redcanaryco / atomic-red-team

Small and highly portable detection tests based on MITRE's ATT&CK.
MIT License
9.56k stars 2.77k forks source link

Blueteam0ps 31072024 #2902

Open blueteam0ps opened 1 month ago

blueteam0ps commented 1 month ago

Details: Added pscp.exe based remote file copy to existing T1105 Added makecab based compression to existing T1560.001 Added an E-mail Hiding technique in M365 by creating a new T1564.008 yaml file

Testing: Tested locally. Screenshots to support execution is provided within the PR

Associated Issues: None T1564 008 T1105_33 T1560 001_1 T1560 001_2