Adversaries may establish persistence by executing malicious content triggered by a file type association.
Langue du texte source : anglais
Menu
Skills dans ce dépôt
SkillsMP a collecté 7 442 skills depuis CyberStrikeus/CyberStrike. Ouvrez un skill pour examiner sa source et ses détails.
CyberStrikeus/CyberStrikeAffichage de 40 skills collectés sur 7 442.
Adversaries may establish persistence by executing malicious content triggered by a file type association.
Langue du texte source : anglais
Adversaries may establish persistence by executing malicious content triggered by user inactivity.
Langue du texte source : anglais
Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
Langue du texte source : anglais
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell.
Langue du texte source : anglais
Adversaries may establish persistence by executing malicious content triggered by an interrupt signal.
Langue du texte source : anglais
Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries.
Langue du texte source : anglais
Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.
Langue du texte source : anglais
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features.
Langue du texte source : anglais
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes.
Langue du texte source : anglais
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.
Langue du texte source : anglais
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.
Langue du texte source : anglais
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers.
Langue du texte source : anglais
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.
Langue du texte source : anglais
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond).
Langue du texte source : anglais
Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.
Langue du texte source : anglais
Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.
Langue du texte source : anglais
Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events.
Langue du texte source : anglais
An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.
Langue du texte source : anglais
Adversaries may bypass UAC mechanisms to elevate process privileges on system.
Langue du texte source : anglais
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges.
Langue du texte source : anglais
Adversaries may leverage the <code>AuthorizationExecuteWithPrivileges</code> API to escalate privileges by prompting the user for credentials.
Langue du texte source : anglais
Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.
Langue du texte source : anglais
Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions.
Langue du texte source : anglais
Adversaries may break out of a container or virtualized environment to gain access to the underlying host.
Langue du texte source : anglais
Adversaries may directly access a volume to bypass file access controls and file system monitoring.
Langue du texte source : anglais
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
Langue du texte source : anglais
Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
Langue du texte source : anglais
Adversaries may perform software packing or virtual machine software protection to conceal their code.
Langue du texte source : anglais
Adversaries may use steganography techniques in order to prevent the detection of hidden information.
Langue du texte source : anglais
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code.
Langue du texte source : anglais
Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed.
Langue du texte source : anglais
Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.
Langue du texte source : anglais
Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis.
Langue du texte source : anglais
Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information.
Langue du texte source : anglais
Adversaries may embed payloads within other files to conceal malicious content from defenses.
Langue du texte source : anglais
Adversaries may obfuscate content during command execution to impede detection.
Langue du texte source : anglais
Adversaries may store data in "fileless" formats to conceal malicious activity from defenses.
Langue du texte source : anglais
Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files.
Langue du texte source : anglais
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
Langue du texte source : anglais
Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection.
Langue du texte source : anglais