Atomic Red Team doc generator
819934cc3f
Generated docs from job=generate-docs branch=master [ci skip]
2022-06-16 22:47:00 +00:00
Atomic Red Team doc generator
5a14d96c37
Generated docs from job=generate-docs branch=master [ci skip]
2022-06-15 21:35:21 +00:00
tccontre
a768529778
Creates Schedule task with hidden attribute settings ( #1986 )
...
* Update T1112.yaml
* Update T1112.yaml
* typos
* Update T1087.002.yaml
* Update T1087.002.yaml
* Update T1087.002.yaml
* Add files via upload
* Update T1053_05_SCTASK_HIDDEN_ATTRIB.xml
* Update T1053.005.yaml
* Update T1053.005.yaml
* Update T1087.002.yaml
* Update T1087.002.yaml
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2022-06-03 18:03:49 -06:00
CircleCI Atomic Red Team doc generator
ba46d54c29
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2022-04-07 15:40:23 +00:00
NoL1mit
9c4cb3a099
Surround time variable in single quotes ( #1855 )
...
* Surround time variable in single quotes
The time in the YAML file should be wrapped in single quotes due to the colon being interpreted to have special meaning.
* Update T1053.005.yaml
Fixed parameters versus command logic
2022-04-07 09:39:55 -06:00
CircleCI Atomic Red Team doc generator
0e616b34b3
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2022-03-02 22:00:09 +00:00
CircleCI Atomic Red Team GUID generator
28e7237bc1
Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2022-03-02 22:00:03 +00:00
SecWilson
b62ba2e548
Atomic that mimics recent Qakbot behavior ( #1793 )
...
* Atomic that mimics recent Qakbot behavior
* small edits
removed elevation_required, shortened test name, made some readability updates.
Co-authored-by: Wilson <SWilson@nti.local >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2022-03-02 14:59:28 -07:00
CircleCI Atomic Red Team doc generator
bc21f59ff0
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-09-04 00:21:31 +00:00
Josh Rickard
1513717eb2
Updating atomics to conform to standard ( #1619 )
...
* Updated format of input_argument types for Url
* Updated type for input_arguments to Url (missed)
* Updating Path type for input_arguments
* Updated String type for input_arguments
* Missed a few Strings and Url types
* Updated default values for input_arguments to align with their types
* Updated Integer type for input_arguments
* Updated formatting and spacing of atomics
2021-09-03 18:20:46 -06:00
CircleCI Atomic Red Team doc generator
c5d92e8cc0
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-07-30 23:00:49 +00:00
Carrie Roberts
9bf1327611
fix cleanup command ( #1575 )
2021-07-30 17:00:00 -06:00
CircleCI Atomic Red Team doc generator
1e024d99ea
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-07-02 12:38:23 +00:00
Carrie Roberts
c0e5117730
moving invoke-maldoc into art repo
2021-07-01 20:11:10 -06:00
CircleCI Atomic Red Team doc generator
36d49de4c8
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-24 17:04:33 +00:00
CircleCI Atomic Red Team doc generator
575b36a8e6
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-24 15:16:54 +00:00
CircleCI Atomic Red Team doc generator
88ad3fd322
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-16 18:41:22 +00:00
SecurityShrimp
42799b033d
added TLS/SSL v1.2 enabling commands to any atomic test utilizing IWR ( #1519 )
...
