All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs317 views
T1597 Search Closed SourcesA

Adversaries may search and gather information about victims from closed (e.g., paid, private, or otherwise not freely available) sources that can be used during targeting.

securitygotesting
0
291
T1598.001 Spearphishing ServiceA

Adversaries may send spearphishing messages via third-party services to elicit sensitive information that can be used during targeting.

securitygotesting
0
291
T1598.002 Spearphishing AttachmentA

Adversaries may send spearphishing messages with a malicious attachment to elicit sensitive information that can be used during targeting.

securitygotesting
0
291
T1598.003 Spearphishing LinkA

Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting.

securitygotesting
0
291
T1598.004 Spearphishing VoiceA

Adversaries may use voice communications to elicit sensitive information that can be used during targeting.

securityrustgo
0
291
T1598 Phishing For InformationA

Adversaries may send phishing messages to elicit sensitive information that can be used during targeting.

securitygotesting
0
291
T1681 Search Threat Vendor DataA

Threat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by other adversaries that may align with...

securitygotesting
0
291
T0801 Monitor Process StateA

Adversaries may gather information about the physical process state.

securitygo
0
291
T0802 Automated CollectionA

Adversaries may automate collection of industrial environment information using tools or scripts.

securitygo
0
291
T0811 Data From Information RepositoriesA

Adversaries may target and collect data from information repositories.

securitygodatabase
0
291
T0830 Adversary In The MiddleA

Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks.

securitygo
0
291
T0845 Program UploadA

Adversaries may attempt to upload a program from a PLC to gather information about an industrial process.

securitygo
0
291
T0852 Screen CaptureA

Adversaries may attempt to perform screen capture of devices in the control system environment.

securitygoapi
0
291
T0861 Point Tag IdentificationA

Adversaries may collect point and tag values to gain a more comprehensive understanding of the process environment.

securitygogit
0
291
T0868 Detect Operating ModeA

Adversaries may gather information about a PLCs or controllers current operating mode.

securitygodebugging
0
291
T0877 Io ImageA

Adversaries may seek to capture process values related to the inputs and outputs of a PLC.

securitygoapi
0
291
T0893 Data From Local SystemA

Adversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases.

securitygodatabase
0
291
T0869 Standard Application Layer ProtocolA

Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus.

securitygo
0
291
T0884 Connection ProxyA

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications.

securityrustgo
0
291
T0885 Commonly Used PortA

Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection.

securitygo
0
291
T0840 Network Connection EnumerationA

Adversaries may perform network connection enumeration to discover information about device communication patterns.

securitygo
0
291
T0842 Network SniffingA

Network sniffing is the practice of using a network interface on a computer system to monitor or capture information regardless of whether it is the specified destination for the information.

securitygo
0
291
T0846 Remote System DiscoveryA

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for subsequent Lateral Movement or Discovery techniques.

securitygo
0
291
T0887 Wireless SniffingA

Adversaries may seek to capture radio frequency (RF) communication used for remote control and reporting in distributed environments.

securitygo
0
291
T0888 Remote System Information DiscoveryA

An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration.

securitygoapi
0
291
T0820 Exploitation For EvasionA

Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection.

securitygosecurity
0
291
T0849 MasqueradingA

Adversaries may use masquerading to disguise a malicious application or executable as another file, to avoid operator and engineer suspicion.

securitygogit
0
291
T0851 RootkitA

Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.

securitygogit
0
291
T0856 Spoof Reporting MessageA

Adversaries may spoof reporting messages in control system environments for evasion and to impair process control.

securitygogit
0
291
T0872 Indicator Removal On HostA

Adversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks.

securitygo
0
291
T0894 System Binary Proxy ExecutionA

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.

securityrustgo
0
291
T0807 Command Line InterfaceA

Adversaries may utilize command-line interfaces (CLIs) to interact with systems and execute commands.

securitygo
0
291
T0821 Modify Controller TaskingA

Adversaries may modify the tasking of a controller to allow for the execution of their own programs.

securitygo
0
291
T0823 Graphical User InterfaceA

Adversaries may attempt to gain access to a machine via a Graphical User Interface (GUI) to enhance execution capabilities.

securitygo
0
291
T0834 Native ApiA

Adversaries may directly interact with the native OS application programming interface (API) to access system functions.

securitygoapi
0
291
T0853 ScriptingA

Adversaries may use scripting languages to execute arbitrary code in the form of a pre-written script or in the form of user-supplied code to an interpreter.

securitypythongo
0
291
T0858 Change Operating ModeA

Adversaries may change the operating mode of a controller to gain additional access to engineering functions such as Program Download.

securitygodebugging
0
291
T0863 User ExecutionA

Adversaries may rely on a targeted organizations user interaction for the execution of malicious code.

securitygo
0
291
T0871 Execution Through ApiA

Adversaries may attempt to leverage Application Program Interfaces (APIs) used for communication between control software and the hardware.

securitygoapi
0
291
T0874 HookingA

Adversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means.

securityrustgo
0
291
T0895 Autorun ImageA

Adversaries may leverage AutoRun functionality or scripts to execute malicious code.

securitygo
0
291
T0813 Denial Of ControlA

Adversaries may cause a denial of control to temporarily prevent operators and engineers from interacting with process controls.

securitygo
0
291
T0815 Denial Of ViewA

Adversaries may cause a denial of view in attempt to disrupt and prevent operator oversight on the status of an ICS environment.

securitygo
0
291
T0826 Loss Of AvailabilityA

Adversaries may attempt to disrupt essential components or systems to prevent owner and operator from delivering products or services.

securitygodatabase
0
291
T0827 Loss Of ControlA

Adversaries may seek to achieve a sustained loss of control or a runaway condition in which operators cannot issue any commands even if the malicious interference has subsided.

securitygosecurity
0
291
T0828 Loss Of Productivity And RevenueA

Adversaries may cause loss of productivity and revenue through disruption and even damage to the availability and integrity of control system operations, devices, and related processes.

securitygosecurity
0
291
T0829 Loss Of ViewA

Adversaries may cause a sustained or permanent loss of view where the ICS equipment will require local, hands-on operator intervention; for instance, a restart or manual operation.

securitygo
0
291
T0831 Manipulation Of ControlA

Adversaries may manipulate physical process control within the industrial environment.

securitygoshell
0
291
T0832 Manipulation Of ViewA

Adversaries may attempt to manipulate the information reported back to operators or controllers.

securitygogit
0
291
T0837 Loss Of ProtectionA

Adversaries may compromise protective system functions designed to prevent the effects of faults and abnormal conditions.

securitygoreact
0
291