Caldera emulation abilities
4 runnable adversary-emulation actions · command + platform · mapped to ATT&CK
All tactics
build-capabilities · 1 collection · 16 command-and-control · 6 credential-access · 10 defense-evasion · 15 detection · 8 discovery · 67 execution · 9 exfiltration · 13 hunt · 4 impact · 8 lateral-movement · 10 persistence · 3 privilege-escalation · 8 response · 14 setup · 10 technical-information-gathering · 1 training · 6 verification · 2
⚠
Abilities
4 shown of 4Hunt for known suspicious files
Use hash of known suspicious file to find instances of said file on hosts
Show command
[{"platform": "windows", "executor": "psh", "command": "$paths = (Get-ChildItem #{file.search.directory} -Recurse -EA:SilentlyContinue | Get-FileHash -EA:SilentlyContinue |\nWhere-Object hash -eq #{file.malicious.hash} | foreach { $_.Path });\n$paths;\n"}]Search for Child Processes (elastic)
Search for Sysmon Event 1 records to discover children of known processes.
Show command
[{"platform": "windows", "executor": "elasticsearch", "command": "process.parent.entity_id:\\{#{investigate.process.guid}\\} AND winlog.event_id:1 AND winlog.provider_name:\"Microsoft-Windows-Sysmon\"\n"}, {"platform": "linux", "executor": "elasticsearch", "command": "process.parent.entity_id:\\{#{investigate.process.guid}\\} AND winlog.event_id:1 AND winlog.provider_name:\"Microsoft-Windows-Sysmon\"\n"}, {"platform": "darwin", "executor": "elasticsearch", "command": "process.parent.entity_id:\\{#{investigate.process.guid}\\} AND winlog.event_id:1 AND winlog.provider_name:\"Microsoft-Windows-Sysmon\"\n"}]Search for Parent Processes (elastic)
Search for Sysmon Event 1 records to discover parents of known processes.
Show command
[{"platform": "windows", "executor": "elasticsearch", "command": "process.entity_id:\\{#{investigate.process.parent_guid}\\} AND winlog.event_id:1 AND winlog.provider_name:\"Microsoft-Windows-Sysmon\"\n"}, {"platform": "linux", "executor": "elasticsearch", "command": "process.entity_id:\\{#{investigate.process.parent_guid}\\} AND winlog.event_id:1 AND winlog.provider_name:\"Microsoft-Windows-Sysmon\"\n"}, {"platform": "darwin", "executor": "elasticsearch", "command": "process.entity_id:\\{#{investigate.process.parent_guid}\\} AND winlog.event_id:1 AND winlog.provider_name:\"Microsoft-Windows-Sysmon\"\n"}]Search for PowerShell ExecutionPolicy Bypass (elastic)
Search for Sysmon Event 1 powershell records with "ExecutionPolicy" and "Bypass"
Show command
[{"platform": "windows", "executor": "elasticsearch", "command": "process.name:powershell.exe AND process.args:*Bypass* AND process.args:*ExecutionPolicy*\n"}, {"platform": "linux", "executor": "elasticsearch", "command": "process.name:powershell.exe AND process.args:*Bypass* AND process.args:*ExecutionPolicy*\n"}, {"platform": "darwin", "executor": "elasticsearch", "command": "process.name:powershell.exe AND process.args:*Bypass* AND process.args:*ExecutionPolicy*\n"}]Showing 1-4 of 4