Linux Commands
Windows Commands
PowerShell Commands
CVSS v3.1
Vocabulary
100

This command is used to interact with a web server using a command line interface.

What is wget?

100

This command is used to display the processes running on a system.

What is tasklist?

100

A command that is used to remotely issue commands to a windows system.

What is invoke-request?

100

In CVSS scoring these are the metric choices for the CIA category.

What are High, Low, and None?

100

A file format that uses attribute-value pairs to define configurations in a structure that is easy for both humans and machines to read and consume.

What is JSON? (JavaScript Object Notation)

200

A command that is used to remotely access a server and obtain shell access.

What is ssh?

200

A command that is used to display network activity, in particular active IP addresses and ports.

What is netstat?

200

This command is used to interact with system using http or https.

What is Invoke-webrequest?

200

These metrics are the choices for the scope category.

What are Changed and Unchanged?

200

A sign that an asset or network has been attacked or is currently under attack.

What is IoC? (Indicator of compromise)

300

This command is used to identify the current session user.

What is whoami?

300

This command is a net command it is used to perform many administrative tasks.

What is the net<option>?

300

Starts a new process, often to load malware or a rouge process.

What is Start-process?

300
These metrics can be associated with the AV in the CVSS 3.1 scoring scale.

What are Physical, Local, Adjacent Network, Network?

300

A process that provides a shared login capability across multiple systems and enterprises. It essentially connects the identity management services of multiple  systems.

What is federation?

400

This command is a cleartext protocol used to perform file transfer.

What is ftp?

400

This command allows local and remote configuration of network-related services.

What is netsh?

400

A command used to display processes configured on a system

What is Get-process?

400

In PR these are the associated metrics.

What are None, Low, High

400

An application attack that allows access to commands, files, and directories that may or may not be connected to the web document root directory.

What is directory traversal?


500

A command used to display network activity, in particular active IP addresses and ports.

What is netstat?

500

This command is a command line interface to WMI/

What is wmic?

500

This command is used to download information from a web server, such as a malicious script or payload.

What is Downloadstring?

500

The metrics of "N" and "R" are part of this category.

What is User Interaction?

500

A framework for ensuring proper application of SPF and DKIM, utilizing a policy published as a DNS record.

What is DMARC? (Domain-based Message Authentication, Reporting, and Conformance)

M
e
n
u