Files
atomic-red-team/atomics/T1147/T1147.yaml
T
Austin Robertson 5cb3fed680 General YAML cleanup (#305)
* Fix string interpolation from ${foo} to #{foo} across all atomics

* remove non-ASCII characters from atomics YAML

* fix erroneous input_arguments
2018-07-26 16:31:50 -06:00

23 lines
383 B
YAML

---
attack_technique: T1147
display_name: Hidden Users
atomic_tests:
- name: Hidden Users
description: |
Add a hidden user on MacOS
supported_platforms:
- macos
input_arguments:
user_name:
description: username to add
type: string
default: APT
executor:
name: sh
command: |
sudo dscl . -create /Users/#{user_name} UniqueID 333