An adversary may disable or modify cloud logging capabilities and integrations to limit what data is collected on their activities and avoid detection.
Skills in this repository
CyberStrikeus/CyberStrike - Page 97
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Adversaries may abuse Windows safe mode to disable endpoint defenses.
Adversaries may downgrade or use a version of system features that may be outdated, vulnerable, and/or does not support updated security controls.
Adversaries may spoof security alerting from tools, presenting false evidence to impair defenders’ awareness of malicious activity.
Adversaries may disable or modify the Linux audit system to hide malicious activity and avoid detection.
Adversaries may disable network device-based firewall mechanisms entirely or add, delete, or modify particular rules in order to bypass controls limiting network usage.
Adversaries may maliciously modify components of a victim environment in order to hinder or disable defensive mechanisms.
Adversaries may set files and directories to be hidden to evade detection mechanisms.
Adversaries may use hidden users to hide the presence of user accounts they create or modify.
Adversaries may use hidden windows to conceal malicious activity from the plain sight of users.
Adversaries may use NTFS file attributes to hide their malicious data in order to evade detection.
Adversaries may use a hidden file system to conceal malicious activity from users and security tools.
Adversaries may carry out malicious operations using a virtual instance to avoid detection.
Adversaries may hide malicious Visual Basic for Applications (VBA) payloads embedded within MS Office documents by replacing the VBA source code with benign data.
Adversaries may use email rules to hide inbound emails in a compromised user's mailbox.
Adversaries may abuse resource forks to hide malicious code or executables to evade detection and bypass security applications.
Adversaries may attempt to hide process command-line arguments by overwriting process memory.
Adversaries may evade defensive mechanisms by executing commands that hide from process interrupt signals.
Adversaries may attempt to hide their file-based artifacts by writing them to specific folders or file names excluded from antivirus (AV) scanning and other defensive capabilities.
Adversaries may abuse bind mounts on file structures to hide their activity and artifacts from native utilities.
Adversaries may abuse extended attributes (xattrs) on macOS and Linux to hide their malicious data in order to evade detection.
Adversaries may attempt to hide artifacts associated with their behaviors to evade detection.
An adversary may create a snapshot or data backup within a cloud account to evade defenses.
An adversary may create a new instance or virtual machine (VM) within the compute service of a cloud account to evade defenses.
An adversary may delete a cloud instance after they have performed malicious activities in an attempt to evade detection and remove evidence of their presence.
An adversary may revert changes made to a cloud instance after they have performed malicious activities in attempt to evade detection and remove evidence of their presence.
Adversaries may modify settings that directly affect the size, locations, and resources available to cloud compute infrastructure in order to evade defenses.
An adversary may attempt to modify a cloud account's compute service infrastructure to evade defenses.
Adversaries may bridge network boundaries by modifying a network device’s Network Address Translation (NAT) configuration.
Adversaries may bridge network boundaries by compromising perimeter network devices or internal devices responsible for network segmentation.
Adversaries may reduce the level of effort required to decrypt data transmitted over the network by reducing the cipher strength of encrypted communications.
Adversaries disable a network device’s dedicated hardware encryption, which may enable them to leverage weaknesses in software encryption in order to reduce the effort involved in collecting, manip...
Adversaries may compromise a network device’s encryption capability in order to bypass encryption that would otherwise protect data communications.
Adversaries may modify the operating system of a network device to introduce new capabilities or weaken existing defenses.
Adversaries may install an older version of the operating system of a network device to weaken security.
Adversaries may make changes to the operating system of embedded network devices to weaken defenses and provide new capabilities for themselves.
Adversaries may deploy a container into an environment to facilitate execution or evade defenses.
Adversaries may build a container image directly on a host to bypass defenses that monitor for the retrieval of malicious images from a public registry.
Adversaries may reflectively load code into a process in order to conceal the execution of malicious payloads.
Adversaries may employ various means to detect and avoid debuggers.