jcwilliamsATmitre
jcwilliamsATmitre
Hey @hxnoyd! Hmm yeah I see what you are getting at. I'm not sure this is something we would add though, since `alert` could apply as a relationship to (almost)...
Circling back to this, we have published the first release of the data sources - https://attack.mitre.org/datasources/ but will consider this feedback for future releases. I'll reach out to directly as...
Hey @chris-counteractive! Thanks for reaching out, we love to hear ATT&CK is helping you and how we further improve that! Addressing your specific questions: **1**. As you saw in the...
**First off, this is a perfect venue for these discussions! We definitely want others to be able to track and build on great ideas so thanks again for sharing.** Interesting...
Yeah we're been interacting/cross-pollinating with @ikiril01 and others from CAR. Still TBD but as you said there may be some interesting opportunities to explore! And regarding STIX extensions, we looked...
@Cyb3rPandaH & OTR thanks for sharing! Going forward we'll definitely start documenting more of these specific event examples for each component, so this info is super helpful! I have some...
Thanks @Cyb3rPandaH!! We just released the integrated data sources (https://attack.mitre.org/datasources/) 🥳 but I will review this for any additional updates we should consider 👍
Hey @leegengyu! Yeah I see what you are saying. I don't think you can change groups, but the solution could be similar to APT29 where the operation is split into...
Hey @leegengyu! This channel works for questions regarding Evals methodology, sorry about the confusion. So as you've seen this privilege escalation takes place in 2 parts, in [3.A](https://github.com/mitre-attack/evals_caldera/blob/master/data/abilities/privilege-escalation/1345bff7-6f26-43b2-a92a-9aabccdb3db0.yml) a token...
Hey @leegengyu! I apologize for the delay. I am glad to see that you figured out the group label error! Regarding your question about high-integrity processes, when using `Invoke-BypassUACTokenManipulation.ps1` we...