Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic.
Quellsprache: Englisch
Menü
Skills in diesem Repository
SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
CyberStrikeus/CyberStrikeEs werden 40 von 7.442 gesammelten Skills angezeigt.
Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic.
Quellsprache: Englisch
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.
Quellsprache: Englisch
Adversaries may use an existing, legitimate external Web service channel as a means for sending commands to and receiving output from a compromised system.
Quellsprache: Englisch
Adversaries may use an existing, legitimate external Web service channel as a means for sending commands to a compromised system without receiving return output.
Quellsprache: Englisch
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.
Quellsprache: Englisch
Adversaries may generate network traffic using a protocol and port pairing that are typically not associated.
Quellsprache: Englisch
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
Quellsprache: Englisch
Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
Quellsprache: Englisch
Adversaries may use SSL Pinning to protect the C2 traffic from being intercepted and analyzed.
Quellsprache: Englisch
Adversaries may explicitly employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
Quellsprache: Englisch
Adversaries may transfer tools or other files from an external system onto a compromised device to facilitate follow-on actions.
Quellsprache: Englisch
Adversaries may use Domain Generation Algorithms (DGAs) to procedurally generate domain names for uses such as command and control communication or malicious application distribution.
Quellsprache: Englisch
Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.
Quellsprache: Englisch
Adversaries may communicate with compromised devices using out of band data streams.
Quellsprache: Englisch
Adversaries may use legitimate remote access software, such as `VNC`, `TeamViewer`, `AirDroid`, `AirMirror`, etc., to establish an interactive command and control channel to target mobile devices.
Quellsprache: Englisch
Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
Quellsprache: Englisch
Adversaries may abuse Unix shell commands and scripts for execution.
Quellsprache: Englisch
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
Quellsprache: Englisch
Adversaries may exploit software vulnerabilities in client applications to execute code.
Quellsprache: Englisch
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
Quellsprache: Englisch
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Quellsprache: Englisch
Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise.
Quellsprache: Englisch
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.
Quellsprache: Englisch
Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.
Quellsprache: Englisch
Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
Quellsprache: Englisch
Adversaries may breach or otherwise leverage organizations who have access to intended victims.
Quellsprache: Englisch
Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access.
Quellsprache: Englisch
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
Quellsprache: Englisch
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
Quellsprache: Englisch
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems.
Quellsprache: Englisch
Adversaries may use voice communications to ultimately gain access to victim systems.
Quellsprache: Englisch
Adversaries may send phishing messages to gain access to victim systems.
Quellsprache: Englisch
Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic.
Quellsprache: Englisch
Adversaries may gain initial access to target systems by connecting to wireless networks.
Quellsprache: Englisch
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
Quellsprache: Englisch
Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code.
Quellsprache: Englisch
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code.
Quellsprache: Englisch
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
Quellsprache: Englisch
Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code.
Quellsprache: Englisch
Adversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule deployment of containers configured to execute malicious code.
Quellsprache: Englisch