From bcb6b50def23d65bf7d64c6f332a6be1e5a33cc8 Mon Sep 17 00:00:00 2001 From: blueteam0ps Date: Fri, 11 Aug 2023 04:20:49 -0700 Subject: [PATCH] Added first batch of M365 atomic simulation logs --- .../m365/collection/enable_pop_imap_owa.zip | Bin 0 -> 686 bytes .../m365/credential_access/o365spray_default.zip | Bin 0 -> 1995 bytes .../credential_access/o365spray_reporting.zip | Bin 0 -> 1830 bytes .../disable _strong_authentication.zip | Bin 0 -> 1028 bytes .../set-mailbox-audit_log_age_limit_to_zero.zip | Bin 0 -> 701 bytes .../set_mailboxauditbypassassociation.zip | Bin 0 -> 696 bytes .../unified_auditlog_ingestion_stopped.zip | Bin 0 -> 678 bytes .../add_a_user_to_company_administrator_role.zip | Bin 0 -> 901 bytes ...ccount_delegation_full_access_permissions.zip | Bin 0 -> 765 bytes 9 files changed, 0 insertions(+), 0 deletions(-) create mode 100644 datasets/atomic/m365/collection/enable_pop_imap_owa.zip create mode 100644 datasets/atomic/m365/credential_access/o365spray_default.zip create mode 100644 datasets/atomic/m365/credential_access/o365spray_reporting.zip create mode 100644 datasets/atomic/m365/defense_evasion/disable _strong_authentication.zip create mode 100644 datasets/atomic/m365/defense_evasion/set-mailbox-audit_log_age_limit_to_zero.zip create mode 100644 datasets/atomic/m365/defense_evasion/set_mailboxauditbypassassociation.zip create mode 100644 datasets/atomic/m365/defense_evasion/unified_auditlog_ingestion_stopped.zip create mode 100644 datasets/atomic/m365/persistence/add_a_user_to_company_administrator_role.zip create mode 100644 datasets/atomic/m365/persistence/mail_account_delegation_full_access_permissions.zip diff --git a/datasets/atomic/m365/collection/enable_pop_imap_owa.zip b/datasets/atomic/m365/collection/enable_pop_imap_owa.zip new file mode 100644 index 0000000000000000000000000000000000000000..eb0da98912623e320c55f79877540d67b2de9708 GIT binary patch literal 686 zcmWIWW@Zs#U|`^2_@&4Z?!I{Ox*v=T3_i>Z3=%-m)V#!`oYeS&{DSz*+{A+T{PIM- ztm6E<-r&=Dw+#gLh`+EGvD(^@`9X7{)m7dgg^bG*8z(Q|D2mt@vvpHSKvAOkiT&kE zZ`8{0JaKz>?##J&llpH)a$N||-Mr?SqPDT$PK7NBF*=!XUa>}#eK&FUuRLTdV3@UN zCzI0NewU(U99QpUX>TpoQ~H)Ad}&3;6xSCgZ{`$ohUVVBJHbagV^w@|oygTVqjOE_ zQ-XX|&f0D?lycg;DJ;Q@yM52=2e+O~|IJ&Ka(L_QYkwED*WF%t!YG%yDR0*VyH;B^ ziKR`!r;0W0p0%FgKbdYfKV`dO>5GIbyRt9$?