All authors

Claude Skills by CyberStrikeus
github.com/CyberStrikeus7,689 skills0 installs16,544 views
- T1550.003 Pass The TicketAdversaries may “pass the ticket” using stolen Kerberos tickets to move laterally within an environment, bypassing normal system access controls.Votes: 0GitHub stars: 2,182
- T1550.004 Web Session CookieAdversaries can use stolen session cookies to authenticate to web applications and services.Votes: 0GitHub stars: 2,182
- T1553.001 Gatekeeper BypassAdversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs.Votes: 0GitHub stars: 2,182
- T1553.002 Code SigningAdversaries may create, acquire, or steal code signing materials to sign their malware or tools.Votes: 0GitHub stars: 2,182
- T1553.004 Install Root CertificateAdversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.Votes: 0GitHub stars: 2,182
- T1553.005 Mark Of The Web BypassAdversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls.Votes: 0GitHub stars: 2,182
- T1553 Subvert Trust ControlsAdversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs.Votes: 0GitHub stars: 2,182
- T1562.001 Disable Or Modify ToolsAdversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities.Votes: 0GitHub stars: 2,182
- T1562.002 Disable Windows Event LoggingAdversaries may disable Windows event logging to limit data that can be leveraged for detections and audits.Votes: 0GitHub stars: 2,182
- T1562.003 Impair Command History LoggingAdversaries may impair command history logging to hide commands they run on a compromised system.Votes: 0GitHub stars: 2,182
- T1562.006 Indicator BlockingAn adversary may attempt to block indicators or events typically captured by sensors from being gathered and analyzed.Votes: 0GitHub stars: 2,182
- T1562.008 Disable Or Modify Cloud LogsAn adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection.Votes: 0GitHub stars: 2,182
- T1562.009 Safe Mode BootAdversaries may abuse Windows safe mode to disable endpoint defenses.Votes: 0GitHub stars: 2,182
- T1562.010 Downgrade AttackAdversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls.Votes: 0GitHub stars: 2,182
- T1562.011 Spoof Security AlertingAdversaries may spoof security alerting from tools, presenting false evidence to impair defenders’ awareness of malicious activity.Votes: 0GitHub stars: 2,182
- T1562 Impair DefensesAdversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms.Votes: 0GitHub stars: 2,182
- T1564.001 Hidden Files And DirectoriesAdversaries may set files and directories to be hidden to evade detection mechanisms.Votes: 0GitHub stars: 2,182
- T1564.002 Hidden UsersAdversaries may use hidden users to hide the presence of user accounts they create or modify.Votes: 0GitHub stars: 2,182
- T1564.003 Hidden WindowAdversaries may use hidden windows to conceal malicious activity from the plain sight of users.Votes: 0GitHub stars: 2,182
- T1564.004 Ntfs File AttributesAdversaries may use NTFS file attributes to hide their malicious data in order to evade detection.Votes: 0GitHub stars: 2,182
- T1564.005 Hidden File SystemAdversaries may use a hidden file system to conceal malicious activity from users and security tools.Votes: 0GitHub stars: 2,182
- T1564.006 Run Virtual InstanceAdversaries may carry out malicious operations using a virtual instance to avoid detection.Votes: 0GitHub stars: 2,182
- T1564.007 Vba StompingAdversaries may hide malicious Visual Basic for Applications (VBA) payloads embedded within MS Office documents by replacing the VBA source code with benign data.Votes: 0GitHub stars: 2,182
- T1564.008 Email Hiding RulesAdversaries may use email rules to hide inbound emails in a compromised user's mailbox.Votes: 0GitHub stars: 2,182
- T1564.009 Resource ForkingAdversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications.Votes: 0GitHub stars: 2,182
- T1564.010 Process Argument SpoofingAdversaries may attempt to hide process command-line arguments by overwriting process memory.Votes: 0GitHub stars: 2,182
- T1564.011 Ignore Process InterruptsAdversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals.Votes: 0GitHub stars: 2,182
- T1564.012 Filepath ExclusionsAdversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other defensive capabilities.Votes: 0GitHub stars: 2,182
- T1564.013 Bind MountsAdversaries may abuse bind mounts on file structures to hide their activity and artifacts from native utilities.Votes: 0GitHub stars: 2,182
- T1564.014 Extended AttributesAdversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade detection.Votes: 0GitHub stars: 2,182
- T1564 Hide ArtifactsAdversaries may attempt to hide artifacts associated with their behaviors to evade detection.Votes: 0GitHub stars: 2,182
- T1578.001 Create SnapshotAn adversary may create a snapshot or data backup within a cloud account to evade defenses.Votes: 0GitHub stars: 2,182
- T1578.002 Create Cloud InstanceAn adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses.Votes: 0GitHub stars: 2,182
- T1578.003 Delete Cloud InstanceAn adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence.Votes: 0GitHub stars: 2,182
- T1578.004 Revert Cloud InstanceAn adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove evidence of their presence.Votes: 0GitHub stars: 2,182
- T1599 Network Boundary BridgingAdversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation.Votes: 0GitHub stars: 2,182
- T1600.001 Reduce Key SpaceAdversaries may reduce the level of effort required to decrypt data transmitted over the network by reducing the cipher strength of encrypted communications.Votes: 0GitHub stars: 2,182
- T1600.002 Disable Crypto HardwareAdversaries disable a network device’s dedicated hardware encryption, which may enable them to leverage weaknesses in software encryption in order to reduce the effort involved in collecting, manip...Votes: 0GitHub stars: 2,182
- T1600 Weaken EncryptionAdversaries may compromise a network device’s encryption capability in order to bypass encryption that would otherwise protect data communications.Votes: 0GitHub stars: 2,182
- T1601.001 Patch System ImageAdversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses.Votes: 0GitHub stars: 2,182
- T1601.002 Downgrade System ImageAdversaries may install an older version of the operating system of a network device to weaken security.Votes: 0GitHub stars: 2,182
- T1601 Modify System ImageAdversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves.Votes: 0GitHub stars: 2,182
- T1610 Deploy ContainerAdversaries may deploy a container into an environment to facilitate execution or evade defenses.Votes: 0GitHub stars: 2,182
- T1612 Build Image On HostAdversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry.Votes: 0GitHub stars: 2,182
- T1620 Reflective Code LoadingAdversaries may reflectively load code into a process in order to conceal the execution of malicious payloads.Votes: 0GitHub stars: 2,182
- T1622 Debugger EvasionAdversaries may employ various means to detect and avoid debuggers.Votes: 0GitHub stars: 2,182
- T1647 Plist File ModificationAdversaries may modify property list files (plist files) to enable other malicious activity, while also potentially evading and bypassing system defenses.Votes: 0GitHub stars: 2,182
- T1656 ImpersonationAdversaries may impersonate a trusted person or organization in order to persuade and trick a target into performing some action on their behalf.Votes: 0GitHub stars: 2,182
- T1666 Modify Cloud Resource HierarchyAdversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses.Votes: 0GitHub stars: 2,182
- T1672 Email SpoofingAdversaries may fake, or spoof, a sender’s identity by modifying the value of relevant email headers in order to establish contact with victims under false pretenses.Votes: 0GitHub stars: 2,182