All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
7,689 skillsA× 7,295B× 380C× 7D× 3F× 40 installs16,699 views
T1668 Exclusive ControlA

Adversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind them – in other words, by preventing other threat actors from initially accessing o...

securitygotesting
0
2,182
T1671 Cloud Application IntegrationA

Adversaries may achieve persistence by leveraging OAuth application integrations in a software-as-a-service environment.

securitygoazure
0
2,182
T1037 Boot Or Logon InitializationA

Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence.

securitygotesting
0
2,182
T1098 002 Additional Email DelegateA

Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account.

securitygoshell
0
2,182
T1098 006 Additional Container ClusterA

An adversary may add additional roles or permissions to an adversary-controlled user or service account to maintain persistent access to a container orchestration system.

securitygokubernetes
0
2,182
T1098 007 Additional Local Or DomainA

An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or domain.

securitygotesting
0
2,182
T1547 001 Registry Run Keys StartupA

Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.

securitygoshell
0
2,182
T1574 005 Executable Installer FileA

Adversaries may execute their own malicious payloads by hijacking the binaries used by an installer.

securityrustgo
0
2,182
T1574 007 Path Interception By PathA

Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries.

securitygoshell
0
2,182
T1574 008 Path Interception By SearchA

Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs.

securitygoshell
0
2,182
T1574 009 Path Interception By UnquotedA

Adversaries may execute their own malicious payloads by hijacking vulnerable file path references.

securitygotesting
0
2,182
T1574 010 Services File PermissionsA

Adversaries may execute their own malicious payloads by hijacking the binaries used by services.

securitygoaws
0
2,182
T1574 011 Services Registry PermissionsA

Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services.

securityrustgo
0
2,182
T1546.002 ScreensaverA

Adversaries may establish persistence by executing malicious content triggered by user inactivity.

securitygotesting
0
2,182
T1546.005 TrapA

Adversaries may establish persistence by executing malicious content triggered by an interrupt signal.

securitygoshell
0
2,182
T1546.006 Lcloaddylib AdditionA

Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries.

securitygotesting
0
2,182
T1546.007 Netsh Helper DllA

Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.

securitygoshell
0
2,182
T1546.008 Accessibility FeaturesA

Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features.

securitygoshell
0
2,182
T1546.009 Appcert DllsA

Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes.

securitygoshell
0
2,182
T1546.010 Appinit DllsA

Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.

securitygonode
0
2,182
T1546.011 Application ShimmingA

Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.

securitygoshell
0
2,182
T1546.013 Powershell ProfileA

Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.

securitygoshell
0
2,182
T1546.014 EmondA

Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond).

securitygobash
0
2,182
T1546.016 Installer PackagesA

Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.

securitygotesting
0
2,182
T1546 Event Triggered ExecutionA

Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events.

securitygoshell
0
2,182
T1548.001 Setuid And SetgidA

An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.

securitygoshell
0
2,182
T1548.002 Bypass User Account ControlA

Adversaries may bypass UAC mechanisms to elevate process privileges on system.

securityrustgo
0
2,182
T1548.003 Sudo And Sudo CachingB

Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges.

securitygobash
0
2,182
T1548.004 Elevated Execution With PromptA

Adversaries may leverage the <code>AuthorizationExecuteWithPrivileges</code> API to escalate privileges by prompting the user for credentials.

securitygotesting
0
2,182
T1548 Abuse Elevation Control MechanismA

Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions.

securitygoshell
0
2,182
T1611 Escape To HostA

Adversaries may break out of a container or virtualized environment to gain access to the underlying host.

securitygoshell
0
2,182
T1068 Exploitation For PrivilegeA

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.

securitygotesting
0
2,182
T1546 001 Change Default FileA

Adversaries may establish persistence by executing malicious content triggered by a file type association.

securitygoshell
0
2,182
T1546 003 Windows ManagementB

Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.

securitygoshell
0
2,182
T1546 004 Unix Shell ConfigurationF

Adversaries may establish persistence through executing malicious commands triggered by a user’s shell.

securitygophp
0
2,182
T1546 012 Image File Execution OptionsA

Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers.

securitygoshell
0
2,182
T1546 015 Component Object ModelA

Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.

securitygoshell
0
2,182
T1548 005 Temporary Elevated CloudA

Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.

securitygoaws
0
2,182
T1006 Direct Volume AccessA

Adversaries may directly access a volume to bypass file access controls and file system monitoring.

securitygoshell
0
2,182
T1014 RootkitA

Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.

securitygobash
0
2,182
T1027.001 Binary PaddingA

Adversaries may use binary padding to add junk data and change the on-disk representation of malware.

securityrustgo
0
2,182
T1027.002 Software PackingA

Adversaries may perform software packing or virtual machine software protection to conceal their code.

securitygobash
0
2,182
T1027.003 SteganographyA

Adversaries may use steganography techniques in order to prevent the detection of hidden information.

securitygoshell
0
2,182
T1027.004 Compile After DeliveryA

Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code.

securitygoc#
0
2,182
T1027.005 Indicator Removal From ToolsA

Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed.

securitygotesting
0
2,182
T1027.006 Html SmugglingA

Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.

securityjavascriptgo
0
2,182
T1027.007 Dynamic Api ResolutionA

Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis.

securitygoshell
0
2,182
T1027.008 Stripped PayloadsA

Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information.

securitygotesting
0
2,182
T1027.009 Embedded PayloadsA

Adversaries may embed payloads within other files to conceal malicious content from defenses.

securityrustgo
0
2,182
T1027.010 Command ObfuscationA

Adversaries may obfuscate content during command execution to impede detection.

securityjavascriptgo
0
2,182