diff --git a/0_custom_configuration/all_modules.txt b/0_custom_configuration/all_modules.txt index 350b3964..a32da81c 100644 Binary files a/0_custom_configuration/all_modules.txt and b/0_custom_configuration/all_modules.txt differ diff --git a/0_custom_configuration/mde_covered_modules.txt b/0_custom_configuration/mde_covered_modules.txt index c19b2b6d..2f6433cc 100644 Binary files a/0_custom_configuration/mde_covered_modules.txt and b/0_custom_configuration/mde_covered_modules.txt differ diff --git a/11_file_create/include_powershell_profiles.xml b/11_file_create/include_powershell_profiles.xml new file mode 100644 index 00000000..2778ca1d --- /dev/null +++ b/11_file_create/include_powershell_profiles.xml @@ -0,0 +1,23 @@ + + + + + + + \Documents\WindowsPowerShell\Profile.ps1 + \Documents\WindowsPowerShell\Microsoft.PowerShell_profile.ps1 + C:\Windows\System32\WindowsPowerShell\v1.0\Profile.ps1 + C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Profile.ps1 + C:\Windows\System32\WindowsPowerShell\v1.0\Microsoft.PowerShell_profile.ps1 + C:\Windows\SysWOW64\WindowsPowerShell\v1.0\Microsoft.PowerShell_profile.ps1 + + + \Documents\PowerShell\Profile.ps1 + \Documents\PowerShell\Microsoft.PowerShell_profile.ps1 + C:\Program Files\PowerShell\7\Profile.ps1 + C:\Program Files\PowerShell\7\Microsoft.PowerShell_profile.ps1 + + + + + diff --git a/attack_matrix/Sysmon-modular.json b/attack_matrix/Sysmon-modular.json index 969e604a..a44ca3fa 100644 --- a/attack_matrix/Sysmon-modular.json +++ b/attack_matrix/Sysmon-modular.json @@ -1105,6 +1105,22 @@ "comment": "", "enabled": true, "metadata": [] + }, + { + "techniqueID": "T1546.013", + "tactic": "persistence", + "color": "#fd8d3c", + "comment": "", + "enabled": true, + "metadata": [] + }, + { + "techniqueID": "T1546.013", + "tactic": "privilege-escalation", + "color": "#fd8d3c", + "comment": "", + "enabled": true, + "metadata": [] } ], "gradient": {