← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 67 of 72

  1. T1429 Audio Capture · cyberstrikeus
    Adversaries may capture audio to collect information by leveraging standard operating system APIs of a mobile device.
    0
    installs
  2. T1512 Video Capture · cyberstrikeus
    An adversary can leverage a device’s cameras to gather information by capturing video recordings.
    0
    installs
  3. T1623 001 Unix Shell · cyberstrikeus
    Adversaries may abuse Unix shell commands and scripts for execution.
    0
    installs
  4. T1059 010 Autohotkey Autoit · cyberstrikeus
    Adversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts.
    0
    installs
  5. T1204 005 Malicious Library · cyberstrikeus
    Adversaries may rely on a user installing a malicious library to facilitate execution.
    0
    installs
  6. T1569 002 Service Execution · cyberstrikeus
    Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
    0
    installs
  7. T1176 Software Extensions · cyberstrikeus
    Adversaries may abuse software extensions to establish persistent access to victim systems.
    0
    installs
  8. T1505 002 Transport Agent · cyberstrikeus
    Adversaries may abuse Microsoft transport agents to establish persistent access to systems.
    0
    installs
  9. T1542 001 System Firmware · cyberstrikeus
    Adversaries may modify system firmware to persist on systems.The BIOS (Basic Input/Output System) and The Unified Extensible Firmware Interface (UEFI) or Extensible Firmware Interface (EFI) are exa...
    0
    installs
  10. T1543 002 Systemd Service · cyberstrikeus
    Adversaries may create or modify systemd services to repeatedly execute malicious payloads as part of persistence.
    0
    installs
  11. T1543 003 Windows Service · cyberstrikeus
    Adversaries may create or modify Windows services to repeatedly execute malicious payloads as part of persistence.
    0
    installs
  12. T1574 004 Dylib Hijacking · cyberstrikeus
    Adversaries may execute their own payloads by placing a malicious dynamic library (dylib) with an expected name in a path a victim application searches at runtime.
    0
    installs
  13. T1027 015 Compression · cyberstrikeus
    Adversaries may use compression to obfuscate their payloads or files.
    0
    installs
  14. T1055 009 Proc Memory · cyberstrikeus
    Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges.
    0
    installs
  15. T1112 Modify Registry · cyberstrikeus
    Adversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.
    0
    installs
  16. T1218 004 Installutil · cyberstrikeus
    Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility.
    0
    installs
  17. T1562 Impair Defenses · cyberstrikeus
    Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms.
    0
    installs
  18. T1564 013 Bind Mounts · cyberstrikeus
    Adversaries may abuse bind mounts on file structures to hide their activity and artifacts from native utilities.
    0
    installs
  19. T1678 Delay Execution · cyberstrikeus
    Adversaries may employ various time-based methods to evade detection and analysis.
    0
    installs
  20. T1557 004 Evil Twin · cyberstrikeus
    Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as Network Sniffing, Transmitted Da...
    0
    installs
  21. T1124 System Time Discovery · cyberstrikeus
    An adversary may gather the system time and/or time zone settings from a local or remote system.
    0
    installs
  22. T1119 Automated Collection · cyberstrikeus
    Once established within a system or network, an adversary may use automated techniques for collecting internal data.
    0
    installs
  23. T1029 Scheduled Transfer · cyberstrikeus
    Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals.
    0
    installs
  24. T1102 Web Service · cyberstrikeus
    Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.
    0
    installs
  25. T1498 001 Direct Network Flood · cyberstrikeus
    Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target.
    0
    installs
  26. T1583 004 Server · cyberstrikeus
    Adversaries may buy, lease, rent, or obtain physical servers that can be used during targeting.
    0
    installs
  27. T1583 005 Botnet · cyberstrikeus
    Adversaries may buy, lease, or rent a network of compromised systems that can be used during targeting.
    0
    installs
  28. T1584 004 Server · cyberstrikeus
    Adversaries may compromise third-party servers that can be used during targeting.
    0
    installs
  29. T1584 005 Botnet · cyberstrikeus
    Adversaries may compromise numerous third-party systems to form a botnet that can be used during targeting.
    0
    installs
  30. T1590 005 Ip Addresses · cyberstrikeus
    Adversaries may gather the victim's IP addresses that can be used during targeting.
    0
    installs
  31. T1593 001 Social Media · cyberstrikeus
    Adversaries may search social media for information about victims that can be used during targeting.
    0
    installs
  32. Improvement Id Im Improvement · cyberstrikeus
    Improvements to organizational cybersecurity risk management processes, procedures and activities are identified across all CSF Functions
    0
    installs
  33. Platform Security Pr Ps Platform Security · cyberstrikeus
    The hardware, software (e.g., firmware, operating systems, applications), and services of physical and virtual platforms are managed consistent with t
    0
    installs
  34. Incident Analysis Rs An Incident Analysis · cyberstrikeus
    Investigations are conducted to ensure effective response and support forensics and recovery activities
    0
    installs
  35. Response Planning Rs Rp Response Planning · cyberstrikeus
    Response Planning
    0
    installs
  36. Ac 4 22 Access Only · cyberstrikeus
    Provide access from a single device to computing platforms, applications, or data residing in multiple different security domains, while preventing in
    0
    installs
  37. Ac 6 Least Privilege · cyberstrikeus
    Employ the principle of least privilege, allowing only authorized accesses for users (or processes acting on behalf of users) that are necessary to ac
    0
    installs
  38. Ma 6 Timely Maintenance · cyberstrikeus
    Obtain maintenance support and/or spare parts for [organization-defined] within [organization-defined] of failure.
    0
    installs
  39. Mp 3 Media Marking · cyberstrikeus
    Mark system media indicating the distribution limitations, handling caveats, and applicable security markings (if any) of the information;
    0
    installs
  40. Mp 4 Media Storage · cyberstrikeus
    Physically control and securely store [organization-defined] within [organization-defined] ;
    0
    installs
  41. Mp 5 3 Custodians · cyberstrikeus
    Employ an identified custodian during transport of system media outside of controlled areas.
    0
    installs
  42. Pl 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] planning policy that: Procedures to facilitate the implementation
    0
    installs
  43. Pl 7 Concept Of Operations · cyberstrikeus
    Develop a Concept of Operations (CONOPS) for the system describing how the organization intends to operate the system from the perspective of infor...
    0
    installs
  44. Pl 8 2 Supplier Diversity · cyberstrikeus
    Require that [organization-defined] allocated to [organization-defined] are obtained from different suppliers.
    0
    installs
  45. T1414 Clipboard Data · cyberstrikeus
    Adversaries may abuse clipboard manager APIs to obtain sensitive information copied to the device clipboard.
    0
    installs
  46. T1417 001 Keylogging · cyberstrikeus
    Adversaries may log user keystrokes to intercept credentials or other information from the user as the user types them.
    0
    installs
  47. T1513 Screen Capture · cyberstrikeus
    Adversaries may use screen capture to collect additional information about a target device, such as applications running in the foreground, user data, credentials, or other sensitive information.
    0
    installs
  48. T1676 Linked Devices · cyberstrikeus
    Adversaries may abuse the “linked devices” feature on messaging applications, such as Signal and WhatsApp, to register the user’s account to an adversary-controlled device.
    0
    installs
  49. T1659 Content Injection · cyberstrikeus
    Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic.
    0
    installs
  50. T1059 008 Network Device CLI · cyberstrikeus
    Adversaries may abuse scripting or built-in command line interpreters (CLI) on network devices to execute malicious command and payloads.
    0
    installs
  51. T1098 Account Manipulation · cyberstrikeus
    Adversaries may manipulate accounts to maintain and/or elevate access to victim systems.
    0
    installs
  52. T1547 012 Print Processors · cyberstrikeus
    Adversaries may abuse print processors to run malicious DLLs during system boot for persistence and/or privilege escalation.
    0
    installs
  53. T1574 014 Appdomainmanager · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking how the .NET `AppDomainManager` loads assemblies.
    0
    installs
  54. T1055 015 Listplanting · cyberstrikeus
    Adversaries may abuse list-view controls to inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.
    0
    installs
  55. T1553 002 Code Signing · cyberstrikeus
    Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
    0
    installs
  56. T1564 002 Hidden Users · cyberstrikeus
    Adversaries may use hidden users to hide the presence of user accounts they create or modify.
    0
    installs
  57. T1564 007 Vba Stomping · cyberstrikeus
    Adversaries may hide malicious Visual Basic for Applications (VBA) payloads embedded within MS Office documents by replacing the VBA source code with benign data.
    0
    installs
  58. T1610 Deploy Container · cyberstrikeus
    Adversaries may deploy a container into an environment to facilitate execution or evade defenses.
    0
    installs
  59. T1622 Debugger Evasion · cyberstrikeus
    Adversaries may employ various means to detect and avoid debuggers.
    0
    installs
  60. T1482 Domain Trust Discovery · cyberstrikeus
    Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
    0
    installs
  61. T1615 Group Policy Discovery · cyberstrikeus
    Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that ca...
    0
    installs
  62. T1021 Remote Services · cyberstrikeus
    Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC.
    0
    installs
  63. T1056 002 Gui Input Capture · cyberstrikeus
    Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt.
    0
    installs
  64. T1213 003 Code Repositories · cyberstrikeus
    Adversaries may leverage code repositories to collect valuable information.
