Adversaries may establish persistence by executing malicious content triggered by a file type association.
لغة النص الأصلي: الإنجليزية
القائمة
Skills في هذا المستودع
جمع SkillsMP عدد ٧٬٤٤٢ من skills من CyberStrikeus/CyberStrike. افتح أي skill لمراجعة مصدره وتفاصيله.
CyberStrikeus/CyberStrikeعرض ٤٠ من أصل ٧٬٤٤٢ skills مجمعة.
Adversaries may establish persistence by executing malicious content triggered by a file type association.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence by executing malicious content triggered by user inactivity.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence by executing malicious content triggered by an interrupt signal.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers.
لغة النص الأصلي: الإنجليزية
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.
لغة النص الأصلي: الإنجليزية
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond).
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.
لغة النص الأصلي: الإنجليزية
Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events.
لغة النص الأصلي: الإنجليزية
An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.
لغة النص الأصلي: الإنجليزية
Adversaries may bypass UAC mechanisms to elevate process privileges on system.
لغة النص الأصلي: الإنجليزية
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges.
لغة النص الأصلي: الإنجليزية
Adversaries may leverage the <code>AuthorizationExecuteWithPrivileges</code> API to escalate privileges by prompting the user for credentials.
لغة النص الأصلي: الإنجليزية
Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.
لغة النص الأصلي: الإنجليزية
Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions.
لغة النص الأصلي: الإنجليزية
Adversaries may break out of a container or virtualized environment to gain access to the underlying host.
لغة النص الأصلي: الإنجليزية
Adversaries may directly access a volume to bypass file access controls and file system monitoring.
لغة النص الأصلي: الإنجليزية
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
لغة النص الأصلي: الإنجليزية
Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
لغة النص الأصلي: الإنجليزية
Adversaries may perform software packing or virtual machine software protection to conceal their code.
لغة النص الأصلي: الإنجليزية
Adversaries may use steganography techniques in order to prevent the detection of hidden information.
لغة النص الأصلي: الإنجليزية
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code.
لغة النص الأصلي: الإنجليزية
Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed.
لغة النص الأصلي: الإنجليزية
Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.
لغة النص الأصلي: الإنجليزية
Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis.
لغة النص الأصلي: الإنجليزية
Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information.
لغة النص الأصلي: الإنجليزية
Adversaries may embed payloads within other files to conceal malicious content from defenses.
لغة النص الأصلي: الإنجليزية
Adversaries may obfuscate content during command execution to impede detection.
لغة النص الأصلي: الإنجليزية
Adversaries may store data in "fileless" formats to conceal malicious activity from defenses.
لغة النص الأصلي: الإنجليزية
Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files.
لغة النص الأصلي: الإنجليزية
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
لغة النص الأصلي: الإنجليزية
Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection.
لغة النص الأصلي: الإنجليزية