← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 64 of 72

  1. Ps 4 Personnel Termination · cyberstrikeus
    Upon termination of individual employment: Disable system access within [organization-defined]; Terminate or revoke any authenticators and credentials
    0
    installs
  2. Ps 9 Position Descriptions · cyberstrikeus
    Incorporate security and privacy roles and responsibilities into organizational position descriptions.
    0
    installs
  3. Sr 4 1 Identity · cyberstrikeus
    Establish and maintain unique identification of the following supply chain elements, processes, and personnel associated with the identified system an
    0
    installs
  4. T0885 Commonly Used Port · cyberstrikeus
    Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection.
    0
    installs
  5. T0881 Service Stop · cyberstrikeus
    Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
    0
    installs
  6. T0862 Supply Chain Compromise · cyberstrikeus
    Adversaries may perform supply chain compromise to gain control systems environment access by means of infected products, software, and workflows.
    0
    installs
  7. T0867 Lateral Tool Transfer · cyberstrikeus
    Adversaries may transfer tools or other files from one system to another to stage adversary tools or other files over the course of an operation.
    0
    installs
  8. T0891 Hardcoded Credentials · cyberstrikeus
    Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset.
    0
    installs
  9. T1624 001 Broadcast Receivers · cyberstrikeus
    Adversaries may establish persistence using system mechanisms that trigger execution based on specific events.
    0
    installs
  10. T1635 001 Uri Hijacking · cyberstrikeus
    Adversaries may register Uniform Resource Identifiers (URIs) to intercept sensitive data.
    0
    installs
  11. T1643 Generate Traffic From Victim · cyberstrikeus
    Adversaries may generate outbound traffic from devices.
    0
    installs
  12. T1521 003 Ssl Pinning · cyberstrikeus
    Adversaries may use SSL Pinning to protect the C2 traffic from being intercepted and analyzed.
    0
    installs
  13. T1609 Container Administration Command · cyberstrikeus
    Adversaries may abuse a container administration service to execute commands within a container.
    0
    installs
  14. T1098 007 Additional Local Or Domain Groups · cyberstrikeus
    An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or domain.
    0
    installs
  15. T1548 001 Setuid And Setgid · cyberstrikeus
    An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.
    0
    installs
  16. T1027 004 Compile After Delivery · cyberstrikeus
    Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code.
    0
    installs
  17. T1027 007 Dynamic API Resolution · cyberstrikeus
    Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis.
    0
    installs
  18. T1036 001 Invalid Code Signature · cyberstrikeus
    Adversaries may attempt to mimic features of valid code signatures to increase the chance of deceiving a user, analyst, or tool.
    0
    installs
  19. T1036 002 Right To Left Override · cyberstrikeus
    Adversaries may abuse the right-to-left override (RTLO or RLO) character (U+202E) to disguise a string and/or file name to make it appear benign.
    0
    installs
  20. T1140 Deobfuscatedecode Files Or Information · cyberstrikeus
    Adversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.
    0
    installs
  21. T1202 Indirect Command Execution · cyberstrikeus
    Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters.
    0
    installs
  22. T1222 002 Linux And Mac File And Directory Permissions Modif · cyberstrikeus
    Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
    0
    installs
  23. T1553 003 Sip And Trust Provider Hijacking · cyberstrikeus
    Adversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature validation checks.
    0
    installs
  24. T1553 005 Mark Of The Web Bypass · cyberstrikeus
    Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls.
    0
    installs
  25. T1601 002 Downgrade System Image · cyberstrikeus
    Adversaries may install an older version of the operating system of a network device to weaken security.
    0
    installs
  26. T1539 Steal Web Session Cookie · cyberstrikeus
    An adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials.
    0
    installs
  27. T1552 001 Credentials In Files · cyberstrikeus
    Adversaries may search local file systems and remote file shares for files containing insecurely stored credentials.
    0
    installs
  28. T1556 008 Network Provider Dll · cyberstrikeus
    Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
    0
    installs
  29. T1613 Container And Resource Discovery · cyberstrikeus
    Adversaries may attempt to discover containers and other resources that are available within a containers environment.
    0
    installs
  30. T1048 Exfiltration Over Alternative Protocol · cyberstrikeus
    Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
    0
    installs
  31. T1567 Exfiltration Over Web Service · cyberstrikeus
    Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel.
    0
    installs
  32. T1567 004 Exfiltration Over Webhook · cyberstrikeus
    Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel.
    0
    installs
  33. T1102 001 Dead Drop Resolver · cyberstrikeus
    Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.
    0
    installs
  34. T1591 003 Identify Business Tempo · cyberstrikeus
    Adversaries may gather information about the victim's business tempo that can be used during targeting.
    0
    installs
  35. T1593 Search Open Websitesdomains · cyberstrikeus
    Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting.
    0
    installs
  36. T1597 002 Purchase Technical Data · cyberstrikeus
    Adversaries may purchase technical information about victims that can be used during targeting.
