Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Added few new tests for T1518.001 and also rdrleakdiag.exe test accessing lsass #2550

Merged
merged 4 commits into from
Oct 3, 2023

Conversation

swachchhanda000
Copy link
Contributor

@swachchhanda000 swachchhanda000 commented Sep 30, 2023

Details:

Impact Analysis

T1518.001 Security Software Discovery
Newly added tests

  • Security Software Discovery - AV Discovery via Get-CimInstance and Get-WmiObject cmdlets
  • Security Software Discovery - Windows Defender Enumeration
  • Security Software Discovery - Windows Firewall Enumeration

Few improvements

  • Software Discovery: Security Software Discovery
  • Security Software Discovery - powershell

T1003.001: LSASS Memory
Newly added tests

  • Dump LSASS.exe using lolbin rdrleakdiag.exe

Testing:

T1003.001: LSASS Memory
image

T1518.001 Security Software Discovery
image

image

Associated Issues:

Copy link
Collaborator

@clr2of8 clr2of8 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

please see inline comment. you can push any changes to your same branch and it will automatically update this PR (you don't need to close this one or make a new one)

atomics/T1518.001/T1518.001.yaml Outdated Show resolved Hide resolved
@cyberbuff cyberbuff removed the linux label Oct 3, 2023
Copy link
Collaborator

@clr2of8 clr2of8 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Looks great, thanks!

@clr2of8 clr2of8 merged commit 9026f98 into redcanaryco:master Oct 3, 2023
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

Successfully merging this pull request may close these issues.

5 participants