cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ T1583 007 Serverless · cyberstrikeusAdversaries may purchase and configure serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting.
- ▌ T1584 002 Dns Server · cyberstrikeusAdversaries may compromise third-party DNS servers that can be used during targeting.
- ▌ T1584 007 Serverless · cyberstrikeusAdversaries may compromise serverless cloud infrastructure, such as Cloudflare Workers, AWS Lambda functions, or Google Apps Scripts, that can be used during targeting.
- ▌ T1650 Acquire Access · cyberstrikeusAdversaries may purchase or otherwise acquire an existing access to a target system or network.
- ▌ T1590 004 Network Topology · cyberstrikeusAdversaries may gather information about the victim's network topology that can be used during targeting.
- ▌
- ▌
- ▌ Information Protection Processes And Procedures Pr Ip Inform · cyberstrikeusInformation Protection Processes and Procedures
- ▌ Rv 1 1 Rv11 · cyberstrikeusGather information from software acquirers, users, and public sources on potential vulnerabilities in the software and third-party components that the
- ▌ Rv 1 2 Rv12 · cyberstrikeusReview, analyze, and/or test the software’s code to identify or confirm the presence of previously undetected vulnerabilities.
- ▌ Rv 1 3 Rv13 · cyberstrikeusHave a policy that addresses vulnerability disclosure and remediation, and implement the roles, responsibilities, and processes needed to support that
- ▌ Rv 2 1 Rv21 · cyberstrikeusAnalyze each vulnerability to gather sufficient information about risk to plan its remediation or other risk response.
- ▌
- ▌
- ▌ Rv 3 2 Rv32 · cyberstrikeusAnalyze the root causes over time to identify patterns, such as a particular secure coding practice not being followed consistently.
- ▌ Rv 3 3 Rv33 · cyberstrikeusReview the software for similar vulnerabilities to eradicate a class of vulnerabilities, and proactively fix them rather than waiting for external rep
- ▌ Rv 3 4 Rv34 · cyberstrikeusReview the SDLC process, and update it if appropriate to prevent (or reduce the likelihood of) the root cause recurring in updates to the software or
- ▌ Ac 2 3 Disable Accounts · cyberstrikeusDisable accounts within [organization-defined] when the accounts: Have expired; Are no longer associated with a user or individual; Are in violation o
- ▌ Cp 9 System Backup · cyberstrikeusConduct backups of user-level information contained in [organization-defined] [organization-defined];
- ▌ Ma 2 Controlled Maintenance · cyberstrikeusSchedule, document, and review records of maintenance, repair, and replacement on system components in accordance with manufacturer or vendor speci...
- ▌ Ma 3 4 Restricted Tool Use · cyberstrikeusRestrict the use of maintenance tools to authorized personnel only.
- ▌ Mp 8 Media Downgrading · cyberstrikeusEstablish [organization-defined] that includes employing downgrading mechanisms with strength and integrity commensurate with the security category...
- ▌
- ▌ T0801 Monitor Process State · cyberstrikeusAdversaries may gather information about the physical process state.
- ▌ T0868 Detect Operating Mode · cyberstrikeusAdversaries may gather information about a PLCs or controllers current operating mode.
- ▌ T0820 Exploitation For Evasion · cyberstrikeusAdversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection.
- ▌ T0807 Command Line Interface · cyberstrikeusAdversaries may utilize command-line interfaces (CLIs) to interact with systems and execute commands.
- ▌ T1422 002 Wi Fi Discovery · cyberstrikeusAdversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
- ▌ T1640 Account Access Removal · cyberstrikeusAdversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
- ▌ T1559 001 Component Object Model · cyberstrikeusAdversaries may use the Windows Component Object Model (COM) for local code execution.
- ▌ T1037 001 Logon Script Windows · cyberstrikeusAdversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence.
- ▌ T1037 003 Network Logon Script · cyberstrikeusAdversaries may use network logon scripts automatically executed at logon initialization to establish persistence.
- ▌ T1133 External Remote Services · cyberstrikeusAdversaries may leverage external-facing remote services to initially access and/or persist within a network.
