Atomic Red Team doc generator
65348695f9
Generated docs from job=generate-docs branch=master [ci skip]
2024-01-18 21:57:17 +00:00
Atomic Red Team GUID generator
9141822411
Generate GUIDs from job=generate-docs branch=master [skip ci]
2024-01-18 21:57:04 +00:00
Bhavin Patel
640330c513
Updated PR 2461 2463 into a new one ( #2655 )
...
* updating ttp
* updating atomics from PR and adding new
* update command
---------
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2024-01-18 15:56:30 -06:00
Atomic Red Team doc generator
b2204555cf
Generated docs from job=generate-docs branch=master [ci skip]
2023-10-02 20:45:35 +00:00
Atomic Red Team GUID generator
19c71c2a40
Generate GUIDs from job=generate-docs branch=master [skip ci]
2023-10-02 20:45:17 +00:00
Mohana Shankar D
3397666c5c
New Atomic Test: PromptOnSecureDesktop ( #2549 )
...
* New Atomic Test: PromptOnSecureDesktop
* Update T1548.002.yaml
---------
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2023-10-02 14:44:36 -06:00
Atomic Red Team doc generator
a228ee8656
Generated docs from job=generate-docs branch=master [ci skip]
2023-09-22 19:15:21 +00:00
Carrie Roberts
d4709021fb
Handle spaces in file paths ( #2535 )
...
* updating atomics count in README.md [ci skip]
* wip
* handle spaces in path
* update readme
* fix typo
---------
Co-authored-by: publish bot <opensource@redcanary.com >
2023-09-22 10:47:25 -06:00
Atomic Red Team doc generator
cef46e4479
Generated docs from job=generate-docs branch=master [ci skip]
2023-06-15 16:17:12 +00:00
Carrie Roberts
068d32b1ea
use ExternalPayloads directory ( #2460 )
...
* use ExternalPayloads directory
* use ExternalPayloads directory
* use ExternalPayloads directory
2023-06-15 10:16:12 -06:00
Atomic Red Team doc generator
b1f3c968f2
Generated docs from job=generate-docs branch=master [ci skip]
2023-05-19 17:06:33 +00:00
Josh Rickard
284886292b
Atomic Red Team - JSON Schema Validation CI ( #2303 )
...
* feat: Adding atomic-red-team JSON Schema defintions
* feat: Adding validate.py script to validate all atomics against the defined schema
* feat: Adding validate-schema GitHub Workflow action to validate on every push to the repo
* ci: Updated the validate-schema workflow to support and use Ruby instead of python
* fix: Updated schema to remove schema draft version (not necessarily needed) and update to remove elevation_required as a required defined property
* fix: Removed the yaml schema version
* docs: Adding start of README
* fix: Adding an updated/better version of the python validation but may ultimately be removed
* feat: Adding Ruby version of validate.rb script
* fix: Removing files not needed since we are changing to github action and using the new validation code
* fix: Adding the yaml schema file back and removed the json version
* docs: Updated README with documentation
* fix: Updating schema to use new format validator
* fix: Updated validate.rb to verify that the Technique IDs are in the correct format.
* fix: Upating validate.rb to raise execptions so that failures flow up to the GitHub Action workflow
* fix: Updated all tests that have input_arguments not conformaing to schema defintion for type value of path
* fix: Updating the Validaton README for typos
* fixL: Minor updates to the schema
* minor schema changes
* github actions fix
* schema changes
---------
Co-authored-by: MSAdministrator <MSAdministrator@users.noreply.github.com >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
Co-authored-by: Hare Sudhan <code@0x6c.dev >
2023-05-12 15:33:47 -06:00
Atomic Red Team doc generator
16594d72c5
Generated docs from job=generate-docs branch=master [ci skip]
2023-02-13 23:11:19 +00:00
Josh Rickard
a5dd0813cd
fix: Updating atomics YAML file structure to align with the new JSON schema definition ( #2323 )
...
* fix: Updating atomics YAML file structure to align with the new JSON schema definition.
This also fixes some white space issues and general line formatting across all impacted atomics.
