cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ Cis Cassandra40 V130 3 3 · cyberstrikeusEnsure there are no unnecessary roles or excessive privileges
- ▌ Cis Cassandra40 V130 3 4 · cyberstrikeusEnsure that Cassandra is run using a non-privileged, dedicated service account
- ▌ Cis Cassandra40 V130 3 5 · cyberstrikeusEnsure that Cassandra only listens for network connections on authorized interfaces
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis GCP Foundations 1 2 · cyberstrikeusEnsure That Multi-Factor Authentication is Enabled for All Non-Service Accounts
- ▌ Cis GCP Foundations 1 3 · cyberstrikeusEnsure That Security Key Enforcement is Enabled for All Admin Accounts
- ▌ Cis GCP Foundations 1 4 · cyberstrikeusEnsure That There Are Only GCP-Managed Service Account Keys for Each Service Account
- ▌
- ▌ Cis GCP Foundations 1 6 · cyberstrikeusEnsure That IAM Users Are Not Assigned the Service Account User or Service Account Token Creator Roles at Project Level
- ▌ Cis GCP Foundations 1 7 · cyberstrikeusEnsure User-Managed/External Keys for Service Accounts Are Rotated Every 90 Days or Fewer
- ▌ Cis GCP Foundations 1 8 · cyberstrikeusEnsure That Separation of Duties Is Enforced While Assigning Service Account Related Roles to Users
- ▌ Cis GCP Foundations 1 9 · cyberstrikeusEnsure That Cloud KMS Cryptokeys Are Not Anonymously or Publicly Accessible
- ▌
- ▌
- ▌ Cis GCP Foundations 2 3 · cyberstrikeusEnsure That Retention Policies on Cloud Storage Buckets Used for Exporting Logs Are Configured Using Bucket Lock
- ▌ Cis GCP Foundations 2 4 · cyberstrikeusEnsure Log Metric Filter and Alerts Exist for Project Ownership Assignments/Changes
- ▌ Cis GCP Foundations 2 5 · cyberstrikeusEnsure That the Log Metric Filter and Alerts Exist for Audit Configuration Changes
- ▌ Cis GCP Foundations 2 6 · cyberstrikeusEnsure That the Log Metric Filter and Alerts Exist for Custom Role Changes
- ▌ Cis GCP Foundations 2 7 · cyberstrikeusEnsure That the Log Metric Filter and Alerts Exist for VPC Network Firewall Rule Changes
- ▌ Cis GCP Foundations 2 8 · cyberstrikeusEnsure That the Log Metric Filter and Alerts Exist for VPC Network Route Changes
- ▌ Cis GCP Foundations 2 9 · cyberstrikeusEnsure That the Log Metric Filter and Alerts Exist for VPC Network Changes
- ▌
- ▌
- ▌
- ▌ Cis GCP Foundations 3 4 · cyberstrikeusEnsure That RSASHA1 Is Not Used for the Key-Signing Key in Cloud DNS DNSSEC
- ▌ Cis GCP Foundations 3 5 · cyberstrikeusEnsure That RSASHA1 Is Not Used for the Zone-Signing Key in Cloud DNS DNSSEC
- ▌
- ▌
- ▌ Cis GCP Foundations 3 8 · cyberstrikeusEnsure That VPC Flow Logs Is Enabled for Every Subnet in a VPC Network
- ▌ Cis GCP Foundations 3 9 · cyberstrikeusEnsure No HTTPS or SSL Proxy Load Balancers Permit SSL Policies With Weak Cipher Suites
- ▌ Cis GCP Foundations 4 1 · cyberstrikeusEnsure That Instances Are Not Configured To Use the Default Service Account
- ▌ Cis GCP Foundations 4 2 · cyberstrikeusEnsure That Instances Are Not Configured To Use the Default Service Account With Full Access to All Cloud APIs
- ▌ Cis GCP Foundations 4 3 · cyberstrikeusEnsure 'Block Project-Wide SSH Keys' Is Enabled for VM Instances
- ▌
- ▌ Cis GCP Foundations 4 5 · cyberstrikeusEnsure 'Enable Connecting to Serial Ports' Is Not Enabled for VM Instance
- ▌
- ▌ Cis GCP Foundations 4 7 · cyberstrikeusEnsure VM Disks for Critical VMs Are Encrypted With Customer-Supplied Encryption Keys (CSEK)
- ▌ Cis GCP Foundations 4 8 · cyberstrikeusEnsure Compute Instances Are Launched With Shielded VM Enabled
- ▌ Cis GCP Foundations 4 9 · cyberstrikeusEnsure That Compute Instances Do Not Have Public IP Addresses
- ▌ Cis GCP Foundations 5 1 · cyberstrikeusEnsure That Cloud Storage Bucket Is Not Anonymously or Publicly Accessible
- ▌ Cis Ubuntu 14 04 Lts 5 2 7 Ensure Ssh Hostbasedauthenticatio · cyberstrikeusVerify SSH HostbasedAuthentication is disabled to prevent host-based trust authentication
- ▌ Cis Ubuntu 14 04 Lts 5 2 8 Ensure Ssh Root Login Is Disabled · cyberstrikeusVerify SSH PermitRootLogin is set to no to prevent direct root login over SSH
- ▌ Cis Ubuntu 14 04 Lts 5 2 9 Ensure Ssh Permitemptypasswords I · cyberstrikeusVerify SSH PermitEmptyPasswords is set to no to prevent login with empty passwords
- ▌ Cis Ubuntu 14 04 Lts 5 3 1 Ensure Password Creation Requirem · cyberstrikeusVerify PAM password quality requirements enforce minimum length and complexity
- ▌ Cis Ubuntu 14 04 Lts 5 3 2 Ensure Lockout For Failed Passwor · cyberstrikeusVerify PAM is configured to lock out users after repeated failed password attempts
- ▌ Cis Ubuntu 14 04 Lts 5 3 3 Ensure Password Reuse Is Limited · cyberstrikeusVerify PAM is configured to remember at least 5 previous passwords to prevent reuse
- ▌ Cis Ubuntu 14 04 Lts 5 3 4 Ensure Password Hashing Algorithm · cyberstrikeusVerify PAM is configured to use SHA-512 hashing algorithm for password storage
- ▌ Cis Ubuntu 14 04 Lts 5 4 2 Ensure System Accounts Are Non Lo · cyberstrikeusVerify system accounts have non-login shells and are locked to prevent interactive access
- ▌ Cis Ubuntu 14 04 Lts 5 4 3 Ensure Default Group For The Root · cyberstrikeusVerify the root account default group is GID 0 to prevent root-owned files becoming accessible
- ▌ Cis Ubuntu 14 04 Lts 5 4 4 Ensure Default User Umask Is 027 · cyberstrikeusVerify default umask is set to 027 or more restrictive in shell configuration files
- ▌ Cis Ubuntu 14 04 Lts 5 4 5 Ensure Default User Shell Timeout · cyberstrikeusVerify TMOUT is set to 900 seconds or less in shell configuration files for idle session timeout
- ▌ Cis Ubuntu 14 04 Lts 6 1 1 Audit System File Permissions · cyberstrikeusAudit system file permissions using dpkg --verify to detect unauthorized changes
- ▌ Cis Ubuntu 14 04 Lts 6 1 2 Ensure Permissions On Etc Passwd · cyberstrikeusVerify /etc/passwd has correct ownership (root:root) and permissions (644)
- ▌ Cis Ubuntu 14 04 Lts 6 1 3 Ensure Permissions On Etc Shadow · cyberstrikeusVerify /etc/shadow has correct ownership (root:shadow) and permissions (640 or more restrictive)
- ▌ Cis Ubuntu 14 04 Lts 6 1 4 Ensure Permissions On Etc Group A · cyberstrikeusVerify /etc/group has correct ownership (root:root) and permissions (644)
- ▌ Cis Ubuntu 14 04 Lts 6 1 5 Ensure Permissions On Etc Gshadow · cyberstrikeusVerify /etc/gshadow has correct ownership (root:shadow) and permissions (640 or more restrictive)
- ▌ Cis Ubuntu 14 04 Lts 6 1 6 Ensure Permissions On Etc Passwd · cyberstrikeusVerify /etc/passwd- has correct ownership (root:root) and permissions (644 or more restrictive)
- ▌ Cis Ubuntu 14 04 Lts 6 1 7 Ensure Permissions On Etc Shadow · cyberstrikeusVerify /etc/shadow- has correct ownership and permissions (640 or more restrictive)
- ▌ Cis Ubuntu 14 04 Lts 6 1 8 Ensure Permissions On Etc Group A · cyberstrikeusVerify /etc/group- has correct ownership (root:root) and permissions (644 or more restrictive)
- ▌ Cis Ubuntu 14 04 Lts 6 1 9 Ensure Permissions On Etc Gshadow · cyberstrikeusVerify /etc/gshadow- has correct ownership and permissions (640 or more restrictive)
- ▌ Cis Ubuntu 14 04 Lts 6 2 1 Ensure Password Fields Are Not Em · cyberstrikeusVerify all accounts in /etc/shadow have a password or are locked
- ▌ Cis Ubuntu 14 04 Lts 6 2 2 Ensure No Legacy Entries Exist In · cyberstrikeusVerify no legacy NIS '+' entries exist in /etc/passwd
- ▌ Cis Ubuntu 14 04 Lts 6 2 3 Ensure No Legacy Entries Exist In · cyberstrikeusVerify no legacy NIS '+' entries exist in /etc/shadow
- ▌ Cis Ubuntu 14 04 Lts 6 2 4 Ensure No Legacy Entries Exist In · cyberstrikeusVerify no legacy NIS '+' entries exist in /etc/group
- ▌ Cis Ubuntu 14 04 Lts 6 2 5 Ensure Root Is The Only Uid 0 Acc · cyberstrikeusVerify that only the root account has UID 0
- ▌ Cis Ubuntu 14 04 Lts 6 2 6 Ensure Root Path Integrity · cyberstrikeusVerify root PATH does not contain writable or non-root-owned directories
- ▌ Cis Ubuntu 14 04 Lts 6 2 7 Ensure All Users Home Directories · cyberstrikeusVerify that all users defined in /etc/passwd have existing home directories
- ▌ Cis Ubuntu 14 04 Lts 6 2 8 Ensure Users Home Directories Per · cyberstrikeusVerify user home directories have permissions of 750 or more restrictive
- ▌ Cis Ubuntu 14 04 Lts 6 2 9 Ensure Users Own Their Home Direc · cyberstrikeusVerify that users own their assigned home directories
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ubuntu1604 V200 1 4 1 · cyberstrikeusEnsure permissions on bootloader config are not overridden
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ubuntu1604 V200 1 5 2 · cyberstrikeusEnsure address space layout randomization (ASLR) is enabled
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