- ▌ T1546 018 Python Startup Hooks · cyberstrikeusAdversaries may achieve persistence by leveraging Python’s startup mechanisms, including path configuration (`.pth`) files and the `sitecustomize.py` or `usercustomize.py` modules.
- ▌ T1546 002 Screensaver · cyberstrikeusAdversaries may establish persistence by executing malicious content triggered by user inactivity.
- ▌ T1006 Direct Volume Access · cyberstrikeusAdversaries may directly access a volume to bypass file access controls and file system monitoring.
- ▌ T1027 002 Software Packing · cyberstrikeusAdversaries may perform software packing or virtual machine software protection to conceal their code.
- ▌ T1027 011 Fileless Storage · cyberstrikeusAdversaries may store data in "fileless" formats to conceal malicious activity from defenses.
- ▌ T1027 014 Polymorphic Code · cyberstrikeusAdversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection.
- ▌ T1070 010 Relocate Malware · cyberstrikeusOnce a payload is delivered, adversaries may reproduce copies of the same malware on the victim system to remove evidence of their presence and/or avoid defenses.
- ▌ T1078 001 Default Accounts · cyberstrikeusAdversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
- ▌ T1480 Execution Guardrails · cyberstrikeusAdversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
- ▌ T1480 002 Mutual Exclusion · cyberstrikeusAdversaries may constrain execution or actions based on the presence of a mutex associated with malware.
- ▌ T1548 006 Tcc Manipulation · cyberstrikeusAdversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions.
- ▌ T1562 010 Downgrade Attack · cyberstrikeusAdversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls.
- ▌ T1564 009 Resource Forking · cyberstrikeusAdversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications.
- ▌ T1578 Modify Cloud Compute Infrastructure · cyberstrikeusAn adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses.
- ▌ T1600 001 Reduce Key Space · cyberstrikeusAdversaries may reduce the level of effort required to decrypt data transmitted over the network by reducing the cipher strength of encrypted communications.
- ▌ T1033 System Owneruser Discovery · cyberstrikeusAdversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
- ▌ T1049 System Network Connections Discovery · cyberstrikeusAdversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
- ▌ T1025 Data From Removable Media · cyberstrikeusAdversaries may search connected removable media on computers they have compromised to find files of interest.
- ▌ T1114 003 Email Forwarding Rule · cyberstrikeusAdversaries may setup email forwarding rules to collect sensitive information.
- ▌ T1185 Browser Session Hijacking · cyberstrikeusAdversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various brow...
- ▌ T1213 004 Customer Relationship Management Software · cyberstrikeusAdversaries may leverage Customer Relationship Management (CRM) software to mine valuable information.
- ▌ T1020 001 Traffic Duplication · cyberstrikeusAdversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure.
- ▌ T1001 Data Obfuscation · cyberstrikeusAdversaries may obfuscate command and control traffic to make it more difficult to detect.
- ▌ T1565 003 Runtime Data Manipulation · cyberstrikeusAdversaries may modify systems in order to manipulate the data as it is accessed and displayed to an end user, thus threatening the integrity of the data.
- ▌ T1608 002 Upload Tool · cyberstrikeusAdversaries may upload tools to third-party or adversary controlled infrastructure to make it accessible during targeting.
- ▌ T1608 005 Link Target · cyberstrikeusAdversaries may put in place resources that are referenced by a link that can be used during targeting.
- ▌ T1590 001 Domain Properties · cyberstrikeusAdversaries may gather information about the victim's network domain(s) that can be used during targeting.
- ▌ T1593 003 Code Repositories · cyberstrikeusAdversaries may search public code repositories for information about victims that can be used during targeting.
- ▌ T1595 003 Wordlist Scanning · cyberstrikeusAdversaries may iteratively probe infrastructure using brute-forcing and crawling techniques.
- ▌ T1597 Search Closed Sources · cyberstrikeusAdversaries may search and gather information about victims from closed (e.g., paid, private, or otherwise not freely available) sources that can be used during targeting.
- ▌ Continuous Monitoring De Cm Continuous Monitoring · cyberstrikeusAssets are monitored to find anomalies, indicators of compromise, and other potentially adverse events
- ▌ Roles Responsibilities And Authorities Gv Rr Roles Responsib · cyberstrikeusCybersecurity roles, responsibilities, and authorities to foster accountability, performance assessment, and continuous improvement are established an
- ▌ Incident Recovery Communication Rc Co Incident Recovery Comm · cyberstrikeusRestoration activities are coordinated with internal and external parties
- ▌ Ac 12 Session Termination · cyberstrikeusAutomatically terminate a user session after [organization-defined].
- ▌
- ▌
- ▌ Ac 21 Information Sharing · cyberstrikeusEnable authorized users to determine whether access authorizations assigned to a sharing partner match the information’s access and use restriction...
- ▌
- ▌ Ir 4 Incident Handling · cyberstrikeusImplement an incident handling capability for incidents that is consistent with the incident response plan and includes preparation, detection and ...
- ▌ Mp 6 Media Sanitization · cyberstrikeusSanitize [organization-defined] prior to disposal, release out of organizational control, or release for reuse using [organization-defined] ;
- ▌
- ▌ Pm 5 System Inventory · cyberstrikeusDevelop and update [organization-defined] an inventory of organizational systems.
- ▌ T0893 Data From Local System · cyberstrikeusAdversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases.
- ▌ T0846 Remote System Discovery · cyberstrikeusAdversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for subsequent Lateral Movement or Discovery techniques.
- ▌ T0872 Indicator Removal On Host · cyberstrikeusAdversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks.
- ▌ T0843 Program Download · cyberstrikeusAdversaries may perform a program download to transfer a user program to a controller.
- ▌ T1627 001 Geofencing · cyberstrikeusAdversaries may use a device’s geographical location to limit certain malicious behaviors.
- ▌ T1628 Hide Artifacts · cyberstrikeusAdversaries may attempt to hide artifacts associated with their behaviors to evade detection.
- ▌ T1634 001 Keychain · cyberstrikeusAdversaries may collect keychain data from an iOS device to acquire credentials.
- ▌ T1636 Protected User Data · cyberstrikeusAdversaries may utilize standard operating system APIs to collect data from permission-backed data stores on a device, such as the calendar or contact list.
- ▌ T1566 002 Spearphishing Link · cyberstrikeusAdversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
- ▌ T1559 Inter Process Communication · cyberstrikeusAdversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution.
- ▌ T1675 Esxi Administration Command · cyberstrikeusAdversaries may abuse ESXi administration services to execute commands on guest machines hosted within an ESXi virtual environment.
- ▌ T1677 Poisoned Pipeline Execution · cyberstrikeusAdversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious code into the build process.
- ▌ T1505 Server Software Component · cyberstrikeusAdversaries may abuse legitimate extensible development features of servers to establish persistent access to systems.
- ▌ T1505 001 SQL Stored Procedures · cyberstrikeusAdversaries may abuse SQL stored procedures to establish persistent access to systems.
- ▌ T1505 005 Terminal Services Dll · cyberstrikeusAdversaries may abuse components of Terminal Services to enable persistent access to systems.
- ▌ T1547 009 Shortcut Modification · cyberstrikeusAdversaries may create or modify shortcuts that can execute a program during system boot or user login.
- ▌ T1547 013 Xdg Autostart Entries · cyberstrikeusAdversaries may add or modify XDG Autostart Entries to execute malicious programs or commands when a user’s desktop environment is loaded at login.
- ▌ T1546 009 Appcert Dlls · cyberstrikeusAdversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes.
- ▌ T1546 010 Appinit Dlls · cyberstrikeusAdversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.
- ▌ T1027 008 Stripped Payloads · cyberstrikeusAdversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information.
- ▌ T1027 009 Embedded Payloads · cyberstrikeusAdversaries may embed payloads within other files to conceal malicious content from defenses.
- ▌ T1055 012 Process Hollowing · cyberstrikeusAdversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses.
- ▌ T1070 009 Clear Persistence · cyberstrikeusAdversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity.
- ▌ T1220 Xsl Script Processing · cyberstrikeusAdversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files.
- ▌ T1497 003 Time Based Checks · cyberstrikeusAdversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.