Meta tags:
Headings (most frequently used words):
att, ck, matrix, for, enterprise,
Text of the page (most frequently used words):
cloud (76), discovery (68), system (62), network (60), data (56), accounts (56), execution (48), and (47), service (47), authentication (44), hijacking (42), file (42), domain (40), process (38), techniques (36), modify (34), account (32), access (32), exfiltration (32), injection (32), software (31), local (30), services (30), windows (30), web (28), email (26), remote (26), dll (26), modification (26), application (24), container (24), over (22), code (22), permissions (22), path (22), information (20), device (20), token (20), credentials (20), command (20), additional (20), for (19), the (18), manipulation (18), protocol (18), capture (18), from (18), spearphishing (18), password (18), boot (18), policy (17), search (17), storage (16), proxy (16), dns (16), api (16), registry (16), image (16), logon (16), compromise (16), att (15), groups (14), exploitation (14), content (14), scheduled (14), multi (14), dynamic (14), media (14), credential (14), component (14), interception (14), create (14), task (14), startup (14), server (14), tools (13), history (13), resource (12), firmware (12), transfer (12), non (12), port (12), management (12), spoofing (12), checks (12), trust (12), shell (12), certificates (12), memory (12), provider (12), modules (12), disable (12), clear (12), event (12), script (12), default (12), link (12), weakness (12), job (12), all (10), encrypted (10), hardware (10), tool (10), infrastructure (10), input (10), collection (10), configuration (10), poisoning (10), object (10), time (10), user (10), security (10), instance (10), keys (10), files (10), factor (10), host (10), control (10), systemd (10), extensions (10), roles (10), malicious (10), victim (10), based (9), group (9), domains (8), flood (8), external (8), internal (8), removal (8), traffic (8), communication (8), resolution (8), impersonation (8), removable (8), protocols (8), applications (8), browser (8), session (8), archive (8), via (8), library (8), name (8), ssh (8), model (8), evasion (8), virtual (8), log (8), window (8), steal (8), identity (8), encryption (8), controller (8), signing (8), firewall (8), valid (8), social (8), thread (8), executable (8), malware (8), installer (8), rules (8), hidden (8), with (8), dlls (8), helper (8), launch (8), items (8), scripts (8), login (8), autostart (8), digital (8), gather (8), scanning (8), filters (7), private (7), mitre (6), enterprise (6), compute (6), direct (6), theft (6), exhaustion (6), disk (6), wipe (6), defacement (6), triggered (6), socket (6), knocking (6), signaling (6), standard (6), encoding (6), through (6), shared (6), drive (6), databases (6), repositories (6), smb (6), ticket (6), connection (6), driver (6), forge (6), proc (6), lsass (6), conditional (6), policies (6), hybrid (6), reversible (6), pluggable (6), filter (6), bypass (6), configurations (6), linux (6), trusted (6), utilities (6), binary (6), smuggling (6), masquerade (6), run (6), bits (6), jobs (6), orchestration (6), timers (6), cron (6), python (6), powershell (6), unix (6), instrumentation (6), agent (6), active (6), outlook (6), office (6), serverless (6), administration (6), cli (6), supply (6), chain (6), capabilities (6), open (6), cookie (5), ics (5), mobile (5), none (5), hide (5), adversary (5), location (5), development (5), threat (5), use (4), components (4), denial (4), stored (4), impact (4), deletion (4), repository (4), physical (4), medium (4), channel (4), asymmetric (4), symmetric (4), automated (4), desktop (4), ide (4), tunneling (4), layer (4), stage (4), channels (4), cryptography (4), generation (4), steganography (4), junk (4), obfuscation (4), hooking (4), portal (4), gui (4), keylogging (4), staging (4), relationship (4), dump (4), audio (4), evil (4), twin (4), dhcp (4), arp (4), cache (4), relay (4), middle (4), pass (4), deployment (4), replication (4), connections (4), lateral (4), activity (4), virtualization (4), sandbox (4), query (4), sniffing (4), share (4), directory (4), debugger (4), tickets (4), etc (4), secrets (4), manager (4), stores (4), space (4), install (4), certificate (4), downgrade (4), mac (4), defense (4), impairment (4), tenant (4), logs (4), jamplus (4), clickonce (4), msbuild (4), developer (4), template (4), html (4), exclusion (4), listplanting (4), vdso (4), doppelgänging (4), hollowing (4), extra (4), ptrace (4), calls (4), asynchronous (4), procedure (4), call (4), portable (4), tftp (4), rommonkit (4), bootkit (4), pre (4), payloads (4), indicator (4), after (4), legitimate (4), persistence (4), appdomainmanager (4), kernelcallbacktable (4), cor_profiler (4), unquoted (4), order (4), environment (4), variable (4), linker (4), dylib (4), hijack (4), flow (4), attributes (4), stealth (4), sid (4), parent (4), pid (4), make (4), impersonate (4), privilege (4), escalation (4), hooks (4), udev (4), packages (4), emond (4), profile (4), options (4), shimming (4), appinit (4), appcert (4), accessibility (4), features (4), netsh (4), lc_load_dylib (4), addition (4), trap (4), subscription (4), screensaver (4), change (4), association (4), daemon (4), hook (4), initialization (4), setup (4), xdg (4), entries (4), print (4), processors (4), monitors (4), shortcut (4), opened (4), kernel (4), support (4), winlogon (4), providers (4), package (4), folder (4), cluster (4), registration (4), authorized (4), delegate (4), elevated (4), sudo (4), client (4), visual (4), dependencies (4), voice (4), attachment (4), phishing (4), public (4), target (4), upload (4), exploits (4), botnet (4), acquire (4), websites (4), technical (4), identify (4), business (4), addresses (4), preferences (3), cti (3), defenses (3), sub (3), tactics (3), page (3), develop (3), person (3), faq (3), 2026 (2), corporation (2), are (2), resources (2), reference (2), campaigns (2), analytics (2), detection (2), strategies (2), assets (2), mitigations (2), matrices (2), core (2), objects (2), shutdown (2), reboot (2), stop (2), sms (2), pumping (2), bandwidth (2), reflection (2), amplification (2), inhibit (2), recovery (2), corruption (2), financial (2), endpoint (2), bombing (2), structure (2), runtime (2), transmitted (2), lifecycle (2), destruction (2), webhook (2), text (2), sites (2), usb (2), bluetooth (2), other (2), unencrypted (2), alternative (2), size (2), limits (2), duplication (2), one (2), way (2), bidirectional (2), dead (2), drop (2), resolver (2), fronting (2), hop (2), ingress (2), fallback (2), calculation (2), algorithms (2), fast (2), flux (2), publish (2), subscribe (2), mail (2), video (2), screen (2), forwarding (2), rule (2), staged (2), messaging (2), customer (2), sharepoint (2), confluence (2), snmp (2), mib (2), clipboard (2), custom (2), method (2), utility (2), collected (2), hash (2), alternate (2), material (2), taint (2), vnc (2), distributed (2), admin (2), shares (2), rdp (2), machine (2), owner (2), internet (2), language (2), backup (2), permission (2), peripheral (2), enumeration (2), dashboard (2), chat (2), messages (2), metadata (2), unsecured (2), ccache (2), rep (2), roasting (2), kerberoasting (2), silver (2), golden (2), kerberos (2), passwd (2), shadow (2), filesystem (2), dcsync (2), cached (2), lsa (2), ntds (2), dumping (2), request (2), saml (2), tokens (2), cookies (2), forced (2), managers (2), browsers (2), securityd (2), keychain (2), stuffing (2), spraying (2), cracking (2), guessing (2), brute (2), force (2), crypto (2), reduce (2), key (2), weaken (2), mark (2), root (2), sip (2), gatekeeper (2), subvert (2), controls (2), safe (2), mode (2), rogue (2), prevent (2), logging (2), plist (2), address (2), translation (2), traversal (2), boundary (2), bridging (2), patch (2), hierarchy (2), revert (2), delete (2), snapshot (2), attack (2), audit (2), spoof (2), xsl (2), processing (2), unused (2), unsupported (2), regions (2), syncappvpublishingserver (2), pubprn (2), electron (2), mmc (2), mavinject (2), verclsid (2), rundll32 (2), regsvr32 (2), regsvcs (2), regasm (2), odbcconf (2), msiexec (2), mshta (2), installutil (2), cmstp (2), panel (2), compiled (2), engineering (2), selective (2), rootkit (2), reflective (2), loading (2), invisible (2), unicode (2), svg (2), insertion (2), compression (2), polymorphic (2), encoded (2), lnk (2), icon (2), fileless (2), embedded (2), stripped (2), compile (2), delivery (2), packing (2), padding (2), obfuscated (2), fingerprint (2), overwrite (2), arguments (2), break (2), trees (2), type (2), double (2), extension (2), filename (2), match (2), rename (2), right (2), left (2), override (2), invalid (2), signature (2), masquerading (2), indirect (2), relocate (2), mailbox (2), timestomp (2), extended (2), bind (2), mounts (2), exclusions (2), ignore (2), interrupts (2), argument (2), forking (2), hiding (2), vba (2), stomping (2), ntfs (2), users (2), directories (2), artifacts (2), mutual (2), environmental (2), keying (2), guardrails (2), volume (2), deobfuscate (2), decode (2), delay (2), build (2), escape (2), tcc (2), temporary (2), prompt (2), caching (2), setuid (2), setgid (2), abuse (2), elevation (2), mechanism (2), vsphere (2), installation (2), bundles (2), terminal (2), iis (2), transport (2), sql (2), procedures (2), power (2), settings (2), add (2), ins (2), home (2), forms (2), test (2), macros (2), implant (2), exclusive (2), integration (2), copy (2), paste (2), systemctl (2), launchctl (2), poisoned (2), pipeline (2), native (2), xpc (2), exchange (2), inter (2), esxi (2), deploy (2), hypervisor (2), lua (2), autohotkey (2), autoit (2), javascript (2), basic (2), applescript (2), scripting (2), interpreter (2), networks (2), additions (2), exploit (2), facing (2), seo (2), artificial (2), intelligence (2), vulnerabilities (2), obtain (2), written (2), generate (2), establish (2), devices (2), malvertising (2), owned (2), vendor (2), engines (2), scan (2), cdns (2), whois (2), passive (2), purchase (2), intel (2), vendors (2), closed (2), sources (2), tempo (2), relationships (2), determine (2), locations (2), org (2), appliances (2), topology (2), properties (2), employee (2), names (2), wordlist (2), vulnerability (2), blocks (2), movement (2), initial (2), reconnaissance (2), side (2), matrix (2), world (2), more (2), cybersecurity (2), knowledge (2), base (2), toggle (2), dropdown (2), blog (2), contribute (2), get (2), started (2), ckcon (2), 2015, registered, trademarks, website, changelog, privacy, terms, contact, reset, show, flat, layout, creation, fulfilling, its, mission, solve, problems, safer, bringing, communities, together, effective, available, any, organization, charge, globally, accessible, real, observations, used, foundation, specific, models, methodologies, sector, government, product, community, asset, campaign, mitigation, source, technique, tactic, random, take, tour, join, october, mclean, hotel, details, can, found, register, here, benefactors, legal, branding, updates, version, engage, advisory, council, learn, about, detections,
Text of the page (random words):
curity software discovery backup software discovery system information discovery system location discovery 1 system language discovery system network configuration discovery 2 internet connection discovery wi fi discovery system network connections discovery system owner user discovery system service discovery system time discovery virtual machine discovery virtualization sandbox evasion 3 system checks user activity based checks time based checks exploitation of remote services internal spearphishing lateral tool transfer remote service session hijacking 2 ssh hijacking rdp hijacking remote services 8 remote desktop protocol smb windows admin shares distributed component object model ssh vnc windows remote management cloud services direct cloud vm connections replication through removable media software deployment tools taint shared content use alternate authentication material 4 application access token pass the hash pass the ticket web session cookie adversary in the middle 4 name resolution poisoning and smb relay arp cache poisoning dhcp spoofing evil twin archive collected data 3 archive via utility archive via library archive via custom method audio capture automated collection browser session hijacking clipboard data data from cloud storage data from configuration repository 2 snmp mib dump network device configuration dump data from information repositories 6 confluence sharepoint code repositories customer relationship management software messaging applications databases data from local system data from network shared drive data from removable media data staged 2 local data staging remote data staging email collection 3 local email collection remote email collection email forwarding rule input capture 4 keylogging gui input capture web portal capture credential api hooking screen capture video capture application layer protocol 5 web protocols file transfer protocols mail protocols dns publish subscribe protocols communication through removable media content injection data encoding 2 standard encoding non standard encoding data obfuscation 3 junk data steganography protocol or service impersonation dynamic resolution 3 fast flux dns domain generation algorithms dns calculation encrypted channel 2 symmetric cryptography asymmetric cryptography fallback channels hide infrastructure ingress tool transfer multi stage channels non application layer protocol non standard port protocol tunneling proxy 4 internal proxy external proxy multi hop proxy domain fronting remote access tools 3 ide tunneling remote desktop software remote access hardware traffic signaling 2 port knocking socket filters web service 3 dead drop resolver bidirectional communication one way communication automated exfiltration 1 traffic duplication data transfer size limits exfiltration over alternative protocol 3 exfiltration over symmetric encrypted non c2 protocol exfiltration over asymmetric encrypted non c2 protocol exfiltration over unencrypted non c2 protocol exfiltration over c2 channel exfiltration over other network medium 1 exfiltration over bluetooth exfiltration over physical medium 1 exfiltration over usb exfiltration over web service 4 exfiltration to code repository exfiltration to cloud storage exfiltration to text storage sites exfiltration over webhook scheduled transfer transfer data to cloud account account access removal data destruction 1 lifecycle triggered deletion data encrypted for impact data manipulation 3 stored data manipulation transmitted data manipulation runtime data manipulation defacement 2 internal defacement external defacement disk wipe 2 disk content wipe disk structure wipe email bombing endpoint denial of service 4 os exhaustion flood service exhaustion flood application exhaustion flood application or system exploitation financial theft firmware corruption inhibit system recovery network denial of service 2 direct network flood reflection amplification resource hijacking 4 compute hijacking bandwidth hijacking sms pumping cloud service hijacking service stop system shutdown reboot reconnaissance resource development initial access execution persistence privilege escalation stealth defense impairment credential access discovery lateral movement collection command and control exfiltration impact 12 techniques 9 techniques 11 techniques 20 techniques 22 techniques 13 techniques 30 techniques 18 techniques 17 techniques 34 techniques 9 techniques 17 techniques 18 techniques 9 techniques 15 techniques active scanning 3 scanning ip blocks vulnerability scanning wordlist scanning gather victim host information 4 hardware software firmware client configurations gather victim identity information 3 credentials email addresses employee names gather victim network information 6 domain properties dns network trust dependencies network topology ip addresses network security appliances gather victim org information 4 determine physical locations business relationships identify business tempo identify roles phishing for information 4 spearphishing service spearphishing attachment spearphishing link spearphishing voice query public ai services search closed sources 2 threat intel vendors purchase technical data search open technical databases 5 dns passive dns whois digital certificates cdns scan databases search open websites domains 3 social media search engines code repositories search threat vendor data search victim owned websites acquire access acquire infrastructure 8 domains dns server virtual private server server botnet web services serverless malvertising compromise accounts 3 social media accounts email accounts cloud accounts compromise infrastructure 8 domains dns server virtual private server server botnet web services serverless network devices develop capabilities 4 malware code signing certificates digital certificates exploits establish accounts 3 social media accounts email accounts cloud accounts generate content 2 written content audio visual content obtain capabilities 7 malware tool code signing certificates digital certificates exploits vulnerabilities artificial intelligence stage capabilities 6 upload malware upload tool install digital certificate drive by target link target seo poisoning content injection drive by compromise exploit public facing application external remote services hardware additions phishing 4 spearphishing attachment spearphishing link spearphishing via service spearphishing voice replication through removable media supply chain compromise 3 compromise software dependencies and development tools compromise software supply chain compromise hardware supply chain trusted relationship valid accounts 4 default accounts domain accounts local accounts cloud accounts wi fi networks bits jobs cloud administration command command and scripting interpreter 13 powershell applescript windows command shell unix shell visual basic python javascript network device cli cloud api autohotkey autoit lua hypervisor cli container cli api container administration command deploy container esxi administration command exploitation for client execution hijack execution flow 12 dll dylib hijacking executable installer file permissions weakness dynamic linker hijacking path interception by path environment variable path interception by search order hijacking path interception by unquoted path services file permissions weakness services registry permissions weakness cor_profiler kernelcallbacktable appdomainmanager input injection inter process communication 3 component object model dynamic data exchange xpc services native api poisoned pipeline execution scheduled task job 5 at cron scheduled task systemd timers container orchestration job serverless execution shared modules software deployment tools system services 3 launchctl service execution systemctl trusted developer utilities proxy execution 3 msbuild clickonce jamplus user execution 5 malicious link malicious file malicious image malicious copy and paste malicious library windows management instrumentation account manipulation 7 additional cloud credentials additional email delegate permissions additional cloud roles ssh authorized keys device registration additional container cluster roles additional local or domain groups bits jobs boot or logon autostart execution 14 registry run keys startup folder authentication package time providers winlogon helper dll security support provider kernel modules and extensions re opened applications lsass driver shortcut modification port monitors print processors xdg autostart entries active setup login items boot or logon initialization scripts 5 logon script windows login hook network logon script rc scripts startup items cloud application integration compromise host software binary create account 3 local account domain account cloud account create or modify system process 5 launch agent systemd service windows service launch daemon container service event triggered execution 18 change default file association screensaver windows management instrumentation event subscription unix shell configuration modification trap lc_load_dylib addition netsh helper dll accessibility features appcert dlls appinit dlls application shimming image file execution options injection powershell profile emond component object model hijacking installer packages udev rules python startup hooks exclusive control external remote services implant internal image modify authentication process 9 domain controller authentication password filter dll pluggable authentication modules network device authentication reversible encryption multi factor authentication hybrid identity network provider dll conditional access policies modify registry office application startup 6 office template macros office test outlook forms outlook home page outlook rules add ins power settings pre os boot 5 system firmware component firmware bootkit rommonkit tftp boot scheduled task job 5 at cron scheduled task systemd timers container orchestration job server software component 6 sql stored procedures transport agent web shell iis components terminal services dll vsphere installation bundles software extensions 2 browser extensions ide extensions traffic signaling 2 port knocking socket filters valid accounts 4 default accounts domain accounts local accounts cloud accounts abuse elevation control mechanism 6 setuid and setgid bypass user account control sudo and sudo caching elevated execution with prompt temporary elevated cloud access tcc manipulation access token manipulation 5 token impersonation theft create process with token make and impersonate token parent pid spoofing sid history injection account manipulation 7 additional cloud credentials additional email delegate permissions additional cloud roles ssh authorized keys device registration additional container cluster roles additional local or domain groups boot or logon autostart execution 14 registry run keys startup folder authentication package time providers winlogon helper dll security support provider kernel modules and extensions re opened applications lsass driver shortcut modification port monitors print processors xdg autostart entries active setup login items boot or logon initialization scripts 5 logon script windows login hook network logon script rc scripts startup items create or modify system process 5 launch agent systemd service windows service launch daemon container service domain or tenant policy modification 2 group policy modification trust modification escape to host event triggered execution 18 change default file association screensaver windows management instrumentation event subscription unix shell configuration modification trap lc_load_dylib addition netsh helper dll accessibility features appcert dlls appinit dlls application shimming image file execution options injection powershell profile emond component object model hijacking installer packages udev rules python startup hooks exploitation for privilege escalation process injection 12 dynamic link library injection portable executable injection thread execution hijacking asynchronous procedure call thread local storage ptrace system calls proc memory extra window memory injection process hollowing process doppelgänging vdso hijacking listplanting scheduled task job 5 at cron scheduled task systemd timers container orchestration job valid accounts 4 default accounts domain accounts local accounts cloud accounts access token manipulation 5 token impersonation theft create process with token make and impersonate token parent pid spoofing sid history injection bits jobs build image on host debugger evasion delay execution deobfuscate decode files or information direct volume access execution guardrails 2 environmental keying mutual exclusion exploitation for stealth hide artifacts 14 hidden files and directories hidden users hidden window ntfs file attributes hidden file system run virtual instance vba stomping email hiding rules resource forking process argument spoofing ignore process interrupts file path exclusions bind mounts extended attributes hijack execution flow 12 dll dylib hijacking executable installer file permissions weakness dynamic linker hijacking path interception by path environment variable path interception by search order hijacking path interception by unquoted path services file permissions weakness services registry permissions weakness cor_profiler kernelcallbacktable appdomainmanager indicator removal 8 clear command history file deletion network share connection removal timestomp clear network connection history and configurations clear mailbox data clear persistence relocate malware indirect command execution masquerading 12 invalid code signature right to left override rename legitimate utilities masquerade task or service match legitimate resource name or location space after filename double file extension masquerade file type break process trees masquerade account name overwrite process arguments browser fingerprint obfuscated files or information 18 binary padding software packing steganography compile after delivery indicator removal from tools html smuggling dynamic api resolution stripped payloads embedded payloads command obfuscation fileless storage lnk icon smuggling encrypted encoded file polymorphic code compression junk code insertion svg smuggling invisible unicode pre os boot 5 system firmware component firmware bootkit rommonkit tftp boot process injection 12 dynamic link library injection portable executable injection thread execution hijacking asynchronous procedure call thread local storage ptrace system calls proc memory extra window memory injection process hollowing process doppelgänging vdso hijacking listplanting reflective code loading rootkit selective exclusion social engineering 2 impersonation email spoofing system binary proxy execution 14 compiled html file control panel cmstp installutil mshta msiexec odbcconf regsvcs regasm regsvr32 rundll32 ver...
|