All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs317 views
PR.AT 03 Prat 03A

Third-party stakeholders (e.g., suppliers, customers, partners) understand their roles and responsibilities

securitygoaws
0
291
PR.AT 04 Prat 04A

Senior executives understand their roles and responsibilities

securitygoaws
0
291
PR.AT 05 Prat 05A

Physical and cybersecurity personnel understand their roles and responsibilities

securitygoaws
0
291
PR.DS 01 Prds 01A

The confidentiality, integrity, and availability of data-at-rest are protected

securitygoaws
0
291
PR.DS 02 Prds 02A

The confidentiality, integrity, and availability of data-in-transit are protected

securitygoaws
0
291
PR.DS 03 Prds 03A

Assets are formally managed throughout removal, transfers, and disposition

securitygoaws
0
291
PR.DS 04 Prds 04A

Adequate capacity to ensure availability is maintained

securitygoaws
0
291
PR.DS 05 Prds 05A

Protections against data leaks are implemented

securitygoaws
0
291
PR.DS 06 Prds 06A

Integrity checking mechanisms are used to verify software, firmware, and information integrity

securitygoaws
0
291
PR.DS 07 Prds 07A

The development and testing environment(s) are separate from the production environment

securitygoaws
0
291
PR.DS 08 Prds 08A

Integrity checking mechanisms are used to verify hardware integrity

securitygoaws
0
291
PR.DS 10 Prds 10A

The confidentiality, integrity, and availability of data-in-use are protected

securitygoaws
0
291
PR.DS 11 Prds 11A

Backups of data are created, protected, maintained, and tested

securitygoaws
0
291
PR.IP 01 Prip 01A

A baseline configuration of information technology/industrial control systems is created and maintained incorporating security principles (e.g.

securitygoaws
0
291
PR.IP 02 Prip 02A

A System Development Life Cycle to manage systems is implemented

securitygoaws
0
291
PR.IP 03 Prip 03A

Configuration change control processes are in place

securitygoaws
0
291
PR.IP 04 Prip 04A

Backups of information are conducted, maintained, and tested

securitygoaws
0
291
PR.IP 05 Prip 05A

Policy and regulations regarding the physical operating environment for organizational assets are met

securitygoaws
0
291
PR.IP 06 Prip 06A

Data is destroyed according to policy

securitygoaws
0
291
PR.IP 07 Prip 07A

Protection processes are improved

securitygoaws
0
291
PR.IP 08 Prip 08A

Effectiveness of protection technologies is shared

securitygoaws
0
291
PR.IP 09 Prip 09A

Response plans (Incident Response and Business Continuity) and recovery plans (Incident Recovery and Disaster Recovery) are in place and managed

securitygoaws
0
291
PR.IP 10 Prip 10A

Response and recovery plans are tested

securitygoaws
0
291
PR.IP 11 Prip 11A

Cybersecurity is included in human resources practices (e.g., deprovisioning, personnel screening)

securitygoaws
0
291
PR.IP 12 Prip 12A

A vulnerability management plan is developed and implemented

securitygoaws
0
291
PR.IR 01 Prir 01A

Networks and environments are protected from unauthorized logical access and usage

securitygoaws
0
291
PR.IR 02 Prir 02A

The organization's technology assets are protected from environmental threats

securitygoaws
0
291
PR.IR 03 Prir 03A

Mechanisms are implemented to achieve resilience requirements in normal and adverse situations

securitygoaws
0
291
PR.IR 04 Prir 04A

Adequate resource capacity to ensure availability is maintained

securitygoaws
0
291
PR.MA 01 Prma 01A

Maintenance and repair of organizational assets are performed and logged, with approved and controlled tools

securitygoaws
0
291
PR.MA 02 Prma 02A

Remote maintenance of organizational assets is approved, logged, and performed in a manner that prevents unauthorized access

securitygoaws
0
291
T1534 Internal SpearphishingA

After they already have access to accounts or systems within the environment, adversaries may use internal spearphishing to gain access to additional information or compromise other users within th...

securityrustgo
0
291
T1563.001 Ssh HijackingA

Adversaries may hijack a legitimate user's SSH session to move laterally within an environment.

securityrustgo
0
291
T1563.002 Rdp HijackingA

Adversaries may hijack a legitimate user’s remote desktop session to move laterally within an environment.

securitygotesting
0
291
T1563 Remote Service Session HijackingA

Adversaries may take control of preexisting sessions with remote services to move laterally in an environment.

securitygotesting
0
291
T1570 Lateral Tool TransferA

Adversaries may transfer tools or other files between systems in a compromised environment.

securitygoshell
0
291
T1005 Data From Local SystemA

Adversaries may search local system sources, such as file systems, configuration files, local databases, virtual machine files, or process memory, to find files of interest and sensitive data prior...

securitygoshell
0
291
T1025 Data From Removable MediaA

Adversaries may search connected removable media on computers they have compromised to find files of interest.

securitygoshell
0
291
T1039 Data From Network Shared DriveA

Adversaries may search network shares on computers they have compromised to find files of interest.

securitygoshell
0
291
T1056.001 KeyloggingA

Adversaries may log user keystrokes to intercept credentials as the user types them.

securitygoshell
0
291
T1056.002 Gui Input CaptureA

Adversaries may mimic common operating system GUI components to prompt users for credentials with a seemingly legitimate prompt.

securityrustgo
0
291
T1056.003 Web Portal CaptureA

Adversaries may install code on externally facing portals, such as a VPN login page, to capture and transmit credentials of users who attempt to log into the service.

securitygotesting
0
291
T1056.004 Credential Api HookingA

Adversaries may hook into Windows application programming interface (API) functions and Linux system functions to collect user credentials.

securitygoshell
0
291
T1056 Input CaptureA

Adversaries may use methods of capturing user input to obtain credentials or collect information.

securitygotesting
0
291
T1074.001 Local Data StagingD

Adversaries may stage collected data in a central location or directory on the local system prior to Exfiltration.

securitygoshell
0
291
T1074.002 Remote Data StagingA

Adversaries may stage data collected from multiple systems in a central location or directory on one system prior to Exfiltration.

securitygoshell
0
291
T1074 Data StagedA

Adversaries may stage collected data in a central location or directory prior to Exfiltration.

securitygoshell
0
291
T1113 Screen CaptureA

Adversaries may attempt to take screen captures of the desktop to gather information over the course of an operation.

securitygobash
0
291
T1114.001 Local Email CollectionA

Adversaries may target user email on local systems to collect sensitive information.

securitygoshell
0
291
T1114.002 Remote Email CollectionA

Adversaries may target an Exchange server, Office 365, or Google Workspace to collect sensitive information.

securitygotesting
0
291