All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs317 views
T1420 File And Directory DiscoveryA

Adversaries may enumerate files and directories or search in specific device locations for desired information within a filesystem.

securitygosecurity
0
291
T1421 System Network Connections DiscoveryA

Adversaries may attempt to get a listing of network connections to or from the compromised device they are currently accessing or from remote systems by querying for information over the network.

securitygoapi
0
291
T1422.001 Internet Connection DiscoveryA

Adversaries may check for Internet connectivity on compromised systems.

securitygoshell
0
291
T1422.002 Wi Fi DiscoveryA

Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.

securitygo
0
291
T1422 System Network Configuration DiscoveryA

Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of devices they access or through information discovery of remote systems.

securitygojava
0
291
T1423 Network Service ScanningA

Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation.

securitygo
0
291
T1424 Process DiscoveryA

Adversaries may attempt to get information about running processes on a device.

securitygosecurity
0
291
T1426 System Information DiscoveryA

Adversaries may attempt to get detailed information about a device’s operating system and hardware, including versions, patches, and architecture.

securitygo
0
291
T1428 Exploitation Of Remote ServicesA

Adversaries may exploit remote services of enterprise servers, workstations, or other resources to gain unauthorized access to internal systems once inside of a network.

securitygosecurity
0
291
T1464 Network Denial Of ServiceA

Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users.

securitygogit
0
291
T1471 Data Encrypted For ImpactA

An adversary may encrypt files stored on a mobile device to prevent the user from accessing them.

securitygo
0
291
T1582 Sms ControlA

Adversaries may delete, alter, or send SMS messages without user authorization.

securitygojava
0
291
T1640 Account Access RemovalA

Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.

securitygogit
0
291
T1641.001 Transmitted Data ManipulationA

Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity.

securitygo
0
291
T1641 Data ManipulationA

Adversaries may insert, delete, or alter data in order to manipulate external outcomes or hide activity.

securitygoapi
0
291
T1642 Endpoint Denial Of ServiceA

Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users.

securitygojava
0
291
T1643 Generate Traffic From VictimA

Adversaries may generate outbound traffic from devices.

securitygo
0
291
T1662 Data DestructionA

Adversaries may destroy data and files on specific devices or in large numbers to interrupt availability to systems, services, and network resources.

securitygo
0
291
T1409 Stored Application DataA

Adversaries may try to access and collect application data resident on the device.

securitygosecurity
0
291
T1414 Clipboard DataA

Adversaries may abuse clipboard manager APIs to obtain sensitive information copied to the device clipboard.

securitygogit
0
291
T1417.001 KeyloggingA

Adversaries may log user keystrokes to intercept credentials or other information from the user as the user types them.

securitygogit
0
291
T1417 Input CaptureA

Adversaries may use methods of capturing user input to obtain credentials or collect information.

securitygo
0
291
T1429 Audio CaptureA

Adversaries may capture audio to collect information by leveraging standard operating system APIs of a mobile device.

securitygoapi
0
291
T1430.001 Remote Device Management ServicesA

An adversary may use access to cloud services (e.g.

securitygosecurity
0
291
T1430.002 Impersonate Ss7 NodesA

Adversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.

securitygonode
0
291
T1430 Location TrackingA

Adversaries may track a device’s physical location through use of standard operating system APIs via malicious or exploited applications on the compromised device.

securitygoapi
0
291
T1453 Abuse Accessibility FeaturesA

Adversaries may abuse accessibility features in Android devices to steal sensitive data and to spread malware to other devices.

securitygogit
0
291
T1512 Video CaptureA

An adversary can leverage a device’s cameras to gather information by capturing video recordings.

securitygoapi
0
291
T1513 Screen CaptureA

Adversaries may use screen capture to collect additional information about a target device, such as applications running in the foreground, user data, credentials, or other sensitive information.

securitygodebugging
0
291
T1517 Access NotificationsA

Adversaries may collect data within notifications sent by the operating system or other applications.

securitygosecurity
0
291
T1532 Archive Collected DataA

Adversaries may compress and/or encrypt data that is collected prior to exfiltration.

securitygo
0
291
T1533 Data From Local SystemA

Adversaries may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to exfiltration.

securitygodatabase
0
291
T1616 Call ControlA

Adversaries may make, forward, or block phone calls without user authorization.

securitygoapi
0
291
T1636.001 Calendar EntriesA

Adversaries may utilize standard operating system APIs to gather calendar entry data.

securitygoapi
0
291
T1636.002 Call LogA

Adversaries may utilize standard operating system APIs to gather call log data.

securitygoapi
0
291
T1636.003 Contact ListA

Adversaries may utilize standard operating system APIs to gather contact list data.

securitygoapi
0
291
T1636.004 Sms MessagesA

Adversaries may utilize standard operating system APIs to gather SMS messages.

securitygoapi
0
291
T1636.005 AccountsA

Adversaries may utilize standard operating system APIs to gather account data.

securitygoapi
0
291
T1636 Protected User DataA

Adversaries may utilize standard operating system APIs to collect data from permission-backed data stores on a device, such as the calendar or contact list.

securitygoapi
0
291
T1638 Adversary In The MiddleA

Adversaries may attempt to position themselves between two or more networked devices to support follow-on behaviors such as Transmitted Data Manipulation or Endpoint Denial of Service.

securitygosecurity
0
291
T1676 Linked DevicesA

Adversaries may abuse the “linked devices” feature on messaging applications, such as Signal and WhatsApp, to register the user’s account to an adversary-controlled device.

securitygogit
0
291
T1639.001 Exfiltration Over Unencrypted Non C2 ProtocolA

Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.

securitygo
0
291
T1639 Exfiltration Over Alternative ProtocolA

Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.

securitygo
0
291
T1646 Exfiltration Over C2 ChannelA

Adversaries may steal data by exfiltrating it over an existing command and control channel.

securitygo
0
291
T1437.001 Web ProtocolsA

Adversaries may communicate using application layer protocols associated with web protocols traffic to avoid detection/network filtering by blending in with existing traffic.

securitygoapi
0
291
T1437 Application Layer ProtocolA

Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic.

securitygo
0
291
T1481.001 Dead Drop ResolverA

Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.

securitygogit
0
291
T1481.002 Bidirectional CommunicationA

Adversaries may use an existing, legitimate external Web service channel as a means for sending commands to and receiving output from a compromised system.

securitygogit
0
291
T1481.003 One Way CommunicationA

Adversaries may use an existing, legitimate external Web service channel as a means for sending commands to a compromised system without receiving return output.

securitygogit
0
291
T1481 Web ServiceA

Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.

securitygogit
0
291