← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 69 of 72

  1. T1570 Lateral Tool Transfer · cyberstrikeus
    Adversaries may transfer tools or other files between systems in a compromised environment.
    0
    installs
  2. T1114 002 Remote Email Collection · cyberstrikeus
    Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information.
    0
    installs
  3. T1030 Data Transfer Size Limits · cyberstrikeus
    An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds.
    0
    installs
  4. T1052 001 Exfiltration Over Usb · cyberstrikeus
    Adversaries may attempt to exfiltrate data over a USB connected physical device.
    0
    installs
  5. T1071 003 Mail Protocols · cyberstrikeus
    Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic.
    0
    installs
  6. T1090 001 Internal Proxy · cyberstrikeus
    Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment.
    0
    installs
  7. T1090 002 External Proxy · cyberstrikeus
    Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure.
    0
    installs
  8. T1568 Dynamic Resolution · cyberstrikeus
    Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.
    0
    installs
  9. T1572 Protocol Tunneling · cyberstrikeus
    Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems.
    0
    installs
  10. T1608 006 SEO Poisoning · cyberstrikeus
    Adversaries may poison mechanisms that influence search engine optimization (SEO) to further lure staged capabilities towards potential victims.
    0
    installs
  11. T1598 004 Spearphishing Voice · cyberstrikeus
    Adversaries may use voice communications to elicit sensitive information that can be used during targeting.
    0
    installs
  12. Technology Infrastructure Resilience Pr Ir Technology Infras · cyberstrikeus
    Security architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizati
    0
    installs
  13. Sp 800 171 03 07 01 030701 · cyberstrikeus
    03.07.01
    0
    installs
  14. Sp 800 171 03 07 02 030702 · cyberstrikeus
    03.07.02
    0
    installs
  15. Sp 800 171 03 07 03 030703 · cyberstrikeus
    03.07.03
    0
    installs
  16. Pw 1 1 Pw11 · cyberstrikeus
    Use forms of risk modeling – such as threat modeling, attack modeling, or attack surface mapping – to help assess the security risk for the software.
    0
    installs
  17. Pw 1 2 Pw12 · cyberstrikeus
    Track and maintain the software’s security requirements, risks, and design decisions.
    0
    installs
  18. Pw 1 3 Pw13 · cyberstrikeus
    Where appropriate, build in support for using standardized security features and services (e.g., enabling software to integrate with existing log m...
    0
    installs
  19. Pw 2 1 Pw21 · cyberstrikeus
    Have 1) a qualified person (or people) who were not involved with the design and/or 2) automated processes instantiated in the toolchain review the so
    0
    installs
  20. Pw 4 1 Pw41 · cyberstrikeus
    Acquire and maintain well-secured software components (e.g., software libraries, modules, middleware, frameworks) from commercial, open-source, and ot
    0
    installs
  21. Pw 4 2 Pw42 · cyberstrikeus
    Create and maintain well-secured software components in-house following SDLC processes to meet common internal software development needs that cannot
    0
    installs
  22. Pw 4 4 Pw44 · cyberstrikeus
    Verify that acquired commercial, open-source, and all other third-party software components comply with the requirements, as defined by the organizati
    0
    installs
  23. Pw 5 1 Pw51 · cyberstrikeus
    Follow all secure coding practices that are appropriate to the development languages and environment to meet the organization’s requirements.
    0
    installs
  24. Pw 6 1 Pw61 · cyberstrikeus
    Use compiler, interpreter, and build tools that offer features to improve executable security.
    0
    installs
  25. Pw 6 2 Pw62 · cyberstrikeus
    Determine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved c
    0
    installs
  26. Pw 7 1 Pw71 · cyberstrikeus
    Determine whether code review (a person looks directly at the code to find issues) and/or code analysis (tools are used to find issues in code, either
    0
    installs
  27. Pw 7 2 Pw72 · cyberstrikeus
    Perform the code review and/or code analysis based on the organization’s secure coding standards, and record and triage all discovered issues and reco
    0
    installs
  28. Pw 8 1 Pw81 · cyberstrikeus
    Determine whether executable code testing should be performed to find vulnerabilities not identified by previous reviews, analysis, or testing and, if
    0
    installs
  29. Pw 8 2 Pw82 · cyberstrikeus
    Scope the testing, design the tests, perform the testing, and document the results, including recording and triaging all discovered issues and recomme
    0
    installs
  30. Pw 9 1 Pw91 · cyberstrikeus
    Define a secure baseline by determining how to configure each setting that has an effect on security or a security-related setting so that the default
    0
    installs
  31. Pw 9 2 Pw92 · cyberstrikeus
    Implement the default settings (or groups of default settings, if applicable), and document each setting for software administrators.
    0
    installs
  32. Ac 3 8 Revocation Of Access Authorizations · cyberstrikeus
    Enforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on [organization-defin
    0
    installs
  33. Ac 4 20 Approved Solutions · cyberstrikeus
    Employ [organization-defined] to control the flow of [organization-defined] across security domains.
