Adversaries may establish persistence by executing malicious content triggered by a file type association.
Idioma do texto original: inglês
Menu
Skills neste repositório
O SkillsMP coletou 7.442 skills de CyberStrikeus/CyberStrike. Abra uma skill para revisar a origem e os detalhes.
CyberStrikeus/CyberStrikeMostrando 40 de 7.442 skills coletadas.
Adversaries may establish persistence by executing malicious content triggered by a file type association.
Idioma do texto original: inglês
Adversaries may establish persistence by executing malicious content triggered by user inactivity.
Idioma do texto original: inglês
Adversaries may establish persistence and elevate privileges by executing malicious content triggered by a Windows Management Instrumentation (WMI) event subscription.
Idioma do texto original: inglês
Adversaries may establish persistence through executing malicious commands triggered by a user’s shell.
Idioma do texto original: inglês
Adversaries may establish persistence by executing malicious content triggered by an interrupt signal.
Idioma do texto original: inglês
Adversaries may establish persistence by executing malicious content triggered by the execution of tainted binaries.
Idioma do texto original: inglês
Adversaries may establish persistence by executing malicious content triggered by Netsh Helper DLLs.
Idioma do texto original: inglês
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features.
Idioma do texto original: inglês
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppCert DLLs loaded into processes.
Idioma do texto original: inglês
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by AppInit DLLs loaded into processes.
Idioma do texto original: inglês
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by application shims.
Idioma do texto original: inglês
Adversaries may establish persistence and/or elevate privileges by executing malicious content triggered by Image File Execution Options (IFEO) debuggers.
Idioma do texto original: inglês
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by PowerShell profiles.
Idioma do texto original: inglês
Adversaries may gain persistence and elevate privileges by executing malicious content triggered by the Event Monitor Daemon (emond).
Idioma do texto original: inglês
Adversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.
Idioma do texto original: inglês
Adversaries may establish persistence and elevate privileges by using an installer to trigger the execution of malicious content.
Idioma do texto original: inglês
Adversaries may establish persistence and/or elevate privileges using system mechanisms that trigger execution based on specific events.
Idioma do texto original: inglês
An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context.
Idioma do texto original: inglês
Adversaries may bypass UAC mechanisms to elevate process privileges on system.
Idioma do texto original: inglês
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges.
Idioma do texto original: inglês
Adversaries may leverage the <code>AuthorizationExecuteWithPrivileges</code> API to escalate privileges by prompting the user for credentials.
Idioma do texto original: inglês
Adversaries may abuse permission configurations that allow them to gain temporarily elevated access to cloud resources.
Idioma do texto original: inglês
Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions.
Idioma do texto original: inglês
Adversaries may break out of a container or virtualized environment to gain access to the underlying host.
Idioma do texto original: inglês
Adversaries may directly access a volume to bypass file access controls and file system monitoring.
Idioma do texto original: inglês
Adversaries may use rootkits to hide the presence of programs, files, network connections, services, drivers, and other system components.
Idioma do texto original: inglês
Adversaries may use binary padding to add junk data and change the on-disk representation of malware.
Idioma do texto original: inglês
Adversaries may perform software packing or virtual machine software protection to conceal their code.
Idioma do texto original: inglês
Adversaries may use steganography techniques in order to prevent the detection of hidden information.
Idioma do texto original: inglês
Adversaries may attempt to make payloads difficult to discover and analyze by delivering files to victims as uncompiled code.
Idioma do texto original: inglês
Adversaries may remove indicators from tools if they believe their malicious tool was detected, quarantined, or otherwise curtailed.
Idioma do texto original: inglês
Adversaries may smuggle data and files past content filters by hiding malicious payloads inside of seemingly benign HTML files.
Idioma do texto original: inglês
Adversaries may obfuscate then dynamically resolve API functions called by their malware in order to conceal malicious functionalities and impair defensive analysis.
Idioma do texto original: inglês
Adversaries may attempt to make a payload difficult to analyze by removing symbols, strings, and other human readable information.
Idioma do texto original: inglês
Adversaries may embed payloads within other files to conceal malicious content from defenses.
Idioma do texto original: inglês
Adversaries may obfuscate content during command execution to impede detection.
Idioma do texto original: inglês
Adversaries may store data in "fileless" formats to conceal malicious activity from defenses.
Idioma do texto original: inglês
Adversaries may smuggle commands to download malicious payloads past content filters by hiding them within otherwise seemingly benign windows shortcut files.
Idioma do texto original: inglês
Adversaries may encrypt or encode files to obfuscate strings, bytes, and other specific patterns to impede detection.
Idioma do texto original: inglês
Adversaries may utilize polymorphic code (also known as metamorphic or mutating code) to evade detection.
Idioma do texto original: inglês