← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 46 of 72

  1. T1630 Indicator Removal On Host · cyberstrikeus
    Adversaries may delete, alter, or hide generated artifacts on a device, including files, jailbreak status, or the malicious application itself.
    0 installs
  2. T1418 001 Security Software Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of security applications and configurations that are installed on a device.
    0 installs
  3. T1646 Exfiltration Over C2 Channel · cyberstrikeus
    Adversaries may steal data by exfiltrating it over an existing command and control channel.
    0 installs
  4. T1544 Ingress Tool Transfer · cyberstrikeus
    Adversaries may transfer tools or other files from an external system onto a compromised device to facilitate follow-on actions.
    0 installs
  5. T1190 Exploit Public Facing Application · cyberstrikeus
    Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
    0 installs
  6. T1027 005 Indicator Removal From Tools · cyberstrikeus
    Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed.
    0 installs
  7. T1211 Exploitation For Defense Evasion · cyberstrikeus
    Adversaries may exploit a system or application vulnerability to bypass security features.
    0 installs
  8. T1562 008 Disable Or Modify Cloud Logs · cyberstrikeus
    An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection.
    0 installs
  9. T1564 001 Hidden Files And Directories · cyberstrikeus
    Adversaries may set files and directories to be hidden to evade detection mechanisms.
    0 installs
  10. T1528 Steal Application Access Token · cyberstrikeus
    Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
    0 installs
  11. T1555 004 Windows Credential Manager · cyberstrikeus
    Adversaries may acquire credentials from the Windows Credential Manager.
    0 installs
  12. T1021 008 Direct Cloud Vm Connections · cyberstrikeus
    Adversaries may leverage Valid Accounts to log directly into accessible cloud hosted compute infrastructure through cloud native methods.
    0 installs
  13. T1210 Exploitation Of Remote Services · cyberstrikeus
    Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
    0 installs
  14. T1588 007 Artificial Intelligence · cyberstrikeus
    Adversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting.
    0 installs
  15. T1590 Gather Victim Network Information · cyberstrikeus
    Adversaries may gather information about the victim's networks that can be used during targeting.
    0 installs
  16. Ac 16 Security And Privacy Attributes · cyberstrikeus
    Provide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission;
    0 installs
  17. Ac 16 5 Attribute Displays On Objects To Be Output · cyberstrikeus
    Display security and privacy attributes in human-readable form on each object that the system transmits to output devices to identify [organization-de
    0 installs
  18. Ac 17 2 Protection Of Confidentiality And Integrity Using En · cyberstrikeus
    Implement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.
    0 installs
  19. Ac 17 9 Disconnect Or Disable Access · cyberstrikeus
    Provide the capability to disconnect or disable remote access to the system within [organization-defined].
    0 installs
  20. Ac 24 1 Transmit Access Authorization Information · cyberstrikeus
    Transmit [organization-defined] using [organization-defined] to [organization-defined] that enforce access control decisions.
    0 installs
  21. Ac 3 5 Security Relevant Information · cyberstrikeus
    Prevent access to [organization-defined] except during secure, non-operable system states.
    0 installs
  22. Ac 4 29 Filter Orchestration Engines · cyberstrikeus
    When transferring information between different security domains, employ content filter orchestration engines to ensure that: Content filtering mechan
    0 installs
  23. Ac 6 10 Prohibit Non Privileged Users From Executing Privile · cyberstrikeus
    Prevent non-privileged users from executing privileged functions.
    0 installs
  24. Au 10 5 Digital Signatures · cyberstrikeus
    Digital Signatures
    0 installs
  25. Au 2 3 Reviews And Updates · cyberstrikeus
    Reviews and Updates
    0 installs
  26. Au 5 4 Shutdown On Failure · cyberstrikeus
    Invoke a [organization-defined] in the event of [organization-defined] , unless an alternate audit logging capability exists.
