cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ T1630 Indicator Removal On Host · cyberstrikeusAdversaries may delete, alter, or hide generated artifacts on a device, including files, jailbreak status, or the malicious application itself.
- ▌ T1418 001 Security Software Discovery · cyberstrikeusAdversaries may attempt to get a listing of security applications and configurations that are installed on a device.
- ▌ T1646 Exfiltration Over C2 Channel · cyberstrikeusAdversaries may steal data by exfiltrating it over an existing command and control channel.
- ▌ T1544 Ingress Tool Transfer · cyberstrikeusAdversaries may transfer tools or other files from an external system onto a compromised device to facilitate follow-on actions.
- ▌ T1190 Exploit Public Facing Application · cyberstrikeusAdversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
- ▌ T1027 005 Indicator Removal From Tools · cyberstrikeusAdversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed.
- ▌ T1211 Exploitation For Defense Evasion · cyberstrikeusAdversaries may exploit a system or application vulnerability to bypass security features.
- ▌ T1562 008 Disable Or Modify Cloud Logs · cyberstrikeusAn adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection.
- ▌ T1564 001 Hidden Files And Directories · cyberstrikeusAdversaries may set files and directories to be hidden to evade detection mechanisms.
- ▌ T1528 Steal Application Access Token · cyberstrikeusAdversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.
- ▌ T1555 004 Windows Credential Manager · cyberstrikeusAdversaries may acquire credentials from the Windows Credential Manager.
- ▌ T1021 008 Direct Cloud Vm Connections · cyberstrikeusAdversaries may leverage Valid Accounts to log directly into accessible cloud hosted compute infrastructure through cloud native methods.
- ▌ T1210 Exploitation Of Remote Services · cyberstrikeusAdversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.
- ▌ T1588 007 Artificial Intelligence · cyberstrikeusAdversaries may obtain access to generative artificial intelligence tools, such as large language models (LLMs), to aid various techniques during targeting.
- ▌ T1590 Gather Victim Network Information · cyberstrikeusAdversaries may gather information about the victim's networks that can be used during targeting.
- ▌ Ac 16 Security And Privacy Attributes · cyberstrikeusProvide the means to associate [organization-defined] with [organization-defined] for information in storage, in process, and/or in transmission;
- ▌ Ac 16 5 Attribute Displays On Objects To Be Output · cyberstrikeusDisplay security and privacy attributes in human-readable form on each object that the system transmits to output devices to identify [organization-de
- ▌ Ac 17 2 Protection Of Confidentiality And Integrity Using En · cyberstrikeusImplement cryptographic mechanisms to protect the confidentiality and integrity of remote access sessions.
- ▌ Ac 17 9 Disconnect Or Disable Access · cyberstrikeusProvide the capability to disconnect or disable remote access to the system within [organization-defined].
- ▌ Ac 24 1 Transmit Access Authorization Information · cyberstrikeusTransmit [organization-defined] using [organization-defined] to [organization-defined] that enforce access control decisions.
- ▌ Ac 3 5 Security Relevant Information · cyberstrikeusPrevent access to [organization-defined] except during secure, non-operable system states.
- ▌ Ac 4 29 Filter Orchestration Engines · cyberstrikeusWhen transferring information between different security domains, employ content filter orchestration engines to ensure that: Content filtering mechan
- ▌ Ac 6 10 Prohibit Non Privileged Users From Executing Privile · cyberstrikeusPrevent non-privileged users from executing privileged functions.
- ▌
- ▌
- ▌ Au 5 4 Shutdown On Failure · cyberstrikeusInvoke a [organization-defined] in the event of [organization-defined] , unless an alternate audit logging capability exists.
- ▌ Au 8 1 Synchronization With Authoritative Time Source · cyberstrikeusSynchronization with Authoritative Time Source
- ▌ Ca 7 4 Risk Monitoring · cyberstrikeusEnsure risk monitoring is an integral part of the continuous monitoring strategy that includes the following: Effectiveness monitoring; Compliance mon
- ▌ Cm 2 Baseline Configuration · cyberstrikeusDevelop, document, and maintain under configuration control, a current baseline configuration of the system;
- ▌
- ▌
- ▌ Cm 3 4 Security And Privacy Representatives · cyberstrikeusRequire [organization-defined] to be members of the [organization-defined].
- ▌ Cm 6 Configuration Settings · cyberstrikeusEstablish and document configuration settings for components employed within the system that reflect the most restrictive mode consistent with oper...
- ▌ Ir 4 1 Automated Incident Handling Processes · cyberstrikeusSupport the incident handling process using [organization-defined].
