← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 62 of 72

  1. T1583 007 Serverless · cyberstrikeus
    Adversaries may purchase and configure serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting.
    0
    installs
  2. T1584 002 Dns Server · cyberstrikeus
    Adversaries may compromise third-party DNS servers that can be used during targeting.
    0
    installs
  3. T1584 007 Serverless · cyberstrikeus
    Adversaries may compromise serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting.
    0
    installs
  4. T1650 Acquire Access · cyberstrikeus
    Adversaries may purchase or otherwise acquire an existing access to a target system or network.
    0
    installs
  5. T1590 004 Network Topology · cyberstrikeus
    Adversaries may gather information about the victim's network topology that can be used during targeting.
    0
    installs
  6. Business Environment Id Be Business Environment · cyberstrikeus
    Business Environment
    0
    installs
  7. Risk Management Strategy Id Rm Risk Management Strategy · cyberstrikeus
    Risk Management Strategy
    0
    installs
  8. Information Protection Processes And Procedures Pr Ip Inform · cyberstrikeus
    Information Protection Processes and Procedures
    0
    installs
  9. Rv 1 1 Rv11 · cyberstrikeus
    Gather information from software acquirers, users, and public sources on potential vulnerabilities in the software and third-party components that the
    0
    installs
  10. Rv 1 2 Rv12 · cyberstrikeus
    Review, analyze, and/or test the software’s code to identify or confirm the presence of previously undetected vulnerabilities.
    0
    installs
  11. Rv 1 3 Rv13 · cyberstrikeus
    Have a policy that addresses vulnerability disclosure and remediation, and implement the roles, responsibilities, and processes needed to support that
    0
    installs
  12. Rv 2 1 Rv21 · cyberstrikeus
    Analyze each vulnerability to gather sufficient information about risk to plan its remediation or other risk response.
    0
    installs
  13. Rv 2 2 Rv22 · cyberstrikeus
    Plan and implement risk responses for vulnerabilities.
    0
    installs
  14. Rv 3 1 Rv31 · cyberstrikeus
    Analyze identified vulnerabilities to determine their root causes.
    0
    installs
  15. Rv 3 2 Rv32 · cyberstrikeus
    Analyze the root causes over time to identify patterns, such as a particular secure coding practice not being followed consistently.
    0
    installs
  16. Rv 3 3 Rv33 · cyberstrikeus
    Review the software for similar vulnerabilities to eradicate a class of vulnerabilities, and proactively fix them rather than waiting for external rep
    0
    installs
  17. Rv 3 4 Rv34 · cyberstrikeus
    Review the SDLC process, and update it if appropriate to prevent (or reduce the likelihood of) the root cause recurring in updates to the software or
    0
    installs
  18. Ac 2 3 Disable Accounts · cyberstrikeus
    Disable accounts within [organization-defined] when the accounts: Have expired; Are no longer associated with a user or individual; Are in violation o
    0
    installs
  19. Cp 9 System Backup · cyberstrikeus
    Conduct backups of user-level information contained in [organization-defined] [organization-defined];
    0
    installs
  20. Ma 2 Controlled Maintenance · cyberstrikeus
    Schedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor speci...
    0
    installs
  21. Ma 3 4 Restricted Tool Use · cyberstrikeus
    Restrict the use of maintenance tools to authorized personnel only.
    0
    installs
  22. Mp 8 Media Downgrading · cyberstrikeus
    Establish [organization-defined] that includes employing downgrading mechanisms with strength and integrity commensurate with the security category...
    0
    installs
  23. Pl 5 Privacy Impact Assessment · cyberstrikeus
    Privacy Impact Assessment
    0
    installs
  24. T0801 Monitor Process State · cyberstrikeus
    Adversaries may gather information about the physical process state.
    0
    installs
  25. T0868 Detect Operating Mode · cyberstrikeus
    Adversaries may gather information about a PLCs or controllers current operating mode.
    0
    installs
  26. T0820 Exploitation For Evasion · cyberstrikeus
    Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection.
    0
    installs
  27. T0807 Command Line Interface · cyberstrikeus
    Adversaries may utilize command-line interfaces (CLIs) to interact with systems and execute commands.
    0
    installs
  28. T1422 002 Wi Fi Discovery · cyberstrikeus
    Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
    0
    installs
  29. T1640 Account Access Removal · cyberstrikeus
    Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
    0
    installs
  30. T1559 001 Component Object Model · cyberstrikeus
    Adversaries may use the Windows Component Object Model (COM) for local code execution.
    0
    installs
  31. T1037 001 Logon Script Windows · cyberstrikeus
    Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence.
