cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ Ps 4 Personnel Termination · cyberstrikeusUpon termination of individual employment: Disable system access within [organization-defined]; Terminate or revoke any authenticators and credentials
- ▌ Ps 9 Position Descriptions · cyberstrikeusIncorporate security and privacy roles and responsibilities into organizational position descriptions.
- ▌ Sr 4 1 Identity · cyberstrikeusEstablish and maintain unique identification of the following supply chain elements, processes, and personnel associated with the identified system an
- ▌ T0885 Commonly Used Port · cyberstrikeusAdversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection.
- ▌ T0881 Service Stop · cyberstrikeusAdversaries may stop or disable services on a system to render those services unavailable to legitimate users.
- ▌ T0862 Supply Chain Compromise · cyberstrikeusAdversaries may perform supply chain compromise to gain control systems environment access by means of infected products, software, and workflows.
- ▌ T0867 Lateral Tool Transfer · cyberstrikeusAdversaries may transfer tools or other files from one system to another to stage adversary tools or other files over the course of an operation.
- ▌ T0891 Hardcoded Credentials · cyberstrikeusAdversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset.
- ▌ T1624 001 Broadcast Receivers · cyberstrikeusAdversaries may establish persistence using system mechanisms that trigger execution based on specific events.
- ▌ T1635 001 Uri Hijacking · cyberstrikeusAdversaries may register Uniform Resource Identifiers (URIs) to intercept sensitive data.
- ▌ T1643 Generate Traffic From Victim · cyberstrikeusAdversaries may generate outbound traffic from devices.
- ▌ T1521 003 Ssl Pinning · cyberstrikeusAdversaries may use SSL Pinning to protect the C2 traffic from being intercepted and analyzed.
- ▌ T1609 Container Administration Command · cyberstrikeusAdversaries may abuse a container administration service to execute commands within a container.
- ▌ T1098 007 Additional Local Or Domain Groups · cyberstrikeusAn adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or domain.
- ▌ T1548 001 Setuid And Setgid · cyberstrikeusAn adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.
- ▌ T1027 004 Compile After Delivery · cyberstrikeusAdversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code.
- ▌ T1027 007 Dynamic API Resolution · cyberstrikeusAdversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis.
- ▌ T1036 001 Invalid Code Signature · cyberstrikeusAdversaries may attempt to mimic features of valid code signatures to increase the chance of deceiving a user, analyst, or tool.
- ▌ T1036 002 Right To Left Override · cyberstrikeusAdversaries may abuse the right-to-left override (RTLO or RLO) character (U+202E) to disguise a string and/or file name to make it appear benign.
- ▌ T1140 Deobfuscatedecode Files Or Information · cyberstrikeusAdversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
- ▌ T1202 Indirect Command Execution · cyberstrikeusAdversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters.
- ▌ T1222 002 Linux And Mac File And Directory Permissions Modif · cyberstrikeusAdversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
- ▌ T1553 003 Sip And Trust Provider Hijacking · cyberstrikeusAdversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature validation checks.
- ▌ T1553 005 Mark Of The Web Bypass · cyberstrikeusAdversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls.
- ▌ T1601 002 Downgrade System Image · cyberstrikeusAdversaries may install an older version of the operating system of a network device to weaken security.
- ▌ T1539 Steal Web Session Cookie · cyberstrikeusAn adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials.
- ▌ T1552 001 Credentials In Files · cyberstrikeusAdversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
- ▌ T1556 008 Network Provider Dll · cyberstrikeusAdversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
- ▌ T1613 Container And Resource Discovery · cyberstrikeusAdversaries may attempt to discover containers and other resources that are available within a containers environment.
- ▌ T1048 Exfiltration Over Alternative Protocol · cyberstrikeusAdversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
- ▌ T1567 Exfiltration Over Web Service · cyberstrikeusAdversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel.
- ▌ T1567 004 Exfiltration Over Webhook · cyberstrikeusAdversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel.
- ▌ T1102 001 Dead Drop Resolver · cyberstrikeusAdversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.
- ▌ T1591 003 Identify Business Tempo · cyberstrikeusAdversaries may gather information about the victim's business tempo that can be used during targeting.
