cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ T0879 Damage To Property · cyberstrikeusAdversaries may cause damage and destruction of property to infrastructure, equipment, and the surrounding environment when attacking control systems.
- ▌ T1669 Wi Fi Networks · cyberstrikeusAdversaries may gain initial access to target systems by connecting to wireless networks.
- ▌ T1204 003 Malicious Image · cyberstrikeusAdversaries may rely on a user running a malicious image to facilitate execution.
- ▌ T1037 005 Startup Items · cyberstrikeusAdversaries may use startup items automatically executed at boot initialization to establish persistence.
- ▌ T1136 001 Local Account · cyberstrikeusAdversaries may create a local account to maintain access to victim systems.
- ▌ T1136 003 Cloud Account · cyberstrikeusAdversaries may create a cloud account to maintain access to victim systems.
- ▌ T1137 003 Outlook Forms · cyberstrikeusAdversaries may abuse Microsoft Outlook forms to obtain persistence on a compromised system.
- ▌ T1137 005 Outlook Rules · cyberstrikeusAdversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system.
- ▌ T1543 004 Launch Daemon · cyberstrikeusAdversaries may create or modify Launch Daemons to execute malicious payloads as part of persistence.
- ▌ T1547 010 Port Monitors · cyberstrikeusAdversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation.
- ▌ T1668 Exclusive Control · cyberstrikeusAdversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind them – in other words, by preventing other threat actors from initially accessing o...
- ▌ T1546 005 Trap · cyberstrikeusAdversaries may establish persistence by executing malicious content triggered by an interrupt signal.
- ▌ T1070 006 Timestomp · cyberstrikeusAdversaries may modify file time attributes to hide new files or changes to existing files.
- ▌ T1127 002 Clickonce · cyberstrikeusAdversaries may use ClickOnce applications (.appref-ms and .application files) to proxy execution of code through a trusted Windows utility.
- ▌ T1218 013 Mavinject · cyberstrikeusAdversaries may abuse mavinject.exe to proxy execution of malicious code.
- ▌ T1542 004 Rommonkit · cyberstrikeusAdversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate device behavior that is difficult to detect.
- ▌ T1542 005 Tftp Boot · cyberstrikeusAdversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server.
- ▌ T1656 Impersonation · cyberstrikeusAdversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf.
- ▌ T1110 Brute Force · cyberstrikeusAdversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
- ▌ T1016 002 Wi Fi Discovery · cyberstrikeusAdversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
- ▌ T1531 Account Access Removal · cyberstrikeusAdversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
- ▌ T1588 002 Tool · cyberstrikeusAdversaries may buy, steal, or download software tools that can be used during targeting.
- ▌ Cybersecurity Supply Chain Risk Management Gv Sc Cybersecuri · cyberstrikeusCyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders
- ▌
- ▌ Ma 3 1 Inspect Tools · cyberstrikeusInspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications.
- ▌ Ma 3 2 Inspect Media · cyberstrikeusCheck media containing diagnostic and test programs for malicious code before the media are used in the system.
- ▌
- ▌ Pl 11 Baseline Tailoring · cyberstrikeusTailor the selected control baseline by applying specified tailoring actions.
- ▌ Pl 8 1 Defense In Depth · cyberstrikeusDesign the security and privacy architectures for the system using a defense-in-depth approach that: Allocates [organization-defined] to [organization
- ▌ T0842 Network Sniffing · cyberstrikeusNetwork sniffing is the practice of using a network interface on a computer system to monitor or capture information regardless of whether it is the specified destination for the information.
- ▌ T0859 Valid Accounts · cyberstrikeusAdversaries may steal the credentials of a specific user or service account using credential access techniques.
- ▌ T0889 Modify Program · cyberstrikeusAdversaries may modify or add a program on a controller to affect how it interacts with the physical process, peripheral devices and other hosts on the network.
- ▌ T1660 Phishing · cyberstrikeusAdversaries may send malicious content to users in order to gain access to their mobile devices.
- ▌ T1617 Hooking · cyberstrikeusAdversaries may utilize hooking to hide the presence of artifacts associated with their behaviors to evade detection.
- ▌ T1662 Data Destruction · cyberstrikeusAdversaries may destroy data and files on specific devices or in large numbers to interrupt availability to systems, services, and network resources.
- ▌ T1616 Call Control · cyberstrikeusAdversaries may make, forward, or block phone calls without user authorization.
- ▌ T1636 002 Call Log · cyberstrikeusAdversaries may utilize standard operating system APIs to gather call log data.
- ▌ T1636 005 Accounts · cyberstrikeusAdversaries may utilize standard operating system APIs to gather account data.
