All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
7,689 skillsA× 7,295B× 380C× 7D× 3F× 40 installs16,675 views
T1087.003 Email AccountA

Adversaries may attempt to get a listing of email addresses and accounts.

securitygoshell
0
2,182
T1087.004 Cloud AccountA

Adversaries may attempt to get a listing of cloud accounts.

securitygoshell
0
2,182
T1087 Account DiscoveryA

Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment.

securitygoshell
0
2,182
T1120 Peripheral Device DiscoveryA

Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.

securitygoshell
0
2,182
T1124 System Time DiscoveryA

An adversary may gather the system time and/or time zone settings from a local or remote system.

securitygoshell
0
2,182
T1135 Network Share DiscoveryA

Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of in...

securitygoshell
0
2,182
T1201 Password Policy DiscoveryA

Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment.

securitygoshell
0
2,182
T1217 Browser Information DiscoveryA

Adversaries may enumerate information about browsers to learn more about compromised environments.

securitygoshell
0
2,182
T1482 Domain Trust DiscoveryA

Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.

securityrustgo
0
2,182
T1518.001 Security Software DiscoveryA

Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.

securitygoshell
0
2,182
T1518.002 Backup Software DiscoveryA

Adversaries may attempt to get a listing of backup software or configurations that are installed on a system.

securitygotesting
0
2,182
T1518 Software DiscoveryA

Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment.

securitygoshell
0
2,182
T1526 Cloud Service DiscoveryA

An adversary may attempt to enumerate the cloud services running on a system after gaining access.

securitygoaws
0
2,182
T1538 Cloud Service DashboardA

An adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment, such as specific services, resources, and features.

securitygoaws
0
2,182
T1580 Cloud Infrastructure DiscoveryA

An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment.

securitygoaws
0
2,182
T1613 Container And Resource DiscoveryA

Adversaries may attempt to discover containers and other resources that are available within a containers environment.

securitygobash
0
2,182
T1614.001 System Language DiscoveryA

Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.

securitygobash
0
2,182
T1614 System Location DiscoveryA

Adversaries may gather information in an attempt to calculate the geographical location of a victim host.

securitygobash
0
2,182
T1615 Group Policy DiscoveryA

Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that ca...

securitygoshell
0
2,182
T1619 Cloud Storage Object DiscoveryA

Adversaries may enumerate objects in cloud storage infrastructure.

securitygoaws
0
2,182
T1652 Device Driver DiscoveryA

Adversaries may attempt to enumerate local device drivers on a victim host.

securitygoshell
0
2,182
T1654 Log EnumerationA

Adversaries may enumerate system and service logs to find useful data.

securitygoshell
0
2,182
T1673 Virtual Machine DiscoveryA

An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor.

securitygotesting
0
2,182
T1680 Local Storage DiscoveryA

Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.

securitygoshell
0
2,182
T1016 System Network ConfigurationA

Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.

securityrustgo
0
2,182
T1049 System Network ConnectionsA

Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.

securitygoshell
0
2,182
T1021.001 Remote Desktop ProtocolA

Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).

securitygoshell
0
2,182
T1021.002 Smbwindows Admin SharesA

Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).

securitygoshell
0
2,182
T1021.004 SshA

Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH).

securitygoshell
0
2,182
T1021.005 VncA

Adversaries may use Valid Accounts to remotely control machines using Virtual Network Computing (VNC).

securitygoc#
0
2,182
T1021.006 Windows Remote ManagementA

Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM).

securitygoruby
0
2,182
T1021.007 Cloud ServicesA

Adversaries may log into accessible cloud services within a compromised environment using Valid Accounts that are synchronized with or federated to on-premises user identities.

securitygoshell
0
2,182
T1021.008 Direct Cloud Vm ConnectionsA

Adversaries may leverage Valid Accounts to log directly into accessible cloud hosted compute infrastructure through cloud native methods.

securitygoaws
0
2,182
T1021 Remote ServicesA

Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC.

securitygoshell
0
2,182
T1080 Taint Shared ContentA

Adversaries may deliver payloads to remote systems by adding content to shared storage locations, such as network drives or internal code repositories.

securitygotesting
0
2,182
T1210 Exploitation Of Remote ServicesA

Adversaries may exploit remote services to gain unauthorized access to internal systems once inside of a network.

securitygosql
0
2,182
T1021 003 Distributed Component ObjectA

Adversaries may use Valid Accounts to interact with remote machines by taking advantage of Distributed Component Object Model (DCOM).

securitygoshell
0
2,182
T1091 Replication Through RemovableA

Adversaries may move onto systems, possibly those on disconnected or air-gapped networks, by copying malware to removable media and taking advantage of Autorun features when the media is inserted i...

securityrustgo
0
2,182
Windows PostexploitB

Windows post-exploitation — Active Directory attacks, Kerberos exploitation, ADCS abuse, lateral movement, persistence, privilege escalation, credential harvesting, stealth encoding (Base64/AMSI/obfuscate), and pwsh.exe support

securityrustgo
0
2,182