All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs317 views
T1664 Exploitation For Initial AccessA

Adversaries may exploit software vulnerabilities to gain initial access to a mobile device.

securitygosecurity
0
291
T1398 Boot Or Logon Initialization ScriptsA

Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence.

securitygosecurity
0
291
T1577 Compromise Application ExecutableA

Adversaries may modify applications installed on a device to establish persistent access to a victim.

securitygogit
0
291
T1624.001 Broadcast ReceiversA

Adversaries may establish persistence using system mechanisms that trigger execution based on specific events.

securitygoapi
0
291
T1624 Event Triggered ExecutionA

Adversaries may establish persistence using system mechanisms that trigger execution based on specific events.

securitygo
0
291
T1625.001 System Runtime Api HijackingA

Adversaries may execute their own malicious payloads by hijacking the way an operating system runs applications.

securitygoapi
0
291
T1625 Hijack Execution FlowA

Adversaries may execute their own malicious payloads by hijacking the way operating systems run applications.

securitygo
0
291
T1645 Compromise Client Software BinaryA

Adversaries may modify system software binaries to establish persistent access to devices.

securitygosecurity
0
291
T1404 Exploitation For Privilege EscalationA

Adversaries may exploit software vulnerabilities in order to elevate privileges.

securitygosecurity
0
291
T1626.001 Device Administrator PermissionsA

Adversaries may abuse Android’s device administration API to obtain a higher degree of control over the device.

securitygoapi
0
291
T1626 Abuse Elevation Control MechanismA

Adversaries may circumvent mechanisms designed to control elevated privileges to gain higher-level permissions.

securitygo
0
291
T1406.001 SteganographyA

Adversaries may use steganography techniques in order to prevent the detection of hidden information.

securitygogit
0
291
T1406.002 Software PackingA

Adversaries may perform software packing to conceal their code.

securitygo
0
291
T1406 Obfuscated Files Or InformationA

Adversaries may attempt to make a payload or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the device or in transit.

securitygosecurity
0
291
T1407 Download New Code At RuntimeA

Adversaries may download and execute dynamic code not included in the original application package after installation.

securityjavascriptgo
0
291
T1516 Input InjectionA

A malicious application can inject input to the user interface to mimic user interaction through the abuse of Android's accessibility APIs.

securitygogit
0
291
T1541 Foreground PersistenceA

Adversaries may abuse Android's `startForeground()` API method to maintain continuous sensor access.

securitygoapi
0
291
T1575 Native ApiA

Adversaries may use Android’s Native Development Kit (NDK) to write native functions that can achieve execution of binaries or functions.

securitygojava
0
291
T1604 Proxy Through VictimA

Adversaries may use a compromised device as a proxy server to the Internet.

securitygogit
0
291
T1617 HookingA

Adversaries may utilize hooking to hide the presence of artifacts associated with their behaviors to evade detection.

securitygoapi
0
291
T1627.001 GeofencingA

Adversaries may use a device’s geographical location to limit certain malicious behaviors.

securitygoapi
0
291
T1627 Execution GuardrailsA

Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.

securitygorails
0
291
T1628.001 Suppress Application IconA

A malicious application could suppress its icon from being displayed to the user in the application launcher.

securitygokotlin
0
291
T1628.002 User EvasionA

Adversaries may attempt to avoid detection by hiding malicious behavior from the user.

securitygosecurity
0
291
T1628.003 Conceal Multimedia FilesA

Adversaries may attempt to hide multimedia files from the user.

securitygogit
0
291
T1628 Hide ArtifactsA

Adversaries may attempt to hide artifacts associated with their behaviors to evade detection.

securitygogit
0
291
T1629.001 Prevent Application RemovalA

Adversaries may abuse the Android device administration API to prevent the user from uninstalling a target application.

securitygoapi
0
291
T1629.002 Device LockoutA

An adversary may seek to inhibit user interaction by locking the legitimate user out of the device.

securitygojava
0
291
T1629.003 Disable Or Modify ToolsA

Adversaries may disable security tools to avoid potential detection of their tools and activities.

securitygosecurity
0
291
T1629 Impair DefensesA

Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms.

securitygosecurity
0
291
T1630.001 Uninstall Malicious ApplicationA

Adversaries may include functionality in malware that uninstalls the malicious application from the device.

securitygoapi
0
291
T1630.002 File DeletionA

Adversaries may wipe a device or delete individual files in order to manipulate external outcomes or hide activity.

securitygodatabase
0
291
T1630.003 Disguise Rootjailbreak IndicatorsA

An adversary could use knowledge of the techniques used by security software to evade detection.

securitygosecurity
0
291
T1630 Indicator Removal On HostA

Adversaries may delete, alter, or hide generated artifacts on a device, including files, jailbreak status, or the malicious application itself.

securitygosecurity
0
291
T1631.001 Ptrace System CallsA

Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.

securitygodebugging
0
291
T1631 Process InjectionA

Adversaries may inject code into processes in order to evade process-based defenses or even elevate privileges.

securitygogit
0
291
T1632.001 Code Signing Policy ModificationA

Adversaries may modify code signing policies to enable execution of applications signed with unofficial or unknown keys.

securityrustgo
0
291
T1632 Subvert Trust ControlsA

Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted applications.

securityrustgo
0
291
T1633.001 System ChecksA

Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.

securitygo
0
291
T1633 Virtualizationsandbox EvasionA

Adversaries may employ various means to detect and avoid virtualization and analysis environments.

securitygogit
0
291
T1655.001 Match Legitimate Name Or LocationA

Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them.

securityrustgo
0
291
T1655 MasqueradingA

Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.

securitygogit
0
291
T1670 Virtualization SolutionA

Adversaries may carry out malicious operations using virtualization solutions to escape from Android sandboxes and to avoid detection.

securitygogit
0
291
T1417.002 Gui Input CaptureA

Adversaries may mimic common operating system GUI components to prompt users for sensitive information with a seemingly legitimate prompt.

securitygogit
0
291
T1634.001 KeychainA

Adversaries may collect keychain data from an iOS device to acquire credentials.

securitygoapi
0
291
T1634 Credentials From Password StoreA

Adversaries may search common password storage locations to obtain user credentials.

securitygosecurity
0
291
T1635.001 Uri HijackingA

Adversaries may register Uniform Resource Identifiers (URIs) to intercept sensitive data.

securitygosecurity
0
291
T1635 Steal Application Access TokenA

Adversaries can steal user application access tokens as a means of acquiring credentials to access remote systems and resources.

securitygoazure
0
291
T1418.001 Security Software DiscoveryA

Adversaries may attempt to get a listing of security applications and configurations that are installed on a device.

securitygoapi
0
291
T1418 Software DiscoveryA

Adversaries may attempt to get a listing of applications that are installed on a device.

securitygoapi
0
291