Adversaries may establish persistence by executing malicious content triggered by a file type association.
Skills in this repository
CyberStrikeus/CyberStrike - Page 93
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Adversaries may establish persistence by executing malicious content triggered by user inactivity.
Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell.
Adversaries may establish persistence by executing malicious content triggered by an interrupt signal.
Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries.
Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features.
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes.
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers.
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond).
Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.
Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.
Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events.
An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.
Adversaries may bypass UAC mechanisms to elevate process privileges on system.
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges.
Adversaries may leverage the <code>AuthorizationExecuteWithPrivileges</code> API to escalate privileges by prompting the user for credentials.
Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.
Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions.
Adversaries may break out of a container or virtualized environment to gain access to the underlying host.
Adversaries may directly access a volume to bypass file access controls and file system monitoring.
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
Adversaries may perform software packing or virtual machine software protection to conceal their code.
Adversaries may use steganography techniques in order to prevent the detection of hidden information.
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code.
Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed.
Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.
Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis.
Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information.
Adversaries may embed payloads within other files to conceal malicious content from defenses.
Adversaries may obfuscate content during command execution to impede detection.
Adversaries may store data in "fileless" formats to conceal malicious activity from defenses.
Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files.
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection.