-
Notifications
You must be signed in to change notification settings - Fork 1.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Can not create new adversaries and import APT29 adversary #2733
Comments
Looks like your first issue -- we aim to respond to issues as quickly as possible. In the meantime, check out our documentation here: http://caldera.readthedocs.io/ |
Hi, unfortunately I cannot help you with this problem. For me, importing the APT29 adversary worked using a non-docker environment. Since I have no experience using CALDERA with docker I cannot tell if the error comes from docker or not. But, I have some information regarding the attack-arsenal/adversary-emulation-library and APT29 that might be interesting for you as well. The attack-arsenal repo that you linked was moved to the adversary emulation library. You can find a note in the attack-arsenal repo as well ( Another but: If you then intent to use the new adversary emulation library with the emu-plugin instead of the old evals-plugin, you will probably find that the generated APT29 adversary profile is faulty. More information on that can be seen in my pull request. Using the APT29 adversary emulation plan I also did not get the operation to work as expected - but I am still investigating this and it should not be a problem for you right now since you have other problems to fix first as it seems. |
Hello. I tried to run CALDERA with non-docker option and configured the evals plugin but It still did not import adversary profiles automatically. I also tried your modification of emulation plan by importing .yaml file. It threw an error as the Fig.3.
|
When using the new emulation plans you no longer need the evals plugin - instead you enable the emu plugin. It automatically generates adversary profiles, abilities, etc from the given YAML adversary emulation plan and puts them into plugins/emu/data/adversaries, plugins/emu/data/abilities, etc. Some questions that might help finding the problem here:
|
Thank you so much! I have just run successfully with emu plugin! |
I have just installed CALDERA version 4.1.0 using Docker environment. I followed this repo and config caldera to import APT29 adversary.
I am struggling with some obstacles, please help me overcome these. Thanks so muck!
`id: 3af0e59b-0d2a-48cd-b934-c46d5d1621d6
name: ATT&CK Eval APT3 - 5.B-8.A
description: Access Token Manipulation, Discovery for Lateral Movement, Persistence, and Discovery for Collection
visible: 1
phases:
1:
Figure 2
Figure 3
*Figure 4
** Figure 5 **
Figure 6
The text was updated successfully, but these errors were encountered: