← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 63 of 72

  1. T1553 001 Gatekeeper Bypass · cyberstrikeus
    Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs.
    0
    installs
  2. T1003 007 Proc Filesystem · cyberstrikeus
    Adversaries may gather credentials from the proc filesystem or `/proc`.
    0
    installs
  3. T1556 007 Hybrid Identity · cyberstrikeus
    Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credent...
    0
    installs
  4. T1558 004 As Rep Roasting · cyberstrikeus
    Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by Password Cracking Kerberos messages.
    0
    installs
  5. T1069 Permission Groups Discovery · cyberstrikeus
    Adversaries may attempt to discover group and permission settings.
    0
    installs
  6. T1120 Peripheral Device Discovery · cyberstrikeus
    Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
    0
    installs
  7. T1080 Taint Shared Content · cyberstrikeus
    Adversaries may deliver payloads to remote systems by adding content to shared storage locations, such as network drives or internal code repositories.
    0
    installs
  8. T1056 004 Credential API Hooking · cyberstrikeus
    Adversaries may hook into Windows application programming interface (API) functions and Linux system functions to collect user credentials.
    0
    installs
  9. T1114 001 Local Email Collection · cyberstrikeus
    Adversaries may target user email on local systems to collect sensitive information.
    0
    installs
  10. T1213 005 Messaging Applications · cyberstrikeus
    Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information.
    0
    installs
  11. T1567 001 Exfiltration To Code Repository · cyberstrikeus
    Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel.
    0
    installs
  12. T1001 002 Steganography · cyberstrikeus
    Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult.
    0
    installs
  13. T1008 Fallback Channels · cyberstrikeus
    Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thre
    0
    installs
  14. T1071 001 Web Protocols · cyberstrikeus
    Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.
    0
    installs
  15. T1219 001 Ide Tunneling · cyberstrikeus
    Adversaries may abuse Integrated Development Environment (IDE) software with remote development features to establish an interactive command and control channel on target systems within a network.
    0
    installs
  16. T1568 001 Fast Flux Dns · cyberstrikeus
    Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution.
    0
    installs
  17. T1571 Non Standard Port · cyberstrikeus
    Adversaries may communicate using a protocol and port pairing that are typically not associated.
    0
    installs
  18. T1573 Encrypted Channel · cyberstrikeus
    Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
    0
    installs
  19. T1583 006 Web Services · cyberstrikeus
    Adversaries may register for web services that can be used during targeting.
    0
    installs
  20. T1583 008 Malvertising · cyberstrikeus
    Adversaries may purchase online advertisements that can be abused to distribute malware to victims.
    0
    installs
  21. T1584 006 Web Services · cyberstrikeus
    Adversaries may compromise access to third-party web services that can be used during targeting.
    0
    installs
  22. T1595 001 Scanning Ip Blocks · cyberstrikeus
    Adversaries may scan victim IP blocks to gather information that can be used during targeting.
    0
    installs
  23. T1598 003 Spearphishing Link · cyberstrikeus
    Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting.
    0
    installs
  24. Awareness And Training Pr At Awareness And Training · cyberstrikeus
    The organization's personnel are provided with cybersecurity awareness and training so that they can perform their cybersecurity-related tasks
    0
    installs
  25. Identity Management Authentication And Access Control Pr Ac · cyberstrikeus
    Identity Management, Authentication and Access Control
    0
    installs
  26. Protective Technology Pr Pt Protective Technology · cyberstrikeus
    Protective Technology
    0
    installs
  27. Incident Recovery Plan Execution Rc Rp Incident Recovery Pla · cyberstrikeus
    Restoration activities are performed to ensure operational availability of systems and services affected by cybersecurity incidents
    0
    installs
  28. Ac 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] access control policy that: Procedures to facilitate the implemen
    0
    installs
  29. Ac 3 14 Individual Access · cyberstrikeus
    Provide [organization-defined] to enable individuals to have access to the following elements of their personally identifiable information: [organizat
    0
    installs
  30. Ac 3 2 Dual Authorization · cyberstrikeus
    Enforce dual authorization for [organization-defined].
    0
    installs
  31. Ac 3 9 Controlled Release · cyberstrikeus
    Release information outside of the system only if: The receiving [organization-defined] provides [organization-defined] ; and [organization-defined] a
    0
    installs
  32. Ac 4 2 Processing Domains · cyberstrikeus
    Use protected processing domains to enforce [organization-defined] as a basis for flow control decisions.
    0
    installs
  33. Ac 4 25 Data Sanitization · cyberstrikeus
    When transferring information between different security domains, sanitize data to minimize [organization-defined] in accordance with [organization-de
    0
    installs
  34. Au 8 Time Stamps · cyberstrikeus
    Use internal system clocks to generate time stamps for audit records;
    0
    installs
  35. Ir 4 6 Insider Threats · cyberstrikeus
    Implement an incident handling capability for incidents involving insider threats.
    0
    installs
  36. Ir 6 Incident Reporting · cyberstrikeus
    Require personnel to report suspected incidents to the organizational incident response capability within [organization-defined] ;
    0
    installs
  37. Pl 3 System Security Plan Update · cyberstrikeus
    System Security Plan Update
    0
    installs
  38. Pl 4 1 Social Media And External Siteapplication Usage Restr · cyberstrikeus
    Include in the rules of behavior, restrictions on: Use of social media, social networking sites, and external sites/applications; Posting organization
    0
    installs
  39. Ps 6 Access Agreements · cyberstrikeus
    Develop and document access agreements for organizational systems;
    0
    installs
  40. Ra 5 5 Privileged Access · cyberstrikeus
    Implement privileged access authorization to [organization-defined] for [organization-defined].
    0
    installs
  41. Ra 9 Criticality Analysis · cyberstrikeus
    Identify critical system components and functions by performing a criticality analysis for [organization-defined] at [organization-defined].
    0
    installs
  42. T0830 Adversary In The Middle · cyberstrikeus
    Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks.
    0
    installs
  43. T0823 Graphical User Interface · cyberstrikeus
    Adversaries may attempt to gain access to a machine via a Graphical User Interface (GUI) to enhance execution capabilities.
    0
    installs
  44. T0817 Drive By Compromise · cyberstrikeus
    Adversaries may gain access to a system during a drive-by compromise, when a user visits a website as part of a regular browsing session.
    0
    installs
  45. T0860 Wireless Compromise · cyberstrikeus
    Adversaries may perform wireless compromise as a method of gaining communications and unauthorized access to a wireless network.
    0
    installs
  46. T0873 Project File Infection · cyberstrikeus
    Adversaries may attempt to infect project files with malicious code.
    0
    installs
  47. T1516 Input Injection · cyberstrikeus
    A malicious application can inject input to the user interface to mimic user interaction through the abuse of Android's accessibility APIs.
    0
    installs
  48. T1098 002 Additional Email Delegate Permissions · cyberstrikeus
    Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account.
    0
    installs
  49. T1547 001 Registry Run Keys Startup Folder · cyberstrikeus
    Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
    0
    installs
  50. T1547 005 Security Support Provider · cyberstrikeus
    Adversaries may abuse security support providers (SSPs) to execute DLLs when the system boots.
    0
    installs
  51. T1574 005 Executable Installer File Permissions Weakness · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking the binaries used by an installer.
    0
    installs
  52. T1574 007 Path Interception By Path Environment Variable · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries.
    0
    installs
  53. T1574 010 Services File Permissions Weakness · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking the binaries used by services.
    0
    installs
  54. T1671 Cloud Application Integration · cyberstrikeus
    Adversaries may achieve persistence by leveraging OAuth application integrations in a software-as-a-service environment.
    0
    installs
  55. T1546 007 Netsh Helper Dll · cyberstrikeus
    Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.
    0
    installs
  56. T1027 013 Encryptedencoded File · cyberstrikeus
    Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
    0
    installs
  57. T1036 007 Double File Extension · cyberstrikeus
    Adversaries may abuse a double extension in the filename as a means of masquerading the true file type.
    0
    installs
  58. T1070 003 Clear Command History · cyberstrikeus
    In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
    0
    installs
  59. T1134 Access Token Manipulation · cyberstrikeus
    Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
    0
    installs
  60. T1134 005 Sid History Injection · cyberstrikeus
    Adversaries may use SID-History Injection to escalate privileges and bypass access controls.
    0
    installs
  61. T1218 015 Electron Applications · cyberstrikeus
    Adversaries may abuse components of the Electron framework to execute malicious code.
    0
    installs
  62. T1578 002 Create Cloud Instance · cyberstrikeus
    An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses.
    0
    installs
  63. T1578 003 Delete Cloud Instance · cyberstrikeus
    An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence.
    0
    installs
  64. T1578 004 Revert Cloud Instance · cyberstrikeus
    An adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove evidence of their presence.
    0
    installs
  65. T1599 Network Boundary Bridging · cyberstrikeus
    Adversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation.
    0
    installs
  66. T1110 004 Credential Stuffing · cyberstrikeus
    Adversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap.
    0
    installs
  67. T1556 002 Password Filter Dll · cyberstrikeus
    Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process to acquire user credentials as they are validated.
    0
    installs
  68. T1557 Adversary In The Middle · cyberstrikeus
    Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Trans...
    0
    installs
  69. T1557 002 Arp Cache Poisoning · cyberstrikeus
    Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices.
    0
    installs
  70. T1518 001 Security Software Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
    0
    installs
  71. T1039 Data From Network Shared Drive · cyberstrikeus
    Adversaries may search network shares on computers they have compromised to find files of interest.
    0
    installs
  72. T1041 Exfiltration Over C2 Channel · cyberstrikeus
    Adversaries may steal data by exfiltrating it over an existing command and control channel.
    0
    installs
  73. T1105 Ingress Tool Transfer · cyberstrikeus
    Adversaries may transfer tools or other files from an external system into a compromised environment.
    0
    installs
  74. T1132 001 Standard Encoding · cyberstrikeus
    Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect.
    0
    installs
  75. T1587 Develop Capabilities · cyberstrikeus
    Adversaries may build capabilities that can be used during targeting.
    0
    installs
  76. T1591 002 Business Relationships · cyberstrikeus
    Adversaries may gather information about the victim's business relationships that can be used during targeting.
    0
    installs
  77. T1595 002 Vulnerability Scanning · cyberstrikeus
    Adversaries may scan victims for vulnerabilities that can be used during targeting.
    0
    installs
  78. Sp 800 171 03 01 13 030113 · cyberstrikeus
    03.01.13
    0
    installs
  79. Sp 800 171 03 01 14 030114 · cyberstrikeus
    03.01.14
    0
    installs
  80. Sp 800 171 03 01 15 030115 · cyberstrikeus
    03.01.15
    0
    installs
  81. Sp 800 171 03 01 17 030117 · cyberstrikeus
    03.01.17
    0
    installs
  82. Sp 800 171 03 01 19 030119 · cyberstrikeus
    03.01.19
    0
    installs
  83. Sp 800 171 03 01 21 030121 · cyberstrikeus
    03.01.21
    0
    installs
  84. Ac 16 9 Attribute Reassignment Regrading Mechanisms · cyberstrikeus
    Change security and privacy attributes associated with information only via regrading mechanisms validated using [organization-defined].
    0
    installs
  85. Ac 2 2 Automated Temporary And Emergency Account Management · cyberstrikeus
    Automatically [organization-defined] temporary and emergency accounts after [organization-defined].
    0
    installs
  86. Ac 24 Access Control Decisions · cyberstrikeus
    [organization-defined] to ensure [organization-defined] are applied to each access request prior to access enforcement.
    0
    installs
  87. Ac 4 12 Data Type Identifiers · cyberstrikeus
    When transferring information between different security domains, use [organization-defined] to validate data essential for information flow decisions
    0
    installs
  88. Ac 4 17 Domain Authentication · cyberstrikeus
    Uniquely identify and authenticate source and destination points by [organization-defined] for information transfer.
    0
    installs
  89. Ac 7 1 Automatic Account Lock · cyberstrikeus
    Automatic Account Lock
    0
    installs
  90. At 2 2 Insider Threat · cyberstrikeus
    Provide literacy training on recognizing and reporting potential indicators of insider threat.
    0
    installs
  91. At 6 Training Feedback · cyberstrikeus
    Provide feedback on organizational training results to the following personnel [organization-defined]: [organization-defined].
    0
    installs
  92. Cm 4 Impact Analyses · cyberstrikeus
    Analyze changes to the system to determine potential security and privacy impacts prior to change implementation.
    0
    installs
  93. Cp 3 1 Simulated Events · cyberstrikeus
    Incorporate simulated events into contingency training to facilitate effective response by personnel in crisis situations.
    0
    installs
  94. Ir 6 1 Automated Reporting · cyberstrikeus
    Report incidents using [organization-defined].
    0
    installs
  95. Ir 8 Incident Response Plan · cyberstrikeus
    Develop an incident response plan that: Provides the organization with a roadmap for implementing its incident response capability; Describes the stru
    0
    installs
  96. Pm 18 Privacy Program Plan · cyberstrikeus
    Develop and disseminate an organization-wide privacy program plan that provides an overview of the agency’s privacy program, and: Includes a descripti
    0
    installs
  97. Pm 23 Data Governance Body · cyberstrikeus
    Establish a Data Governance Body consisting of [organization-defined] with [organization-defined].
    0
    installs
  98. Pm 24 Data Integrity Board · cyberstrikeus
    Establish a Data Integrity Board to: Review proposals to conduct or participate in a matching program; and Conduct an annual review of all matching pr
    0
    installs
  99. Pm 26 Complaint Management · cyberstrikeus
    Implement a process for receiving and responding to complaints, concerns, or questions from individuals about the organizational security and privacy
    0
    installs
  100. Ps 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] personnel security policy that: Procedures to facilitate the impl
    0
    installs