    0
    installs
  32. T1037 003 Network Logon Script · cyberstrikeus
    Adversaries may use network logon scripts automatically executed at logon initialization to establish persistence.
    0
    installs
  33. T1133 External Remote Services · cyberstrikeus
    Adversaries may leverage external-facing remote services to initially access and/or persist within a network.
    0
    installs
  34. T1546 018 Python Startup Hooks · cyberstrikeus
    Adversaries may achieve persistence by leveraging Python’s startup mechanisms, including path configuration (`.pth`) files and the `sitecustomize.py` or `usercustomize.py` modules.
    0
    installs
  35. T1546 002 Screensaver · cyberstrikeus
    Adversaries may establish persistence by executing malicious content triggered by user inactivity.
    0
    installs
  36. T1006 Direct Volume Access · cyberstrikeus
    Adversaries may directly access a volume to bypass file access controls and file system monitoring.
    0
    installs
  37. T1027 002 Software Packing · cyberstrikeus
    Adversaries may perform software packing or virtual machine software protection to conceal their code.
    0
    installs
  38. T1027 011 Fileless Storage · cyberstrikeus
    Adversaries may store data in "fileless" formats to conceal malicious activity from defenses.
    0
    installs
  39. T1027 014 Polymorphic Code · cyberstrikeus
    Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection.
    0
    installs
  40. T1070 010 Relocate Malware · cyberstrikeus
    Once a payload is delivered, adversaries may reproduce copies of the same malware on the victim system to remove evidence of their presence and/or avoid defenses.
    0
    installs
  41. T1078 001 Default Accounts · cyberstrikeus
    Adversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
    0
    installs
  42. T1480 Execution Guardrails · cyberstrikeus
    Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
    0
    installs
  43. T1480 002 Mutual Exclusion · cyberstrikeus
    Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
    0
    installs
  44. T1548 006 Tcc Manipulation · cyberstrikeus
    Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions.
    0
    installs
  45. T1562 010 Downgrade Attack · cyberstrikeus
    Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls.
    0
    installs
  46. T1564 009 Resource Forking · cyberstrikeus
    Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications.
    0
    installs
  47. T1578 Modify Cloud Compute Infrastructure · cyberstrikeus
    An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses.
    0
    installs
  48. T1600 001 Reduce Key Space · cyberstrikeus
    Adversaries may reduce the level of effort required to decrypt data transmitted over the network by reducing the cipher strength of encrypted communications.
    0
    installs
  49. T1033 System Owneruser Discovery · cyberstrikeus
    Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
    0
    installs
  50. T1049 System Network Connections Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
    0
    installs
  51. T1025 Data From Removable Media · cyberstrikeus
    Adversaries may search connected removable media on computers they have compromised to find files of interest.
    0
    installs
  52. T1114 003 Email Forwarding Rule · cyberstrikeus
    Adversaries may setup email forwarding rules to collect sensitive information.
    0
    installs
  53. T1185 Browser Session Hijacking · cyberstrikeus
    Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various brow...
    0
    installs
  54. T1213 004 Customer Relationship Management Software · cyberstrikeus
    Adversaries may leverage Customer Relationship Management (CRM) software to mine valuable information.
    0
    installs
  55. T1020 001 Traffic Duplication · cyberstrikeus
    Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure.
    0
    installs
  56. T1001 Data Obfuscation · cyberstrikeus
    Adversaries may obfuscate command and control traffic to make it more difficult to detect.
    0
    installs
  57. T1565 003 Runtime Data Manipulation · cyberstrikeus
    Adversaries may modify systems in order to manipulate the data as it is accessed and displayed to an end user, thus threatening the integrity of the data.
    0
    installs
  58. T1608 002 Upload Tool · cyberstrikeus
    Adversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting.
    0
    installs
  59. T1608 005 Link Target · cyberstrikeus
    Adversaries may put in place resources that are referenced by a link that can be used during targeting.
    0
    installs
  60. T1590 001 Domain Properties · cyberstrikeus
    Adversaries may gather information about the victim's network domain(s) that can be used during targeting.
    0
    installs
  61. T1593 003 Code Repositories · cyberstrikeus
    Adversaries may search public code repositories for information about victims that can be used during targeting.
    0
    installs
  62. T1595 003 Wordlist Scanning · cyberstrikeus
    Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques.
    0
    installs
  63. T1597 Search Closed Sources · cyberstrikeus
    Adversaries may search and gather information about victims from closed (e.g., paid, private, or otherwise not freely available) sources that can be used during targeting.
    0
    installs
  64. Continuous Monitoring De Cm Continuous Monitoring · cyberstrikeus
    Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events
    0
    installs
  65. Roles Responsibilities And Authorities Gv Rr Roles Responsib · cyberstrikeus
    Cybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established an
    0
    installs
  66. Incident Recovery Communication Rc Co Incident Recovery Comm · cyberstrikeus
    Restoration activities are coordinated with internal and external parties
    0
    installs
  67. Ac 12 Session Termination · cyberstrikeus
    Automatically terminate a user session after [organization-defined].
    0
    installs
  68. Ac 2 11 Usage Conditions · cyberstrikeus
    Enforce [organization-defined] for [organization-defined].
    0
    installs
  69. Ac 2 5 Inactivity Logout · cyberstrikeus
    Require that users log out when [organization-defined].
    0
    installs
  70. Ac 21 Information Sharing · cyberstrikeus
    Enable authorized users to determine whether access authorizations assigned to a sharing partner match the information’s access and use restriction...
    0
    installs
  71. Ac 5 Separation Of Duties · cyberstrikeus
    Identify and document [organization-defined] ;
    0
    installs
  72. Ir 4 Incident Handling · cyberstrikeus
    Implement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and ...
    0
    installs
  73. Mp 6 Media Sanitization · cyberstrikeus
    Sanitize [organization-defined] prior to disposal, release out of organizational control, or release for reuse using [organization-defined] ;
    0
    installs
  74. Pl 2 2 Functional Architecture · cyberstrikeus
    Functional Architecture
    0
    installs
  75. Pm 5 System Inventory · cyberstrikeus
    Develop and update [organization-defined] an inventory of organizational systems.
    0
    installs
  76. T0893 Data From Local System · cyberstrikeus
    Adversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases.
    0
    installs
  77. T0846 Remote System Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for subsequent Lateral Movement or Discovery techniques.
    0
    installs
  78. T0872 Indicator Removal On Host · cyberstrikeus
    Adversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks.
    0
    installs
  79. T0843 Program Download · cyberstrikeus
    Adversaries may perform a program download to transfer a user program to a controller.
    0
    installs
  80. T1627 001 Geofencing · cyberstrikeus
    Adversaries may use a device’s geographical location to limit certain malicious behaviors.
    0
    installs
  81. T1628 Hide Artifacts · cyberstrikeus
    Adversaries may attempt to hide artifacts associated with their behaviors to evade detection.
    0
    installs
  82. T1634 001 Keychain · cyberstrikeus
    Adversaries may collect keychain data from an iOS device to acquire credentials.
    0
    installs
  83. T1636 Protected User Data · cyberstrikeus
    Adversaries may utilize standard operating system APIs to collect data from permission-backed data stores on a device, such as the calendar or contact list.
    0
    installs
  84. T1566 002 Spearphishing Link · cyberstrikeus
    Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
    0
    installs
  85. T1559 Inter Process Communication · cyberstrikeus
    Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution.
    0
    installs
  86. T1675 Esxi Administration Command · cyberstrikeus
    Adversaries may abuse ESXi administration services to execute commands on guest machines hosted within an ESXi virtual environment.
    0
    installs
  87. T1677 Poisoned Pipeline Execution · cyberstrikeus
    Adversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious code into the build process.
    0
    installs
  88. T1505 Server Software Component · cyberstrikeus
    Adversaries may abuse legitimate extensible development features of servers to establish persistent access to systems.
    0
    installs
  89. T1505 001 SQL Stored Procedures · cyberstrikeus
    Adversaries may abuse SQL stored procedures to establish persistent access to systems.
    0
    installs
  90. T1505 005 Terminal Services Dll · cyberstrikeus
    Adversaries may abuse components of Terminal Services to enable persistent access to systems.
    0
    installs
  91. T1547 009 Shortcut Modification · cyberstrikeus
    Adversaries may create or modify shortcuts that can execute a program during system boot or user login.
    0
    installs
  92. T1547 013 Xdg Autostart Entries · cyberstrikeus
    Adversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user’s desktop environment is loaded at login.
    0
    installs
  93. T1546 009 Appcert Dlls · cyberstrikeus
    Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes.
    0
    installs
  94. T1546 010 Appinit Dlls · cyberstrikeus
    Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.
    0
    installs
  95. T1027 008 Stripped Payloads · cyberstrikeus
    Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information.
    0
    installs
  96. T1027 009 Embedded Payloads · cyberstrikeus
    Adversaries may embed payloads within other files to conceal malicious content from defenses.
    0
    installs
  97. T1055 012 Process Hollowing · cyberstrikeus
    Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses.
    0
    installs
  98. T1070 009 Clear Persistence · cyberstrikeus
    Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity.
    0
    installs
  99. T1220 Xsl Script Processing · cyberstrikeus
    Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files.
    0
    installs
  100. T1497 003 Time Based Checks · cyberstrikeus
    Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.
    0
    installs