Skip to main content

이 저장소의 skills

CyberStrikeus/CyberStrike - 84페이지

SkillsMP는 CyberStrikeus/CyberStrike에서 7,442개의 skill을 수집했습니다. skill을 열어 소스와 세부 정보를 확인하세요.

CyberStrikeus/CyberStrike

수집된 skill 7,442개 중 40개를 표시합니다.

직업 분류
네트워크·컴퓨터 시스템 관리자
설명

Ensure HTTP Strict Transport Security (HSTS) is enabled (Manual)

원문 언어: 영어

업데이트
직업 분류
네트워크·컴퓨터 시스템 관리자
설명

Ensure upstream server traffic is authenticated with a client certificate (Manual)

원문 언어: 영어

업데이트
직업 분류
네트워크·컴퓨터 시스템 관리자
설명

Ensure allow and deny filters limit access to specific IP addresses (Manual)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Ensure only approved HTTP methods are allowed (Manual)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Ensure timeout values for reading the client header and body are set correctly (Manual)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Ensure the maximum request body size is set correctly (Manual)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Ensure the maximum buffer size for URIs is defined (Manual)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Ensure the number of connections per IP address is limited (Manual)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Ensure rate limits by IP address are set (Manual)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Ensure X-Content-Type-Options header is configured and enabled (Manual)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Ensure that Content Security Policy (CSP) is enabled and configured properly (Manual)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Ensure the Referrer Policy is enabled and configured properly (Manual)

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may gather information about the physical process state.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may automate collection of industrial environment information using tools or scripts.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries with privileged network access may seek to modify network traffic in real time using adversary-in-the-middle (AiTM) attacks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may attempt to upload a program from a PLC to gather information about an industrial process.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may attempt to perform screen capture of devices in the control system environment.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may collect point and tag values to gain a more comprehensive understanding of the process environment.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may gather information about a PLCs or controllers current operating mode.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may seek to capture process values related to the inputs and outputs of a PLC.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may target and collect data from local system sources, such as file systems, configuration files, or local databases.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may use a connection proxy to direct network traffic between systems or act as an intermediary for network communications.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may communicate over a commonly used port to bypass firewalls or network detection systems and to blend in with normal network activity, to avoid more detailed inspection.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may perform network connection enumeration to discover information about device communication patterns.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Network sniffing is the practice of using a network interface on a computer system to monitor or capture information regardless of whether it is the specified destination for the information.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may attempt to get a listing of other systems by IP address, hostname, or other logical identifier on a network that may be used for subsequent Lateral Movement or Discovery techniques.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may seek to capture radio frequency (RF) communication used for remote control and reporting in distributed environments.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

An adversary may attempt to get detailed information about remote systems and their peripherals, such as make/model, role, and configuration.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to evade detection.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may use masquerading to disguise a malicious application or executable as another file, to avoid operator and engineer suspicion.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may deploy rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may spoof reporting messages in control system environments for evasion and to impair process control.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may attempt to remove indicators of their presence on a system in an effort to cover their tracks.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may utilize command-line interfaces (CLIs) to interact with systems and execute commands.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may modify the tasking of a controller to allow for the execution of their own programs.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may attempt to gain access to a machine via a Graphical User Interface (GUI) to enhance execution capabilities.

원문 언어: 영어

업데이트
직업 분류
정보 보안 분석가
설명

Adversaries may directly interact with the native OS application programming interface (API) to access system functions.

원문 언어: 영어

업데이트
수집된 skill 7,442개 중 40개를 표시합니다.