Repository navigation
Expand file tree
/
Copy pathtags.json
More file actions
86 lines (86 loc) · 10.1 KB
/
Copy pathtags.json
File metadata and controls
86 lines (86 loc) · 10.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
{
"tactic": {
"recon": { "desc": "Information gathering, footprinting, target enumeration", "aliases": ["reconnaissance", "footprinting", "enumeration"] },
"resource-development": { "desc": "Building infrastructure, tooling, or payloads before an operation", "aliases": ["resource-dev", "infra-setup", "weaponization"] },
"initial-access": { "desc": "Gaining an initial foothold in the target environment", "aliases": ["initial-compromise", "foothold", "entry"] },
"execution": { "desc": "Running attacker-controlled code on a target", "aliases": ["code-execution", "exec"] },
"persistence": { "desc": "Maintaining access across reboots, credential changes, or interruptions", "aliases": ["persist", "backdoor"] },
"privilege-escalation": { "desc": "Gaining higher-level permissions on a system", "aliases": ["privesc", "lpe", "eop", "escalation", "escape"] },
"defense-evasion": { "desc": "Avoiding detection, bypassing EDR/AV, obfuscation, anti-analysis", "aliases": ["evasion", "detection-evasion", "obfuscation", "anti-analysis", "stealth", "amsi-bypass", "edr-bypass", "av-bypass", "unhooking"] },
"credential-access": { "desc": "Stealing credentials, hashes, tokens, or secrets", "aliases": ["creds", "credentials", "credential-theft", "secrets"] },
"discovery": { "desc": "Enumerating hosts, accounts, network, and environment after access", "aliases": ["situational-awareness", "internal-recon"] },
"lateral-movement": { "desc": "Moving between systems within a network", "aliases": ["lateral", "pivoting", "man-in-the-middle", "mitm"] },
"collection": { "desc": "Gathering data of interest from the target", "aliases": ["data-collection", "harvesting"] },
"command-and-control": { "desc": "Communicating with compromised systems to control them", "aliases": ["c2-phase", "command-control", "beaconing"] },
"exfiltration": { "desc": "Stealing data out of the target environment", "aliases": ["exfil", "data-theft", "data-exfiltration"] },
"impact": { "desc": "Disrupting, destroying, or manipulating systems and data", "aliases": ["destruction", "ransomware", "sabotage"] }
},
"target": {
"windows": { "desc": "Microsoft Windows systems", "aliases": ["win", "win32", "endpoint", "endpoint-security"] },
"linux": { "desc": "Linux systems and distributions", "aliases": ["unix", "*nix"] },
"macos": { "desc": "Apple macOS systems", "aliases": ["osx", "apple", "mac"] },
"active-directory": { "desc": "Active Directory, Kerberos, domain, LDAP, ADCS", "aliases": ["ad", "kerberos", "ldap", "domain", "adcs", "azure-ad", "entra"] },
"cloud": { "desc": "Cloud platforms: AWS, Azure, GCP, SaaS", "aliases": ["aws", "azure", "gcp", "saas", "serverless"] },
"container": { "desc": "Containers and orchestration: Docker, Kubernetes", "aliases": ["docker", "kubernetes", "k8s", "vmware"] },
"web": { "desc": "Web applications, APIs, and HTTP services", "aliases": ["webapp", "http", "api-security", "waf", "ssrf", "rce", "xss", "sqli"] },
"mobile": { "desc": "Mobile platforms: Android and iOS", "aliases": ["android", "ios"] },
"network": { "desc": "Network protocols, devices, sniffing, and infrastructure", "aliases": ["networking", "protocol", "sniffing", "packet", "bluetooth"] },
"wifi": { "desc": "Wireless / 802.11 attacks and auditing", "aliases": ["wireless", "802.11", "wpa"] },
"iot": { "desc": "Internet-of-things and embedded/ICS devices", "aliases": ["embedded", "ics", "scada", "firmware"] },
"database": { "desc": "Databases: SQL, NoSQL, data stores", "aliases": ["sql", "nosql", "db", "mssql", "mysql", "postgres"] },
"hardware": { "desc": "Physical hardware, chips, JTAG, side-channel, arch-specific", "aliases": ["arm", "driver", "physical", "physical-security", "side-channel", "jtag"] }
},
"function": {
"scanner": { "desc": "Scanning and enumeration tooling (ports, vulns, assets)", "aliases": ["scan", "vulnerability-scanner", "port-scanner", "nuclei"] },
"fuzzer": { "desc": "Fuzzing and input mutation tooling", "aliases": ["fuzzing", "fuzz"] },
"exploit": { "desc": "Exploits, PoCs, and vulnerability exploitation", "aliases": ["exploitation", "poc", "cve", "vulnerability", "rce-exploit", "0day"] },
"c2": { "desc": "Command-and-control frameworks and agents", "aliases": ["c2-framework", "implant", "beacon", "rat", "remote-access"] },
"osint": { "desc": "Open-source intelligence collection", "aliases": ["open-source-intel", "people-search", "recon-osint"] },
"password-cracking": { "desc": "Cracking hashes and passwords", "aliases": ["cracking", "hash-cracking", "bruteforce", "crack"] },
"crypto": { "desc": "Cryptography, encryption, and cryptanalysis", "aliases": ["cryptography", "encryption", "cryptanalysis"] },
"steganography": { "desc": "Hiding or extracting data within files/media", "aliases": ["stego", "stegano"] },
"reversing": { "desc": "Reverse engineering, disassembly, debugging", "aliases": ["reverse-engineering", "disassembly", "debugger", "sandbox", "deobfuscation", "re"] },
"binary-exploitation": { "desc": "Memory corruption, shellcode, ROP, pwn", "aliases": ["pwn", "shellcode", "shellcoding", "rop", "heap", "memory-corruption"] },
"phishing": { "desc": "Phishing kits, lures, and email attacks", "aliases": ["phish", "credential-phishing", "smishing"] },
"social-engineering": { "desc": "Human-targeted manipulation beyond phishing", "aliases": ["se", "pretexting"] },
"tunneling": { "desc": "Proxying, pivoting, and traffic tunneling", "aliases": ["proxy", "pivot", "port-forwarding", "socks"] },
"post-exploitation": { "desc": "Post-compromise operations and tradecraft", "aliases": ["post-ex", "postex"] },
"blue-team": { "desc": "General defensive security tooling", "aliases": ["defense", "defensive", "monitoring", "hardening", "compliance", "audit", "purple-team"] },
"red-team": { "desc": "General offensive tradecraft: red-team frameworks/resources not tied to one specific tactic", "aliases": ["red-teaming", "pentest", "pentesting", "penetration-testing", "adversary-emulation", "offensive-security", "offensive"] },
"detection": { "desc": "Detection engineering, rules, signatures", "aliases": ["detection-engineering", "detection-as-code", "sigma", "yara", "kql", "detection-rules"] },
"threat-hunting": { "desc": "Proactively hunting adversaries in an environment", "aliases": ["hunting", "threat-hunt", "hunt"] },
"incident-response": { "desc": "IR, DFIR, triage, containment, recovery", "aliases": ["ir", "dfir", "response", "recovery", "triage"] },
"threat-intel": { "desc": "Threat intelligence, APT tracking, IOCs", "aliases": ["threat-intelligence", "cti", "apt", "ioc", "intel"] },
"malware-dev": { "desc": "Building offensive malware, loaders, droppers", "aliases": ["malware-development", "maldev", "malware", "loader", "dropper", "packer"] },
"malware-analysis": { "desc": "Analyzing malicious software behavior", "aliases": ["unpacking", "dynamic-analysis", "static-analysis"] },
"forensics": { "desc": "Digital forensics, memory/disk analysis", "aliases": ["memory-analysis", "disk-forensics", "artifact-analysis"] },
"deception": { "desc": "Honeypots, canaries, and deception tech", "aliases": ["honeypot", "honeytoken", "canary", "decoy"] },
"dos": { "desc": "Denial-of-service and resource-exhaustion tooling", "aliases": ["ddos", "denial-of-service", "stress-test"] },
"privacy": { "desc": "Anonymity, OPSEC, and privacy tooling", "aliases": ["anonymity", "opsec", "onion", "tor", "anti-forensics"] }
},
"reference": {
"cheatsheet": { "desc": "Cheatsheets, command references, quick guides", "aliases": ["cheat-sheet", "reference", "notes"] },
"mindmap": { "desc": "Mind maps and visual methodology diagrams", "aliases": ["mind-map", "diagram"] },
"payloads": { "desc": "Ready-to-use payloads and injection strings", "aliases": ["payload", "one-liners"] },
"wordlist": { "desc": "Wordlists and dictionaries", "aliases": ["wordlists", "dictionary"] },
"awesome-list": { "desc": "Curated 'awesome' link/resource collections", "aliases": ["awesome", "curated-list", "link-list", "resource-list"] },
"writeup": { "desc": "Blog posts, articles, and technical writeups", "aliases": ["article", "blog", "writeups", "walkthrough"] },
"training": { "desc": "Labs, CTFs, courses, and learning material", "aliases": ["ctf", "oscp", "education", "lab", "lab-environment", "course", "practice"] },
"misc": { "desc": "Uncategorized or general-purpose", "aliases": ["other", "general", "utility"] }
},
"language": {
"python": { "desc": "Python", "aliases": ["py", "python3"], "ext": [".py"] },
"powershell": { "desc": "PowerShell", "aliases": ["ps1", "posh", "pwsh"], "ext": [".ps1", ".psm1"] },
"csharp": { "desc": "C# / .NET", "aliases": ["c#", "dotnet", ".net"], "ext": [".cs"] },
"c": { "desc": "C", "aliases": [], "ext": [".c", ".h"] },
"cpp": { "desc": "C++", "aliases": ["c++", "cplusplus"], "ext": [".cpp", ".cc", ".cxx", ".hpp"] },
"go": { "desc": "Go / Golang", "aliases": ["golang"], "ext": [".go"] },
"rust": { "desc": "Rust", "aliases": ["rs"], "ext": [".rs"] },
"bash": { "desc": "Bash / shell scripts", "aliases": ["shell", "sh", "zsh"], "ext": [".sh", ".bash", ".zsh"] },
"java": { "desc": "Java", "aliases": ["jvm"], "ext": [".java"] },
"ruby": { "desc": "Ruby", "aliases": ["rb"], "ext": [".rb"] },
"php": { "desc": "PHP", "aliases": [], "ext": [".php"] },
"javascript": { "desc": "JavaScript / TypeScript / Node", "aliases": ["js", "typescript", "ts", "node", "nodejs"], "ext": [".js", ".ts", ".jsx", ".tsx"] },
"assembly": { "desc": "Assembly", "aliases": ["asm"], "ext": [".asm", ".s"] }
}
}