Skip to content

Commit 788b9c2

Browse files
Use sub-technique and add missing modules
1 parent 7ce2bdc commit 788b9c2

24 files changed

+49
-24
lines changed

modules/auxiliary/admin/smb/psexec_ntdsgrab.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ def initialize(info = {})
3535
'References' => [
3636
[ 'URL', 'http://sourceforge.net/projects/smbexec' ],
3737
[ 'URL', 'https://www.optiv.com/blog/owning-computers-without-shell-access' ],
38-
[ 'ATT&CK', Mitre::Attack::Technique::T1003_OS_CREDENTIAL_DUMPING ]
38+
[ 'ATT&CK', Mitre::Attack::Technique::T1003_003_NTDS ]
3939
],
4040
'Notes' => {
4141
'Stability' => [CRASH_SAFE],

modules/auxiliary/gather/checkpoint_gateway_fileread_cve_2024_24919.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -35,7 +35,7 @@ def initialize(info = {})
3535
[ 'URL', 'https://www.rapid7.com/blog/post/2024/05/30/etr-cve-2024-24919-check-point-security-gateway-information-disclosure/' ],
3636
# Publication of first proof-of-concept exploit
3737
[ 'URL', 'https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/' ],
38-
[ 'ATT&CK', Mitre::Attack::Technique::T1003_OS_CREDENTIAL_DUMPING ]
38+
[ 'ATT&CK', Mitre::Attack::Technique::T1003_008_ETC_PASSWD_AND_ETC_SHADOW ]
3939
]
4040
)
4141
)

modules/auxiliary/gather/fortios_vpnssl_traversal_creds_leak.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ def initialize(info = {})
3232
['URL', 'https://www.fortiguard.com/psirt/FG-IR-18-384'],
3333
['URL', 'https://i.blackhat.com/USA-19/Wednesday/us-19-Tsai-Infiltrating-Corporate-Intranet-Like-NSA.pdf'],
3434
['URL', 'https://devco.re/blog/2019/08/09/attacking-ssl-vpn-part-2-breaking-the-Fortigate-ssl-vpn/'],
35-
['ATT&CK', Mitre::Attack::Technique::T1003_OS_CREDENTIAL_DUMPING]
35+
['ATT&CK', Mitre::Attack::Technique::T1003_008_ETC_PASSWD_AND_ETC_SHADOW]
3636
],
3737
'Author' => [
3838
'Meh Chang', # discovery and PoC

modules/auxiliary/gather/qnap_lfi.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ def initialize(info = {})
3737
['URL', 'https://infosecwriteups.com/qnap-pre-auth-root-rce-affecting-450k-devices-on-the-internet-d55488d28a05'],
3838
['URL', 'https://www.qnap.com/en-us/security-advisory/nas-201911-25'],
3939
['URL', 'https://github.com/Imanfeng/QNAP-NAS-RCE'],
40-
['ATT&CK', Mitre::Attack::Technique::T1003_OS_CREDENTIAL_DUMPING]
40+
['ATT&CK', Mitre::Attack::Technique::T1003_008_ETC_PASSWD_AND_ETC_SHADOW]
4141
],
4242
'DisclosureDate' => '2019-11-25', # Vendor advisory
4343
'Actions' => [

modules/auxiliary/gather/windows_secrets_dump.rb

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -68,7 +68,10 @@ module will fallback to the original implementation, which consists
6868
],
6969
'References' => [
7070
['URL', 'https://github.com/SecureAuthCorp/impacket/blob/master/examples/secretsdump.py'],
71-
['ATT&CK', Mitre::Attack::Technique::T1003_OS_CREDENTIAL_DUMPING],
71+
['ATT&CK', Mitre::Attack::Technique::T1003_002_SECURITY_ACCOUNT_MANAGER],
72+
['ATT&CK', Mitre::Attack::Technique::T1003_004_LSA_SECRETS],
73+
['ATT&CK', Mitre::Attack::Technique::T1003_005_CACHED_DOMAIN_CREDENTIALS],
74+
['ATT&CK', Mitre::Attack::Technique::T1003_006_DCSYNC]
7275
],
7376
'Notes' => {
7477
'Reliability' => [],

modules/auxiliary/scanner/ssh/apache_karaf_command_execution.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -34,7 +34,7 @@ def initialize(info = {})
3434
'SideEffects' => UNKNOWN_SIDE_EFFECTS
3535
},
3636
'References' => [
37-
[ 'ATT&CK', Mitre::Attack::Technique::T1003_OS_CREDENTIAL_DUMPING ]
37+
[ 'ATT&CK', Mitre::Attack::Technique::T1003_008_ETC_PASSWD_AND_ETC_SHADOW ]
3838
]
3939
)
4040
)

modules/post/aix/hashdump.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ def initialize(info = {})
2323
'Reliability' => []
2424
},
2525
'References' => [
26-
[ 'ATT&CK', Mitre::Attack::Technique::T1003_OS_CREDENTIAL_DUMPING ]
26+
[ 'ATT&CK', Mitre::Attack::Technique::T1003_008_ETC_PASSWD_AND_ETC_SHADOW ]
2727
]
2828
)
2929
)

modules/post/bsd/gather/hashdump.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -24,7 +24,7 @@ def initialize(info = {})
2424
'Reliability' => []
2525
},
2626
'References' => [
27-
[ 'ATT&CK', Mitre::Attack::Technique::T1003_OS_CREDENTIAL_DUMPING ]
27+
[ 'ATT&CK', Mitre::Attack::Technique::T1003_008_ETC_PASSWD_AND_ETC_SHADOW ]
2828
]
2929
)
3030
)

modules/post/linux/gather/hashdump.rb

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ def initialize(info = {})
2323
'Reliability' => []
2424
},
2525
'References' => [
26-
[ 'ATT&CK', Mitre::Attack::Technique::T1003_OS_CREDENTIAL_DUMPING ]
26+
[ 'ATT&CK', Mitre::Attack::Technique::T1003_008_ETC_PASSWD_AND_ETC_SHADOW ]
2727
]
2828
)
2929
)

modules/post/linux/gather/mimipenguin.rb

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -38,7 +38,8 @@ def initialize(info = {})
3838
[ 'URL', 'https://bugs.launchpad.net/ubuntu/+source/gnome-keyring/+bug/1772919' ],
3939
[ 'URL', 'https://bugs.launchpad.net/ubuntu/+source/lightdm/+bug/1717490' ],
4040
[ 'CVE', '2018-20781' ],
41-
[ 'ATT&CK', Mitre::Attack::Technique::T1003_OS_CREDENTIAL_DUMPING ]
41+
[ 'ATT&CK', Mitre::Attack::Technique::T1003_007_PROC_FILESYSTEM ],
42+
[ 'ATT&CK', Mitre::Attack::Technique::T1003_008_ETC_PASSWD_AND_ETC_SHADOW ]
4243
],
4344
'DisclosureDate' => '2018-05-23',
4445
'DefaultTarget' => 0,

0 commit comments

Comments
 (0)