← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 70 of 72

  1. T1598 Phishing For Information · cyberstrikeus
    Adversaries may send phishing messages to elicit sensitive information that can be used during targeting.
    0
    installs
  2. Asset Management Id Am Asset Management · cyberstrikeus
    Assets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identifie
    0
    installs
  3. Risk Assessment Id Ra Risk Assessment · cyberstrikeus
    The cybersecurity risk to the organization, assets, and individuals is understood by the organization
    0
    installs
  4. Identity Management Authentication And Access Control Pr Aa · cyberstrikeus
    Access to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauth
    0
    installs
  5. Ac 12 2 Termination Message · cyberstrikeus
    Display an explicit logout message to users indicating the termination of authenticated communications sessions.
    0
    installs
  6. Ac 16 7 Consistent Attribute Interpretation · cyberstrikeus
    Provide a consistent interpretation of security and privacy attributes transmitted between distributed system components.
    0
    installs
  7. Ac 23 Data Mining Protection · cyberstrikeus
    Employ [organization-defined] for [organization-defined] to detect and protect against unauthorized data mining.
    0
    installs
  8. Ac 8 System Use Notification · cyberstrikeus
    Display [organization-defined] to users before granting access to the system that provides privacy and security notices consistent with applicable law
    0
    installs
  9. Au 2 Event Logging · cyberstrikeus
    Identify the types of events that the system is capable of logging in support of the audit function: [organization-defined];
    0
    installs
  10. Cp 4 5 Self Challenge · cyberstrikeus
    Employ [organization-defined] to [organization-defined] to disrupt and adversely affect the system or system component.
    0
    installs
  11. Ir 3 1 Automated Testing · cyberstrikeus
    Test the incident response capability using [organization-defined].
    0
    installs
  12. Ma 4 7 Disconnect Verification · cyberstrikeus
    Verify session and network connection termination after the completion of nonlocal maintenance and diagnostic sessions.
    0
    installs
  13. Mp 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] media protection policy that: Procedures to facilitate the implem
    0
    installs
  14. Mp 6 7 Dual Authorization · cyberstrikeus
    Enforce dual authorization for the sanitization of [organization-defined].
    0
    installs
  15. Ps 3 Personnel Screening · cyberstrikeus
    Screen individuals prior to authorizing access to the system;
    0
    installs
  16. Ps 8 Personnel Sanctions · cyberstrikeus
    Employ a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures;
    0
    installs
  17. Ra 4 Risk Assessment Update · cyberstrikeus
    Risk Assessment Update
    0
    installs
  18. Ra 6 Technical Surveillance Countermeasures Survey · cyberstrikeus
    Employ a technical surveillance countermeasures survey at [organization-defined] [organization-defined].
    0
    installs
  19. T0884 Connection Proxy · cyberstrikeus
    Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications.
    0
    installs
  20. T0864 Transient Cyber Asset · cyberstrikeus
    Adversaries may target devices that are transient across ICS networks and external networks.
    0
    installs
  21. T0812 Default Credentials · cyberstrikeus
    Adversaries may leverage manufacturer or supplier set default credentials on control system devices.
    0
    installs
  22. T1625 Hijack Execution Flow · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking the way operating systems run applications.
    0
    installs
  23. T1406 001 Steganography · cyberstrikeus
    Adversaries may use steganography techniques in order to prevent the detection of hidden information.
    0
    installs
  24. T1630 002 File Deletion · cyberstrikeus
    Adversaries may wipe a device or delete individual files in order to manipulate external outcomes or hide activity.
    0
    installs
  25. T1631 Process Injection · cyberstrikeus
    Adversaries may inject code into processes in order to evade process-based defenses or even elevate privileges.
    0
    installs
  26. T1633 001 System Checks · cyberstrikeus
    Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.
    0
    installs
  27. T1642 Endpoint Denial Of Service · cyberstrikeus
    Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users.
    0
    installs
  28. T1532 Archive Collected Data · cyberstrikeus
    Adversaries may compress and/or encrypt data that is collected prior to exfiltration.
    0
    installs
  29. T1533 Data From Local System · cyberstrikeus
    Adversaries may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to exfiltration.
    0
    installs
  30. T1037 Boot Or Logon Initialization Scripts · cyberstrikeus
    Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence.
    0
    installs
  31. T1574 006 Dynamic Linker Hijacking · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries.
    0
    installs
  32. T1036 006 Space After Filename · cyberstrikeus
    Adversaries can hide a program's true filetype by changing the extension of a file.
    0
    installs
  33. T1036 008 Masquerade File Type · cyberstrikeus
    Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents.
