dwhite9
0f77fd91fb
Update T1036.yaml ( #609 )
...
* Adding T1086 Alternate Data Stream atomic
* Added newline T1086
* Syncing changes with updstream and origin.
* Added Cleanup to Logon Scripts Atomic T1037
* Added timout to allow time for detection logic to register change.
* Fixed issue with upstream sync, Re-added timout to allow time for detection logic.
* Fixed cleanup command. Yaml tag not working to allow it to run.
* Update T1158 test 11.
Corrected ADS syntax. Added loop to run embedded ADS command from shell. Also added cleanup code.
* Update T1037.yaml
Moved Reg delete command under the cleanup_command tag for consistency.
* Update T1037.yaml
Moved reg removal command under cleanup_command tag for consistency.
* Update T1086.yaml
Bug Fix: Updated Base64 encoded command in T1086-12 with correct syntax and environment variables for power shell compatibility (was for cmd.exe only). Original decoded payload referenced %SystemRoot%, whereas PowerShell uses $env:SystemRoot. Also replaced single quotes with double quotes to prevent PowerShell from interpreting it as a literal string.
Enhancement: Added Cleanup_commands for T1086-12. Added comments for what the Base64 encoded payload is.
* Update T1036.yaml
Added Cleanup commands for the windows tests
2019-11-05 12:07:15 -07:00
..
2019-09-03 13:36:10 +00:00
2019-10-21 21:00:53 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-11-05 18:59:40 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-11-05 12:07:15 -07:00
2019-10-21 21:04:31 +00:00
2019-10-08 18:02:00 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-11-05 19:01:25 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-15 00:46:28 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-24 14:36:14 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:13:51 +00:00
2019-11-05 18:58:09 +00:00
2019-09-17 16:44:59 +00:00
2019-09-17 19:17:51 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-16 15:09:00 +00:00
2019-10-24 17:09:43 +00:00
2019-09-21 15:19:44 +00:00
2019-09-03 20:11:38 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:37:19 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 20:11:38 +00:00
2019-10-24 17:24:54 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 20:11:38 +00:00
2019-09-03 15:21:17 +00:00
2019-09-03 15:21:17 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-10-15 20:15:34 +00:00
2019-09-03 15:21:17 +00:00
2019-09-03 15:21:17 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 15:21:17 +00:00
2019-09-03 15:21:17 +00:00
2019-09-03 15:21:17 +00:00
2019-09-03 15:21:17 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 15:21:17 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 20:11:38 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-19 11:24:18 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 15:21:17 +00:00
2019-09-03 13:36:10 +00:00
2019-10-08 17:27:21 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 15:31:13 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:36:10 +00:00
2019-09-03 13:36:10 +00:00
2019-10-24 17:09:43 +00:00
2019-09-03 13:37:19 +00:00
2019-11-05 18:52:46 +00:00
2019-11-05 19:05:50 +00:00
2019-11-05 19:04:09 +00:00
2019-11-05 17:14:33 +00:00
2019-11-05 19:05:50 +00:00
2019-11-05 19:05:50 +00:00
2019-11-05 19:05:50 +00:00
2019-11-05 19:05:50 +00:00
2019-11-05 19:05:50 +00:00
2019-11-05 19:05:50 +00:00
2019-11-05 19:05:50 +00:00
2019-11-05 19:05:50 +00:00
2019-11-05 19:05:50 +00:00
2019-11-05 19:05:50 +00:00