← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 61 of 72

  1. Sa 5 1 Functional Properties Of Security Controls · cyberstrikeus
    Functional Properties of Security Controls
    0
    installs
  2. Sa 8 3 Modularity And Layering · cyberstrikeus
    Implement the security design principles of modularity and layering in [organization-defined].
    0
    installs
  3. Sc 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] system and communications protection policy that: Procedures to f
    0
    installs
  4. Sc 23 Session Authenticity · cyberstrikeus
    Protect the authenticity of communications sessions.
    0
    installs
  5. Sc 3 5 Layered Structures · cyberstrikeus
    Implement security functions as a layered structure minimizing interactions between layers of the design and avoiding any dependence by lower layers o
    0
    installs
  6. Sc 31 2 Maximum Bandwidth · cyberstrikeus
    Reduce the maximum bandwidth for identified covert [organization-defined] channels to [organization-defined].
    0
    installs
  7. Sc 37 Out Of Band Channels · cyberstrikeus
    Employ the following out-of-band channels for the physical delivery or electronic transmission of [organization-defined] to [organization-defined]: [o
    0
    installs
  8. Sc 6 Resource Availability · cyberstrikeus
    Protect the availability of resources by allocating [organization-defined] by [organization-defined].
    0
    installs
  9. Si 13 1 Transferring Component Responsibilities · cyberstrikeus
    Take system components out of service by transferring component responsibilities to substitute components no later than [organization-defined] of mean
    0
    installs
  10. Si 3 Malicious Code Protection · cyberstrikeus
    Implement [organization-defined] malicious code protection mechanisms at system entry and exit points to detect and eradicate malicious code;
    0
    installs
  11. Si 4 12 Automated Organization Generated Alerts · cyberstrikeus
    Alert [organization-defined] using [organization-defined] when the following indications of inappropriate or unusual activities with security or priva
    0
    installs
  12. Si 7 8 Auditing Capability For Significant Events · cyberstrikeus
    Upon detection of a potential integrity violation, provide the capability to audit the event and initiate the following actions: [organization-defined
    0
    installs
  13. Sr 11 1 Anti Counterfeit Training · cyberstrikeus
    Train [organization-defined] to detect counterfeit system components (including hardware, software, and firmware).
    0
    installs
  14. Sr 11 3 Anti Counterfeit Scanning · cyberstrikeus
    Scan for counterfeit system components [organization-defined].
    0
    installs
  15. Sr 4 3 Validate As Genuine And Not Altered · cyberstrikeus
    Employ the following controls to validate that the system or system component received is genuine and has not been altered: [organization-defined].
    0
    installs
  16. Cis Docker V160 2 10 · cyberstrikeus
    Ensure the default cgroup usage has been confirmed
    0
    installs
  17. Cis Docker V160 2 11 · cyberstrikeus
    Ensure base device size is not changed until needed
    0
    installs
  18. Cis Docker V160 2 12 · cyberstrikeus
    Ensure that authorization for Docker client commands is enabled
    0
    installs
  19. Cis Docker V160 2 13 · cyberstrikeus
    Ensure centralized and remote logging is configured
    0
    installs
  20. Cis Docker V160 2 14 · cyberstrikeus
    Ensure containers are restricted from acquiring new privileges
    0
    installs
  21. Cis Docker V160 2 15 · cyberstrikeus
    Ensure live restore is enabled
    0
    installs
  22. Cis Docker V160 2 16 · cyberstrikeus
    Ensure Userland Proxy is Disabled
    0
    installs
  23. Cis Docker V160 2 17 · cyberstrikeus
    Ensure that a daemon-wide custom seccomp profile is applied if appropriate
    0
    installs
  24. Cis Docker V160 2 18 · cyberstrikeus
    Ensure that experimental features are not implemented in production
    0
    installs
  25. Cis Docker V170 2 10 · cyberstrikeus
    Ensure the default cgroup usage has been confirmed
    0
    installs
  26. Cis Docker V170 2 11 · cyberstrikeus
    Ensure base device size is not changed until needed
    0
    installs
  27. Cis Docker V170 2 12 · cyberstrikeus
    Ensure that authorization for Docker client commands is enabled
    0
    installs
  28. Cis Docker V170 2 13 · cyberstrikeus
    Ensure centralized and remote logging is configured
    0
    installs
  29. Cis Docker V170 2 14 · cyberstrikeus
    Ensure containers are restricted from acquiring new privileges
    0
    installs
  30. Cis Docker V170 2 15 · cyberstrikeus
    Ensure live restore is enabled
    0
    installs
  31. Cis Docker V170 2 16 · cyberstrikeus
    Ensure Userland Proxy is Disabled
    0
    installs
  32. Cis Docker V170 2 17 · cyberstrikeus
    Ensure that a daemon-wide custom seccomp profile is applied if appropriate
    0
    installs
  33. Cis Docker V170 2 18 · cyberstrikeus
