← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 54 of 72

  1. T1059 007 Javascript · cyberstrikeus
    Adversaries may abuse various implementations of JavaScript for execution.
    0 installs
  2. T1129 Shared Modules · cyberstrikeus
    Adversaries may execute malicious payloads via loading shared modules.
    0 installs
  3. T1204 User Execution · cyberstrikeus
    An adversary may rely upon specific actions by a user in order to gain execution.
    0 installs
  4. T1012 Query Registry · cyberstrikeus
    Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
    0 installs
  5. T1021 004 Ssh · cyberstrikeus
    Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH).
    0 installs
  6. T1021 005 Vnc · cyberstrikeus
    Adversaries may use Valid Accounts to remotely control machines using Virtual Network Computing (VNC).
    0 installs
  7. T1056 Input Capture · cyberstrikeus
    Adversaries may use methods of capturing user input to obtain credentials or collect information.
    0 installs
  8. T1123 Audio Capture · cyberstrikeus
    An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listen...
    0 installs
  9. T1125 Video Capture · cyberstrikeus
    An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering ...
    0 installs
  10. T1213 006 Databases · cyberstrikeus
    Adversaries may leverage databases to mine valuable information.
    0 installs
  11. T1565 Data Manipulation · cyberstrikeus
    Adversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data.
    0 installs
  12. T1596 002 Whois · cyberstrikeus
    Adversaries may search public WHOIS data for information about victims that can be used during targeting.
    0 installs
  13. T0815 Denial Of View · cyberstrikeus
    Adversaries may cause a denial of view in attempt to disrupt and prevent operator oversight on the status of an ICS environment.
    0 installs
  14. T0880 Loss Of Safety · cyberstrikeus
    Adversaries may compromise safety system functions designed to maintain safe operation of a process when unacceptable or dangerous conditions occur.
    0 installs
  15. T1582 Sms Control · cyberstrikeus
    Adversaries may delete, alter, or send SMS messages without user authorization.
    0 installs
  16. T1059 002 Applescript · cyberstrikeus
    Adversaries may abuse AppleScript for execution.
    0 installs
  17. T1569 System Services · cyberstrikeus
    Adversaries may abuse system services or daemons to execute commands or programs.
    0 installs
  18. T1674 Input Injection · cyberstrikeus
    Adversaries may simulate keystrokes on a victim’s computer by various means to perform any type of action on behalf of the user, such as launching the command interpreter using keyboard shortcuts, ...
    0 installs
  19. T1505 003 Web Shell · cyberstrikeus
    Adversaries may backdoor web servers with web shells to establish persistent access to systems.
    0 installs
  20. T1197 Bits Jobs · cyberstrikeus
    Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks.
    0 installs
  21. T1218 003 Cmstp · cyberstrikeus
    Adversaries may abuse CMSTP to proxy execution of malicious code.
    0 installs
  22. T1218 005 Mshta · cyberstrikeus
    Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility.
    0 installs
  23. T1654 Log Enumeration · cyberstrikeus
    Adversaries may enumerate system and service logs to find useful data.
    0 installs
  24. T1056 001 Keylogging · cyberstrikeus
    Adversaries may log user keystrokes to intercept credentials as the user types them.
    0 installs
  25. T1113 Screen Capture · cyberstrikeus
    Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation.
    0 installs
  26. T1115 Clipboard Data · cyberstrikeus
    Adversaries may collect data stored in the clipboard from users copying information within or between applications.
    0 installs
  27. T1213 001 Confluence · cyberstrikeus
    Adversaries may leverage Confluence repositories to mine valuable information.
    0 installs
  28. T1213 002 Sharepoint · cyberstrikeus
    Adversaries may leverage the SharePoint repository as a source to mine valuable information.
    0 installs
  29. T1090 Proxy · cyberstrikeus
    Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to ...
    0 installs
  30. T1496 Resource Hijacking · cyberstrikeus
    Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
    0 installs
  31. Oversight Gv Ov Oversight · cyberstrikeus
    Results of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management stra
    0 installs
  32. Ps 1 1 Ps11 · cyberstrikeus
    Store all forms of code – including source code, executable code, and configuration-as-code – based on the principle of least privilege so that onl...
    0 installs
  33. Ps 2 1 Ps21 · cyberstrikeus
    Make software integrity verification information available to software acquirers.
