cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ T1059 007 Javascript · cyberstrikeusAdversaries may abuse various implementations of JavaScript for execution.
- ▌ T1129 Shared Modules · cyberstrikeusAdversaries may execute malicious payloads via loading shared modules.
- ▌ T1204 User Execution · cyberstrikeusAn adversary may rely upon specific actions by a user in order to gain execution.
- ▌ T1012 Query Registry · cyberstrikeusAdversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
- ▌ T1021 004 Ssh · cyberstrikeusAdversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH).
- ▌ T1021 005 Vnc · cyberstrikeusAdversaries may use Valid Accounts to remotely control machines using Virtual Network Computing (VNC).
- ▌ T1056 Input Capture · cyberstrikeusAdversaries may use methods of capturing user input to obtain credentials or collect information.
- ▌ T1123 Audio Capture · cyberstrikeusAn adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listen...
- ▌ T1125 Video Capture · cyberstrikeusAn adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering ...
- ▌ T1213 006 Databases · cyberstrikeusAdversaries may leverage databases to mine valuable information.
- ▌ T1565 Data Manipulation · cyberstrikeusAdversaries may insert, delete, or manipulate data in order to influence external outcomes or hide activity, thus threatening the integrity of the data.
- ▌ T1596 002 Whois · cyberstrikeusAdversaries may search public WHOIS data for information about victims that can be used during targeting.
- ▌ T0815 Denial Of View · cyberstrikeusAdversaries may cause a denial of view in attempt to disrupt and prevent operator oversight on the status of an ICS environment.
- ▌ T0880 Loss Of Safety · cyberstrikeusAdversaries may compromise safety system functions designed to maintain safe operation of a process when unacceptable or dangerous conditions occur.
- ▌ T1582 Sms Control · cyberstrikeusAdversaries may delete, alter, or send SMS messages without user authorization.
- ▌
- ▌ T1569 System Services · cyberstrikeusAdversaries may abuse system services or daemons to execute commands or programs.
- ▌ T1674 Input Injection · cyberstrikeusAdversaries may simulate keystrokes on a victim’s computer by various means to perform any type of action on behalf of the user, such as launching the command interpreter using keyboard shortcuts, ...
- ▌ T1505 003 Web Shell · cyberstrikeusAdversaries may backdoor web servers with web shells to establish persistent access to systems.
- ▌ T1197 Bits Jobs · cyberstrikeusAdversaries may abuse BITS jobs to persistently execute code and perform various background tasks.
- ▌
- ▌ T1218 005 Mshta · cyberstrikeusAdversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility.
- ▌ T1654 Log Enumeration · cyberstrikeusAdversaries may enumerate system and service logs to find useful data.
- ▌ T1056 001 Keylogging · cyberstrikeusAdversaries may log user keystrokes to intercept credentials as the user types them.
- ▌ T1113 Screen Capture · cyberstrikeusAdversaries may attempt to take screen captures of the desktop to gather information over the course of an operation.
- ▌ T1115 Clipboard Data · cyberstrikeusAdversaries may collect data stored in the clipboard from users copying information within or between applications.
- ▌ T1213 001 Confluence · cyberstrikeusAdversaries may leverage Confluence repositories to mine valuable information.
- ▌ T1213 002 Sharepoint · cyberstrikeusAdversaries may leverage the SharePoint repository as a source to mine valuable information.
- ▌ T1090 Proxy · cyberstrikeusAdversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to ...
- ▌ T1496 Resource Hijacking · cyberstrikeusAdversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
- ▌ Oversight Gv Ov Oversight · cyberstrikeusResults of organization-wide cybersecurity risk management activities and performance are used to inform, improve, and adjust the risk management stra
- ▌ Ps 1 1 Ps11 · cyberstrikeusStore all forms of code – including source code, executable code, and configuration-as-code – based on the principle of least privilege so that onl...
- ▌ Ps 2 1 Ps21 · cyberstrikeusMake software integrity verification information available to software acquirers.
