WELCOME
 

Welcome to this month's edition of the Atomic Newsletter, a monthly email with updates and news about Atomic Red Team™ and its related projects such as MITRE ATT&CK®, Invoke-AtomicRedTeam, AtomicTestHarnesses, and more. Visit our website and join the community chat with us on Slack!

 
 
The latest from Atomic Red Team
 
 
 
post-thumbnail
 
The Threat Detection Report…now in Sigma!
 

For the second year in a row, Micah Babinski graciously translated the many detection opportunities in Red Canary’s Threat Detection Report to Sigma format.

 
post-thumbnail
 
Purple March Madness recap
 

You can find every episode of Atomics on a Friday’s series on how various red, blue, and purple team tools stack up against each other in this X thread.

 
Meet Freyja
 

This new Mythic agent from Antonio Piazza allows you to run atomic tests as part of larger purple team campaigns.

 
...and meet EDI
 

Compiled by members of Inovasys’s blue team, this emulation, detection, and intelligence (EDI, pronounced “Eddy”) repository includes Sigma files, atomic tests, and sample log files for various ATT&CK techniques.

 
NEW TESTS
 
 
 
SOAPHOUND build cache and BloodHound dump
 

Maintainer Mike Haag recently added an atomic test for SOAPHOUND, a tool for enumerating Active Directory environments.

 
T1137.001 - Office Application Startup: Office Template Macros
 

Daniel Cortez wrote a blog post detailing how he conceived and formatted a new atomic test for changes to Microsoft Office templates that automatically load when the application opens.

 
CONTRIBUTOR SUPPORT
 
 

Top contributors

  • TrentonTait
  • chandangupta1997
  • ohadm-cynet
  • prashanthpulisetti
  • ZitniH
  • pratinavchandra
  • Badoodish
  • NagaSivaGunturu
  • clr2of81
  • jandress

New contributors

  • pyth0n1c
  • pratinavchandra
  • TrentonTait
  • ohadm-cynet
  • NagaSivaGunturu
  • HyperionRising12
  • chandangupta1997
  • W00glin
  • Badoodish
  • raghavsingh7
 
 
Say hi at RSA!
 

Join Red Canary’s Brian Donohue and former Atomic Red Team maintainer Adam Mashinchi as they present “The ART of Probable: Test with AI, Atomic Red Team, and Threat Metrics” on Thursday, May 9 at this year’s RSA conference.

 
SEE YOU THERE
 
 
  Twitter   LinkedIn   GitHub   YouTube   Slack