Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

APT 29 - Adversary emulation plan changes from CALDERA_DIY to Emulation_Plan - APT29.yml #84

Open
leonardogavaudan opened this issue May 4, 2021 · 0 comments

Comments

@leonardogavaudan
Copy link

leonardogavaudan commented May 4, 2021

Hi,

I managed to successfully complete the Day 1 Scenario for the evals plugin with the plan

adversary_emulation_library/apt29/Archive/CALDERA_DIY/evals/data/adversaries/d6115456-604a-4707-b30e-079dec5aad53.yml

Caldera DIY Emulation plan

but when launching the day 1 scenario through the Emu plugin using the

adversary_emulation_library/apt29/Emulation_Plan/yaml/APT29.yaml

Yaml emulation plan

I spotted new abilities present in the emulation plan, that are neither in the CALDERA DIY plan, nor in the documentation for the Emulation Plan. I've encountered errors with these new abilities and wondered if anyone shared a similar experience or had any advice.

I'll be creating a separate issue for each new ability that is causing an error

And updating this issue if I find further errors/bugs with new abilities in the Emulation Plan

1. Bypass User Account Control

Step 3.A.2

Ability in Emulation Plan

Dedicated Issue

2. Credential Dumping using Process Injection

Step 5.A.1

Ability in Emulation Plan

Dedicated Issue

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant