BlueTeamOps
f8c8fbcab1
Added Audit Policy Config based Logging Impairment ( #1378 )
...
* Added Audit Policy Config based Logging Impairment
Auditpol can be used to manipulate audit log configuration. Test 3 simulates the adversary disabling certain audit policies to prevent respective events from being recorded in the log
* Add link, update test name
Adding in the Solarigate write-up link for reference and also removing the test # from the title (this gets added automatically to the Markdown file)
* added cleanup commands
Hi Carrie, The pre-req commands enables the auditpols initially so that it can be disabled when the atomic command is executed. I have copied the same syntax as pre-req to clean-up so it is reinstated. Based on additional research I have several more commands of interest I would like to add which were not part of the MS article but would be considered suspicious. Shall I add them as separate tests? i.e. sub-commands such as clear, restore, remove
* Removed the dependency section
Removed the dependency section
Co-authored-by: Carrie Roberts <clr2of8@gmail.com >
2021-02-09 11:13:25 -07:00
..
2021-02-03 02:33:01 +00:00
2020-09-29 13:53:28 +00:00
2021-02-03 02:33:01 +00:00
2021-01-22 16:30:47 +00:00
2020-10-24 08:15:58 -06:00
2020-09-29 13:53:28 +00:00
2021-01-06 18:47:31 +00:00
2020-11-30 09:18:32 -07:00
2020-10-29 22:54:55 -06:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-10-15 16:28:04 +00:00
2020-11-30 14:34:25 -07:00
2020-11-30 09:18:32 -07:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-10-24 08:17:34 -06:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-12-01 13:31:40 -07:00
2020-09-29 13:53:28 +00:00
2020-10-29 22:54:55 -06:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2021-01-07 16:43:14 +00:00
2020-09-29 13:53:28 +00:00
2021-01-08 16:42:27 +00:00
2021-01-01 23:43:53 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-11-30 09:18:32 -07:00
2020-09-29 13:53:28 +00:00
2020-12-15 14:18:41 -07:00
2021-01-06 18:42:39 +00:00
2021-01-08 09:19:55 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-11-09 16:41:52 +00:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-11-30 09:18:32 -07:00
2020-09-29 13:53:28 +00:00
2021-01-08 09:12:14 -07:00
2020-09-29 13:53:28 +00:00
2020-12-28 22:45:56 +00:00
2020-10-24 08:19:12 -06:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-11-12 13:40:23 -07:00
2020-12-16 11:27:51 -07:00
2020-12-16 11:27:51 -07:00
2020-09-29 13:53:28 +00:00
2020-11-19 11:18:53 -05:00
2020-11-12 13:40:23 -07:00
2020-09-29 13:53:28 +00:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-10-08 13:39:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2021-01-06 19:39:15 +00:00
2020-09-29 13:53:28 +00:00
2021-02-01 17:01:17 +00:00
2020-11-09 16:41:52 +00:00
2020-11-12 13:40:23 -07:00
2020-09-29 13:53:28 +00:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2021-01-20 23:27:31 +00:00
2020-09-29 13:53:28 +00:00
2020-11-30 09:18:32 -07:00
2020-10-29 22:54:55 -06:00
2020-10-22 14:34:31 -06:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-10-29 22:54:55 -06:00
2020-10-29 22:54:55 -06:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2021-01-13 19:14:46 +00:00
2020-12-15 14:18:41 -07:00
2020-10-29 22:54:55 -06:00
2021-01-08 16:12:45 +00:00
2021-01-08 16:51:05 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 15:47:51 +00:00
2021-01-08 16:16:04 +00:00
2020-10-22 14:34:31 -06:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-10-22 14:34:31 -06:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2021-01-11 03:40:28 +00:00
2020-12-21 16:40:14 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2021-01-25 13:43:05 +00:00
2020-09-29 13:53:28 +00:00
2020-11-09 16:41:52 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2021-01-24 00:53:46 +00:00
2020-09-29 13:53:28 +00:00
2020-10-29 22:54:55 -06:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-12-21 16:14:07 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-11-30 09:18:32 -07:00
2020-09-29 13:53:28 +00:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-12-17 22:57:51 -07:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-10-06 16:13:36 +00:00
2021-01-05 23:31:24 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-10-29 22:54:55 -06:00
2020-11-12 13:40:23 -07:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-12-01 13:31:40 -07:00
2020-09-29 13:53:28 +00:00
2021-01-06 18:35:50 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2021-01-13 03:23:42 +00:00
2020-11-12 13:40:23 -07:00
2021-02-09 11:13:25 -07:00
2020-12-15 14:18:41 -07:00
2020-11-12 13:40:23 -07:00
2020-10-29 22:54:55 -06:00
2020-09-29 13:53:28 +00:00
2020-12-16 11:27:51 -07:00
2020-09-29 13:53:28 +00:00
2020-10-29 22:54:55 -06:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-12-15 14:18:41 -07:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-09-29 13:53:28 +00:00
2020-12-29 14:18:50 +00:00
2020-09-29 13:53:28 +00:00
2020-11-12 13:40:23 -07:00
2020-11-30 09:18:32 -07:00
2020-12-15 14:18:41 -07:00
2021-02-03 02:32:53 +00:00