- ▌ Ps 3 1 Ps31 · cyberstrikeusSecurely archive the necessary files and supporting data (e.g., integrity verification information, provenance data) to be retained for each software
- ▌ Ps 3 2 Ps32 · cyberstrikeusCollect, safeguard, maintain, and share provenance data for all components of each software release (e.g., in a software bill of materials .SBOM).
- ▌ T0827 Loss Of Control · cyberstrikeusAdversaries may seek to achieve a sustained loss of control or a runaway condition in which operators cannot issue any commands even if the malicious interference has subsided.
- ▌
- ▌ T1559 003 Xpc Services · cyberstrikeusAdversaries can provide malicious content to an XPC service daemon for local code execution.
- ▌ T1037 002 Login Hook · cyberstrikeusAdversaries may use a Login Hook to establish persistence executed upon user logon.
- ▌ T1037 004 Rc Scripts · cyberstrikeusAdversaries may establish persistence by modifying RC scripts, which are executed during a Unix-like system’s startup.
- ▌ T1136 Create Account · cyberstrikeusAdversaries may create an account to maintain access to victim systems.
- ▌ T1546 017 Udev Rules · cyberstrikeusAdversaries may maintain persistence through executing malicious content triggered using udev rules.
- ▌ T1653 Power Settings · cyberstrikeusAdversaries may impair a system's ability to hibernate, reboot, or shut down in order to extend access to infected machines.
- ▌ T1216 001 Pubprn · cyberstrikeusAdversaries may use PubPrn to proxy execution of malicious remote files.
- ▌ T1003 003 Ntds · cyberstrikeusAdversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as...
- ▌ T1069 001 Local Groups · cyberstrikeusAdversaries may attempt to find local system groups and permission settings.
- ▌ T1069 003 Cloud Groups · cyberstrikeusAdversaries may attempt to find cloud groups and permission settings.
- ▌ T1495 Firmware Corruption · cyberstrikeusAdversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying th...
- ▌ Organizational Context Gv Oc Organizational Context · cyberstrikeusThe circumstances - mission, stakeholder expectations, dependencies, and legal, regulatory, and contractual requirements - surrounding the organizatio
- ▌ T0895 Autorun Image · cyberstrikeusAdversaries may leverage AutoRun functionality or scripts to execute malicious code.
- ▌ T1053 Scheduled Taskjob · cyberstrikeusAdversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
- ▌ T1137 002 Office Test · cyberstrikeusAdversaries may abuse the Microsoft Office "Office Test" Registry key to obtain persistence on a compromised system.
- ▌ T1547 015 Login Items · cyberstrikeusAdversaries may add login items to execute upon user login to gain persistence or escalate privileges.
- ▌ T1574 012 Corprofiler · cyberstrikeusAdversaries may leverage the COR_PROFILER environment variable to hijack the execution flow of programs that load the .NET CLR.
- ▌ T1127 001 Msbuild · cyberstrikeusAdversaries may use MSBuild to proxy execution of code through a trusted Windows utility.
- ▌ T1127 003 Jamplus · cyberstrikeusAdversaries may use `JamPlus` to proxy the execution of a malicious script.
- ▌ T1218 007 Msiexec · cyberstrikeusAdversaries may abuse msiexec.exe to proxy execution of malicious payloads.
- ▌ T1542 Pre Os Boot · cyberstrikeusAdversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system.
- ▌ T1057 Process Discovery · cyberstrikeusAdversaries may attempt to get information about running processes on a system.
- ▌ T1069 002 Domain Groups · cyberstrikeusAdversaries may attempt to find domain-level groups and permission settings.
- ▌ T1087 Account Discovery · cyberstrikeusAdversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment.
- ▌ T1087 001 Local Account · cyberstrikeusAdversaries may attempt to get a listing of local system accounts.
- ▌ T1087 003 Email Account · cyberstrikeusAdversaries may attempt to get a listing of email addresses and accounts.
- ▌
- ▌ T1114 Email Collection · cyberstrikeusAdversaries may target user email to collect sensitive information.
- ▌ T1071 004 Dns · cyberstrikeusAdversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic.
- ▌ T1592 001 Hardware · cyberstrikeusAdversaries may gather information about the victim's host hardware that can be used during targeting.
- ▌ T1592 002 Software · cyberstrikeusAdversaries may gather information about the victim's host software that can be used during targeting.
- ▌ T1592 003 Firmware · cyberstrikeusAdversaries may gather information about the victim's host firmware that can be used during targeting.
- ▌
- ▌ Mp 7 Media Use · cyberstrikeus[organization-defined] the use of [organization-defined] on [organization-defined] using [organization-defined] ;
- ▌ Pl 4 Rules Of Behavior · cyberstrikeusEstablish and provide to individuals requiring access to the system, the rules that describe their responsibilities and expected behavior for infor...
- ▌ T0863 User Execution · cyberstrikeusAdversaries may rely on a targeted organizations user interaction for the execution of malicious code.
- ▌ T0813 Denial Of Control · cyberstrikeusAdversaries may cause a denial of control to temporarily prevent operators and engineers from interacting with process controls.
- ▌ T1053 005 Scheduled Task · cyberstrikeusAdversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
- ▌ T1053 006 Systemd Timers · cyberstrikeusAdversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code.
- ▌ T1059 012 Hypervisor CLI · cyberstrikeusAdversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands.
- ▌ T1204 001 Malicious Link · cyberstrikeusAn adversary may rely upon a user clicking a malicious link in order to gain execution.
- ▌ T1204 002 Malicious File · cyberstrikeusAn adversary may rely upon a user opening a malicious file in order to gain execution.
- ▌ T1543 001 Launch Agent · cyberstrikeusAdversaries may create or modify launch agents to repeatedly execute malicious payloads as part of persistence.
- ▌ T1547 008 Lsass Driver · cyberstrikeusAdversaries may modify or add LSASS drivers to obtain persistence on compromised systems.
- ▌ T1547 014 Active Setup · cyberstrikeusAdversaries may achieve persistence by adding a Registry key to the Active Setup of the local machine.
- ▌ T1036 Masquerading · cyberstrikeusAdversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
- ▌ T1218 008 Odbcconf · cyberstrikeusAdversaries may abuse odbcconf.exe to proxy execution of malicious payloads.
- ▌ T1218 010 Regsvr32 · cyberstrikeusAdversaries may abuse Regsvr32.exe to proxy execution of malicious code.
- ▌ T1218 011 Rundll32 · cyberstrikeusAdversaries may abuse rundll32.exe to proxy execution of malicious code.
- ▌ T1218 012 Verclsid · cyberstrikeusAdversaries may abuse verclsid.exe to proxy execution of malicious code.
- ▌ T1003 006 Dcsync · cyberstrikeusAdversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process fr...
- ▌ T1087 002 Domain Account · cyberstrikeusAdversaries may attempt to get a listing of domain accounts.
- ▌ T1518 Software Discovery · cyberstrikeusAdversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment.
- ▌ T1602 001 Snmp Mib Dump · cyberstrikeusAdversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP).
- ▌ T1496 001 Compute Hijacking · cyberstrikeusAdversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
- ▌ T1529 System Shutdownreboot · cyberstrikeusAdversaries may shutdown/reboot systems to interrupt access to, or aid in the destruction of, those systems.
- ▌ T1561 001 Disk Content Wipe · cyberstrikeusAdversaries may erase the contents of storage devices on specific systems or in large numbers in a network to interrupt availability to system and network resources.
- ▌
- ▌ Ir 2 3 Breach · cyberstrikeusProvide incident response training on how to identify and respond to a breach, including the organization’s process for reporting a breach.
- ▌
- ▌ T0845 Program Upload · cyberstrikeusAdversaries may attempt to upload a program from a PLC to gather information about an industrial process.
- ▌ T0852 Screen Capture · cyberstrikeusAdversaries may attempt to perform screen capture of devices in the control system environment.
- ▌ T0837 Loss Of Protection · cyberstrikeusAdversaries may compromise protective system functions designed to prevent the effects of faults and abnormal conditions.