All authors

Claude Skills by CyberStrikeus
github.com/CyberStrikeus7,689 skills0 installs16,544 views
- T1678 Delay ExecutionAdversaries may employ various time-based methods to evade detection and analysis.Votes: 0GitHub stars: 2,182
- T1679 Selective ExclusionAdversaries may intentionally exclude certain files, folders, directories, file types, or system components from encryption or tampering during a ransomware or malicious payload execution.Votes: 0GitHub stars: 2,182
- T1036 005 Match Legitimate ResourceAdversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.Votes: 0GitHub stars: 2,182
- T1070 005 Network Share ConnectionAdversaries may remove share connections that are no longer useful in order to clean up traces of their operation.Votes: 0GitHub stars: 2,182
- T1070 007 Clear Network ConnectionAdversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations.Votes: 0GitHub stars: 2,182
- T1127 Trusted Developer Utilities ProxyAdversaries may take advantage of trusted developer utilities to proxy execution of malicious payloads.Votes: 0GitHub stars: 2,182
- T1140 Deobfuscatedecode Files OrAdversaries may use Obfuscated Files or Information to hide artifacts of an intrusion from analysis.Votes: 0GitHub stars: 2,182
- T1222 001 Windows File And DirectoryAdversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.Votes: 0GitHub stars: 2,182
- T1222 002 Linux And Mac File AndAdversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.Votes: 0GitHub stars: 2,182
- T1222 File And Directory PermissionsAdversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.Votes: 0GitHub stars: 2,182
- T1484 Domain Or Tenant PolicyAdversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments.Votes: 0GitHub stars: 2,182
- T1550 Use Alternate AuthenticationAdversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal s...Votes: 0GitHub stars: 2,182
- T1553 003 Sip And Trust ProviderAdversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature validation checks.Votes: 0GitHub stars: 2,182
- T1553 006 Code Signing PolicyAdversaries may modify code signing policies to enable execution of unsigned or self-signed code.Votes: 0GitHub stars: 2,182
- T1562 004 Disable Or Modify SystemAdversaries may disable or modify system firewalls in order to bypass controls limiting network usage.Votes: 0GitHub stars: 2,182
- T1562 007 Disable Or Modify CloudAdversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.Votes: 0GitHub stars: 2,182
- T1562 012 Disable Or Modify Linux AuditAdversaries may disable or modify the Linux audit system to hide malicious activity and avoid detection.Votes: 0GitHub stars: 2,182
- T1562 013 Disable Or Modify NetworkAdversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage.Votes: 0GitHub stars: 2,182
- T1578 005 Modify Cloud ComputeAdversaries may modify settings that directly affect the size, locations, and resources available to cloud compute infrastructure in order to evade defenses.Votes: 0GitHub stars: 2,182
- T1578 Modify Cloud ComputeAn adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses.Votes: 0GitHub stars: 2,182
- T1599 001 Network Address TranslationAdversaries may bridge network boundaries by modifying a network device’s Network Address Translation (NAT) configuration.Votes: 0GitHub stars: 2,182
- T1003.001 Lsass MemoryAdversaries may attempt to access credential material stored in the process memory of the Local Security Authority Subsystem Service (LSASS).Votes: 0GitHub stars: 2,182
- T1003.002 Security Account ManagerAdversaries may attempt to extract credential material from the Security Account Manager (SAM) database either through in-memory techniques or through the Windows Registry where the SAM database is...Votes: 0GitHub stars: 2,182
- T1003.003 NtdsAdversaries may attempt to access or create a copy of the Active Directory domain database in order to steal credential information, as well as obtain other information about domain members such as...Votes: 0GitHub stars: 2,182
- T1003.004 Lsa SecretsAdversaries with SYSTEM access to a host may attempt to access Local Security Authority (LSA) secrets, which can contain a variety of different credential materials, such as credentials for service...Votes: 0GitHub stars: 2,182
- T1003.005 Cached Domain CredentialsAdversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable.Votes: 0GitHub stars: 2,182
