Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.
原文语言:英语
菜单
这个仓库中的 skills
SkillsMP 已收集 CyberStrikeus/CyberStrike 中的 7,442 个 Skill。打开任一 Skill 可查看来源和详情。
CyberStrikeus/CyberStrike已展示 40 / 7,442 个已收集 Skill。
Adversaries may abuse mmc.exe to proxy execution of malicious .msc files.
原文语言:英语
Adversaries may abuse components of the Electron framework to execute malicious code.
原文语言:英语
Adversaries may bypass process and/or signature-based defenses by proxying execution of malicious content with signed, or otherwise trusted, binaries.
原文语言:英语
Adversaries may bypass application control and obscure execution of code by embedding scripts inside XSL files.
原文语言:英语
Adversaries may create or modify references in user document templates to conceal malicious code or force authentication attempts.
原文语言:英语
Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
原文语言:英语
Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files.
原文语言:英语
Adversaries may environmentally key payloads or other features of malware to evade defenses and constraint execution to a specific target environment.
原文语言:英语
Adversaries may constrain execution or actions based on the presence of a mutex associated with malware.
原文语言:英语
Adversaries may use execution guardrails to constrain execution or actions based on adversary supplied and environment specific conditions that are expected to be present on the target.
原文语言:英语
Adversaries may modify Group Policy Objects (GPOs) to subvert the intended discretionary access controls for a domain, usually with the intention of escalating privileges on the domain.
原文语言:英语
Adversaries may add new domain trusts, modify the properties of existing domain trusts, or otherwise change the configuration of trust relationships between domains and tenants to evade defenses an...
原文语言:英语
Adversaries may modify the configuration settings of a domain or identity tenant to evade defenses and/or escalate privileges in centrally managed environments.
原文语言:英语
Adversaries may employ various system checks to detect and avoid virtualization and analysis environments.
原文语言:英语
Adversaries may employ various user activity checks to detect and avoid virtualization and analysis environments.
原文语言:英语
Adversaries may employ various time-based methods to detect virtualization and analysis environments, particularly those that attempt to manipulate time mechanisms to simulate longer elapses of time.
原文语言:英语
Adversaries may employ various means to detect and avoid virtualization and analysis environments.
原文语言:英语
Adversaries may create cloud instances in unused geographic service regions in order to evade detection.
原文语言:英语
Adversaries may abuse the ROM Monitor (ROMMON) by loading an unauthorized firmware with adversary code to provide persistent access and manipulate device behavior that is difficult to detect.
原文语言:英语
Adversaries may abuse netbooting to load an unauthorized network device operating system from a Trivial File Transfer Protocol (TFTP) server.
原文语言:英语
Adversaries may abuse Pre-OS Boot mechanisms as a way to establish persistence on a system.
原文语言:英语
Adversaries can manipulate or abuse the Transparency, Consent, & Control (TCC) service or database to grant malicious executables elevated permissions.
原文语言:英语
Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems.
原文语言:英语
Adversaries may “pass the hash” using stolen password hashes to move laterally within an environment, bypassing normal system access controls.
原文语言:英语
Adversaries may “pass the ticket” using stolen Kerberos tickets to move laterally within an environment, bypassing normal system access controls.
原文语言:英语
Adversaries can use stolen session cookies to authenticate to web applications and services.
原文语言:英语
Adversaries may use alternate authentication material, such as password hashes, Kerberos tickets, and application access tokens, in order to move laterally within an environment and bypass normal s...
原文语言:英语
Adversaries may modify file attributes and subvert Gatekeeper functionality to evade user prompts and execute untrusted programs.
原文语言:英语
Adversaries may create, acquire, or steal code signing materials to sign their malware or tools.
原文语言:英语
Adversaries may tamper with SIP and trust provider components to mislead the operating system and application control tools when conducting signature validation checks.
原文语言:英语
Adversaries may install a root certificate on a compromised system to avoid warnings when connecting to adversary controlled web servers.
原文语言:英语
Adversaries may abuse specific file formats to subvert Mark-of-the-Web (MOTW) controls.
原文语言:英语
Adversaries may modify code signing policies to enable execution of unsigned or self-signed code.
原文语言:英语
Adversaries may undermine security controls that will either warn users of untrusted activity or prevent execution of untrusted programs.
原文语言:英语
Adversaries may modify and/or disable security tools to avoid possible detection of their malware/tools and activities.
原文语言:英语
Adversaries may disable Windows event logging to limit data that can be leveraged for detections and audits.
原文语言:英语
Adversaries may impair command history logging to hide commands they run on a compromised system.
原文语言:英语
Adversaries may disable or modify system firewalls in order to bypass controls limiting network usage.
原文语言:英语
An adversary may attempt to block indicators or events typically captured by sensors from being gathered and analyzed.
原文语言:英语
Adversaries may disable or modify a firewall within a cloud environment to bypass controls that limit access to cloud resources.
原文语言:英语