All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
7,689 skillsA× 7,295B× 380C× 7D× 3F× 40 installs16,680 views
T1550.003 Pass The TicketA

Adversaries may “pass the ticket” using stolen Kerberos tickets to move laterally within an environment, bypassing normal system access controls.

securitygoshell
0
2,182
T1550.004 Web Session CookieA

Adversaries can use stolen session cookies to authenticate to web applications and services.

securitygotesting
0
2,182
T1553.001 Gatekeeper BypassA

Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs.

securityrustgo
0
2,182
T1553.002 Code SigningA

Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.

securityrustgo
0
2,182
T1553.004 Install Root CertificateA

Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.

securityrustgo
0
2,182
T1553.005 Mark Of The Web BypassA

Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls.

securityrustgo
0
2,182
T1553 Subvert Trust ControlsA

Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs.

securityrustgo
0
2,182
T1562.001 Disable Or Modify ToolsA

Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities.

securitygobash
0
2,182
T1562.002 Disable Windows Event LoggingA

Adversaries may disable Windows event logging to limit data that can be leveraged for detections and audits.

securitygoshell
0
2,182
T1562.003 Impair Command History LoggingB

Adversaries may impair command history logging to hide commands they run on a compromised system.

securitygoshell
0
2,182
T1562.006 Indicator BlockingA

An adversary may attempt to block indicators or events typically captured by sensors from being gathered and analyzed.

securitygoshell
0
2,182
T1562.008 Disable Or Modify Cloud LogsA

An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection.

securitygoaws
0
2,182
T1562.009 Safe Mode BootA

Adversaries may abuse Windows safe mode to disable endpoint defenses.

securitygotesting
0
2,182
T1562.010 Downgrade AttackA

Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls.

securitygoshell
0
2,182
T1562.011 Spoof Security AlertingA

Adversaries may spoof security alerting from tools, presenting false evidence to impair defenders’ awareness of malicious activity.

securitygotesting
0
2,182
T1562 Impair DefensesA

Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms.

securitygoshell
0
2,182
T1564.001 Hidden Files And DirectoriesA

Adversaries may set files and directories to be hidden to evade detection mechanisms.

securitygobash
0
2,182
T1564.002 Hidden UsersA

Adversaries may use hidden users to hide the presence of user accounts they create or modify.

securitygophp
0
2,182
T1564.003 Hidden WindowA

Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.

securitygojava
0
2,182
T1564.004 Ntfs File AttributesA

Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection.

securitygoshell
0
2,182
T1564.005 Hidden File SystemA

Adversaries may use a hidden file system to conceal malicious activity from users and security tools.

securitygotesting
0
2,182
T1564.006 Run Virtual InstanceA

Adversaries may carry out malicious operations using a virtual instance to avoid detection.

securitygoshell
0
2,182
T1564.007 Vba StompingA

Adversaries may hide malicious Visual Basic for Applications (VBA) payloads embedded within MS Office documents by replacing the VBA source code with benign data.

securitygotesting
0
2,182
T1564.008 Email Hiding RulesA

Adversaries may use email rules to hide inbound emails in a compromised user's mailbox.

securitygoshell
0
2,182
T1564.009 Resource ForkingA

Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications.

securitygotesting
0
2,182
T1564.010 Process Argument SpoofingA

Adversaries may attempt to hide process command-line arguments by overwriting process memory.

securitygoshell
0
2,182
T1564.011 Ignore Process InterruptsA

Adversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals.

securitygoshell
0
2,182
T1564.012 Filepath ExclusionsA

Adversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other defensive capabilities.

securityrustgo
0
2,182
T1564.013 Bind MountsA

Adversaries may abuse bind mounts on file structures to hide their activity and artifacts from native utilities.

securitygodocker
0
2,182
T1564.014 Extended AttributesA

Adversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade detection.

securityrustgo
0
2,182
T1564 Hide ArtifactsA

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection.

securityrustgo
0
2,182
T1578.001 Create SnapshotA

An adversary may create a snapshot or data backup within a cloud account to evade defenses.

securitygoaws
0
2,182
T1578.002 Create Cloud InstanceA

An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses.

securitygoaws
0
2,182
T1578.003 Delete Cloud InstanceA

An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence.

securitygoaws
0
2,182
T1578.004 Revert Cloud InstanceA

An adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove evidence of their presence.

securitygoaws
0
2,182
T1599 Network Boundary BridgingA

Adversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation.

securityrustgo
0
2,182
T1600.001 Reduce Key SpaceA

Adversaries may reduce the level of effort required to decrypt data transmitted over the network by reducing the cipher strength of encrypted communications.

securitygotesting
0
2,182
T1600.002 Disable Crypto HardwareA

Adversaries disable a network device’s dedicated hardware encryption, which may enable them to leverage weaknesses in software encryption in order to reduce the effort involved in collecting, manip...

securitygotesting
0
2,182
T1600 Weaken EncryptionA

Adversaries may compromise a network device’s encryption capability in order to bypass encryption that would otherwise protect data communications.

securitygotesting
0
2,182
T1601.001 Patch System ImageA

Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses.

securitygoshell
0
2,182
T1601.002 Downgrade System ImageA

Adversaries may install an older version of the operating system of a network device to weaken security.

securitygotesting
0
2,182
T1601 Modify System ImageA

Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves.

securitygotesting
0
2,182
T1610 Deploy ContainerA

Adversaries may deploy a container into an environment to facilitate execution or evade defenses.

securitygobash
0
2,182
T1612 Build Image On HostA

Adversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry.

securitygobash
0
2,182
T1620 Reflective Code LoadingA

Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads.

securitygoshell
0
2,182
T1622 Debugger EvasionA

Adversaries may employ various means to detect and avoid debuggers.

securitygoshell
0
2,182
T1647 Plist File ModificationA

Adversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses.

securitygotesting
0
2,182
T1656 ImpersonationA

Adversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf.

securityrustgo
0
2,182
T1666 Modify Cloud Resource HierarchyA

Adversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses.

securitygorails
0
2,182
T1672 Email SpoofingA

Adversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses.

securitygotesting
0
2,182