Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add T1056.002 GUI Input Capture macOS test #2531

Merged
merged 4 commits into from
Oct 3, 2023

Conversation

jonod8698
Copy link
Contributor

Details:
Prompt user for their password using a fake system update prompt without requiring permissions to send Apple events to System Settings.

Testing:

Getting prerequisites for T1056.002-3
PathToAtomicsFolder = /Users/admin/atomic-red-team/atomics

GetPrereq's for: T1056.002-3 AppleScript - Spoofing a credential prompt using osascript
No Preqs Defined
------------------------------------------------------------
Running T1056.002-3
PathToAtomicsFolder = /Users/admin/atomic-red-team/atomics

Executing test: T1056.002-3 AppleScript - Spoofing a credential prompt using osascript
button returned:OK, text returned:Summer2023
Done executing test: T1056.002-3 AppleScript - Spoofing a credential prompt using osascript
Test complete
image

@svc-github-aws-opensource svc-github-aws-opensource force-pushed the master branch 2 times, most recently from 3d55b47 to b220455 Compare October 2, 2023 20:45
@cyberbuff cyberbuff merged commit 81368ac into redcanaryco:master Oct 3, 2023
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants