Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
Skills in this repository
CyberStrikeus/CyberStrike - Page 90
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Adversaries may abuse PowerShell commands and scripts for execution.
Adversaries may abuse AppleScript for execution.
Adversaries may abuse the Windows command shell for execution.
Adversaries may abuse Unix shell commands and scripts for execution.
Adversaries may abuse Visual Basic (VB) for execution.
Adversaries may abuse Python commands and scripts for execution.
Adversaries may abuse various implementations of JavaScript for execution.
Adversaries may abuse scripting or built-in command line interpreters (CLI) on network devices to execute malicious command and payloads.
Adversaries may abuse cloud APIs to execute malicious commands.
Adversaries may execute commands and perform malicious tasks using AutoIT and AutoHotKey automation scripts.
Adversaries may abuse Lua commands and scripts for execution.
Adversaries may abuse hypervisor command line interpreters (CLIs) to execute malicious commands.
Adversaries may abuse built-in CLI tools or API calls to execute malicious commands in containerized environments.
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
Adversaries may gain access to and use centralized software suites installed within an enterprise to execute commands and move laterally through the network.
Adversaries may interact with the native OS application programming interface (API) to execute behaviors.
Adversaries may execute malicious payloads via loading shared modules.
Adversaries may exploit software vulnerabilities in client applications to execute code.
An adversary may rely upon a user clicking a malicious link in order to gain execution.
An adversary may rely upon a user opening a malicious file in order to gain execution.
Adversaries may rely on a user running a malicious image to facilitate execution.
An adversary may rely upon a user copying and pasting code in order to gain execution.
Adversaries may rely on a user installing a malicious library to facilitate execution.
An adversary may rely upon specific actions by a user in order to gain execution.
Adversaries may use the Windows Component Object Model (COM) for local code execution.
Adversaries may use Windows Dynamic Data Exchange (DDE) to execute arbitrary commands.
Adversaries can provide malicious content to an XPC service daemon for local code execution.
Adversaries may abuse inter-process communication (IPC) mechanisms for local code or command execution.
Adversaries may abuse launchctl to execute commands or programs.
Adversaries may abuse the Windows service control manager to execute malicious commands or payloads.
Adversaries may abuse systemctl to execute commands or programs.
Adversaries may abuse system services or daemons to execute commands or programs.
Adversaries may abuse a container administration service to execute commands within a container.
Adversaries may abuse serverless computing, integration, and automation services to execute arbitrary code in cloud environments.
Adversaries may abuse cloud management services to execute commands within virtual machines.
Adversaries may simulate keystrokes on a victim’s computer by various means to perform any type of action on behalf of the user, such as launching the command interpreter using keyboard shortcuts, ...
Adversaries may abuse ESXi administration services to execute commands on guest machines hosted within an ESXi virtual environment.
Adversaries may manipulate continuous integration / continuous development (CI/CD) processes by injecting malicious code into the build process.
Adversaries may use Windows logon scripts automatically executed at logon initialization to establish persistence.