Meta tags:
Headings (most frequently used words):
att, ck, matrix, for, enterprise,
Text of the page (most frequently used words):
cloud (76), discovery (68), system (62), network (60), data (56), accounts (56), execution (48), and (47), service (47), authentication (44), hijacking (42), file (42), domain (40), process (38), techniques (36), modify (34), account (32), access (32), exfiltration (32), injection (32), software (31), local (30), services (30), windows (30), web (28), email (26), remote (26), dll (26), modification (26), application (24), container (24), over (22), code (22), permissions (22), path (22), information (20), device (20), token (20), credentials (20), command (20), additional (20), for (19), the (18), manipulation (18), protocol (18), capture (18), from (18), spearphishing (18), password (18), boot (18), policy (17), search (17), storage (16), proxy (16), dns (16), api (16), registry (16), image (16), logon (16), compromise (16), att (15), groups (14), exploitation (14), content (14), scheduled (14), multi (14), dynamic (14), media (14), credential (14), component (14), interception (14), create (14), task (14), startup (14), server (14), tools (13), history (13), resource (12), firmware (12), transfer (12), non (12), port (12), management (12), spoofing (12), checks (12), trust (12), shell (12), certificates (12), memory (12), provider (12), modules (12), disable (12), clear (12), event (12), script (12), default (12), link (12), weakness (12), job (12), all (10), encrypted (10), hardware (10), tool (10), infrastructure (10), input (10), collection (10), configuration (10), poisoning (10), object (10), time (10), user (10), security (10), instance (10), keys (10), files (10), factor (10), host (10), control (10), systemd (10), extensions (10), roles (10), malicious (10), victim (10), based (9), group (9), domains (8), flood (8), external (8), internal (8), removal (8), traffic (8), communication (8), resolution (8), impersonation (8), removable (8), protocols (8), applications (8), browser (8), session (8), archive (8), via (8), library (8), name (8), ssh (8), model (8), evasion (8), virtual (8), log (8), window (8), steal (8), identity (8), encryption (8), controller (8), signing (8), firewall (8), valid (8), social (8), thread (8), executable (8), malware (8), installer (8), rules (8), hidden (8), with (8), dlls (8), helper (8), launch (8), items (8), scripts (8), login (8), autostart (8), digital (8), gather (8), scanning (8), filters (7), private (7), mitre (6), enterprise (6), compute (6), direct (6), theft (6), exhaustion (6), disk (6), wipe (6), defacement (6), triggered (6), socket (6), knocking (6), signaling (6), standard (6), encoding (6), through (6), shared (6), drive (6), databases (6), repositories (6), smb (6), ticket (6), connection (6), driver (6), forge (6), proc (6), lsass (6), conditional (6), policies (6), hybrid (6), reversible (6), pluggable (6), filter (6), bypass (6), configurations (6), linux (6), trusted (6), utilities (6), binary (6), smuggling (6), masquerade (6), run (6), bits (6), jobs (6), orchestration (6), timers (6), cron (6), python (6), powershell (6), unix (6), instrumentation (6), agent (6), active (6), outlook (6), office (6), serverless (6), administration (6), cli (6), supply (6), chain (6), capabilities (6), open (6), cookie (5), ics (5), mobile (5), none (5), hide (5), adversary (5), location (5), development (5), threat (5), use (4), components (4), denial (4), stored (4), impact (4), deletion (4), repository (4), physical (4), medium (4), channel (4), asymmetric (4), symmetric (4), automated (4), desktop (4), ide (4), tunneling (4), layer (4), stage (4), channels (4), cryptography (4), generation (4), steganography (4), junk (4), obfuscation (4), hooking (4), portal (4), gui (4), keylogging (4), staging (4), relationship (4), dump (4), audio (4), evil (4), twin (4), dhcp (4), arp (4), cache (4), relay (4), middle (4), pass (4), deployment (4), replication (4), connections (4), lateral (4), activity (4), virtualization (4), sandbox (4), query (4), sniffing (4), share (4), directory (4), debugger (4), tickets (4), etc (4), secrets (4), manager (4), stores (4), space (4), install (4), certificate (4), downgrade (4), mac (4), defense (4), impairment (4), tenant (4), logs (4), jamplus (4), clickonce (4), msbuild (4), developer (4), template (4), html (4), exclusion (4), listplanting (4), vdso (4), doppelgänging (4), hollowing (4), extra (4), ptrace (4), calls (4), asynchronous (4), procedure (4), call (4), portable (4), tftp (4), rommonkit (4), bootkit (4), pre (4), payloads (4), indicator (4), after (4), legitimate (4), persistence (4), appdomainmanager (4), kernelcallbacktable (4), cor_profiler (4), unquoted (4), order (4), environment (4), variable (4), linker (4), dylib (4), hijack (4), flow (4), attributes (4), stealth (4), sid (4), parent (4), pid (4), make (4), impersonate (4), privilege (4), escalation (4), hooks (4), udev (4), packages (4), emond (4), profile (4), options (4), shimming (4), appinit (4), appcert (4), accessibility (4), features (4), netsh (4), lc_load_dylib (4), addition (4), trap (4), subscription (4), screensaver (4), change (4), association (4), daemon (4), hook (4), initialization (4), setup (4), xdg (4), entries (4), print (4), processors (4), monitors (4), shortcut (4), opened (4), kernel (4), support (4), winlogon (4), providers (4), package (4), folder (4), cluster (4), registration (4), authorized (4), delegate (4), elevated (4), sudo (4), client (4), visual (4), dependencies (4), voice (4), attachment (4), phishing (4), public (4), target (4), upload (4), exploits (4), botnet (4), acquire (4), websites (4), technical (4), identify (4), business (4), addresses (4), preferences (3), cti (3), defenses (3), sub (3), tactics (3), page (3), develop (3), person (3), faq (3), 2026 (2), corporation (2), are (2), resources (2), reference (2), campaigns (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), matrices (2), core (2), objects (2), shutdown (2), reboot (2), stop (2), sms (2), pumping (2), bandwidth (2), reflection (2), amplification (2), inhibit (2), recovery (2), corruption (2), financial (2), endpoint (2), bombing (2), structure (2), runtime (2), transmitted (2), lifecycle (2), destruction (2), webhook (2), text (2), sites (2), usb (2), bluetooth (2), other (2), unencrypted (2), alternative (2), size (2), limits (2), duplication (2), one (2), way (2), bidirectional (2), dead (2), drop (2), resolver (2), fronting (2), hop (2), ingress (2), fallback (2), calculation (2), algorithms (2), fast (2), flux (2), publish (2), subscribe (2), mail (2), video (2), screen (2), forwarding (2), rule (2), staged (2), messaging (2), customer (2), sharepoint (2), confluence (2), snmp (2), mib (2), clipboard (2), custom (2), method (2), utility (2), collected (2), hash (2), alternate (2), material (2), taint (2), vnc (2), distributed (2), admin (2), shares (2), rdp (2), machine (2), owner (2), internet (2), language (2), backup (2), permission (2), peripheral (2), enumeration (2), dashboard (2), chat (2), messages (2), metadata (2), unsecured (2), ccache (2), rep (2), roasting (2), kerberoasting (2), silver (2), golden (2), kerberos (2), passwd (2), shadow (2), filesystem (2), dcsync (2), cached (2), lsa (2), ntds (2), dumping (2), request (2), saml (2), tokens (2), cookies (2), forced (2), managers (2), browsers (2), securityd (2), keychain (2), stuffing (2), spraying (2), cracking (2), guessing (2), brute (2), force (2), crypto (2), reduce (2), key (2), weaken (2), mark (2), root (2), sip (2), gatekeeper (2), subvert (2), controls (2), safe (2), mode (2), rogue (2), prevent (2), logging (2), plist (2), address (2), translation (2), traversal (2), boundary (2), bridging (2), patch (2), hierarchy (2), revert (2), delete (2), snapshot (2), attack (2), audit (2), spoof (2), xsl (2), processing (2), unused (2), unsupported (2), regions (2), syncappvpublishingserver (2), pubprn (2), electron (2), mmc (2), mavinject (2), verclsid (2), rundll32 (2), regsvr32 (2), regsvcs (2), regasm (2), odbcconf (2), msiexec (2), mshta (2), installutil (2), cmstp (2), panel (2), compiled (2), engineering (2), selective (2), rootkit (2), reflective (2), loading (2), invisible (2), unicode (2), svg (2), insertion (2), compression (2), polymorphic (2), encoded (2), lnk (2), icon (2), fileless (2), embedded (2), stripped (2), compile (2), delivery (2), packing (2), padding (2), obfuscated (2), fingerprint (2), overwrite (2), arguments (2), break (2), trees (2), type (2), double (2), extension (2), filename (2), match (2), rename (2), right (2), left (2), override (2), invalid (2), signature (2), masquerading (2), indirect (2), relocate (2), mailbox (2), timestomp (2), extended (2), bind (2), mounts (2), exclusions (2), ignore (2), interrupts (2), argument (2), forking (2), hiding (2), vba (2), stomping (2), ntfs (2), users (2), directories (2), artifacts (2), mutual (2), environmental (2), keying (2), guardrails (2), volume (2), deobfuscate (2), decode (2), delay (2), build (2), escape (2), tcc (2), temporary (2), prompt (2), caching (2), setuid (2), setgid (2), abuse (2), elevation (2), mechanism (2), vsphere (2), installation (2), bundles (2), terminal (2), iis (2), transport (2), sql (2), procedures (2), power (2), settings (2), add (2), ins (2), home (2), forms (2), test (2), macros (2), implant (2), exclusive (2), integration (2), copy (2), paste (2), systemctl (2), launchctl (2), poisoned (2), pipeline (2), native (2), xpc (2), exchange (2), inter (2), esxi (2), deploy (2), hypervisor (2), lua (2), autohotkey (2), autoit (2), javascript (2), basic (2), applescript (2), scripting (2), interpreter (2), networks (2), additions (2), exploit (2), facing (2), seo (2), artificial (2), intelligence (2), vulnerabilities (2), obtain (2), written (2), generate (2), establish (2), devices (2), malvertising (2), owned (2), vendor (2), engines (2), scan (2), cdns (2), whois (2), passive (2), purchase (2), intel (2), vendors (2), closed (2), sources (2), tempo (2), relationships (2), determine (2), locations (2), org (2), appliances (2), topology (2), properties (2), employee (2), names (2), wordlist (2), vulnerability (2), blocks (2), movement (2), initial (2), reconnaissance (2), side (2), matrix (2), world (2), more (2), cybersecurity (2), knowledge (2), base (2), toggle (2), dropdown (2), blog (2), contribute (2), get (2), started (2), ckcon (2), 2015, registered, trademarks, website, changelog, privacy, terms, contact, reset, show, flat, layout, creation, fulfilling, its, mission, solve, problems, safer, bringing, communities, together, effective, available, any, organization, charge, globally, accessible, real, observations, used, foundation, specific, models, methodologies, sector, government, product, community, asset, campaign, mitigation, source, technique, tactic, random, take, tour, join, october, mclean, hotel, details, can, found, register, here, benefactors, legal, branding, updates, version, engage, advisory, council, learn, about, detections,
Text of the page (random words):
modification port monitors print processors xdg autostart entries active setup login items boot or logon initialization scripts 5 logon script windows login hook network logon script rc scripts startup items cloud application integration compromise host software binary create account 3 local account domain account cloud account create or modify system process 5 launch agent systemd service windows service launch daemon container service event triggered execution 18 change default file association screensaver windows management instrumentation event subscription unix shell configuration modification trap lc_load_dylib addition netsh helper dll accessibility features appcert dlls appinit dlls application shimming image file execution options injection powershell profile emond component object model hijacking installer packages udev rules python startup hooks exclusive control external remote services implant internal image modify authentication process 9 domain controller authentication password filter dll pluggable authentication modules network device authentication reversible encryption multi factor authentication hybrid identity network provider dll conditional access policies modify registry office application startup 6 office template macros office test outlook forms outlook home page outlook rules add ins power settings pre os boot 5 system firmware component firmware bootkit rommonkit tftp boot scheduled task job 5 at cron scheduled task systemd timers container orchestration job server software component 6 sql stored procedures transport agent web shell iis components terminal services dll vsphere installation bundles software extensions 2 browser extensions ide extensions traffic signaling 2 port knocking socket filters valid accounts 4 default accounts domain accounts local accounts cloud accounts abuse elevation control mechanism 6 setuid and setgid bypass user account control sudo and sudo caching elevated execution with prompt temporary elevated cloud access tcc manipulation access token manipulation 5 token impersonation theft create process with token make and impersonate token parent pid spoofing sid history injection account manipulation 7 additional cloud credentials additional email delegate permissions additional cloud roles ssh authorized keys device registration additional container cluster roles additional local or domain groups boot or logon autostart execution 14 registry run keys startup folder authentication package time providers winlogon helper dll security support provider kernel modules and extensions re opened applications lsass driver shortcut modification port monitors print processors xdg autostart entries active setup login items boot or logon initialization scripts 5 logon script windows login hook network logon script rc scripts startup items create or modify system process 5 launch agent systemd service windows service launch daemon container service domain or tenant policy modification 2 group policy modification trust modification escape to host event triggered execution 18 change default file association screensaver windows management instrumentation event subscription unix shell configuration modification trap lc_load_dylib addition netsh helper dll accessibility features appcert dlls appinit dlls application shimming image file execution options injection powershell profile emond component object model hijacking installer packages udev rules python startup hooks exploitation for privilege escalation process injection 12 dynamic link library injection portable executable injection thread execution hijacking asynchronous procedure call thread local storage ptrace system calls proc memory extra window memory injection process hollowing process doppelgänging vdso hijacking listplanting scheduled task job 5 at cron scheduled task systemd timers container orchestration job valid accounts 4 default accounts domain accounts local accounts cloud accounts access token manipulation 5 token impersonation theft create process with token make and impersonate token parent pid spoofing sid history injection bits jobs build image on host debugger evasion delay execution deobfuscate decode files or information direct volume access execution guardrails 2 environmental keying mutual exclusion exploitation for stealth hide artifacts 14 hidden files and directories hidden users hidden window ntfs file attributes hidden file system run virtual instance vba stomping email hiding rules resource forking process argument spoofing ignore process interrupts file path exclusions bind mounts extended attributes hijack execution flow 12 dll dylib hijacking executable installer file permissions weakness dynamic linker hijacking path interception by path environment variable path interception by search order hijacking path interception by unquoted path services file permissions weakness services registry permissions weakness cor_profiler kernelcallbacktable appdomainmanager indicator removal 8 clear command history file deletion network share connection removal timestomp clear network connection history and configurations clear mailbox data clear persistence relocate malware indirect command execution masquerading 12 invalid code signature right to left override rename legitimate utilities masquerade task or service match legitimate resource name or location space after filename double file extension masquerade file type break process trees masquerade account name overwrite process arguments browser fingerprint obfuscated files or information 18 binary padding software packing steganography compile after delivery indicator removal from tools html smuggling dynamic api resolution stripped payloads embedded payloads command obfuscation fileless storage lnk icon smuggling encrypted encoded file polymorphic code compression junk code insertion svg smuggling invisible unicode pre os boot 5 system firmware component firmware bootkit rommonkit tftp boot process injection 12 dynamic link library injection portable executable injection thread execution hijacking asynchronous procedure call thread local storage ptrace system calls proc memory extra window memory injection process hollowing process doppelgänging vdso hijacking listplanting reflective code loading rootkit selective exclusion social engineering 2 impersonation email spoofing system binary proxy execution 14 compiled html file control panel cmstp installutil mshta msiexec odbcconf regsvcs regasm regsvr32 rundll32 verclsid mavinject mmc electron applications system script proxy execution 2 pubprn syncappvpublishingserver template injection traffic signaling 2 port knocking socket filters trusted developer utilities proxy execution 3 msbuild clickonce jamplus unused unsupported cloud regions valid accounts 4 default accounts domain accounts local accounts cloud accounts virtualization sandbox evasion 3 system checks user activity based checks time based checks xsl script processing disable or modify system firewall 3 cloud firewall network device firewall windows host firewall disable or modify tools 6 disable or modify windows event log disable or modify cloud log modify or spoof tool ui disable or modify linux audit system log clear windows event logs clear linux or mac system logs domain or tenant policy modification 2 group policy modification trust modification downgrade attack exploitation for defense impairment file and directory permissions modification 2 windows permissions linux and mac permissions modify authentication process 9 domain controller authentication password filter dll pluggable authentication modules network device authentication reversible encryption multi factor authentication hybrid identity network provider dll conditional access policies modify cloud compute infrastructure 5 create snapshot create cloud instance delete cloud instance revert cloud instance modify cloud compute configurations modify cloud resource hierarchy modify registry modify system image 2 patch system image downgrade system image network boundary bridging 1 network address translation traversal plist file modification prevent command history logging rogue domain controller safe mode boot subvert trust controls 6 gatekeeper bypass code signing sip and trust provider hijacking install root certificate mark of the web bypass code signing policy modification weaken encryption 2 reduce key space disable crypto hardware adversary in the middle 4 name resolution poisoning and smb relay arp cache poisoning dhcp spoofing evil twin brute force 4 password guessing password cracking password spraying credential stuffing credentials from password stores 6 keychain securityd memory credentials from web browsers windows credential manager password managers cloud secrets management stores exploitation for credential access forced authentication forge web credentials 2 web cookies saml tokens input capture 4 keylogging gui input capture web portal capture credential api hooking modify authentication process 9 domain controller authentication password filter dll pluggable authentication modules network device authentication reversible encryption multi factor authentication hybrid identity network provider dll conditional access policies multi factor authentication interception multi factor authentication request generation network sniffing os credential dumping 8 lsass memory security account manager ntds lsa secrets cached domain credentials dcsync proc filesystem etc passwd and etc shadow steal application access token steal or forge authentication certificates steal or forge kerberos tickets 5 golden ticket silver ticket kerberoasting as rep roasting ccache files steal web session cookie unsecured credentials 8 credentials in files credentials in registry shell history private keys cloud instance metadata api group policy preferences container api chat messages account discovery 4 local account domain account email account cloud account application window discovery browser information discovery cloud infrastructure discovery cloud service dashboard cloud service discovery cloud storage object discovery container and resource discovery debugger evasion device driver discovery domain trust discovery file and directory discovery group policy discovery local storage discovery log enumeration network service discovery network share discovery network sniffing password policy discovery peripheral device discovery permission groups discovery 3 local groups domain groups cloud groups process discovery query registry remote system discovery software discovery 2 security software discovery backup software discovery system information discovery system location discovery 1 system language discovery system network configuration discovery 2 internet connection discovery wi fi discovery system network connections discovery system owner user discovery system service discovery system time discovery virtual machine discovery virtualization sandbox evasion 3 system checks user activity based checks time based checks exploitation of remote services internal spearphishing lateral tool transfer remote service session hijacking 2 ssh hijacking rdp hijacking remote services 8 remote desktop protocol smb windows admin shares distributed component object model ssh vnc windows remote management cloud services direct cloud vm connections replication through removable media software deployment tools taint shared content use alternate authentication material 4 application access token pass the hash pass the ticket web session cookie adversary in the middle 4 name resolution poisoning and smb relay arp cache poisoning dhcp spoofing evil twin archive collected data 3 archive via utility archive via library archive via custom method audio capture automated collection browser session hijacking clipboard data data from cloud storage data from configuration repository 2 snmp mib dump network device configuration dump data from information repositories 6 confluence sharepoint code repositories customer relationship management software messaging applications databases data from local system data from network shared drive data from removable media data staged 2 local data staging remote data staging email collection 3 local email collection remote email collection email forwarding rule input capture 4 keylogging gui input capture web portal capture credential api hooking screen capture video capture application layer protocol 5 web protocols file transfer protocols mail protocols dns publish subscribe protocols communication through removable media content injection data encoding 2 standard encoding non standard encoding data obfuscation 3 junk data steganography protocol or service impersonation dynamic resolution 3 fast flux dns domain generation algorithms dns calculation encrypted channel 2 symmetric cryptography asymmetric cryptography fallback channels hide infrastructure ingress tool transfer multi stage channels non application layer protocol non standard port protocol tunneling proxy 4 internal proxy external proxy multi hop proxy domain fronting remote access tools 3 ide tunneling remote desktop software remote access hardware traffic signaling 2 port knocking socket filters web service 3 dead drop resolver bidirectional communication one way communication automated exfiltration 1 traffic duplication data transfer size limits exfiltration over alternative protocol 3 exfiltration over symmetric encrypted non c2 protocol exfiltration over asymmetric encrypted non c2 protocol exfiltration over unencrypted non c2 protocol exfiltration over c2 channel exfiltration over other network medium 1 exfiltration over bluetooth exfiltration over physical medium 1 exfiltration over usb exfiltration over web service 4 exfiltration to code repository exfiltration to cloud storage exfiltration to text storage sites exfiltration over webhook scheduled transfer transfer data to cloud account account access removal data destruction 1 lifecycle triggered deletion data encrypted for impact data manipulation 3 stored data manipulation transmitted data manipulation runtime data manipulation defacement 2 internal defacement external defacement disk wipe 2 disk content wipe disk structure wipe email bombing endpoint denial of service 4 os exhaustion flood service exhaustion flood application exhaustion flood application or system exploitation financial theft firmware corruption inhibit system recovery network denial of service 2 direct network flood reflection amplification resource hijacking 4 compute hijacking bandwidth hijacking sms pumping cloud service hijacking service stop system shutdown reboot reconnaissance resource development initial access execution persistence privilege escalation stealth defense impairment credential access discovery lateral movement collection command and control exfiltration impact 12 techniques 9 techniques 11 techniques 20 techniques 22 techniques 13 techniques 30 techniques 18 techniqu...
|