cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ T1553 001 Gatekeeper Bypass · cyberstrikeusAdversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs.
- ▌ T1003 007 Proc Filesystem · cyberstrikeusAdversaries may gather credentials from the proc filesystem or `/proc`.
- ▌ T1556 007 Hybrid Identity · cyberstrikeusAdversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credent...
- ▌ T1558 004 As Rep Roasting · cyberstrikeusAdversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by Password Cracking Kerberos messages.
- ▌ T1069 Permission Groups Discovery · cyberstrikeusAdversaries may attempt to discover group and permission settings.
- ▌ T1120 Peripheral Device Discovery · cyberstrikeusAdversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
- ▌ T1080 Taint Shared Content · cyberstrikeusAdversaries may deliver payloads to remote systems by adding content to shared storage locations, such as network drives or internal code repositories.
- ▌ T1056 004 Credential API Hooking · cyberstrikeusAdversaries may hook into Windows application programming interface (API) functions and Linux system functions to collect user credentials.
- ▌ T1114 001 Local Email Collection · cyberstrikeusAdversaries may target user email on local systems to collect sensitive information.
- ▌ T1213 005 Messaging Applications · cyberstrikeusAdversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information.
- ▌ T1567 001 Exfiltration To Code Repository · cyberstrikeusAdversaries may exfiltrate data to a code repository rather than over their primary command and control channel.
- ▌ T1001 002 Steganography · cyberstrikeusAdversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult.
- ▌ T1008 Fallback Channels · cyberstrikeusAdversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thre
- ▌ T1071 001 Web Protocols · cyberstrikeusAdversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
- ▌ T1219 001 Ide Tunneling · cyberstrikeusAdversaries may abuse Integrated Development Environment (IDE) software with remote development features to establish an interactive command and control channel on target systems within a network.
- ▌ T1568 001 Fast Flux Dns · cyberstrikeusAdversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution.
- ▌ T1571 Non Standard Port · cyberstrikeusAdversaries may communicate using a protocol and port pairing that are typically not associated.
- ▌ T1573 Encrypted Channel · cyberstrikeusAdversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
- ▌ T1583 006 Web Services · cyberstrikeusAdversaries may register for web services that can be used during targeting.
- ▌ T1583 008 Malvertising · cyberstrikeusAdversaries may purchase online advertisements that can be abused to distribute malware to victims.
- ▌ T1584 006 Web Services · cyberstrikeusAdversaries may compromise access to third-party web services that can be used during targeting.
- ▌ T1595 001 Scanning Ip Blocks · cyberstrikeusAdversaries may scan victim IP blocks to gather information that can be used during targeting.
- ▌ T1598 003 Spearphishing Link · cyberstrikeusAdversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting.
- ▌ Awareness And Training Pr At Awareness And Training · cyberstrikeusThe organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks
- ▌ Identity Management Authentication And Access Control Pr Ac · cyberstrikeusIdentity Management, Authentication and Access Control
- ▌
- ▌ Incident Recovery Plan Execution Rc Rp Incident Recovery Pla · cyberstrikeusRestoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents
- ▌ Ac 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] access control policy that: Procedures to facilitate the implemen
- ▌ Ac 3 14 Individual Access · cyberstrikeusProvide [organization-defined] to enable individuals to have access to the following elements of their personally identifiable information: [organizat
- ▌
- ▌ Ac 3 9 Controlled Release · cyberstrikeusRelease information outside of the system only if: The receiving [organization-defined] provides [organization-defined] ; and [organization-defined] a
- ▌ Ac 4 2 Processing Domains · cyberstrikeusUse protected processing domains to enforce [organization-defined] as a basis for flow control decisions.
- ▌ Ac 4 25 Data Sanitization · cyberstrikeusWhen transferring information between different security domains, sanitize data to minimize [organization-defined] in accordance with [organization-de
- ▌ Au 8 Time Stamps · cyberstrikeusUse internal system clocks to generate time stamps for audit records;
- ▌ Ir 4 6 Insider Threats · cyberstrikeusImplement an incident handling capability for incidents involving insider threats.
- ▌ Ir 6 Incident Reporting · cyberstrikeusRequire personnel to report suspected incidents to the organizational incident response capability within [organization-defined] ;
- ▌
- ▌ Pl 4 1 Social Media And External Siteapplication Usage Restr · cyberstrikeusInclude in the rules of behavior, restrictions on: Use of social media, social networking sites, and external sites/applications; Posting organization
- ▌ Ps 6 Access Agreements · cyberstrikeusDevelop and document access agreements for organizational systems;
- ▌ Ra 5 5 Privileged Access · cyberstrikeusImplement privileged access authorization to [organization-defined] for [organization-defined].
- ▌ Ra 9 Criticality Analysis · cyberstrikeusIdentify critical system components and functions by performing a criticality analysis for [organization-defined] at [organization-defined].
- ▌ T0830 Adversary In The Middle · cyberstrikeusAdversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks.
- ▌ T0823 Graphical User Interface · cyberstrikeusAdversaries may attempt to gain access to a machine via a Graphical User Interface (GUI) to enhance execution capabilities.
- ▌ T0817 Drive By Compromise · cyberstrikeusAdversaries may gain access to a system during a drive-by compromise, when a user visits a website as part of a regular browsing session.
- ▌ T0860 Wireless Compromise · cyberstrikeusAdversaries may perform wireless compromise as a method of gaining communications and unauthorized access to a wireless network.
- ▌ T0873 Project File Infection · cyberstrikeusAdversaries may attempt to infect project files with malicious code.
- ▌ T1516 Input Injection · cyberstrikeusA malicious application can inject input to the user interface to mimic user interaction through the abuse of Android's accessibility APIs.
- ▌ T1098 002 Additional Email Delegate Permissions · cyberstrikeusAdversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account.
- ▌ T1547 001 Registry Run Keys Startup Folder · cyberstrikeusAdversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
- ▌ T1547 005 Security Support Provider · cyberstrikeusAdversaries may abuse security support providers (SSPs) to execute DLLs when the system boots.
- ▌ T1574 005 Executable Installer File Permissions Weakness · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking the binaries used by an installer.
- ▌ T1574 007 Path Interception By Path Environment Variable · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking environment variables used to load libraries.
- ▌ T1574 010 Services File Permissions Weakness · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking the binaries used by services.
- ▌ T1671 Cloud Application Integration · cyberstrikeusAdversaries may achieve persistence by leveraging OAuth application integrations in a software-as-a-service environment.
- ▌ T1546 007 Netsh Helper Dll · cyberstrikeusAdversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.
- ▌ T1027 013 Encryptedencoded File · cyberstrikeusAdversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
- ▌ T1036 007 Double File Extension · cyberstrikeusAdversaries may abuse a double extension in the filename as a means of masquerading the true file type.
- ▌ T1070 003 Clear Command History · cyberstrikeusIn addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
- ▌ T1134 Access Token Manipulation · cyberstrikeusAdversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
- ▌ T1134 005 Sid History Injection · cyberstrikeusAdversaries may use SID-History Injection to escalate privileges and bypass access controls.
- ▌ T1218 015 Electron Applications · cyberstrikeusAdversaries may abuse components of the Electron framework to execute malicious code.
- ▌ T1578 002 Create Cloud Instance · cyberstrikeusAn adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses.
- ▌ T1578 003 Delete Cloud Instance · cyberstrikeusAn adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence.
- ▌ T1578 004 Revert Cloud Instance · cyberstrikeusAn adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove evidence of their presence.
- ▌ T1599 Network Boundary Bridging · cyberstrikeusAdversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation.
- ▌ T1110 004 Credential Stuffing · cyberstrikeusAdversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap.
- ▌ T1556 002 Password Filter Dll · cyberstrikeusAdversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process to acquire user credentials as they are validated.
- ▌ T1557 Adversary In The Middle · cyberstrikeusAdversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Trans...
- ▌ T1557 002 Arp Cache Poisoning · cyberstrikeusAdversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices.
- ▌ T1518 001 Security Software Discovery · cyberstrikeusAdversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
- ▌ T1039 Data From Network Shared Drive · cyberstrikeusAdversaries may search network shares on computers they have compromised to find files of interest.
- ▌ T1041 Exfiltration Over C2 Channel · cyberstrikeusAdversaries may steal data by exfiltrating it over an existing command and control channel.
- ▌ T1105 Ingress Tool Transfer · cyberstrikeusAdversaries may transfer tools or other files from an external system into a compromised environment.
- ▌ T1132 001 Standard Encoding · cyberstrikeusAdversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect.
- ▌ T1587 Develop Capabilities · cyberstrikeusAdversaries may build capabilities that can be used during targeting.
- ▌ T1591 002 Business Relationships · cyberstrikeusAdversaries may gather information about the victim's business relationships that can be used during targeting.
- ▌ T1595 002 Vulnerability Scanning · cyberstrikeusAdversaries may scan victims for vulnerabilities that can be used during targeting.
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Ac 16 9 Attribute Reassignment Regrading Mechanisms · cyberstrikeusChange security and privacy attributes associated with information only via regrading mechanisms validated using [organization-defined].
- ▌ Ac 2 2 Automated Temporary And Emergency Account Management · cyberstrikeusAutomatically [organization-defined] temporary and emergency accounts after [organization-defined].
- ▌ Ac 24 Access Control Decisions · cyberstrikeus[organization-defined] to ensure [organization-defined] are applied to each access request prior to access enforcement.
- ▌ Ac 4 12 Data Type Identifiers · cyberstrikeusWhen transferring information between different security domains, use [organization-defined] to validate data essential for information flow decisions
- ▌ Ac 4 17 Domain Authentication · cyberstrikeusUniquely identify and authenticate source and destination points by [organization-defined] for information transfer.
- ▌
- ▌ At 2 2 Insider Threat · cyberstrikeusProvide literacy training on recognizing and reporting potential indicators of insider threat.
- ▌ At 6 Training Feedback · cyberstrikeusProvide feedback on organizational training results to the following personnel [organization-defined]: [organization-defined].
- ▌ Cm 4 Impact Analyses · cyberstrikeusAnalyze changes to the system to determine potential security and privacy impacts prior to change implementation.
- ▌ Cp 3 1 Simulated Events · cyberstrikeusIncorporate simulated events into contingency training to facilitate effective response by personnel in crisis situations.
- ▌
- ▌ Ir 8 Incident Response Plan · cyberstrikeusDevelop an incident response plan that: Provides the organization with a roadmap for implementing its incident response capability; Describes the stru
- ▌ Pm 18 Privacy Program Plan · cyberstrikeusDevelop and disseminate an organization-wide privacy program plan that provides an overview of the agency’s privacy program, and: Includes a descripti
- ▌ Pm 23 Data Governance Body · cyberstrikeusEstablish a Data Governance Body consisting of [organization-defined] with [organization-defined].
- ▌ Pm 24 Data Integrity Board · cyberstrikeusEstablish a Data Integrity Board to: Review proposals to conduct or participate in a matching program; and Conduct an annual review of all matching pr
- ▌ Pm 26 Complaint Management · cyberstrikeusImplement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy
- ▌ Ps 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] personnel security policy that: Procedures to facilitate the impl