mit einem Klick
mitre-attack-agent-skills
mitre-attack-agent-skills enthält 918 gesammelte Skills von santosomar, mit Repository-Berufsabdeckung und Skill-Detailseiten auf SkillsMP.
Skills in diesem Repository
Analyze MITRE ATT&CK T1398 Boot or Logon Initialization Scripts in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1398, Boot or Logon Initialization Scripts, or mobile ATT&CK. Adversaries may use scripts automatically executed at boot or logon initialization to establish persistence.
Analyze MITRE ATT&CK T1404 Exploitation for Privilege Escalation in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1404, Exploitation for Privilege Escalation, or mobile ATT&CK. Adversaries may exploit software vulnerabilities in order to elevate privileges.
Analyze MITRE ATT&CK T1406.001 Steganography in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1406.001, Steganography, or mobile ATT&CK. Adversaries may use steganography techniques in order to prevent the detection of hidden information.
Analyze MITRE ATT&CK T1406.002 Software Packing in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1406.002, Software Packing, or mobile ATT&CK. Adversaries may perform software packing to conceal their code.
Analyze MITRE ATT&CK T1406 Obfuscated Files or Information in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1406, Obfuscated Files or Information, or mobile ATT&CK. Adversaries may attempt to make a payload or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the device or in transit.
Analyze MITRE ATT&CK T1407 Download New Code at Runtime in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1407, Download New Code at Runtime, or mobile ATT&CK. Adversaries may download and execute dynamic code not included in the original application package after installation.
Analyze MITRE ATT&CK T1409 Stored Application Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1409, Stored Application Data, or mobile ATT&CK. Adversaries may try to access and collect application data resident on the device.
Analyze MITRE ATT&CK T1414 Clipboard Data in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1414, Clipboard Data, or mobile ATT&CK. Adversaries may abuse clipboard manager APIs to obtain sensitive information copied to the device clipboard.
Analyze MITRE ATT&CK T1417.001 Keylogging in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1417.001, Keylogging, or mobile ATT&CK. Adversaries may log user keystrokes to intercept credentials or other information from the user as the user types them.
Analyze MITRE ATT&CK T1417.002 GUI Input Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1417.002, GUI Input Capture, or mobile ATT&CK. Adversaries may mimic common operating system GUI components to prompt users for sensitive information with a seemingly legitimate prompt.
Analyze MITRE ATT&CK T1417 Input Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1417, Input Capture, or mobile ATT&CK. Adversaries may use methods of capturing user input to obtain credentials or collect information.
Analyze MITRE ATT&CK T1418.001 Security Software Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1418.001, Security Software Discovery, or mobile ATT&CK. Adversaries may attempt to get a listing of security applications and configurations that are installed on a device.
Analyze MITRE ATT&CK T1418 Software Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1418, Software Discovery, or mobile ATT&CK. Adversaries may attempt to get a listing of applications that are installed on a device.
Analyze MITRE ATT&CK T1420 File and Directory Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1420, File and Directory Discovery, or mobile ATT&CK. Adversaries may enumerate files and directories or search in specific device locations for desired information within a filesystem.
Analyze MITRE ATT&CK T1421 System Network Connections Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1421, System Network Connections Discovery, or mobile ATT&CK. Adversaries may attempt to get a listing of network connections to or from the compromised device they are currently accessing or from remote systems by querying for information over the network.
Analyze MITRE ATT&CK T1422.001 Internet Connection Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422.001, Internet Connection Discovery, or mobile ATT&CK. Adversaries may check for Internet connectivity on compromised systems.
Analyze MITRE ATT&CK T1422.002 Wi-Fi Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422.002, Wi-Fi Discovery, or mobile ATT&CK. Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
Analyze MITRE ATT&CK T1422 System Network Configuration Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1422, System Network Configuration Discovery, or mobile ATT&CK. Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of devices they access or through information discovery of remote systems.
Analyze MITRE ATT&CK T1423 Network Service Scanning in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1423, Network Service Scanning, or mobile ATT&CK. Adversaries may attempt to get a listing of services running on remote hosts, including those that may be vulnerable to remote software exploitation.
Analyze MITRE ATT&CK T1424 Process Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1424, Process Discovery, or mobile ATT&CK. Adversaries may attempt to get information about running processes on a device.
Analyze MITRE ATT&CK T1426 System Information Discovery in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1426, System Information Discovery, or mobile ATT&CK. Adversaries may attempt to get detailed information about a device’s operating system and hardware, including versions, patches, and architecture.
