Commit Graph

909 Commits

Author SHA1 Message Date
Nik Seetharaman dbae21ab77 Add test for T1191 UAC Bypass 2018-07-27 02:59:47 -05:00
CircleCI Atomic Red Team doc generator 58fc9342e4 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-26 22:31:58 +00:00
Austin Robertson 5cb3fed680 General YAML cleanup (#305)
* Fix string interpolation from ${foo} to #{foo} across all atomics

* remove non-ASCII characters from atomics YAML

* fix erroneous input_arguments
2018-07-26 16:31:50 -06:00
CircleCI Atomic Red Team doc generator 2e9c9c4aa1 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-26 17:53:34 +00:00
Keith McCammon d1a5f97ecf Merge pull request #304 from aus/patch-2
T1140 - Fix string interpolation from ${foo} to #{foo}
2018-07-26 11:53:21 -06:00
Austin Robertson 69cd89be91 Fix string interpolation from ${foo} to #{foo} 2018-07-26 11:25:08 -05:00
CircleCI Atomic Red Team doc generator 7c946955b7 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-25 16:39:20 +00:00
Michael Haag 259a0ff7e0 Merge pull request #303 from vector-sec/master
Added T1165 Startup Items emond rules test
2018-07-25 12:38:48 -04:00
Eric 9b1db5906e Additional identity crisis 2018-07-21 22:22:17 -04:00
Eric 2edde3688a Identity crisis 2018-07-21 22:16:44 -04:00
vector-sec 88bc32c778 Added T1165 emond rule test 2018-07-21 22:15:11 -04:00
CircleCI Atomic Red Team doc generator 9c278eba0d Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-16 18:54:03 +00:00
Michael Haag 81b6d0ce6a Merge pull request #299 from ForensicITGuy/RC13378-tl
Systemd Service Creation Test
2018-07-16 14:52:20 -04:00
Michael Haag 5f734f7dda Merge pull request #298 from vector-sec/t1031-modifying-a-service
T1031 modifying a service
2018-07-16 13:56:03 -04:00
CircleCI Atomic Red Team doc generator 6f86b3ef5d Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-16 17:55:18 +00:00
Michael Haag 982f8aca2c Merge pull request #297 from timfrazier1/master
Substituted variable in T1127.yaml
2018-07-16 13:54:05 -04:00
Michael Haag 178ab165b6 Merge pull request #296 from nicholasaleks/T1074/collect-n-compress-file-types
T1074/collect n compress file types
2018-07-16 13:30:32 -04:00
Tony M Lambert 04ebe02152 Systemd Service Creation Test 2018-07-13 16:27:15 -05:00
Tim Frazier 5b72734e90 Moving csproj file to src folder 2018-07-12 20:39:25 -04:00
timfrazier1 65025fe84c Update T1127.yaml
Substitute variable for hard coded filename
2018-07-12 20:13:57 -04:00
timfrazier1 ec58b50b2b Merge pull request #3 from redcanaryco/master
Merging in latest changes
2018-07-12 20:12:56 -04:00
Eric Turpin 0f76c98adb Updated T1031 Modify Existing Service Test 2018-07-12 16:53:35 -04:00
Eric Turpin 9488f53dc5 Added T1031 Modify Existing Service Test 2018-07-12 16:40:46 -04:00
nicholasaleks 8634293566 T1074/collect-n-compress-file-types: Updated typos in atomic test #2 2018-07-12 00:33:42 -04:00
nicholasaleks ceb9e59afe T1074/collect-n-compress-file-types: Fixed yaml errors in T1074 2018-07-12 00:25:34 -04:00
nicholasaleks fab7677f2d T1074/collect-n-compress-file-types: Yamlized the attack (again raising questions in comments about best practices) 2018-07-12 00:21:47 -04:00
nicholasaleks 1845c6fe17 T1074/collect-n-compress-file-types: Outlined a new collection > data staged attack type (collect n compress file types) within the T1074.md readme. Also raised a few questions on best practices 2018-07-12 00:21:01 -04:00
caseysmithrc 4d6586fc91 Merge pull request #294 from redcanaryco/T1086-mhaag
T1086 Powershell Additions
2018-07-09 10:56:19 -06:00
CircleCI Atomic Red Team doc generator e9852d00b4 Generate docs from job=validate_atomics_generate_docs branch=T1086-mhaag 2018-07-09 16:52:30 +00:00
Michael Haag f5a5aa8d6a Add Invoke-DownloadCradle by @mgreen27
Added @mgreen27 Invoke-DownloadCradle as method to run additional endpoint and network tests using Powershell.
2018-07-09 12:52:07 -04:00
CircleCI Atomic Red Team doc generator 19dbbc1b30 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-06 19:56:44 +00:00
caseysmithrc 812fd86208 Merge pull request #292 from swelcher/T1132
T1132 Base64 Encoded Data
2018-07-06 13:56:36 -06:00
CircleCI Atomic Red Team doc generator 6ec08211f8 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-06 19:56:24 +00:00
caseysmithrc 5fb93a9c14 Merge pull request #289 from swelcher/T1126
Add T1126 removing network shares
2018-07-06 13:56:17 -06:00
CircleCI Atomic Red Team doc generator 7f613df3a3 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-06 19:54:35 +00:00
caseysmithrc 6d1279ccd9 Merge pull request #288 from swelcher/T1049
Added T1049 System Network Connections Discovery
2018-07-06 13:54:27 -06:00
CircleCI Atomic Red Team doc generator e50fe48294 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-06 19:54:11 +00:00
caseysmithrc c0eb1a3b8c Merge pull request #287 from swelcher/T1062
Added T1062
2018-07-06 13:54:03 -06:00
CircleCI Atomic Red Team doc generator f20f312506 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-06 19:53:41 +00:00
caseysmithrc a8c90dc35c Merge pull request #286 from swelcher/T1214temp
T1214 Registry Enumeration
2018-07-06 13:53:33 -06:00
CircleCI Atomic Red Team doc generator 5262243222 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-06 18:37:14 +00:00
Michael Haag 520ea0fe08 Merge pull request #290 from swelcher/T1046
T1046 Port Scans
2018-07-06 14:37:06 -04:00
CircleCI Atomic Red Team doc generator 7263af3423 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-06 18:36:44 +00:00
Michael Haag c85c0079c2 Merge pull request #291 from swelcher/T1169
Added SUDO enumeration
2018-07-06 14:36:33 -04:00
CircleCI Atomic Red Team doc generator f528410b76 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-06 18:34:03 +00:00
caseysmithrc 99853acc99 Merge pull request #285 from swelcher/T1193
T1193 Spearphishing Attachment
2018-07-06 12:33:52 -06:00
CircleCI Atomic Red Team doc generator 151a1edfa9 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-06 18:33:16 +00:00
caseysmithrc c16636efd8 Merge pull request #283 from aleixsb/patch-2
Update T1124.yaml
2018-07-06 12:33:06 -06:00
caseysmithrc 37e523292f Merge pull request #281 from jmaas/T1148-wrong-technique-number
T1148. Use the correct technique number in the YAML spec.
2018-07-06 12:32:35 -06:00
CircleCI Atomic Red Team doc generator c33e02c545 Generate docs from job=validate_atomics_generate_docs branch=master 2018-07-06 18:32:14 +00:00