    0
    installs
  37. Maintenance Personnel 03 07 06 Maintenance Personnel · cyberstrikeus
    Establish a process for maintenance personnel authorization.
    0
    installs
  38. Sp 800 171 03 11 03 031103 · cyberstrikeus
    03.11.03
    0
    installs
  39. Ac 12 1 User Initiated Logouts · cyberstrikeus
    Provide a logout capability for user-initiated communications sessions whenever authentication is used to gain access to [organization-defined].
    0
    installs
  40. Ac 14 Permitted Actions Without Identification Or Authentica · cyberstrikeus
    Identify [organization-defined] that can be performed on the system without identification or authentication consistent with organizational mission...
    0
    installs
  41. Ac 17 6 Protection Of Mechanism Information · cyberstrikeus
    Protect information about remote access mechanisms from unauthorized use and disclosure.
    0
    installs
  42. Ac 17 1 Monitoring And Control · cyberstrikeus
    Employ automated mechanisms to monitor and control remote access methods.
    0
    installs
  43. Ac 18 2 Monitoring Unauthorized Connections · cyberstrikeus
    Monitoring Unauthorized Connections
    0
    installs
  44. Ac 19 2 Use Of Personally Owned Portable Storage Devices · cyberstrikeus
    Use of Personally Owned Portable Storage Devices
    0
    installs
  45. Ac 2 1 Automated System Account Management · cyberstrikeus
    Support the management of system accounts using [organization-defined].
    0
    installs
  46. Ac 2 4 Automated Audit Actions · cyberstrikeus
    Automatically audit account creation, modification, enabling, disabling, and removal actions.
    0
    installs
  47. Ac 4 30 Filter Mechanisms Using Multiple Processes · cyberstrikeus
    When transferring information between different security domains, implement content filtering mechanisms using multiple processes.
    0
    installs
  48. Ac 4 31 Failed Content Transfer Prevention · cyberstrikeus
    When transferring information between different security domains, prevent the transfer of failed content to the receiving domain.
    0
    installs
  49. Ac 4 19 Validation Of Metadata · cyberstrikeus
    When transferring information between different security domains, implement [organization-defined] on metadata.
    0
    installs
  50. Ac 4 7 One Way Flow Mechanisms · cyberstrikeus
    Enforce one-way information flows through hardware-based flow control mechanisms.
    0
    installs
  51. Ac 6 6 Privileged Access By Non Organizational Users · cyberstrikeus
    Prohibit privileged access to the system by non-organizational users.
    0
    installs
  52. Au 10 Non Repudiation · cyberstrikeus
    Provide irrefutable evidence that an individual (or process acting on behalf of an individual) has performed [organization-defined].
    0
    installs
  53. Cp 2 2 Capacity Planning · cyberstrikeus
    Conduct capacity planning so that necessary capacity for information processing, telecommunications, and environmental support exists during contingen
    0
    installs
  54. Cp 3 Contingency Training · cyberstrikeus
    Provide contingency training to system users consistent with assigned roles and responsibilities: Within [organization-defined] of assuming a continge
    0
    installs
  55. Cp 4 3 Automated Testing · cyberstrikeus
    Test the contingency plan using [organization-defined].
    0
    installs
  56. Ir 4 7 Insider Threats Intra Organization Coordination · cyberstrikeus
    Coordinate an incident handling capability for insider threats that includes the following organizational entities [organization-defined].
    0
    installs
  57. Pl 2 3 Plan And Coordinate With Other Organizational Entitie · cyberstrikeus
    Plan and Coordinate with Other Organizational Entities
    0
    installs
  58. Pm 10 Authorization Process · cyberstrikeus
    Manage the security and privacy state of organizational systems and the environments in which those systems operate through authorization processes;
    0
    installs
  59. Pm 17 Protecting Controlled Unclassified Information On Exte · cyberstrikeus
    Establish policy and procedures to ensure that requirements for the protection of controlled unclassified information that is processed, stored or ...
    0
    installs
  60. Ra 5 7 Automated Detection And Notification Of Unauthorized · cyberstrikeus
    Automated Detection and Notification of Unauthorized Components
    0
    installs
  61. Ra 5 1 Update Tool Capability · cyberstrikeus
    Update Tool Capability
    0
    installs
  62. T0828 Loss Of Productivity And Revenue · cyberstrikeus
    Adversaries may cause loss of productivity and revenue through disruption and even damage to the availability and integrity of control system operations, devices, and related processes.
    0
    installs
  63. T0882 Theft Of Operational Information · cyberstrikeus
    Adversaries may steal operational information on a production environment as a direct mission outcome for personal gain or to inform future operations.
    0
    installs
  64. T0836 Modify Parameter · cyberstrikeus
    Adversaries may modify parameters used to instruct industrial control system devices.
    0
    installs
  65. T0822 External Remote Services · cyberstrikeus
    Adversaries may leverage external remote services as a point of initial access into your network.
