elastic / SWAT

Simple Workspace Attack Tool (SWAT) is a tool for simulating malicious behavior against Google Workspace in reference to the MITRE ATT&CK framework.
Apache License 2.0
161 stars 7 forks source link

[Emulation Tuning] Adjust `Access Stored Keys and Tokens in Drive` Emulation #75

Closed terrancedejesus closed 1 year ago

terrancedejesus commented 1 year ago

Overview

This pull request makes adjustments to the Access Stored Keys and Tokens in Drive emulation.

emulation log file: collection_drive_access_private_keys.log note that these "private key" files are empty and the URLs are NULL including the folder ID within Google Workspace.

Screenshot 2023-08-31 at 10 47 48 AM