Commit Graph

2276 Commits

Author SHA1 Message Date
Jesse Moore f4d059dbbc Update T1003.002.yaml for PowerDump (#1196)
* Update T1003.002.yaml for PowerDump

Added PowerDump to parse SAM and SYSTEM for usernames and Hash

* Add fixes

Updated with fixes.
Its not erroring with Multiple cleanup
Removed preReqs, don't need them
Removed SAM and SYSTEM file dep... PowerDump can just Dump Registry for Hashes and Usernames

* Getting permanent links to file

Added permanent link to PowerDump in BC-SECURITY Github

* updated description

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-15 20:31:19 -06:00
CircleCI Atomic Red Team doc generator 2de9e9fc3a Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-16 02:24:17 +00:00
Tsora-Pop 6bd48533a3 Moved Atomic for RDP Hijacking (#1199)
* Removing RDP Hijacking Atomic

Removing RDP Hijacking Atomic and moving to T1563.002-RDP Hijacking

* Create T1563.002.yaml

Moved from T1021.001
2020-08-15 20:23:54 -06:00
CircleCI Atomic Red Team doc generator 22a8e308ca Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-15 23:14:57 +00:00
Dragonlord0 751a827e86 T1218 (#1197)
* Added T1203 ProtocolHandler.exe

* Fixed numbering error

* remove white space

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-15 17:14:34 -06:00
CircleCI Atomic Red Team doc generator eb13ba719f Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-13 22:11:38 +00:00
Jil Larner 006bd1b046 Rough implementation of T1070.001 (clear Windows event logs) (#1151)
* Rough implementation of T1070.001 (clear Windows event logs)

* Enhanced PS log clearing to cover all eventlogs

Co-authored-by: Jil <jil@localhost>
Co-authored-by: Michael Haag <mike@redcanary.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-13 16:11:16 -06:00
Carrie Roberts 2dce548893 typo fix (#1187)
* typo fix

* Update README.md
2020-08-11 13:35:09 -06:00
CircleCI Atomic Red Team doc generator bbb0d07652 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-07 23:34:08 +00:00
Victuos ab26dc3f70 Wrong commands in T1016 (#1186)
* Update T1016.md

* Update T1016.yaml

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-07 17:33:16 -06:00
CircleCI Atomic Red Team doc generator 0f0b930b19 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-07 23:31:52 +00:00
harml3ss 84416dfdb3 Create sys_info.vbs (#1182)
* Create sys_info.vbs

This file is to be used with a new atomic I am writing for T1059.005.

* Create sys_info.vbs

Moved vbscript to /src directory.

* Create T1059.005.yaml

Added yaml file for T1059.005

* Delete sys_info.vbs

* Update T1059.005.yaml

* Update T1059.005.yaml

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-07 17:31:18 -06:00
CircleCI Atomic Red Team doc generator bfa4d8bc54 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-07 19:33:50 +00:00
masonharrell cd1c015dfa added prereq to test #2 (#1185)
* added prereq to test #2

* Update T1071.001.yaml

remove test "z"

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-07 13:33:31 -06:00
CircleCI Atomic Red Team doc generator 54c0e74a6c Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-07 17:38:33 +00:00
Carrie Roberts aa307557ea adding missing descriptions (#1184) 2020-08-07 11:38:14 -06:00
CircleCI Atomic Red Team doc generator 99a4e8850a Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-07 17:14:19 +00:00
Carrie Roberts d8733662f9 fix markdown spacing after description (#1183) 2020-08-07 11:13:55 -06:00
CircleCI Atomic Red Team doc generator a97f3f7e3a Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-07 14:44:32 +00:00
Jesse Moore c4706bb0d9 Update T1078.001 (#1179)
* Create T1078.001 and yaml

Creating Folder for sub technique and yaml for .001

* Update T1078.001.yaml

* Update T1078.001.yaml

* Update T1078.001.yaml

Added Remote Desktop Users group and the capability to have multiple RDP connections to Desktop for Guest user

* edit display name

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-07 08:43:47 -06:00
CircleCI Atomic Red Team doc generator 3702cf9b21 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-07 14:28:20 +00:00
bbucao d2bf308a63 T1531 - Removed the need for dependencies on tests 1 and 2 (#1181)
* Update T1531.yaml

* Update T1531.yaml removed need for dependencies on tests 1 and 2
2020-08-07 08:27:36 -06:00
CircleCI Atomic Red Team doc generator 3a6402298a Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-06 14:49:43 +00:00
Jesse Moore 5a67b43021 Create T1078.001 and yaml (#1178)
* Create T1078.001 and yaml

Creating Folder for sub technique and yaml for .001

* Update T1078.001.yaml

* Update T1078.001.yaml

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-06 08:49:27 -06:00
CircleCI Atomic Red Team doc generator bb59d266d5 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-05 04:28:13 +00:00
Jesse Moore dce7ce6949 Update T1040.yaml Use Built-in Windows Packet capture (#1172)
* Update T1040.yaml

 Uses the built-in Windows packet capture

* Update T1040

Adding temp folder and del command to delete that trace.etl and added sleep command before and after (it does a little bit of processing when stopped) with PowerShell.