    0
    installs
  65. T1486 Data Encrypted For Impact · cyberstrikeus
    Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
    0
    installs
  66. T1498 Network Denial Of Service · cyberstrikeus
    Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users.
    0
    installs
  67. T1499 004 Application Or System Exploitation · cyberstrikeus
    Adversaries may exploit software vulnerabilities that can cause an application or system to crash and deny availability to users.
    0
    installs
  68. T1583 001 Domains · cyberstrikeus
    Adversaries may acquire domains that can be used during targeting.
    0
    installs
  69. T1584 001 Domains · cyberstrikeus
    Adversaries may hijack domains and/or subdomains that can be used during targeting.
    0
    installs
  70. T1587 001 Malware · cyberstrikeus
    Adversaries may develop malware and malware components that can be used during targeting.
    0
    installs
  71. T1588 001 Malware · cyberstrikeus
    Adversaries may buy, steal, or download malware that can be used during targeting.
    0
    installs
  72. Improvements Rc Im Improvements · cyberstrikeus
    Improvements
    0
    installs
  73. Improvements Rs Im Improvements · cyberstrikeus
    Improvements
    0
    installs
  74. Ac 18 Wireless Access · cyberstrikeus
    Establish configuration requirements, connection requirements, and implementation guidance for each type of wireless access;
    0
    installs
  75. Ac 4 9 Human Reviews · cyberstrikeus
    Enforce the use of human reviews for [organization-defined] under the following conditions: [organization-defined].
    0
    installs
  76. Cp 12 Safe Mode · cyberstrikeus
    When [organization-defined] are detected, enter a safe mode of operation with [organization-defined].
    0
    installs
  77. Ra 10 Threat Hunting · cyberstrikeus
    Establish and maintain a cyber threat hunting capability to: Search for indicators of compromise in organizational systems; and Detect, track, and dis
    0
    installs
  78. Ra 3 Risk Assessment · cyberstrikeus
    Conduct a risk assessment, including: Identifying threats to and vulnerabilities in the system; Determining the likelihood and magnitude of harm from
    0
    installs
  79. T1575 Native API · cyberstrikeus
    Adversaries may use Android’s Native Development Kit (NDK) to write native functions that can achieve execution of binaries or functions.
    0
    installs
  80. T1200 Hardware Additions · cyberstrikeus
    Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access.
    0
    installs
  81. T1137 004 Outlook Home Page · cyberstrikeus
    Adversaries may abuse Microsoft Outlook's Home Page feature to obtain persistence on a compromised system.
    0
    installs
  82. T1543 005 Container Service · cyberstrikeus
    Adversaries may create or modify container or container cluster management tools that run as daemons, agents, or services on individual hosts.
    0
    installs
  83. T1574 Hijack Execution Flow · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking the way operating systems run programs.
    0
    installs
  84. T1027 003 Steganography · cyberstrikeus
    Adversaries may use steganography techniques in order to prevent the detection of hidden information.
    0
    installs
  85. T1027 017 Svg Smuggling · cyberstrikeus
    Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign SVG files.
    0
    installs
  86. T1055 Process Injection · cyberstrikeus
    Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges.
    0
    installs
  87. T1070 Indicator Removal · cyberstrikeus
    Adversaries may delete or modify artifacts generated within systems to remove evidence of their presence or hinder defenses.
    0
    installs
  88. T1070 004 File Deletion · cyberstrikeus
    Adversaries may delete files left behind by the actions of their intrusion activity.
    0
    installs
  89. T1205 Traffic Signaling · cyberstrikeus
    Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control.
    0
    installs
  90. T1205 001 Port Knocking · cyberstrikeus
    Adversaries may use port knocking to hide open ports used for persistence or command and control.
    0
    installs
  91. T1218 002 Control Panel · cyberstrikeus
    Adversaries may abuse control.exe to proxy execution of malicious payloads.
    0
    installs
  92. T1218 009 Regsvcsregasm · cyberstrikeus
    Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility.
    0
    installs
  93. T1497 001 System Checks · cyberstrikeus
    Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.
    0
    installs
  94. T1550 002 Pass The Hash · cyberstrikeus
    Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls.
    0
    installs
  95. T1564 003 Hidden Window · cyberstrikeus
    Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
    0
    installs
  96. T1600 Weaken Encryption · cyberstrikeus
    Adversaries may compromise a network device’s encryption capability in order to bypass encryption that would otherwise protect data communications.
    0
    installs
  97. T1003 004 Lsa Secrets · cyberstrikeus
    Adversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service...
    0
    installs
  98. T1606 001 Web Cookies · cyberstrikeus
    Adversaries may forge web cookies that can be used to gain access to web applications or Internet services.
    0
    installs
  99. T1606 002 Saml Tokens · cyberstrikeus
    An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate.
    0
    installs
  100. T1018 Remote System Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
    0
    installs