    0
    installs
  34. Ac 4 5 Embedded Data Types · cyberstrikeus
    Enforce [organization-defined] on embedding data types within other data types.
    0
    installs
  35. Ac 6 5 Privileged Accounts · cyberstrikeus
    Restrict privileged accounts on the system to [organization-defined].
    0
    installs
  36. Ac 9 1 Unsuccessful Logons · cyberstrikeus
    Notify the user, upon successful logon, of the number of unsuccessful logon attempts since the last successful logon.
    0
    installs
  37. Cp 2 Contingency Plan · cyberstrikeus
    Develop a contingency plan for the system that: Identifies essential mission and business functions and associated contingency requirements; Provides
    0
    installs
  38. Cp 6 3 Accessibility · cyberstrikeus
    Identify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitig
    0
    installs
  39. Ir 2 1 Simulated Events · cyberstrikeus
    Incorporate simulated events into incident response training to facilitate the required response by personnel in crisis situations.
    0
    installs
  40. Ir 5 Incident Monitoring · cyberstrikeus
    Track and document incidents.
    0
    installs
  41. Ma 4 3 Comparable Security And Sanitization · cyberstrikeus
    Require that nonlocal maintenance and diagnostic services be performed from a system that implements a security capability comparable to the capabi...
    0
    installs
  42. Ma 5 2 Security Clearances For Classified Systems · cyberstrikeus
    Verify that personnel performing maintenance and diagnostic activities on a system processing, storing, or transmitting classified information possess
    0
    installs
  43. Ma 5 5 Non System Maintenance · cyberstrikeus
    Ensure that non-escorted personnel performing maintenance activities not directly associated with the system but in the physical proximity of the syst
    0
    installs
  44. Ma 6 1 Preventive Maintenance · cyberstrikeus
    Perform preventive maintenance on [organization-defined] at [organization-defined].
    0
    installs
  45. Ma 6 2 Predictive Maintenance · cyberstrikeus
    Perform predictive maintenance on [organization-defined] at [organization-defined].
    0
    installs
  46. Mp 6 2 Equipment Testing · cyberstrikeus
    Test sanitization equipment and procedures [organization-defined] to ensure that the intended sanitization is being achieved.
    0
    installs
  47. Mp 6 6 Media Destruction · cyberstrikeus
    Media Destruction
    0
    installs
  48. Mp 8 2 Equipment Testing · cyberstrikeus
    Test downgrading equipment and procedures [organization-defined] to ensure that downgrading actions are being achieved.
    0
    installs
  49. Pm 27 Privacy Reporting · cyberstrikeus
    Develop [organization-defined] and disseminate to: [organization-defined] to demonstrate accountability with statutory, regulatory, and policy privacy
    0
    installs
  50. Ps 5 Personnel Transfer · cyberstrikeus
    Review and confirm ongoing operational need for current logical and physical access authorizations to systems and facilities when individuals are r...
    0
    installs
  51. Ra 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] risk assessment policy that: Procedures to facilitate the impleme
    0
    installs
  52. T0861 Point Tag Identification · cyberstrikeus
    Adversaries may collect point and tag values to gain a more comprehensive understanding of the process environment.
    0
    installs
  53. T0888 Remote System Information Discovery · cyberstrikeus
    An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration.
    0
    installs
  54. T0821 Modify Controller Tasking · cyberstrikeus
    Adversaries may modify the tasking of a controller to allow for the execution of their own programs.
    0
    installs
  55. T1461 Lockscreen Bypass · cyberstrikeus
    An adversary with physical access to a mobile device may seek to bypass the device’s lockscreen.
    0
    installs
  56. T1628 002 User Evasion · cyberstrikeus
    Adversaries may attempt to avoid detection by hiding malicious behavior from the user.
    0
    installs
  57. T1464 Network Denial Of Service · cyberstrikeus
    Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users.
    0
    installs
  58. T1471 Data Encrypted For Impact · cyberstrikeus
    An adversary may encrypt files stored on a mobile device to prevent the user from accessing them.
    0
    installs
  59. T1027 010 Command Obfuscation · cyberstrikeus
    Adversaries may obfuscate content during command execution to impede detection.
    0
    installs
  60. T1027 016 Junk Code Insertion · cyberstrikeus
    Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
    0
    installs
  61. T1036 009 Break Process Trees · cyberstrikeus
    An adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID).
    0
    installs
  62. T1036 012 Browser Fingerprint · cyberstrikeus
    Adversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc.
    0
    installs
  63. T1055 008 Ptrace System Calls · cyberstrikeus
    Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.
    0
    installs
  64. T1134 004 Parent Pid Spoofing · cyberstrikeus
    Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.
    0
    installs
  65. T1207 Rogue Domain Controller · cyberstrikeus
    Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data.
