All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs318 views
T1071.005 Publishsubscribe ProtocolsA

Adversaries may communicate using publish/subscribe (pub/sub) application layer protocols to avoid detection/network filtering by blending in with existing traffic.

securityrustgo
0
291
T1071 Application Layer ProtocolA

Adversaries may communicate using OSI application layer protocols to avoid detection/network filtering by blending in with existing traffic.

securitygoshell
0
291
T1090.001 Internal ProxyA

Adversaries may use an internal proxy to direct command and control traffic between two or more systems in a compromised environment.

securityrustgo
0
291
T1090.002 External ProxyA

Adversaries may use an external proxy to act as an intermediary for network communications to a command and control server to avoid direct connections to their infrastructure.

securityrustgo
0
291
T1090.003 Multi Hop ProxyB

Adversaries may chain together multiple proxies to disguise the source of malicious traffic.

securitygoshell
0
291
T1090.004 Domain FrontingA

Adversaries may take advantage of routing schemes in Content Delivery Networks (CDNs) and other services which host multiple domains to obfuscate the intended destination of HTTPS traffic or traffi...

securitygotesting
0
291
T1090 ProxyA

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications to a command and control server to avoid direct connections to ...

securityrustgo
0
291
T1092 Communication Through Removable MediaA

Adversaries can perform command and control between compromised hosts on potentially disconnected networks using removable media to transfer commands from system to system.

securitygotesting
0
291
T1095 Non Application Layer ProtocolA

Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network.

securitypythongo
0
291
T1102.001 Dead Drop ResolverA

Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.

securitygotesting
0
291
T1102.002 Bidirectional CommunicationA

Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel.

securitygotesting
0
291
T1102.003 One Way CommunicationA

Adversaries may use an existing, legitimate external Web service as a means for sending commands to a compromised system without receiving return output over the Web service channel.

securitygotesting
0
291
T1102 Web ServiceA

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.

securitygotesting
0
291
T1104 Multi Stage ChannelsA

Adversaries may create multiple stages for command and control that are employed under different conditions or for certain functions.

securitygoshell
0
291
T1105 Ingress Tool TransferA

Adversaries may transfer tools or other files from an external system into a compromised environment.

securityrustgo
0
291
T1132.001 Standard EncodingA

Adversaries may encode data with a standard data encoding system to make the content of command and control traffic more difficult to detect.

securitygoshell
0
291
T1132.002 Non Standard EncodingA

Adversaries may encode data with a non-standard data encoding system to make the content of command and control traffic more difficult to detect.

securitygotesting
0
291
T1132 Data EncodingA

Adversaries may encode data to make the content of command and control traffic more difficult to detect.

securitygotesting
0
291
T1219.001 Ide TunnelingA

Adversaries may abuse Integrated Development Environment (IDE) software with remote development features to establish an interactive command and control channel on target systems within a network.

securitygoshell
0
291
T1219.002 Remote Desktop SoftwareA

An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks.

securitygotesting
0
291
T1219.003 Remote Access HardwareA

An adversary may use legitimate remote access hardware to establish an interactive command and control channel to target systems within networks.

securitygotesting
0
291
T1219 Remote Access ToolsA

An adversary may use legitimate remote access tools to establish an interactive command and control channel within a network.

securityrustgo
0
291
T1568.001 Fast Flux DnsA

Adversaries may use Fast Flux DNS to hide a command and control channel behind an array of rapidly changing IP addresses linked to a single domain resolution.

securitygotesting
0
291
T1568.002 Domain Generation AlgorithmsA

Adversaries may make use of Domain Generation Algorithms (DGAs) to dynamically identify a destination domain for command and control traffic rather than relying on a list of static IP addresses or ...

securitygotesting
0
291
T1568.003 Dns CalculationA

Adversaries may perform calculations on addresses returned in DNS results to determine which port and IP address to use for command and control, rather than relying on a predetermined port number o...

securitygotesting
0
291
T1568 Dynamic ResolutionA

Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.

securitygotesting
0
291
T1571 Non Standard PortA

Adversaries may communicate using a protocol and port pairing that are typically not associated.

securitygoshell
0
291
T1572 Protocol TunnelingA

Adversaries may tunnel network communications to and from a victim system within a separate protocol to avoid detection/network filtering and/or enable access to otherwise unreachable systems.

securityrustgo
0
291
T1573.001 Symmetric CryptographyA

Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.

securitygotesting
0
291
T1573.002 Asymmetric CryptographyA

Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.

securitygotesting
0
291
T1573 Encrypted ChannelA

Adversaries may employ an encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.

securitygoshell
0
291
T1665 Hide InfrastructureA

Adversaries may manipulate network traffic in order to hide and evade detection of their C2 infrastructure.

securityrustgo
0
291
T1485.001 Lifecycle Triggered DeletionA

Adversaries may modify the lifecycle policies of a cloud storage bucket to destroy all objects stored within.

securitygoaws
0
291
T1485 Data DestructionA

Adversaries may destroy data and files on specific systems or in large numbers on a network to interrupt availability to systems, services, and network resources.

securitygoshell
0
291
T1486 Data Encrypted For ImpactA

Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.

securitygobash
0
291
T1489 Service StopA

Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.

securitygobash
0
291
T1490 Inhibit System RecoveryA

Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.

securitygoshell
0
291
T1491.001 Internal DefacementA

An adversary may deface systems internal to an organization in an attempt to intimidate or mislead users, thus discrediting the integrity of the systems.

securitygoshell
0
291
T1491.002 External DefacementA

An adversary may deface systems external to an organization in an attempt to deliver messaging, intimidate, or otherwise mislead an organization or users.

securityrustgo
0
291
T1491 DefacementA

Adversaries may modify visual content available internally or externally to an enterprise network, thus affecting the integrity of the original content.

securitygotesting
0
291
T1495 Firmware CorruptionA

Adversaries may overwrite or corrupt the flash memory contents of system BIOS or other firmware in devices attached to a system in order to render them inoperable or unable to boot, thus denying th...

securityrustgo
0
291
T1496.001 Compute HijackingA

Adversaries may leverage the compute resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

securitygodocker
0
291
T1496.002 Bandwidth HijackingA

Adversaries may leverage the network bandwidth resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

securitygotesting
0
291
T1496.003 Sms PumpingA

Adversaries may leverage messaging services for SMS pumping, which may impact system and/or hosted service availability.

securitygoaws
0
291
T1496.004 Cloud Service HijackingA

Adversaries may leverage compromised software-as-a-service (SaaS) applications to complete resource-intensive tasks, which may impact hosted service availability.

securitygoaws
0
291
T1496 Resource HijackingA

Adversaries may leverage the resources of co-opted systems to complete resource-intensive tasks, which may impact system and/or hosted service availability.

securitygoshell
0
291
T1498.001 Direct Network FloodA

Adversaries may attempt to cause a denial of service (DoS) by directly sending a high-volume of network traffic to a target.

securitygotesting
0
291
T1498.002 Reflection AmplificationA

Adversaries may attempt to cause a denial of service (DoS) by reflecting a high-volume of network traffic to a target.

securitygotesting
0
291
T1498 Network Denial Of ServiceA

Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users.

securitygotesting
0
291
T1499.001 Os Exhaustion FloodA

Adversaries may launch a denial of service (DoS) attack targeting an endpoint's operating system (OS).

securitygotesting
0
291