All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
7,689 skillsA× 7,295B× 380C× 7D× 3F× 40 installs16,699 views
T1127.003 JamplusA

Adversaries may use `JamPlus` to proxy the execution of a malicious script.

securityrustgo
0
2,182
T1134.001 Token ImpersonationtheftA

Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls.

securitygoshell
0
2,182
T1134.002 Create Process With TokenA

Adversaries may create a new process with an existing token to escalate privileges and bypass access controls.

securitygoshell
0
2,182
T1134.003 Make And Impersonate TokenA

Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls.

securitygotesting
0
2,182
T1134.004 Parent Pid SpoofingA

Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.

securitygoshell
0
2,182
T1134.005 Sid History InjectionA

Adversaries may use SID-History Injection to escalate privileges and bypass access controls.

securityrustgo
0
2,182
T1134 Access Token ManipulationA

Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.

securitygotesting
0
2,182
T1197 Bits JobsA

Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks.

securitygoshell
0
2,182
T1202 Indirect Command ExecutionA

Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters.

securitygoshell
0
2,182
T1205.001 Port KnockingA

Adversaries may use port knocking to hide open ports used for persistence or command and control.

securitygotesting
0
2,182
T1205.002 Socket FiltersA

Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and control.

securitygoshell
0
2,182
T1205 Traffic SignalingA

Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control.

securitygotesting
0
2,182
T1207 Rogue Domain ControllerA

Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data.

securitygoshell
0
2,182
T1211 Exploitation For Defense EvasionA

Adversaries may exploit a system or application vulnerability to bypass security features.

securitygoaws
0
2,182
T1216.001 PubprnA

Adversaries may use PubPrn to proxy execution of malicious remote files.

securitygoshell
0
2,182
T1216.002 SyncappvpublishingserverA

Adversaries may abuse SyncAppvPublishingServer.vbs to proxy execution of malicious PowerShell commands.

securityrustgo
0
2,182
T1216 System Script Proxy ExecutionA

Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files.

securityrustgo
0
2,182
T1218.001 Compiled Html FileA

Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code.

securitygojava
0
2,182
T1218.002 Control PanelA

Adversaries may abuse control.exe to proxy execution of malicious payloads.

securitygotesting
0
2,182
T1218.003 CmstpA

Adversaries may abuse CMSTP to proxy execution of malicious code.

securitygotesting
0
2,182
T1218.004 InstallutilA

Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility.

securityrustgo
0
2,182
T1218.005 MshtaA

Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility.

securityjavascriptrust
0
2,182
T1218.007 MsiexecA

Adversaries may abuse msiexec.exe to proxy execution of malicious payloads.

securitygoshell
0
2,182
T1218.008 OdbcconfA

Adversaries may abuse odbcconf.exe to proxy execution of malicious payloads.

securitygoshell
0
2,182
T1218.009 RegsvcsregasmA

Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility.

securityrustgo
0
2,182
T1218.010 Regsvr32A

Adversaries may abuse Regsvr32.exe to proxy execution of malicious code.

securitygotesting
0
2,182
T1218.011 Rundll32A

Adversaries may abuse rundll32.exe to proxy execution of malicious code.

securityjavascriptgo
0
2,182
T1218.012 VerclsidA

Adversaries may abuse verclsid.exe to proxy execution of malicious code.

securitygoshell
0
2,182
T1218.013 MavinjectA

Adversaries may abuse mavinject.exe to proxy execution of malicious code.

securitygotesting
0
2,182
T1218.014 MmcA

Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.

securityrustgo
0
2,182
T1218.015 Electron ApplicationsA

Adversaries may abuse components of the Electron framework to execute malicious code.

securityjavascriptrust
0
2,182
T1218 System Binary Proxy ExecutionA

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.

securityjavascriptrust
0
2,182
T1220 Xsl Script ProcessingA

Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files.

securityjavascriptrust
0
2,182
T1221 Template InjectionA

Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts.

securitygotesting
0
2,182
T1480.001 Environmental KeyingA

Adversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution to a specific target environment.

securitygorails
0
2,182
T1480.002 Mutual ExclusionA

Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.

securitygorails
0
2,182
T1480 Execution GuardrailsA

Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.

securitygorails
0
2,182
T1484.001 Group Policy ModificationA

Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.

securitygoshell
0
2,182
T1484.002 Trust ModificationA

Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses an...

securityrustgo
0
2,182
T1497.001 System ChecksA

Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.

securitygoshell
0
2,182
T1497.002 User Activity Based ChecksA

Adversaries may employ various user activity checks to detect and avoid virtualization and analysis environments.

securitygotesting
0
2,182
T1497.003 Time Based ChecksA

Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.

securitygobash
0
2,182
T1497 Virtualizationsandbox EvasionA

Adversaries may employ various means to detect and avoid virtualization and analysis environments.

securitygotesting
0
2,182
T1535 Unusedunsupported Cloud RegionsA

Adversaries may create cloud instances in unused geographic service regions in order to evade detection.

securitygoaws
0
2,182
T1542.004 RommonkitA

Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate device behavior that is difficult to detect.

securitygotesting
0
2,182
T1542.005 Tftp BootA

Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server.

securityrustgo
0
2,182
T1542 Pre Os BootA

Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system.

securityrustgo
0
2,182
T1548.006 Tcc ManipulationA

Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions.

securitygotesting
0
2,182
T1550.001 Application Access TokenA

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems.

securitygoaws
0
2,182
T1550.002 Pass The HashA

Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls.

securitygoshell
0
2,182