    0
    installs
  66. T1484 Domain Or Tenant Policy Modification · cyberstrikeus
    Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments.
    0
    installs
  67. T1553 006 Code Signing Policy Modification · cyberstrikeus
    Adversaries may modify code signing policies to enable execution of unsigned or self-signed code.
    0
    installs
  68. T1564 012 Filepath Exclusions · cyberstrikeus
    Adversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other defensive capabilities.
    0
    installs
  69. T1564 014 Extended Attributes · cyberstrikeus
    Adversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade detection.
    0
    installs
  70. T1620 Reflective Code Loading · cyberstrikeus
    Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads.
    0
    installs
  71. T1647 Plist File Modification · cyberstrikeus
    Adversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses.
    0
    installs
  72. T1003 Os Credential Dumping · cyberstrikeus
    Adversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password.
    0
    installs
  73. T1110 001 Password Guessing · cyberstrikeus
    Adversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts.
    0
    installs
  74. T1110 002 Password Cracking · cyberstrikeus
    Adversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are obtained.
    0
    installs
  75. T1110 003 Password Spraying · cyberstrikeus
    Adversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials.
    0
    installs
  76. T1187 Forced Authentication · cyberstrikeus
    Adversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept.
    0
    installs
  77. T1552 Unsecured Credentials · cyberstrikeus
    Adversaries may search compromised systems to find and obtain insecurely stored credentials.
    0
    installs
  78. T1555 005 Password Managers · cyberstrikeus
    Adversaries may acquire user credentials from third-party password managers.
    0
    installs
  79. T1556 001 Domain Controller Authentication · cyberstrikeus
    Adversaries may patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.
    0
    installs
  80. T1606 Forge Web Credentials · cyberstrikeus
    Adversaries may forge credential materials that can be used to gain access to web applications or Internet services.
    0
    installs
  81. T1217 Browser Information Discovery · cyberstrikeus
    Adversaries may enumerate information about browsers to learn more about compromised environments.
    0
    installs
  82. T1518 002 Backup Software Discovery · cyberstrikeus
    Adversaries may attempt to get a listing of backup software or configurations that are installed on a system.
    0
    installs
  83. T1614 001 System Language Discovery · cyberstrikeus
    Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
    0
    installs
  84. T1534 Internal Spearphishing · cyberstrikeus
    After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within th...
    0
    installs
  85. T1090 003 Multi Hop Proxy · cyberstrikeus
    Adversaries may chain together multiple proxies to disguise the source of malicious traffic.
    0
    installs
  86. T1090 004 Domain Fronting · cyberstrikeus
    Adversaries may take advantage of routing schemes in Content Delivery Networks (CDNs) and other services which host multiple domains to obfuscate the intended destination of HTTPS traffic or traffi...
    0
    installs
  87. T1219 Remote Access Tools · cyberstrikeus
    An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
    0
    installs
  88. T1568 003 Dns Calculation · cyberstrikeus
    Adversaries may perform calculations on addresses returned in DNS results to determine which port and IP address to use for command and control, rather than relying on a predetermined port number o...
    0
    installs
  89. T1665 Hide Infrastructure · cyberstrikeus
    Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure.
    0
    installs
  90. T1485 001 Lifecycle Triggered Deletion · cyberstrikeus
    Adversaries may modify the lifecycle policies of a cloud storage bucket to destroy all objects stored within.
    0
    installs
  91. T1499 003 Application Exhaustion Flood · cyberstrikeus
    Adversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications.
    0
    installs
  92. T1585 Establish Accounts · cyberstrikeus
    Adversaries may create and cultivate accounts with services that can be used during targeting.
    0
    installs
  93. T1585 002 Email Accounts · cyberstrikeus
    Adversaries may create email accounts that can be used during targeting.
    0
    installs
  94. T1585 003 Cloud Accounts · cyberstrikeus
    Adversaries may create accounts with cloud providers that can be used during targeting.
    0
    installs
  95. T1586 002 Email Accounts · cyberstrikeus
    Adversaries may compromise email accounts that can be used during targeting.
    0
    installs
  96. T1586 003 Cloud Accounts · cyberstrikeus
    Adversaries may compromise cloud accounts that can be used during targeting.
    0
    installs
  97. T1608 Stage Capabilities · cyberstrikeus
    Adversaries may upload, install, or otherwise set up capabilities that can be used during targeting.
    0
    installs
  98. T1608 001 Upload Malware · cyberstrikeus
    Adversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting.
    0
    installs
  99. T1596 003 Digital Certificates · cyberstrikeus
    Adversaries may search public digital certificate data for information about victims that can be used during targeting.
    0
    installs
  100. T1597 001 Threat Intel Vendors · cyberstrikeus
    Adversaries may search private data from threat intelligence vendors for information that can be used during targeting.
    0
    installs