cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ T1570 Lateral Tool Transfer · cyberstrikeusAdversaries may transfer tools or other files between systems in a compromised environment.
- ▌ T1114 002 Remote Email Collection · cyberstrikeusAdversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information.
- ▌ T1030 Data Transfer Size Limits · cyberstrikeusAn adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds.
- ▌ T1052 001 Exfiltration Over Usb · cyberstrikeusAdversaries may attempt to exfiltrate data over a USB connected physical device.
- ▌ T1071 003 Mail Protocols · cyberstrikeusAdversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic.
- ▌ T1090 001 Internal Proxy · cyberstrikeusAdversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment.
- ▌ T1090 002 External Proxy · cyberstrikeusAdversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure.
- ▌ T1568 Dynamic Resolution · cyberstrikeusAdversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.
- ▌ T1572 Protocol Tunneling · cyberstrikeusAdversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems.
- ▌ T1608 006 SEO Poisoning · cyberstrikeusAdversaries may poison mechanisms that influence search engine optimization (SEO) to further lure staged capabilities towards potential victims.
- ▌ T1598 004 Spearphishing Voice · cyberstrikeusAdversaries may use voice communications to elicit sensitive information that can be used during targeting.
- ▌ Technology Infrastructure Resilience Pr Ir Technology Infras · cyberstrikeusSecurity architectures are managed with the organization's risk strategy to protect asset confidentiality, integrity, and availability, and organizati
- ▌
- ▌
- ▌
- ▌ Pw 1 1 Pw11 · cyberstrikeusUse forms of risk modeling – such as threat modeling, attack modeling, or attack surface mapping – to help assess the security risk for the software.
- ▌ Pw 1 2 Pw12 · cyberstrikeusTrack and maintain the software’s security requirements, risks, and design decisions.
- ▌ Pw 1 3 Pw13 · cyberstrikeusWhere appropriate, build in support for using standardized security features and services (e.g., enabling software to integrate with existing log m...
- ▌ Pw 2 1 Pw21 · cyberstrikeusHave 1) a qualified person (or people) who were not involved with the design and/or 2) automated processes instantiated in the toolchain review the so
- ▌ Pw 4 1 Pw41 · cyberstrikeusAcquire and maintain well-secured software components (e.g., software libraries, modules, middleware, frameworks) from commercial, open-source, and ot
- ▌ Pw 4 2 Pw42 · cyberstrikeusCreate and maintain well-secured software components in-house following SDLC processes to meet common internal software development needs that cannot
- ▌ Pw 4 4 Pw44 · cyberstrikeusVerify that acquired commercial, open-source, and all other third-party software components comply with the requirements, as defined by the organizati
- ▌ Pw 5 1 Pw51 · cyberstrikeusFollow all secure coding practices that are appropriate to the development languages and environment to meet the organization’s requirements.
- ▌ Pw 6 1 Pw61 · cyberstrikeusUse compiler, interpreter, and build tools that offer features to improve executable security.
- ▌ Pw 6 2 Pw62 · cyberstrikeusDetermine which compiler, interpreter, and build tool features should be used and how each should be configured, then implement and use the approved c
- ▌ Pw 7 1 Pw71 · cyberstrikeusDetermine whether code review (a person looks directly at the code to find issues) and/or code analysis (tools are used to find issues in code, either
- ▌ Pw 7 2 Pw72 · cyberstrikeusPerform the code review and/or code analysis based on the organization’s secure coding standards, and record and triage all discovered issues and reco
- ▌ Pw 8 1 Pw81 · cyberstrikeusDetermine whether executable code testing should be performed to find vulnerabilities not identified by previous reviews, analysis, or testing and, if
- ▌ Pw 8 2 Pw82 · cyberstrikeusScope the testing, design the tests, perform the testing, and document the results, including recording and triaging all discovered issues and recomme
- ▌ Pw 9 1 Pw91 · cyberstrikeusDefine a secure baseline by determining how to configure each setting that has an effect on security or a security-related setting so that the default
- ▌ Pw 9 2 Pw92 · cyberstrikeusImplement the default settings (or groups of default settings, if applicable), and document each setting for software administrators.
- ▌ Ac 3 8 Revocation Of Access Authorizations · cyberstrikeusEnforce the revocation of access authorizations resulting from changes to the security attributes of subjects and objects based on [organization-defin
- ▌ Ac 4 20 Approved Solutions · cyberstrikeusEmploy [organization-defined] to control the flow of [organization-defined] across security domains.
