Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation.
Skills in this repository
CyberStrikeus/CyberStrike - Page 88
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Adversaries may attempt to get information about running processes on a device.
Adversaries may attempt to get detailed information about a device’s operating system and hardware, including versions, patches, and architecture.
Adversaries may exploit remote services of enterprise servers, workstations, or other resources to gain unauthorized access to internal systems once inside of a network.
Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users.
An adversary may encrypt files stored on a mobile device to prevent the user from accessing them.
Adversaries may delete, alter, or send SMS messages without user authorization.
Adversaries may interrupt availability of system and network resources by inhibiting access to accounts utilized by legitimate users.
Adversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity.
Adversaries may insert, delete, or alter data in order to manipulate external outcomes or hide activity.
Adversaries may perform Endpoint Denial of Service (DoS) attacks to degrade or block the availability of services to users.
Adversaries may generate outbound traffic from devices.
Adversaries may destroy data and files on specific devices or in large numbers to interrupt availability to systems, services, and network resources.
Adversaries may try to access and collect application data resident on the device.
Adversaries may abuse clipboard manager APIs to obtain sensitive information copied to the device clipboard.
Adversaries may log user keystrokes to intercept credentials or other information from the user as the user types them.
Adversaries may use methods of capturing user input to obtain credentials or collect information.
Adversaries may capture audio to collect information by leveraging standard operating system APIs of a mobile device.
An adversary may use access to cloud services (e.g.
Adversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.
Adversaries may track a device’s physical location through use of standard operating system APIs via malicious or exploited applications on the compromised device.
Adversaries may abuse accessibility features in Android devices to steal sensitive data and to spread malware to other devices.
An adversary can leverage a device’s cameras to gather information by capturing video recordings.
Adversaries may use screen capture to collect additional information about a target device, such as applications running in the foreground, user data, credentials, or other sensitive information.
Adversaries may collect data within notifications sent by the operating system or other applications.
Adversaries may compress and/or encrypt data that is collected prior to exfiltration.
Adversaries may search local system sources, such as file systems or local databases, to find files of interest and sensitive data prior to exfiltration.
Adversaries may make, forward, or block phone calls without user authorization.
Adversaries may utilize standard operating system APIs to gather calendar entry data.
Adversaries may utilize standard operating system APIs to gather call log data.
Adversaries may utilize standard operating system APIs to gather contact list data.
Adversaries may utilize standard operating system APIs to gather SMS messages.
Adversaries may utilize standard operating system APIs to gather account data.
Adversaries may utilize standard operating system APIs to collect data from permission-backed data stores on a device, such as the calendar or contact list.
Adversaries may attempt to position themselves between two or more networked devices to support follow-on behaviors such as Transmitted Data Manipulation or Endpoint Denial of Service.
Adversaries may abuse the “linked devices” feature on messaging applications, such as Signal and WhatsApp, to register the user’s account to an adversary-controlled device.
Adversaries may steal data by exfiltrating it over an un-encrypted network protocol other than that of the existing command and control channel.
Adversaries may steal data by exfiltrating it over a different protocol than that of the existing command and control channel.
Adversaries may steal data by exfiltrating it over an existing command and control channel.
Adversaries may communicate using application layer protocols associated with web protocols traffic to avoid detection/network filtering by blending in with existing traffic.