← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 66 of 72

  1. Wstg Busl 06 · cyberstrikeus
    Test Circumvention of Work Flows
    0
    installs
  2. Wstg Busl 07 · cyberstrikeus
    Test Defenses Against Application Misuse
    0
    installs
  3. Wstg Busl 08 · cyberstrikeus
    Test Upload of Unexpected File Types
    0
    installs
  4. Wstg Busl 09 · cyberstrikeus
    Test Upload of Malicious Files
    0
    installs
  5. Wstg Busl 10 · cyberstrikeus
    Test Payment Functionality
    0
    installs
  6. Wstg Clnt 01 · cyberstrikeus
    Testing for DOM-Based Cross Site Scripting
    0
    installs
  7. Wstg Clnt 02 · cyberstrikeus
    Testing for JavaScript Execution
    0
    installs
  8. Wstg Clnt 03 · cyberstrikeus
    Testing for HTML Injection
    0
    installs
  9. Wstg Clnt 04 · cyberstrikeus
    Testing for Client-Side URL Redirect
    0
    installs
  10. Wstg Clnt 05 · cyberstrikeus
    Testing for CSS Injection
    0
    installs
  11. Wstg Clnt 06 · cyberstrikeus
    Testing for Client-Side Resource Manipulation
    0
    installs
  12. Wstg Clnt 07 · cyberstrikeus
    Testing for Cross-Origin Resource Sharing (CORS)
    0
    installs
  13. Wstg Clnt 08 · cyberstrikeus
    Testing for Cross-Site Flashing
    0
    installs
  14. Wstg Clnt 09 · cyberstrikeus
    Testing for Clickjacking
    0
    installs
  15. Wstg Clnt 10 · cyberstrikeus
    Testing WebSockets
    0
    installs
  16. Wstg Clnt 11 · cyberstrikeus
    Testing Web Messaging
    0
    installs
  17. Wstg Clnt 12 · cyberstrikeus
    Testing Browser Storage
    0
    installs
  18. Wstg Clnt 13 · cyberstrikeus
    Testing for Cross-Site Script Inclusion (XSSI)
    0
    installs
  19. Wstg Clnt 14 · cyberstrikeus
    Testing for Reverse Tabnabbing
    0
    installs
  20. Wstg Conf 01 · cyberstrikeus
    Test Network Infrastructure Configuration
    0
    installs
  21. Wstg Conf 02 · cyberstrikeus
    Test Application Platform Configuration
    0
    installs
  22. Wstg Conf 03 · cyberstrikeus
    Test File Extensions Handling for Sensitive Information
    0
    installs
  23. Wstg Conf 04 · cyberstrikeus
    Review Old Backup and Unreferenced Files for Sensitive Information
    0
    installs
  24. Wstg Conf 05 · cyberstrikeus
    Enumerate Infrastructure and Application Admin Interfaces
    0
    installs
  25. Wstg Conf 06 · cyberstrikeus
    Test HTTP Methods
    0
    installs
  26. Wstg Conf 07 · cyberstrikeus
    Test HTTP Strict Transport Security
    0
    installs
  27. Wstg Conf 08 · cyberstrikeus
    Test RIA Cross Domain Policy
    0
    installs
  28. Wstg Conf 09 · cyberstrikeus
    Test File Permission
    0
    installs
  29. Wstg Conf 10 · cyberstrikeus
    Test for Subdomain Takeover
    0
    installs
  30. Wstg Conf 11 · cyberstrikeus
    Test Cloud Storage
    0
    installs
  31. Wstg Conf 12 · cyberstrikeus
    Test for Content Security Policy
    0
    installs
  32. Wstg Conf 13 · cyberstrikeus
    Test for Path Confusion
    0
    installs
  33. Wstg Cryp 01 · cyberstrikeus
    Testing for Weak Transport Layer Security
    0
    installs
  34. Wstg Cryp 02 · cyberstrikeus
    Testing for Padding Oracle
    0
    installs
  35. Wstg Cryp 03 · cyberstrikeus
    Testing for Sensitive Information Sent via Unencrypted Channels
    0
    installs
  36. Wstg Cryp 04 · cyberstrikeus
    Testing for Weak Encryption
    0
    installs
  37. Wstg Errh 01 · cyberstrikeus
