Commit Graph

3730 Commits

Author SHA1 Message Date
Jay_darknight 32aec500d4 Added module license to the T1014.c (#1864) 2022-04-12 12:29:59 -06:00
CircleCI Atomic Red Team doc generator 8d11407f52 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-12 18:28:03 +00:00
Jay_darknight 8cb901bd91 Update the prereq commands for T1014-1,2 tests (#1863) 2022-04-12 12:27:38 -06:00
CircleCI Atomic Red Team doc generator b354cd4ed1 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-11 20:06:00 +00:00
CircleCI Atomic Red Team GUID generator 98659aee67 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-11 20:05:54 +00:00
Matt Graeber 40ce7a7cea Adding and refactoring msiexec tests (#1861) 2022-04-11 14:05:24 -06:00
CircleCI Atomic Red Team doc generator 905e3df079 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-11 15:38:05 +00:00
jovial7 3a00e9fe6a Deleting test (TamperData) (#1860)
Deleting test 'Disable Windows Defender Tamper Protection'

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-11 09:37:33 -06:00
frack113 80b1e0e591 Add T1195 (#1858)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-11 09:32:29 -06:00
CircleCI Atomic Red Team doc generator 23d30f599d Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-11 15:26:24 +00:00
frack113 3fb0610204 Fix prereq_command test 2 (#1857)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-11 09:25:50 -06:00
CircleCI Atomic Red Team doc generator da4d80c694 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-11 15:22:21 +00:00
Leo Verlod f13ec2fb08 Rewriting T1036 Test 1 in Powershell (#1859) 2022-04-11 09:21:40 -06:00
CircleCI Atomic Red Team doc generator 4d713c6a01 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-08 15:13:11 +00:00
lucasRiley 38d904f4f1 T1003.002 #4, Powerdump Improvement (#1856)
* T1003.002 #4 Improvement

* T1003.002 #4 Improvement

* keep previous guid

Co-authored-by: Riley <lriley@NTI.local>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-08 09:12:28 -06:00
CircleCI Atomic Red Team doc generator ba46d54c29 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-07 15:40:23 +00:00
NoL1mit 9c4cb3a099 Surround time variable in single quotes (#1855)
* Surround time variable in single quotes

The time in the YAML file should be wrapped in single quotes due to the colon being interpreted to have special meaning.

* Update T1053.005.yaml

Fixed parameters versus command logic
2022-04-07 09:39:55 -06:00
CircleCI Atomic Red Team doc generator 58880ec29c Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-05 22:56:27 +00:00
CircleCI Atomic Red Team GUID generator f8cfabb253 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-05 22:56:22 +00:00
Liam Somerville fc30a1ea05 T1078.003.yaml - Add MacOS commands (#1851)
* T1078.003.yaml - Add MacOS commands

add mac os commands to create user

* Update T1078.003.yaml

remove list users, better technique described under T1087.001

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-05 16:56:04 -06:00
CircleCI Atomic Red Team doc generator f290e08d83 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-05 21:45:23 +00:00
CircleCI Atomic Red Team GUID generator 1d109a96b7 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-05 21:45:18 +00:00
Liam Somerville 3cade57156 Update T1082.yaml - Add System Integrity Protection status (MacOS) (#1852)
* Update T1082.yaml - Add System Integrity Protection status (MacOS)

csrutil is commonly used by malware and post-exploitation tools to determine whether certain files and directories on the system are writable or not. This command checks and displays System Integrity Protection status.

* Update T1082.yaml

* Update T1082.yaml

fix formatting issues
2022-04-05 15:44:46 -06:00
CircleCI Atomic Red Team doc generator 66f6f4d8b2 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-05 15:59:36 +00:00
CircleCI Atomic Red Team GUID generator d758660559 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-05 15:59:31 +00:00
Leo Verlod cbeebddaa4 Adding T1562.001 Test 28 (Issue 1839) (#1845)
* Adding T1562.001 Test 28 (Issue 1839)

* Updating T1562.001 YAML to include additional input arg and cleanup

* make folder delete optional

* Update T1562.001.yaml

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-05 09:59:08 -06:00
Carrie Roberts 5006f24bfb add cloud executors (#1848) 2022-04-04 12:36:12 -06:00
CircleCI Atomic Red Team doc generator 0f612a3f16 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-04 12:54:36 +00:00
CircleCI Atomic Red Team GUID generator 7f144097c6 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-04 12:54:30 +00:00
Leo Verlod 92825f626b Create T1539 Test 1 - Steal Firefox Cookies (#1842)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-04 06:54:08 -06:00
CircleCI Atomic Red Team doc generator 51b7c9fe77 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-04 12:50:31 +00:00
CircleCI Atomic Red Team GUID generator 961f8c7e80 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-04 12:50:24 +00:00
IntelScott 3fb3fb2a84 Create T1555.004.yaml (#1843)
* Create T1555.004.yaml

* remove blank auto-generated guid

* use standard quotes

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-04 06:49:57 -06:00
CircleCI Atomic Red Team doc generator 14f6ec8047 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-04 12:42:03 +00:00
frack113 750f0ae00c Fix test 33-34 (#1844) 2022-04-04 06:41:33 -06:00
CircleCI Atomic Red Team doc generator bbe0da2d8a Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-03 01:03:02 +00:00
MrOrOneEquals1 f8a2984634 do a little cleanup immediately to avoid execution issues with later tests (#1841) 2022-04-02 19:02:27 -06:00
CircleCI Atomic Red Team doc generator 1302296c39 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-01 15:08:14 +00:00
Carrie Roberts 0686474ce2 remove atomic until it can be fixed (#1840) 2022-04-01 09:07:40 -06:00
Jose Enrique Hernandez a5576220c0 first skeleton of github ci files (#1836)
* first skeleton of github ci files

* removing guids gen for now

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2022-04-01 08:41:15 -06:00
CircleCI Atomic Red Team doc generator 7091fa8b16 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-01 14:37:00 +00:00
Jose Enrique Hernandez dfb7aef0b4 Merge pull request #1837 from clr2of8/nav-filter2
add nav layer filters and update enterprise-attack.json
2022-04-01 10:36:31 -04:00
Jose Enrique Hernandez 225d39ed9a Merge branch 'master' into nav-filter2 2022-04-01 10:11:02 -04:00
CircleCI Atomic Red Team doc generator 3c7b481fc8 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-01 13:59:40 +00:00
CircleCI Atomic Red Team GUID generator b0859bc9e4 Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-04-01 13:59:32 +00:00
Carrie Roberts d9f09df84a move to different T# (#1838)
* moving T# to better fit

* moving T# to better fit

* moving T# to better fit
2022-04-01 07:58:53 -06:00
Carrie Roberts bc3e0c1745 add nav layer filters and update enterprise-attack.json 2022-03-31 21:07:38 -06:00
CircleCI Atomic Red Team doc generator 17a758ade1 Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-31 20:37:38 +00:00
CircleCI Atomic Red Team GUID generator 6618ffa41a Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci] 2022-03-31 20:37:33 +00:00
Michael Haag b2a0d07d9b Add Root Certificate to CurrentUser (#1835) 2022-03-31 14:37:10 -06:00