This repository contains simple script to test your EDR solution against Mitre ATT&CK framework (with some extras). This project is very much in its infancy right now. Only a small subset of tests are presently added but more will be added later. Chances are this script will be redesigned to facilitate this in the future.
Right now this script only works on Windows.
How To
Run the script and observe alerts coming to your EDR console. Cross-verify these alerts to check if your EDR solution identified them correctly. Most tests will just execute calc.exe but it can be easily modified to try to download and exec i.e. Mimikatz.
Tested On
- Windows 7 x86
- Windows 7 x64
- Windows 10 x64