SecurityRiskAdvisors / VECTR

VECTR is a tool that facilitates tracking of your red and blue team testing activities to measure detection and prevention capabilities across different attack scenarios
1.36k stars 161 forks source link

v8.2.2 - Imported Atomic Red Team executor setting ignored, commands don't match "Operator Guidance" #170

Closed clr2of8 closed 2 years ago

clr2of8 commented 2 years ago

I imported the latest index.yaml from Atomic Red Team. When I used the "Automation & Logging" feature, the executor for this Windows test was set to "sh" which leads to an error during execution.

image

image

If I go into "Configure", I see that the executor is set to "sh" (should be CMD) and the Commands are Linux commands from another test completely and don't match what is in the Operator Guidance Section.

Actually, I noticed there are two versions of this test. One has this issue and one doesn't. I think one comes packaged with VECTR and one is the one I just imported.

image

SRAPSpencer commented 2 years ago

Thanks for pointing this out. This data actually exists in the instance before the Atomic Red is imported, hence the lack of "ART" at the beginning of the test case.

We're working on updating the shipping datasets for VECTR which should address some of these issues. It is a larger than expected technical lift to accomplish this so no ETA at this time. Hopefully in a release in the not too distant future.

SRAPSpencer commented 2 years ago

This has been resolved by Release 8.4.2