- ▌ T1593 Search Open Websitesdomains · cyberstrikeusAdversaries may search freely available websites and/or domains for information about victims that can be used during targeting.
- ▌ T1597 002 Purchase Technical Data · cyberstrikeusAdversaries may purchase technical information about victims that can be used during targeting.
- ▌ Maintenance Personnel 03 07 06 Maintenance Personnel · cyberstrikeusEstablish a process for maintenance personnel authorization.
- ▌
- ▌ Ac 12 1 User Initiated Logouts · cyberstrikeusProvide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [organization-defined].
- ▌ Ac 14 Permitted Actions Without Identification Or Authentica · cyberstrikeusIdentify [organization-defined] that can be performed on the system without identification or authentication consistent with organizational mission...
- ▌ Ac 17 6 Protection Of Mechanism Information · cyberstrikeusProtect information about remote access mechanisms from unauthorized use and disclosure.
- ▌ Ac 17 1 Monitoring And Control · cyberstrikeusEmploy automated mechanisms to monitor and control remote access methods.
- ▌
- ▌ Ac 19 2 Use Of Personally Owned Portable Storage Devices · cyberstrikeusUse of Personally Owned Portable Storage Devices
- ▌ Ac 2 1 Automated System Account Management · cyberstrikeusSupport the management of system accounts using [organization-defined].
- ▌ Ac 2 4 Automated Audit Actions · cyberstrikeusAutomatically audit account creation, modification, enabling, disabling, and removal actions.
- ▌ Ac 4 30 Filter Mechanisms Using Multiple Processes · cyberstrikeusWhen transferring information between different security domains, implement content filtering mechanisms using multiple processes.
- ▌ Ac 4 31 Failed Content Transfer Prevention · cyberstrikeusWhen transferring information between different security domains, prevent the transfer of failed content to the receiving domain.
- ▌ Ac 4 19 Validation Of Metadata · cyberstrikeusWhen transferring information between different security domains, implement [organization-defined] on metadata.
- ▌ Ac 4 7 One Way Flow Mechanisms · cyberstrikeusEnforce one-way information flows through hardware-based flow control mechanisms.
- ▌ Ac 6 6 Privileged Access By Non Organizational Users · cyberstrikeusProhibit privileged access to the system by non-organizational users.
- ▌ Au 10 Non Repudiation · cyberstrikeusProvide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined].
- ▌ Cp 2 2 Capacity Planning · cyberstrikeusConduct capacity planning so that necessary capacity for information processing, telecommunications, and environmental support exists during contingen
- ▌ Cp 3 Contingency Training · cyberstrikeusProvide contingency training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming a continge
- ▌
- ▌ Ir 4 7 Insider Threats Intra Organization Coordination · cyberstrikeusCoordinate an incident handling capability for insider threats that includes the following organizational entities [organization-defined].
- ▌ Pl 2 3 Plan And Coordinate With Other Organizational Entitie · cyberstrikeusPlan and Coordinate with Other Organizational Entities
- ▌ Pm 10 Authorization Process · cyberstrikeusManage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes;
- ▌ Pm 17 Protecting Controlled Unclassified Information On Exte · cyberstrikeusEstablish policy and procedures to ensure that requirements for the protection of controlled unclassified information that is processed, stored or ...
- ▌ Ra 5 7 Automated Detection And Notification Of Unauthorized · cyberstrikeusAutomated Detection and Notification of Unauthorized Components
- ▌
- ▌ T0828 Loss Of Productivity And Revenue · cyberstrikeusAdversaries may cause loss of productivity and revenue through disruption and even damage to the availability and integrity of control system operations, devices, and related processes.
- ▌ T0882 Theft Of Operational Information · cyberstrikeusAdversaries may steal operational information on a production environment as a direct mission outcome for personal gain or to inform future operations.
- ▌ T0836 Modify Parameter · cyberstrikeusAdversaries may modify parameters used to instruct industrial control system devices.
- ▌ T0822 External Remote Services · cyberstrikeusAdversaries may leverage external remote services as a point of initial access into your network.
- ▌ T0865 Spearphishing Attachment · cyberstrikeusAdversaries may use a spearphishing attachment, a variant of spearphishing, as a form of a social engineering attack against specific targets.
