
Claude Skills by CyberStrikeus
github.com/CyberStrikeusAdversaries may cause damage and destruction of property to infrastructure, equipment, and the surrounding environment when attacking control systems.
Adversaries may compromise safety system functions designed to maintain safe operation of a process when unacceptable or dangerous conditions occur.
Adversaries may steal operational information on a production environment as a direct mission outcome for personal gain or to inform future operations.
Adversaries may repetitively or successively change I/O point values to perform an action.
Adversaries may modify parameters used to instruct industrial control system devices.
Adversaries may send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, or without the logical preconditions to trigger thei...
Adversaries may activate firmware update mode on devices to prevent expected response functions from engaging in reaction to an emergency or process malfunction.
Adversaries may block a command message from reaching its intended target to prevent command execution.
Adversaries may block or prevent a reporting message from reaching its intended target.
Adversaries may block access to serial COM to prevent instructions or configurations from reaching target devices.
Adversaries may perform data destruction over the course of an operation.
Adversaries may perform Denial-of-Service (DoS) attacks to disrupt expected device functionality.
Adversaries may forcibly restart or shutdown a device in an ICS environment to disrupt and potentially negatively impact physical processes.
Adversaries may manipulate the I/O image of PLCs through various means to prevent them from functioning as expected.
Adversaries may modify alarm settings to prevent alerts that may inform operators of their presence or to prevent responses to dangerous and unintended scenarios.
Adversaries may target protection function alarms to prevent them from notifying operators of critical conditions.
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
Adversaries may modify software and device credentials to prevent operator and responder access.
Adversaries may gain access to a system during a drive-by compromise, when a user visits a website as part of a regular browsing session.
Adversaries may leverage weaknesses to exploit internet-facing software for initial access into an industrial network.
Adversaries may leverage external remote services as a point of initial access into your network.
Adversaries may move onto systems, such as those separated from the enterprise network, by copying malware to removable media which is inserted into the control systems environment.
Adversaries may setup a rogue master to leverage control server functions to communicate with outstations.
Adversaries may perform wireless compromise as a method of gaining communications and unauthorized access to a wireless network.
Adversaries may perform supply chain compromise to gain control systems environment access by means of infected products, software, and workflows.
Adversaries may target devices that are transient across ICS networks and external networks.
Adversaries may use a spearphishing attachment, a variant of spearphishing, as a form of a social engineering attack against specific targets.
Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service ab...
Adversaries may gain access into industrial environments through systems exposed directly to the internet for remote access rather than through External Remote Services.
Adversaries may leverage remote services to move between assets and network segments.
Adversaries may leverage manufacturer or supplier set default credentials on control system devices.
Adversaries may perform a program download to transfer a user program to a controller.
Adversaries may transfer tools or other files from one system to another to stage adversary tools or other files over the course of an operation.
Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset.
Adversaries may install malicious or vulnerable firmware onto modular hardware devices.
System firmware on modern assets is often designed with an update feature.
Adversaries may steal the credentials of a specific user or service account using credential access techniques.
Adversaries may attempt to infect project files with malicious code.
Adversaries may modify or add a program on a controller to affect how it interacts with the physical process, peripheral devices and other hosts on the network.
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Adversaries may gain access to mobile devices through transfers or swaps from victims’ phone numbers to adversary-controlled SIM cards and mobile devices.
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
Adversaries may move onto devices by exploiting or copying malware to devices connected via USB.
An adversary with physical access to a mobile device may seek to bypass the device’s lockscreen.
Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.
Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
Adversaries may send malicious content to users in order to gain access to their mobile devices.
An adversary may push an update to a previously benign application to add malicious code.