* Update T1204.002.md
Added lines to each test using IWR for invoke-webrequest to set the acceptable TLS versions for the commands to complete successfully by prepending the tests with
```[Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12```
* Update T1555.yaml
added line to set ssl/tls version
* Update T1134.001.yaml
updated IWR lines to allow ssl/tls version 1.2
* Update T1069.002.yaml
added lines to every IWR instance to set ssl/tls version to 1.2
* Update T1558.003.yaml
added line to allow TLS/SSL 1.2
* Update T1033.yaml
added command to enable SSL/TLS v1.2
* Update T1055.012.yaml
added command to enable TLS/SSL v1.2
* Update T1115.yaml
Added command to enable SSL/TLS v1.2
* Update T1070.001.yaml
added command enabling SSL/TLS v 1.2
* Update T1564.yaml
added commands to enable SSL/TLS v 1.2
* Update T1566.001.yaml
added command to enable SSL/TLS V1.2
* Update T1135.yaml
added command to enable SSL/TLS v1.2
* Update T1055.yaml
added commands to enable TLS/SSL v 1.2
* Update T1110.003.yaml
added command to enable TLS/SSL v1.2
* Update T1003.yaml
Added command to enable TLS/SSL v1.2
* Update T1053.005.yaml
added command to enable TLS/SSL v1.2
* Update T1003.001.yaml
added commands to enable TLS/SSL v1.2 for any command using invoke-webrequest
* Update T1069.002.yaml
syntax correction
* Update T1134.001.yaml
syntax correction
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2021-06-16 12:41:04 -06:00
CircleCI Atomic Red Team doc generator
5dd066ec61
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-04-30 20:50:27 +00:00
CircleCI Atomic Red Team GUID generator
50f1ea7a06
Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-04-30 20:50:22 +00:00
Ján Trenčanský
731a7c9ed6
T1053.005 create SchduledTask using WMI class ( #1434 )
...
* ScheduledTask via WMI
* Fix typos and XML load
* Fix wrong cmdlet name in test name
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2021-04-30 14:49:42 -06:00
CircleCI Atomic Red Team doc generator
228dcb1ae3
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-04-02 13:28:54 +00:00
Carrie Roberts
8b6c9af427
add usebasicparsing flag ( #1410 )
2021-04-02 07:28:29 -06:00
Keith McCammon
28086402e2
Maintainers updates ( #1328 )
...
* Update maintainers.md
Remove reference to announcements channel, which has been created.
* Generate docs from job=validate_atomics_generate_docs branch=maintainers-updates
* Update maintainers.md
Updates to maintainers meeting purpose, scope, and agendas.
* Generate docs from job=validate_atomics_generate_docs branch=maintainers-updates
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-12-15 14:18:41 -07:00
Ama Smuggle Avocados
4fc97b9206
Taskscheduler ( #1317 )
...
* initial push for T1053.005 (Task Scheduler via VBA)
* updates
* updates
* updates
Co-authored-by: avocado <avocados@smuggler.com >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-12-10 09:42:46 -07:00
CircleCI Atomic Red Team doc generator
910a2a764a
Generate docs from job=validate_atomics_generate_docs branch=master
2020-09-29 13:53:28 +00:00
CircleCI Atomic Red Team doc generator
923f68a941
Generate docs from job=validate_atomics_generate_docs branch=master
2020-07-27 13:36:37 +00:00
P4T12ICK
5bb282f2e7
bug fix atomics in T1053.005 ( #1156 )
...
Co-authored-by: Patrick Bareiss <pbareib@splunk.com >
2020-07-27 07:36:02 -06:00
CircleCI Atomic Red Team doc generator
01f44d4333
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-26 19:00:18 +00:00
Clément Notin
bdb98ff77b
T1053.005: in remote schtasks, we need username and password for authentication ( #1093 )
...
/RU and /RP are credentials for "runas" when running the task, not for remote auth when creating it
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-06-26 12:59:54 -06:00
CircleCI Atomic Red Team doc generator
7d473448df
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-19 22:58:17 +00:00
Clément Notin
8869067e86
T1053.005: scheduled task creation doesn't require admin ( #1045 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-06-19 16:57:46 -06:00
CircleCI Atomic Red Team doc generator
ffb170aa83
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-19 22:21:43 +00:00
Clément Notin
5a5807aba7
T1053.005: execute remotely the cleanup command, after remote creation of scheduled task ( #1070 )
...
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-06-19 16:21:23 -06:00
CircleCI Atomic Red Team doc generator
8a82e9b66a
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-18 01:57:35 +00:00
Carrie Roberts
24549e3866
Convert to Mitre ATT&CK sub-technique schema ( #1056 )
...
