Adversaries may use scripting languages to execute arbitrary code in the form of a pre-written script or in the form of user-supplied code to an interpreter.
Skills in this repository
CyberStrikeus/CyberStrike - Page 85
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Adversaries may change the operating mode of a controller to gain additional access to engineering functions such as Program Download.
Adversaries may rely on a targeted organizations user interaction for the execution of malicious code.
Adversaries may attempt to leverage Application Program Interfaces (APIs) used for communication between control software and the hardware.
Adversaries may hook into application programming interface (API) functions used by processes to redirect calls for execution and privilege escalation means.
Adversaries may leverage AutoRun functionality or scripts to execute malicious code.
Adversaries may cause a denial of control to temporarily prevent operators and engineers from interacting with process controls.
Adversaries may cause a denial of view in attempt to disrupt and prevent operator oversight on the status of an ICS environment.
Adversaries may attempt to disrupt essential components or systems to prevent owner and operator from delivering products or services.
Adversaries may seek to achieve a sustained loss of control or a runaway condition in which operators cannot issue any commands even if the malicious interference has subsided.
Adversaries may cause loss of productivity and revenue through disruption and even damage to the availability and integrity of control system operations, devices, and related processes.
Adversaries may cause a sustained or permanent loss of view where the ICS equipment will require local, hands-on operator intervention; for instance, a restart or manual operation.
Adversaries may manipulate physical process control within the industrial environment.
Adversaries may attempt to manipulate the information reported back to operators or controllers.
Adversaries may compromise protective system functions designed to prevent the effects of faults and abnormal conditions.
Adversaries may cause damage and destruction of property to infrastructure, equipment, and the surrounding environment when attacking control systems.
Adversaries may compromise safety system functions designed to maintain safe operation of a process when unacceptable or dangerous conditions occur.
Adversaries may steal operational information on a production environment as a direct mission outcome for personal gain or to inform future operations.
Adversaries may repetitively or successively change I/O point values to perform an action.
Adversaries may modify parameters used to instruct industrial control system devices.
Adversaries may send unauthorized command messages to instruct control system assets to perform actions outside of their intended functionality, or without the logical preconditions to trigger thei...
Adversaries may activate firmware update mode on devices to prevent expected response functions from engaging in reaction to an emergency or process malfunction.
Adversaries may block a command message from reaching its intended target to prevent command execution.
Adversaries may block or prevent a reporting message from reaching its intended target.
Adversaries may block access to serial COM to prevent instructions or configurations from reaching target devices.
Adversaries may perform data destruction over the course of an operation.
Adversaries may perform Denial-of-Service (DoS) attacks to disrupt expected device functionality.
Adversaries may forcibly restart or shutdown a device in an ICS environment to disrupt and potentially negatively impact physical processes.
Adversaries may manipulate the I/O image of PLCs through various means to prevent them from functioning as expected.
Adversaries may modify alarm settings to prevent alerts that may inform operators of their presence or to prevent responses to dangerous and unintended scenarios.
Adversaries may target protection function alarms to prevent them from notifying operators of critical conditions.
Adversaries may stop or disable services on a system to render those services unavailable to legitimate users.
Adversaries may modify software and device credentials to prevent operator and responder access.
Adversaries may gain access to a system during a drive-by compromise, when a user visits a website as part of a regular browsing session.
Adversaries may leverage weaknesses to exploit internet-facing software for initial access into an industrial network.
Adversaries may leverage external remote services as a point of initial access into your network.
Adversaries may move onto systems, such as those separated from the enterprise network, by copying malware to removable media which is inserted into the control systems environment.
Adversaries may setup a rogue master to leverage control server functions to communicate with outstations.
Adversaries may perform wireless compromise as a method of gaining communications and unauthorized access to a wireless network.
Adversaries may perform supply chain compromise to gain control systems environment access by means of infected products, software, and workflows.