Adversaries may use compression to obfuscate their payloads or files.
Quellsprache: Englisch
Menü
Skills in diesem Repository
SkillsMP hat 7.442 Skills aus CyberStrikeus/CyberStrike gesammelt. Öffne einen Skill, um Quelle und Details zu prüfen.
CyberStrikeus/CyberStrikeEs werden 40 von 7.442 gesammelten Skills angezeigt.
Adversaries may use compression to obfuscate their payloads or files.
Quellsprache: Englisch
Adversaries may use junk code / dead code to obfuscate a malware’s functionality.
Quellsprache: Englisch
Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign SVG files.
Quellsprache: Englisch
Adversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
Quellsprache: Englisch
Adversaries may attempt to mimic features of valid code signatures to increase the chance of deceiving a user, analyst, or tool.
Quellsprache: Englisch
Adversaries may abuse the right-to-left override (RTLO or RLO) character (U+202E) to disguise a string and/or file name to make it appear benign.
Quellsprache: Englisch
Adversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities.
Quellsprache: Englisch
Adversaries may attempt to manipulate the name of a task or service to make it appear legitimate or benign.
Quellsprache: Englisch
Adversaries may match or approximate the name or location of legitimate files, Registry keys, or other resources when naming/placing them.
Quellsprache: Englisch
Adversaries can hide a program's true filetype by changing the extension of a file.
Quellsprache: Englisch
Adversaries may abuse a double extension in the filename as a means of masquerading the true file type.
Quellsprache: Englisch
Adversaries may masquerade malicious payloads as legitimate files through changes to the payload's formatting, including the file’s signature, extension, icon, and contents.
Quellsprache: Englisch
An adversary may attempt to evade process tree-based analysis by modifying executed malware's parent process ID (PPID).
Quellsprache: Englisch
Adversaries may match or approximate the names of legitimate accounts to make newly created ones appear benign.
Quellsprache: Englisch
Adversaries may modify a process's in-memory arguments to change its name in order to appear as a legitimate or benign process.
Quellsprache: Englisch
Adversaries may attempt to blend in with legitimate traffic by spoofing browser and system attributes like operating system, system language, platform, user-agent string, resolution, time zone, etc.
Quellsprache: Englisch
Adversaries may attempt to manipulate features of their artifacts to make them appear legitimate or benign to users and/or security tools.
Quellsprache: Englisch
Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may inject portable executables (PE) into processes in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may inject malicious code into processes via thread local storage (TLS) callbacks in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may inject malicious code into processes via ptrace (process trace) system calls in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may inject malicious code into processes via the /proc filesystem in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may inject malicious code into process via Extra Window Memory (EWM) in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may inject malicious code into suspended and hollowed processes in order to evade process-based defenses.
Quellsprache: Englisch
Adversaries may inject malicious code into process via process doppelgänging in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may inject malicious code into processes via VDSO hijacking in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may abuse list-view controls to inject malicious code into hijacked processes in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may inject code into processes in order to evade process-based defenses as well as possibly elevate privileges.
Quellsprache: Englisch
Adversaries may clear Windows Event Logs to hide the activity of an intrusion.
Quellsprache: Englisch
Adversaries may clear system logs to hide evidence of an intrusion.
Quellsprache: Englisch
In addition to clearing system logs, an adversary may clear the command history of a compromised account to conceal the actions undertaken during an intrusion.
Quellsprache: Englisch
Adversaries may delete files left behind by the actions of their intrusion activity.
Quellsprache: Englisch
Adversaries may remove share connections that are no longer useful in order to clean up traces of their operation.
Quellsprache: Englisch
Adversaries may modify file time attributes to hide new files or changes to existing files.
Quellsprache: Englisch
Adversaries may clear or remove evidence of malicious network connections in order to clean up traces of their operations.
Quellsprache: Englisch
Adversaries may modify mail and mail application data to remove evidence of their activity.
Quellsprache: Englisch
Adversaries may clear artifacts associated with previously established persistence on a host system to remove evidence of their activity.
Quellsprache: Englisch
Once a payload is delivered, adversaries may reproduce copies of the same malware on the victim system to remove evidence of their presence and/or avoid defenses.
Quellsprache: Englisch