* Update T1040.yaml

Changed to use variables where possible (couldn't get %temp% to work in the command) Use a long time out (50 seconds) as it took awhile for collections to complete . Added more description to explain what artifacts are left after execution. Thanks Carrie with all your time/input spent on this to make it great.

* Update T1040.yaml

added %LOCALAPPDATA%

* Update T1040.yaml

Switched to %temp%

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-04 22:27:30 -06:00
CircleCI Atomic Red Team doc generator ccb518616d Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-05 00:46:55 +00:00
harml3ss e0449bc608 Update T1003.004.yaml (#1170)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-04 18:46:28 -06:00
CircleCI Atomic Red Team doc generator 6165e9e71d Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-05 00:38:43 +00:00
Carrie Roberts a4277af9d6 fix for printing prereqs in md (#1171) 2020-08-04 18:38:06 -06:00
CircleCI Atomic Red Team doc generator 9af633aa05 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-04 17:51:19 +00:00
harml3ss c340a61f43 Create T1003.004.yaml (#1168)
* Create T1003.004.yaml

* remove some extra white space

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-04 11:50:49 -06:00
secjake f77c2a4f8b Update RegKey AppInit_DLLs Path (#1166) 2020-08-03 13:42:04 -06:00
CircleCI Atomic Red Team doc generator 55e967cd13 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-02 00:31:08 +00:00
wilsonwr 50c0326c5a T1053.001 test1 (#1165)
* Fix: only_platform circular argument reference

Remove a circular argument reference of only_platform, which was causing scripts in ./bin/ to error out when using Ruby version 2.7.

* Add T1053.001 Test 1

Co-authored-by: Billy Wilson <billy_wilson@byu.edu>
2020-08-01 18:30:38 -06:00
CircleCI Atomic Red Team doc generator d8dd757a24 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-01 22:54:55 +00:00
tlor89 34953ac95f T1070.003-Update (#1164)
* T1070.003-Update

* wording update

Co-authored-by: Toua Lor <tlor@nti.local>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-01 16:54:39 -06:00
CircleCI Atomic Red Team doc generator 5714759941 Generate docs from job=validate_atomics_generate_docs branch=master 2020-08-01 16:48:28 +00:00
Jake Hill e686b9944e Add mac test for T1518 that discovers Safari browser version (#1150)
Co-authored-by: Jake Hill <jake.hill@voya.com>
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-08-01 10:48:13 -06:00
Michael Haag 2cc5348312 Fix T1551 to T1070 (#1161)
* Fix T1551 to T1070

Found that we had T1070 labeled incorrectly as T1551. MITRE pushed a fix for this per https://attack.mitre.org/resources/updates/updates-july-2020/

```
Indicator Removal on Host Was incorrectly re-IDd to T1551, restored to T1070 and its sub-techniques were changed to T1070.001, T1070.002, T1070.003, T1070.004, T1070.005, and T1070.006
```

* Generate MD fix

Attempting to get the MD to generate

* Update enterprise-attack.json

* Generate docs from job=validate_atomics_generate_docs branch=T1070-indicator-removal-fix

Co-authored-by: CircleCI Atomic Red Team doc generator <email>
2020-08-01 09:46:06 -06:00
wilsonwr c67a4f55f7 Fix: only_platform circular argument reference (#1160)
Remove a circular argument reference of only_platform, which was causing scripts in ./bin/ to error out when using Ruby version 2.7.
2020-07-30 11:36:12 -06:00
CircleCI Atomic Red Team doc generator 0edb546228 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-27 14:04:42 +00:00
Laken Harrell 3946f9880e added T1218.010 test 4 (#1155)
* added T1218.010 test 4

* Update T1218.010.yaml

removed template comments

Co-authored-by: Harrell <LHarrell@nti.local>
Co-authored-by: Michael Haag <mike@redcanary.com>
2020-07-27 08:04:20 -06:00
CircleCI Atomic Red Team doc generator 923f68a941 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-27 13:36:37 +00:00
P4T12ICK 5bb282f2e7 bug fix atomics in T1053.005 (#1156)
Co-authored-by: Patrick Bareiss <pbareib@splunk.com>
2020-07-27 07:36:02 -06:00
Sergio Gonzalez 36f83b728b Update Discovery.bat (#1154) 2020-07-23 09:57:55 -06:00
CircleCI Atomic Red Team doc generator a001d93114 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-20 23:42:37 +00:00
Danil Karandin 139386e8bd T1003 Creds Dumping with NPPSpy (#1149)
Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2020-07-20 17:41:47 -06:00
CircleCI Atomic Red Team doc generator a5216ecdd6 Generate docs from job=validate_atomics_generate_docs branch=master 2020-07-20 23:24:04 +00:00
Carrie Roberts e99213cfa6 configurable host to scan (#1148) 2020-07-20 17:23:24 -06:00