* Initial transfer of atomics to MITRE subtechniques
* Add GUIDs back in, attack_technique to string (#1019 )
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* Subtechnique transfer T1220-T1546.005 (#1020 )
* Create T1222.001.yaml
* Create T1222.002.yaml
* Create T1505.002.yaml
* Update T1543.003.yaml
* Update AtomicService.cs
* Update T1546.005.yaml
* Delete T1222.yaml
* Update T1482.yaml
* Update T1485.yaml
* Update T1220.yaml
* Update T1489.yaml
* Update T1490.yaml
* Update T1496.yaml
* Update T1505.003.yaml
* Update T1505.yaml
* Update T1518.001.yaml
* Update T1518.yaml
* Update T1529.yaml
* Update T1543.004.yaml
* Update T1546.001.yaml
* Update T1546.002.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.002.yaml
* Update T1543.001.yaml
* Update T1518.001.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1531.yaml
* Update T1222.001.yaml
* Update T1222.002.yaml
* Update T1505.002.yaml
* Update T1505.003.yaml
* Update T1518.001.yaml
* Update T1543.001.yaml
* Update T1546.005.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.003.yaml
* Update T1543.002.yaml
* added auto_generated_guid 1220
* added T1222.001 auto_generated_guid
* Update T1222.002.yaml
added auto_generated_guid entries
* Update T1482.yaml
auto_generated_guid added
* Update T1485.yaml
added auto_generated_guids
* Update T1489.yaml
added auto_generated_guids
* Update T1490.yaml
added auto_generated_guids
* Update T1496.yaml
added auto_generated_guid
* Update T1505.002.yaml
added auto_generated_guid from old T1505 same atomic
* Update T1505.003.yaml
added auto_generated_guid from previous atomic 1100
* Delete T1505.yaml
no longer needed, moved to 1505.002
* Update T1518.yaml
added auto_generated_guids
* Update T1529.yaml
added auto_generated_guids
* Update T1531.yaml
added auto_generated_guids
* Update T1543.001.yaml
added auto_generated_guid
* Update T1543.002.yaml
added auto_generated_guid
* Update T1543.004.yaml
added auto_generated_guid
* Update T1546.001.yaml
added auto_generated_guid
* Update T1546.002.yaml
added auto_generated_guid
* Update T1546.003.yaml
* Update T1546.004.yaml
added auto_generated_guid
* Update T1546.005.yaml
added auto_generated_guid
* add guids back in
* fix spacing issue
* fix spacing
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Sub-techniques T1053-T1113 - Updates (#1022 )
* Sub-techniques T1053-T1113 - Updates
Updated techniques for sub-techniques.
* minor fixes
format fixing
* Added GUIDs
- Added GUIDs back
- Fixed typo (T1054)
- Fixed attack_technique from an array to a string
* Sub-technique updates T1546.008 through T1574.011 (#1024 )
* sub technique updates
* sub technique updates
* sub technique updates
* Carrie updates (#1017 )
* updated T1110,12,13
* updated T1114
* updated T1114
* updated T1115
* updated T1119
* updated T1123,24
* updated T1127
* updated T1114
* updated T1127
* updated T1132
* T1134.004
* T1134.004
* updated T1135
* updated T1136
* updated T1137
* updated T1140
* remove depracted T1153
* updated T1176
* updated T1197
* updated T1201
* updated T1202
* updated T1204
* updated T1207
* updated T1216
* updated T1204
* updated T1217
* updated T1218
* updated T1218
* updated T1219
* updated T1218
* attack_technique to string
* Subtechnique transfer (#1025 )
* T1003 review
* T1005 manual review changes
* T1027.002 sub-technique review
* T1027.004 sub-technique review
* T1036 sub-technique review
* T1037 sub-technique review
* T1048 sub-technique review
* YAML bugfixes
* Adding auto-generated GUIDs back to tests
* merging with Mike's PR
* Merging with Carrie's PR
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Subtechnique fix (#1026 )
* add atomic_tests: element
* add atomic_tests: element
* more fixes
* more fixes
* more fixes
* sub technique minor fixes 1 (#1027 )
* fixes
* fixes
* more fixes
* more fixes
* display name fix (#1028 )
* remove some deprecated stuff. reorganize a little (#1031 )
* Gendocs fix (#1033 )
* gendocs updates for subtechniques
* add folders
* ignore auto generated markdown files
* remove tmp files
* add tmp files
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
* navigator layer v3.0
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
Co-authored-by: Matt Graeber <60448025+mgraeber-rc@users.noreply.github.com >
Co-authored-by: Tsora-Pop <35981510+Tsora-Pop@users.noreply.github.com >
Co-authored-by: Michael Haag <mike@redcanary.com >
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
2020-06-17 12:55:46 -06:00