Files
atomic-red-team/atomics/Indexes/Indexes-CSV/linux-index.csv
T
2020-04-03 17:14:40 +00:00

7.9 KiB

1TacticTechnique #Test #Test Name
2persistenceT11561Add command to .bash_profile
3persistenceT11562Add command to .bashrc
4persistenceT11761Chrome (Developer Mode)
5persistenceT11762Chrome (Chrome Web Store)
6persistenceT11763Firefox
7persistenceT11361Create a user account on a Linux system
8persistenceT11365Create a new user in Linux with `root` UID and GID.
9persistenceT11581Create a hidden file in a hidden directory
10persistenceT12151Linux - Load Kernel Module via insmod
11persistenceT11681Cron - Replace crontab with referenced file
12persistenceT11682Cron - Add script to cron folder
13persistenceT11683Event Monitor Daemon Persistence
14persistenceT11661Make and modify binary from C source
15persistenceT11662Set a SetUID flag on file
16persistenceT11663Set a SetGID flag on file
17persistenceT15011Create Systemd Service
18persistenceT11541Trap
19impactT14852macOS/Linux - Overwrite file with DD
20impactT14961macOS/Linux - Simulate CPU Load with Yes
21impactT15293Restart System via `shutdown` - macOS/Linux
22impactT15294Shutdown System via `shutdown` - macOS/Linux
23impactT15295Restart System via `reboot` - macOS/Linux
24impactT15296Shutdown System via `halt` - Linux
25impactT15297Reboot System via `halt` - Linux
26impactT15298Shutdown System via `poweroff` - Linux
27impactT15299Reboot System via `poweroff` - Linux
28discoveryT10871Enumerate all accounts
29discoveryT10872View sudoers access
30discoveryT10873View accounts with UID 0
31discoveryT10874List opened files by user
32discoveryT10875Show if a user account has ever logged in remotely
33discoveryT10876Enumerate users and groups
34discoveryT12171List Mozilla Firefox Bookmark Database Files on Linux
35discoveryT10833Nix File and Diectory Discovery
36discoveryT10834Nix File and Directory Discovery 2
37discoveryT10461Port Scan
38discoveryT10462Port Scan Nmap
39discoveryT11351Network Share Discovery
40discoveryT10401Packet Capture Linux
41discoveryT12011Examine password complexity policy - Ubuntu
42discoveryT12012Examine password complexity policy - CentOS/RHEL 7.x
43discoveryT12013Examine password complexity policy - CentOS/RHEL 6.x
44discoveryT12014Examine password expiration policy - All Linux
45discoveryT10691Permission Groups Discovery
46discoveryT10571Process Discovery - ps
47discoveryT10186Remote System Discovery - arp nix
48discoveryT10187Remote System Discovery - sweep
49discoveryT10822System Information Discovery
50discoveryT10823List OS Information
51discoveryT10824Linux VM Check via Hardware
52discoveryT10825Linux VM Check via Kernel Modules
53discoveryT10827Hostname Discovery
54discoveryT10163System Network Configuration Discovery
55discoveryT10493System Network Connections Discovery Linux & MacOS
56discoveryT10332System Owner/User Discovery
57credential-accessT11391Search Through Bash History
58credential-accessT10812Extract passwords with grep
59credential-accessT10401Packet Capture Linux
60credential-accessT11452Discover Private SSH Keys
61credential-accessT11453Copy Private SSH Keys with CP
62credential-accessT11454Copy Private SSH Keys with rsync
63defense-evasionT10091Pad Binary to Change Hash - Linux/macOS dd
64defense-evasionT11461Clear Bash history (rm)
65defense-evasionT11462Clear Bash history (echo)
66defense-evasionT11463Clear Bash history (cat dev/null)
67defense-evasionT11464Clear Bash history (ln dev/null)
68defense-evasionT11465Clear Bash history (truncate)
69defense-evasionT11466Clear history of a bunch of shells
70defense-evasionT10901Connection Proxy
71defense-evasionT10891Disable iptables firewall
72defense-evasionT10892Disable syslog
73defense-evasionT10893Disable Cb Response
74defense-evasionT10894Disable SELinux
75defense-evasionT11071Delete a single file - Linux/macOS
76defense-evasionT11072Delete an entire folder - Linux/macOS
77defense-evasionT11073Overwrite and delete a file with shred
78defense-evasionT11078Delete Filesystem - Linux
79defense-evasionT12228chmod - Change file or folder mode (numeric mode)
80defense-evasionT12229chmod - Change file or folder mode (symbolic mode)
81defense-evasionT122210chmod - Change file or folder mode (numeric mode) recursively
82defense-evasionT122211chmod - Change file or folder mode (symbolic mode) recursively
83defense-evasionT122212chown - Change file or folder ownership and group
84defense-evasionT122213chown - Change file or folder ownership and group recursively
85defense-evasionT122214chown - Change file or folder mode ownership only
86defense-evasionT122215chown - Change file or folder ownership recursively
87defense-evasionT122216chattr - Remove immutable file attribute
88defense-evasionT11481Disable history collection
89defense-evasionT11482Mac HISTCONTROL
90defense-evasionT11581Create a hidden file in a hidden directory
91defense-evasionT10703rm -rf
92defense-evasionT10704Overwrite Linux Mail Spool
93defense-evasionT10705Overwrite Linux Log
94defense-evasionT11301Install root CA on CentOS/RHEL
95defense-evasionT10362Masquerading as Linux crond process.
96defense-evasionT10271Decode base64 Data into Script
97defense-evasionT10552Shared Library Injection via /etc/ld.so.preload
98defense-evasionT10553Shared Library Injection via LD_PRELOAD
99defense-evasionT10141Loadable Kernel Module based Rootkit
100defense-evasionT10142Loadable Kernel Module based Rootkit
101defense-evasionT10641Create and Execute Bash Shell Script
102defense-evasionT10991Set a file's access timestamp
103defense-evasionT10992Set a file's modification timestamp
104defense-evasionT10993Set a file's creation timestamp
105defense-evasionT10994Modify file timestamps using reference file
106lateral-movementT11051rsync remote file copy (push)
107lateral-movementT11052rsync remote file copy (pull)
108lateral-movementT11053scp remote file copy (push)
109lateral-movementT11054scp remote file copy (pull)
110lateral-movementT11055sftp remote file copy (push)
111lateral-movementT11056sftp remote file copy (pull)
112collectionT10742Stage data from Discovery.sh
113collectionT11133X Windows Capture
114collectionT11134Import
115exfiltrationT10023Data Compressed - nix - zip
116exfiltrationT10024Data Compressed - nix - gzip Single File
117exfiltrationT10025Data Compressed - nix - tar Folder or File
118exfiltrationT10221Data Encrypted with zip and gpg symmetric
119exfiltrationT10301Data Transfer Size Limits
120exfiltrationT10481Exfiltration Over Alternative Protocol - SSH
121exfiltrationT10482Exfiltration Over Alternative Protocol - SSH
122exfiltrationT10483Exfiltration Over Alternative Protocol - HTTP
123exfiltrationT10485Exfiltration Over Alternative Protocol - DNS
124executionT10591Command-Line Interface
125executionT11681Cron - Replace crontab with referenced file
126executionT11682Cron - Add script to cron folder
127executionT11683Event Monitor Daemon Persistence
128executionT10641Create and Execute Bash Shell Script
129executionT11531Execute Script using Source
130executionT11532Execute Script using Source Alias
131executionT11541Trap
132command-and-controlT10901Connection Proxy
133command-and-controlT11321Base64 Encoded data.
134command-and-controlT11051rsync remote file copy (push)
135command-and-controlT11052rsync remote file copy (pull)
136command-and-controlT11053scp remote file copy (push)
137command-and-controlT11054scp remote file copy (pull)
138command-and-controlT11055sftp remote file copy (push)
139command-and-controlT11056sftp remote file copy (pull)
140command-and-controlT10713Malicious User Agents - Nix
141command-and-controlT10652Testing usage of uncommonly used port
142privilege-escalationT10552Shared Library Injection via /etc/ld.so.preload
143privilege-escalationT10553Shared Library Injection via LD_PRELOAD
144privilege-escalationT11661Make and modify binary from C source
145privilege-escalationT11662Set a SetUID flag on file
146privilege-escalationT11663Set a SetGID flag on file
147privilege-escalationT11691Sudo usage
148privilege-escalationT12061Unlimited sudo cache timeout
149privilege-escalationT12062Disable tty_tickets for sudo caching