
Claude Skills by CyberStrikeus
github.com/CyberStrikeusAdversaries who successfully compromise a system may attempt to maintain persistence by “closing the door” behind them – in other words, by preventing other threat actors from initially accessing o...
Adversaries may achieve persistence by leveraging OAuth application integrations in a software-as-a-service environment.
Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence.
Adversaries may grant additional permission levels to maintain persistent access to an adversary-controlled email account.
An adversary may add additional roles or permissions to an adversary-controlled user or service account to maintain persistent access to a container orchestration system.
An adversary may add additional local or domain groups to an adversary-controlled account to maintain persistent access to a system or domain.
Adversaries may achieve persistence by adding a program to a startup folder or referencing it with a Registry run key.
Adversaries may execute their own malicious payloads by hijacking the binaries used by an installer.
Adversaries may execute their own malicious payloads by hijacking environment variables used to load libraries.
Adversaries may execute their own malicious payloads by hijacking the search order used to load other programs.
Adversaries may execute their own malicious payloads by hijacking vulnerable file path references.
Adversaries may execute their own malicious payloads by hijacking the binaries used by services.
Adversaries may execute their own malicious payloads by hijacking the Registry entries used by services.
Adversaries may establish persistence by executing malicious content triggered by user inactivity.
Adversaries may establish persistence by executing malicious content triggered by an interrupt signal.
Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries.
Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features.
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes.
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond).
Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.
Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events.
An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.
Adversaries may bypass UAC mechanisms to elevate process privileges on system.
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges.
Adversaries may leverage the <code>AuthorizationExecuteWithPrivileges</code> API to escalate privileges by prompting the user for credentials.
Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions.
Adversaries may break out of a container or virtualized environment to gain access to the underlying host.
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Adversaries may establish persistence by executing malicious content triggered by a file type association.
Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell.
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers.
Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.
Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.
Adversaries may directly access a volume to bypass file access controls and file system monitoring.
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
Adversaries may perform software packing or virtual machine software protection to conceal their code.
Adversaries may use steganography techniques in order to prevent the detection of hidden information.
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code.
Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed.
Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.
Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis.
Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information.
Adversaries may embed payloads within other files to conceal malicious content from defenses.
Adversaries may obfuscate content during command execution to impede detection.