    0
    installs
  34. T1055 005 Thread Local Storage · cyberstrikeus
    Adversaries may inject malicious code into processes via thread local storage (TLS) callbacks in order to evade process-based defenses as well as possibly elevate privileges.
    0
    installs
  35. T1055 013 Process Doppelgnging · cyberstrikeus
    Adversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly elevate privileges.
    0
    installs
  36. T1480 001 Environmental Keying · cyberstrikeus
    Adversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution to a specific target environment.
    0
    installs
  37. T1564 004 Ntfs File Attributes · cyberstrikeus
    Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection.
    0
    installs
  38. T1564 006 Run Virtual Instance · cyberstrikeus
    Adversaries may carry out malicious operations using a virtual instance to avoid detection.
    0
    installs
  39. T1578 005 Modify Cloud Compute Configurations · cyberstrikeus
    Adversaries may modify settings that directly affect the size, locations, and resources available to cloud compute infrastructure in order to evade defenses.
    0
    installs
  40. T1580 Cloud Infrastructure Discovery · cyberstrikeus
    An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment.
    0
    installs
  41. T1619 Cloud Storage Object Discovery · cyberstrikeus
    Adversaries may enumerate objects in cloud storage infrastructure.
    0
    installs
  42. T1560 003 Archive Via Custom Method · cyberstrikeus
    An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method.
    0
    installs
  43. T1104 Multi Stage Channels · cyberstrikeus
    Adversaries may create multiple stages for command and control that are employed under different conditions or for certain functions.
    0
    installs
  44. T1565 002 Transmitted Data Manipulation · cyberstrikeus
    Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity, thus threatening the integrity of the data.
    0
    installs
  45. T1584 008 Network Devices · cyberstrikeus
    Adversaries may compromise third-party network devices that can be used during targeting.
    0
    installs
  46. T1586 Compromise Accounts · cyberstrikeus
    Adversaries may compromise accounts with services that can be used during targeting.
    0
    installs
  47. T1588 Obtain Capabilities · cyberstrikeus
    Adversaries may buy and/or steal capabilities that can be used during targeting.
    0
    installs
  48. T1588 006 Vulnerabilities · cyberstrikeus
    Adversaries may acquire information about vulnerabilities that can be used during targeting.
    0
    installs
  49. T1608 004 Drive By Target · cyberstrikeus
    Adversaries may prepare an operational environment to infect systems that visit a website over the normal course of browsing.
    0
    installs
  50. T1592 004 Client Configurations · cyberstrikeus
    Adversaries may gather information about the victim's client configurations that can be used during targeting.
    0
    installs
  51. T1598 001 Spearphishing Service · cyberstrikeus
    Adversaries may send spearphishing messages via third-party services to elicit sensitive information that can be used during targeting.
    0
    installs
  52. T1681 Search Threat Vendor Data · cyberstrikeus
    Threat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by other adversaries that may align with...
    0
    installs
  53. Ac 20 Use Of External Systems · cyberstrikeus
    [organization-defined] , consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external s
    0
    installs
  54. Ac 4 23 Modify Non Releasable Information · cyberstrikeus
    When transferring information between different security domains, modify non-releasable information by implementing [organization-defined].
    0
    installs
  55. At 4 Training Records · cyberstrikeus
    Document and monitor information security and privacy training activities, including security and privacy awareness training and specific role-base...
    0
    installs
  56. Au 14 Session Audit · cyberstrikeus
    Provide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ;
    0
    installs
  57. Ir 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] incident response policy that: Procedures to facilitate the imple
    0
    installs
  58. Ir 4 13 Behavior Analysis · cyberstrikeus
    Analyze anomalous or suspected adversarial behavior in or related to [organization-defined].
    0
    installs
  59. Ma 3 5 Execution With Privilege · cyberstrikeus
    Monitor the use of maintenance tools that execute with increased privilege.
    0
    installs
  60. Ma 4 6 Cryptographic Protection · cyberstrikeus
    Implement the following cryptographic mechanisms to protect the integrity and confidentiality of nonlocal maintenance and diagnostic communications: [
    0
    installs
  61. Ps 4 2 Automated Actions · cyberstrikeus
    Use [organization-defined] to [organization-defined].
    0
    installs
  62. Ra 2 Security Categorization · cyberstrikeus
    Categorize the system and information it processes, stores, and transmits;
    0
    installs
  63. Sr 4 Provenance · cyberstrikeus
    Document, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined].