    Ensure that experimental features are not implemented in production
    0
    installs
  34. Cis Docker V170 3 10 · cyberstrikeus
    Ensure that TLS CA certificate file permissions are set to 444 or more restrictively
    0
    installs
  35. Cis Docker V170 3 11 · cyberstrikeus
    Ensure that Docker server certificate file ownership is set to root:root
    0
    installs
  36. Cis Docker V170 3 12 · cyberstrikeus
    Ensure that the Docker server certificate file permissions are set to 444 or more restrictively
    0
    installs
  37. Cis Docker V170 3 13 · cyberstrikeus
    Ensure that the Docker server certificate key file ownership is set to root:root
    0
    installs
  38. Cis Docker V170 3 14 · cyberstrikeus
    Ensure that the Docker server certificate key file permissions are set to 400
    0
    installs
  39. Cis Docker V170 3 15 · cyberstrikeus
    Ensure that the Docker socket file ownership is set to root:docker
    0
    installs
  40. Cis Docker V170 3 16 · cyberstrikeus
    Ensure that the Docker socket file permissions are set to 660 or more restrictively
    0
    installs
  41. Cis Docker V170 3 17 · cyberstrikeus
    Ensure that the daemon.json file ownership is set to root:root
    0
    installs
  42. Cis Docker V170 3 18 · cyberstrikeus
    Ensure that daemon.json file permissions are set to 644 or more restrictive
    0
    installs
  43. Cis Docker V170 3 19 · cyberstrikeus
    Ensure that the /etc/default/docker file ownership is set to root:root
    0
    installs
  44. Cis Docker V170 3 20 · cyberstrikeus
    Ensure that the /etc/default/docker file permissions are set to 644 or more restrictively
    0
    installs
  45. Cis Docker V170 3 21 · cyberstrikeus
    Ensure that the /etc/sysconfig/docker file permissions are set to 644 or more restrictively
    0
    installs
  46. Cis Docker V170 3 22 · cyberstrikeus
    Ensure that the /etc/sysconfig/docker file ownership is set to root:root
    0
    installs
  47. Cis Docker V170 3 23 · cyberstrikeus
    Ensure that the Containerd socket file ownership is set to root:root
    0
    installs
  48. T1589 002 Email Addresses · cyberstrikeus
    Adversaries may gather email addresses that can be used during targeting.
    0
    installs
  49. Adverse Event Analysis De Ae Adverse Event Analysis · cyberstrikeus
    Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
    0
    installs
  50. Supply Chain Risk Management Id Sc Supply Chain Risk Managem · cyberstrikeus
    Supply Chain Risk Management
    0
    installs
  51. Data Security Pr Ds Data Security · cyberstrikeus
    Data are managed consistent with the organization's risk strategy to protect the confidentiality, integrity, and availability of information
    0
    installs
  52. Ac 14 1 Necessary Uses · cyberstrikeus
    Necessary Uses
    0
    installs
  53. Ac 15 Automated Marking · cyberstrikeus
    Automated Marking
    0
    installs
  54. Ac 2 Account Management · cyberstrikeus
    Define and document the types of accounts allowed and specifically prohibited for use within the system;
    0
    installs
  55. Ac 25 Reference Monitor · cyberstrikeus
    Implement a reference monitor for [organization-defined] that is tamperproof, always invoked, and small enough to be subject to analysis and testing,
    0
    installs
  56. Ac 3 Access Enforcement · cyberstrikeus
    Enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
    0
    installs
  57. Ma 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] maintenance policy that: Procedures to facilitate the implementat
    0
    installs
  58. Ma 4 1 Logging And Review · cyberstrikeus
    Log [organization-defined] for nonlocal maintenance and diagnostic sessions;
    0
    installs
  59. Ma 5 Maintenance Personnel · cyberstrikeus
    Establish a process for maintenance personnel authorization and maintain a list of authorized maintenance organizations or personnel;
    0
    installs
  60. Pl 2 1 Concept Of Operations · cyberstrikeus
    Concept of Operations
    0
    installs
  61. T0802 Automated Collection · cyberstrikeus
    Adversaries may automate collection of industrial environment information using tools or scripts.
    0
    installs
  62. T0856 Spoof Reporting Message · cyberstrikeus
    Adversaries may spoof reporting messages in control system environments for evasion and to impair process control.
    0
    installs
  63. T0858 Change Operating Mode · cyberstrikeus
    Adversaries may change the operating mode of a controller to gain additional access to engineering functions such as Program Download.
    0
    installs
  64. T0871 Execution Through API · cyberstrikeus
    Adversaries may attempt to leverage Application Program Interfaces (APIs) used for communication between control software and the hardware.
    0
    installs
  65. T1451 Sim Card Swap · cyberstrikeus
    Adversaries may gain access to mobile devices through transfers or swaps from victims’ phone numbers to adversary-controlled SIM cards and mobile devices.
    0
    installs
  66. T1655 Masquerading · cyberstrikeus
    Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
    0
    installs
  67. T1418 Software Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of applications that are installed on a device.
    0
    installs
  68. T1430 Location Tracking · cyberstrikeus
    Adversaries may track a device’s physical location through use of standard operating system APIs via malicious or exploited applications on the compromised device.
    0
    installs
  69. T1199 Trusted Relationship · cyberstrikeus
    Adversaries may breach or otherwise leverage organizations who have access to intended victims.
    0
    installs
  70. T1059 003 Windows Command Shell · cyberstrikeus
    Adversaries may abuse the Windows command shell for execution.
    0
    installs
  71. T1072 Software Deployment Tools · cyberstrikeus
    Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
    0
    installs
  72. T1559 002 Dynamic Data Exchange · cyberstrikeus
    Adversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands.
    0
    installs
  73. T1098 004 Ssh Authorized Keys · cyberstrikeus
    Adversaries may modify the SSH <code>authorized_keys</code> file to maintain persistence on a victim host.
    0
    installs
  74. T1098 005 Device Registration · cyberstrikeus
    Adversaries may register a device to an adversary-controlled account.
    0
    installs
  75. T1547 004 Winlogon Helper Dll · cyberstrikeus
    Adversaries may abuse features of Winlogon to execute DLLs and/or executables when a user logs in.
    0
    installs
  76. T1574 013 Kernelcallbacktable · cyberstrikeus
    Adversaries may abuse the <code>KernelCallbackTable</code> of a process to hijack its execution flow in order to run their own payloads.
    0
    installs
  77. T1611 Escape To Host · cyberstrikeus
    Adversaries may break out of a container or virtualized environment to gain access to the underlying host.
    0
    installs
  78. T1078 002 Domain Accounts · cyberstrikeus
    Adversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
    0
    installs
  79. T1550 003 Pass The Ticket · cyberstrikeus
    Adversaries may “pass the ticket” using stolen Kerberos tickets to move laterally within an environment, bypassing normal system access controls.
    0
    installs
  80. T1578 001 Create Snapshot · cyberstrikeus
    An adversary may create a snapshot or data backup within a cloud account to evade defenses.
    0
    installs
  81. T1601 Modify System Image · cyberstrikeus
    Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves.
    0
    installs
  82. T1612 Build Image On Host · cyberstrikeus
    Adversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry.
    0
    installs
  83. T1679 Selective Exclusion · cyberstrikeus
    Adversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.
    0
    installs
  84. T1552 003 Shell History · cyberstrikeus
    Adversaries may search the command history on compromised systems for insecurely stored credentials.
    0
    installs
  85. T1552 007 Container API · cyberstrikeus
    Adversaries may gather credentials via APIs within a containers environment.
    0
    installs
  86. T1552 008 Chat Messages · cyberstrikeus
    Adversaries may directly collect unsecured credentials stored or passed through user communication services.
    0
    installs
  87. T1557 003 Dhcp Spoofing · cyberstrikeus
    Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network.
    0
    installs
  88. T1558 001 Golden Ticket · cyberstrikeus
    Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket.
    0
    installs
  89. T1558 002 Silver Ticket · cyberstrikeus
    Adversaries who have the password hash of a target service account (e.g.
    0
    installs
  90. T1558 003 Kerberoasting · cyberstrikeus
    Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.
    0
    installs
  91. T1046 Network Service Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
    0
    installs
  92. T1201 Password Policy Discovery · cyberstrikeus
    Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment.
    0
    installs
  93. T1614 System Location Discovery · cyberstrikeus
    Adversaries may gather information in an attempt to calculate the geographical location of a victim host.
    0
    installs
  94. T1673 Virtual Machine Discovery · cyberstrikeus
    An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor.
    0
    installs
  95. T1021 007 Cloud Services · cyberstrikeus
    Adversaries may log into accessible cloud services within a compromised environment using Valid Accounts that are synchronized with or federated to on-premises user identities.
    0
    installs
  96. T1020 Automated Exfiltration · cyberstrikeus
    Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.
    0
    installs
  97. T1498 002 Reflection Amplification · cyberstrikeus
    Adversaries may attempt to cause a denial of service (DoS) by reflecting a high-volume of network traffic to a target.
    0
    installs
  98. T1499 002 Service Exhaustion Flood · cyberstrikeus
    Adversaries may target the different network services provided by systems to conduct a denial of service (DoS).
    0
    installs
  99. T1565 001 Stored Data Manipulation · cyberstrikeus
    Adversaries may insert, delete, or manipulate data at rest in order to influence external outcomes or hide activity, thus threatening the integrity of the data.
    0
    installs
  100. T1583 002 Dns Server · cyberstrikeus
    Adversaries may set up their own Domain Name System (DNS) servers that can be used during targeting.
    0
    installs