← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 68 of 72

  1. T1135 Network Share Discovery · cyberstrikeus
    Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of in...
    0
    installs
  2. T1526 Cloud Service Discovery · cyberstrikeus
    An adversary may attempt to enumerate the cloud services running on a system after gaining access.
    0
    installs
  3. T1538 Cloud Service Dashboard · cyberstrikeus
    An adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment, such as specific services, resources, and features.
    0
    installs
  4. T1652 Device Driver Discovery · cyberstrikeus
    Adversaries may attempt to enumerate local device drivers on a victim host.
    0
    installs
  5. T1680 Local Storage Discovery · cyberstrikeus
    Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
    0
    installs
  6. T1005 Data From Local System · cyberstrikeus
    Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior...
    0
    installs
  7. T1056 003 Web Portal Capture · cyberstrikeus
    Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service.
    0
    installs
  8. T1074 001 Local Data Staging · cyberstrikeus
    Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration.
    0
    installs
  9. T1560 Archive Collected Data · cyberstrikeus
    An adversary may compress and/or encrypt data that is collected prior to exfiltration.
    0
    installs
  10. T1001 001 Junk Data · cyberstrikeus
    Adversaries may add junk data to protocols used for command and control to make detection more difficult.
    0
    installs
  11. T1132 Data Encoding · cyberstrikeus
    Adversaries may encode data to make the content of command and control traffic more difficult to detect.
    0
    installs
  12. T1499 Endpoint Denial Of Service · cyberstrikeus
    Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users.
    0
    installs
  13. T1587 004 Exploits · cyberstrikeus
    Adversaries may develop exploits that can be used during targeting.
    0
    installs
  14. T1588 005 Exploits · cyberstrikeus
    Adversaries may buy, steal, or download exploits that can be used during targeting.
    0
    installs
  15. T1589 003 Employee Names · cyberstrikeus
    Adversaries may gather employee names that can be used during targeting.
    0
    installs
  16. T1591 004 Identify Roles · cyberstrikeus
    Adversaries may gather information about identities and roles within the victim organization that can be used during targeting.
    0
    installs
  17. T1593 002 Search Engines · cyberstrikeus
    Adversaries may use search engines to collect information about victims that can be used during targeting.
    0
    installs
  18. T1596 001 Dnspassive Dns · cyberstrikeus
    Adversaries may search DNS data for information about victims that can be used during targeting.
    0
    installs
  19. T1596 005 Scan Databases · cyberstrikeus
    Adversaries may search within public scan databases for information about victims that can be used during targeting.
    0
    installs
  20. Detection Processes De Dp Detection Processes · cyberstrikeus
    Detection Processes
    0
    installs
  21. Risk Management Strategy Gv Rm Risk Management Strategy · cyberstrikeus
    The organization's priorities, constraints, risk tolerance and appetite statements, and assumptions are established, communicated, and used to support
    0
    installs
  22. Incident Management Rs Ma Incident Management · cyberstrikeus
    Responses to detected cybersecurity incidents are managed
    0
    installs
  23. Incident Mitigation Rs Mi Incident Mitigation · cyberstrikeus
    Activities are performed to prevent expansion of an event and mitigate its effects
    0
    installs
  24. Po 1 1 Po11 · cyberstrikeus
    Identify and document all security requirements for the organization’s software development infrastructures and processes, and maintain the requiremen
    0
    installs
  25. Po 1 2 Po12 · cyberstrikeus
    Identify and document all security requirements for organization-developed software to meet, and maintain the requirements over time.
    0
    installs
  26. Po 1 3 Po13 · cyberstrikeus
    Communicate requirements to all third parties who will provide commercial software components to the organization for reuse by the organization’s o...
    0
    installs
  27. Po 2 1 Po21 · cyberstrikeus
    Create new roles and alter responsibilities for existing roles as needed to encompass all parts of the SDLC.
    0
    installs
  28. Po 2 2 Po22 · cyberstrikeus
    Provide role-based training for all personnel with responsibilities that contribute to secure development.
    0
    installs
  29. Po 2 3 Po23 · cyberstrikeus
    Obtain upper management or authorizing official commitment to secure development, and convey that commitment to all with development-related roles and
    0
    installs
  30. Po 3 1 Po31 · cyberstrikeus
    Specify which tools or tool types must or should be included in each toolchain to mitigate identified risks, as well as how the toolchain components a
    0
    installs
  31. Po 3 2 Po32 · cyberstrikeus
    Follow recommended security practices to deploy, operate, and maintain tools and toolchains.
    0
    installs
  32. Po 3 3 Po33 · cyberstrikeus
    Configure tools to generate artifacts of their support of secure software development practices as defined by the organization.
