← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 55 of 72

  1. T0879 Damage To Property · cyberstrikeus
    Adversaries may cause damage and destruction of property to infrastructure, equipment, and the surrounding environment when attacking control systems.
    0 installs
  2. T1669 Wi Fi Networks · cyberstrikeus
    Adversaries may gain initial access to target systems by connecting to wireless networks.
    0 installs
  3. T1204 003 Malicious Image · cyberstrikeus
    Adversaries may rely on a user running a malicious image to facilitate execution.
    0 installs
  4. T1037 005 Startup Items · cyberstrikeus
    Adversaries may use startup items automatically executed at boot initialization to establish persistence.
    0 installs
  5. T1136 001 Local Account · cyberstrikeus
    Adversaries may create a local account to maintain access to victim systems.
    0 installs
  6. T1136 003 Cloud Account · cyberstrikeus
    Adversaries may create a cloud account to maintain access to victim systems.
    0 installs
  7. T1137 003 Outlook Forms · cyberstrikeus
    Adversaries may abuse Microsoft Outlook forms to obtain persistence on a compromised system.
    0 installs
  8. T1137 005 Outlook Rules · cyberstrikeus
    Adversaries may abuse Microsoft Outlook rules to obtain persistence on a compromised system.
    0 installs
  9. T1543 004 Launch Daemon · cyberstrikeus
    Adversaries may create or modify Launch Daemons to execute malicious payloads as part of persistence.
    0 installs
  10. T1547 010 Port Monitors · cyberstrikeus
    Adversaries may use port monitors to run an adversary supplied DLL during system boot for persistence or privilege escalation.
    0 installs
  11. T1668 Exclusive Control · cyberstrikeus
    Adversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind them – in other words, by preventing other threat actors from initially accessing o...
    0 installs
  12. T1546 005 Trap · cyberstrikeus
    Adversaries may establish persistence by executing malicious content triggered by an interrupt signal.
    0 installs
  13. T1070 006 Timestomp · cyberstrikeus
    Adversaries may modify file time attributes to hide new files or changes to existing files.
    0 installs
  14. T1127 002 Clickonce · cyberstrikeus
    Adversaries may use ClickOnce applications (.appref-ms and .application files) to proxy execution of code through a trusted Windows utility.
    0 installs
  15. T1218 013 Mavinject · cyberstrikeus
    Adversaries may abuse mavinject.exe to proxy execution of malicious code.
    0 installs
  16. T1542 004 Rommonkit · cyberstrikeus
    Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate device behavior that is difficult to detect.
    0 installs
  17. T1542 005 Tftp Boot · cyberstrikeus
    Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server.
    0 installs
  18. T1656 Impersonation · cyberstrikeus
    Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf.
    0 installs
  19. T1110 Brute Force · cyberstrikeus
    Adversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.
    0 installs
  20. T1016 002 Wi Fi Discovery · cyberstrikeus
    Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
    0 installs
  21. T1531 Account Access Removal · cyberstrikeus
    Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
    0 installs
  22. T1588 002 Tool · cyberstrikeus
    Adversaries may buy, steal, or download software tools that can be used during targeting.
    0 installs
  23. Cybersecurity Supply Chain Risk Management Gv Sc Cybersecuri · cyberstrikeus
    Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders
    0 installs
  24. Governance Id Gv Governance · cyberstrikeus
    Governance
    0 installs
  25. Ma 3 1 Inspect Tools · cyberstrikeus
    Inspect the maintenance tools used by maintenance personnel for improper or unauthorized modifications.
    0 installs
  26. Ma 3 2 Inspect Media · cyberstrikeus
    Check media containing diagnostic and test programs for malicious code before the media are used in the system.
    0 installs
  27. Pl 10 Baseline Selection · cyberstrikeus
    Select a control baseline for the system.
    0 installs
  28. Pl 11 Baseline Tailoring · cyberstrikeus
    Tailor the selected control baseline by applying specified tailoring actions.
    0 installs
  29. Pl 8 1 Defense In Depth · cyberstrikeus
    Design the security and privacy architectures for the system using a defense-in-depth approach that: Allocates [organization-defined] to [organization
    0 installs
  30. T0842 Network Sniffing · cyberstrikeus
    Network sniffing is the practice of using a network interface on a computer system to monitor or capture information regardless of whether it is the specified destination for the information.
    0 installs
  31. T0859 Valid Accounts · cyberstrikeus
    Adversaries may steal the credentials of a specific user or service account using credential access techniques.
    0 installs
  32. T0889 Modify Program · cyberstrikeus
    Adversaries may modify or add a program on a controller to affect how it interacts with the physical process, peripheral devices and other hosts on the network.
    0 installs
  33. T1660 Phishing · cyberstrikeus
    Adversaries may send malicious content to users in order to gain access to their mobile devices.
    0 installs
  34. T1617 Hooking · cyberstrikeus
    Adversaries may utilize hooking to hide the presence of artifacts associated with their behaviors to evade detection.
    0 installs
  35. T1662 Data Destruction · cyberstrikeus
    Adversaries may destroy data and files on specific devices or in large numbers to interrupt availability to systems, services, and network resources.
    0 installs
  36. T1616 Call Control · cyberstrikeus
    Adversaries may make, forward, or block phone calls without user authorization.
    0 installs
  37. T1636 002 Call Log · cyberstrikeus
    Adversaries may utilize standard operating system APIs to gather call log data.
    0 installs
  38. T1636 005 Accounts · cyberstrikeus
    Adversaries may utilize standard operating system APIs to gather account data.
    0 installs
  39. T1059 013 Container Cliapi · cyberstrikeus
    Adversaries may abuse built-in CLI tools or API calls to execute malicious commands in containerized environments.
    0 installs
  40. T1648 Serverless Execution · cyberstrikeus
    Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments.
    0 installs
  41. T1136 002 Domain Account · cyberstrikeus
    Adversaries may create a domain account to maintain access to victim systems.
    0 installs
  42. T1176 002 Ide Extensions · cyberstrikeus
    Adversaries may abuse an integrated development environment (IDE) extension to establish persistent access to victim systems.
    0 installs
  43. T1505 004 Iis Components · cyberstrikeus
    Adversaries may install malicious components that run on Internet Information Services (IIS) web servers to establish persistence.
    0 installs
  44. T1547 003 Time Providers · cyberstrikeus
    Adversaries may abuse time providers to execute DLLs when the system boots.
    0 installs
  45. T1546 014 Emond · cyberstrikeus
    Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond).
    0 installs
  46. T1078 Valid Accounts · cyberstrikeus
    Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
    0 installs
  47. T1564 Hide Artifacts · cyberstrikeus
    Adversaries may attempt to hide artifacts associated with their behaviors to evade detection.
    0 installs
  48. Cis Docker V170 3 24 · cyberstrikeus
    Ensure that the Containerd socket file permissions are set to 660 or more restrictively
    0 installs
  49. Cis Docker V170 4 10 · cyberstrikeus
    Ensure secrets are not stored in Dockerfiles
    0 installs
  50. Cis Docker V170 4 11 · cyberstrikeus
    Ensure only verified packages are installed
    0 installs
  51. Cis Docker V170 4 12 · cyberstrikeus
    Ensure all signed artifacts are validated
    0 installs
  52. Cis Docker V170 5 10 · cyberstrikeus
    Ensure that the host's network namespace is not shared
    0 installs
  53. Cis Docker V170 5 11 · cyberstrikeus
    Ensure that the memory usage for containers is limited
    0 installs
  54. Cis Docker V170 5 12 · cyberstrikeus
    Ensure that CPU priority is set appropriately on containers
    0 installs
  55. Cis Docker V170 5 13 · cyberstrikeus
    Ensure that the container's root filesystem is mounted as read only
    0 installs
  56. Cis Docker V170 5 14 · cyberstrikeus
    Ensure that incoming container traffic is bound to a specific host interface
    0 installs
  57. Cis Docker V170 5 15 · cyberstrikeus
    Ensure that the 'on-failure' container restart policy is set to '5'
    0 installs
  58. Cis Docker V170 5 16 · cyberstrikeus
    Ensure that the host's process namespace is not shared
    0 installs
  59. Cis Docker V170 5 17 · cyberstrikeus
    Ensure that the host's IPC namespace is not shared
    0 installs
  60. Cis Docker V170 5 18 · cyberstrikeus
    Ensure that host devices are not directly exposed to containers
    0 installs
  61. Cis Docker V170 5 19 · cyberstrikeus
    Ensure that the default ulimit is overwritten at runtime if needed
    0 installs
  62. Cis Docker V170 5 20 · cyberstrikeus
    Ensure mount propagation mode is not set to shared
    0 installs
  63. Cis Docker V170 5 21 · cyberstrikeus
    Ensure that the host's UTS namespace is not shared
    0 installs
  64. Cis Docker V170 5 22 · cyberstrikeus
    Ensure the default seccomp profile is not Disabled
    0 installs
  65. Cis Docker V170 5 23 · cyberstrikeus
    Ensure that docker exec commands are not used with the privileged option
    0 installs
  66. Cis Docker V170 5 24 · cyberstrikeus
    Ensure that docker exec commands are not used with the user=root option
    0 installs
  67. Cis Docker V170 5 25 · cyberstrikeus
