cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ Sa 5 1 Functional Properties Of Security Controls · cyberstrikeusFunctional Properties of Security Controls
- ▌ Sa 8 3 Modularity And Layering · cyberstrikeusImplement the security design principles of modularity and layering in [organization-defined].
- ▌ Sc 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] system and communications protection policy that: Procedures to f
- ▌
- ▌ Sc 3 5 Layered Structures · cyberstrikeusImplement security functions as a layered structure minimizing interactions between layers of the design and avoiding any dependence by lower layers o
- ▌ Sc 31 2 Maximum Bandwidth · cyberstrikeusReduce the maximum bandwidth for identified covert [organization-defined] channels to [organization-defined].
- ▌ Sc 37 Out Of Band Channels · cyberstrikeusEmploy the following out-of-band channels for the physical delivery or electronic transmission of [organization-defined] to [organization-defined]: [o
- ▌ Sc 6 Resource Availability · cyberstrikeusProtect the availability of resources by allocating [organization-defined] by [organization-defined].
- ▌ Si 13 1 Transferring Component Responsibilities · cyberstrikeusTake system components out of service by transferring component responsibilities to substitute components no later than [organization-defined] of mean
- ▌ Si 3 Malicious Code Protection · cyberstrikeusImplement [organization-defined] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code;
- ▌ Si 4 12 Automated Organization Generated Alerts · cyberstrikeusAlert [organization-defined] using [organization-defined] when the following indications of inappropriate or unusual activities with security or priva
- ▌ Si 7 8 Auditing Capability For Significant Events · cyberstrikeusUpon detection of a potential integrity violation, provide the capability to audit the event and initiate the following actions: [organization-defined
- ▌ Sr 11 1 Anti Counterfeit Training · cyberstrikeusTrain [organization-defined] to detect counterfeit system components (including hardware, software, and firmware).
- ▌ Sr 11 3 Anti Counterfeit Scanning · cyberstrikeusScan for counterfeit system components [organization-defined].
- ▌ Sr 4 3 Validate As Genuine And Not Altered · cyberstrikeusEmploy the following controls to validate that the system or system component received is genuine and has not been altered: [organization-defined].
- ▌
- ▌
- ▌ Cis Docker V160 2 12 · cyberstrikeusEnsure that authorization for Docker client commands is enabled
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker V160 2 17 · cyberstrikeusEnsure that a daemon-wide custom seccomp profile is applied if appropriate
- ▌ Cis Docker V160 2 18 · cyberstrikeusEnsure that experimental features are not implemented in production
- ▌
- ▌
- ▌ Cis Docker V170 2 12 · cyberstrikeusEnsure that authorization for Docker client commands is enabled
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Docker V170 2 17 · cyberstrikeusEnsure that a daemon-wide custom seccomp profile is applied if appropriate
- ▌ Cis Docker V170 2 18 · cyberstrikeusEnsure that experimental features are not implemented in production
- ▌ Cis Docker V170 3 10 · cyberstrikeusEnsure that TLS CA certificate file permissions are set to 444 or more restrictively
- ▌ Cis Docker V170 3 11 · cyberstrikeusEnsure that Docker server certificate file ownership is set to root:root
- ▌ Cis Docker V170 3 12 · cyberstrikeusEnsure that the Docker server certificate file permissions are set to 444 or more restrictively
- ▌ Cis Docker V170 3 13 · cyberstrikeusEnsure that the Docker server certificate key file ownership is set to root:root
- ▌ Cis Docker V170 3 14 · cyberstrikeusEnsure that the Docker server certificate key file permissions are set to 400
- ▌ Cis Docker V170 3 15 · cyberstrikeusEnsure that the Docker socket file ownership is set to root:docker
- ▌ Cis Docker V170 3 16 · cyberstrikeusEnsure that the Docker socket file permissions are set to 660 or more restrictively
- ▌
- ▌ Cis Docker V170 3 18 · cyberstrikeusEnsure that daemon.json file permissions are set to 644 or more restrictive
- ▌ Cis Docker V170 3 19 · cyberstrikeusEnsure that the /etc/default/docker file ownership is set to root:root
- ▌ Cis Docker V170 3 20 · cyberstrikeusEnsure that the /etc/default/docker file permissions are set to 644 or more restrictively
- ▌ Cis Docker V170 3 21 · cyberstrikeusEnsure that the /etc/sysconfig/docker file permissions are set to 644 or more restrictively
- ▌ Cis Docker V170 3 22 · cyberstrikeusEnsure that the /etc/sysconfig/docker file ownership is set to root:root
- ▌ Cis Docker V170 3 23 · cyberstrikeusEnsure that the Containerd socket file ownership is set to root:root
- ▌ T1589 002 Email Addresses · cyberstrikeusAdversaries may gather email addresses that can be used during targeting.
- ▌ Adverse Event Analysis De Ae Adverse Event Analysis · cyberstrikeusAnomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
- ▌ Supply Chain Risk Management Id Sc Supply Chain Risk Managem · cyberstrikeusSupply Chain Risk Management
- ▌ Data Security Pr Ds Data Security · cyberstrikeusData are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information
- ▌
- ▌
- ▌ Ac 2 Account Management · cyberstrikeusDefine and document the types of accounts allowed and specifically prohibited for use within the system;
- ▌ Ac 25 Reference Monitor · cyberstrikeusImplement a reference monitor for [organization-defined] that is tamperproof, always invoked, and small enough to be subject to analysis and testing,
- ▌ Ac 3 Access Enforcement · cyberstrikeusEnforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
- ▌ Ma 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] maintenance policy that: Procedures to facilitate the implementat
- ▌ Ma 4 1 Logging And Review · cyberstrikeusLog [organization-defined] for nonlocal maintenance and diagnostic sessions;
- ▌ Ma 5 Maintenance Personnel · cyberstrikeusEstablish a process for maintenance personnel authorization and maintain a list of authorized maintenance organizations or personnel;
- ▌
- ▌ T0802 Automated Collection · cyberstrikeusAdversaries may automate collection of industrial environment information using tools or scripts.
- ▌ T0856 Spoof Reporting Message · cyberstrikeusAdversaries may spoof reporting messages in control system environments for evasion and to impair process control.
- ▌ T0858 Change Operating Mode · cyberstrikeusAdversaries may change the operating mode of a controller to gain additional access to engineering functions such as Program Download.
- ▌ T0871 Execution Through API · cyberstrikeusAdversaries may attempt to leverage Application Program Interfaces (APIs) used for communication between control software and the hardware.
- ▌ T1451 Sim Card Swap · cyberstrikeusAdversaries may gain access to mobile devices through transfers or swaps from victims’ phone numbers to adversary-controlled SIM cards and mobile devices.
- ▌ T1655 Masquerading · cyberstrikeusAdversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
- ▌ T1418 Software Discovery · cyberstrikeusAdversaries may attempt to get a listing of applications that are installed on a device.
- ▌ T1430 Location Tracking · cyberstrikeusAdversaries may track a device’s physical location through use of standard operating system APIs via malicious or exploited applications on the compromised device.
- ▌ T1199 Trusted Relationship · cyberstrikeusAdversaries may breach or otherwise leverage organizations who have access to intended victims.
- ▌ T1059 003 Windows Command Shell · cyberstrikeusAdversaries may abuse the Windows command shell for execution.
- ▌ T1072 Software Deployment Tools · cyberstrikeusAdversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
- ▌ T1559 002 Dynamic Data Exchange · cyberstrikeusAdversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands.
- ▌ T1098 004 Ssh Authorized Keys · cyberstrikeusAdversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host.
- ▌ T1098 005 Device Registration · cyberstrikeusAdversaries may register a device to an adversary-controlled account.
- ▌ T1547 004 Winlogon Helper Dll · cyberstrikeusAdversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in.
- ▌ T1574 013 Kernelcallbacktable · cyberstrikeusAdversaries may abuse the <code>KernelCallbackTable</code> of a process to hijack its execution flow in order to run their own payloads.
- ▌ T1611 Escape To Host · cyberstrikeusAdversaries may break out of a container or virtualized environment to gain access to the underlying host.
- ▌ T1078 002 Domain Accounts · cyberstrikeusAdversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
- ▌ T1550 003 Pass The Ticket · cyberstrikeusAdversaries may “pass the ticket” using stolen Kerberos tickets to move laterally within an environment, bypassing normal system access controls.
- ▌ T1578 001 Create Snapshot · cyberstrikeusAn adversary may create a snapshot or data backup within a cloud account to evade defenses.
- ▌ T1601 Modify System Image · cyberstrikeusAdversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves.
- ▌ T1612 Build Image On Host · cyberstrikeusAdversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry.
- ▌ T1679 Selective Exclusion · cyberstrikeusAdversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.
- ▌ T1552 003 Shell History · cyberstrikeusAdversaries may search the command history on compromised systems for insecurely stored credentials.
- ▌ T1552 007 Container API · cyberstrikeusAdversaries may gather credentials via APIs within a containers environment.
- ▌ T1552 008 Chat Messages · cyberstrikeusAdversaries may directly collect unsecured credentials stored or passed through user communication services.
- ▌ T1557 003 Dhcp Spoofing · cyberstrikeusAdversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network.
- ▌ T1558 001 Golden Ticket · cyberstrikeusAdversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket.
- ▌ T1558 002 Silver Ticket · cyberstrikeusAdversaries who have the password hash of a target service account (e.g.
- ▌ T1558 003 Kerberoasting · cyberstrikeusAdversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.
- ▌ T1046 Network Service Discovery · cyberstrikeusAdversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
- ▌ T1201 Password Policy Discovery · cyberstrikeusAdversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment.
- ▌ T1614 System Location Discovery · cyberstrikeusAdversaries may gather information in an attempt to calculate the geographical location of a victim host.
- ▌ T1673 Virtual Machine Discovery · cyberstrikeusAn adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor.
- ▌ T1021 007 Cloud Services · cyberstrikeusAdversaries may log into accessible cloud services within a compromised environment using Valid Accounts that are synchronized with or federated to on-premises user identities.
- ▌ T1020 Automated Exfiltration · cyberstrikeusAdversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.
- ▌ T1498 002 Reflection Amplification · cyberstrikeusAdversaries may attempt to cause a denial of service (DoS) by reflecting a high-volume of network traffic to a target.
- ▌ T1499 002 Service Exhaustion Flood · cyberstrikeusAdversaries may target the different network services provided by systems to conduct a denial of service (DoS).
- ▌ T1565 001 Stored Data Manipulation · cyberstrikeusAdversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data.
- ▌ T1583 002 Dns Server · cyberstrikeusAdversaries may set up their own Domain Name System (DNS) servers that can be used during targeting.