Files
atomic-red-team/atomics
BlueTeamOps f8c8fbcab1 Added Audit Policy Config based Logging Impairment (#1378)
* Added Audit Policy Config based Logging Impairment

Auditpol can be used to manipulate audit log configuration.  Test 3 simulates the adversary disabling certain audit policies to prevent respective events from being recorded in the log

* Add link, update test name

Adding in the Solarigate write-up link for reference and also removing the test # from the title (this gets added automatically to the Markdown file)

* added cleanup commands

Hi Carrie, The pre-req commands enables the auditpols initially so that it can be disabled when the atomic command is executed.  I have copied the same syntax as pre-req to clean-up so it is reinstated. Based on additional research I have several more commands of interest I would like to add which were not part of the MS article but would be considered suspicious.  Shall I add them as separate tests? i.e. sub-commands such as clear, restore, remove

* Removed the dependency section 

Removed the dependency section

Co-authored-by: Carrie Roberts <clr2of8@gmail.com>
2021-02-09 11:13:25 -07:00
..
2020-10-24 08:15:58 -06:00
2020-11-30 09:18:32 -07:00
2020-11-30 09:18:32 -07:00
2020-12-15 14:18:41 -07:00
2020-10-24 08:17:34 -06:00
2020-12-01 13:31:40 -07:00
2020-11-30 09:18:32 -07:00
2020-12-15 14:18:41 -07:00
2021-01-08 09:19:55 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-11-30 09:18:32 -07:00
2021-01-08 09:12:14 -07:00
2020-10-24 08:19:12 -06:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-11-30 09:18:32 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-11-30 09:18:32 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-12-17 22:57:51 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-12-01 13:31:40 -07:00
2020-12-15 14:18:41 -07:00
2020-12-15 14:18:41 -07:00
2020-11-30 09:18:32 -07:00
2020-12-15 14:18:41 -07:00