    0 installs
  27. Au 8 1 Synchronization With Authoritative Time Source · cyberstrikeus
    Synchronization with Authoritative Time Source
    0 installs
  28. Ca 7 4 Risk Monitoring · cyberstrikeus
    Ensure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: Effectiveness monitoring; Compliance mon
    0 installs
  29. Cm 2 Baseline Configuration · cyberstrikeus
    Develop, document, and maintain under configuration control, a current baseline configuration of the system;
    0 installs
  30. Cm 2 1 Reviews And Updates · cyberstrikeus
    Reviews and Updates
    0 installs
  31. Cm 2 5 Authorized Software · cyberstrikeus
    Authorized Software
    0 installs
  32. Cm 3 4 Security And Privacy Representatives · cyberstrikeus
    Require [organization-defined] to be members of the [organization-defined].
    0 installs
  33. Cm 6 Configuration Settings · cyberstrikeus
    Establish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with oper...
    0 installs
  34. Ir 4 1 Automated Incident Handling Processes · cyberstrikeus
    Support the incident handling process using [organization-defined].
    0 installs
  35. Ir 4 10 Supply Chain Coordination · cyberstrikeus
    Coordinate incident handling activities involving supply chain events with other organizations involved in the supply chain.
    0 installs
  36. Ir 9 Information Spillage Response · cyberstrikeus
    Respond to information spills by: Assigning [organization-defined] with responsibility for responding to information spills; Identifying the specific
    0 installs
  37. Ma 2 2 Automated Maintenance Activities · cyberstrikeus
    Schedule, conduct, and document maintenance, repair, and replacement actions for the system using [organization-defined] ;
    0 installs
  38. Mp 2 1 Automated Restricted Access · cyberstrikeus
    Automated Restricted Access
    0 installs
  39. Mp 4 2 Automated Restricted Access · cyberstrikeus
    Restrict access to media storage areas and log access attempts and access granted using [organization-defined].
    0 installs
  40. Mp 5 2 Documentation Of Activities · cyberstrikeus
    Documentation of Activities
    0 installs
  41. Mp 7 2 Prohibit Use Of Sanitization Resistant Media · cyberstrikeus
    Prohibit the use of sanitization-resistant media in organizational systems.
    0 installs
  42. Pm 2 Information Security Program Leadership Role · cyberstrikeus
    Appoint a senior agency information security officer with the mission and resources to coordinate, develop, implement, and maintain an organization-wi
    0 installs
  43. Pm 8 Critical Infrastructure Plan · cyberstrikeus
    Address information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protect
    0 installs
  44. Ra 3 1 Supply Chain Risk Assessment · cyberstrikeus
    Assess supply chain risks associated with [organization-defined] ;
    0 installs
  45. Sa 23 Specialization · cyberstrikeus
    Employ [organization-defined] on [organization-defined] supporting mission essential services or functions to increase the trustworthiness in those sy
    0 installs
  46. Si 18 3 Collection · cyberstrikeus
    Collect personally identifiable information directly from the individual.
    0 installs
  47. Si 19 1 Collection · cyberstrikeus
    De-identify the dataset upon collection by not collecting personally identifiable information.
    0 installs
  48. Sr 4 2 Track And Trace · cyberstrikeus
    Establish and maintain unique identification of the following systems and critical system components for tracking through the supply chain: [organizat
    0 installs
  49. Sr 5 1 Adequate Supply · cyberstrikeus
    Employ the following controls to ensure an adequate supply of [organization-defined]: [organization-defined].
    0 installs
  50. T0811 Data From Information Repositories · cyberstrikeus
    Adversaries may target and collect data from information repositories.
    0 installs
  51. T0835 Manipulate Io Image · cyberstrikeus
    Adversaries may manipulate the I/O image of PLCs through various means to prevent them from functioning as expected.
    0 installs
  52. T1630 003 Disguise Rootjailbreak Indicators · cyberstrikeus
    An adversary could use knowledge of the techniques used by security software to evade detection.