    0
    installs
  64. T0894 System Binary Proxy Execution · cyberstrikeus
    Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
    0
    installs
  65. T0806 Brute Force Io · cyberstrikeus
    Adversaries may repetitively or successively change I/O point values to perform an action.
    0
    installs
  66. T1456 Drive By Compromise · cyberstrikeus
    Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
    0
    installs
  67. T1629 002 Device Lockout · cyberstrikeus
    An adversary may seek to inhibit user interaction by locking the legitimate user out of the device.
    0
    installs
  68. T1423 Network Service Scanning · cyberstrikeus
    Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation.
    0
    installs
  69. T1409 Stored Application Data · cyberstrikeus
    Adversaries may try to access and collect application data resident on the device.
    0
    installs
  70. T1638 Adversary In The Middle · cyberstrikeus
    Adversaries may attempt to position themselves between two or more networked devices to support follow-on behaviors such as Transmitted Data Manipulation or Endpoint Denial of Service.
    0
    installs
  71. T1053 007 Container Orchestration Job · cyberstrikeus
    Adversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule deployment of containers configured to execute malicious code.
    0
    installs
  72. Wstg Inpv 19 · cyberstrikeus
    Testing for Server-Side Request Forgery (SSRF)
    0
    installs
  73. Wstg Inpv 20 · cyberstrikeus
    Testing for Mass Assignment
    0
    installs
  74. Wstg Sess 01 · cyberstrikeus
    Testing for Session Management Schema
    0
    installs
  75. Wstg Sess 02 · cyberstrikeus
    Testing for Cookies Attributes
    0
    installs
  76. Wstg Sess 03 · cyberstrikeus
    Testing for Session Fixation
    0
    installs
  77. Wstg Sess 04 · cyberstrikeus
    Testing for Exposed Session Variables
    0
    installs
  78. Wstg Sess 05 · cyberstrikeus
    Testing for Cross Site Request Forgery (CSRF)
    0
    installs
  79. Wstg Sess 06 · cyberstrikeus
    Testing for Logout Functionality
    0
    installs
  80. Wstg Sess 07 · cyberstrikeus
    Testing for Session Timeout
    0
    installs
  81. Wstg Sess 08 · cyberstrikeus
    Testing for Session Puzzling
    0
    installs
  82. Wstg Sess 09 · cyberstrikeus
    Testing for Session Hijacking
    0
    installs
  83. Wstg Sess 10 · cyberstrikeus
    Testing JSON Web Tokens (JWT)
    0
    installs
  84. Wstg Sess 11 · cyberstrikeus
    Testing for Concurrent Sessions
    0
    installs
  85. Wstg Authz 01 · cyberstrikeus
    Testing Directory Traversal File Include
    0
    installs
  86. Wstg Authz 02 · cyberstrikeus
    Testing for Bypassing Authorization Schema
    0
    installs
  87. Wstg Authz 03 · cyberstrikeus
    Testing for Privilege Escalation
    0
    installs
  88. Wstg Authz 04 · cyberstrikeus
    Testing for Insecure Direct Object References (IDOR)
    0
    installs
  89. Wstg Authz 05 · cyberstrikeus
    Testing for OAuth Weaknesses
    0
    installs
  90. Wstg Clnt 01 1 · cyberstrikeus
    Testing for Self DOM-Based XSS
    0
    installs
  91. Wstg Injection · cyberstrikeus
    WSTG input validation and injection testing - SQLi, XSS, SSTI, SSRF, command injection, XXE
    0
    installs
  92. Wstg Inpv 05 1 · cyberstrikeus
    Testing for SQL Injection - Oracle
    0
    installs
  93. Wstg Inpv 05 2 · cyberstrikeus
    Testing for SQL Injection - MySQL
    0
    installs
  94. Wstg Inpv 05 3 · cyberstrikeus
    Testing for SQL Injection - SQL Server
    0
    installs
  95. Wstg Inpv 05 4 · cyberstrikeus
    Testing for SQL Injection - PostgreSQL
    0
    installs
  96. Wstg Inpv 05 5 · cyberstrikeus
    Testing for SQL Injection - MS Access
    0
    installs
  97. Wstg Inpv 05 6 · cyberstrikeus
    Testing for NoSQL Injection
    0
    installs
  98. Wstg Inpv 05 7 · cyberstrikeus
    Testing for ORM Injection
    0
    installs
  99. Wstg Inpv 05 8 · cyberstrikeus
    Testing for Client-Side SQL Injection
    0
    installs
  100. Wstg Inpv 11 1 · cyberstrikeus
    Testing for File Inclusion (LFI/RFI)
    0
    installs