    0
    installs
  33. Po 4 1 Po41 · cyberstrikeus
    Define criteria for software security checks and track throughout the SDLC.
    0
    installs
  34. Po 4 2 Po42 · cyberstrikeus
    Implement processes, mechanisms, etc.
    0
    installs
  35. Po 5 1 Po51 · cyberstrikeus
    Separate and protect each environment involved in software development.
    0
    installs
  36. Po 5 2 Po52 · cyberstrikeus
    Secure and harden development endpoints (i.e., endpoints for software designers, developers, testers, builders, etc.) to perform development-related t
    0
    installs
  37. Ma 4 Nonlocal Maintenance · cyberstrikeus
    Approve and monitor nonlocal maintenance and diagnostic activities;
    0
    installs
  38. Ma 5 4 Foreign Nationals · cyberstrikeus
    Ensure that: Foreign nationals with appropriate security clearances are used to conduct maintenance and diagnostic activities on classified systems on
    0
    installs
  39. Mp 5 Media Transport · cyberstrikeus
    Protect and control [organization-defined] during transport outside of controlled areas using [organization-defined];
    0
    installs
  40. Pm 28 Risk Framing · cyberstrikeus
    Identify and document: Assumptions affecting risk assessments, risk responses, and risk monitoring; Constraints affecting risk assessments, risk respo
    0
    installs
  41. Pm 7 1 Offloading · cyberstrikeus
    Offload [organization-defined] to other systems, system components, or an external provider.
    0
    installs
  42. T0831 Manipulation Of Control · cyberstrikeus
    Adversaries may manipulate physical process control within the industrial environment.
    0
    installs
  43. T0886 Remote Services · cyberstrikeus
    Adversaries may leverage remote services to move between assets and network segments.
    0
    installs
  44. T1424 Process Discovery · cyberstrikeus
    Adversaries may attempt to get information about running processes on a device.
    0
    installs
  45. T1636 003 Contact List · cyberstrikeus
    Adversaries may utilize standard operating system APIs to gather contact list data.
    0
    installs
  46. T1636 004 Sms Messages · cyberstrikeus
    Adversaries may utilize standard operating system APIs to gather SMS messages.
    0
    installs
  47. T1603 Scheduled Taskjob · cyberstrikeus
    Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
    0
    installs
  48. T1189 Drive By Compromise · cyberstrikeus
    Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
    0
    installs
  49. T1176 001 Browser Extensions · cyberstrikeus
    Adversaries may abuse internet browser extensions to establish persistent access to victim systems.
    0
    installs
  50. T1525 Implant Internal Image · cyberstrikeus
    Adversaries may implant cloud or container images with malicious code to establish persistence after gaining access to an environment.
    0
    installs
  51. T1542 002 Component Firmware · cyberstrikeus
    Adversaries may modify component firmware to persist on systems.
    0
    installs
  52. T1027 001 Binary Padding · cyberstrikeus
    Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
    0
    installs
  53. T1027 006 HTML Smuggling · cyberstrikeus
    Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.
    0
    installs
  54. T1055 014 Vdso Hijacking · cyberstrikeus
    Adversaries may inject malicious code into processes via VDSO hijacking in order to evade process-based defenses as well as possibly elevate privileges.
    0
    installs
  55. T1078 003 Local Accounts · cyberstrikeus
    Adversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
    0
    installs
  56. T1078 004 Cloud Accounts · cyberstrikeus
    Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion.
    0
    installs
  57. T1205 002 Socket Filters · cyberstrikeus
    Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and control.
    0
    installs
  58. T1221 Template Injection · cyberstrikeus
    Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts.
    0
    installs
  59. T1562 009 Safe Mode Boot · cyberstrikeus
    Adversaries may abuse Windows safe mode to disable endpoint defenses.
    0
    installs
  60. T1003 001 Lsass Memory · cyberstrikeus
    Adversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).
    0
    installs
  61. T1040 Network Sniffing · cyberstrikeus
    Adversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network.
    0
    installs
  62. T1552 004 Private Keys · cyberstrikeus
    Adversaries may search for private key certificate files on compromised systems for insecurely stored credentials.
    0
    installs
  63. T1558 005 Ccache Files · cyberstrikeus
    Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache).
    0
    installs
  64. T1007 System Service Discovery · cyberstrikeus
    Adversaries may try to gather information about registered local system services.
    0
    installs
  65. T1563 001 Ssh Hijacking · cyberstrikeus
    Adversaries may hijack a legitimate user's SSH session to move laterally within an environment.
    0
    installs
  66. T1563 002 Rdp Hijacking · cyberstrikeus
    Adversaries may hijack a legitimate user’s remote desktop session to move laterally within an environment.
    0
    installs
  67. T1074 002 Remote Data Staging · cyberstrikeus
    Adversaries may stage data collected from multiple systems in a central location or directory on one system prior to Exfiltration.
    0
    installs
  68. T1530 Data From Cloud Storage · cyberstrikeus
    Adversaries may access data from cloud storage.
    0
    installs
  69. T1560 001 Archive Via Utility · cyberstrikeus
    Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.
    0
    installs
  70. T1560 002 Archive Via Library · cyberstrikeus
    An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries.
    0
    installs
  71. T1496 004 Cloud Service Hijacking · cyberstrikeus
    Adversaries may leverage compromised software-as-a-service (SaaS) applications to complete resource-intensive tasks, which may impact hosted service availability.
    0
    installs
  72. T1629 Impair Defenses · cyberstrikeus
    Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms.
    0
    installs
  73. T1517 Access Notifications · cyberstrikeus
    Adversaries may collect data within notifications sent by the operating system or other applications.
    0
    installs
  74. T1636 001 Calendar Entries · cyberstrikeus
    Adversaries may utilize standard operating system APIs to gather calendar entry data.
    0
    installs
  75. T1481 Web Service · cyberstrikeus
    Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.
    0
    installs
  76. T1195 Supply Chain Compromise · cyberstrikeus
    Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
    0
    installs
  77. T1195 001 Compromise Software Dependencies And Development T · cyberstrikeus
    Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise.
    0
    installs
  78. T1566 004 Spearphishing Voice · cyberstrikeus
    Adversaries may use voice communications to ultimately gain access to victim systems.
    0
    installs
  79. T1204 004 Malicious Copy And Paste · cyberstrikeus
    An adversary may rely upon a user copying and pasting code in order to gain execution.
    0
    installs
  80. T1651 Cloud Administration Command · cyberstrikeus
    Adversaries may abuse cloud management services to execute commands within virtual machines.
    0
    installs
  81. T1098 003 Additional Cloud Roles · cyberstrikeus
    An adversary may add additional roles or permissions to an adversary-controlled cloud account to maintain persistent access to a tenant.
    0
    installs
  82. T1137 Office Application Startup · cyberstrikeus
    Adversaries may leverage Microsoft Office-based applications for persistence between startups.
    0
    installs
  83. T1137 001 Office Template Macros · cyberstrikeus
    Adversaries may abuse Microsoft Office templates to obtain persistence on a compromised system.
    0
    installs
  84. T1547 002 Authentication Package · cyberstrikeus
    Adversaries may abuse authentication packages to execute DLLs when the system boots.
    0
    installs
  85. T1547 007 Re Opened Applications · cyberstrikeus
    Adversaries may modify plist files to automatically run an application when a user logs in.
    0
    installs
  86. T1027 012 Lnk Icon Smuggling · cyberstrikeus
    Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files.
    0
    installs
  87. T1070 008 Clear Mailbox Data · cyberstrikeus
    Adversaries may modify mail and mail application data to remove evidence of their activity.
    0
    installs
  88. T1218 001 Compiled HTML File · cyberstrikeus
    Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code.
    0
    installs
  89. T1484 002 Trust Modification · cyberstrikeus
    Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses an...
    0
    installs
  90. T1550 004 Web Session Cookie · cyberstrikeus
    Adversaries can use stolen session cookies to authenticate to web applications and services.
    0
    installs
  91. T1553 Subvert Trust Controls · cyberstrikeus
    Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs.
    0
    installs
  92. T1562 006 Indicator Blocking · cyberstrikeus
    An adversary may attempt to block indicators or events typically captured by sensors from being gathered and analyzed.
    0
    installs
  93. T1564 005 Hidden File System · cyberstrikeus
    Adversaries may use a hidden file system to conceal malicious activity from users and security tools.
    0
    installs
  94. T1564 008 Email Hiding Rules · cyberstrikeus
    Adversaries may use email rules to hide inbound emails in a compromised user's mailbox.
    0
    installs
  95. T1601 001 Patch System Image · cyberstrikeus
    Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses.
    0
    installs
  96. T1555 002 Securityd Memory · cyberstrikeus
    An adversary with root access may gather credentials by reading `securityd`’s memory.
    0
    installs
  97. T1010 Application Window Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of open application windows.
    0
    installs
  98. T1016 System Network Configuration Discovery · cyberstrikeus
    Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
    0
    installs
  99. T1082 System Information Discovery · cyberstrikeus
    An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
    0
    installs
  100. T1083 File And Directory Discovery · cyberstrikeus
    Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
    0
    installs