cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ Ac 16 6 Maintenance Of Attribute Association · cyberstrikeusRequire personnel to associate and maintain the association of [organization-defined] with [organization-defined] in accordance with [organization-def
- ▌ Ac 2 10 Shared And Group Account Credential Change · cyberstrikeusShared and Group Account Credential Change
- ▌ Ac 2 7 Privileged User Accounts · cyberstrikeusEstablish and administer privileged user accounts in accordance with [organization-defined];
- ▌ Ac 20 2 Portable Storage Devices Restricted Use · cyberstrikeusRestrict the use of organization-controlled portable storage devices by authorized individuals on external systems using [organization-defined].
- ▌ Ac 20 5 Portable Storage Devices Prohibited Use · cyberstrikeusProhibit the use of organization-controlled portable storage devices by authorized individuals on external systems.
- ▌ Ac 3 3 Mandatory Access Control · cyberstrikeusEnforce [organization-defined] over the set of covered subjects and objects specified in the policy, and where the policy: Is uniformly enforced acros
- ▌ Ac 4 16 Information Transfers On Interconnected Systems · cyberstrikeusInformation Transfers on Interconnected Systems
- ▌ Ac 4 32 Process Requirements For Information Transfer · cyberstrikeusWhen transferring information between different security domains, the process that transfers information between filter pipelines: Does not filter mes
- ▌ Ac 4 4 Flow Control Of Encrypted Information · cyberstrikeusPrevent encrypted information from bypassing [organization-defined] by [organization-defined].
- ▌ Ac 4 26 Audit Filtering Actions · cyberstrikeusWhen transferring information between different security domains, record and audit content filtering actions and results for the information being fil
- ▌ Ac 4 28 Linear Filter Pipelines · cyberstrikeusWhen transferring information between different security domains, implement a linear content filter pipeline that is enforced with discretionary and m
- ▌ Ac 6 2 Non Privileged Access For Nonsecurity Functions · cyberstrikeusRequire that users of system accounts (or roles) with access to [organization-defined] use non-privileged accounts or roles, when accessing nonsecurit
- ▌ Ac 6 8 Privilege Levels For Code Execution · cyberstrikeusPrevent the following software from executing at higher privilege levels than users executing the software: [organization-defined].
- ▌ Ac 7 Unsuccessful Logon Attempts · cyberstrikeusEnforce a limit of [organization-defined] consecutive invalid logon attempts by a user during a [organization-defined] ;
- ▌ Ac 9 Previous Logon Notification · cyberstrikeusNotify the user, upon successful logon to the system, of the date and time of the last logon.
- ▌ At 3 Role Based Training · cyberstrikeusProvide role-based security and privacy training to personnel with the following roles and responsibilities: [organization-defined]: Before authorizin
- ▌ Ca 6 Authorization · cyberstrikeusAssign a senior official as the authorizing official for the system;
- ▌ Cp 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] contingency planning policy that: Procedures to facilitate the im
- ▌ Ir 7 1 Automation Support For Availability Of Information An · cyberstrikeusIncrease the availability of incident response information and support using [organization-defined].
- ▌
- ▌ Ir 9 3 Post Spill Operations · cyberstrikeusImplement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks whi
- ▌ Ma 4 5 Approvals And Notifications · cyberstrikeusRequire the approval of each nonlocal maintenance session by [organization-defined] ;
- ▌ Ma 5 3 Citizenship Requirements For Classified Systems · cyberstrikeusVerify that personnel performing maintenance and diagnostic activities on a system processing, storing, or transmitting classified information are ...
- ▌
- ▌
- ▌ Mp 8 3 Controlled Unclassified Information · cyberstrikeusDowngrade system media containing controlled unclassified information prior to public release.
- ▌ Mp 8 4 Classified Information · cyberstrikeusDowngrade system media containing classified information prior to release to individuals without required access authorizations.
- ▌ Pl 2 System Security And Privacy Plans · cyberstrikeusDevelop security and privacy plans for the system that: Are consistent with the organization’s enterprise architecture; Explicitly define the constitu
- ▌ Pm 12 Insider Threat Program · cyberstrikeusImplement an insider threat program that includes a cross-discipline insider threat incident handling team.
- ▌ Pm 6 Measures Of Performance · cyberstrikeusDevelop, monitor, and report on the results of information security and privacy measures of performance.
- ▌ Pm 7 Enterprise Architecture · cyberstrikeusDevelop and maintain an enterprise architecture with consideration for information security, privacy, and the resulting risk to organizational operati
- ▌ Ra 8 Privacy Impact Assessments · cyberstrikeusConduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes pe
- ▌ Si 20 Tainting · cyberstrikeusEmbed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly remove
- ▌ T0840 Network Connection Enumeration · cyberstrikeusAdversaries may perform network connection enumeration to discover information about device communication patterns.
- ▌ T1661 Application Versioning · cyberstrikeusAn adversary may push an update to a previously benign application to add malicious code.
- ▌ T1624 Event Triggered Execution · cyberstrikeusAdversaries may establish persistence using system mechanisms that trigger execution based on specific events.
- ▌ T1437 001 Web Protocols · cyberstrikeusAdversaries may communicate using application layer protocols associated with web protocols traffic to avoid detection/network filtering by blending in with existing traffic.
- ▌ T1509 Non Standard Port · cyberstrikeusAdversaries may generate network traffic using a protocol and port pairing that are typically not associated.
- ▌ T1521 Encrypted Channel · cyberstrikeusAdversaries may explicitly employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
- ▌ T1566 003 Spearphishing Via Service · cyberstrikeusAdversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems.
- ▌ T1047 Windows Management Instrumentation · cyberstrikeusAdversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
- ▌ T1098 006 Additional Container Cluster Roles · cyberstrikeusAn adversary may add additional roles or permissions to an adversary-controlled user or service account to maintain persistent access to a container orchestration system.
- ▌ T1098 001 Additional Cloud Credentials · cyberstrikeusAdversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
- ▌ T1505 006 Vsphere Installation Bundles · cyberstrikeusAdversaries may abuse vSphere Installation Bundles (VIBs) to establish persistent access to ESXi hypervisors.
- ▌ T1546 001 Change Default File Association · cyberstrikeusAdversaries may establish persistence by executing malicious content triggered by a file type association.
- ▌ T1070 005 Network Share Connection Removal · cyberstrikeusAdversaries may remove share connections that are no longer useful in order to clean up traces of their operation.
- ▌ T1070 007 Clear Network Connection History And Configuration · cyberstrikeusAdversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations.
- ▌ Attack JWT · cyberstrikeusJWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping
- ▌ Attack Xxe · cyberstrikeusXML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsing
- ▌
- ▌ Attack Cors · cyberstrikeusCORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage
- ▌ Attack Ssrf · cyberstrikeusServer-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques
- ▌ Attack Ssti · cyberstrikeusServer-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines
- ▌ Bun File Io · cyberstrikeusUse this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.
- ▌ Cicd Attacks · cyberstrikeusCI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab
- ▌ Ebpf Attacks · cyberstrikeuseBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux
- ▌ LLM Security · cyberstrikeusOWASP LLM Top 10 security testing - prompt injection, system prompt leakage, excessive agency, sensitive data disclosure
- ▌ CI Assessment · cyberstrikeusREAD-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chain
- ▌ Attack GRAPHQL · cyberstrikeusGraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass
- ▌ K8S Assessment · cyberstrikeusREAD-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectl
- ▌ AWS Postexploit · cyberstrikeusAWS post-exploitation — 92 programs for full kill chain from recon to cleanup via AWS CLI
- ▌ GCP Postexploit · cyberstrikeusGCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDK
- ▌ K8S Postexploit · cyberstrikeusKubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
- ▌ Attack Websocket · cyberstrikeusWebSocket security testing — CSWSH, message injection, auth bypass, origin validation
- ▌ Cloud Assessment · cyberstrikeusMulti-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checks
- ▌
- ▌ Azure Postexploit · cyberstrikeusAzure/Entra ID post-exploitation — 154 programs for tenant compromise, CIS compliance, identity attacks, data exfiltration, and M365 abuse
- ▌ Linux Postexploit · cyberstrikeusLinux post-exploitation — credential harvesting, privilege escalation, persistence, lateral movement, evasion, exfiltration, and network attacks with multi-exec fallback (bash/sh/python3/perl/busybox) and stealth modes (base64/memfd/shm)
- ▌ Macos Postexploit · cyberstrikeusmacOS post-exploitation — 46 programs across recon, credential harvesting, privilege escalation, persistence, evasion, monitoring, lateral movement, and exfiltration
- ▌
- ▌ Attack Host Header · cyberstrikeusHost header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host
- ▌ Attack Cache Poison · cyberstrikeusWeb cache poisoning — unkeyed header/parameter injection to serve malicious content to all users
- ▌ Windows Postexploit · cyberstrikeusWindows post-exploitation — Active Directory attacks, Kerberos exploitation, ADCS abuse, lateral movement, persistence, privilege escalation, credential harvesting, stealth encoding (Base64/AMSI/obfuscate), and pwsh.exe support
- ▌ Attack Open Redirect · cyberstrikeusOpen redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains
- ▌ Attack Race Condition · cyberstrikeusRace condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flaws
- ▌ Attack Idor Automation · cyberstrikeusIDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure
- ▌ Attack Rate Limit Bypass · cyberstrikeusRate limit bypass testing — XFF rotation, case variation, method switching, header manipulation
- ▌ Attack Request Smuggling · cyberstrikeusHTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass
- ▌ Attack Subdomain Takeover · cyberstrikeusSubdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation
- ▌ Attack Prototype Pollution · cyberstrikeusJavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