cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ T1135 Network Share Discovery · cyberstrikeusAdversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of in...
- ▌ T1526 Cloud Service Discovery · cyberstrikeusAn adversary may attempt to enumerate the cloud services running on a system after gaining access.
- ▌ T1538 Cloud Service Dashboard · cyberstrikeusAn adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment, such as specific services, resources, and features.
- ▌ T1652 Device Driver Discovery · cyberstrikeusAdversaries may attempt to enumerate local device drivers on a victim host.
- ▌ T1680 Local Storage Discovery · cyberstrikeusAdversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
- ▌ T1005 Data From Local System · cyberstrikeusAdversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior...
- ▌ T1056 003 Web Portal Capture · cyberstrikeusAdversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service.
- ▌ T1074 001 Local Data Staging · cyberstrikeusAdversaries may stage collected data in a central location or directory on the local system prior to Exfiltration.
- ▌ T1560 Archive Collected Data · cyberstrikeusAn adversary may compress and/or encrypt data that is collected prior to exfiltration.
- ▌ T1001 001 Junk Data · cyberstrikeusAdversaries may add junk data to protocols used for command and control to make detection more difficult.
- ▌ T1132 Data Encoding · cyberstrikeusAdversaries may encode data to make the content of command and control traffic more difficult to detect.
- ▌ T1499 Endpoint Denial Of Service · cyberstrikeusAdversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users.
- ▌ T1587 004 Exploits · cyberstrikeusAdversaries may develop exploits that can be used during targeting.
- ▌ T1588 005 Exploits · cyberstrikeusAdversaries may buy, steal, or download exploits that can be used during targeting.
- ▌ T1589 003 Employee Names · cyberstrikeusAdversaries may gather employee names that can be used during targeting.
- ▌ T1591 004 Identify Roles · cyberstrikeusAdversaries may gather information about identities and roles within the victim organization that can be used during targeting.
- ▌ T1593 002 Search Engines · cyberstrikeusAdversaries may use search engines to collect information about victims that can be used during targeting.
- ▌ T1596 001 Dnspassive Dns · cyberstrikeusAdversaries may search DNS data for information about victims that can be used during targeting.
- ▌ T1596 005 Scan Databases · cyberstrikeusAdversaries may search within public scan databases for information about victims that can be used during targeting.
- ▌
- ▌ Risk Management Strategy Gv Rm Risk Management Strategy · cyberstrikeusThe organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support
- ▌ Incident Management Rs Ma Incident Management · cyberstrikeusResponses to detected cybersecurity incidents are managed
- ▌ Incident Mitigation Rs Mi Incident Mitigation · cyberstrikeusActivities are performed to prevent expansion of an event and mitigate its effects
- ▌ Po 1 1 Po11 · cyberstrikeusIdentify and document all security requirements for the organization’s software development infrastructures and processes, and maintain the requiremen
- ▌ Po 1 2 Po12 · cyberstrikeusIdentify and document all security requirements for organization-developed software to meet, and maintain the requirements over time.
- ▌ Po 1 3 Po13 · cyberstrikeusCommunicate requirements to all third parties who will provide commercial software components to the organization for reuse by the organization’s o...
- ▌ Po 2 1 Po21 · cyberstrikeusCreate new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC.
- ▌ Po 2 2 Po22 · cyberstrikeusProvide role-based training for all personnel with responsibilities that contribute to secure development.
- ▌ Po 2 3 Po23 · cyberstrikeusObtain upper management or authorizing official commitment to secure development, and convey that commitment to all with development-related roles and
- ▌ Po 3 1 Po31 · cyberstrikeusSpecify which tools or tool types must or should be included in each toolchain to mitigate identified risks, as well as how the toolchain components a
- ▌ Po 3 2 Po32 · cyberstrikeusFollow recommended security practices to deploy, operate, and maintain tools and toolchains.
- ▌ Po 3 3 Po33 · cyberstrikeusConfigure tools to generate artifacts of their support of secure software development practices as defined by the organization.
