Cleaning YAML, updated new category Tamper

This commit is contained in:
Conor Richard 2022-09-17 07:55:16 -04:00 committed by GitHub
parent 5ba729ee1d
commit e878c66e6f
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23

View File

@ -7,10 +7,9 @@ Commands:
- Command: fsutil file setZeroData offset=0 length=9999999999 C:\Windows\Temp\payload.dll
Description: Zero out a file
Usecase: Can be used to forensically erase a file
Category: Forensics
Category: Tamper
Privileges: User
MitreID: T1485
MitreLink: https://attack.mitre.org/techniques/T1485/
OperatingSystem: Windows XP, Windows Vista, Windows 7, Windows 8, Windows 8.1, Windows 10
Full_Path:
- Path: C:\Windows\System32\fsutil.exe
@ -21,4 +20,3 @@ Detection:
Acknowledgement:
- Person: Elliot Killick
Handle: '@elliotkillick'
---