    Testing for Improper Error Handling
    0
    installs
  38. Wstg Errh 02 · cyberstrikeus
    Testing for Stack Traces
    0
    installs
  39. Wstg Idnt 01 · cyberstrikeus
    Test Role Definitions
    0
    installs
  40. Wstg Idnt 02 · cyberstrikeus
    Test User Registration Process
    0
    installs
  41. Wstg Idnt 03 · cyberstrikeus
    Test Account Provisioning Process
    0
    installs
  42. Wstg Idnt 04 · cyberstrikeus
    Test Account Enumeration
    0
    installs
  43. Wstg Idnt 05 · cyberstrikeus
    Test Username Policy
    0
    installs
  44. Wstg Info 01 · cyberstrikeus
    Conduct Search Engine Discovery Reconnaissance for Information Leakage
    0
    installs
  45. Wstg Info 02 · cyberstrikeus
    Fingerprint Web Server
    0
    installs
  46. Wstg Info 03 · cyberstrikeus
    Review Webserver Metafiles for Information Leakage
    0
    installs
  47. Wstg Info 04 · cyberstrikeus
    Enumerate Applications on Webserver
    0
    installs
  48. Wstg Info 05 · cyberstrikeus
    Review Web Page Content for Information Leakage
    0
    installs
  49. Wstg Info 06 · cyberstrikeus
    Identify Application Entry Points
    0
    installs
  50. Wstg Info 07 · cyberstrikeus
    Map Execution Paths Through Application
    0
    installs
  51. Wstg Info 08 · cyberstrikeus
    Fingerprint Web Application Framework
    0
    installs
  52. Wstg Info 09 · cyberstrikeus
    Fingerprint Web Application
    0
    installs
  53. Wstg Info 10 · cyberstrikeus
    Map Application Architecture
    0
    installs
  54. Wstg Inpv 01 · cyberstrikeus
    Testing for Reflected Cross-Site Scripting (XSS)
    0
    installs
  55. Wstg Inpv 02 · cyberstrikeus
    Testing for Stored Cross-Site Scripting (XSS)
    0
    installs
  56. Wstg Inpv 03 · cyberstrikeus
    Testing for HTTP Verb Tampering
    0
    installs
  57. Wstg Inpv 04 · cyberstrikeus
    Testing for HTTP Parameter Pollution (HPP)
    0
    installs
  58. Wstg Inpv 05 · cyberstrikeus
    Testing for SQL Injection
    0
    installs
  59. Wstg Inpv 06 · cyberstrikeus
    Testing for LDAP Injection
    0
    installs
  60. Wstg Inpv 07 · cyberstrikeus
    Testing for XML Injection
    0
    installs
  61. Wstg Inpv 08 · cyberstrikeus
    Testing for SSI Injection
    0
    installs
  62. Wstg Inpv 09 · cyberstrikeus
    Testing for XPath Injection
    2
    installs
  63. Wstg Inpv 10 · cyberstrikeus
    Testing for IMAP/SMTP Injection
    0
    installs
  64. Wstg Inpv 11 · cyberstrikeus
    Testing for Code Injection
    0
    installs
  65. Wstg Inpv 12 · cyberstrikeus
    Testing for Command Injection
    0
    installs
  66. Wstg Inpv 13 · cyberstrikeus
    Testing for Format String Injection
    0
    installs
  67. Wstg Inpv 14 · cyberstrikeus
    Testing for Incubated Vulnerabilities
    0
    installs
  68. Wstg Inpv 15 · cyberstrikeus
    Testing for HTTP Splitting/Smuggling
    0
    installs
  69. Wstg Inpv 16 · cyberstrikeus
    Testing for HTTP Incoming Requests
    0
    installs
  70. Wstg Inpv 17 · cyberstrikeus
    Testing for Host Header Injection
    0
    installs
  71. Wstg Inpv 18 · cyberstrikeus
    Testing for Server-Side Template Injection (SSTI)
    0
    installs
  72. T1672 Email Spoofing · cyberstrikeus
    Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses.
    0
    installs
  73. T1555 001 Keychain · cyberstrikeus
    Adversaries may acquire credentials from Keychain.
    0
    installs
  74. T1490 Inhibit System Recovery · cyberstrikeus
    Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
    0
    installs
  75. T1491 001 Internal Defacement · cyberstrikeus
    An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.
    0
    installs
  76. T1491 002 External Defacement · cyberstrikeus
    An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or otherwise mislead an organization or users.
    0
    installs
  77. T1496 002 Bandwidth Hijacking · cyberstrikeus
    Adversaries may leverage the network bandwidth resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.
    0
    installs
  78. T1499 001 Os Exhaustion Flood · cyberstrikeus
    Adversaries may launch a denial of service (DoS) attack targeting an endpoint's operating system (OS).
    0
    installs
  79. T1561 002 Disk Structure Wipe · cyberstrikeus
    Adversaries may corrupt or wipe the disk data structures on a hard drive necessary to boot a system; targeting specific critical systems or in large numbers in a network to interrupt availability t...
    0
    installs
  80. T1589 001 Credentials · cyberstrikeus
    Adversaries may gather credentials that can be used during targeting.
    0
    installs
  81. T1595 Active Scanning · cyberstrikeus
    Adversaries may execute active reconnaissance scans to gather information that can be used during targeting.
    0
    installs
  82. Maintenance Pr Ma Maintenance · cyberstrikeus
    Maintenance
    0
    installs
  83. Incident Response Reporting And Communication Rs Co Incident · cyberstrikeus
    Response activities are coordinated with internal and external stakeholders as required by laws, regulations, or policies
    0
    installs
  84. Ac 17 Remote Access · cyberstrikeus
    Establish and document usage restrictions, configuration/connection requirements, and implementation guidance for each type of remote access allowed;
    0
    installs
  85. Ir 8 1 Breaches · cyberstrikeus
    Include the following in the Incident Response Plan for breaches involving personally identifiable information: A process to determine if notice to in
    0
    installs
  86. Ir 9 2 Training · cyberstrikeus
    Provide information spillage response training [organization-defined].
    0
    installs
  87. Ma 2 1 Record Content · cyberstrikeus
    Record Content
    0
    installs
  88. Ma 3 Maintenance Tools · cyberstrikeus
    Approve, control, and monitor the use of system maintenance tools;
    0
    installs
  89. Ma 7 Field Maintenance · cyberstrikeus
    Restrict or prohibit field maintenance on [organization-defined] to [organization-defined].
    0
    installs
  90. Mp 2 Media Access · cyberstrikeus
    Restrict access to [organization-defined] to [organization-defined].
    0
    installs
  91. Pm 32 Purposing · cyberstrikeus
    Analyze [organization-defined] supporting mission essential services or functions to ensure that the information resources are being used consistent w
    0
    installs
  92. Ra 7 Risk Response · cyberstrikeus
    Respond to findings from security and privacy assessments, monitoring, and audits in accordance with organizational risk tolerance.
    0
    installs
  93. T0887 Wireless Sniffing · cyberstrikeus
    Adversaries may seek to capture radio frequency (RF) communication used for remote control and reporting in distributed environments.
    0
    installs
  94. T0826 Loss Of Availability · cyberstrikeus
    Adversaries may attempt to disrupt essential components or systems to prevent owner and operator from delivering products or services.
    0
    installs
  95. T0832 Manipulation Of View · cyberstrikeus
    Adversaries may attempt to manipulate the information reported back to operators or controllers.
    0
    installs
  96. T0848 Rogue Master · cyberstrikeus
    Adversaries may setup a rogue master to leverage control server functions to communicate with outstations.
    0
    installs
  97. T0839 Module Firmware · cyberstrikeus
    Adversaries may install malicious or vulnerable firmware onto modular hardware devices.
    0
    installs
  98. T0857 System Firmware · cyberstrikeus
    System firmware on modern assets is often designed with an update feature.
    0
    installs
  99. T1641 Data Manipulation · cyberstrikeus
    Adversaries may insert, delete, or alter data in order to manipulate external outcomes or hide activity.
    0
    installs
  100. T1417 Input Capture · cyberstrikeus
    Adversaries may use methods of capturing user input to obtain credentials or collect information.
    0
    installs