- ▌ Ac 4 5 Embedded Data Types · cyberstrikeusEnforce [organization-defined] on embedding data types within other data types.
- ▌ Ac 6 5 Privileged Accounts · cyberstrikeusRestrict privileged accounts on the system to [organization-defined].
- ▌ Ac 9 1 Unsuccessful Logons · cyberstrikeusNotify the user, upon successful logon, of the number of unsuccessful logon attempts since the last successful logon.
- ▌ Cp 2 Contingency Plan · cyberstrikeusDevelop a contingency plan for the system that: Identifies essential mission and business functions and associated contingency requirements; Provides
- ▌ Cp 6 3 Accessibility · cyberstrikeusIdentify potential accessibility problems to the alternate storage site in the event of an area-wide disruption or disaster and outline explicit mitig
- ▌ Ir 2 1 Simulated Events · cyberstrikeusIncorporate simulated events into incident response training to facilitate the required response by personnel in crisis situations.
- ▌
- ▌ Ma 4 3 Comparable Security And Sanitization · cyberstrikeusRequire that nonlocal maintenance and diagnostic services be performed from a system that implements a security capability comparable to the capabi...
- ▌ Ma 5 2 Security Clearances For Classified Systems · cyberstrikeusVerify that personnel performing maintenance and diagnostic activities on a system processing, storing, or transmitting classified information possess
- ▌ Ma 5 5 Non System Maintenance · cyberstrikeusEnsure that non-escorted personnel performing maintenance activities not directly associated with the system but in the physical proximity of the syst
- ▌ Ma 6 1 Preventive Maintenance · cyberstrikeusPerform preventive maintenance on [organization-defined] at [organization-defined].
- ▌ Ma 6 2 Predictive Maintenance · cyberstrikeusPerform predictive maintenance on [organization-defined] at [organization-defined].
- ▌ Mp 6 2 Equipment Testing · cyberstrikeusTest sanitization equipment and procedures [organization-defined] to ensure that the intended sanitization is being achieved.
- ▌
- ▌ Mp 8 2 Equipment Testing · cyberstrikeusTest downgrading equipment and procedures [organization-defined] to ensure that downgrading actions are being achieved.
- ▌ Pm 27 Privacy Reporting · cyberstrikeusDevelop [organization-defined] and disseminate to: [organization-defined] to demonstrate accountability with statutory, regulatory, and policy privacy
- ▌ Ps 5 Personnel Transfer · cyberstrikeusReview and confirm ongoing operational need for current logical and physical access authorizations to systems and facilities when individuals are r...
- ▌ Ra 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] risk assessment policy that: Procedures to facilitate the impleme
- ▌ T0861 Point Tag Identification · cyberstrikeusAdversaries may collect point and tag values to gain a more comprehensive understanding of the process environment.
- ▌ T0888 Remote System Information Discovery · cyberstrikeusAn adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration.
- ▌ T0821 Modify Controller Tasking · cyberstrikeusAdversaries may modify the tasking of a controller to allow for the execution of their own programs.
- ▌ T1461 Lockscreen Bypass · cyberstrikeusAn adversary with physical access to a mobile device may seek to bypass the device’s lockscreen.
- ▌ T1628 002 User Evasion · cyberstrikeusAdversaries may attempt to avoid detection by hiding malicious behavior from the user.
- ▌ T1464 Network Denial Of Service · cyberstrikeusAdversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users.
- ▌ T1471 Data Encrypted For Impact · cyberstrikeusAn adversary may encrypt files stored on a mobile device to prevent the user from accessing them.
- ▌ T1027 010 Command Obfuscation · cyberstrikeusAdversaries may obfuscate content during command execution to impede detection.
- ▌ T1027 016 Junk Code Insertion · cyberstrikeusAdversaries may use junk code / dead code to obfuscate a malware’s functionality.
- ▌ T1036 009 Break Process Trees · cyberstrikeusAn adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID).
- ▌ T1036 012 Browser Fingerprint · cyberstrikeusAdversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc.
- ▌ T1055 008 Ptrace System Calls · cyberstrikeusAdversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1134 004 Parent Pid Spoofing · cyberstrikeusAdversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.
- ▌ T1207 Rogue Domain Controller · cyberstrikeusAdversaries may register a rogue Domain Controller to enable manipulation of Active Directory data.