- T1003.006 DcsyncAdversaries may attempt to access credentials and other sensitive information by abusing a Windows Domain Controller's application programming interface (API) to simulate the replication process fr...Votes: 0GitHub stars: 2,182
- T1003.007 Proc FilesystemAdversaries may gather credentials from the proc filesystem or `/proc`.Votes: 0GitHub stars: 2,182
- T1003.008 Etcpasswd And EtcshadowAdversaries may attempt to dump the contents of <code>/etc/passwd</code> and <code>/etc/shadow</code> to enable offline password cracking.Votes: 0GitHub stars: 2,182
- T1003 Os Credential DumpingAdversaries may attempt to dump credentials to obtain account login and credential material, normally in the form of a hash or a clear text password.Votes: 0GitHub stars: 2,182
- T1040 Network SniffingAdversaries may passively sniff network traffic to capture information about an environment, including authentication material passed over the network.Votes: 0GitHub stars: 2,182
- T1110.001 Password GuessingAdversaries with no prior knowledge of legitimate credentials within the system or environment may guess passwords to attempt access to accounts.Votes: 0GitHub stars: 2,182
- T1110.002 Password CrackingAdversaries may use password cracking to attempt to recover usable credentials, such as plaintext passwords, when credential material such as password hashes are obtained.Votes: 0GitHub stars: 2,182
- T1110.003 Password SprayingAdversaries may use a single or small list of commonly used passwords against many different accounts to attempt to acquire valid account credentials.Votes: 0GitHub stars: 2,182
- T1110.004 Credential StuffingAdversaries may use credentials obtained from breach dumps of unrelated accounts to gain access to target accounts through credential overlap.Votes: 0GitHub stars: 2,182
- T1110 Brute ForceAdversaries may use brute force techniques to gain access to accounts when passwords are unknown or when password hashes are obtained.Votes: 0GitHub stars: 2,182
- T1187 Forced AuthenticationAdversaries may gather credential material by invoking or forcing a user to automatically provide authentication information through a mechanism in which they can intercept.Votes: 0GitHub stars: 2,182
- T1212 Exploitation For Credential AccessAdversaries may exploit software vulnerabilities in an attempt to collect credentials.Votes: 0GitHub stars: 2,182
- T1528 Steal Application Access TokenAdversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.Votes: 0GitHub stars: 2,182
- T1539 Steal Web Session CookieAn adversary may steal web application or service session cookies and use them to gain access to web applications or Internet services as an authenticated user without needing credentials.Votes: 0GitHub stars: 2,182
- T1552.001 Credentials In FilesAdversaries may search local file systems and remote file shares for files containing insecurely stored credentials.Votes: 0GitHub stars: 2,182
- T1552.002 Credentials In RegistryAdversaries may search the Registry on compromised systems for insecurely stored credentials.Votes: 0GitHub stars: 2,182
- T1552.003 Shell HistoryAdversaries may search the command history on compromised systems for insecurely stored credentials.Votes: 0GitHub stars: 2,182
- T1552.004 Private KeysAdversaries may search for private key certificate files on compromised systems for insecurely stored credentials.Votes: 0GitHub stars: 2,182
- T1552.005 Cloud Instance Metadata ApiAdversaries may attempt to access the Cloud Instance Metadata API to collect credentials and other sensitive data.Votes: 0GitHub stars: 2,182
- T1552.006 Group Policy PreferencesAdversaries may attempt to find unsecured credentials in Group Policy Preferences (GPP).Votes: 0GitHub stars: 2,182
- T1552.007 Container ApiAdversaries may gather credentials via APIs within a containers environment.Votes: 0GitHub stars: 2,182
- T1552.008 Chat MessagesAdversaries may directly collect unsecured credentials stored or passed through user communication services.Votes: 0GitHub stars: 2,182
- T1552 Unsecured CredentialsAdversaries may search compromised systems to find and obtain insecurely stored credentials.Votes: 0GitHub stars: 2,182
- T1555.001 KeychainAdversaries may acquire credentials from Keychain.Votes: 0GitHub stars: 2,182