redcanaryco / atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.
MIT License
9.74k stars 2.79k forks source link

Update T1546.008.yaml #2878

Closed abhijose09 closed 3 months ago

abhijose09 commented 3 months ago

New Test Added : Auto-start application on user logon

Existing Test Atbroker.exe (AT) Executes Arbitrary Command via Registry Key added modified for addition of elevated privileges to carry out the required testing

Details:

Testing:

Associated Issues: