
Claude Skills by CyberStrikeus
github.com/CyberStrikeusThird-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities
Senior executives understand their roles and responsibilities
Physical and cybersecurity personnel understand their roles and responsibilities
The confidentiality, integrity, and availability of data-at-rest are protected
The confidentiality, integrity, and availability of data-in-transit are protected
Assets are formally managed throughout removal, transfers, and disposition
Adequate capacity to ensure availability is maintained
Protections against data leaks are implemented
Integrity checking mechanisms are used to verify software, firmware, and information integrity
The development and testing environment(s) are separate from the production environment
Integrity checking mechanisms are used to verify hardware integrity
The confidentiality, integrity, and availability of data-in-use are protected
Backups of data are created, protected, maintained, and tested
A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g.
A System Development Life Cycle to manage systems is implemented
Configuration change control processes are in place
Backups of information are conducted, maintained, and tested
Policy and regulations regarding the physical operating environment for organizational assets are met
Data is destroyed according to policy
Protection processes are improved
Effectiveness of protection technologies is shared
Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed
Response and recovery plans are tested
Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening)
A vulnerability management plan is developed and implemented
Networks and environments are protected from unauthorized logical access and usage
The organization's technology assets are protected from environmental threats
Mechanisms are implemented to achieve resilience requirements in normal and adverse situations
Adequate resource capacity to ensure availability is maintained
Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools
Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access
After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within th...
Adversaries may hijack a legitimate user's SSH session to move laterally within an environment.
Adversaries may hijack a legitimate user’s remote desktop session to move laterally within an environment.
Adversaries may take control of preexisting sessions with remote services to move laterally in an environment.
Adversaries may transfer tools or other files between systems in a compromised environment.
Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior...
Adversaries may search connected removable media on computers they have compromised to find files of interest.
Adversaries may search network shares on computers they have compromised to find files of interest.
Adversaries may log user keystrokes to intercept credentials as the user types them.
Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt.
Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service.
Adversaries may hook into Windows application programming interface (API) functions and Linux system functions to collect user credentials.
Adversaries may use methods of capturing user input to obtain credentials or collect information.
Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration.
Adversaries may stage data collected from multiple systems in a central location or directory on one system prior to Exfiltration.
Adversaries may stage collected data in a central location or directory prior to Exfiltration.
Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation.
Adversaries may target user email on local systems to collect sensitive information.
Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information.