Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.
Langue du texte source : anglais
Menu
Skills dans ce dépôt
SkillsMP a collecté 7 442 skills depuis CyberStrikeus/CyberStrike. Ouvrez un skill pour examiner sa source et ses détails.
CyberStrikeus/CyberStrikeAffichage de 40 skills collectés sur 7 442.
Adversaries may acquire credentials from cloud-native secret management solutions such as AWS Secrets Manager, GCP Secret Manager, Azure Key Vault, and Terraform Vault.
Langue du texte source : anglais
Adversaries may search for common password storage locations to obtain user credentials.
Langue du texte source : anglais
Adversaries may patch the authentication process on a domain controller to bypass the typical authentication mechanisms and enable access to accounts.
Langue du texte source : anglais
Adversaries may register malicious password filter dynamic link libraries (DLLs) into the authentication process to acquire user credentials as they are validated.
Langue du texte source : anglais
Adversaries may modify pluggable authentication modules (PAM) to access user credentials or enable otherwise unwarranted access to accounts.
Langue du texte source : anglais
Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices.
Langue du texte source : anglais
An adversary may abuse Active Directory authentication encryption properties to gain access to credentials on Windows systems.
Langue du texte source : anglais
Adversaries may disable or modify multi-factor authentication (MFA) mechanisms to enable persistent access to compromised accounts.
Langue du texte source : anglais
Adversaries may patch, modify, or otherwise backdoor cloud authentication processes that are tied to on-premises user identities in order to bypass typical authentication mechanisms, access credent...
Langue du texte source : anglais
Adversaries may register malicious network provider dynamic link libraries (DLLs) to capture cleartext user credentials during the authentication process.
Langue du texte source : anglais
Adversaries may disable or modify conditional access policies to enable persistent access to compromised accounts.
Langue du texte source : anglais
Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts.
Langue du texte source : anglais
By responding to LLMNR/NBT-NS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system.
Langue du texte source : anglais
Adversaries may poison Address Resolution Protocol (ARP) caches to position themselves between the communication of two or more networked devices.
Langue du texte source : anglais
Adversaries may redirect network traffic to adversary-owned systems by spoofing Dynamic Host Configuration Protocol (DHCP) traffic and acting as a malicious DHCP server on the victim network.
Langue du texte source : anglais
Adversaries may host seemingly genuine Wi-Fi access points to deceive users into connecting to malicious networks as a way of supporting follow-on behaviors such as Network Sniffing, Transmitted Da...
Langue du texte source : anglais
Adversaries may attempt to position themselves between two or more networked devices using an adversary-in-the-middle (AiTM) technique to support follow-on behaviors such as Network Sniffing, Trans...
Langue du texte source : anglais
Adversaries who have the KRBTGT account password hash may forge Kerberos ticket-granting tickets (TGT), also known as a golden ticket.
Langue du texte source : anglais
Adversaries who have the password hash of a target service account (e.g.
Langue du texte source : anglais
Adversaries may abuse a valid Kerberos ticket-granting ticket (TGT) or sniff network traffic to obtain a ticket-granting service (TGS) ticket that may be vulnerable to Brute Force.
Langue du texte source : anglais
Adversaries may reveal credentials of accounts that have disabled Kerberos preauthentication by Password Cracking Kerberos messages.
Langue du texte source : anglais
Adversaries may attempt to steal Kerberos tickets stored in credential cache files (or ccache).
Langue du texte source : anglais
Adversaries may attempt to subvert Kerberos authentication by stealing or forging Kerberos tickets to enable Pass the Ticket.
Langue du texte source : anglais
Adversaries may forge web cookies that can be used to gain access to web applications or Internet services.
Langue du texte source : anglais
An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate.
Langue du texte source : anglais
Adversaries may forge credential materials that can be used to gain access to web applications or Internet services.
Langue du texte source : anglais
Adversaries may attempt to bypass multi-factor authentication (MFA) mechanisms and gain access to accounts by generating MFA requests sent to users.
Langue du texte source : anglais
Adversaries may steal or forge certificates used for authentication to access remote systems or resources.
Langue du texte source : anglais
Adversaries may try to gather information about registered local system services.
Langue du texte source : anglais
Adversaries may attempt to get a listing of open application windows.
Langue du texte source : anglais
Adversaries may interact with the Windows Registry to gather information about the system, configuration, and installed software.
Langue du texte source : anglais
Adversaries may check for Internet connectivity on compromised systems.
Langue du texte source : anglais
Adversaries may search for information about Wi-Fi networks, such as network names and passwords, on compromised systems.
Langue du texte source : anglais
Adversaries may look for details about the network configuration and settings, such as IP and/or MAC addresses, of systems they access or through information discovery of remote systems.
Langue du texte source : anglais
Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for Lateral Movement from the current system.
Langue du texte source : anglais
Adversaries may attempt to identify the primary user, currently logged in user, set of users that commonly uses a system, or whether a user is actively using the system.
Langue du texte source : anglais
Adversaries may attempt to get a listing of services running on remote hosts and local network infrastructure devices, including those that may be vulnerable to remote software exploitation.
Langue du texte source : anglais
Adversaries may attempt to get a listing of network connections to or from the compromised system they are currently accessing or from remote systems by querying for information over the network.
Langue du texte source : anglais
Adversaries may attempt to get information about running processes on a system.
Langue du texte source : anglais
Adversaries may attempt to find local system groups and permission settings.
Langue du texte source : anglais