`l1G=I6QE<}}lcxmQCoesx>Ay|)Yq zjw)D{(lfPZ70_QzFT zjrfmvrwcbPzYgEe7~svwWY2&ry{G_F3X{U?)5OFCQS}q9z(V=r8v4H57zC|x-+b{= zU*bs=aJdVW@8YTJ6EeWDiZ#ZKSArCAJN~22>*r~(oKxhTgbTfgSFSVqPN4eNBTerG zlpHh~i%0Bn^`U6$z`~#J?2&SBR)Ne*3C2BSVr=mIqLa0+D~ZU=9s8bQP0u%6@RZ3= z^K~cLF;(LC+gVbnAJY6H{5p7{=v>-aE=n*R4aNLa@-w8F?i*%U&M9n<-4xmK+AAJy zedjF+Rs&^cE*!bt`8J$=9yT{@GFlc@S#N)%EcO*hfs2lAuG)oBo@Po_j&10_=1g#* zD0PoNx2r!2*|~k>J#*Y+jyk`+yk zdTD}e=Y%L62wofYeYbRUr)zAWLm~K%S{l3-?K5M;T8hCtclcu-c%8Gh;kEs>UF|F` zuU-}Zw(@TB1$-Q~d8G#-I;U2SU45Vxo;S;g>vhP3w-+IQQxMo^Tk|J-;$Nh?BNapfk@w0&fV@JE_(hYu7=Fz&EAQu1jl>S5V#%uiy!iRN!T!#`F>y+a(kf~uF z1Xl}MZR>7!t1_SN%UFCI6N(z(r+fR>^fwF0Q%f)>JEOZ!PsI=T`}Ph8nlvT$TCZv2 zTd%W|8agIW2^;Dt)vV9FyzKphlm3SrijS{#lvPX(;X4P{bhMlN7Ow|{$Cl1EyuW=P zw=iH;b5P*nk&)A)J~iBnfo*1wt;8Y=Z*t;|23=PdHY@D!*wySz!_ECgBBm{CSHloA zJ_#1%7;?+MHcInuBtIjA+G()7H)Rxa4_cW#H9SB5_46h}ln^8|HX9sOg1z*ZV6w&O zVHX1D`;Ruw@nzEIJk&!92-Zky1Qm%!rD}$t^;p07g~WCj#Gv1U`#M#!b7W3D_&`!( z9uNP^d`A?3S#zSlAx>VqoD;IT@IGa;#6d3gTsJqUDc|GMHAq9A@Qlwql$K&o;gRT1 zjT((h;wUW_ES_`9G|rojXx!r8C1sjNf4u#fRj{uR=3lEEptS#9yZYQ0?J;vgXcXPu zDiJdKD6PHVI(Cdm4U6j~4&CRz-j-E512HRl>NVU+(2H`*jxq$nOp9H0c_T@-ZApGD zUVfT9u&;}n>=VhVQd$e-v0kzqVf)pB*RLH}Z5kT?b?;XHuy+ehBZ>$q?9( zwY0m;w8xi4w=QH7WFvz*kuT{c2SLCHQDl5Qjf-SO7@$mF*%X1jS|5@M*L1_sV$h@Q zP5RAm8JVDHR*(8FRmC7WQ^ z11j)faMZT9Gwp0qCPRrP)N&Zn6xiN+e}l$lx-j{c+8}0$;guo%p|9n`_)gcgLrkkI zEqU-oA=_b>9{-yG{=FW9Xiyu+wc8uzh(y$ieQ7s>y!RB-3MzX%${@nWAO&=hmtDj=XT@=pDpE;BNh1m{h)&QGmgI7cL+Pvs^x- ztVeeJ)_VLqC2Ku&YZ+H-nCpUV1Q%27nuqrhJ<}p4t0*e2jjDt)(gi4~Y35qf*Xpag zyVnnJ*qJxNnJ?w*MO{vjorx=+alvzcusIBeLCW0`(q{l2kHgLgDoB8zq3^R)i+2HY z`5;hZFMD3O@a><;mO*KiJ*vAk>fquPJrRrjX|5fsKrvAH^v&DQLZr~%mz0bc|}vHj6}Cw35%>8?3Xyksk0=rd}%1Fxj%VBXDOaePg(G9 ze4M)%CwEVk>kw2@lqEme!Wr2%OtfF7QXe<7|h&pYxZzm%Q7rD)2D zW8iiD>#_3GN80I;vQYiHjOZu3RYI%B6Y7LhxCp?z)#umlUy`DQlFo|)2t08)fVxFV zdo{a#jG03g>Hs*5grqa@UpO`R0o1=o_y7C9;41&mUjonoE;}CX5I&id_^0r%;V{xN Re+P*liuvI_KadRo{{!77n&$uj literal 0 HcmV?d00001 diff --git a/datasets/atomic/m365/credential_access/o365spray_reporting.zip b/datasets/atomic/m365/credential_access/o365spray_reporting.zip new file mode 100644 index 0000000000000000000000000000000000000000..e881d1ee13919229fb7f5eeb7ce48880fe17b9b8 GIT binary patch literal 1830 zcmZ{lX*3&%7Jw5XVoNjDAhlIU6(!OTOPZjy6UCE`s#f~i(TY8Jw!V^RN@WPGrIy;O z)1nxfPAwg3DHRk&MW5RDrD}<`n7ny&-oLr`oO{pRe%*V|M{*Jc$pZiY2tc3-@us(0 zEQNppfCf(h04~f1n_y3chlE{@@(cTCNN`w0K+rYA>*2vct2sWwgGTb56KMjdR{*?