cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ T1429 Audio Capture · cyberstrikeusAdversaries may capture audio to collect information by leveraging standard operating system APIs of a mobile device.
- ▌ T1512 Video Capture · cyberstrikeusAn adversary can leverage a device’s cameras to gather information by capturing video recordings.
- ▌ T1623 001 Unix Shell · cyberstrikeusAdversaries may abuse Unix shell commands and scripts for execution.
- ▌ T1059 010 Autohotkey Autoit · cyberstrikeusAdversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts.
- ▌ T1204 005 Malicious Library · cyberstrikeusAdversaries may rely on a user installing a malicious library to facilitate execution.
- ▌ T1569 002 Service Execution · cyberstrikeusAdversaries may abuse the Windows service control manager to execute malicious commands or payloads.
- ▌ T1176 Software Extensions · cyberstrikeusAdversaries may abuse software extensions to establish persistent access to victim systems.
- ▌ T1505 002 Transport Agent · cyberstrikeusAdversaries may abuse Microsoft transport agents to establish persistent access to systems.
- ▌ T1542 001 System Firmware · cyberstrikeusAdversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are exa...
- ▌ T1543 002 Systemd Service · cyberstrikeusAdversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence.
- ▌ T1543 003 Windows Service · cyberstrikeusAdversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
- ▌ T1574 004 Dylib Hijacking · cyberstrikeusAdversaries may execute their own payloads by placing a malicious dynamic library (dylib) with an expected name in a path a victim application searches at runtime.
- ▌ T1027 015 Compression · cyberstrikeusAdversaries may use compression to obfuscate their payloads or files.
- ▌ T1055 009 Proc Memory · cyberstrikeusAdversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1112 Modify Registry · cyberstrikeusAdversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
- ▌ T1218 004 Installutil · cyberstrikeusAdversaries may use InstallUtil to proxy execution of code through a trusted Windows utility.
- ▌ T1562 Impair Defenses · cyberstrikeusAdversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms.
- ▌ T1564 013 Bind Mounts · cyberstrikeusAdversaries may abuse bind mounts on file structures to hide their activity and artifacts from native utilities.
- ▌ T1678 Delay Execution · cyberstrikeusAdversaries may employ various time-based methods to evade detection and analysis.
- ▌ T1557 004 Evil Twin · cyberstrikeusAdversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as Network Sniffing, Transmitted Da...
- ▌ T1124 System Time Discovery · cyberstrikeusAn adversary may gather the system time and/or time zone settings from a local or remote system.
- ▌ T1119 Automated Collection · cyberstrikeusOnce established within a system or network, an adversary may use automated techniques for collecting internal data.
- ▌ T1029 Scheduled Transfer · cyberstrikeusAdversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals.
- ▌ T1102 Web Service · cyberstrikeusAdversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.
- ▌ T1498 001 Direct Network Flood · cyberstrikeusAdversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target.
- ▌ T1583 004 Server · cyberstrikeusAdversaries may buy, lease, rent, or obtain physical servers that can be used during targeting.
- ▌ T1583 005 Botnet · cyberstrikeusAdversaries may buy, lease, or rent a network of compromised systems that can be used during targeting.
- ▌ T1584 004 Server · cyberstrikeusAdversaries may compromise third-party servers that can be used during targeting.
- ▌ T1584 005 Botnet · cyberstrikeusAdversaries may compromise numerous third-party systems to form a botnet that can be used during targeting.
- ▌ T1590 005 Ip Addresses · cyberstrikeusAdversaries may gather the victim's IP addresses that can be used during targeting.
- ▌ T1593 001 Social Media · cyberstrikeusAdversaries may search social media for information about victims that can be used during targeting.
