Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.
Idioma del texto original: inglés
Menú
Skills en este repositorio
SkillsMP ha recopilado 7442 skills de CyberStrikeus/CyberStrike. Abre una skill para revisar su origen y sus detalles.
CyberStrikeus/CyberStrikeMostrando 40 de 7442 skills recopiladas.
Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.
Idioma del texto original: inglés
Adversaries may search for common password storage locations to obtain user credentials.
Idioma del texto original: inglés
Adversaries may patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.
Idioma del texto original: inglés
Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process to acquire user credentials as they are validated.
Idioma del texto original: inglés
Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.
Idioma del texto original: inglés
Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices.
Idioma del texto original: inglés
An adversary may abuse Active Directory authentication encryption properties to gain access to credentials on Windows systems.
Idioma del texto original: inglés
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Idioma del texto original: inglés
Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credent...
Idioma del texto original: inglés
Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
Idioma del texto original: inglés
Adversaries may disable or modify conditional access policies to enable persistent access to compromised accounts.
Idioma del texto original: inglés
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts.
Idioma del texto original: inglés
By responding to LLMNR/NBT-NS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system.
Idioma del texto original: inglés
Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices.
Idioma del texto original: inglés
Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network.
Idioma del texto original: inglés
Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as Network Sniffing, Transmitted Da...
Idioma del texto original: inglés
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Trans...
Idioma del texto original: inglés
Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket.
Idioma del texto original: inglés
Adversaries who have the password hash of a target service account (e.g.
Idioma del texto original: inglés
Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.
Idioma del texto original: inglés
Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by Password Cracking Kerberos messages.
Idioma del texto original: inglés
Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache).
Idioma del texto original: inglés
Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket.
Idioma del texto original: inglés
Adversaries may forge web cookies that can be used to gain access to web applications or Internet services.
Idioma del texto original: inglés
An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate.
Idioma del texto original: inglés
Adversaries may forge credential materials that can be used to gain access to web applications or Internet services.
Idioma del texto original: inglés
Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
Idioma del texto original: inglés
Adversaries may steal or forge certificates used for authentication to access remote systems or resources.
Idioma del texto original: inglés
Adversaries may try to gather information about registered local system services.
Idioma del texto original: inglés
Adversaries may attempt to get a listing of open application windows.
Idioma del texto original: inglés
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
Idioma del texto original: inglés
Adversaries may check for Internet connectivity on compromised systems.
Idioma del texto original: inglés
Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
Idioma del texto original: inglés
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
Idioma del texto original: inglés
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
Idioma del texto original: inglés
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
Idioma del texto original: inglés
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
Idioma del texto original: inglés
Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
Idioma del texto original: inglés
Adversaries may attempt to get information about running processes on a system.
Idioma del texto original: inglés
Adversaries may attempt to find local system groups and permission settings.
Idioma del texto original: inglés