Adversaries may gather information about the victim's host hardware that can be used during targeting.
Skills in this repository
CyberStrikeus/CyberStrike - Page 106
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Adversaries may gather information about the victim's host software that can be used during targeting.
Adversaries may gather information about the victim's host firmware that can be used during targeting.
Adversaries may gather information about the victim's client configurations that can be used during targeting.
Adversaries may gather information about the victim's hosts that can be used during targeting.
Adversaries may search social media for information about victims that can be used during targeting.
Adversaries may use search engines to collect information about victims that can be used during targeting.
Adversaries may search public code repositories for information about victims that can be used during targeting.
Adversaries may search freely available websites and/or domains for information about victims that can be used during targeting.
Adversaries may search websites owned by the victim for information that can be used during targeting.
Adversaries may scan victim IP blocks to gather information that can be used during targeting.
Adversaries may scan victims for vulnerabilities that can be used during targeting.
Adversaries may iteratively probe infrastructure using brute-forcing and crawling techniques.
Adversaries may execute active reconnaissance scans to gather information that can be used during targeting.
Adversaries may search DNS data for information about victims that can be used during targeting.
Adversaries may search public WHOIS data for information about victims that can be used during targeting.
Adversaries may search public digital certificate data for information about victims that can be used during targeting.
Adversaries may search content delivery network (CDN) data about victims that can be used during targeting.
Adversaries may search within public scan databases for information about victims that can be used during targeting.
Adversaries may search freely available technical databases for information about victims that can be used during targeting.
Adversaries may search private data from threat intelligence vendors for information that can be used during targeting.
Adversaries may purchase technical information about victims that can be used during targeting.
Adversaries may search and gather information about victims from closed (e.g., paid, private, or otherwise not freely available) sources that can be used during targeting.
Adversaries may send spearphishing messages via third-party services to elicit sensitive information that can be used during targeting.
Adversaries may send spearphishing messages with a malicious attachment to elicit sensitive information that can be used during targeting.
Adversaries may send spearphishing messages with a malicious link to elicit sensitive information that can be used during targeting.
Adversaries may use voice communications to elicit sensitive information that can be used during targeting.
Adversaries may send phishing messages to elicit sensitive information that can be used during targeting.
Threat actors may seek information/indicators from closed or open threat intelligence sources gathered about their own campaigns, as well as those conducted by other adversaries that may align with...
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events
A baseline of network operations and expected data flows for users and systems is established and managed
Potentially adverse events are analyzed to better understand associated activities
Information is correlated from multiple sources
The estimated impact and scope of adverse events are understood
Incident alert thresholds are established
Information on adverse events is provided to authorized staff and tools
Cyber threat intelligence and other contextual information are integrated into the analysis
Incidents are declared when adverse events meet the defined incident criteria
Networks and network services are monitored to find potentially adverse events