{JmSs6OUW4 zXS~)FV~ifMakI)rcQ*pFawI(DG&@wME91ELG5?9uOdK+ooh;S-G5(k#$g!-|&+*;P zB!0;EXYx!JV(Huar^SubWaWgNp#AR5_W9nzr(WVMW=sOAEC-S!KIM-|054u(aUeXkP2HZW1lu61cUp3`p_#MY zGt${ORCPsW5WB$IYW>GvY)9Xdud5ZcRMqkVrBlu~JsR)io{?$(Wyy`a)lm^w`yqPh zC9jy9w;foF%U|e9_>lCOdh4TV-FmcRmb&ZMtAvg>iFbDRHGM>;`8O&bGZO2Cecw1% z(cRQKA~3+_Hjmjf6r5TbjtM03bF0L;cq|DFNnMicEIkge+W!7l5Kp!Hnjju*&4ji& z7L0umfr8im;p@FESU&4LwK27&fS=5sq;LP0&09%65q2-d(CS1t>1KAS+DZ!iW2v`Y zq^6R$oqBj^6z1bZL5oSq?p-j?r2fHdiPP@dTF}GcYu{KnV1?XdZ_%G`aM6^+K`pt|-0%W9|az3q)C(|%bz_GwRM)%frMCP8KH z%S8LU;;`>}Y>sKQ>H0$rlgh^mkax`$FR}!E9>60 zUws7J>J@kXWuI4!x!)`Ib-Rmv{M3dwOjBC3Eg^Yca|E%E)bo z=rbMIcS+EG$qEP(ow6Doz$r?j;E=>Rw-99{w)#1RrSfbjK&2vGOID^g4s0hz52?%Y z#i7sP(MQovrLSqppU%7Hb%px_NA%6nRmg7=?h8*iZ|>7C#cJbF4hh5QWr!e5|4malR!)zVjtXs$WS}ha8cHF z?h3?ux>tMyghIFFQqpbX#U0Ie%N?p6qwTfL4z)=vW+EP@7|5zp$jk0Q`4i?bgEoA* zNXy;ovljl5J)xOswlfD_l5U||+RNNz>a@_^mFOpnF13}YiTz~mQLGfeH-lt!MShE2BZpcru3bjP%UQm_9(rU^ z96QBj-yY{!Dy5nCx!${!vBj|uIdCYn?GbBs(ZW^HLn`~BG&RaMMV=i;d6uaa|9(uw z^BGMNrkDP&(7|` z(k(Et5B0xNxQehpa+_!Ewm1=D{4NQm{!HSB0B-*g*(QJeE~k5qTh74G!Ox`}F22-} zjnHZXF@Vg%Yl%o&z`3jgH;skkYO0cuXvssC6r&7eoObDV?FD6u!-br-vO`hH^cNAn zsGpFDNgz?-(qT?x1EmK01%!SNJXRjIC4V5J1aj~(kAQ7S*OVH#j19zxe^Mnm0Yy#& z{*F`HLQ?%#H2$=IPc6y6I)Fm96*uKoE_QtY{x$M{M{*Jq@(%z23iZ0sKl(HJ13+Cn A+W-In literal 0 HcmV?d00001 diff --git a/datasets/atomic/m365/defense_evasion/disable _strong_authentication.zip b/datasets/atomic/m365/defense_evasion/disable _strong_authentication.zip new file mode 100644 index 0000000000000000000000000000000000000000..a8cb1f03e1ab3b5d68d2441562a77986f031f62b GIT binary patch literal 1028 zcmWIWW@Zs#U|`^2U{>M?UtRgV)q#K^Z8Tl3ARXl#{9uUtCg@pO+q=SXz>i znpcvUoLG{XpQo2qoS*kL{B+-C1ChI*MMI|r^#AdgvqYPVb)}Py3%AY*4$E)8oJ%|l zWft`OdLN^{R5q^3(Mc*`wU=Mc{NnlF0`;19i%rpd+K&nmA!jTNB4Aix$lzCZ;>Se`L!!