Repository navigation
Conversation
| display_name: 'Modify Authentication Process: Multi-Factor Authentication' | ||
| atomic_tests: | ||
| - name: Disable MFA by Blackholing Provider Domain via Windows hosts File | ||
| auto_generated_guid: 9f5deb8d-f3cf-47df-899c-0de1958980c6 |
There was a problem hiding this comment.
@einlamye - can we remove this auto_generated_guid
This gets auto_generated_guid
also, remove the .MD file - that also gets auto generated!
There was a problem hiding this comment.
Yes do as you wish tanks for your review 🙏
Deleted as said in the comment
Removed auto generated field as said in the comment
einlamye
left a comment
There was a problem hiding this comment.
Just did the requested changes:
- Remove the md file
- Remove the auto generated field
|
Thank you! Can you share execution and cleanup commands of this atomic via Invoke, this would help us with reviewing and merging of the atomic! Neat atomic ! |
|
Thanks! Here are the Invoke-AtomicRedTeam commands for both atomics. Windows: Invoke-AtomicTest T1556.006 -TestNames "Disable MFA by Blackholing Provider Domain via Windows hosts File" -InputArgs @{"mfa_domain"="api-xxxxxxxx.duosecurity.com"}
Invoke-AtomicTest T1556.006 -TestNames "Disable MFA by Blackholing Provider Domain via Windows hosts File" -InputArgs @{"mfa_domain"="api-xxxxxxxx.duosecurity.com"} -CleanupLinux/macOS: Invoke-AtomicTest T1556.006 -TestNames "Disable MFA by Blackholing Provider Domain via /etc/hosts" -InputArgs @{"mfa_domain"="api-xxxxxxxx.duosecurity.com"}
Invoke-AtomicTest T1556.006 -TestNames "Disable MFA by Blackholing Provider Domain via /etc/hosts" -InputArgs @{"mfa_domain"="api-xxxxxxxx.duosecurity.com"} -CleanupThe Both atomics require elevated privileges, as reflected by Thanks again for taking a look. |
|
This PR is stale because it has been open 45 days with no activity. Remove stale label or comment or this will be closed in 10 days. |
Details:
Adds two atomic tests for T1556.006 (Multi-Factor Authentication).
example: null-routes the MFA provider hostname in
%windir%\System32\drivers\etc\hosts.Both keyed on a
# T1556.006marker comment for clean, reversible cleanup.Testing: pydantic-model validated;
elevation_required: trueset wheresudois used.Associated Issues: (none)