--- attack_technique: TODO display_name: TODO atomic_tests: - name: TODO description: | TODO supported_platforms: - windows - macos - linux input_arguments: output_file: description: TODO type: TODO default: TODO dependency_executor_name: powershell # (optional) The executor for the prereq commands, defaults to the same executor used by the attack commands. dependencies: # (optional) - description: | TODO prereq_command: | # Commands to check if prerequisites for running this test are met. For the "command_prompt" executor, if any command returns a non-zero exit code, the prerequisites are not met. For the "powershell" executor, all commands are run as a script block and the script block must return 0 for success. TODO get_prereq_command: | # Commands to meet this prerequisite or a message describing how to meet this prerequisite. TODO executor: name: command_prompt elevation_required: true # Indicates whether command must be run with admin privileges. If the elevation_required attribute is not defined, the value is assumed to be false. command: | # These are the actaul attack commands, at least one command must be provided. TODO cleanup_command: | # You can remove the cleanup_command section if there are no cleanup commands. TODO