mitre / training

A CALDERA plugin
https://caldera.mitre.org/
25 stars 17 forks source link

Blue Training: Malicious File on System #167

Open jasonlmaynard opened 1 year ago

jasonlmaynard commented 1 year ago

In the training module - blue team

Write a file on the Windows machine under the C:\Users\Public directory. Get the SHA256 hash of this file, and write it to C:\Users\Public\malicious_files.txt. The autonomous defender should automatically find and delete the file.

image

File is removed but flag is not granted and I cannot move on in the training.

sato-cyber commented 8 months ago

Hi everyone involved. I'm having the same problem with the flag 'Detect malicious file on system' in CALDERA4.2. I hope this issue will be resolved soon.