Adversaries may attempt to find domain-level groups and permission settings.
Skills in this repository
CyberStrikeus/CyberStrike - Page 100
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Adversaries may attempt to find cloud groups and permission settings.
Adversaries may attempt to discover group and permission settings.
An adversary may attempt to get detailed information about the operating system and hardware, including version, patches, hotfixes, service packs, and architecture.
Adversaries may enumerate files and directories or may search in specific locations of a host or network share for certain information within a file system.
Adversaries may attempt to get a listing of local system accounts.
Adversaries may attempt to get a listing of domain accounts.
Adversaries may attempt to get a listing of email addresses and accounts.
Adversaries may attempt to get a listing of cloud accounts.
Adversaries may attempt to get a listing of valid accounts, usernames, or email addresses on a system or within a compromised environment.
Adversaries may attempt to gather information about attached peripheral devices and components connected to a computer system.
An adversary may gather the system time and/or time zone settings from a local or remote system.
Adversaries may look for folders and drives shared on remote systems as a means of identifying sources of information to gather as a precursor for Collection and to identify potential systems of in...
Adversaries may attempt to access detailed information about the password policy used within an enterprise network or cloud environment.
Adversaries may enumerate information about browsers to learn more about compromised environments.
Adversaries may attempt to gather information on domain trust relationships that may be used to identify lateral movement opportunities in Windows multi-domain/forest environments.
Adversaries may attempt to get a listing of security software, configurations, defensive tools, and sensors that are installed on a system or in a cloud environment.
Adversaries may attempt to get a listing of backup software or configurations that are installed on a system.
Adversaries may attempt to get a listing of software and software versions that are installed on a system or in a cloud environment.
An adversary may attempt to enumerate the cloud services running on a system after gaining access.
An adversary may use a cloud service dashboard GUI with stolen credentials to gain useful information from an operational cloud environment, such as specific services, resources, and features.
An adversary may attempt to discover infrastructure and resources that are available within an infrastructure-as-a-service (IaaS) environment.
Adversaries may attempt to discover containers and other resources that are available within a containers environment.
Adversaries may attempt to gather information about the system language of a victim in order to infer the geographical location of that host.
Adversaries may gather information in an attempt to calculate the geographical location of a victim host.
Adversaries may gather information on Group Policy settings to identify paths for privilege escalation, security measures applied within a domain, and to discover patterns in domain objects that ca...
Adversaries may enumerate objects in cloud storage infrastructure.
Adversaries may attempt to enumerate local device drivers on a victim host.
Adversaries may enumerate system and service logs to find useful data.
An adversary may attempt to enumerate running virtual machines (VMs) after gaining access to a host or hypervisor.
Adversaries may enumerate local drives, disks, and/or volumes and their attributes like total or free space and volume serial number.
Adversaries may use Valid Accounts to log into a computer using the Remote Desktop Protocol (RDP).
Adversaries may use Valid Accounts to interact with a remote network share using Server Message Block (SMB).
Adversaries may use Valid Accounts to interact with remote machines by taking advantage of Distributed Component Object Model (DCOM).
Adversaries may use Valid Accounts to log into remote machines using Secure Shell (SSH).
Adversaries may use Valid Accounts to remotely control machines using Virtual Network Computing (VNC).
Adversaries may use Valid Accounts to interact with remote systems using Windows Remote Management (WinRM).
Adversaries may log into accessible cloud services within a compromised environment using Valid Accounts that are synchronized with or federated to on-premises user identities.
Adversaries may leverage Valid Accounts to log directly into accessible cloud hosted compute infrastructure through cloud native methods.
Adversaries may use Valid Accounts to log into a service that accepts remote connections, such as telnet, SSH, and VNC.