cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ T1637 Dynamic Resolution · cyberstrikeusAdversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.
- ▌ T1195 002 Compromise Software Supply Chain · cyberstrikeusAdversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ T1195 003 Compromise Hardware Supply Chain · cyberstrikeusAdversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ T1547 Boot Or Logon Autostart Execution · cyberstrikeusAdversaries may configure system settings to automatically execute a program during system boot or logon to maintain persistence or gain higher-level privileges on compromised systems.
- ▌ T1547 006 Kernel Modules And Extensions · cyberstrikeusAdversaries may modify the kernel to automatically execute programs on system boot.
- ▌ T1574 009 Path Interception By Unquoted Path · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking vulnerable file path references.
- ▌ T1574 011 Services Registry Permissions Weakness · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking the Registry entries used by services.
- ▌ T1546 006 Lcloaddylib Addition · cyberstrikeusAdversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries.
- ▌ T1546 011 Application Shimming · cyberstrikeusAdversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.
- ▌ T1036 005 Match Legitimate Resource Name Or Location · cyberstrikeusAdversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
- ▌ T1134 002 Create Process With Token · cyberstrikeusAdversaries may create a new process with an existing token to escalate privileges and bypass access controls.
- ▌ T1216 System Script Proxy Execution · cyberstrikeusAdversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files.
- ▌ T1218 System Binary Proxy Execution · cyberstrikeusAdversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
- ▌ T1484 001 Group Policy Modification · cyberstrikeusAdversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.
- ▌ T1497 Virtualizationsandbox Evasion · cyberstrikeusAdversaries may employ various means to detect and avoid virtualization and analysis environments.
- ▌ T1562 013 Disable Or Modify Network Device Firewall · cyberstrikeusAdversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage.
- ▌ T1564 010 Process Argument Spoofing · cyberstrikeusAdversaries may attempt to hide process command-line arguments by overwriting process memory.
- ▌ T1564 011 Ignore Process Interrupts · cyberstrikeusAdversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals.
- ▌ T1003 008 Etcpasswd And Etcshadow · cyberstrikeusAdversaries may attempt to dump the contents of <code>/etc/passwd</code> and <code>/etc/shadow</code> to enable offline password cracking.
- ▌ T1111 Multi Factor Authentication Interception · cyberstrikeusAdversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and netw...
- ▌ T1552 002 Credentials In Registry · cyberstrikeusAdversaries may search the Registry on compromised systems for insecurely stored credentials.
- ▌ T1621 Multi Factor Authentication Request Generation · cyberstrikeusAdversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
- ▌ T1213 Data From Information Repositories · cyberstrikeusAdversaries may leverage information repositories to mine valuable information.
- ▌ T1602 Data From Configuration Repository · cyberstrikeusAdversaries may collect data related to managed devices from configuration repositories.
- ▌ T1048 002 Exfiltration Over Asymmetric Encrypted Non C2 Prot · cyberstrikeusAdversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel.
- ▌ T1567 003 Exfiltration To Text Storage Sites · cyberstrikeusAdversaries may exfiltrate data to text storage sites instead of their primary command and control channel.
- ▌ T1102 003 One Way Communication · cyberstrikeusAdversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the Web service channel.
- ▌ T1132 002 Non Standard Encoding · cyberstrikeusAdversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect.
- ▌ T1587 003 Digital Certificates · cyberstrikeusAdversaries may create self-signed SSL/TLS certificates that can be used during targeting.
- ▌ T1588 004 Digital Certificates · cyberstrikeusAdversaries may buy and/or steal SSL/TLS certificates that can be used during targeting.
- ▌ T1590 003 Network Trust Dependencies · cyberstrikeusAdversaries may gather information about the victim's network trust dependencies that can be used during targeting.
- ▌ T1592 Gather Victim Host Information · cyberstrikeusAdversaries may gather information about the victim's hosts that can be used during targeting.
- ▌ System Security Plan 03 15 02 System Security Plan · cyberstrikeusDevelop a system security plan that: Defines the constituent system components; Identifies the information types processed, stored, and transmitted by
- ▌ Ac 16 2 Attribute Value Changes By Authorized Individuals · cyberstrikeusProvide authorized individuals (or processes acting on behalf of individuals) the capability to define or change the value of associated security and
- ▌ Ac 16 8 Association Techniques And Technologies · cyberstrikeusImplement [organization-defined] in associating security and privacy attributes to information.
- ▌ Ac 2 8 Dynamic Account Management · cyberstrikeusCreate, activate, manage, and deactivate [organization-defined] dynamically.
- ▌ Ac 20 3 Non Organizationally Owned Systems Restricted Use · cyberstrikeusRestrict the use of non-organizationally owned systems or system components to process, store, or transmit organizational information using [organizat
- ▌ Ac 20 4 Network Accessible Storage Devices Prohibited Use · cyberstrikeusProhibit the use of [organization-defined] in external systems.
- ▌ Ac 3 10 Audited Override Of Access Control Mechanisms · cyberstrikeusEmploy an audited override of automated access control mechanisms under [organization-defined] by [organization-defined].
- ▌ Ac 4 1 Object Security And Privacy Attributes · cyberstrikeusUse [organization-defined] associated with [organization-defined] to enforce [organization-defined] as a basis for flow control decisions.
- ▌ Ac 4 14 Security Or Privacy Policy Filter Constraints · cyberstrikeusWhen transferring information between different security domains, implement [organization-defined] requiring fully enumerated formats that restrict da
- ▌ Ac 4 8 Security And Privacy Policy Filters · cyberstrikeusEnforce information flow control using [organization-defined] as a basis for flow control decisions for [organization-defined] ;
- ▌ Ac 7 3 Biometric Attempt Limiting · cyberstrikeusLimit the number of unsuccessful biometric logon attempts to [organization-defined].
- ▌ Ac 9 2 Successful And Unsuccessful Logons · cyberstrikeusNotify the user, upon successful logon, of the number of [organization-defined] during [organization-defined].
- ▌ At 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] awareness and training policy that: Procedures to facilitate the
- ▌
- ▌ Au 5 2 Real Time Alerts · cyberstrikeusProvide an alert within [organization-defined] to [organization-defined] when the following audit failure events occur: [organization-defined].
- ▌ Au 9 6 Read Only Access · cyberstrikeusAuthorize read-only access to audit information to [organization-defined].
- ▌ Cm 7 Least Functionality · cyberstrikeusConfigure the system to provide only [organization-defined] ;
- ▌
- ▌
- ▌ Ir 2 Incident Response Training · cyberstrikeusProvide incident response training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming an i
- ▌ Ir 4 2 Dynamic Reconfiguration · cyberstrikeusInclude the following types of dynamic reconfiguration for [organization-defined] as part of the incident response capability: [organization-defined].
- ▌ Ir 4 4 Information Correlation · cyberstrikeusCorrelate incident information and individual incident responses to achieve an organization-wide perspective on incident awareness and response.
- ▌ Ir 9 4 Exposure To Unauthorized Personnel · cyberstrikeusEmploy the following controls for personnel exposed to information not within assigned access authorizations: [organization-defined].
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Pm 16 Threat Awareness Program · cyberstrikeusImplement a threat awareness program that includes a cross-organization information-sharing capability for threat intelligence.
- ▌ Pm 5 1 Inventory Of Personally Identifiable Information · cyberstrikeusEstablish, maintain, and update [organization-defined] an inventory of all systems, applications, and projects that process personally identifiable in
- ▌ Ps 2 Position Risk Designation · cyberstrikeusAssign a risk designation to all organizational positions;
- ▌ Ps 3 1 Classified Information · cyberstrikeusVerify that individuals accessing a system processing, storing, or transmitting classified information are cleared and indoctrinated to the highest cl
- ▌ Ra 5 Vulnerability Monitoring And Scanning · cyberstrikeusMonitor and scan for vulnerabilities in the system and hosted applications [organization-defined] and when new vulnerabilities potentially affectin...
- ▌ Sc 26 Decoys · cyberstrikeusInclude components within organizational systems specifically designed to be the target of malicious attacks for detecting, deflecting, and analyzing
- ▌ Si 19 3 Release · cyberstrikeusRemove personally identifiable information elements from a dataset prior to its release if those elements in the dataset do not need to be part of the
- ▌ T0805 Block Serial Com · cyberstrikeusAdversaries may block access to serial COM to prevent instructions or configurations from reaching target devices.
- ▌ T0809 Data Destruction · cyberstrikeusAdversaries may perform data destruction over the course of an operation.
- ▌ T1630 001 Uninstall Malicious Application · cyberstrikeusAdversaries may include functionality in malware that uninstalls the malicious application from the device.
- ▌ T1631 001 Ptrace System Calls · cyberstrikeusAdversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1632 001 Code Signing Policy Modification · cyberstrikeusAdversaries may modify code signing policies to enable execution of applications signed with unofficial or unknown keys.
- ▌ T1670 Virtualization Solution · cyberstrikeusAdversaries may carry out malicious operations using virtualization solutions to escape from Android sandboxes and to avoid detection.
- ▌ T1417 002 Gui Input Capture · cyberstrikeusAdversaries may mimic common operating system GUI components to prompt users for sensitive information with a seemingly legitimate prompt.
- ▌ T1430 001 Remote Device Management Services · cyberstrikeusAn adversary may use access to cloud services (e.g.
- ▌ T1453 Abuse Accessibility Features · cyberstrikeusAdversaries may abuse accessibility features in Android devices to steal sensitive data and to spread malware to other devices.
- ▌ T1546 Event Triggered Execution · cyberstrikeusAdversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events.
- ▌ T1548 003 Sudo And Sudo Caching · cyberstrikeusAdversaries may perform sudo caching and/or use the sudoers file to elevate privileges.
- ▌ T1036 004 Masquerade Task Or Service · cyberstrikeusAdversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign.
- ▌ T1055 003 Thread Execution Hijacking · cyberstrikeusAdversaries may inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1134 003 Make And Impersonate Token · cyberstrikeusAdversaries may make new tokens and impersonate users to escalate privileges and bypass access controls.
- ▌ T1222 001 Windows File And Directory Permissions Modificatio · cyberstrikeusAdversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
- ▌ T1222 File And Directory Permissions Modification · cyberstrikeusAdversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
- ▌ T1497 002 User Activity Based Checks · cyberstrikeusAdversaries may employ various user activity checks to detect and avoid virtualization and analysis environments.
- ▌ T1003 002 Security Account Manager · cyberstrikeusAdversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is...
- ▌ T1552 006 Group Policy Preferences · cyberstrikeusAdversaries may attempt to find unsecured credentials in Group Policy Preferences (GPP).
- ▌ T1555 006 Cloud Secrets Management Stores · cyberstrikeusAdversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.
- ▌ T1556 003 Pluggable Authentication Modules · cyberstrikeusAdversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.
- ▌ T1021 006 Windows Remote Management · cyberstrikeusAdversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM).
- ▌ T1091 Replication Through Removable Media · cyberstrikeusAdversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted i...
- ▌ T1048 003 Exfiltration Over Unencrypted Non C2 Protocol · cyberstrikeusAdversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.
- ▌ T1052 Exfiltration Over Physical Medium · cyberstrikeusAdversaries may attempt to exfiltrate data via a physical medium, such as a removable drive.
- ▌ T1567 002 Exfiltration To Cloud Storage · cyberstrikeusAdversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.
- ▌ T1071 Application Layer Protocol · cyberstrikeusAdversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic.
- ▌ T1219 003 Remote Access Hardware · cyberstrikeusAn adversary may use legitimate remote access hardware to establish an interactive command and control channel to target systems within networks.
- ▌ T1573 001 Symmetric Cryptography · cyberstrikeusAdversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
- ▌ T1584 Compromise Infrastructure · cyberstrikeusAdversaries may compromise third-party infrastructure that can be used during targeting.
- ▌ T1585 001 Social Media Accounts · cyberstrikeusAdversaries may create and cultivate social media accounts that can be used during targeting.
- ▌ T1586 001 Social Media Accounts · cyberstrikeusAdversaries may compromise social media accounts that can be used during targeting.
- ▌ T1590 006 Network Security Appliances · cyberstrikeusAdversaries may gather information about the victim's network security appliances that can be used during targeting.