-
Notifications
You must be signed in to change notification settings - Fork 2.8k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Update T1562.001.yaml #2570
Update T1562.001.yaml #2570
Conversation
Adding new test for T1562.001 for disabling real-time protection on Linux and MacOS.
Fixed yaml formatting issue
Remove blank auto GUID to resolve build error
Hello @JeffMichelmore : Can you add installation of mdtap as a pre requisite for this atomic, this tool is not available by default on Mac/Linux and we will need it to be installed in order for the atomic to be executed. |
Thank you @patel-bhavin this should be resolved in the latest commit. |
f196a65
to
6efc6d9
Compare
@JeffMichelmore : curious to know if there is a CLI way we could install mdtap ? |
On Linux, not completely. On MacOS, no. On Linux, there are a series of commands which vary across distros including adding distro version specific repos (ie sudo yum-config-manager --add-repo=https://packages.microsoft.com/config/rhel/7/prod.repo for rhel 7 and sudo yum-config-manager --add-repo=https://packages.microsoft.com/config/rhel/6/prod.repo for rhel 6). Even still, there requires downloading the onboarding script from MDE portal afterwards which cannot be done via CLI or API call as far as I know. |
yes, appreciate the details in there. It what i could gather as well from the interwebz! Thank you for your first contribution https://github.com/redcanaryco/atomic-red-team/wiki/Contributing#claim-your-free-t-shirt |
Adding new test for T1562.001 for disabling real-time protection on Linux and MacOS.