    0 installs
  34. Ps 3 1 Ps31 · cyberstrikeus
    Securely archive the necessary files and supporting data (e.g., integrity verification information, provenance data) to be retained for each software
    0 installs
  35. Ps 3 2 Ps32 · cyberstrikeus
    Collect, safeguard, maintain, and share provenance data for all components of each software release (e.g., in a software bill of materials .SBOM).
    0 installs
  36. T0827 Loss Of Control · cyberstrikeus
    Adversaries may seek to achieve a sustained loss of control or a runaway condition in which operators cannot issue any commands even if the malicious interference has subsided.
    0 installs
  37. T1059 005 Visual Basic · cyberstrikeus
    Adversaries may abuse Visual Basic (VB) for execution.
    0 installs
  38. T1559 003 Xpc Services · cyberstrikeus
    Adversaries can provide malicious content to an XPC service daemon for local code execution.
    0 installs
  39. T1037 002 Login Hook · cyberstrikeus
    Adversaries may use a Login Hook to establish persistence executed upon user logon.
    0 installs
  40. T1037 004 Rc Scripts · cyberstrikeus
    Adversaries may establish persistence by modifying RC scripts, which are executed during a Unix-like system’s startup.
    0 installs
  41. T1136 Create Account · cyberstrikeus
    Adversaries may create an account to maintain access to victim systems.
    0 installs
  42. T1546 017 Udev Rules · cyberstrikeus
    Adversaries may maintain persistence through executing malicious content triggered using udev rules.
    0 installs
  43. T1653 Power Settings · cyberstrikeus
    Adversaries may impair a system's ability to hibernate, reboot, or shut down in order to extend access to infected machines.
    0 installs
  44. T1216 001 Pubprn · cyberstrikeus
    Adversaries may use PubPrn to proxy execution of malicious remote files.
    0 installs
  45. T1003 003 Ntds · cyberstrikeus
    Adversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as...
    0 installs
  46. T1069 001 Local Groups · cyberstrikeus
    Adversaries may attempt to find local system groups and permission settings.
    0 installs
  47. T1069 003 Cloud Groups · cyberstrikeus
    Adversaries may attempt to find cloud groups and permission settings.
    0 installs
  48. T1495 Firmware Corruption · cyberstrikeus
    Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying th...
    0 installs
  49. Organizational Context Gv Oc Organizational Context · cyberstrikeus
    The circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organizatio
    0 installs
  50. T0895 Autorun Image · cyberstrikeus
    Adversaries may leverage AutoRun functionality or scripts to execute malicious code.
    0 installs
  51. T1053 Scheduled Taskjob · cyberstrikeus
    Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
    0 installs
  52. T1137 002 Office Test · cyberstrikeus
    Adversaries may abuse the Microsoft Office "Office Test" Registry key to obtain persistence on a compromised system.
    0 installs
  53. T1547 015 Login Items · cyberstrikeus
    Adversaries may add login items to execute upon user login to gain persistence or escalate privileges.
    0 installs
  54. T1574 012 Corprofiler · cyberstrikeus
    Adversaries may leverage the COR_PROFILER environment variable to hijack the execution flow of programs that load the .NET CLR.
    0 installs
  55. T1127 001 Msbuild · cyberstrikeus
    Adversaries may use MSBuild to proxy execution of code through a trusted Windows utility.
    0 installs
  56. T1127 003 Jamplus · cyberstrikeus
    Adversaries may use `JamPlus` to proxy the execution of a malicious script.
    0 installs
  57. T1218 007 Msiexec · cyberstrikeus
    Adversaries may abuse msiexec.exe to proxy execution of malicious payloads.
    0 installs
  58. T1542 Pre Os Boot · cyberstrikeus
    Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system.
    0 installs
  59. T1057 Process Discovery · cyberstrikeus
    Adversaries may attempt to get information about running processes on a system.
    0 installs
  60. T1069 002 Domain Groups · cyberstrikeus
    Adversaries may attempt to find domain-level groups and permission settings.
    0 installs
  61. T1087 Account Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment.
    0 installs
  62. T1087 001 Local Account · cyberstrikeus
    Adversaries may attempt to get a listing of local system accounts.
    0 installs
  63. T1087 003 Email Account · cyberstrikeus
    Adversaries may attempt to get a listing of email addresses and accounts.
    0 installs
  64. T1087 004 Cloud Account · cyberstrikeus
    Adversaries may attempt to get a listing of cloud accounts.
    0 installs
  65. T1114 Email Collection · cyberstrikeus
    Adversaries may target user email to collect sensitive information.
    0 installs
  66. T1071 004 Dns · cyberstrikeus
    Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic.
    0 installs
  67. T1592 001 Hardware · cyberstrikeus
    Adversaries may gather information about the victim's host hardware that can be used during targeting.
    0 installs
  68. T1592 002 Software · cyberstrikeus
    Adversaries may gather information about the victim's host software that can be used during targeting.
    0 installs
  69. T1592 003 Firmware · cyberstrikeus
    Adversaries may gather information about the victim's host firmware that can be used during targeting.
    0 installs
  70. Ac 4 6 Metadata · cyberstrikeus
    Enforce information flow control based on [organization-defined].
    0 installs
  71. Mp 7 Media Use · cyberstrikeus
    [organization-defined] the use of [organization-defined] on [organization-defined] using [organization-defined] ;
    0 installs
  72. Pl 4 Rules Of Behavior · cyberstrikeus
    Establish and provide to individuals requiring access to the system, the rules that describe their responsibilities and expected behavior for infor...
    0 installs
  73. T0863 User Execution · cyberstrikeus
    Adversaries may rely on a targeted organizations user interaction for the execution of malicious code.
    0 installs
  74. T0813 Denial Of Control · cyberstrikeus
    Adversaries may cause a denial of control to temporarily prevent operators and engineers from interacting with process controls.
    0 installs
  75. T1053 005 Scheduled Task · cyberstrikeus
    Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
    0 installs
  76. T1053 006 Systemd Timers · cyberstrikeus
    Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code.
    0 installs
  77. T1059 012 Hypervisor CLI · cyberstrikeus
    Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands.
    0 installs
  78. T1204 001 Malicious Link · cyberstrikeus
    An adversary may rely upon a user clicking a malicious link in order to gain execution.
    0 installs
  79. T1204 002 Malicious File · cyberstrikeus
    An adversary may rely upon a user opening a malicious file in order to gain execution.
    0 installs
  80. T1543 001 Launch Agent · cyberstrikeus
    Adversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence.
    0 installs
  81. T1547 008 Lsass Driver · cyberstrikeus
    Adversaries may modify or add LSASS drivers to obtain persistence on compromised systems.
    0 installs
  82. T1547 014 Active Setup · cyberstrikeus
    Adversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine.
    0 installs
  83. T1036 Masquerading · cyberstrikeus
    Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
    0 installs
  84. T1218 008 Odbcconf · cyberstrikeus
    Adversaries may abuse odbcconf.exe to proxy execution of malicious payloads.
    0 installs
  85. T1218 010 Regsvr32 · cyberstrikeus
    Adversaries may abuse Regsvr32.exe to proxy execution of malicious code.
    0 installs
  86. T1218 011 Rundll32 · cyberstrikeus
    Adversaries may abuse rundll32.exe to proxy execution of malicious code.
    0 installs
  87. T1218 012 Verclsid · cyberstrikeus
    Adversaries may abuse verclsid.exe to proxy execution of malicious code.
    0 installs
  88. T1003 006 Dcsync · cyberstrikeus
    Adversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process fr...
    0 installs
  89. T1087 002 Domain Account · cyberstrikeus
    Adversaries may attempt to get a listing of domain accounts.
    0 installs
  90. T1518 Software Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment.
    0 installs
  91. T1602 001 Snmp Mib Dump · cyberstrikeus
    Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP).
    0 installs
  92. T1496 001 Compute Hijacking · cyberstrikeus
    Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
    0 installs
  93. T1529 System Shutdownreboot · cyberstrikeus
    Adversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
    0 installs
  94. T1561 001 Disk Content Wipe · cyberstrikeus
    Adversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources.
    0 installs
  95. Ac 11 Device Lock · cyberstrikeus
    Prevent further access to the system by [organization-defined] ;
    0 installs
  96. Ir 2 3 Breach · cyberstrikeus
    Provide incident response training on how to identify and respond to a breach, including the organization’s process for reporting a breach.
    0 installs
  97. Pl 9 Central Management · cyberstrikeus
    Centrally manage [organization-defined].
    0 installs
  98. T0845 Program Upload · cyberstrikeus
    Adversaries may attempt to upload a program from a PLC to gather information about an industrial process.
    0 installs
  99. T0852 Screen Capture · cyberstrikeus
    Adversaries may attempt to perform screen capture of devices in the control system environment.
    0 installs
  100. T0837 Loss Of Protection · cyberstrikeus
    Adversaries may compromise protective system functions designed to prevent the effects of faults and abnormal conditions.
    0 installs