mashinchi e787817cf8 Merge branch 'master' into T1059.001-obfuscated-powershell 2021-07-27 07:44:28 -07:00
Adam Mashinchi b6c3dd4714 Merge pull request #1569 from redcanaryco/T1059.003-suspicious-execution
Add Suspicious Execution to T1059.003
2021-07-27 07:44:14 -07:00
Adam Mashinchi 48c159d3ea Merge branch 'master' into T1059.003-suspicious-execution 2021-07-27 07:43:27 -07:00
CircleCI Atomic Red Team doc generator 5956ac532b Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:42:34 +00:00
Adam Mashinchi 54f1913243 Merge branch 'master' into T1059.003-suspicious-execution 2021-07-27 07:42:29 -07:00
CircleCI Atomic Red Team GUID generator d55b581331 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-27 14:42:28 +00:00
Adam Mashinchi 3b350cf553 Merge pull request #1570 from redcanaryco/T1105-additional-powershell-example
Additional PowerShell Download in T1105
2021-07-27 07:42:00 -07:00
Matt Graeber 0960fca14e Update T1059.001.yaml
Removing extra space in line 379
2021-07-27 09:47:29 -04:00
Adam Mashinchi e8899b4df6 Additional PowerShell Download in T1105 2021-07-26 13:00:42 -07:00
Adam Mashinchi 64966be2fd Add Suspicious Execution to T1059.003 2021-07-26 12:57:10 -07:00
Adam Mashinchi ba20bcd95a Add obfuscated PowerShell to T1059.001
Additional obfuscated PowerShell example.
2021-07-26 12:52:18 -07:00
CircleCI Atomic Red Team doc generator 4ab80721ac Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-19 21:21:58 +00:00
Josh Rickard 9d2212bd20 T1543.004 - Updated cleanup key (#1553)
Updated the key `cleanup` to `cleanup_command` to conform to other tests.

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2021-07-19 15:21:15 -06:00
CircleCI Atomic Red Team doc generator 0f8eb34b74 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-19 21:20:24 +00:00
Josh Rickard 842a5df879 T1056.001 - Updating dependencies (#1555)
* T1056.001 - Updating dependencies

Moved `prereq_command` and `get_prereq_command` under dependencies to conform to other tests

* white space correction

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2021-07-19 15:19:59 -06:00
Adam Mashinchi b402f11979 Update the README as per Wiki Update (#1550)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2021-07-19 15:15:04 -06:00
CircleCI Atomic Red Team doc generator 6f2bf060fb Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-19 20:51:52 +00:00
Josh Rickard df34cadff9 T1135 - Fixed key name in executor test (#1552)
* Fixed key name of `elevation_require` to `elevation_required`
2021-07-19 14:51:21 -06:00
CircleCI Atomic Red Team doc generator 4af8bae9f4 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-14 17:14:29 +00:00
CircleCI Atomic Red Team GUID generator 1f82f6af1f Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-14 17:14:23 +00:00
Jay_darknight d42bda32a1 Dump svchost.exe to gather RDP plaintext credential (#1551) 2021-07-14 11:13:59 -06:00
dependabot[bot] 223584b41f Bump addressable from 2.7.0 to 2.8.0 (#1549)
Bumps [addressable](https://github.com/sporkmonger/addressable) from 2.7.0 to 2.8.0.
- [Release notes](https://github.com/sporkmonger/addressable/releases)
- [Changelog](https://github.com/sporkmonger/addressable/blob/main/CHANGELOG.md)
- [Commits](https://github.com/sporkmonger/addressable/compare/addressable-2.7.0...addressable-2.8.0)

---
updated-dependencies:
- dependency-name: addressable
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2021-07-13 12:13:33 -06:00
CircleCI Atomic Red Team doc generator d50e69b5c8 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-09 15:35:13 +00:00
Carrie Roberts 79e706f2df fix cleanup cmd as per issue #1543 (#1548) 2021-07-09 09:34:32 -06:00
CircleCI Atomic Red Team doc generator b51f415e30 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-08 17:23:38 +00:00
CircleCI Atomic Red Team GUID generator 6c2c28f497 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-08 17:23:32 +00:00
Clément Notin 2411b36008 T1098.001: implement AAD application hijacking tests (#1454)
* T1098.001: implement AAD application hijacking tests

Create Azure AD Application Hijacking Tests

* T1098.001 : add end of test string

* T1098.001: use new "azure-ad" platform

* T1098.001: use new "azure-ad" platform

* Update T1098.001.yaml

* Update T1098.001.yaml

* Update T1098.001.yaml

Co-authored-by: piaconsigny <49986009+piaconsigny@users.noreply.github.com>
2021-07-08 11:23:05 -06:00
CircleCI Atomic Red Team doc generator 66bf3375ba Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-08 17:21:56 +00:00
CircleCI Atomic Red Team GUID generator 6036df88ac Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-08 17:21:50 +00:00
piaconsigny 62943530e9 T1110.001 azureadaccounts (#1482)
* T1110.001 azureadaccounts

* Update T1110.001.yaml

* Apply suggestion

* Remove typo

Co-authored-by: Clément Notin <cnotin@tenable.com>
2021-07-08 11:21:08 -06:00
CircleCI Atomic Red Team doc generator 6f40c444af Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-07 17:38:50 +00:00
Clément Notin 1a4c4a97d2 Improve discoverability of "Active Directory" attacks (#1544) 2021-07-07 11:38:22 -06:00
CircleCI Atomic Red Team doc generator 412b05ad26 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-06 20:24:45 +00:00
CircleCI Atomic Red Team GUID generator 08b524ecf6 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-06 20:24:39 +00:00
Ayantaker 572f6e2fc5 Added a new test - XOR Encoded data to T1132.001 'Data Encoding: Standard Encoding (#1542)
* Added a new test - XOR Encoded data to T1132.001 'Data Encoding: Standard Encoding'

* change default url to example.com

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2021-07-06 14:24:19 -06:00
CircleCI Atomic Red Team doc generator e54b5b1d48 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-02 17:00:00 +00:00
CircleCI Atomic Red Team GUID generator 155ba706b9 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-02 16:59:54 +00:00
Bhavin Patel e41d672ebe Merge pull request #1483 from AlsidOfficial/pr-passwordspraying-azure
T1110.003 azureadaccounts
2021-07-02 11:59:27 -05:00
piaconsigny 841c509aa0 Merge branch 'master' into pr-passwordspraying-azure 2021-07-02 09:49:07 -07:00
CircleCI Atomic Red Team doc generator 1e024d99ea Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2021-07-02 12:38:23 +00:00
Matt Graeber bb46c17c3c Merge pull request #1540 from clr2of8/mv-invoke-maldoc
moving invoke-maldoc into art repo
2021-07-02 08:37:52 -04:00
piaconsigny b62c0a024a Apply suggestion 2021-07-02 13:53:39 +02:00
piaconsigny 6f2f97ad74 Apply suggestion 2021-07-02 13:50:01 +02:00
Carrie Roberts c0e5117730 moving invoke-maldoc into art repo 2021-07-01 20:11:10 -06:00