Ensure HTTP Strict Transport Security (HSTS) is enabled (Manual)
Skills in this repository
CyberStrikeus/CyberStrike - Page 84
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Ensure upstream server traffic is authenticated with a client certificate (Manual)
Ensure allow and deny filters limit access to specific IP addresses (Manual)
Ensure only approved HTTP methods are allowed (Manual)
Ensure timeout values for reading the client header and body are set correctly (Manual)
Ensure the maximum request body size is set correctly (Manual)
Ensure the maximum buffer size for URIs is defined (Manual)
Ensure the number of connections per IP address is limited (Manual)
Ensure rate limits by IP address are set (Manual)
Ensure X-Content-Type-Options header is configured and enabled (Manual)
Ensure that Content Security Policy (CSP) is enabled and configured properly (Manual)
Ensure the Referrer Policy is enabled and configured properly (Manual)
Adversaries may gather information about the physical process state.
Adversaries may automate collection of industrial environment information using tools or scripts.
Adversaries may target and collect data from information repositories.
Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks.
Adversaries may attempt to upload a program from a PLC to gather information about an industrial process.
Adversaries may attempt to perform screen capture of devices in the control system environment.
Adversaries may collect point and tag values to gain a more comprehensive understanding of the process environment.
Adversaries may gather information about a PLCs or controllers current operating mode.
Adversaries may seek to capture process values related to the inputs and outputs of a PLC.
Adversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases.
Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus.
Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications.
Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection.
Adversaries may perform network connection enumeration to discover information about device communication patterns.
Network sniffing is the practice of using a network interface on a computer system to monitor or capture information regardless of whether it is the specified destination for the information.
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for subsequent Lateral Movement or Discovery techniques.
Adversaries may seek to capture radio frequency (RF) communication used for remote control and reporting in distributed environments.
An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration.
Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection.
Adversaries may use masquerading to disguise a malicious application or executable as another file, to avoid operator and engineer suspicion.
Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
Adversaries may spoof reporting messages in control system environments for evasion and to impair process control.
Adversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks.
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
Adversaries may utilize command-line interfaces (CLIs) to interact with systems and execute commands.
Adversaries may modify the tasking of a controller to allow for the execution of their own programs.
Adversaries may attempt to gain access to a machine via a Graphical User Interface (GUI) to enhance execution capabilities.
Adversaries may directly interact with the native OS application programming interface (API) to access system functions.