- ▌ Po 4 1 Po41 · cyberstrikeusDefine criteria for software security checks and track throughout the SDLC.
- ▌
- ▌
- ▌ Po 5 2 Po52 · cyberstrikeusSecure and harden development endpoints (i.e., endpoints for software designers, developers, testers, builders, etc.) to perform development-related t
- ▌ Ma 4 Nonlocal Maintenance · cyberstrikeusApprove and monitor nonlocal maintenance and diagnostic activities;
- ▌ Ma 5 4 Foreign Nationals · cyberstrikeusEnsure that: Foreign nationals with appropriate security clearances are used to conduct maintenance and diagnostic activities on classified systems on
- ▌ Mp 5 Media Transport · cyberstrikeusProtect and control [organization-defined] during transport outside of controlled areas using [organization-defined];
- ▌ Pm 28 Risk Framing · cyberstrikeusIdentify and document: Assumptions affecting risk assessments, risk responses, and risk monitoring; Constraints affecting risk assessments, risk respo
- ▌ Pm 7 1 Offloading · cyberstrikeusOffload [organization-defined] to other systems, system components, or an external provider.
- ▌ T0831 Manipulation Of Control · cyberstrikeusAdversaries may manipulate physical process control within the industrial environment.
- ▌ T0886 Remote Services · cyberstrikeusAdversaries may leverage remote services to move between assets and network segments.
- ▌ T1424 Process Discovery · cyberstrikeusAdversaries may attempt to get information about running processes on a device.
- ▌ T1636 003 Contact List · cyberstrikeusAdversaries may utilize standard operating system APIs to gather contact list data.
- ▌ T1636 004 Sms Messages · cyberstrikeusAdversaries may utilize standard operating system APIs to gather SMS messages.
- ▌ T1603 Scheduled Taskjob · cyberstrikeusAdversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
- ▌ T1189 Drive By Compromise · cyberstrikeusAdversaries may gain access to a system through a user visiting a website over the normal course of browsing.
- ▌ T1176 001 Browser Extensions · cyberstrikeusAdversaries may abuse internet browser extensions to establish persistent access to victim systems.
- ▌ T1525 Implant Internal Image · cyberstrikeusAdversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment.
- ▌ T1542 002 Component Firmware · cyberstrikeusAdversaries may modify component firmware to persist on systems.
- ▌ T1027 001 Binary Padding · cyberstrikeusAdversaries may use binary padding to add junk data and change the on-disk representation of malware.
- ▌ T1027 006 HTML Smuggling · cyberstrikeusAdversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.
- ▌ T1055 014 Vdso Hijacking · cyberstrikeusAdversaries may inject malicious code into processes via VDSO hijacking in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1078 003 Local Accounts · cyberstrikeusAdversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
- ▌ T1078 004 Cloud Accounts · cyberstrikeusValid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
- ▌ T1205 002 Socket Filters · cyberstrikeusAdversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and control.
- ▌ T1221 Template Injection · cyberstrikeusAdversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts.
- ▌ T1562 009 Safe Mode Boot · cyberstrikeusAdversaries may abuse Windows safe mode to disable endpoint defenses.
- ▌ T1003 001 Lsass Memory · cyberstrikeusAdversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
- ▌ T1040 Network Sniffing · cyberstrikeusAdversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network.
- ▌ T1552 004 Private Keys · cyberstrikeusAdversaries may search for private key certificate files on compromised systems for insecurely stored credentials.
- ▌ T1558 005 Ccache Files · cyberstrikeusAdversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache).
- ▌ T1007 System Service Discovery · cyberstrikeusAdversaries may try to gather information about registered local system services.
- ▌ T1563 001 Ssh Hijacking · cyberstrikeusAdversaries may hijack a legitimate user's SSH session to move laterally within an environment.
- ▌ T1563 002 Rdp Hijacking · cyberstrikeusAdversaries may hijack a legitimate user’s remote desktop session to move laterally within an environment.
