All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
7,689 skillsA× 7,295B× 380C× 7D× 3F× 40 installs16,699 views
T1555.002 Securityd MemoryA

An adversary with root access may gather credentials by reading `securityd`’s memory.

securitygotesting
0
2,182
T1555.003 Credentials From Web BrowsersA

Adversaries may acquire credentials from web browsers by reading files specific to the target browser.

securitygoshell
0
2,182
T1555.004 Windows Credential ManagerA

Adversaries may acquire credentials from the Windows Credential Manager.

securitygoshell
0
2,182
T1555.005 Password ManagersA

Adversaries may acquire user credentials from third-party password managers.

securitygotesting
0
2,182
T1555 Credentials From Password StoresA

Adversaries may search for common password storage locations to obtain user credentials.

securitygoshell
0
2,182
T1556.002 Password Filter DllA

Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process to acquire user credentials as they are validated.

securityrustgo
0
2,182
T1556.004 Network Device AuthenticationA

Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices.

securitygotesting
0
2,182
T1556.005 Reversible EncryptionA

An adversary may abuse Active Directory authentication encryption properties to gain access to credentials on Windows systems.

securitygoshell
0
2,182
T1556.006 Multi Factor AuthenticationA

Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.

securitygoazure
0
2,182
T1556.007 Hybrid IdentityA

Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credent...

securityrustgo
0
2,182
T1556.008 Network Provider DllA

Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.

securitygotesting
0
2,182
T1556.009 Conditional Access PoliciesA

Adversaries may disable or modify conditional access policies to enable persistent access to compromised accounts.

securityrustgo
0
2,182
T1556 Modify Authentication ProcessA

Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts.

securitygoazure
0
2,182
T1557.002 Arp Cache PoisoningA

Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices.

securitygotesting
0
2,182
T1557.003 Dhcp SpoofingA

Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network.

securityrustgo
0
2,182
T1557.004 Evil TwinA

Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as Network Sniffing, Transmitted Da...

securityrustgo
0
2,182
T1557 Adversary In The MiddleA

Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Trans...

securitygotesting
0
2,182
T1558.001 Golden TicketA

Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket.

securitygoshell
0
2,182
T1558.002 Silver TicketA

Adversaries who have the password hash of a target service account (e.g.

securitygoshell
0
2,182
T1558.003 KerberoastingA

Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.

securitygoshell
0
2,182
T1558.004 As Rep RoastingA

Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by Password Cracking Kerberos messages.

securitygoshell
0
2,182
T1558.005 Ccache FilesA

Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache).

securitygotesting
0
2,182
T1558 Steal Or Forge Kerberos TicketsA

Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket.

securitygoazure
0
2,182
T1606.001 Web CookiesA

Adversaries may forge web cookies that can be used to gain access to web applications or Internet services.

securitygotesting
0
2,182
T1606.002 Saml TokensA

An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate.

securityrustgo
0
2,182
T1606 Forge Web CredentialsA

Adversaries may forge credential materials that can be used to gain access to web applications or Internet services.

securitygoaws
0
2,182
T1111 Multi Factor AuthenticationA

Adversaries may target multi-factor authentication (MFA) mechanisms, (i.e., smart cards, token generators, etc.) to gain access to credentials that can be used to access systems, services, and netw...

securitygotesting
0
2,182
T1555 006 Cloud Secrets ManagementA

Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.

securitygoaws
0
2,182
T1556 001 Domain ControllerA

Adversaries may patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.

securitygoshell
0
2,182
T1556 003 Pluggable AuthenticationB

Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.

securitygobash
0
2,182
T1557 001 Llmnrnbt Ns Poisoning And SmbA

By responding to LLMNR/NBT-NS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system.

securitygoshell
0
2,182
T1621 Multi Factor AuthenticationA

Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.

securitygoazure
0
2,182
T1649 Steal Or Forge AuthenticationA

Adversaries may steal or forge certificates used for authentication to access remote systems or resources.

securityrustgo
0
2,182
T1007 System Service DiscoveryB

Adversaries may try to gather information about registered local system services.

securitygoshell
0
2,182
T1010 Application Window DiscoveryA

Adversaries may attempt to get a listing of open application windows.

securitygoc#
0
2,182
T1012 Query RegistryA

Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.

securitygoshell
0
2,182
T1016.001 Internet Connection DiscoveryA

Adversaries may check for Internet connectivity on compromised systems.

securitygoshell
0
2,182
T1016.002 Wi Fi DiscoveryB

Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.

securitygoshell
0
2,182
T1018 Remote System DiscoveryB

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.

securitygotesting
0
2,182
T1033 System Owneruser DiscoveryA

Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.

securitygoshell
0
2,182
T1046 Network Service DiscoveryA

Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.

securitypythongo
0
2,182
T1057 Process DiscoveryA

Adversaries may attempt to get information about running processes on a system.

securitygoshell
0
2,182
T1069.001 Local GroupsA

Adversaries may attempt to find local system groups and permission settings.

securitygoshell
0
2,182
T1069.002 Domain GroupsA

Adversaries may attempt to find domain-level groups and permission settings.

securitygoshell
0
2,182
T1069.003 Cloud GroupsA

Adversaries may attempt to find cloud groups and permission settings.

securitygoshell
0
2,182
T1069 Permission Groups DiscoveryA

Adversaries may attempt to discover group and permission settings.

securitygokubernetes
0
2,182
T1082 System Information DiscoveryA

An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.

securitygobash
0
2,182
T1083 File And Directory DiscoveryA

Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.

securitygoshell
0
2,182
T1087.001 Local AccountB

Adversaries may attempt to get a listing of local system accounts.

securitygobash
0
2,182
T1087.002 Domain AccountA

Adversaries may attempt to get a listing of domain accounts.

securitygoshell
0
2,182