SecurityRiskAdvisors / VECTR

VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios
1.39k stars 164 forks source link

Import Atomic Red Team Test Cases #103

Closed clr2of8 closed 3 years ago

clr2of8 commented 3 years ago

I want to update the Atomic Red Team test cases to match the latest from the Atomic Red Team repo so I imported this file https://github.com/redcanaryco/atomic-red-team/raw/master/atomics/Indexes/index.yaml and there were no errors but I don't see any of the new data that got imported. I expect to see all the new test cases that are in the Atomic Red Team repo now as well as the new sub-technique numbering structure.

image

I click submit and get this message:

image

carlvonderheid commented 3 years ago

Hi, thanks for bringing this to our attention. I confirmed this as a bug, it looks like the new pre-attack mappings for resource-development and reconnaissance were missed in the backend processing. We will fix this in a release in early January. In the meantime, if you use an index without the pre-attack merge (or delete all the resource-development and reconnaissance from the index you tried) it should work.

clr2of8 commented 3 years ago

Awesome, thanks for posting the work around and excited to try to fix in January.

carlvonderheid commented 3 years ago

This should be fixed in 6.1.0, but it looks like no test cases are generated for resource-development and reconnaissance, as Test Cases are generated from the "atomic_tests".