- ▌ Improvement Id Im Improvement · cyberstrikeusImprovements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
- ▌ Platform Security Pr Ps Platform Security · cyberstrikeusThe hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with t
- ▌ Incident Analysis Rs An Incident Analysis · cyberstrikeusInvestigations are conducted to ensure effective response and support forensics and recovery activities
- ▌
- ▌ Ac 4 22 Access Only · cyberstrikeusProvide access from a single device to computing platforms, applications, or data residing in multiple different security domains, while preventing in
- ▌ Ac 6 Least Privilege · cyberstrikeusEmploy the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to ac
- ▌ Ma 6 Timely Maintenance · cyberstrikeusObtain maintenance support and/or spare parts for [organization-defined] within [organization-defined] of failure.
- ▌ Mp 3 Media Marking · cyberstrikeusMark system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information;
- ▌ Mp 4 Media Storage · cyberstrikeusPhysically control and securely store [organization-defined] within [organization-defined] ;
- ▌ Mp 5 3 Custodians · cyberstrikeusEmploy an identified custodian during transport of system media outside of controlled areas.
- ▌ Pl 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] planning policy that: Procedures to facilitate the implementation
- ▌ Pl 7 Concept Of Operations · cyberstrikeusDevelop a Concept of Operations (CONOPS) for the system describing how the organization intends to operate the system from the perspective of infor...
- ▌ Pl 8 2 Supplier Diversity · cyberstrikeusRequire that [organization-defined] allocated to [organization-defined] are obtained from different suppliers.
- ▌ T1414 Clipboard Data · cyberstrikeusAdversaries may abuse clipboard manager APIs to obtain sensitive information copied to the device clipboard.
- ▌ T1417 001 Keylogging · cyberstrikeusAdversaries may log user keystrokes to intercept credentials or other information from the user as the user types them.
- ▌ T1513 Screen Capture · cyberstrikeusAdversaries may use screen capture to collect additional information about a target device, such as applications running in the foreground, user data, credentials, or other sensitive information.
- ▌ T1676 Linked Devices · cyberstrikeusAdversaries may abuse the “linked devices” feature on messaging applications, such as Signal and WhatsApp, to register the user’s account to an adversary-controlled device.
- ▌ T1659 Content Injection · cyberstrikeusAdversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic.
- ▌ T1059 008 Network Device CLI · cyberstrikeusAdversaries may abuse scripting or built-in command line interpreters (CLI) on network devices to execute malicious command and payloads.
- ▌ T1098 Account Manipulation · cyberstrikeusAdversaries may manipulate accounts to maintain and/or elevate access to victim systems.
- ▌ T1547 012 Print Processors · cyberstrikeusAdversaries may abuse print processors to run malicious DLLs during system boot for persistence and/or privilege escalation.
- ▌ T1574 014 Appdomainmanager · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies.
- ▌ T1055 015 Listplanting · cyberstrikeusAdversaries may abuse list-view controls to inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1553 002 Code Signing · cyberstrikeusAdversaries may create, acquire, or steal code signing materials to sign their malware or tools.
- ▌ T1564 002 Hidden Users · cyberstrikeusAdversaries may use hidden users to hide the presence of user accounts they create or modify.
- ▌ T1564 007 Vba Stomping · cyberstrikeusAdversaries may hide malicious Visual Basic for Applications (VBA) payloads embedded within MS Office documents by replacing the VBA source code with benign data.
- ▌ T1610 Deploy Container · cyberstrikeusAdversaries may deploy a container into an environment to facilitate execution or evade defenses.
- ▌ T1622 Debugger Evasion · cyberstrikeusAdversaries may employ various means to detect and avoid debuggers.
- ▌ T1482 Domain Trust Discovery · cyberstrikeusAdversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
- ▌ T1615 Group Policy Discovery · cyberstrikeusAdversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that ca...
- ▌ T1021 Remote Services · cyberstrikeusAdversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC.
- ▌ T1056 002 Gui Input Capture · cyberstrikeusAdversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt.
- ▌ T1213 003 Code Repositories · cyberstrikeusAdversaries may leverage code repositories to collect valuable information.
- ▌ T1486 Data Encrypted For Impact · cyberstrikeusAdversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
- ▌ T1498 Network Denial Of Service · cyberstrikeusAdversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users.
- ▌ T1499 004 Application Or System Exploitation · cyberstrikeusAdversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
- ▌ T1583 001 Domains · cyberstrikeusAdversaries may acquire domains that can be used during targeting.
- ▌ T1584 001 Domains · cyberstrikeusAdversaries may hijack domains and/or subdomains that can be used during targeting.
- ▌ T1587 001 Malware · cyberstrikeusAdversaries may develop malware and malware components that can be used during targeting.
- ▌ T1588 001 Malware · cyberstrikeusAdversaries may buy, steal, or download malware that can be used during targeting.
- ▌
- ▌
- ▌ Ac 18 Wireless Access · cyberstrikeusEstablish configuration requirements, connection requirements, and implementation guidance for each type of wireless access;
- ▌ Ac 4 9 Human Reviews · cyberstrikeusEnforce the use of human reviews for [organization-defined] under the following conditions: [organization-defined].
- ▌ Cp 12 Safe Mode · cyberstrikeusWhen [organization-defined] are detected, enter a safe mode of operation with [organization-defined].
- ▌ Ra 10 Threat Hunting · cyberstrikeusEstablish and maintain a cyber threat hunting capability to: Search for indicators of compromise in organizational systems; and Detect, track, and dis
- ▌ Ra 3 Risk Assessment · cyberstrikeusConduct a risk assessment, including: Identifying threats to and vulnerabilities in the system; Determining the likelihood and magnitude of harm from
- ▌ T1575 Native API · cyberstrikeusAdversaries may use Android’s Native Development Kit (NDK) to write native functions that can achieve execution of binaries or functions.
- ▌ T1200 Hardware Additions · cyberstrikeusAdversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access.
- ▌ T1137 004 Outlook Home Page · cyberstrikeusAdversaries may abuse Microsoft Outlook's Home Page feature to obtain persistence on a compromised system.
- ▌ T1543 005 Container Service · cyberstrikeusAdversaries may create or modify container or container cluster management tools that run as daemons, agents, or services on individual hosts.
- ▌ T1574 Hijack Execution Flow · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking the way operating systems run programs.
- ▌ T1027 003 Steganography · cyberstrikeusAdversaries may use steganography techniques in order to prevent the detection of hidden information.
- ▌ T1027 017 Svg Smuggling · cyberstrikeusAdversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign SVG files.
- ▌ T1055 Process Injection · cyberstrikeusAdversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1070 Indicator Removal · cyberstrikeusAdversaries may delete or modify artifacts generated within systems to remove evidence of their presence or hinder defenses.
- ▌ T1070 004 File Deletion · cyberstrikeusAdversaries may delete files left behind by the actions of their intrusion activity.
- ▌ T1205 Traffic Signaling · cyberstrikeusAdversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control.
- ▌ T1205 001 Port Knocking · cyberstrikeusAdversaries may use port knocking to hide open ports used for persistence or command and control.
- ▌ T1218 002 Control Panel · cyberstrikeusAdversaries may abuse control.exe to proxy execution of malicious payloads.
- ▌ T1218 009 Regsvcsregasm · cyberstrikeusAdversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility.
- ▌ T1497 001 System Checks · cyberstrikeusAdversaries may employ various system checks to detect and avoid virtualization and analysis environments.
- ▌ T1550 002 Pass The Hash · cyberstrikeusAdversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls.
- ▌ T1564 003 Hidden Window · cyberstrikeusAdversaries may use hidden windows to conceal malicious activity from the plain sight of users.
- ▌ T1600 Weaken Encryption · cyberstrikeusAdversaries may compromise a network device’s encryption capability in order to bypass encryption that would otherwise protect data communications.
- ▌ T1003 004 Lsa Secrets · cyberstrikeusAdversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service...
- ▌ T1606 001 Web Cookies · cyberstrikeusAdversaries may forge web cookies that can be used to gain access to web applications or Internet services.
- ▌ T1606 002 Saml Tokens · cyberstrikeusAn adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate.
- ▌ T1018 Remote System Discovery · cyberstrikeusAdversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.