- ▌ T1074 002 Remote Data Staging · cyberstrikeusAdversaries may stage data collected from multiple systems in a central location or directory on one system prior to Exfiltration.
- ▌
- ▌ T1560 001 Archive Via Utility · cyberstrikeusAdversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
- ▌ T1560 002 Archive Via Library · cyberstrikeusAn adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries.
- ▌ T1496 004 Cloud Service Hijacking · cyberstrikeusAdversaries may leverage compromised software-as-a-service (SaaS) applications to complete resource-intensive tasks, which may impact hosted service availability.
- ▌ T1629 Impair Defenses · cyberstrikeusAdversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms.
- ▌ T1517 Access Notifications · cyberstrikeusAdversaries may collect data within notifications sent by the operating system or other applications.
- ▌ T1636 001 Calendar Entries · cyberstrikeusAdversaries may utilize standard operating system APIs to gather calendar entry data.
- ▌ T1481 Web Service · cyberstrikeusAdversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.
- ▌ T1195 Supply Chain Compromise · cyberstrikeusAdversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ T1195 001 Compromise Software Dependencies And Development T · cyberstrikeusAdversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise.
- ▌ T1566 004 Spearphishing Voice · cyberstrikeusAdversaries may use voice communications to ultimately gain access to victim systems.
- ▌ T1204 004 Malicious Copy And Paste · cyberstrikeusAn adversary may rely upon a user copying and pasting code in order to gain execution.
- ▌ T1651 Cloud Administration Command · cyberstrikeusAdversaries may abuse cloud management services to execute commands within virtual machines.
- ▌ T1098 003 Additional Cloud Roles · cyberstrikeusAn adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant.
- ▌ T1137 Office Application Startup · cyberstrikeusAdversaries may leverage Microsoft Office-based applications for persistence between startups.
- ▌ T1137 001 Office Template Macros · cyberstrikeusAdversaries may abuse Microsoft Office templates to obtain persistence on a compromised system.
- ▌ T1547 002 Authentication Package · cyberstrikeusAdversaries may abuse authentication packages to execute DLLs when the system boots.
- ▌ T1547 007 Re Opened Applications · cyberstrikeusAdversaries may modify plist files to automatically run an application when a user logs in.
- ▌ T1027 012 Lnk Icon Smuggling · cyberstrikeusAdversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files.
- ▌ T1070 008 Clear Mailbox Data · cyberstrikeusAdversaries may modify mail and mail application data to remove evidence of their activity.
- ▌ T1218 001 Compiled HTML File · cyberstrikeusAdversaries may abuse Compiled HTML files (.chm) to conceal malicious code.
- ▌ T1484 002 Trust Modification · cyberstrikeusAdversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses an...
- ▌ T1550 004 Web Session Cookie · cyberstrikeusAdversaries can use stolen session cookies to authenticate to web applications and services.
- ▌ T1553 Subvert Trust Controls · cyberstrikeusAdversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs.
- ▌ T1562 006 Indicator Blocking · cyberstrikeusAn adversary may attempt to block indicators or events typically captured by sensors from being gathered and analyzed.
- ▌ T1564 005 Hidden File System · cyberstrikeusAdversaries may use a hidden file system to conceal malicious activity from users and security tools.
- ▌ T1564 008 Email Hiding Rules · cyberstrikeusAdversaries may use email rules to hide inbound emails in a compromised user's mailbox.
- ▌ T1601 001 Patch System Image · cyberstrikeusAdversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses.
- ▌ T1555 002 Securityd Memory · cyberstrikeusAn adversary with root access may gather credentials by reading `securityd`’s memory.
- ▌ T1010 Application Window Discovery · cyberstrikeusAdversaries may attempt to get a listing of open application windows.
- ▌ T1016 System Network Configuration Discovery · cyberstrikeusAdversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
- ▌ T1082 System Information Discovery · cyberstrikeusAn adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
- ▌ T1083 File And Directory Discovery · cyberstrikeusAdversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.