← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 65 of 72

  1. Ac 16 6 Maintenance Of Attribute Association · cyberstrikeus
    Require personnel to associate and maintain the association of [organization-defined] with [organization-defined] in accordance with [organization-def
    0
    installs
  2. Ac 2 10 Shared And Group Account Credential Change · cyberstrikeus
    Shared and Group Account Credential Change
    0
    installs
  3. Ac 2 7 Privileged User Accounts · cyberstrikeus
    Establish and administer privileged user accounts in accordance with [organization-defined];
    0
    installs
  4. Ac 20 2 Portable Storage Devices Restricted Use · cyberstrikeus
    Restrict the use of organization-controlled portable storage devices by authorized individuals on external systems using [organization-defined].
    0
    installs
  5. Ac 20 5 Portable Storage Devices Prohibited Use · cyberstrikeus
    Prohibit the use of organization-controlled portable storage devices by authorized individuals on external systems.
    0
    installs
  6. Ac 3 3 Mandatory Access Control · cyberstrikeus
    Enforce [organization-defined] over the set of covered subjects and objects specified in the policy, and where the policy: Is uniformly enforced acros
    0
    installs
  7. Ac 4 16 Information Transfers On Interconnected Systems · cyberstrikeus
    Information Transfers on Interconnected Systems
    0
    installs
  8. Ac 4 32 Process Requirements For Information Transfer · cyberstrikeus
    When transferring information between different security domains, the process that transfers information between filter pipelines: Does not filter mes
    0
    installs
  9. Ac 4 4 Flow Control Of Encrypted Information · cyberstrikeus
    Prevent encrypted information from bypassing [organization-defined] by [organization-defined].
    0
    installs
  10. Ac 4 26 Audit Filtering Actions · cyberstrikeus
    When transferring information between different security domains, record and audit content filtering actions and results for the information being fil
    0
    installs
  11. Ac 4 28 Linear Filter Pipelines · cyberstrikeus
    When transferring information between different security domains, implement a linear content filter pipeline that is enforced with discretionary and m
    0
    installs
  12. Ac 6 2 Non Privileged Access For Nonsecurity Functions · cyberstrikeus
    Require that users of system accounts (or roles) with access to [organization-defined] use non-privileged accounts or roles, when accessing nonsecurit
    0
    installs
  13. Ac 6 8 Privilege Levels For Code Execution · cyberstrikeus
    Prevent the following software from executing at higher privilege levels than users executing the software: [organization-defined].
    0
    installs
  14. Ac 7 Unsuccessful Logon Attempts · cyberstrikeus
    Enforce a limit of [organization-defined] consecutive invalid logon attempts by a user during a [organization-defined] ;
    0
    installs
  15. Ac 9 Previous Logon Notification · cyberstrikeus
    Notify the user, upon successful logon to the system, of the date and time of the last logon.
    0
    installs
  16. At 3 Role Based Training · cyberstrikeus
    Provide role-based security and privacy training to personnel with the following roles and responsibilities: [organization-defined]: Before authorizin
    0
    installs
  17. Ca 6 Authorization · cyberstrikeus
    Assign a senior official as the authorizing official for the system;
    0
    installs
  18. Cp 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] contingency planning policy that: Procedures to facilitate the im
    0
    installs
  19. Ir 7 1 Automation Support For Availability Of Information An · cyberstrikeus
    Increase the availability of incident response information and support using [organization-defined].
    0
    installs
  20. Ir 9 1 Responsible Personnel · cyberstrikeus
    Responsible Personnel
    0
    installs
  21. Ir 9 3 Post Spill Operations · cyberstrikeus
    Implement the following procedures to ensure that organizational personnel impacted by information spills can continue to carry out assigned tasks whi
    0
    installs
  22. Ma 4 5 Approvals And Notifications · cyberstrikeus
    Require the approval of each nonlocal maintenance session by [organization-defined] ;
    0
    installs
  23. Ma 5 3 Citizenship Requirements For Classified Systems · cyberstrikeus
    Verify that personnel performing maintenance and diagnostic activities on a system processing, storing, or transmitting classified information are ...