    0 installs
  53. T1639 Exfiltration Over Alternative Protocol · cyberstrikeus
    Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
    0 installs
  54. T1481 001 Dead Drop Resolver · cyberstrikeus
    Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.
    0 installs
  55. T1663 Remote Access Software · cyberstrikeus
    Adversaries may use legitimate remote access software, such as `VNC`, `TeamViewer`, `AirDroid`, `AirMirror`, etc., to establish an interactive command and control channel to target mobile devices.
    0 installs
  56. T1546 004 Unix Shell Configuration Modification · cyberstrikeus
    Adversaries may establish persistence through executing malicious commands triggered by a user’s shell.
    0 installs
  57. T1548 005 Temporary Elevated Cloud Access · cyberstrikeus
    Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.
    0 installs
  58. T1055 002 Portable Executable Injection · cyberstrikeus
    Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges.
    0 installs
  59. T1055 011 Extra Window Memory Injection · cyberstrikeus
    Adversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as possibly elevate privileges.
    0 installs
  60. T1127 Trusted Developer Utilities Proxy Execution · cyberstrikeus
    Adversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads.
    0 installs
  61. T1562 012 Disable Or Modify Linux Audit System · cyberstrikeus
    Adversaries may disable or modify the Linux audit system to hide malicious activity and avoid detection.
    0 installs
  62. T1562 002 Disable Windows Event Logging · cyberstrikeus
    Adversaries may disable Windows event logging to limit data that can be leveraged for detections and audits.
    0 installs
  63. T1552 005 Cloud Instance Metadata API · cyberstrikeus
    Adversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data.
    0 installs
  64. T1556 006 Multi Factor Authentication · cyberstrikeus
    Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
    0 installs
  65. T1556 009 Conditional Access Policies · cyberstrikeus
    Adversaries may disable or modify conditional access policies to enable persistent access to compromised accounts.
    0 installs
  66. T1558 Steal Or Forge Kerberos Tickets · cyberstrikeus
    Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket.
    0 installs
  67. T1021 003 Distributed Component Object Model · cyberstrikeus
    Adversaries may use Valid Accounts to interact with remote machines by taking advantage of Distributed Component Object Model (DCOM).
    0 installs
  68. T1563 Remote Service Session Hijacking · cyberstrikeus
    Adversaries may take control of preexisting sessions with remote services to move laterally in an environment.
    0 installs
  69. T1589 Gather Victim Identity Information · cyberstrikeus
    Adversaries may gather information about the victim's identity that can be used during targeting.
    0 installs
  70. Access Enforcement 03 01 02 Access Enforcement · cyberstrikeus
    Access Enforcement
    0 installs
  71. Device Lock 03 01 10 Device Lock · cyberstrikeus
    Prevent access to the system by [organization-defined].
    0 installs
  72. Sp 800 171 03 02 03 030203 · cyberstrikeus
    03.02.03
    0 installs
  73. Incident Response Plan 03 06 05 Incident Response Plan · cyberstrikeus
    Develop an incident response plan that: Provides the organization with a roadmap for implementing its incident response capability, Describes the stru
    0 installs
  74. Ac 16 1 Dynamic Attribute Association · cyberstrikeus
    Dynamically associate security and privacy attributes with [organization-defined] in accordance with the following security and privacy policies as in
    0 installs
  75. Ac 17 10 Authenticate Remote Commands · cyberstrikeus
    Implement [organization-defined] to authenticate [organization-defined].
    0 installs
  76. Ac 17 3 Managed Access Control Points · cyberstrikeus
    Route remote accesses through authorized and managed network access control points.
    0 installs
  77. Ac 18 1 Authentication And Encryption · cyberstrikeus
    Protect wireless access to the system using authentication of [organization-defined] and encryption.
    0 installs
  78. Ac 19 5 Full Device Or Container Based Encryption · cyberstrikeus
    Employ [organization-defined] to protect the confidentiality and integrity of information on [organization-defined].