* fix: One additional change needed
---------
Co-authored-by: MSAdministrator <MSAdministrator@users.noreply.github.com >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2023-02-13 16:10:37 -07:00
Atomic Red Team doc generator
c17e4303bc
Generated docs from job=generate-docs branch=master [ci skip]
2022-12-14 22:50:55 +00:00
Carrie Roberts
063610ad8e
correct name
2022-12-03 18:37:00 -05:00
Atomic Red Team doc generator
54f7393181
Generated docs from job=generate-docs branch=master [ci skip]
2022-11-15 23:53:18 +00:00
Atomic Red Team GUID generator
f5526d45fd
Generate GUIDs from job=generate-docs branch=master [skip ci]
2022-11-15 23:53:11 +00:00
Michael Haag
2d6d00c01c
Update T1548.002.yaml - WSReset UAC Bypass ( #2232 )
...
* Update T1548.002.yaml
* removed elevation requirement
2022-11-15 18:52:41 -05:00
Atomic Red Team doc generator
c55f3ecce0
Generated docs from job=generate-docs branch=master [ci skip]
2022-11-07 21:25:36 +00:00
Carrie Roberts
ee954d215c
mv 2 1547 tests to 1546 ( #2223 )
2022-11-07 14:25:09 -07:00
Atomic Red Team doc generator
84cd4177fe
Generated docs from job=generate-docs branch=master [ci skip]
2022-10-13 17:48:19 +00:00
harshalcoep
a7bf035f55
Modify description of "Disable UAC admin consent prompt" ( #2184 )
...
Changing the description of atomic test 251c5936-569f-42f4-9ac2-87a173b9e9b8 from "modifying the registry key" to "setting the registry key". In this context, the word "setting" sounds more appropriate than "modifying".
2022-10-13 11:47:48 -06:00
Atomic Red Team doc generator
112ee4dd2e
Generated docs from job=generate-docs branch=master [ci skip]
2022-10-13 14:20:53 +00:00
harshalcoep
c566f8d83f
New Atomic-Test ( #2183 )
...
* New Atomic-Test
Proposing a new atomic test "Disable UAC admin consent prompt". The existing atomic test with guid 9e8af564-53ec-407e-aaa8-3cb20c3af7f9) disables UAC by setting "EnableLUA" registry value to 0. UAC can also be disabled by setting "ConsentPromptBehaviorAdmin" registry value to 0 (https://learn.microsoft.com/en-us/openspecs/windows_protocols/ms-gpsb/341747f5-6b5d-4d30-85fc-fa1cc04038d4 ). This registry value has been altered by several malwares in the past (https://cloudsek.com/technical-analysis-of-medusalocker-ransomware/ , https://blogs.blackberry.com/en/2022/01/threat-thursday-purple-fox-rootkit , https://blogs.blackberry.com/en/2021/06/threat-thursday-avaddon-ransomware-uses-ddos-attacks-as-triple-threat ). Hence, proposing a new atomic test with guid 251c5936-569f-42f4-9ac2-87a173b9e9b8 that bypasses UAC by setting the registry key HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\ConsentPromptBehaviorAdmin to 0.
* add blog links
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2022-10-13 08:20:18 -06:00
Atomic Red Team doc generator
d0dad62dbc
Generated docs from job=generate-docs branch=master [ci skip]
2022-09-23 22:57:18 +00:00
Atomic Red Team doc generator
819934cc3f
Generated docs from job=generate-docs branch=master [ci skip]
2022-06-16 22:47:00 +00:00
Atomic Red Team doc generator
a971545b2a
Generated docs from job=generate-docs branch=master [ci skip]
2022-05-12 00:45:32 +00:00
Atomic Red Team GUID generator
f45cfaa33a
Generate GUIDs from job=generate-docs branch=master [skip ci]
2022-05-12 00:45:27 +00:00
tlor89
ff1f81472c
WinPwn Bypass UAC ( #1941 )
...
Co-authored-by: Toua Lor <tlor@nti.local >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2022-05-11 18:45:03 -06:00
CircleCI Atomic Red Team doc generator
021449e282
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2022-02-28 19:20:26 +00:00
Carrie Roberts
a1f4a9b8e2
move uacme.zip into RC repo ( #1790 )
...
