← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 58 of 72

  1. T1637 Dynamic Resolution · cyberstrikeus
    Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.
    0 installs
  2. T1195 002 Compromise Software Supply Chain · cyberstrikeus
    Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.
    0 installs
  3. T1195 003 Compromise Hardware Supply Chain · cyberstrikeus
    Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.
    0 installs
  4. T1547 Boot Or Logon Autostart Execution · cyberstrikeus
    Adversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems.
    0 installs
  5. T1547 006 Kernel Modules And Extensions · cyberstrikeus
    Adversaries may modify the kernel to automatically execute programs on system boot.
    0 installs
  6. T1574 009 Path Interception By Unquoted Path · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking vulnerable file path references.
    0 installs
  7. T1574 011 Services Registry Permissions Weakness · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services.
    0 installs
  8. T1546 006 Lcloaddylib Addition · cyberstrikeus
    Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries.
    0 installs
  9. T1546 011 Application Shimming · cyberstrikeus
    Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.
    0 installs
  10. T1036 005 Match Legitimate Resource Name Or Location · cyberstrikeus
    Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
    0 installs
  11. T1134 002 Create Process With Token · cyberstrikeus
    Adversaries may create a new process with an existing token to escalate privileges and bypass access controls.
    0 installs
  12. T1216 System Script Proxy Execution · cyberstrikeus
    Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files.
    0 installs
  13. T1218 System Binary Proxy Execution · cyberstrikeus
    Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
    0 installs
  14. T1484 001 Group Policy Modification · cyberstrikeus
    Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.
    0 installs
  15. T1497 Virtualizationsandbox Evasion · cyberstrikeus
    Adversaries may employ various means to detect and avoid virtualization and analysis environments.
    0 installs
  16. T1562 013 Disable Or Modify Network Device Firewall · cyberstrikeus
    Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage.
    0 installs
  17. T1564 010 Process Argument Spoofing · cyberstrikeus
    Adversaries may attempt to hide process command-line arguments by overwriting process memory.
    0 installs
  18. T1564 011 Ignore Process Interrupts · cyberstrikeus
    Adversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals.
    0 installs
  19. T1003 008 Etcpasswd And Etcshadow · cyberstrikeus
    Adversaries may attempt to dump the contents of <code>/etc/passwd</code> and <code>/etc/shadow</code> to enable offline password cracking.
    0 installs
  20. T1111 Multi Factor Authentication Interception · cyberstrikeus
    Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and netw...
    0 installs
  21. T1552 002 Credentials In Registry · cyberstrikeus
    Adversaries may search the Registry on compromised systems for insecurely stored credentials.
    0 installs
  22. T1621 Multi Factor Authentication Request Generation · cyberstrikeus
    Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
    0 installs
  23. T1213 Data From Information Repositories · cyberstrikeus
    Adversaries may leverage information repositories to mine valuable information.
    0 installs
  24. T1602 Data From Configuration Repository · cyberstrikeus
    Adversaries may collect data related to managed devices from configuration repositories.
    0 installs
  25. T1048 002 Exfiltration Over Asymmetric Encrypted Non C2 Prot · cyberstrikeus
    Adversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel.
    0 installs
  26. T1567 003 Exfiltration To Text Storage Sites · cyberstrikeus
    Adversaries may exfiltrate data to text storage sites instead of their primary command and control channel.
    0 installs
  27. T1102 003 One Way Communication · cyberstrikeus
    Adversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the Web service channel.
    0 installs
  28. T1132 002 Non Standard Encoding · cyberstrikeus
    Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect.
    0 installs
  29. T1587 003 Digital Certificates · cyberstrikeus
    Adversaries may create self-signed SSL/TLS certificates that can be used during targeting.
    0 installs
  30. T1588 004 Digital Certificates · cyberstrikeus
    Adversaries may buy and/or steal SSL/TLS certificates that can be used during targeting.
    0 installs
  31. T1590 003 Network Trust Dependencies · cyberstrikeus
    Adversaries may gather information about the victim's network trust dependencies that can be used during targeting.
    0 installs
  32. T1592 Gather Victim Host Information · cyberstrikeus
    Adversaries may gather information about the victim's hosts that can be used during targeting.
    0 installs
  33. System Security Plan 03 15 02 System Security Plan · cyberstrikeus
    Develop a system security plan that: Defines the constituent system components; Identifies the information types processed, stored, and transmitted by
    0 installs
  34. Ac 16 2 Attribute Value Changes By Authorized Individuals · cyberstrikeus
    Provide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security and
    0 installs
  35. Ac 16 8 Association Techniques And Technologies · cyberstrikeus
    Implement [organization-defined] in associating security and privacy attributes to information.
