center-for-threat-informed-defense / adversary_emulation_library

An open library of adversary emulation plans designed to empower organizations to test their defenses based on real-world TTPs.
https://ctid.io/adversary-emulation
Apache License 2.0
1.6k stars 292 forks source link

[TURLA]: Missing/Inaccurate steps for configuring Linux Attack Platform (`modin`) in Azure #152

Open rtkcgrantcharov opened 7 months ago

rtkcgrantcharov commented 7 months ago

Several issues have been uncovered in several of the steps outlined in: Setup-RedTeam.md

  1. Run files/support/kali/kali-prereqs.sh
  2. Run files/support/kali/kali-update.sh
rtkcgrantcharov commented 7 months ago

After some more digging around, it appears that SimpleDropper_http.exe and SimpleDropper_https.exe might in fact be EPICDropper_http.exe and EPICDropper_https.exe in the binaries.zip. This inconsistency should be fixed.