All authors

Claude Skills by CyberStrikeus
github.com/CyberStrikeus7,689 skills0 installs16,544 views
- T1027.011 Fileless StorageAdversaries may store data in "fileless" formats to conceal malicious activity from defenses.Votes: 0GitHub stars: 2,182
- T1027.012 Lnk Icon SmugglingAdversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files.Votes: 0GitHub stars: 2,182
- T1027.013 Encryptedencoded FileAdversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.Votes: 0GitHub stars: 2,182
- T1027.014 Polymorphic CodeAdversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection.Votes: 0GitHub stars: 2,182
- T1027.015 CompressionAdversaries may use compression to obfuscate their payloads or files.Votes: 0GitHub stars: 2,182
- T1027.016 Junk Code InsertionAdversaries may use junk code / dead code to obfuscate a malware’s functionality.Votes: 0GitHub stars: 2,182
- T1027.017 Svg SmugglingAdversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign SVG files.Votes: 0GitHub stars: 2,182
- T1027 Obfuscated Files Or InformationAdversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.Votes: 0GitHub stars: 2,182
- T1036.001 Invalid Code SignatureAdversaries may attempt to mimic features of valid code signatures to increase the chance of deceiving a user, analyst, or tool.Votes: 0GitHub stars: 2,182
- T1036.002 Right To Left OverrideAdversaries may abuse the right-to-left override (RTLO or RLO) character (U+202E) to disguise a string and/or file name to make it appear benign.Votes: 0GitHub stars: 2,182
- T1036.003 Rename Legitimate UtilitiesAdversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities.Votes: 0GitHub stars: 2,182
- T1036.004 Masquerade Task Or ServiceAdversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign.Votes: 0GitHub stars: 2,182
- T1036.006 Space After FilenameAdversaries can hide a program's true filetype by changing the extension of a file.Votes: 0GitHub stars: 2,182
- T1036.007 Double File ExtensionAdversaries may abuse a double extension in the filename as a means of masquerading the true file type.Votes: 0GitHub stars: 2,182
- T1036.008 Masquerade File TypeAdversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents.Votes: 0GitHub stars: 2,182
- T1036.009 Break Process TreesAn adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID).Votes: 0GitHub stars: 2,182
- T1036.010 Masquerade Account NameAdversaries may match or approximate the names of legitimate accounts to make newly created ones appear benign.Votes: 0GitHub stars: 2,182
- T1036.011 Overwrite Process ArgumentsAdversaries may modify a process's in-memory arguments to change its name in order to appear as a legitimate or benign process.Votes: 0GitHub stars: 2,182
- T1036.012 Browser FingerprintAdversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc.Votes: 0GitHub stars: 2,182
- T1036 MasqueradingAdversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.Votes: 0GitHub stars: 2,182
- T1055.001 Dynamic Link Library InjectionAdversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055.002 Portable Executable InjectionAdversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055.003 Thread Execution HijackingAdversaries may inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055.004 Asynchronous Procedure CallAdversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055.005 Thread Local StorageAdversaries may inject malicious code into processes via thread local storage (TLS) callbacks in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055.008 Ptrace System CallsAdversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055.009 Proc MemoryAdversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055.011 Extra Window Memory InjectionAdversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055.012 Process HollowingAdversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses.Votes: 0GitHub stars: 2,182
- T1055.013 Process DoppelgngingAdversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055.014 Vdso HijackingAdversaries may inject malicious code into processes via VDSO hijacking in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055.015 ListplantingAdversaries may abuse list-view controls to inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1055 Process InjectionAdversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges.Votes: 0GitHub stars: 2,182
- T1070.001 Clear Windows Event LogsAdversaries may clear Windows Event Logs to hide the activity of an intrusion.Votes: 0GitHub stars: 2,182
- T1070.002 Clear Linux Or Mac System LogsAdversaries may clear system logs to hide evidence of an intrusion.Votes: 0GitHub stars: 2,182
- T1070.003 Clear Command HistoryIn addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.Votes: 0GitHub stars: 2,182
- T1070.004 File DeletionAdversaries may delete files left behind by the actions of their intrusion activity.Votes: 0GitHub stars: 2,182
- T1070.006 TimestompAdversaries may modify file time attributes to hide new files or changes to existing files.Votes: 0GitHub stars: 2,182
- T1070.008 Clear Mailbox DataAdversaries may modify mail and mail application data to remove evidence of their activity.Votes: 0GitHub stars: 2,182
- T1070.009 Clear PersistenceAdversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity.Votes: 0GitHub stars: 2,182
- T1070.010 Relocate MalwareOnce a payload is delivered, adversaries may reproduce copies of the same malware on the victim system to remove evidence of their presence and/or avoid defenses.Votes: 0GitHub stars: 2,182
- T1070 Indicator RemovalAdversaries may delete or modify artifacts generated within systems to remove evidence of their presence or hinder defenses.Votes: 0GitHub stars: 2,182
- T1078.001 Default AccountsAdversaries may obtain and abuse credentials of a default account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.Votes: 0GitHub stars: 2,182
- T1078.002 Domain AccountsAdversaries may obtain and abuse credentials of a domain account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.Votes: 0GitHub stars: 2,182
- T1078.003 Local AccountsAdversaries may obtain and abuse credentials of a local account as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.Votes: 0GitHub stars: 2,182
- T1078.004 Cloud AccountsValid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion.Votes: 0GitHub stars: 2,182
- T1078 Valid AccountsAdversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion.Votes: 0GitHub stars: 2,182
- T1112 Modify RegistryAdversaries may interact with the Windows Registry as part of a variety of other techniques to aid in defense evasion, persistence, and execution.Votes: 0GitHub stars: 2,182
- T1127.001 MsbuildAdversaries may use MSBuild to proxy execution of code through a trusted Windows utility.Votes: 0GitHub stars: 2,182
- T1127.002 ClickonceAdversaries may use ClickOnce applications (.appref-ms and .application files) to proxy execution of code through a trusted Windows utility.Votes: 0GitHub stars: 2,182