From 19fcf8d053bc0e989842a747ff76efd133f4af51 Mon Sep 17 00:00:00 2001 From: Ilija Lazoroski Date: Wed, 5 Oct 2022 11:30:09 +0200 Subject: [PATCH] Agent: Import attack technique tags from common in MimikatzCollector --- .../mimikatz_collector/mimikatz_credential_collector.py | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/monkey/infection_monkey/credential_collectors/mimikatz_collector/mimikatz_credential_collector.py b/monkey/infection_monkey/credential_collectors/mimikatz_collector/mimikatz_credential_collector.py index b4bf4135e..b2e3217b3 100644 --- a/monkey/infection_monkey/credential_collectors/mimikatz_collector/mimikatz_credential_collector.py +++ b/monkey/infection_monkey/credential_collectors/mimikatz_collector/mimikatz_credential_collector.py @@ -4,6 +4,7 @@ from typing import Sequence from common.agent_events import CredentialsStolenEvent from common.credentials import Credentials, LMHash, NTHash, Password, Username from common.event_queue import IAgentEventQueue +from common.tags import T1003_ATTACK_TECHNIQUE_TAG, T1005_ATTACK_TECHNIQUE_TAG from infection_monkey.i_puppet import ICredentialCollector from infection_monkey.model import USERNAME_PREFIX from infection_monkey.utils.ids import get_agent_id @@ -15,8 +16,6 @@ logger = logging.getLogger(__name__) MIMIKATZ_CREDENTIAL_COLLECTOR_TAG = "mimikatz-credentials-collector" -T1003_ATTACK_TECHNIQUE_TAG = "attack-t1003" -T1005_ATTACK_TECHNIQUE_TAG = "attack-t1005" MIMIKATZ_EVENT_TAGS = frozenset( (