All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs318 views
T1114.003 Email Forwarding RuleA

Adversaries may setup email forwarding rules to collect sensitive information.

securitygotesting
0
291
T1114 Email CollectionA

Adversaries may target user email to collect sensitive information.

securityrustgo
0
291
T1115 Clipboard DataA

Adversaries may collect data stored in the clipboard from users copying information within or between applications.

securitygoruby
0
291
T1119 Automated CollectionA

Once established within a system or network, an adversary may use automated techniques for collecting internal data.

securitygoshell
0
291
T1123 Audio CaptureA

An adversary can leverage a computer's peripheral devices (e.g., microphones and webcams) or applications (e.g., voice and video call services) to capture audio recordings for the purpose of listen...

securitygoshell
0
291
T1125 Video CaptureA

An adversary can leverage a computer's peripheral devices (e.g., integrated cameras or webcams) or applications (e.g., video call services) to capture video recordings for the purpose of gathering ...

securitygotesting
0
291
T1185 Browser Session HijackingA

Adversaries may take advantage of security vulnerabilities and inherent functionality in browser software to change content, modify user-behaviors, and intercept information as part of various brow...

securitygotesting
0
291
T1213.001 ConfluenceA

Adversaries may leverage Confluence repositories to mine valuable information.

securitygotesting
0
291
T1213.002 SharepointA

Adversaries may leverage the SharePoint repository as a source to mine valuable information.

securitygotesting
0
291
T1213.003 Code RepositoriesA

Adversaries may leverage code repositories to collect valuable information.

securitygotesting
0
291
T1213.004 Customer Relationship Management SoftwareA

Adversaries may leverage Customer Relationship Management (CRM) software to mine valuable information.

securitygotesting
0
291
T1213.005 Messaging ApplicationsA

Adversaries may leverage chat and messaging applications, such as Microsoft Teams, Google Chat, and Slack, to mine valuable information.

securitygotesting
0
291
T1213.006 DatabasesA

Adversaries may leverage databases to mine valuable information.

securitygosql
0
291
T1213 Data From Information RepositoriesA

Adversaries may leverage information repositories to mine valuable information.

securitygoaws
0
291
T1530 Data From Cloud StorageA

Adversaries may access data from cloud storage.

securitygosql
0
291
T1560.001 Archive Via UtilityA

Adversaries may use utilities to compress and/or encrypt collected data prior to exfiltration.

securitygobash
0
291
T1560.002 Archive Via LibraryA

An adversary may compress or encrypt data that is collected prior to exfiltration using 3rd party libraries.

securitypythongo
0
291
T1560.003 Archive Via Custom MethodA

An adversary may compress or encrypt data that is collected prior to exfiltration using a custom method.

securitygotesting
0
291
T1560 Archive Collected DataA

An adversary may compress and/or encrypt data that is collected prior to exfiltration.

securitygoshell
0
291
T1602.001 Snmp Mib DumpA

Adversaries may target the Management Information Base (MIB) to collect and/or mine valuable information in a network managed using Simple Network Management Protocol (SNMP).

securityrustgo
0
291
T1602.002 Network Device Configuration DumpA

Adversaries may access network configuration files to collect sensitive data about the device and the network.

securityrustgo
0
291
T1602 Data From Configuration RepositoryA

Adversaries may collect data related to managed devices from configuration repositories.

securityrustgo
0
291
T1011.001 Exfiltration Over BluetoothA

Adversaries may attempt to exfiltrate data over Bluetooth rather than the command and control channel.

securitygotesting
0
291
T1011 Exfiltration Over Other Network MediumA

Adversaries may attempt to exfiltrate data over a different network medium than the command and control channel.

securitygotesting
0
291
T1020.001 Traffic DuplicationA

Adversaries may leverage traffic mirroring in order to automate data exfiltration over compromised infrastructure.

securitygoaws
0
291
T1020 Automated ExfiltrationA

Adversaries may exfiltrate data, such as sensitive documents, through the use of automated processing after being gathered during Collection.

securitygoshell
0
291
T1029 Scheduled TransferA

Adversaries may schedule data exfiltration to be performed only at certain times of day or at certain intervals.

securitygotesting
0
291
T1030 Data Transfer Size LimitsA

An adversary may exfiltrate data in fixed size chunks instead of whole files or limit packet sizes below certain thresholds.

securitygoshell
0
291
T1041 Exfiltration Over C2 ChannelA

Adversaries may steal data by exfiltrating it over an existing command and control channel.

securitygoshell
0
291
T1048.001 Exfiltration Over Symmetric Encrypted Non C2 ProtocolA

Adversaries may steal data by exfiltrating it over a symmetrically encrypted network protocol other than that of the existing command and control channel.

securitygotesting
0
291
T1048.002 Exfiltration Over Asymmetric Encrypted Non C2 ProtocolA

Adversaries may steal data by exfiltrating it over an asymmetrically encrypted network protocol other than that of the existing command and control channel.

securitygobash
0
291
T1048.003 Exfiltration Over Unencrypted Non C2 ProtocolA

Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.

securitypythongo
0
291
T1048 Exfiltration Over Alternative ProtocolB

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.

securitygoshell
0
291
T1052.001 Exfiltration Over UsbA

Adversaries may attempt to exfiltrate data over a USB connected physical device.

securitygotesting
0
291
T1052 Exfiltration Over Physical MediumA

Adversaries may attempt to exfiltrate data via a physical medium, such as a removable drive.

securitygotesting
0
291
T1537 Transfer Data To Cloud AccountA

Adversaries may exfiltrate data by transferring the data, including through sharing/syncing and creating backups of cloud environments, to another cloud account they control on the same service.

securityrustgo
0
291
T1567.001 Exfiltration To Code RepositoryA

Adversaries may exfiltrate data to a code repository rather than over their primary command and control channel.

securitygotesting
0
291
T1567.002 Exfiltration To Cloud StorageA

Adversaries may exfiltrate data to a cloud storage service rather than over their primary command and control channel.

securitygoshell
0
291
T1567.003 Exfiltration To Text Storage SitesA

Adversaries may exfiltrate data to text storage sites instead of their primary command and control channel.

securitygophp
0
291
T1567.004 Exfiltration Over WebhookA

Adversaries may exfiltrate data to a webhook endpoint rather than over their primary command and control channel.

securitygosql
0
291
T1567 Exfiltration Over Web ServiceA

Adversaries may use an existing, legitimate external Web service to exfiltrate data rather than their primary command and control channel.

securitygotesting
0
291
T1001.001 Junk DataA

Adversaries may add junk data to protocols used for command and control to make detection more difficult.

securitygotesting
0
291
T1001.002 SteganographyB

Adversaries may use steganographic techniques to hide command and control traffic to make detection efforts more difficult.

securitygoshell
0
291
T1001.003 Protocol Or Service ImpersonationA

Adversaries may impersonate legitimate protocols or web service traffic to disguise command and control activity and thwart analysis efforts.

securityrustgo
0
291
T1001 Data ObfuscationA

Adversaries may obfuscate command and control traffic to make it more difficult to detect.

securitygotesting
0
291
T1008 Fallback ChannelsA

Adversaries may use fallback or alternate communication channels if the primary channel is compromised or inaccessible in order to maintain reliable command and control and to avoid data transfer thre

securitygotesting
0
291
T1071.001 Web ProtocolsA

Adversaries may communicate using application layer protocols associated with web traffic to avoid detection/network filtering by blending in with existing traffic.

securitygoshell
0
291
T1071.002 File Transfer ProtocolsA

Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic.

securityrustgo
0
291
T1071.003 Mail ProtocolsA

Adversaries may communicate using application layer protocols associated with electronic mail delivery to avoid detection/network filtering by blending in with existing traffic.

securityrustgo
0
291
T1071.004 DnsA

Adversaries may communicate using the Domain Name System (DNS) application layer protocol to avoid detection/network filtering by blending in with existing traffic.

securityrustgo
0
291