Adversaries may establish persistence by executing malicious content triggered by a file type association.
Quellsprache: Englisch
Menü
Skills in diesem Repository
SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
CyberStrikeus/CyberStrikeEs werden 40 von 7.442 gesammelten Skills angezeigt.
Adversaries may establish persistence by executing malicious content triggered by a file type association.
Quellsprache: Englisch
Adversaries may establish persistence by executing malicious content triggered by user inactivity.
Quellsprache: Englisch
Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
Quellsprache: Englisch
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell.
Quellsprache: Englisch
Adversaries may establish persistence by executing malicious content triggered by an interrupt signal.
Quellsprache: Englisch
Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries.
Quellsprache: Englisch
Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.
Quellsprache: Englisch
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features.
Quellsprache: Englisch
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes.
Quellsprache: Englisch
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.
Quellsprache: Englisch
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.
Quellsprache: Englisch
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers.
Quellsprache: Englisch
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.
Quellsprache: Englisch
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond).
Quellsprache: Englisch
Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.
Quellsprache: Englisch
Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.
Quellsprache: Englisch
Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events.
Quellsprache: Englisch
An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.
Quellsprache: Englisch
Adversaries may bypass UAC mechanisms to elevate process privileges on system.
Quellsprache: Englisch
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges.
Quellsprache: Englisch
Adversaries may leverage the <code>AuthorizationExecuteWithPrivileges</code> API to escalate privileges by prompting the user for credentials.
Quellsprache: Englisch
Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.
Quellsprache: Englisch
Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions.
Quellsprache: Englisch
Adversaries may break out of a container or virtualized environment to gain access to the underlying host.
Quellsprache: Englisch
Adversaries may directly access a volume to bypass file access controls and file system monitoring.
Quellsprache: Englisch
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
Quellsprache: Englisch
Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
Quellsprache: Englisch
Adversaries may perform software packing or virtual machine software protection to conceal their code.
Quellsprache: Englisch
Adversaries may use steganography techniques in order to prevent the detection of hidden information.
Quellsprache: Englisch
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code.
Quellsprache: Englisch
Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed.
Quellsprache: Englisch
Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.
Quellsprache: Englisch
Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis.
Quellsprache: Englisch
Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information.
Quellsprache: Englisch
Adversaries may embed payloads within other files to conceal malicious content from defenses.
Quellsprache: Englisch
Adversaries may obfuscate content during command execution to impede detection.
Quellsprache: Englisch
Adversaries may store data in "fileless" formats to conceal malicious activity from defenses.
Quellsprache: Englisch
Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files.
Quellsprache: Englisch
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
Quellsprache: Englisch
Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection.
Quellsprache: Englisch