* move uacme.zip into RC repo
* set outfile
2022-02-28 12:19:52 -07:00
CircleCI Atomic Red Team doc generator
69c0e80bce
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-10-01 14:33:29 +00:00
CircleCI Atomic Red Team GUID generator
68dd3dbf48
Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-10-01 14:33:24 +00:00
zedutchmann
6d358b996c
Updated T1548.002.yaml file ( #1636 )
...
* Update T1548.002.yaml
Added (11) tests from UACMe project
* Update T1548.002.yaml
Added permalink for .zip file and changed descriptions
* Update T1548.002.yaml
* removed nonworking methods 37,58,65
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2021-10-01 08:33:02 -06:00
CircleCI Atomic Red Team doc generator
bc21f59ff0
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-09-04 00:21:31 +00:00
Josh Rickard
1513717eb2
Updating atomics to conform to standard ( #1619 )
...
* Updated format of input_argument types for Url
* Updated type for input_arguments to Url (missed)
* Updating Path type for input_arguments
* Updated String type for input_arguments
* Missed a few Strings and Url types
* Updated default values for input_arguments to align with their types
* Updated Integer type for input_arguments
* Updated formatting and spacing of atomics
2021-09-03 18:20:46 -06:00
CircleCI Atomic Red Team doc generator
36d49de4c8
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-24 17:04:33 +00:00
CircleCI Atomic Red Team doc generator
575b36a8e6
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-24 15:16:54 +00:00
CircleCI Atomic Red Team doc generator
7549cc7d61
Generate docs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-03 02:48:44 +00:00
CircleCI Atomic Red Team GUID generator
3726625d58
Generate GUIDs from job=generate_and_commit_guids_and_docs branch=master [skip ci]
2021-06-03 02:48:38 +00:00
tlor89
980c7e8bd5
T1548.002-Update ( #1492 )
...
* T1548.002-Update
* formatting
Co-authored-by: Toua Lor <tlor@nti.local >
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2021-06-02 20:48:22 -06:00
Keith McCammon
28086402e2
Maintainers updates ( #1328 )
...
* Update maintainers.md
Remove reference to announcements channel, which has been created.
* Generate docs from job=validate_atomics_generate_docs branch=maintainers-updates
* Update maintainers.md
Updates to maintainers meeting purpose, scope, and agendas.
* Generate docs from job=validate_atomics_generate_docs branch=maintainers-updates
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2020-12-15 14:18:41 -07:00
Matt Graeber
e9cb3c2f59
Update README.md ( #1302 )
...
* Update README.md
Updating execution frameworks link.
* Generate docs from job=validate_atomics_generate_docs branch=mgraeber-rc-patch-1
* Generate docs from job=validate_atomics_generate_docs branch=mgraeber-rc-patch-1
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
Co-authored-by: Michael Haag <mike@redcanary.com >
2020-11-30 09:18:32 -07:00
P4T12ICK
83b21a9487
atomic for disable UAC ( #1289 )
...
Co-authored-by: P4T12ICK <pbareib@splunk.com >
2020-11-20 09:17:23 -07:00
CircleCI Atomic Red Team doc generator
910a2a764a
Generate docs from job=validate_atomics_generate_docs branch=master
2020-09-29 13:53:28 +00:00
CircleCI Atomic Red Team doc generator
8a82e9b66a
Generate docs from job=validate_atomics_generate_docs branch=master
2020-06-18 01:57:35 +00:00
Carrie Roberts
24549e3866
Convert to Mitre ATT&CK sub-technique schema ( #1056 )
...
