Files
2025-11-05 01:55:34 +00:00

92 KiB

Linux Atomic Tests by ATT&CK Tactic & Technique

defense-evasion

privilege-escalation

execution

persistence

command-and-control

collection

lateral-movement

credential-access

discovery

impact

  • T1561.002 Disk Structure Wipe CONTRIBUTE A TEST
  • T1498.001 Direct Network Flood CONTRIBUTE A TEST
  • T1491.002 External Defacement CONTRIBUTE A TEST
  • T1499.001 OS Exhaustion Flood CONTRIBUTE A TEST
  • T1499.003 Application Exhaustion Flood CONTRIBUTE A TEST
  • T1561 Disk Wipe CONTRIBUTE A TEST
  • T1565.001 Stored Data Manipulation CONTRIBUTE A TEST
  • T1489 Service Stop
    • Atomic Test #4: Linux - Stop service using systemctl [linux]
    • Atomic Test #5: Linux - Stop service by killing process using killall [linux]
    • Atomic Test #6: Linux - Stop service by killing process using kill [linux]
    • Atomic Test #7: Linux - Stop service by killing process using pkill [linux]
    • Atomic Test #8: Abuse of linux magic system request key for Send a SIGTERM to all processes [linux]
  • T1499.004 Application or System Exploitation CONTRIBUTE A TEST
  • T1565.003 Runtime Data Manipulation CONTRIBUTE A TEST
  • T1498.002 Reflection Amplification CONTRIBUTE A TEST
  • T1499.002 Service Exhaustion Flood CONTRIBUTE A TEST
  • T1491 Defacement CONTRIBUTE A TEST
  • T1496.002 Bandwidth Hijacking CONTRIBUTE A TEST
  • T1657 Financial Theft CONTRIBUTE A TEST
  • T1491.001 Defacement: Internal Defacement CONTRIBUTE A TEST
  • T1496.001 Compute Hijacking CONTRIBUTE A TEST
  • T1565 Data Manipulation CONTRIBUTE A TEST
  • T1531 Account Access Removal
    • Atomic Test #4: Change User Password via passwd [macos, linux]
  • T1486 Data Encrypted for Impact
    • Atomic Test #1: Encrypt files using gpg (FreeBSD/Linux) [linux]
    • Atomic Test #2: Encrypt files using 7z (FreeBSD/Linux) [linux]
    • Atomic Test #3: Encrypt files using ccrypt (FreeBSD/Linux) [linux]
    • Atomic Test #4: Encrypt files using openssl (FreeBSD/Linux) [linux]
  • T1667 Email Bombing CONTRIBUTE A TEST
  • T1499 Endpoint Denial of Service CONTRIBUTE A TEST
  • T1496 Resource Hijacking
    • Atomic Test #1: FreeBSD/macOS/Linux - Simulate CPU Load with Yes [linux, macos]
  • T1565.002 Transmitted Data Manipulation CONTRIBUTE A TEST
  • T1485 Data Destruction
    • Atomic Test #2: FreeBSD/macOS/Linux - Overwrite file with DD [linux, macos]
  • T1498 Network Denial of Service CONTRIBUTE A TEST
  • T1495 Firmware Corruption CONTRIBUTE A TEST
  • T1490 Inhibit System Recovery CONTRIBUTE A TEST
  • T1561.001 Disk Content Wipe CONTRIBUTE A TEST
  • T1529 System Shutdown/Reboot
    • Atomic Test #3: Restart System via shutdown - FreeBSD/macOS/Linux [linux, macos]
    • Atomic Test #4: Shutdown System via shutdown - FreeBSD/macOS/Linux [linux, macos]
    • Atomic Test #5: Restart System via reboot - FreeBSD/macOS/Linux [linux, macos]
    • Atomic Test #6: Shutdown System via halt - FreeBSD/Linux [linux]
    • Atomic Test #7: Reboot System via halt - FreeBSD [linux]
    • Atomic Test #8: Reboot System via halt - Linux [linux]
    • Atomic Test #9: Shutdown System via poweroff - FreeBSD/Linux [linux]
    • Atomic Test #10: Reboot System via poweroff - FreeBSD [linux]
    • Atomic Test #11: Reboot System via poweroff - Linux [linux]
    • Atomic Test #16: Abuse of Linux Magic System Request Key for Reboot [linux]

initial-access

exfiltration