Skip to content

Version 0.6.0

Choose a tag to compare

@andrewbwm andrewbwm released this 06 Jul 16:04
· 69 commits to master since this release

This new version of coreLang comes with the following changes:

  • Introduce more bypasses of defences:
    • Add bypasses for the SupplyChainAudit and HardwareModificationsProtection defences on the Hardware asset.
    • Add bypasses for the Effectiveness defence on the IDPS asset.
    • Add bypasses for the SupplyChainAudit defence on the Application asset.
    • Add bypasses for the SecurityAwareness defence on the User asset.
    • Add bypasses for the Restricted and PayloadInspection defences on the ConnectionRule asset.
    • Rework some of the existing bypass attack steps on the Network asset.
  • Rework IAMObject abstract asset to extend the Information asset.
    • Add attack steps to represent the impacts of an attacker manipulating the access control privileges defined by the IAMObject assets.
    • This was implemented as part of the conversation regarding how the IAMObject subassets(Identity, Group, and Privileges) can be used to represent directory/domain policy entries in the a directory/domain policy service.
    • Move the Subprivileges association to the IAMObject from the Group and Identity assets, this way the behaviour is homogeneous and Privileges can form hierarchies too.
  • Rework Deny and Write on Credentials.
    • Have Write on Credentials lead to Assume as the logic is that the credentials are overwritten for the authentication mechanism, and not simply a file containing credentials.
    • Have Deny on Credentials lead to Lockout on the associated Identity if all of the Credentials assets that are associated have been denied.
  • Lockout a Group if all of its member Identities have suffered a Lockout.
  • Assume by default that Credentials are weak if the Identity asset is not connected or User asset is not connected to the Identity associated with the Credentials.
  • Rename some of the social engineering attack steps on the Application asset for more clarity.
  • Bypass IDPS on Deny as well, not only on FullAccess.
  • Minor fixes, improvements and typo corrections.