-!UOwda+E;F0nT=<2PxC zPM`nl>O3Pu#m7863#X{5EV(pck4BJ_@090E(}flaeitc8K3lZgkze@#t+J`n7EgDH zd5X=wc46C&_ma0N8KUPTPvP>@oW5{}{^Njq*L>g3+Gd&ks&u8Uo#;Cs^VhZ+3zj{8 zV0mL(`P|-S@!r~K(^J1K|6YllkrlqLJu=gA_p!WMo1fA(@02rRBiA4Jcj#Px-rtEk ztKTmyyLbNH_G)?AD{NU*=-TmRfQ2i^j-DU67-4Vw{cNM0*%51v()1uRzvFc`*Yvs_W!Rq`LgAx@U%ON zN}MvqcwDUQ=fwM6-g7OqJyYsyZQo-<=Hnac^x3B;?aN7A`G#x5;dA@0ywSc_`*B~} zch#A{=Dl2PF#m7ZY2LY_3p4wF{9};a)^S+u{iW46GS-&(b&9z<9-31$>6C%`u?qq2 zTAG)b_#)~K{8KzL+s03xX>WI8;_0}jUNe;s>1|uvTzdPlNV2EmLWN3|4`q`lOfX?P zveYox#>Y3Wi!uFbgS4Kj0*JMd%XOG$w{%oN3A?Bf1S8&^0q&}KFr_pbpPdP6I4BQT0bT!d9Fxxobo_1 zaV5iH<#Wm$`>%?vVAx-KB`x@E|J97ex4tpII>gcc?d9SZ_0witHvRdU%`SHG|3juf zB?G(}nd}*GWjz&O<^ur*FiBKKP^K_Y~CBo`15pZ|zI|$11rc z;{W{)ySu7uEWRhm5a8nQwu5t_;sdQ@i$0OU15-$C^wfuhW`r`)E*?$L@&klUO zsCVD#@Y9|?Q+%dwS@|*VSx8V|@9G)x_nu{PuATC2hYe@w*^Uh+0%w=1tXi0mrMhJD za}MFU6N0gqs&AL?l>fEq{kDs0HC#Kl{1sc+eK*gEO?m2LUV#mwN2}H-bItWAP|HwO z6~AJ$+;;MZ2cIU?zAD+h;TnHL;Dxsj;;;RW^pF3&l}FhkFKPMlHQMw4{V*~6`!=tV z`_HpxmTP+|y;o0ijO6z6UU1f0MYq%`*2Mktd;X)7Pfk5tVJI(Hu>SVniY*y`A6{kh z+noL?>3!0^cjn!_`}=Os_&?bpc!qy?;V(n&upKXdZqJ%Cc^8|rL70M4LbF@wJPl{v zhBX@3_gMU84)A7VvS+}RR8)Y81q2kpBxwnU3#yBeL4qN~tNhfvnd-D$%%D|OwQGuhX_E*?mxEs5=i3YGZ|kOg_G!?N@K8%Q`%~tMjKb{H z>vdYDaZDj=w3enW-Ed;Vw-XN4+S!UrO!_u#x8@O6-nzzMqx9vnG7Ft=`+UWZ&+RM} zeEi@Rr}3l1$G*J1|I*@RMtsr1i^dEW*0h{5zHMU4tiM)w#ggv8=X`es{`}gZe7nZx zSnc$%lS^tH(vk;L*Ue-%e|&v4gOfae?}_5gp%cq9sBqmmYdJG zc;@QCzb1dvp6q%P_2%-|A|>tOg~f5OsSgzdc(byB OL>Pgv0!V8yfp`F^a3OyH literal 0 HcmV?d00001 diff --git a/datasets/atomic/m365/defense_evasion/unified_auditlog_ingestion_stopped.zip b/datasets/atomic/m365/defense_evasion/unified_auditlog_ingestion_stopped.zip new file mode 100644 index 0000000000000000000000000000000000000000..77d3fc3079053d1e79dbab6f0a44019e5cfe8763 GIT binary patch literal 678 zcmWIWW@Zs#U|`^25K!U>mq}rLc8QUJ;S>`CgE~;OG%qtPGc_eXu{0&KBqu*TJ~J;p zwYVfRKQF$xB)^~_HAOG0I6tp6=ycv~1A#xH&dbF(Sof)P*3i$6FECi_G)& zqGuXu?DCL$a({QoTPE8l3J!PX&YTou0~JY);pqg-+CgJs^T z*;%>X-8=j;vL<|BQ+{`w?dCDh7VFj0o`vd5Sl%q3>^)g2V4L3JR@=567Plwd=Wl;1 zP-`I)Vzok|&i{bt-pz9kuyh+7lYO*ft4B5et8Eu&Ij&A-t0+ImbMl>>f5NmWk1O7N zHd|dI=a@469G}DQi%ZMj339O{yBRLiP2axu!P})jr~Buxs-EsvV31iWcj1W52-)j@_5n|jbH7?m0X6YbA1!jCzP@MEbeIkXjFEn zXX&F$(#A(@dYo;KBpY!4t66upfaS%bl35ety3ZMP3YzgYPL=4ka%cGzR=u<}Va|(s zzV#{^YveY02Y%&FzQd9Iah3et|JwgoEW2HI(wVW{xnotu-CbW!FWq!k|MywhH2Hg6 zK2P6>W@dH0o+ccWtQ60jxmf7Mp#q6tUsvwpxq19S^XBX78`{1kf85aJ_5B>v`?