cyberstrikeus
- 7.2k skills
- 0 followers
- 21 hours ago last updated
- ▌ T1598 Phishing For Information · cyberstrikeusAdversaries may send phishing messages to elicit sensitive information that can be used during targeting.
- ▌ Asset Management Id Am Asset Management · cyberstrikeusAssets (e.g., data, hardware, software, systems, facilities, services, people) that enable the organization to achieve business purposes are identifie
- ▌ Risk Assessment Id Ra Risk Assessment · cyberstrikeusThe cybersecurity risk to the organization, assets, and individuals is understood by the organization
- ▌ Identity Management Authentication And Access Control Pr Aa · cyberstrikeusAccess to physical and logical assets is limited to authorized users, services, and hardware and managed commensurate with the assessed risk of unauth
- ▌ Ac 12 2 Termination Message · cyberstrikeusDisplay an explicit logout message to users indicating the termination of authenticated communications sessions.
- ▌ Ac 16 7 Consistent Attribute Interpretation · cyberstrikeusProvide a consistent interpretation of security and privacy attributes transmitted between distributed system components.
- ▌ Ac 23 Data Mining Protection · cyberstrikeusEmploy [organization-defined] for [organization-defined] to detect and protect against unauthorized data mining.
- ▌ Ac 8 System Use Notification · cyberstrikeusDisplay [organization-defined] to users before granting access to the system that provides privacy and security notices consistent with applicable law
- ▌ Au 2 Event Logging · cyberstrikeusIdentify the types of events that the system is capable of logging in support of the audit function: [organization-defined];
- ▌ Cp 4 5 Self Challenge · cyberstrikeusEmploy [organization-defined] to [organization-defined] to disrupt and adversely affect the system or system component.
- ▌ Ir 3 1 Automated Testing · cyberstrikeusTest the incident response capability using [organization-defined].
- ▌ Ma 4 7 Disconnect Verification · cyberstrikeusVerify session and network connection termination after the completion of nonlocal maintenance and diagnostic sessions.
- ▌ Mp 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] media protection policy that: Procedures to facilitate the implem
- ▌ Mp 6 7 Dual Authorization · cyberstrikeusEnforce dual authorization for the sanitization of [organization-defined].
- ▌ Ps 3 Personnel Screening · cyberstrikeusScreen individuals prior to authorizing access to the system;
- ▌ Ps 8 Personnel Sanctions · cyberstrikeusEmploy a formal sanctions process for individuals failing to comply with established information security and privacy policies and procedures;
- ▌
- ▌ Ra 6 Technical Surveillance Countermeasures Survey · cyberstrikeusEmploy a technical surveillance countermeasures survey at [organization-defined] [organization-defined].
- ▌ T0884 Connection Proxy · cyberstrikeusAdversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications.
- ▌ T0864 Transient Cyber Asset · cyberstrikeusAdversaries may target devices that are transient across ICS networks and external networks.
- ▌ T0812 Default Credentials · cyberstrikeusAdversaries may leverage manufacturer or supplier set default credentials on control system devices.
- ▌ T1625 Hijack Execution Flow · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking the way operating systems run applications.
- ▌ T1406 001 Steganography · cyberstrikeusAdversaries may use steganography techniques in order to prevent the detection of hidden information.
- ▌ T1630 002 File Deletion · cyberstrikeusAdversaries may wipe a device or delete individual files in order to manipulate external outcomes or hide activity.
- ▌ T1631 Process Injection · cyberstrikeusAdversaries may inject code into processes in order to evade process-based defenses or even elevate privileges.
- ▌ T1633 001 System Checks · cyberstrikeusAdversaries may employ various system checks to detect and avoid virtualization and analysis environments.
- ▌ T1642 Endpoint Denial Of Service · cyberstrikeusAdversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users.
- ▌ T1532 Archive Collected Data · cyberstrikeusAdversaries may compress and/or encrypt data that is collected prior to exfiltration.
- ▌ T1533 Data From Local System · cyberstrikeusAdversaries may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to exfiltration.
- ▌ T1037 Boot Or Logon Initialization Scripts · cyberstrikeusAdversaries may use scripts automatically executed at boot or logon initialization to establish persistence.
- ▌ T1574 006 Dynamic Linker Hijacking · cyberstrikeusAdversaries may execute their own malicious payloads by hijacking environment variables the dynamic linker uses to load shared libraries.
- ▌ T1036 006 Space After Filename · cyberstrikeusAdversaries can hide a program's true filetype by changing the extension of a file.
- ▌ T1036 008 Masquerade File Type · cyberstrikeusAdversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents.
- ▌ T1055 005 Thread Local Storage · cyberstrikeusAdversaries may inject malicious code into processes via thread local storage (TLS) callbacks in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1055 013 Process Doppelgnging · cyberstrikeusAdversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly elevate privileges.
- ▌ T1480 001 Environmental Keying · cyberstrikeusAdversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution to a specific target environment.
