Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic.
Langue du texte source : anglais
Menu
Skills dans ce dépôt
SkillsMP a collecté 7 442 skills depuis CyberStrikeus/CyberStrike. Ouvrez un skill pour examiner sa source et ses détails.
CyberStrikeus/CyberStrikeAffichage de 40 skills collectés sur 7 442.
Adversaries may communicate using application layer protocols to avoid detection/network filtering by blending in with existing traffic.
Langue du texte source : anglais
Adversaries may use an existing, legitimate external Web service to host information that points to additional command and control (C2) infrastructure.
Langue du texte source : anglais
Adversaries may use an existing, legitimate external Web service channel as a means for sending commands to and receiving output from a compromised system.
Langue du texte source : anglais
Adversaries may use an existing, legitimate external Web service channel as a means for sending commands to a compromised system without receiving return output.
Langue du texte source : anglais
Adversaries may use an existing, legitimate external Web service as a means for relaying data to/from a compromised system.
Langue du texte source : anglais
Adversaries may generate network traffic using a protocol and port pairing that are typically not associated.
Langue du texte source : anglais
Adversaries may employ a known symmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
Langue du texte source : anglais
Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
Langue du texte source : anglais
Adversaries may use SSL Pinning to protect the C2 traffic from being intercepted and analyzed.
Langue du texte source : anglais
Adversaries may explicitly employ a known encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
Langue du texte source : anglais
Adversaries may transfer tools or other files from an external system onto a compromised device to facilitate follow-on actions.
Langue du texte source : anglais
Adversaries may use Domain Generation Algorithms (DGAs) to procedurally generate domain names for uses such as command and control communication or malicious application distribution.
Langue du texte source : anglais
Adversaries may dynamically establish connections to command and control infrastructure to evade common detections and remediations.
Langue du texte source : anglais
Adversaries may communicate with compromised devices using out of band data streams.
Langue du texte source : anglais
Adversaries may use legitimate remote access software, such as `VNC`, `TeamViewer`, `AirDroid`, `AirMirror`, etc., to establish an interactive command and control channel to target mobile devices.
Langue du texte source : anglais
Adversaries may abuse task scheduling functionality to facilitate initial or recurring execution of malicious code.
Langue du texte source : anglais
Adversaries may abuse Unix shell commands and scripts for execution.
Langue du texte source : anglais
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
Langue du texte source : anglais
Adversaries may exploit software vulnerabilities in client applications to execute code.
Langue du texte source : anglais
Adversaries may gain access to a system through a user visiting a website over the normal course of browsing.
Langue du texte source : anglais
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network.
Langue du texte source : anglais
Adversaries may manipulate software dependencies and development tools prior to receipt by a final consumer for the purpose of data or system compromise.
Langue du texte source : anglais
Adversaries may manipulate application software prior to receipt by a final consumer for the purpose of data or system compromise.
Langue du texte source : anglais
Adversaries may manipulate hardware components in products prior to receipt by a final consumer for the purpose of data or system compromise.
Langue du texte source : anglais
Adversaries may manipulate products or product delivery mechanisms prior to receipt by a final consumer for the purpose of data or system compromise.
Langue du texte source : anglais
Adversaries may breach or otherwise leverage organizations who have access to intended victims.
Langue du texte source : anglais
Adversaries may physically introduce computer accessories, networking hardware, or other computing devices into a system or network that can be used as a vector to gain access.
Langue du texte source : anglais
Adversaries may send spearphishing emails with a malicious attachment in an attempt to gain access to victim systems.
Langue du texte source : anglais
Adversaries may send spearphishing emails with a malicious link in an attempt to gain access to victim systems.
Langue du texte source : anglais
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems.
Langue du texte source : anglais
Adversaries may use voice communications to ultimately gain access to victim systems.
Langue du texte source : anglais
Adversaries may send phishing messages to gain access to victim systems.
Langue du texte source : anglais
Adversaries may gain access and continuously communicate with victims by injecting malicious content into systems through online network traffic.
Langue du texte source : anglais
Adversaries may gain initial access to target systems by connecting to wireless networks.
Langue du texte source : anglais
Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
Langue du texte source : anglais
Adversaries may abuse the at utility to perform task scheduling for initial or recurring execution of malicious code.
Langue du texte source : anglais
Adversaries may abuse the <code>cron</code> utility to perform task scheduling for initial or recurring execution of malicious code.
Langue du texte source : anglais
Adversaries may abuse the Windows Task Scheduler to perform task scheduling for initial or recurring execution of malicious code.
Langue du texte source : anglais
Adversaries may abuse systemd timers to perform task scheduling for initial or recurring execution of malicious code.
Langue du texte source : anglais
Adversaries may abuse task scheduling functionality provided by container orchestration tools such as Kubernetes to schedule deployment of containers configured to execute malicious code.
Langue du texte source : anglais