Commit Graph

5497 Commits

Author SHA1 Message Date
publish bot bedfdfd91a updating atomics count in README.md [ci skip] 2023-10-03 01:05:05 +00:00
dependabot[bot] ebf17ef2bc Bump urllib3 from 2.0.4 to 2.0.6 (#2551)
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.0.4 to 2.0.6.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](https://github.com/urllib3/urllib3/compare/2.0.4...2.0.6)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-type: indirect
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 19:04:14 -06:00
Atomic Red Team doc generator b2204555cf Generated docs from job=generate-docs branch=master [ci skip] 2023-10-02 20:45:35 +00:00
Atomic Red Team GUID generator 19c71c2a40 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-10-02 20:45:17 +00:00
Mohana Shankar D 3397666c5c New Atomic Test: PromptOnSecureDesktop (#2549)
* New Atomic Test: PromptOnSecureDesktop

* Update T1548.002.yaml

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-10-02 14:44:36 -06:00
traceflow 30947260a6 adding test simulating DarkGate malware writing script to file from cmd (#2548)
* adding test simulating DarkGate malware writing script to file from cmd

* adding test simulating DarkGate malware writing script to file from cmd

* updating atomics count in README.md [ci skip]

---------

Co-authored-by: publish bot <opensource@redcanary.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:52:48 -06:00
Atomic Red Team doc generator d387c3e718 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-29 14:51:00 +00:00
Atomic Red Team GUID generator 971f54bdf9 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-29 14:50:42 +00:00
Swachchhanda Shrawan Poudel 247349eb5c Added new tests for techniques T1082 and T1070 (#2547)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:50:02 -06:00
Atomic Red Team doc generator 9bf809338a Generated docs from job=generate-docs branch=master [ci skip] 2023-09-29 14:45:43 +00:00
Atomic Red Team GUID generator 33aa1e0df2 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-29 14:45:20 +00:00
Tuutaans 2dc70561dd Provlaunch.exe Executes Arbitrary Command via Registry Key (#2546)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:44:32 -06:00
Atomic Red Team doc generator ccdf46f389 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-29 14:41:30 +00:00
Antonio Piazza f68822b349 Added ExternalPayloads directory (#2545)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173

* Update T1003.002.yaml

Added ExternalPayloads directory creation PowerShell command for procedure 804f28fc-68fc-40da-b5a2-e9d0bce5c193

* Update T1110.004.yaml

Added Powershell Command to creat ExternalPayloads dir for the second prereq for procedure 4852c630-87a9-409b-bb5e-5dc12c9ebcde.

* Update T1110.001.yaml

Added ExrernalPayload directory creation PowerShell command for procedure 59dbeb1a-79a7-4c2a-baf4-46d0f4c761c4
prereq 2

* Added ExternalPayloads Dir

Added Powershell command to create new ExternalPayloads dir for procedure fad04df1-5229-4185-b016-fb6010cd87ac

* Add ExternalPayloads Dir

Added PowerShell Command to create new ExternalPayloads directory for procedure c6f25ec3-6475-47a9-b75d-09ac593c5ecb

* Added prereq download directories

Added powershell command to create prereq download directories for procedure 6f2c5c87-a4d5-4898-9bd1-47a55ecaf1dd

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-29 08:40:27 -06:00
zaicurity 273e3c0fb7 Fix T1083-6 DirLister PreReqs (#2541)
* Fix T1083-6 DirLister PreReqs

A quote symbol in the get_prereq_command was wrong which caused the directory name to include "-Force". Due to this the script failed.

* updating atomics count in README.md [ci skip]

---------

Co-authored-by: publish bot <opensource@redcanary.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:35:42 -06:00
Atomic Red Team doc generator dc194fadf2 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-25 20:31:57 +00:00
Antonio Piazza b524d93bad New ExternalPayloads dir creation (#2544)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173

* Update T1003.002.yaml

Added ExternalPayloads directory creation PowerShell command for procedure 804f28fc-68fc-40da-b5a2-e9d0bce5c193

* Update T1110.004.yaml

Added Powershell Command to creat ExternalPayloads dir for the second prereq for procedure 4852c630-87a9-409b-bb5e-5dc12c9ebcde.

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:31:00 -06:00
publish bot b223a8e79b updating atomics count in README.md [ci skip] 2023-09-25 20:29:14 +00:00
dependabot[bot] ba4ba09d39 Bump jsonschema from 4.19.0 to 4.19.1 (#2540)
Bumps [jsonschema](https://github.com/python-jsonschema/jsonschema) from 4.19.0 to 4.19.1.
- [Release notes](https://github.com/python-jsonschema/jsonschema/releases)
- [Changelog](https://github.com/python-jsonschema/jsonschema/blob/main/CHANGELOG.rst)
- [Commits](https://github.com/python-jsonschema/jsonschema/compare/v4.19.0...v4.19.1)

---
updated-dependencies:
- dependency-name: jsonschema
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:28:32 -06:00
Atomic Red Team doc generator 098dfbfe5b Generated docs from job=generate-docs branch=master [ci skip] 2023-09-25 20:27:05 +00:00
Antonio Piazza a301206811 Download Directory creation (#2543)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173

