Skip to content

Commit

Permalink
Update T1562.yaml
Browse files Browse the repository at this point in the history
Updated the atomic test(#1, redcanaryco#2) name and description.
Added clean-up commands.
  • Loading branch information
D4rkCiph3r authored Mar 18, 2023
1 parent 6798df9 commit 0f0cdf3
Showing 1 changed file with 11 additions and 5 deletions.
16 changes: 11 additions & 5 deletions atomics/T1562/T1562.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -20,23 +20,29 @@ atomic_tests:
reg delete HKLM\SYSTEM\CurrentControlSet\Control\LSA /v RunAsPPL /f >nul 2>&1
name: command_prompt
elevation_required: true
- name: Disable journal logging
- name: Disable journal logging via systemctl utility
description: |
The atomic test disables the journal logging using built-in systemctl utility
supported_platforms:
- linux
executor:
command: |
sudo systemctl stop systemd-journald #disables journal logging
sudo systemctl stop systemd-journald #disables journal logging
cleanup_command: |
sudo systemctl start systemd-journald #starts journal service
sudo systemctl enable systemd-journald #starts journal service automatically at boot time
name: sh
elevation_required: true
- name: Disable journal logging via journald.conf
- name: Disable journal logging via sed utility
description: |
The atomic test diables the journal logging by searching and replacing the "Storage" parameter to "none" within the journald.conf file, thus any new journal entries will only be temporarily available in memory and not written to disk
The atomic test disables the journal logging by searching and replacing the "Storage" parameter to "none" within the journald.conf file, thus any new journal entries will only be temporarily available in memory and not written to disk
supported_platforms:
- linux
executor:
command: |
sudo sed -i 's/Storage=auto/Storage=none/' /etc/systemd/journald.conf
sudo sed -i 's/Storage=auto/Storage=none/' /etc/systemd/journald.conf
cleanup_command: |
sudo sed -i 's/Storage=none/Storage=auto/' /etc/systemd/journald.conf #re-enables storage of journal data
sudo systemctl restart systemd-journald #restart the journal service
name: sh
elevation_required: true

0 comments on commit 0f0cdf3

Please sign in to comment.