- ▌ T1564 004 Ntfs File Attributes · cyberstrikeusAdversaries may use NTFS file attributes to hide their malicious data in order to evade detection.
- ▌ T1564 006 Run Virtual Instance · cyberstrikeusAdversaries may carry out malicious operations using a virtual instance to avoid detection.
- ▌ T1578 005 Modify Cloud Compute Configurations · cyberstrikeusAdversaries may modify settings that directly affect the size, locations, and resources available to cloud compute infrastructure in order to evade defenses.
- ▌ T1580 Cloud Infrastructure Discovery · cyberstrikeusAn adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment.
- ▌ T1619 Cloud Storage Object Discovery · cyberstrikeusAdversaries may enumerate objects in cloud storage infrastructure.
- ▌ T1560 003 Archive Via Custom Method · cyberstrikeusAn adversary may compress or encrypt data that is collected prior to exfiltration using a custom method.
- ▌ T1104 Multi Stage Channels · cyberstrikeusAdversaries may create multiple stages for command and control that are employed under different conditions or for certain functions.
- ▌ T1565 002 Transmitted Data Manipulation · cyberstrikeusAdversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity, thus threatening the integrity of the data.
- ▌ T1584 008 Network Devices · cyberstrikeusAdversaries may compromise third-party network devices that can be used during targeting.
- ▌ T1586 Compromise Accounts · cyberstrikeusAdversaries may compromise accounts with services that can be used during targeting.
- ▌ T1588 Obtain Capabilities · cyberstrikeusAdversaries may buy and/or steal capabilities that can be used during targeting.
- ▌ T1588 006 Vulnerabilities · cyberstrikeusAdversaries may acquire information about vulnerabilities that can be used during targeting.
- ▌ T1608 004 Drive By Target · cyberstrikeusAdversaries may prepare an operational environment to infect systems that visit a website over the normal course of browsing.
- ▌ T1592 004 Client Configurations · cyberstrikeusAdversaries may gather information about the victim's client configurations that can be used during targeting.
- ▌ T1598 001 Spearphishing Service · cyberstrikeusAdversaries may send spearphishing messages via third-party services to elicit sensitive information that can be used during targeting.
- ▌ T1681 Search Threat Vendor Data · cyberstrikeusThreat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by other adversaries that may align with...
- ▌ Ac 20 Use Of External Systems · cyberstrikeus[organization-defined] , consistent with the trust relationships established with other organizations owning, operating, and/or maintaining external s
- ▌ Ac 4 23 Modify Non Releasable Information · cyberstrikeusWhen transferring information between different security domains, modify non-releasable information by implementing [organization-defined].
- ▌ At 4 Training Records · cyberstrikeusDocument and monitor information security and privacy training activities, including security and privacy awareness training and specific role-base...
- ▌ Au 14 Session Audit · cyberstrikeusProvide and implement the capability for [organization-defined] to [organization-defined] the content of a user session under [organization-defined] ;
- ▌ Ir 1 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to [organization-defined]: [organization-defined] incident response policy that: Procedures to facilitate the imple
- ▌ Ir 4 13 Behavior Analysis · cyberstrikeusAnalyze anomalous or suspected adversarial behavior in or related to [organization-defined].
- ▌ Ma 3 5 Execution With Privilege · cyberstrikeusMonitor the use of maintenance tools that execute with increased privilege.
- ▌ Ma 4 6 Cryptographic Protection · cyberstrikeusImplement the following cryptographic mechanisms to protect the integrity and confidentiality of nonlocal maintenance and diagnostic communications: [
- ▌
- ▌ Ra 2 Security Categorization · cyberstrikeusCategorize the system and information it processes, stores, and transmits;
- ▌ Sr 4 Provenance · cyberstrikeusDocument, monitor, and maintain valid provenance of the following systems, system components, and associated data: [organization-defined].
- ▌ T0894 System Binary Proxy Execution · cyberstrikeusAdversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
- ▌ T0806 Brute Force Io · cyberstrikeusAdversaries may repetitively or successively change I/O point values to perform an action.
- ▌ T1456 Drive By Compromise · cyberstrikeusAdversaries may gain access to a system through a user visiting a website over the normal course of browsing.
- ▌ T1629 002 Device Lockout · cyberstrikeusAn adversary may seek to inhibit user interaction by locking the legitimate user out of the device.
- ▌ T1423 Network Service Scanning · cyberstrikeusAdversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation.
- ▌ T1409 Stored Application Data · cyberstrikeusAdversaries may try to access and collect application data resident on the device.
- ▌ T1638 Adversary In The Middle · cyberstrikeusAdversaries may attempt to position themselves between two or more networked devices to support follow-on behaviors such as Transmitted Data Manipulation or Endpoint Denial of Service.
- ▌ T1053 007 Container Orchestration Job · cyberstrikeusAdversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule deployment of containers configured to execute malicious code.
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Wstg Injection · cyberstrikeusWSTG input validation and injection testing - SQLi, XSS, SSTI, SSRF, command injection, XXE
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