    0
    installs
  24. Mp 6 4 Controlled Unclassified Information · cyberstrikeus
    Controlled Unclassified Information
    0
    installs
  25. Mp 6 5 Classified Information · cyberstrikeus
    Classified Information
    0
    installs
  26. Mp 8 3 Controlled Unclassified Information · cyberstrikeus
    Downgrade system media containing controlled unclassified information prior to public release.
    0
    installs
  27. Mp 8 4 Classified Information · cyberstrikeus
    Downgrade system media containing classified information prior to release to individuals without required access authorizations.
    0
    installs
  28. Pl 2 System Security And Privacy Plans · cyberstrikeus
    Develop security and privacy plans for the system that: Are consistent with the organization’s enterprise architecture; Explicitly define the constitu
    0
    installs
  29. Pm 12 Insider Threat Program · cyberstrikeus
    Implement an insider threat program that includes a cross-discipline insider threat incident handling team.
    0
    installs
  30. Pm 6 Measures Of Performance · cyberstrikeus
    Develop, monitor, and report on the results of information security and privacy measures of performance.
    0
    installs
  31. Pm 7 Enterprise Architecture · cyberstrikeus
    Develop and maintain an enterprise architecture with consideration for information security, privacy, and the resulting risk to organizational operati
    0
    installs
  32. Ra 8 Privacy Impact Assessments · cyberstrikeus
    Conduct privacy impact assessments for systems, programs, or other activities before: Developing or procuring information technology that processes pe
    0
    installs
  33. Si 20 Tainting · cyberstrikeus
    Embed data or capabilities in the following systems or system components to determine if organizational data has been exfiltrated or improperly remove
    0
    installs
  34. T0840 Network Connection Enumeration · cyberstrikeus
    Adversaries may perform network connection enumeration to discover information about device communication patterns.
    0
    installs
  35. T1661 Application Versioning · cyberstrikeus
    An adversary may push an update to a previously benign application to add malicious code.
    0
    installs
  36. T1624 Event Triggered Execution · cyberstrikeus
    Adversaries may establish persistence using system mechanisms that trigger execution based on specific events.
    0
    installs
  37. T1437 001 Web Protocols · cyberstrikeus
    Adversaries may communicate using application layer protocols associated with web protocols traffic to avoid detection/network filtering by blending in with existing traffic.
    0
    installs
  38. T1509 Non Standard Port · cyberstrikeus
    Adversaries may generate network traffic using a protocol and port pairing that are typically not associated.
    0
    installs
  39. T1521 Encrypted Channel · cyberstrikeus
    Adversaries may explicitly employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
    0
    installs
  40. T1566 003 Spearphishing Via Service · cyberstrikeus
    Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems.
    0
    installs
  41. T1047 Windows Management Instrumentation · cyberstrikeus
    Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
    0
    installs
  42. T1098 006 Additional Container Cluster Roles · cyberstrikeus
    An adversary may add additional roles or permissions to an adversary-controlled user or service account to maintain persistent access to a container orchestration system.
    0
    installs
  43. T1098 001 Additional Cloud Credentials · cyberstrikeus
    Adversaries may add adversary-controlled credentials to a cloud account to maintain persistent access to victim accounts and instances within the environment.
    0
    installs
  44. T1505 006 Vsphere Installation Bundles · cyberstrikeus
    Adversaries may abuse vSphere Installation Bundles (VIBs) to establish persistent access to ESXi hypervisors.
    0
    installs
  45. T1546 001 Change Default File Association · cyberstrikeus
    Adversaries may establish persistence by executing malicious content triggered by a file type association.
    0
    installs
  46. T1070 005 Network Share Connection Removal · cyberstrikeus
    Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation.
    0
    installs
  47. T1070 007 Clear Network Connection History And Configuration · cyberstrikeus
    Adversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations.
    0
    installs
  48. Attack JWT · cyberstrikeus
    JWT token attacks — alg:none bypass, key confusion, claim tampering, signature stripping
    0
    installs
  49. Attack Xxe · cyberstrikeus
    XML External Entity injection — file read, SSRF, data exfiltration via out-of-band XML parsing
    0
    installs
  50. Ad Security · cyberstrikeus
    Active Directory security testing and attack techniques
    0
    installs
  51. Attack Cors · cyberstrikeus
    CORS misconfiguration testing — origin reflection, wildcard bypass, null origin, credential leakage
    0
    installs
  52. Attack Ssrf · cyberstrikeus
    Server-Side Request Forgery — internal network access, cloud metadata theft, filter bypass techniques
    0
    installs
  53. Attack Ssti · cyberstrikeus
    Server-Side Template Injection — detection, engine fingerprinting, and exploitation across 7 template engines
    0
    installs
  54. Bun File Io · cyberstrikeus
    Use this when you are working on file operations like reading, writing, scanning, or deleting files. It summarizes the preferred file APIs and patterns used in this repo. It also notes when to use filesystem helpers for directories.
    0
    installs
  55. Cicd Attacks · cyberstrikeus
    CI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab
    0
    installs
  56. Ebpf Attacks · cyberstrikeus
    eBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux
    0
    installs
  57. LLM Security · cyberstrikeus
    OWASP LLM Top 10 security testing - prompt injection, system prompt leakage, excessive agency, sensitive data disclosure
    0
    installs
  58. CI Assessment · cyberstrikeus
    READ-ONLY CI/CD pipeline security assessment for GitHub Actions, dependency security, and software supply chain
    0
    installs
  59. Attack GRAPHQL · cyberstrikeus
    GraphQL vulnerability testing — introspection exposure, complexity DoS, batch abuse, mutation auth bypass
    0
    installs
  60. K8S Assessment · cyberstrikeus
    READ-ONLY Kubernetes security assessment based on CIS Kubernetes Benchmark using kubectl
    0
    installs
  61. AWS Postexploit · cyberstrikeus
    AWS post-exploitation — 92 programs for full kill chain from recon to cleanup via AWS CLI
    0
    installs
  62. GCP Postexploit · cyberstrikeus
    GCP post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via google-cloud SDK
    0
    installs
  63. K8S Postexploit · cyberstrikeus
    Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
    0
    installs
  64. Attack Websocket · cyberstrikeus
    WebSocket security testing — CSWSH, message injection, auth bypass, origin validation
    0
    installs
  65. Cloud Assessment · cyberstrikeus
    Multi-cloud READ-ONLY security assessment methodology for AWS, Azure, and GCP using CIS benchmark-aligned checks
    0
    installs
  66. Kerberos Attacks · cyberstrikeus
    Kerberos protocol attack techniques and exploitation
    0
    installs
  67. Azure Postexploit · cyberstrikeus
    Azure/Entra ID post-exploitation — 154 programs for tenant compromise, CIS compliance, identity attacks, data exfiltration, and M365 abuse
    0
    installs
  68. Linux Postexploit · cyberstrikeus
    Linux post-exploitation — credential harvesting, privilege escalation, persistence, lateral movement, evasion, exfiltration, and network attacks with multi-exec fallback (bash/sh/python3/perl/busybox) and stealth modes (base64/memfd/shm)
    0
    installs
  69. Macos Postexploit · cyberstrikeus
    macOS post-exploitation — 46 programs across recon, credential harvesting, privilege escalation, persistence, evasion, monitoring, lateral movement, and exfiltration
    0
    installs
  70. Recon Methodology · cyberstrikeus
    Bug bounty and pentest reconnaissance methodology