- ▌ T1059 013 Container Cliapi · cyberstrikeusAdversaries may abuse built-in CLI tools or API calls to execute malicious commands in containerized environments.
- ▌ T1648 Serverless Execution · cyberstrikeusAdversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments.
- ▌ T1136 002 Domain Account · cyberstrikeusAdversaries may create a domain account to maintain access to victim systems.
- ▌ T1176 002 Ide Extensions · cyberstrikeusAdversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim systems.
- ▌ T1505 004 Iis Components · cyberstrikeusAdversaries may install malicious components that run on Internet Information Services (IIS) web servers to establish persistence.
- ▌ T1547 003 Time Providers · cyberstrikeusAdversaries may abuse time providers to execute DLLs when the system boots.
- ▌ T1546 014 Emond · cyberstrikeusAdversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond).
- ▌ T1078 Valid Accounts · cyberstrikeusAdversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
- ▌ T1564 Hide Artifacts · cyberstrikeusAdversaries may attempt to hide artifacts associated with their behaviors to evade detection.
- ▌ Cis Docker V170 3 24 · cyberstrikeusEnsure that the Containerd socket file permissions are set to 660 or more restrictively
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker V170 5 13 · cyberstrikeusEnsure that the container's root filesystem is mounted as read only
- ▌ Cis Docker V170 5 14 · cyberstrikeusEnsure that incoming container traffic is bound to a specific host interface
- ▌ Cis Docker V170 5 15 · cyberstrikeusEnsure that the 'on-failure' container restart policy is set to '5'
- ▌
- ▌
- ▌ Cis Docker V170 5 18 · cyberstrikeusEnsure that host devices are not directly exposed to containers
- ▌ Cis Docker V170 5 19 · cyberstrikeusEnsure that the default ulimit is overwritten at runtime if needed
- ▌
- ▌
- ▌
- ▌ Cis Docker V170 5 23 · cyberstrikeusEnsure that docker exec commands are not used with the privileged option
- ▌ Cis Docker V170 5 24 · cyberstrikeusEnsure that docker exec commands are not used with the user=root option
- ▌
- ▌ Cis Docker V170 5 26 · cyberstrikeusEnsure that the container is restricted from acquiring additional privileges
- ▌
- ▌ Cis Docker V170 5 28 · cyberstrikeusEnsure that Docker commands always make use of the latest version of their image
- ▌
- ▌
- ▌
- ▌ Cis Docker V170 5 32 · cyberstrikeusEnsure that the Docker socket is not mounted inside any containers
- ▌
- ▌
- ▌ Cis Gke V170 5 10 2 · cyberstrikeusEnsure that Alpha clusters are not used for production workloads (Automated)
- ▌ Cis Gke V170 5 10 3 · cyberstrikeusConsider GKE Sandbox for running untrusted workloads (Automated)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Gke V180 5 10 2 · cyberstrikeusEnsure that Alpha clusters are not used for production workloads (Automated)
- ▌ Cis Gke V180 5 10 3 · cyberstrikeusConsider GKE Sandbox for running untrusted workloads (Automated)
- ▌
- ▌
- ▌ Cis Oke V150 3 2 10 · cyberstrikeusEnsure that the --rotate-server-certificates argument is set to true (Automated)
- ▌ Cis Oke V170 3 2 10 · cyberstrikeusEnsure that the --rotate-server-certificates argument is set to true (Automated)
- ▌ Cis Oke V180 3 2 10 · cyberstrikeusEnsure that the --rotate-server-certificates argument is set to true (Automated)
- ▌ Mobile Code 03 13 13 Mobile Code · cyberstrikeusDefine acceptable mobile code and mobile code technologies.
- ▌ Literacy Training And Awareness 03 02 01 Literacy Training A · cyberstrikeusProvide security literacy training to system users: As part of initial training for new users and [organization-defined] thereafter, When required by
- ▌ Audit Record Content 03 03 02 Audit Record Content · cyberstrikeusInclude the following content in audit records: What type of event occurred When the event occurred Where the event occurred Source of the event Outco
- ▌ System Component Inventory 03 04 10 System Component Invento · cyberstrikeusDevelop and document an inventory of system components.
- ▌
- ▌
- ▌
- ▌
- ▌ Configure Software To Have Secure Settings By Default Pw 9 C · cyberstrikeusHelp improve the security of the software at the time of installation to reduce the likelihood of the software being deployed with weak security setti
- ▌ Create Source Code By Adhering To Secure Coding Practices Pw · cyberstrikeusDecrease the number of security vulnerabilities in the software, and reduce costs by minimizing vulnerabilities introduced during source code creation
- ▌ Au 10 2 Validate Binding Of Information Producer Identity · cyberstrikeusValidate the binding of the information producer identity to the information at [organization-defined] ;