
Claude Skills by CyberStrikeus
github.com/CyberStrikeusAdversaries may search and gather information about victims from closed (e.g., paid, private, or otherwise not freely available) sources that can be used during targeting.
Adversaries may send spearphishing messages via third-party services to elicit sensitive information that can be used during targeting.
Adversaries may send spearphishing messages with a malicious attachment to elicit sensitive information that can be used during targeting.
Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting.
Adversaries may use voice communications to elicit sensitive information that can be used during targeting.
Adversaries may send phishing messages to elicit sensitive information that can be used during targeting.
Threat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by other adversaries that may align with...
Adversaries may gather information about the physical process state.
Adversaries may automate collection of industrial environment information using tools or scripts.
Adversaries may target and collect data from information repositories.
Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks.
Adversaries may attempt to upload a program from a PLC to gather information about an industrial process.
Adversaries may attempt to perform screen capture of devices in the control system environment.
Adversaries may collect point and tag values to gain a more comprehensive understanding of the process environment.
Adversaries may gather information about a PLCs or controllers current operating mode.
Adversaries may seek to capture process values related to the inputs and outputs of a PLC.
Adversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases.
Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus.
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications.
Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection.
Adversaries may perform network connection enumeration to discover information about device communication patterns.
Network sniffing is the practice of using a network interface on a computer system to monitor or capture information regardless of whether it is the specified destination for the information.
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for subsequent Lateral Movement or Discovery techniques.
Adversaries may seek to capture radio frequency (RF) communication used for remote control and reporting in distributed environments.
An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration.
Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection.
Adversaries may use masquerading to disguise a malicious application or executable as another file, to avoid operator and engineer suspicion.
Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
Adversaries may spoof reporting messages in control system environments for evasion and to impair process control.
Adversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks.
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
Adversaries may utilize command-line interfaces (CLIs) to interact with systems and execute commands.
Adversaries may modify the tasking of a controller to allow for the execution of their own programs.
Adversaries may attempt to gain access to a machine via a Graphical User Interface (GUI) to enhance execution capabilities.
Adversaries may directly interact with the native OS application programming interface (API) to access system functions.
Adversaries may use scripting languages to execute arbitrary code in the form of a pre-written script or in the form of user-supplied code to an interpreter.
Adversaries may change the operating mode of a controller to gain additional access to engineering functions such as Program Download.
Adversaries may rely on a targeted organizations user interaction for the execution of malicious code.
Adversaries may attempt to leverage Application Program Interfaces (APIs) used for communication between control software and the hardware.
Adversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means.
Adversaries may leverage AutoRun functionality or scripts to execute malicious code.
Adversaries may cause a denial of control to temporarily prevent operators and engineers from interacting with process controls.
Adversaries may cause a denial of view in attempt to disrupt and prevent operator oversight on the status of an ICS environment.
Adversaries may attempt to disrupt essential components or systems to prevent owner and operator from delivering products or services.
Adversaries may seek to achieve a sustained loss of control or a runaway condition in which operators cannot issue any commands even if the malicious interference has subsided.
Adversaries may cause loss of productivity and revenue through disruption and even damage to the availability and integrity of control system operations, devices, and related processes.
Adversaries may cause a sustained or permanent loss of view where the ICS equipment will require local, hands-on operator intervention; for instance, a restart or manual operation.
Adversaries may manipulate physical process control within the industrial environment.
Adversaries may attempt to manipulate the information reported back to operators or controllers.
Adversaries may compromise protective system functions designed to prevent the effects of faults and abnormal conditions.