- ▌ T1406 002 Software Packing · cyberstrikeusAdversaries may perform software packing to conceal their code.
- ▌ T1604 Proxy Through Victim · cyberstrikeusAdversaries may use a compromised device as a proxy server to the Internet.
- ▌ T1627 Execution Guardrails · cyberstrikeusAdversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
- ▌ T1421 System Network Connections Discovery · cyberstrikeusAdversaries may attempt to get a listing of network connections to or from the compromised device they are currently accessing or from remote systems by querying for information over the network.
- ▌ T1430 002 Impersonate Ss7 Nodes · cyberstrikeusAdversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.
- ▌ T1644 Out Of Band Data · cyberstrikeusAdversaries may communicate with compromised devices using out of band data streams.
- ▌ T1566 001 Spearphishing Attachment · cyberstrikeusAdversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
- ▌ T1059 Command And Scripting Interpreter · cyberstrikeusAdversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
- ▌ T1203 Exploitation For Client Execution · cyberstrikeusAdversaries may exploit software vulnerabilities in client applications to execute code.
- ▌ T1543 Create Or Modify System Process · cyberstrikeusAdversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence.
- ▌ T1554 Compromise Host Software Binary · cyberstrikeusAdversaries may modify host software binaries to establish persistent access to systems.
- ▌ T1574 008 Path Interception By Search Order Hijacking · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking the search order used to load other programs.
- ▌ T1546 003 Windows Management Instrumentation Event Subscript · cyberstrikeusAdversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
- ▌ T1546 013 Powershell Profile · cyberstrikeusAdversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.
- ▌ T1546 016 Installer Packages · cyberstrikeusAdversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.
- ▌ T1036 010 Masquerade Account Name · cyberstrikeusAdversaries may match or approximate the names of legitimate accounts to make newly created ones appear benign.
- ▌ T1562 007 Disable Or Modify Cloud Firewall · cyberstrikeusAdversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
- ▌ T1562 001 Disable Or Modify Tools · cyberstrikeusAdversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities.
- ▌ T1562 011 Spoof Security Alerting · cyberstrikeusAdversaries may spoof security alerting from tools, presenting false evidence to impair defenders’ awareness of malicious activity.
- ▌ T1600 002 Disable Crypto Hardware · cyberstrikeusAdversaries disable a network device’s dedicated hardware encryption, which may enable them to leverage weaknesses in software encryption in order to reduce the effort involved in collecting, manip...
- ▌ T1556 005 Reversible Encryption · cyberstrikeusAn adversary may abuse Active Directory authentication encryption properties to gain access to credentials on Windows systems.
- ▌ T1016 001 Internet Connection Discovery · cyberstrikeusAdversaries may check for Internet connectivity on compromised systems.
- ▌ T1602 002 Network Device Configuration Dump · cyberstrikeusAdversaries may access network configuration files to collect sensitive data about the device and the network.
- ▌ T1537 Transfer Data To Cloud Account · cyberstrikeusAdversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
- ▌ T1001 003 Protocol Or Service Impersonation · cyberstrikeusAdversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts.
- ▌ T1583 Acquire Infrastructure · cyberstrikeusAdversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting.
- ▌ T1594 Search Victim Owned Websites · cyberstrikeusAdversaries may search websites owned by the victim for information that can be used during targeting.
- ▌ T1598 002 Spearphishing Attachment · cyberstrikeusAdversaries may send spearphishing messages with a malicious attachment to elicit sensitive information that can be used during targeting.
- ▌
- ▌
- ▌ Ac 10 Concurrent Session Control · cyberstrikeusLimit the number of concurrent sessions for each [organization-defined] to [organization-defined].
- ▌ Ac 11 1 Pattern Hiding Displays · cyberstrikeusConceal, via the device lock, information previously visible on the display with a publicly viewable image.
- ▌ Ac 12 3 Timeout Warning Message · cyberstrikeusDisplay an explicit message to users indicating that the session will end in [organization-defined].
- ▌ Ac 16 3 Maintenance Of Attribute Associations By System · cyberstrikeusMaintain the association and integrity of [organization-defined] to [organization-defined].