    0 installs
  36. Ac 2 8 Dynamic Account Management · cyberstrikeus
    Create, activate, manage, and deactivate [organization-defined] dynamically.
    0 installs
  37. Ac 20 3 Non Organizationally Owned Systems Restricted Use · cyberstrikeus
    Restrict the use of non-organizationally owned systems or system components to process, store, or transmit organizational information using [organizat
    0 installs
  38. Ac 20 4 Network Accessible Storage Devices Prohibited Use · cyberstrikeus
    Prohibit the use of [organization-defined] in external systems.
    0 installs
  39. Ac 3 10 Audited Override Of Access Control Mechanisms · cyberstrikeus
    Employ an audited override of automated access control mechanisms under [organization-defined] by [organization-defined].
    0 installs
  40. Ac 4 1 Object Security And Privacy Attributes · cyberstrikeus
    Use [organization-defined] associated with [organization-defined] to enforce [organization-defined] as a basis for flow control decisions.
    0 installs
  41. Ac 4 14 Security Or Privacy Policy Filter Constraints · cyberstrikeus
    When transferring information between different security domains, implement [organization-defined] requiring fully enumerated formats that restrict da
    0 installs
  42. Ac 4 8 Security And Privacy Policy Filters · cyberstrikeus
    Enforce information flow control using [organization-defined] as a basis for flow control decisions for [organization-defined] ;
    0 installs
  43. Ac 7 3 Biometric Attempt Limiting · cyberstrikeus
    Limit the number of unsuccessful biometric logon attempts to [organization-defined].
    0 installs
  44. Ac 9 2 Successful And Unsuccessful Logons · cyberstrikeus
    Notify the user, upon successful logon, of the number of [organization-defined] during [organization-defined].
    0 installs
  45. At 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] awareness and training policy that: Procedures to facilitate the
    0 installs
  46. Au 14 1 System Start Up · cyberstrikeus
    Initiate session audits automatically at system start-up.
    0 installs
  47. Au 5 2 Real Time Alerts · cyberstrikeus
    Provide an alert within [organization-defined] to [organization-defined] when the following audit failure events occur: [organization-defined].
    0 installs
  48. Au 9 6 Read Only Access · cyberstrikeus
    Authorize read-only access to audit information to [organization-defined].
    0 installs
  49. Cm 7 Least Functionality · cyberstrikeus
    Configure the system to provide only [organization-defined] ;
    0 installs
  50. Cp 10 5 Failover Capability · cyberstrikeus
    Failover Capability
    0 installs
  51. Cp 5 Contingency Plan Update · cyberstrikeus
    Contingency Plan Update
    0 installs
  52. Ir 2 Incident Response Training · cyberstrikeus
    Provide incident response training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming an i
    0 installs
  53. Ir 4 2 Dynamic Reconfiguration · cyberstrikeus
    Include the following types of dynamic reconfiguration for [organization-defined] as part of the incident response capability: [organization-defined].
    0 installs
  54. Ir 4 4 Information Correlation · cyberstrikeus
    Correlate incident information and individual incident responses to achieve an organization-wide perspective on incident awareness and response.
    0 installs
  55. Ir 9 4 Exposure To Unauthorized Personnel · cyberstrikeus
    Employ the following controls for personnel exposed to information not within assigned access authorizations: [organization-defined].
    0 installs
  56. Ma 4 2 Document Nonlocal Maintenance · cyberstrikeus
    Document Nonlocal Maintenance
    0 installs
  57. Mp 2 2 Cryptographic Protection · cyberstrikeus
    Cryptographic Protection
    0 installs
  58. Mp 4 1 Cryptographic Protection · cyberstrikeus
    Cryptographic Protection
    0 installs
  59. Mp 5 4 Cryptographic Protection · cyberstrikeus
    Cryptographic Protection
    0 installs
  60. Mp 8 1 Documentation Of Process · cyberstrikeus
    Document system media downgrading actions.
    0 installs
  61. Pm 16 Threat Awareness Program · cyberstrikeus
    Implement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence.
    0 installs
  62. Pm 5 1 Inventory Of Personally Identifiable Information · cyberstrikeus
    Establish, maintain, and update [organization-defined] an inventory of all systems, applications, and projects that process personally identifiable in
    0 installs
  63. Ps 2 Position Risk Designation · cyberstrikeus
    Assign a risk designation to all organizational positions;
    0 installs
  64. Ps 3 1 Classified Information · cyberstrikeus
    Verify that individuals accessing a system processing, storing, or transmitting classified information are cleared and indoctrinated to the highest cl
    0 installs
  65. Ra 5 Vulnerability Monitoring And Scanning · cyberstrikeus
    Monitor and scan for vulnerabilities in the system and hosted applications [organization-defined] and when new vulnerabilities potentially affectin...
    0 installs
  66. Sc 26 Decoys · cyberstrikeus
    Include components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing
    0 installs
  67. Si 19 3 Release · cyberstrikeus
    Remove personally identifiable information elements from a dataset prior to its release if those elements in the dataset do not need to be part of the
    0 installs
  68. T0805 Block Serial Com · cyberstrikeus
    Adversaries may block access to serial COM to prevent instructions or configurations from reaching target devices.
    0 installs
  69. T0809 Data Destruction · cyberstrikeus
    Adversaries may perform data destruction over the course of an operation.
    0 installs
  70. T1630 001 Uninstall Malicious Application · cyberstrikeus
    Adversaries may include functionality in malware that uninstalls the malicious application from the device.
    0 installs
  71. T1631 001 Ptrace System Calls · cyberstrikeus
    Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.
    0 installs
  72. T1632 001 Code Signing Policy Modification · cyberstrikeus
    Adversaries may modify code signing policies to enable execution of applications signed with unofficial or unknown keys.
    0 installs
  73. T1670 Virtualization Solution · cyberstrikeus
    Adversaries may carry out malicious operations using virtualization solutions to escape from Android sandboxes and to avoid detection.
    0 installs
  74. T1417 002 Gui Input Capture · cyberstrikeus
    Adversaries may mimic common operating system GUI components to prompt users for sensitive information with a seemingly legitimate prompt.
    0 installs
  75. T1430 001 Remote Device Management Services · cyberstrikeus
    An adversary may use access to cloud services (e.g.
    0 installs
  76. T1453 Abuse Accessibility Features · cyberstrikeus
    Adversaries may abuse accessibility features in Android devices to steal sensitive data and to spread malware to other devices.
    0 installs
  77. T1546 Event Triggered Execution · cyberstrikeus
    Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events.
    0 installs
  78. T1548 003 Sudo And Sudo Caching · cyberstrikeus
    Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges.
    0 installs
  79. T1036 004 Masquerade Task Or Service · cyberstrikeus
    Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign.
    0 installs
  80. T1055 003 Thread Execution Hijacking · cyberstrikeus
    Adversaries may inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.
    0 installs
  81. T1134 003 Make And Impersonate Token · cyberstrikeus
    Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls.
    0 installs
  82. T1222 001 Windows File And Directory Permissions Modificatio · cyberstrikeus
    Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
    0 installs
  83. T1222 File And Directory Permissions Modification · cyberstrikeus
    Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
    0 installs
  84. T1497 002 User Activity Based Checks · cyberstrikeus
    Adversaries may employ various user activity checks to detect and avoid virtualization and analysis environments.
    0 installs
  85. T1003 002 Security Account Manager · cyberstrikeus
    Adversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is...
    0 installs
  86. T1552 006 Group Policy Preferences · cyberstrikeus
    Adversaries may attempt to find unsecured credentials in Group Policy Preferences (GPP).
    0 installs
  87. T1555 006 Cloud Secrets Management Stores · cyberstrikeus
    Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.
    0 installs
  88. T1556 003 Pluggable Authentication Modules · cyberstrikeus
    Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.
    0 installs
  89. T1021 006 Windows Remote Management · cyberstrikeus
    Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM).
    0 installs
  90. T1091 Replication Through Removable Media · cyberstrikeus
    Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted i...
    0 installs
  91. T1048 003 Exfiltration Over Unencrypted Non C2 Protocol · cyberstrikeus
    Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.
    0 installs
  92. T1052 Exfiltration Over Physical Medium · cyberstrikeus
    Adversaries may attempt to exfiltrate data via a physical medium, such as a removable drive.
    0 installs
  93. T1567 002 Exfiltration To Cloud Storage · cyberstrikeus
    Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
    0 installs
  94. T1071 Application Layer Protocol · cyberstrikeus
    Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic.
    0 installs
  95. T1219 003 Remote Access Hardware · cyberstrikeus
    An adversary may use legitimate remote access hardware to establish an interactive command and control channel to target systems within networks.
    0 installs
  96. T1573 001 Symmetric Cryptography · cyberstrikeus
    Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
    0 installs
  97. T1584 Compromise Infrastructure · cyberstrikeus
    Adversaries may compromise third-party infrastructure that can be used during targeting.
    0 installs
  98. T1585 001 Social Media Accounts · cyberstrikeus
    Adversaries may create and cultivate social media accounts that can be used during targeting.
    0 installs
  99. T1586 001 Social Media Accounts · cyberstrikeus
    Adversaries may compromise social media accounts that can be used during targeting.
    0 installs
  100. T1590 006 Network Security Appliances · cyberstrikeus
    Adversaries may gather information about the victim's network security appliances that can be used during targeting.
    0 installs