
Claude Skills by CyberStrikeus
github.com/CyberStrikeusAdversaries may use `JamPlus` to proxy the execution of a malicious script.
Adversaries may duplicate then impersonate another user's existing token to escalate privileges and bypass access controls.
Adversaries may create a new process with an existing token to escalate privileges and bypass access controls.
Adversaries may make new tokens and impersonate users to escalate privileges and bypass access controls.
Adversaries may spoof the parent process identifier (PPID) of a new process to evade process-monitoring defenses or to elevate privileges.
Adversaries may use SID-History Injection to escalate privileges and bypass access controls.
Adversaries may modify access tokens to operate under a different user or system security context to perform actions and bypass access controls.
Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks.
Adversaries may abuse utilities that allow for command execution to bypass security restrictions that limit the use of command-line interpreters.
Adversaries may use port knocking to hide open ports used for persistence or command and control.
Adversaries may attach filters to a network socket to monitor then activate backdoors used for persistence or command and control.
Adversaries may use traffic signaling to hide open ports or other malicious functionality used for persistence or command and control.
Adversaries may register a rogue Domain Controller to enable manipulation of Active Directory data.
Adversaries may exploit a system or application vulnerability to bypass security features.
Adversaries may use PubPrn to proxy execution of malicious remote files.
Adversaries may abuse SyncAppvPublishingServer.vbs to proxy execution of malicious PowerShell commands.
Adversaries may use trusted scripts, often signed with certificates, to proxy the execution of malicious files.
Adversaries may abuse Compiled HTML files (.chm) to conceal malicious code.
Adversaries may abuse control.exe to proxy execution of malicious payloads.
Adversaries may abuse CMSTP to proxy execution of malicious code.
Adversaries may use InstallUtil to proxy execution of code through a trusted Windows utility.
Adversaries may abuse mshta.exe to proxy execution of malicious .hta files and Javascript or VBScript through a trusted Windows utility.
Adversaries may abuse msiexec.exe to proxy execution of malicious payloads.
Adversaries may abuse odbcconf.exe to proxy execution of malicious payloads.
Adversaries may abuse Regsvcs and Regasm to proxy execution of code through a trusted Windows utility.
Adversaries may abuse Regsvr32.exe to proxy execution of malicious code.
Adversaries may abuse rundll32.exe to proxy execution of malicious code.
Adversaries may abuse verclsid.exe to proxy execution of malicious code.
Adversaries may abuse mavinject.exe to proxy execution of malicious code.
Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.
Adversaries may abuse components of the Electron framework to execute malicious code.
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files.
Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts.
Adversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution to a specific target environment.
Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.
Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses an...
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.
Adversaries may employ various user activity checks to detect and avoid virtualization and analysis environments.
Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.
Adversaries may employ various means to detect and avoid virtualization and analysis environments.
Adversaries may create cloud instances in unused geographic service regions in order to evade detection.
Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate device behavior that is difficult to detect.
Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server.
Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system.
Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions.
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems.
Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls.