Repository navigation
Version 0.6.0
This new version of coreLang comes with the following changes:
- Introduce more bypasses of defences:
- Add bypasses for the
SupplyChainAuditandHardwareModificationsProtectiondefences on theHardwareasset. - Add bypasses for the
Effectivenessdefence on theIDPSasset. - Add bypasses for the
SupplyChainAuditdefence on theApplicationasset. - Add bypasses for the
SecurityAwarenessdefence on theUserasset. - Add bypasses for the
RestrictedandPayloadInspectiondefences on theConnectionRuleasset. - Rework some of the existing bypass attack steps on the
Networkasset.
- Add bypasses for the
- Rework
IAMObjectabstract asset to extend theInformationasset.- Add attack steps to represent the impacts of an attacker manipulating the access control privileges defined by the
IAMObjectassets. - This was implemented as part of the conversation regarding how the
IAMObjectsubassets(Identity,Group, andPrivileges) can be used to represent directory/domain policy entries in the a directory/domain policy service. - Move the
Subprivilegesassociation to theIAMObjectfrom theGroupandIdentityassets, this way the behaviour is homogeneous andPrivilegescan form hierarchies too.
- Add attack steps to represent the impacts of an attacker manipulating the access control privileges defined by the
- Rework
DenyandWriteonCredentials.- Have
WriteonCredentialslead toAssumeas the logic is that the credentials are overwritten for the authentication mechanism, and not simply a file containing credentials. - Have
DenyonCredentialslead toLockouton the associatedIdentityif all of theCredentialsassets that are associated have been denied.
- Have
LockoutaGroupif all of its memberIdentitieshave suffered aLockout.- Assume by default that
Credentialsare weak if theIdentityasset is not connected orUserasset is not connected to theIdentityassociated with theCredentials. - Rename some of the social engineering attack steps on the
Applicationasset for more clarity. - Bypass
IDPSonDenyas well, not only onFullAccess. - Minor fixes, improvements and typo corrections.