    0 installs
  79. Ac 2 13 Disable Accounts For High Risk Individuals · cyberstrikeus
    Disable accounts of individuals within [organization-defined] of discovery of [organization-defined].
    0 installs
  80. Ac 3 1 Restricted Access To Privileged Functions · cyberstrikeus
    Restricted Access to Privileged Functions
    0 installs
  81. Ac 3 12 Assert And Enforce Application Access · cyberstrikeus
    Require applications to assert, as part of the installation process, the access needed to the following system applications and functions: [organiz...
    0 installs
  82. Ac 4 10 Enable And Disable Security Or Privacy Policy Filter · cyberstrikeus
    Provide the capability for privileged administrators to enable and disable [organization-defined] under the following conditions: [organization-define
    0 installs
  83. Ac 4 21 Physical Or Logical Separation Of Information Flows · cyberstrikeus
    Separate information flows logically or physically using [organization-defined] to accomplish [organization-defined].
    0 installs
  84. Ac 4 27 Redundantindependent Filtering Mechanisms · cyberstrikeus
    When transferring information between different security domains, implement content filtering solutions that provide redundant and independent filteri
    0 installs
  85. Ac 7 4 Use Of Alternate Authentication Factor · cyberstrikeus
    Allow the use of [organization-defined] that are different from the primary authentication factors after the number of organization-defined consecu...
    0 installs
  86. At 3 1 Environmental Controls · cyberstrikeus
    Provide [organization-defined] with initial and [organization-defined] training in the employment and operation of environmental controls.
    0 installs
  87. Au 11 Audit Record Retention · cyberstrikeus
    Retain audit records for [organization-defined] to provide support for after-the-fact investigations of incidents and to meet regulatory and organizat
    0 installs
  88. Au 2 4 Privileged Functions · cyberstrikeus
    Privileged Functions
    0 installs
  89. Au 7 1 Automatic Processing · cyberstrikeus
    Provide and implement the capability to process, sort, and search audit records for events of interest based on the following content: [organization-d
    0 installs
  90. Ca 2 Control Assessments · cyberstrikeus
    Select the appropriate assessor or assessment team for the type of assessment to be conducted;
    0 installs
  91. Ca 8 Penetration Testing · cyberstrikeus
    Conduct penetration testing [organization-defined] on [organization-defined].
    0 installs
  92. Cm 2 3 Retention Of Previous Configurations · cyberstrikeus
    Retain [organization-defined] of previous versions of baseline configurations of the system to support rollback.
    0 installs
  93. Cp 2 8 Identify Critical Assets · cyberstrikeus
    Identify critical system assets supporting [organization-defined] mission and business functions.
    0 installs
  94. Cp 8 Telecommunications Services · cyberstrikeus
    Establish alternate telecommunications services, including necessary agreements to permit the resumption of [organization-defined] for essential missi
    0 installs
  95. Cp 8 3 Separation Of Primary And Alternate Providers · cyberstrikeus
    Obtain alternate telecommunications services from providers that are separated from primary service providers to reduce susceptibility to the same thr
    0 installs
  96. Cp 8 2 Single Points Of Failure · cyberstrikeus
    Obtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services.
    0 installs
  97. Cp 9 8 Cryptographic Protection · cyberstrikeus
    Implement cryptographic mechanisms to prevent unauthorized disclosure and modification of [organization-defined].
    0 installs
  98. Ir 4 12 Malicious Code And Forensic Analysis · cyberstrikeus
    Analyze malicious code and/or other residual artifacts remaining in the system after the incident.
    0 installs
  99. Ir 4 14 Security Operations Center · cyberstrikeus
    Establish and maintain a security operations center.
    0 installs
  100. Ir 4 9 Dynamic Response Capability · cyberstrikeus
    Employ [organization-defined] to respond to incidents.
    0 installs