#;q zoA&6st$vOi^B(%k6h7%rMIKKVyJ5Ba=M?u7sfi xOd24d049k}CR|Vrj0_SCy#muuygYdmnAT81fHx}}NQ4mxD}l5)FeNfD002{n6l4GZ literal 0 HcmV?d00001 diff --git a/datasets/atomic/m365/persistence/add_a_user_to_company_administrator_role.zip b/datasets/atomic/m365/persistence/add_a_user_to_company_administrator_role.zip new file mode 100644 index 0000000000000000000000000000000000000000..e5090ea71877c9392b984250bde8cccca4aa344b GIT binary patch literal 901 zcmWIWW@Zs#U|`^2c&Eq_ZeJ&&wv>s1A%=~CK^G{Rn358o7++ePS`=TBAD^6`TacJn z8K0Pvo0*qcTvC)+l3x^Gl%JETmsOmfw>IQ--faVcJ>oCyC9Gz%xdyGDlXZhLfyKA` zhA*FMK){nz3Cf*puIhzM|EoQJO*G-(!C5u=#LSy>Z?eiSn#h#0-Gvv(4bN z&^-8M%{$51!v~bl%-R0RuA!+&Z>Dmyi^O9Y!#Q3dVWEv1d`?|@{Vc@do+U@_lbo#u zz0dw_kG@uxwKKNNFJ+eq)2?$5>q-**5}%$+>d`znV@c1vC6eCzIqpW?ec6~Nt=jW@ z)fJ_!2pQ(*2#0}s8WpBO(^@l0EN zi@o^Z>!tgvBivvAljDq@`|y&XQ>Wl|gYvKQ0?yriv*>H6{jXI^S6#^tE#Gj^tbgO; z`3K+nDXIn}L>WvG3vH5ED5>>`N%_sQ*{O!!3diiuM7@)^ttQ`kd{y+7ny3B$uF1Vj zJ9s-ZUqkxps&i8B9$6`vH6QDYoN?m+z2~Y|zGkk@zwIle|9h_E>1gR)Z|7yl?!5Us zvpqunaedUZvwkYC>k{_d`EA?sP9agWJ~fC#&#Q-Jt=17QpMZ&*ggiTEdQ`-TioV&I za{jNv+37Vl_oQVlqx0DBe-`qQIqVZYw{_X=J-#bDCL1m0Fme=Zo}n;LxKYUOl!@XU z)s0Uj_dR5l>Q2^j@eGU-DtM}~Af{s7}d0ye~-<)ctfIB zf8!^c=K|?Wp`Km>!iB9CXN{(a8|q!2lWOE0@A<6RB>vOSj}P5nyiN7oG`S_!f7;Wm z^v`#Vqw4>CVGrmnUyBLd}6w0p6^@ Tti`~<2!!=O`U5btF)#oCwswJ| literal 0 HcmV?d00001 diff --git a/datasets/atomic/m365/persistence/mail_account_delegation_full_access_permissions.zip b/datasets/atomic/m365/persistence/mail_account_delegation_full_access_permissions.zip new file mode 100644 index 0000000000000000000000000000000000000000..53b201f33aa7050f2b80a259db1c3eb951f59b71 GIT binary patch literal 765 zcmWIWW@Zs#U|`^2c&f+|&iveSH$M{tLn$)@g9%VHH!(9OJ~25tzcjBTJ|#6LH9fH; zGe0jrtuzNLo?2WSUyxdqn^{~86fV}wD$dXA4LY57#X(??@<;v?>J!SsK5shySeV=E z2p7}p6ycUdGS4nfO3 zlapJ&wP{Q5;fAk*lg*ZO*Q?z)5?g)Jg4thVsp-TmpN_OG;QYFDD^v8=0*i8Gjb$!XSdCCyWPEPis{wIQQy>e z*yyrcs(4rFD z@Bi_tkNJm5?SeAq8;uuV7xvh%*t_z-MXYRa;TOlib@%tAKAm&9GBnV3dCb1U3#WRX z=zgS8RTq4xTgUcR_fILt^ksMZm-=5=%3(QMJb1@k+jIBV7Rs1UudFy$xFcWQtcJWn;$eN8ggd<}A2$STI}tfW(C(8EPNSYP+rBP-Tp> zdfFS}wffPwudDY5cr!BDGvG>MD!@br0t#S~yadMu)y>Et!7$y$VEW6GHyNSE!Knam TRyGia5eVCWbRsa3GcW)EQ~p40 literal 0 HcmV?d00001