- ▌ Ir 4 10 Supply Chain Coordination · cyberstrikeusCoordinate incident handling activities involving supply chain events with other organizations involved in the supply chain.
- ▌ Ir 9 Information Spillage Response · cyberstrikeusRespond to information spills by: Assigning [organization-defined] with responsibility for responding to information spills; Identifying the specific
- ▌ Ma 2 2 Automated Maintenance Activities · cyberstrikeusSchedule, conduct, and document maintenance, repair, and replacement actions for the system using [organization-defined] ;
- ▌
- ▌ Mp 4 2 Automated Restricted Access · cyberstrikeusRestrict access to media storage areas and log access attempts and access granted using [organization-defined].
- ▌
- ▌ Mp 7 2 Prohibit Use Of Sanitization Resistant Media · cyberstrikeusProhibit the use of sanitization-resistant media in organizational systems.
- ▌ Pm 2 Information Security Program Leadership Role · cyberstrikeusAppoint a senior agency information security officer with the mission and resources to coordinate, develop, implement, and maintain an organization-wi
- ▌ Pm 8 Critical Infrastructure Plan · cyberstrikeusAddress information security and privacy issues in the development, documentation, and updating of a critical infrastructure and key resources protect
- ▌ Ra 3 1 Supply Chain Risk Assessment · cyberstrikeusAssess supply chain risks associated with [organization-defined] ;
- ▌ Sa 23 Specialization · cyberstrikeusEmploy [organization-defined] on [organization-defined] supporting mission essential services or functions to increase the trustworthiness in those sy
- ▌ Si 18 3 Collection · cyberstrikeusCollect personally identifiable information directly from the individual.
- ▌ Si 19 1 Collection · cyberstrikeusDe-identify the dataset upon collection by not collecting personally identifiable information.
- ▌ Sr 4 2 Track And Trace · cyberstrikeusEstablish and maintain unique identification of the following systems and critical system components for tracking through the supply chain: [organizat
- ▌ Sr 5 1 Adequate Supply · cyberstrikeusEmploy the following controls to ensure an adequate supply of [organization-defined]: [organization-defined].
- ▌ T0811 Data From Information Repositories · cyberstrikeusAdversaries may target and collect data from information repositories.
- ▌ T0835 Manipulate Io Image · cyberstrikeusAdversaries may manipulate the I/O image of PLCs through various means to prevent them from functioning as expected.
- ▌ T1630 003 Disguise Rootjailbreak Indicators · cyberstrikeusAn adversary could use knowledge of the techniques used by security software to evade detection.
- ▌ T1639 Exfiltration Over Alternative Protocol · cyberstrikeusAdversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
- ▌ T1481 001 Dead Drop Resolver · cyberstrikeusAdversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.
- ▌ T1663 Remote Access Software · cyberstrikeusAdversaries may use legitimate remote access software, such as `VNC`, `TeamViewer`, `AirDroid`, `AirMirror`, etc., to establish an interactive command and control channel to target mobile devices.
- ▌ T1546 004 Unix Shell Configuration Modification · cyberstrikeusAdversaries may establish persistence through executing malicious commands triggered by a user’s shell.
- ▌ T1548 005 Temporary Elevated Cloud Access · cyberstrikeusAdversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.
- ▌ T1055 002 Portable Executable Injection · cyberstrikeusAdversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1055 011 Extra Window Memory Injection · cyberstrikeusAdversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1127 Trusted Developer Utilities Proxy Execution · cyberstrikeusAdversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads.
- ▌ T1562 012 Disable Or Modify Linux Audit System · cyberstrikeusAdversaries may disable or modify the Linux audit system to hide malicious activity and avoid detection.
- ▌ T1562 002 Disable Windows Event Logging · cyberstrikeusAdversaries may disable Windows event logging to limit data that can be leveraged for detections and audits.
- ▌ T1552 005 Cloud Instance Metadata API · cyberstrikeusAdversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data.
- ▌ T1556 006 Multi Factor Authentication · cyberstrikeusAdversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
- ▌ T1556 009 Conditional Access Policies · cyberstrikeusAdversaries may disable or modify conditional access policies to enable persistent access to compromised accounts.
- ▌ T1558 Steal Or Forge Kerberos Tickets · cyberstrikeusAdversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket.
- ▌ T1021 003 Distributed Component Object Model · cyberstrikeusAdversaries may use Valid Accounts to interact with remote machines by taking advantage of Distributed Component Object Model (DCOM).
- ▌ T1563 Remote Service Session Hijacking · cyberstrikeusAdversaries may take control of preexisting sessions with remote services to move laterally in an environment.
- ▌ T1589 Gather Victim Identity Information · cyberstrikeusAdversaries may gather information about the victim's identity that can be used during targeting.
- ▌
- ▌ Device Lock 03 01 10 Device Lock · cyberstrikeusPrevent access to the system by [organization-defined].
- ▌
- ▌ Incident Response Plan 03 06 05 Incident Response Plan · cyberstrikeusDevelop an incident response plan that: Provides the organization with a roadmap for implementing its incident response capability, Describes the stru
- ▌ Ac 16 1 Dynamic Attribute Association · cyberstrikeusDynamically associate security and privacy attributes with [organization-defined] in accordance with the following security and privacy policies as in
- ▌ Ac 17 10 Authenticate Remote Commands · cyberstrikeusImplement [organization-defined] to authenticate [organization-defined].
- ▌ Ac 17 3 Managed Access Control Points · cyberstrikeusRoute remote accesses through authorized and managed network access control points.
- ▌ Ac 18 1 Authentication And Encryption · cyberstrikeusProtect wireless access to the system using authentication of [organization-defined] and encryption.
- ▌ Ac 19 5 Full Device Or Container Based Encryption · cyberstrikeusEmploy [organization-defined] to protect the confidentiality and integrity of information on [organization-defined].
- ▌ Ac 2 13 Disable Accounts For High Risk Individuals · cyberstrikeusDisable accounts of individuals within [organization-defined] of discovery of [organization-defined].
- ▌ Ac 3 1 Restricted Access To Privileged Functions · cyberstrikeusRestricted Access to Privileged Functions
- ▌ Ac 3 12 Assert And Enforce Application Access · cyberstrikeusRequire applications to assert, as part of the installation process, the access needed to the following system applications and functions: [organiz...
- ▌ Ac 4 10 Enable And Disable Security Or Privacy Policy Filter · cyberstrikeusProvide the capability for privileged administrators to enable and disable [organization-defined] under the following conditions: [organization-define
- ▌ Ac 4 21 Physical Or Logical Separation Of Information Flows · cyberstrikeusSeparate information flows logically or physically using [organization-defined] to accomplish [organization-defined].
- ▌ Ac 4 27 Redundantindependent Filtering Mechanisms · cyberstrikeusWhen transferring information between different security domains, implement content filtering solutions that provide redundant and independent filteri
- ▌ Ac 7 4 Use Of Alternate Authentication Factor · cyberstrikeusAllow the use of [organization-defined] that are different from the primary authentication factors after the number of organization-defined consecu...
- ▌ At 3 1 Environmental Controls · cyberstrikeusProvide [organization-defined] with initial and [organization-defined] training in the employment and operation of environmental controls.
- ▌ Au 11 Audit Record Retention · cyberstrikeusRetain audit records for [organization-defined] to provide support for after-the-fact investigations of incidents and to meet regulatory and organizat
- ▌
- ▌ Au 7 1 Automatic Processing · cyberstrikeusProvide and implement the capability to process, sort, and search audit records for events of interest based on the following content: [organization-d
- ▌ Ca 2 Control Assessments · cyberstrikeusSelect the appropriate assessor or assessment team for the type of assessment to be conducted;
- ▌ Ca 8 Penetration Testing · cyberstrikeusConduct penetration testing [organization-defined] on [organization-defined].
- ▌ Cm 2 3 Retention Of Previous Configurations · cyberstrikeusRetain [organization-defined] of previous versions of baseline configurations of the system to support rollback.
- ▌ Cp 2 8 Identify Critical Assets · cyberstrikeusIdentify critical system assets supporting [organization-defined] mission and business functions.
- ▌ Cp 8 Telecommunications Services · cyberstrikeusEstablish alternate telecommunications services, including necessary agreements to permit the resumption of [organization-defined] for essential missi
- ▌ Cp 8 3 Separation Of Primary And Alternate Providers · cyberstrikeusObtain alternate telecommunications services from providers that are separated from primary service providers to reduce susceptibility to the same thr
- ▌ Cp 8 2 Single Points Of Failure · cyberstrikeusObtain alternate telecommunications services to reduce the likelihood of sharing a single point of failure with primary telecommunications services.
- ▌ Cp 9 8 Cryptographic Protection · cyberstrikeusImplement cryptographic mechanisms to prevent unauthorized disclosure and modification of [organization-defined].
- ▌ Ir 4 12 Malicious Code And Forensic Analysis · cyberstrikeusAnalyze malicious code and/or other residual artifacts remaining in the system after the incident.
- ▌ Ir 4 14 Security Operations Center · cyberstrikeusEstablish and maintain a security operations center.
- ▌ Ir 4 9 Dynamic Response Capability · cyberstrikeusEmploy [organization-defined] to respond to incidents.