* Initial transfer of atomics to MITRE subtechniques
* Add GUIDs back in, attack_technique to string (#1019 )
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* technique to string and add guids back in
* Subtechnique transfer T1220-T1546.005 (#1020 )
* Create T1222.001.yaml
* Create T1222.002.yaml
* Create T1505.002.yaml
* Update T1543.003.yaml
* Update AtomicService.cs
* Update T1546.005.yaml
* Delete T1222.yaml
* Update T1482.yaml
* Update T1485.yaml
* Update T1220.yaml
* Update T1489.yaml
* Update T1490.yaml
* Update T1496.yaml
* Update T1505.003.yaml
* Update T1505.yaml
* Update T1518.001.yaml
* Update T1518.yaml
* Update T1529.yaml
* Update T1543.004.yaml
* Update T1546.001.yaml
* Update T1546.002.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.002.yaml
* Update T1543.001.yaml
* Update T1518.001.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1531.yaml
* Update T1222.001.yaml
* Update T1222.002.yaml
* Update T1505.002.yaml
* Update T1505.003.yaml
* Update T1518.001.yaml
* Update T1543.001.yaml
* Update T1546.005.yaml
* Update T1546.004.yaml
* Update T1546.003.yaml
* Update T1546.002.yaml
* Update T1546.001.yaml
* Update T1543.004.yaml
* Update T1543.003.yaml
* Update T1543.002.yaml
* added auto_generated_guid 1220
* added T1222.001 auto_generated_guid
* Update T1222.002.yaml
added auto_generated_guid entries
* Update T1482.yaml
auto_generated_guid added
* Update T1485.yaml
added auto_generated_guids
* Update T1489.yaml
added auto_generated_guids
* Update T1490.yaml
added auto_generated_guids
* Update T1496.yaml
added auto_generated_guid
* Update T1505.002.yaml
added auto_generated_guid from old T1505 same atomic
* Update T1505.003.yaml
added auto_generated_guid from previous atomic 1100
* Delete T1505.yaml
no longer needed, moved to 1505.002
* Update T1518.yaml
added auto_generated_guids
* Update T1529.yaml
added auto_generated_guids
* Update T1531.yaml
added auto_generated_guids
* Update T1543.001.yaml
added auto_generated_guid
* Update T1543.002.yaml
added auto_generated_guid
* Update T1543.004.yaml
added auto_generated_guid
* Update T1546.001.yaml
added auto_generated_guid
* Update T1546.002.yaml
added auto_generated_guid
* Update T1546.003.yaml
* Update T1546.004.yaml
added auto_generated_guid
* Update T1546.005.yaml
added auto_generated_guid
* add guids back in
* fix spacing issue
* fix spacing
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Sub-techniques T1053-T1113 - Updates (#1022 )
* Sub-techniques T1053-T1113 - Updates
Updated techniques for sub-techniques.
* minor fixes
format fixing
* Added GUIDs
- Added GUIDs back
- Fixed typo (T1054)
- Fixed attack_technique from an array to a string
* Sub-technique updates T1546.008 through T1574.011 (#1024 )
* sub technique updates
* sub technique updates
* sub technique updates
* Carrie updates (#1017 )
* updated T1110,12,13
* updated T1114
* updated T1114
* updated T1115
* updated T1119
* updated T1123,24
* updated T1127
* updated T1114
* updated T1127
* updated T1132
* T1134.004
* T1134.004
* updated T1135
* updated T1136
* updated T1137
* updated T1140
* remove depracted T1153
* updated T1176
* updated T1197
* updated T1201
* updated T1202
* updated T1204
* updated T1207
* updated T1216
* updated T1204
* updated T1217
* updated T1218
* updated T1218
* updated T1219
* updated T1218
* attack_technique to string
* Subtechnique transfer (#1025 )
* T1003 review
* T1005 manual review changes
* T1027.002 sub-technique review
* T1027.004 sub-technique review
* T1036 sub-technique review
* T1037 sub-technique review
* T1048 sub-technique review
* YAML bugfixes
* Adding auto-generated GUIDs back to tests
* merging with Mike's PR
* Merging with Carrie's PR
* fix spacing
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
* Subtechnique fix (#1026 )
* add atomic_tests: element
* add atomic_tests: element
* more fixes
* more fixes
* more fixes
* sub technique minor fixes 1 (#1027 )
* fixes
* fixes
* more fixes
* more fixes
* display name fix (#1028 )
* remove some deprecated stuff. reorganize a little (#1031 )
* Gendocs fix (#1033 )
* gendocs updates for subtechniques
* add folders
* ignore auto generated markdown files
* remove tmp files
* add tmp files
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
* navigator layer v3.0
* Generate docs from job=validate_atomics_generate_docs branch=subtechnique_transfer
Co-authored-by: Matt Graeber <60448025+mgraeber-rc@users.noreply.github.com >
Co-authored-by: Tsora-Pop <35981510+Tsora-Pop@users.noreply.github.com >
Co-authored-by: Michael Haag <mike@redcanary.com >
Co-authored-by: CircleCI Atomic Red Team doc generator <email>
2020-06-17 12:55:46 -06:00