    Ensure that cgroup usage is confirmed
    0 installs
  68. Cis Docker V170 5 26 · cyberstrikeus
    Ensure that the container is restricted from acquiring additional privileges
    0 installs
  69. Cis Docker V170 5 27 · cyberstrikeus
    Ensure that container health is checked at runtime
    0 installs
  70. Cis Docker V170 5 28 · cyberstrikeus
    Ensure that Docker commands always make use of the latest version of their image
    0 installs
  71. Cis Docker V170 5 29 · cyberstrikeus
    Ensure that the PIDs cgroup limit is used
    0 installs
  72. Cis Docker V170 5 30 · cyberstrikeus
    Ensure that Docker's default bridge docker0 is not used
    0 installs
  73. Cis Docker V170 5 31 · cyberstrikeus
    Ensure that the host's user namespaces are not shared
    0 installs
  74. Cis Docker V170 5 32 · cyberstrikeus
    Ensure that the Docker socket is not mounted inside any containers
    0 installs
  75. Cis Gke V170 4 1 10 · cyberstrikeus
    Avoid non-default bindings to system:authenticated (Automated)
    0 installs
  76. Cis Gke V170 5 10 1 · cyberstrikeus
    Ensure Kubernetes Web UI is Disabled (Automated)
    0 installs
  77. Cis Gke V170 5 10 2 · cyberstrikeus
    Ensure that Alpha clusters are not used for production workloads (Automated)
    0 installs
  78. Cis Gke V170 5 10 3 · cyberstrikeus
    Consider GKE Sandbox for running untrusted workloads (Automated)
    0 installs
  79. Cis Gke V170 5 10 4 · cyberstrikeus
    Ensure use of Binary Authorization (Automated)
    0 installs
  80. Cis Gke V170 5 10 5 · cyberstrikeus
    Enable Security Posture (Manual)
    0 installs
  81. Cis Gke V180 4 1 10 · cyberstrikeus
    Avoid non-default bindings to system:authenticated (Automated)
    0 installs
  82. Cis Gke V180 5 10 1 · cyberstrikeus
    Ensure Kubernetes Web UI is Disabled (Automated)
    0 installs
  83. Cis Gke V180 5 10 2 · cyberstrikeus
    Ensure that Alpha clusters are not used for production workloads (Automated)
    0 installs
  84. Cis Gke V180 5 10 3 · cyberstrikeus
    Consider GKE Sandbox for running untrusted workloads (Automated)
    0 installs
  85. Cis Gke V180 5 10 4 · cyberstrikeus
    Enable Security Posture (Manual)
    0 installs
  86. Cis Gke V190 5 10 4 · cyberstrikeus
    Enable Security Posture (Automated)
    0 installs
  87. Cis Oke V150 3 2 10 · cyberstrikeus
    Ensure that the --rotate-server-certificates argument is set to true (Automated)
    0 installs
  88. Cis Oke V170 3 2 10 · cyberstrikeus
    Ensure that the --rotate-server-certificates argument is set to true (Automated)
    0 installs
  89. Cis Oke V180 3 2 10 · cyberstrikeus
    Ensure that the --rotate-server-certificates argument is set to true (Automated)
    0 installs
  90. Mobile Code 03 13 13 Mobile Code · cyberstrikeus
    Define acceptable mobile code and mobile code technologies.
    0 installs
  91. Literacy Training And Awareness 03 02 01 Literacy Training A · cyberstrikeus
    Provide security literacy training to system users: As part of initial training for new users and [organization-defined] thereafter, When required by
    0 installs
  92. Audit Record Content 03 03 02 Audit Record Content · cyberstrikeus
    Include the following content in audit records: What type of event occurred When the event occurred Where the event occurred Source of the event Outco
    0 installs
  93. System Component Inventory 03 04 10 System Component Invento · cyberstrikeus
    Develop and document an inventory of system components.
    0 installs
  94. Sp 800 171 03 05 06 030506 · cyberstrikeus
    03.05.06
    0 installs
  95. Sp 800 171 03 05 08 030508 · cyberstrikeus
    03.05.08
    0 installs
  96. Sp 800 171 03 05 09 030509 · cyberstrikeus
    03.05.09
    0 installs
  97. Sp 800 171 03 05 10 030510 · cyberstrikeus
    03.05.10
    0 installs
  98. Configure Software To Have Secure Settings By Default Pw 9 C · cyberstrikeus
    Help improve the security of the software at the time of installation to reduce the likelihood of the software being deployed with weak security setti
    0 installs
  99. Create Source Code By Adhering To Secure Coding Practices Pw · cyberstrikeus
    Decrease the number of security vulnerabilities in the software, and reduce costs by minimizing vulnerabilities introduced during source code creation
    0 installs
  100. Au 10 2 Validate Binding Of Information Producer Identity · cyberstrikeus
    Validate the binding of the information producer identity to the information at [organization-defined] ;
    0 installs