    0
    installs
  66. T0865 Spearphishing Attachment · cyberstrikeus
    Adversaries may use a spearphishing attachment, a variant of spearphishing, as a form of a social engineering attack against specific targets.
    0
    installs
  67. T1406 002 Software Packing · cyberstrikeus
    Adversaries may perform software packing to conceal their code.
    0
    installs
  68. T1604 Proxy Through Victim · cyberstrikeus
    Adversaries may use a compromised device as a proxy server to the Internet.
    0
    installs
  69. T1627 Execution Guardrails · cyberstrikeus
    Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
    0
    installs
  70. T1421 System Network Connections Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of network connections to or from the compromised device they are currently accessing or from remote systems by querying for information over the network.
    0
    installs
  71. T1430 002 Impersonate Ss7 Nodes · cyberstrikeus
    Adversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.
    0
    installs
  72. T1644 Out Of Band Data · cyberstrikeus
    Adversaries may communicate with compromised devices using out of band data streams.
    0
    installs
  73. T1566 001 Spearphishing Attachment · cyberstrikeus
    Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
    0
    installs
  74. T1059 Command And Scripting Interpreter · cyberstrikeus
    Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
    0
    installs
  75. T1203 Exploitation For Client Execution · cyberstrikeus
    Adversaries may exploit software vulnerabilities in client applications to execute code.
    0
    installs
  76. T1543 Create Or Modify System Process · cyberstrikeus
    Adversaries may create or modify system-level processes to repeatedly execute malicious payloads as part of persistence.
    0
    installs
  77. T1554 Compromise Host Software Binary · cyberstrikeus
    Adversaries may modify host software binaries to establish persistent access to systems.
    0
    installs
  78. T1574 008 Path Interception By Search Order Hijacking · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs.
    0
    installs
  79. T1546 003 Windows Management Instrumentation Event Subscript · cyberstrikeus
    Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
    0
    installs
  80. T1546 013 Powershell Profile · cyberstrikeus
    Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.
    0
    installs
  81. T1546 016 Installer Packages · cyberstrikeus
    Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.
    0
    installs
  82. T1036 010 Masquerade Account Name · cyberstrikeus
    Adversaries may match or approximate the names of legitimate accounts to make newly created ones appear benign.
    0
    installs
  83. T1562 007 Disable Or Modify Cloud Firewall · cyberstrikeus
    Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
    0
    installs
  84. T1562 001 Disable Or Modify Tools · cyberstrikeus
    Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities.
    0
    installs
  85. T1562 011 Spoof Security Alerting · cyberstrikeus
    Adversaries may spoof security alerting from tools, presenting false evidence to impair defenders’ awareness of malicious activity.
    0
    installs
  86. T1600 002 Disable Crypto Hardware · cyberstrikeus
    Adversaries disable a network device’s dedicated hardware encryption, which may enable them to leverage weaknesses in software encryption in order to reduce the effort involved in collecting, manip...
    0
    installs
  87. T1556 005 Reversible Encryption · cyberstrikeus
    An adversary may abuse Active Directory authentication encryption properties to gain access to credentials on Windows systems.
    0
    installs
  88. T1016 001 Internet Connection Discovery · cyberstrikeus
    Adversaries may check for Internet connectivity on compromised systems.
    0
    installs
  89. T1602 002 Network Device Configuration Dump · cyberstrikeus
    Adversaries may access network configuration files to collect sensitive data about the device and the network.
    0
    installs
  90. T1537 Transfer Data To Cloud Account · cyberstrikeus
    Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.
    0
    installs
  91. T1001 003 Protocol Or Service Impersonation · cyberstrikeus
    Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts.
    0
    installs
  92. T1583 Acquire Infrastructure · cyberstrikeus
    Adversaries may buy, lease, rent, or obtain infrastructure that can be used during targeting.
    0
    installs
  93. T1594 Search Victim Owned Websites · cyberstrikeus
    Adversaries may search websites owned by the victim for information that can be used during targeting.
    0
    installs
  94. T1598 002 Spearphishing Attachment · cyberstrikeus
    Adversaries may send spearphishing messages with a malicious attachment to elicit sensitive information that can be used during targeting.
    0
    installs
  95. Sp 800 171 03 08 06 030806 · cyberstrikeus
    03.08.06
    0
    installs
  96. Sp 800 171 03 08 08 030808 · cyberstrikeus
    03.08.08
    0
    installs
  97. Ac 10 Concurrent Session Control · cyberstrikeus
    Limit the number of concurrent sessions for each [organization-defined] to [organization-defined].
    0
    installs
  98. Ac 11 1 Pattern Hiding Displays · cyberstrikeus
    Conceal, via the device lock, information previously visible on the display with a publicly viewable image.
    0
    installs
  99. Ac 12 3 Timeout Warning Message · cyberstrikeus
    Display an explicit message to users indicating that the session will end in [organization-defined].
    0
    installs
  100. Ac 16 3 Maintenance Of Attribute Associations By System · cyberstrikeus
    Maintain the association and integrity of [organization-defined] to [organization-defined].
    0
    installs