* Update T1003.002.yaml

Added ExternalPayloads directory creation PowerShell command for procedure 804f28fc-68fc-40da-b5a2-e9d0bce5c193

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-25 14:26:08 -06:00
Atomic Red Team doc generator d146373e1f Generated docs from job=generate-docs branch=master [ci skip] 2023-09-25 20:24:07 +00:00
Antonio Piazza 7c61ce15f0 Update T1036.yaml (#2542)
Added ExternalPayloads directory creation via powershell command for procedure 4449c89b-ec82-43a4-89c1-91e2f1abeecc
2023-09-25 14:22:53 -06:00
Atomic Red Team doc generator 81692e20cd Generated docs from job=generate-docs branch=master [ci skip] 2023-09-23 03:44:15 +00:00
Carrie Roberts fc3bfecda2 use ExternalPayloads folder (#2538) 2023-09-22 23:43:06 -04:00
Atomic Red Team doc generator 78204c6965 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-22 21:07:21 +00:00
final five three fantasy 31713d27c6 updated lazagne URL (#2536)
* Repair path error

* Repair path error

* Update dependency URL

* Update T1555.003.yaml

---------

Co-authored-by: ywliang <ywliang@Hillstonenet.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-22 15:06:06 -06:00
Atomic Red Team doc generator a228ee8656 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-22 19:15:21 +00:00
Antonio Piazza e3b45b7b30 Added ExternalPayloads dir creation (#2537)
* Added ExternalPayloads dir creation

* Created ExternaPayloads Dir

Created ExternaPayloads Directory using powershell command

* Added External Payloads Dir

Added External Payloads Directory using a powershell command for all Procedures.

* Fixed ExternalPayload directory creation

Fixed ExternalPayload directory creation.  Got rid of the Split path

* Created External Payloads directory

Created External Payloads directory for procedure 14d55ca0-920e-4b44-8425-37eedd72b173
2023-09-22 13:14:23 -06:00
Carrie Roberts d4709021fb Handle spaces in file paths (#2535)
* updating atomics count in README.md [ci skip]

* wip

* handle spaces in path

* update readme

* fix typo

---------

Co-authored-by: publish bot <opensource@redcanary.com>
2023-09-22 10:47:25 -06:00
publish bot 5e9e3d2273 updating atomics count in README.md [ci skip] 2023-09-19 19:54:14 +00:00
sidahmed-malaoui 5a5f05362b Add backslash to path to make it valid (#2530)
Co-authored-by: Hare Sudhan <code@0x6c.dev>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-19 13:53:28 -06:00
Atomic Red Team doc generator 429bad7d5b Generated docs from job=generate-docs branch=master [ci skip] 2023-09-19 19:51:19 +00:00
Atomic Red Team GUID generator 9cb101bde7 Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-19 19:51:00 +00:00
Maskit Ariely 33fa790c25 T1005 (#2532)
* final test

* final test

* remove auto_generated_guid:

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-19 13:50:16 -06:00
Atomic Red Team doc generator fc49b11d8e Generated docs from job=generate-docs branch=master [ci skip] 2023-09-19 19:41:40 +00:00
Atomic Red Team GUID generator d604c832de Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-19 19:41:22 +00:00
Swachchhanda Shrawan Poudel f62d4c157c Modify Internet Zone Protocol Defaults in Current User Registry through PowerShell (#2534)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-19 13:40:44 -06:00
Atomic Red Team doc generator ac64299bcc Generated docs from job=generate-docs branch=master [ci skip] 2023-09-19 19:37:14 +00:00
final five three fantasy e1fa1bfd42 fixed some path errors (#2533)
* Repair path error

* Repair path error

---------

Co-authored-by: ywliang <ywliang@Hillstonenet.com>
2023-09-19 13:35:57 -06:00
Atomic Red Team doc generator 980f3f83fd Generated docs from job=generate-docs branch=master [ci skip] 2023-09-14 13:27:41 +00:00
Atomic Red Team GUID generator 9c8e0a75aa Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-14 13:27:17 +00:00
Ryan Plas a297bbc206 T1564.003 - Headless Browser Mockbin (#2529)
* T1564.003 - Headless Browser Mockbin

* Update T1564.003.yaml

---------

Co-authored-by: Michael Haag <5632822+MHaggis@users.noreply.github.com>
2023-09-14 07:26:24 -06:00
Atomic Red Team doc generator b76b49523e Generated docs from job=generate-docs branch=master [ci skip] 2023-09-13 01:31:11 +00:00
Atomic Red Team GUID generator 2ce6565ace Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-13 01:30:53 +00:00
Nasreddine Bencherchali 39534eb4ed Update T1112.yaml (#2522)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-12 19:30:08 -06:00
Atomic Red Team doc generator 205e8b3149 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-13 01:28:09 +00:00
Atomic Red Team GUID generator c973f6a07c Generate GUIDs from job=generate-docs branch=master [skip ci] 2023-09-13 01:27:43 +00:00
Maskit Ariely 6dd26cd1f3 T1567.003 (#2523)
* init

* finished test

---------

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2023-09-12 19:26:54 -06:00
Atomic Red Team doc generator 5d76ff7aa1 Generated docs from job=generate-docs branch=master [ci skip] 2023-09-13 01:22:52 +00:00