    0
    installs
  71. Attack Host Header · cyberstrikeus
    Host header injection — password reset poisoning, cache poisoning, routing bypass, SSRF via Host
    0
    installs
  72. Attack Cache Poison · cyberstrikeus
    Web cache poisoning — unkeyed header/parameter injection to serve malicious content to all users
    0
    installs
  73. Windows Postexploit · cyberstrikeus
    Windows post-exploitation — Active Directory attacks, Kerberos exploitation, ADCS abuse, lateral movement, persistence, privilege escalation, credential harvesting, stealth encoding (Base64/AMSI/obfuscate), and pwsh.exe support
    0
    installs
  74. Attack Open Redirect · cyberstrikeus
    Open redirect exploitation — URL parameter manipulation, OAuth token theft, phishing chains
    0
    installs
  75. Attack Race Condition · cyberstrikeus
    Race condition / TOCTOU testing — concurrent requests to exploit time-of-check-to-time-of-use flaws
    0
    installs
  76. Attack Idor Automation · cyberstrikeus
    IDOR automated testing — cross-account access, horizontal/vertical privilege escalation, mass data exposure
    0
    installs
  77. Attack Rate Limit Bypass · cyberstrikeus
    Rate limit bypass testing — XFF rotation, case variation, method switching, header manipulation
    0
    installs
  78. Attack Request Smuggling · cyberstrikeus
    HTTP request smuggling — CL.TE, TE.CL, TE.TE desync attacks for cache poisoning and auth bypass
    0
    installs
  79. Attack Subdomain Takeover · cyberstrikeus
    Subdomain takeover — CNAME detection, cloud service fingerprinting, dangling DNS exploitation
    0
    installs
  80. Attack Prototype Pollution · cyberstrikeus
    JavaScript prototype pollution — __proto__ injection, constructor.prototype, gadget chain exploitation
    0
    installs
  81. Wstg Apit 00 · cyberstrikeus
    API Testing Overview
    0
    installs
  82. Wstg Apit 01 · cyberstrikeus
    API Reconnaissance
    0
    installs
  83. Wstg Apit 02 · cyberstrikeus
    Testing for Broken Object Level Authorization (BOLA)
    0
    installs
  84. Wstg Apit 99 · cyberstrikeus
    Testing GraphQL
    0
    installs
  85. Wstg Athn 01 · cyberstrikeus
    Testing for Credentials Transported over an Encrypted Channel
    0
    installs
  86. Wstg Athn 02 · cyberstrikeus
    Testing for Default Credentials
    0
    installs
  87. Wstg Athn 03 · cyberstrikeus
    Testing for Weak Lock Out Mechanism
    0
    installs
  88. Wstg Athn 04 · cyberstrikeus
    Testing for Bypassing Authentication Schema
    0
    installs
  89. Wstg Athn 05 · cyberstrikeus
    Testing for Vulnerable Remember Password
    0
    installs
  90. Wstg Athn 06 · cyberstrikeus
    Testing for Browser Cache Weaknesses
    0
    installs
  91. Wstg Athn 07 · cyberstrikeus
    Testing for Weak Password Policy
    0
    installs
  92. Wstg Athn 08 · cyberstrikeus
    Testing for Weak Security Question Answer
    0
    installs
  93. Wstg Athn 09 · cyberstrikeus
    Testing for Weak Password Change or Reset Functionalities
    0
    installs
  94. Wstg Athn 10 · cyberstrikeus
    Testing for Weaker Authentication in Alternative Channel
    0
    installs
  95. Wstg Athn 11 · cyberstrikeus
    Testing Multi-Factor Authentication (MFA)
    0
    installs
  96. Wstg Busl 01 · cyberstrikeus
    Test Business Logic Data Validation
    0
    installs
  97. Wstg Busl 02 · cyberstrikeus
    Test Ability to Forge Requests
    0
    installs
  98. Wstg Busl 03 · cyberstrikeus
    Test Integrity Checks
    0
    installs
  99. Wstg Busl 04 · cyberstrikeus
    Test for Process Timing
    0
    installs
  100. Wstg Busl 05 · cyberstrikeus
    Test Number of Times a Function Can Be Used Limits
    0
    installs