
Claude Skills by CyberStrikeus
github.com/CyberStrikeusAdversaries may generate network traffic using a protocol and port pairing that are typically not associated.
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
Adversaries may use SSL Pinning to protect the C2 traffic from being intercepted and analyzed.
Adversaries may explicitly employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
Adversaries may transfer tools or other files from an external system onto a compromised device to facilitate follow-on actions.
Adversaries may use Domain Generation Algorithms (DGAs) to procedurally generate domain names for uses such as command and control communication or malicious application distribution.
Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.
Adversaries may communicate with compromised devices using out of band data streams.
Adversaries may use legitimate remote access software, such as `VNC`, `TeamViewer`, `AirDroid`, `AirMirror`, etc., to establish an interactive command and control channel to target mobile devices.
Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
Adversaries may abuse Unix shell commands and scripts for execution.
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
Adversaries may exploit software vulnerabilities in client applications to execute code.
Bug bounty and pentest reconnaissance methodology