Commit Graph

2253 Commits

Author SHA1 Message Date
Jesse Moore 5a67b43021 Create T1078.001 and yaml (#1178)
* Create T1078.001 and yaml

Creating Folder for sub technique and yaml for .001

* Update T1078.001.yaml

* Update T1078.001.yaml

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-06 08:49:27 -06:00
CircleCI Atomic Red Team doc generator bb59d266d5 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-05 04:28:13 +00:00
Jesse Moore dce7ce6949 Update T1040.yaml Use Built-in Windows Packet capture (#1172)
* Update T1040.yaml

 Uses the built-in Windows packet capture

* Update T1040

Adding temp folder and del command to delete that trace.etl and added sleep command before and after (it does a little bit of processing when stopped) with PowerShell.

* Update T1040.yaml

Changed to use variables where possible (couldn't get %temp% to work in the command) Use a long time out (50 seconds) as it took awhile for collections to complete . Added more description to explain what artifacts are left after execution. Thanks Carrie with all your time/input spent on this to make it great.

* Update T1040.yaml

added %LOCALAPPDATA%

* Update T1040.yaml

Switched to %temp%

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-04 22:27:30 -06:00
CircleCI Atomic Red Team doc generator ccb518616d Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-05 00:46:55 +00:00
harml3ss e0449bc608 Update T1003.004.yaml (#1170)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-04 18:46:28 -06:00
CircleCI Atomic Red Team doc generator 6165e9e71d Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-05 00:38:43 +00:00
Carrie Roberts a4277af9d6 fix for printing prereqs in md (#1171) 2020-08-04 18:38:06 -06:00
CircleCI Atomic Red Team doc generator 9af633aa05 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-04 17:51:19 +00:00
harml3ss c340a61f43 Create T1003.004.yaml (#1168)
* Create T1003.004.yaml

* remove some extra white space

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-04 11:50:49 -06:00
secjake f77c2a4f8b Update RegKey AppInit_DLLs Path (#1166) 2020-08-03 13:42:04 -06:00
CircleCI Atomic Red Team doc generator 55e967cd13 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-02 00:31:08 +00:00
wilsonwr 50c0326c5a T1053.001 test1 (#1165)
* Fix: only_platform circular argument reference

Remove a circular argument reference of only_platform, which was causing scripts in ./bin/ to error out when using Ruby version 2.7.

* Add T1053.001 Test 1

Co-authored-by: Billy Wilson <billy_wilson@byu.edu>
2020-08-01 18:30:38 -06:00
CircleCI Atomic Red Team doc generator d8dd757a24 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-01 22:54:55 +00:00
tlor89 34953ac95f T1070.003-Update (#1164)
* T1070.003-Update

* wording update

Co-authored-by: Toua Lor <tlor@nti.local>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-01 16:54:39 -06:00
CircleCI Atomic Red Team doc generator 5714759941 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-01 16:48:28 +00:00
Jake Hill e686b9944e Add mac test for T1518 that discovers Safari browser version (#1150)
Co-authored-by: Jake Hill <jake.hill@voya.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-01 10:48:13 -06:00
Michael Haag 2cc5348312 Fix T1551 to T1070 (#1161)
* Fix T1551 to T1070

Found that we had T1070 labeled incorrectly as T1551. MITRE pushed a fix for this per https://attack.mitre.org/resources/updates/updates-july-2020/

```
Indicator Removal on Host Was incorrectly re-IDd to T1551, restored to T1070 and its sub-techniques were changed to T1070.001, T1070.002, T1070.003, T1070.004, T1070.005, and T1070.006
```

* Generate MD fix

Attempting to get the MD to generate

* Update enterprise-attack.json

* Generate docs from job=validate_atomics_generate_docs branch=T1070-indicator-removal-fix

Co-authored-by: CircleCI Atomic Red Team doc generator <email>
2020-08-01 09:46:06 -06:00
wilsonwr c67a4f55f7 Fix: only_platform circular argument reference (#1160)
Remove a circular argument reference of only_platform, which was causing scripts in ./bin/ to error out when using Ruby version 2.7.
2020-07-30 11:36:12 -06:00
CircleCI Atomic Red Team doc generator 0edb546228 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-27 14:04:42 +00:00
Laken Harrell 3946f9880e added T1218.010 test 4 (#1155)
* added T1218.010 test 4

* Update T1218.010.yaml

removed template comments

Co-authored-by: Harrell <LHarrell@nti.local>
Co-authored-by: Michael Haag <mike@redcanary.com>
2020-07-27 08:04:20 -06:00
CircleCI Atomic Red Team doc generator 923f68a941 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-27 13:36:37 +00:00
P4T12ICK 5bb282f2e7 bug fix atomics in T1053.005 (#1156)
Co-authored-by: Patrick Bareiss <pbareib@splunk.com>
2020-07-27 07:36:02 -06:00
Sergio Gonzalez 36f83b728b Update Discovery.bat (#1154) 2020-07-23 09:57:55 -06:00
CircleCI Atomic Red Team doc generator a001d93114 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-20 23:42:37 +00:00
Danil Karandin 139386e8bd T1003 Creds Dumping with NPPSpy (#1149)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-07-20 17:41:47 -06:00
CircleCI Atomic Red Team doc generator a5216ecdd6 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-20 23:24:04 +00:00
Carrie Roberts e99213cfa6 configurable host to scan (#1148) 2020-07-20 17:23:24 -06:00
Bryan Richardson 7e7344f2c2 Add Golang repo to execution frameworks README (#1013)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-07-20 14:46:26 -06:00
CircleCI Atomic Red Team doc generator 979befcf8a Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-20 17:44:44 +00:00
JB b3da61d0a4 Improved automation by adding -accepteula option (#1144)
* added -accepteula flag for PsExec 

will make test seamless and fully automatable
ref https://github.com/redcanaryco/atomic-red-team/issues/1092

* Added reference to making tests not require interaction like -accepteula -q options

* added -accepteula to PsExec command

will make it automated

* Added /accepteula option to Autoruns execution in test 1

prior this may have prevented full automation of the test

* Update spec.yaml

* typo, nice catch cnotin

Co-authored-by: Clément Notin <clement@notin.org>

* fixing mystery text accidentally added to branch (rm'd)

* added -accepteula on psexec test, thanks @cnotin for the catch!

* added back in word, 'manually' removed in last pull acc.

thanks @cnotin

* removing /accepteula proposed previously, from test 1

Co-authored-by: Clément Notin <clement@notin.org>
2020-07-20 11:44:23 -06:00
CircleCI Atomic Red Team doc generator 5c7b60b218 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-20 16:17:21 +00:00
P4T12ICK 4836bfd525 T1136.001 new atomics (#1109)
* new atomic T1136_001

* new atomic T1136_001

* new atomic T1136_001

Co-authored-by: Patrick Bareiss <pbareib@splunk.com>
2020-07-20 10:17:05 -06:00
CircleCI Atomic Red Team doc generator 4d907c1c8e Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-20 16:15:36 +00:00
P4T12ICK 55133f23ee Atomics change t1021 001 atc (#1147)
* atomics T1021 changed

* changes

* changes

* changes

Co-authored-by: Patrick Bareiss <pbareib@splunk.com>
2020-07-20 10:15:18 -06:00
CircleCI Atomic Red Team doc generator 3d13b787ae Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-20 15:52:30 +00:00
JB 13397ba910 Directory clean-up (per spec.yaml) pass (#1146)
* moving shell script file to /src directory to meet spec.yaml

* fixing path to script in test 2 (just moved file in prior commit)

* fixed newline added a few mins ago

* fixed newline

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-07-20 09:52:14 -06:00
CircleCI Atomic Red Team doc generator e8340a678f Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-20 12:37:27 +00:00
Matt Graeber 1e373f8f6d Merge pull request #1142 from clr2of8/remove-problem-test
removing problematic test as described in issue 1105
2020-07-20 08:37:05 -04:00
Matt Graeber 5e90f9a2f1 Merge branch 'master' into remove-problem-test 2020-07-20 08:35:05 -04:00
CircleCI Atomic Red Team doc generator e80f7cfe29 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-18 03:04:26 +00:00
Tsora-Pop 801ff20807 atomic added to T1021.006 (#1116)
* T1021.006 evil-winrm atomic

* Update T1021.006.yaml

* Update T1021.006.yaml

fixed input args

* Update T1021.006.yaml

added Prereqs for Ruby and moved Evil-WinRM to a Prereq

* Update T1021.006.yaml

removed duplicate description and changed Ctrl + C to exit.

* Updated yaml

updated descriptions for prereqs. removed un-needed "exit" from cleanup_command.

* $env:username replaced

$env:username replaced with $env:Temp to account for when people have who have user profiles in althernative locations than C and also download to TEMP instead of Desktop.

* Removing cleanup_command

Removing cleanup_command as the evil-winrm is a prereq gem. in the future, if a cleanup_prereq_command is implemented this may be worth adding back in(gem uninstall evil-winrm -x).

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-07-17 21:03:58 -06:00
CircleCI Atomic Red Team doc generator f59bb10f9f Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-17 23:52:22 +00:00
bbucao 7c4a0fd25e T1046 Test 3 Nmap Port Scan from Windows (#1133)
* Update to fix dependency issues

* Update to fix dependency issues

* optimized code

Co-authored-by: Ben Bucao <bbucao@nti.local>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-07-17 17:51:56 -06:00
clr2of8 465476abb3 removing problematic test as described in issue 1105 2020-07-17 15:15:43 -06:00
CircleCI Atomic Red Team doc generator 00ad63fa2a Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-17 19:58:50 +00:00
Scoubi d1e3ba6991 Update T1555.003.yaml (#1137)
Add a line to include/force TLS1.2 in order for the prereq function to work on win2k16
All the credit to clr2of8 for sending me the string

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-07-17 13:58:10 -06:00
CircleCI Atomic Red Team doc generator 705e7aaadf Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-17 19:53:05 +00:00
Scoubi 276d32a79d Update T1003.001.yaml (#1138)
Add a line to include/force TLS1.2 in order for the prereq function to work on win2k16
All the credit to clr2of8 for sending me the string

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-07-17 13:52:37 -06:00
CircleCI Atomic Red Team doc generator 2b81b471d8 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-17 19:50:25 +00:00
Scoubi 15846f1c4a Update T1546.011.yaml (#1139)
Add a line to include/force TLS1.2 in order for the prereq function to work on win2k16
All the credit to clr2of8 for sending me the string

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-07-17 13:50:06 -06:00