Analyze MITRE ATT&CK T1428 Exploitation of Remote Services in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1428, Exploitation of Remote Services, or mobile ATT&CK. Adversaries may exploit remote services of enterprise servers, workstations, or other resources to gain unauthorized access to internal systems once inside of a network.
Analyze MITRE ATT&CK T1429 Audio Capture in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1429, Audio Capture, or mobile ATT&CK. Adversaries may capture audio to collect information by leveraging standard operating system APIs of a mobile device.
Analyze MITRE ATT&CK T1430.001 Remote Device Management Services in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1430.001, Remote Device Management Services, or mobile ATT&CK. An adversary may use access to cloud services (e.g.
Analyze MITRE ATT&CK T1430.002 Impersonate SS7 Nodes in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1430.002, Impersonate SS7 Nodes, or mobile ATT&CK. Adversaries may exploit the lack of authentication in signaling system network nodes to track the location of mobile devices by impersonating a node.(Citation: Engel-SS7)(Citation: Engel-SS7-2008)(Citation: 3GPP-Securit…
Analyze MITRE ATT&CK T1430 Location Tracking in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1430, Location Tracking, or mobile ATT&CK. Adversaries may track a device’s physical location through use of standard operating system APIs via malicious or exploited applications on the compromised device.
Analyze MITRE ATT&CK T1437.001 Web Protocols in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1437.001, Web Protocols, or mobile ATT&CK. Adversaries may communicate using application layer protocols associated with web protocols traffic to avoid detection/network filtering by blending in with existing traffic.
Analyze MITRE ATT&CK T1437 Application Layer Protocol in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1437, Application Layer Protocol, or mobile ATT&CK. Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic.
Analyze MITRE ATT&CK T1451 SIM Card Swap in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1451, SIM Card Swap, or mobile ATT&CK. Adversaries may gain access to mobile devices through transfers or swaps from victims’ phone numbers to adversary-controlled SIM cards and mobile devices.(Citation: ATT SIM Swap Scams)(Citation: Verizon SIM Swapping) Th…
Analyze MITRE ATT&CK T1453 Abuse Accessibility Features in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1453, Abuse Accessibility Features, or mobile ATT&CK. Adversaries may abuse accessibility features in Android devices to steal sensitive data and to spread malware to other devices.
Analyze MITRE ATT&CK T1456 Drive-By Compromise in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1456, Drive-By Compromise, or mobile ATT&CK. Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
Analyze MITRE ATT&CK T1458 Replication Through Removable Media in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1458, Replication Through Removable Media, or mobile ATT&CK. Adversaries may move onto devices by exploiting or copying malware to devices connected via USB.
Analyze MITRE ATT&CK T1461 Lockscreen Bypass in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1461, Lockscreen Bypass, or mobile ATT&CK. An adversary with physical access to a mobile device may seek to bypass the device’s lockscreen.
Analyze MITRE ATT&CK T1464 Network Denial of Service in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1464, Network Denial of Service, or mobile ATT&CK. Adversaries may perform Network Denial of Service (DoS) attacks to degrade or block the availability of targeted resources to users.
Analyze MITRE ATT&CK T1471 Data Encrypted for Impact in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1471, Data Encrypted for Impact, or mobile ATT&CK. An adversary may encrypt files stored on a mobile device to prevent the user from accessing them.
Analyze MITRE ATT&CK T1474.001 Compromise Software Dependencies and Development Tools in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474.001, Compromise Software Dependencies and Development Tools, or mobile ATT&CK. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
Analyze MITRE ATT&CK T1474.002 Compromise Hardware Supply Chain in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474.002, Compromise Hardware Supply Chain, or mobile ATT&CK. Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.
Analyze MITRE ATT&CK T1474.003 Compromise Software Supply Chain in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474.003, Compromise Software Supply Chain, or mobile ATT&CK. Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.
Analyze MITRE ATT&CK T1474 Supply Chain Compromise in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1474, Supply Chain Compromise, or mobile ATT&CK. Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
Analyze MITRE ATT&CK T1481.001 Dead Drop Resolver in the mobile matrix. Use for TTP triage, detection engineering, hunting, defensive emulation planning, mitigations, incident response mapping, ATT&CK coverage, or questions mentioning T1481.001, Dead Drop Resolver, or mobile ATT&CK. Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.