- ▌ T1484 Domain Or Tenant Policy Modification · cyberstrikeusAdversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments.
- ▌ T1553 006 Code Signing Policy Modification · cyberstrikeusAdversaries may modify code signing policies to enable execution of unsigned or self-signed code.
- ▌ T1564 012 Filepath Exclusions · cyberstrikeusAdversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other defensive capabilities.
- ▌ T1564 014 Extended Attributes · cyberstrikeusAdversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade detection.
- ▌ T1620 Reflective Code Loading · cyberstrikeusAdversaries may reflectively load code into a process in order to conceal the execution of malicious payloads.
- ▌ T1647 Plist File Modification · cyberstrikeusAdversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses.
- ▌ T1003 Os Credential Dumping · cyberstrikeusAdversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password.
- ▌ T1110 001 Password Guessing · cyberstrikeusAdversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts.
- ▌ T1110 002 Password Cracking · cyberstrikeusAdversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are obtained.
- ▌ T1110 003 Password Spraying · cyberstrikeusAdversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials.
- ▌ T1187 Forced Authentication · cyberstrikeusAdversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept.
- ▌ T1552 Unsecured Credentials · cyberstrikeusAdversaries may search compromised systems to find and obtain insecurely stored credentials.
- ▌ T1555 005 Password Managers · cyberstrikeusAdversaries may acquire user credentials from third-party password managers.
- ▌ T1556 001 Domain Controller Authentication · cyberstrikeusAdversaries may patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.
- ▌ T1606 Forge Web Credentials · cyberstrikeusAdversaries may forge credential materials that can be used to gain access to web applications or Internet services.
- ▌ T1217 Browser Information Discovery · cyberstrikeusAdversaries may enumerate information about browsers to learn more about compromised environments.
- ▌ T1518 002 Backup Software Discovery · cyberstrikeusAdversaries may attempt to get a listing of backup software or configurations that are installed on a system.
- ▌ T1614 001 System Language Discovery · cyberstrikeusAdversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
- ▌ T1534 Internal Spearphishing · cyberstrikeusAfter they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within th...
- ▌ T1090 003 Multi Hop Proxy · cyberstrikeusAdversaries may chain together multiple proxies to disguise the source of malicious traffic.
- ▌ T1090 004 Domain Fronting · cyberstrikeusAdversaries may take advantage of routing schemes in Content Delivery Networks (CDNs) and other services which host multiple domains to obfuscate the intended destination of HTTPS traffic or traffi...
- ▌ T1219 Remote Access Tools · cyberstrikeusAn adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.
- ▌ T1568 003 Dns Calculation · cyberstrikeusAdversaries may perform calculations on addresses returned in DNS results to determine which port and IP address to use for command and control, rather than relying on a predetermined port number o...
- ▌ T1665 Hide Infrastructure · cyberstrikeusAdversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure.
- ▌ T1485 001 Lifecycle Triggered Deletion · cyberstrikeusAdversaries may modify the lifecycle policies of a cloud storage bucket to destroy all objects stored within.
- ▌ T1499 003 Application Exhaustion Flood · cyberstrikeusAdversaries may target resource intensive features of applications to cause a denial of service (DoS), denying availability to those applications.
- ▌ T1585 Establish Accounts · cyberstrikeusAdversaries may create and cultivate accounts with services that can be used during targeting.
- ▌ T1585 002 Email Accounts · cyberstrikeusAdversaries may create email accounts that can be used during targeting.
- ▌ T1585 003 Cloud Accounts · cyberstrikeusAdversaries may create accounts with cloud providers that can be used during targeting.
- ▌ T1586 002 Email Accounts · cyberstrikeusAdversaries may compromise email accounts that can be used during targeting.
- ▌ T1586 003 Cloud Accounts · cyberstrikeusAdversaries may compromise cloud accounts that can be used during targeting.
- ▌ T1608 Stage Capabilities · cyberstrikeusAdversaries may upload, install, or otherwise set up capabilities that can be used during targeting.
- ▌ T1608 001 Upload Malware · cyberstrikeusAdversaries may upload malware to third-party or adversary controlled infrastructure to make it accessible during targeting.
- ▌ T1596 003 Digital Certificates · cyberstrikeusAdversaries may search public digital certificate data for information about victims that can be used during targeting.
- ▌ T1597 001 Threat Intel Vendors · cyberstrikeusAdversaries may search private data from threat intelligence vendors for information that can be used during targeting.