All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs317 views
T0879 Damage To PropertyA

Adversaries may cause damage and destruction of property to infrastructure, equipment, and the surrounding environment when attacking control systems.

securitygoshell
0
291
T0880 Loss Of SafetyA

Adversaries may compromise safety system functions designed to maintain safe operation of a process when unacceptable or dangerous conditions occur.

securitygoreact
0
291
T0882 Theft Of Operational InformationA

Adversaries may steal operational information on a production environment as a direct mission outcome for personal gain or to inform future operations.

securitygodatabase
0
291
T0806 Brute Force IoA

Adversaries may repetitively or successively change I/O point values to perform an action.

securitygo
0
291
T0836 Modify ParameterA

Adversaries may modify parameters used to instruct industrial control system devices.

securitygo
0
291
T0855 Unauthorized Command MessageA

Adversaries may send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, or without the logical preconditions to trigger thei...

securitygogit
0
291
T0800 Activate Firmware Update ModeA

Adversaries may activate firmware update mode on devices to prevent expected response functions from engaging in reaction to an emergency or process malfunction.

securitygoreact
0
291
T0803 Block Command MessageA

Adversaries may block a command message from reaching its intended target to prevent command execution.

securitygo
0
291
T0804 Block Reporting MessageA

Adversaries may block or prevent a reporting message from reaching its intended target.

securitygo
0
291
T0805 Block Serial ComA

Adversaries may block access to serial COM to prevent instructions or configurations from reaching target devices.

securitygo
0
291
T0809 Data DestructionA

Adversaries may perform data destruction over the course of an operation.

securitygo
0
291
T0814 Denial Of ServiceA

Adversaries may perform Denial-of-Service (DoS) attacks to disrupt expected device functionality.

securitygoreact
0
291
T0816 Device RestartshutdownA

Adversaries may forcibly restart or shutdown a device in an ICS environment to disrupt and potentially negatively impact physical processes.

securitygogit
0
291
T0835 Manipulate Io ImageA

Adversaries may manipulate the I/O image of PLCs through various means to prevent them from functioning as expected.

securitygotesting
0
291
T0838 Modify Alarm SettingsA

Adversaries may modify alarm settings to prevent alerts that may inform operators of their presence or to prevent responses to dangerous and unintended scenarios.

securitygo
0
291
T0878 Alarm SuppressionA

Adversaries may target protection function alarms to prevent them from notifying operators of critical conditions.

securitygo
0
291
T0881 Service StopA

Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.

securitygogit
0
291
T0892 Change CredentialA

Adversaries may modify software and device credentials to prevent operator and responder access.

securitygo
0
291
T0817 Drive By CompromiseA

Adversaries may gain access to a system during a drive-by compromise, when a user visits a website as part of a regular browsing session.

securityjavascriptrust
0
291
T0819 Exploit Public Facing ApplicationA

Adversaries may leverage weaknesses to exploit internet-facing software for initial access into an industrial network.

securitygoapi
0
291
T0822 External Remote ServicesA

Adversaries may leverage external remote services as a point of initial access into your network.

securityrustgo
0
291
T0847 Replication Through Removable MediaA

Adversaries may move onto systems, such as those separated from the enterprise network, by copying malware to removable media which is inserted into the control systems environment.

securityrustgo
0
291
T0848 Rogue MasterA

Adversaries may setup a rogue master to leverage control server functions to communicate with outstations.

securitygogit
0
291
T0860 Wireless CompromiseA

Adversaries may perform wireless compromise as a method of gaining communications and unauthorized access to a wireless network.

securitygoshell
0
291
T0862 Supply Chain CompromiseA

Adversaries may perform supply chain compromise to gain control systems environment access by means of infected products, software, and workflows.

securityrustgo
0
291
T0864 Transient Cyber AssetA

Adversaries may target devices that are transient across ICS networks and external networks.

securityrustgo
0
291
T0865 Spearphishing AttachmentA

Adversaries may use a spearphishing attachment, a variant of spearphishing, as a form of a social engineering attack against specific targets.

securitygo
0
291
T0866 Exploitation Of Remote ServicesA

Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service ab...

securitygosecurity
0
291
T0883 Internet Accessible DeviceA

Adversaries may gain access into industrial environments through systems exposed directly to the internet for remote access rather than through External Remote Services.

securitygo
0
291
T0886 Remote ServicesA

Adversaries may leverage remote services to move between assets and network segments.

securitygo
0
291
T0812 Default CredentialsA

Adversaries may leverage manufacturer or supplier set default credentials on control system devices.

securitygosecurity
0
291
T0843 Program DownloadA

Adversaries may perform a program download to transfer a user program to a controller.

securitygoapi
0
291
T0867 Lateral Tool TransferA

Adversaries may transfer tools or other files from one system to another to stage adversary tools or other files over the course of an operation.

securitygo
0
291
T0891 Hardcoded CredentialsA

Adversaries may leverage credentials that are hardcoded in software or firmware to gain an unauthorized interactive user session to an asset.

securitygoapi
0
291
T0839 Module FirmwareA

Adversaries may install malicious or vulnerable firmware onto modular hardware devices.

securityrustgo
0
291
T0857 System FirmwareA

System firmware on modern assets is often designed with an update feature.

securityrustgo
0
291
T0859 Valid AccountsA

Adversaries may steal the credentials of a specific user or service account using credential access techniques.

securitygogit
0
291
T0873 Project File InfectionA

Adversaries may attempt to infect project files with malicious code.

securityrustgo
0
291
T0889 Modify ProgramA

Adversaries may modify or add a program on a controller to affect how it interacts with the physical process, peripheral devices and other hosts on the network.

securitygoapi
0
291
T0890 Exploitation For Privilege EscalationA

Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.

securitygosecurity
0
291
T1451 Sim Card SwapA

Adversaries may gain access to mobile devices through transfers or swaps from victims’ phone numbers to adversary-controlled SIM cards and mobile devices.

securitygosecurity
0
291
T1456 Drive By CompromiseA

Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.

securityjavascriptgo
0
291
T1458 Replication Through Removable MediaA

Adversaries may move onto devices by exploiting or copying malware to devices connected via USB.

securityrustgo
0
291
T1461 Lockscreen BypassA

An adversary with physical access to a mobile device may seek to bypass the device’s lockscreen.

securitygosecurity
0
291
T1474.001 Compromise Software Dependencies And Development ToolsA

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

securitygo
0
291
T1474.002 Compromise Hardware Supply ChainA

Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.

securitygosecurity
0
291
T1474.003 Compromise Software Supply ChainA

Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.

securitygosecurity
0
291
T1474 Supply Chain CompromiseA

Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.

securitygogit
0
291
T1660 PhishingA

Adversaries may send malicious content to users in order to gain access to their mobile devices.

securityrustgo
0
291
T1661 Application VersioningA

An adversary may push an update to a previously benign application to add malicious code.

securityrustgo
0
291