-
Notifications
You must be signed in to change notification settings - Fork 83
Open
Description
Hey there,
I'm currently integrating CALDERA (including this plugin) into another framework I'm working on, which basically simulates a small company network. Everything works out so far, but one question remains: What causes some abilities to be skipped every single time? I ran 20 separate simulations and in every single one of them the following abilities (from APT29) didn't execute:
- 1.B - PowerShell
- 8.B - Copy Sandcat File
- 18.A - Exfiltrate data to OneDrive
- 20.A.1 - Execute Invoke-Mimikatz
It's not directly a problem that these don't run, but I need to know for sure why that happens, I can't just guess it. Can you point me to any resource where I could find more information? The CALDERA docs sadly were of no help, neither are the respective ability files. Am I overlooking something?
Metadata
Metadata
Assignees
Labels
No labels