cyberstrikeus
- 7.2k skills
- 0 followers
- 22 hours ago last updated
- ▌
- ▌ Cis Apache24 7 12 · cyberstrikeusEnsure Only Cipher Suites That Provide Forward Secrecy Are Enabled (Manual)
- ▌
- ▌ Cis Azure Compute 2 1 11 · cyberstrikeusEnsure incoming client certificates are enabled and required (if in use)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Azure Compute 2 1 16 · cyberstrikeusEnsure private endpoints are used to access App Service apps
- ▌ Cis Azure Compute 2 1 17 · cyberstrikeusEnsure private endpoints used to access App Service apps use private DNS zones
- ▌
- ▌ Cis Azure Compute 2 1 19 · cyberstrikeusEnsure configuration is routed through the virtual network integration
- ▌
- ▌ Cis Azure Compute 2 1 21 · cyberstrikeusEnsure cross-origin resource sharing does not allow all origins
- ▌
- ▌ Cis Azure Compute 2 2 11 · cyberstrikeusEnsure incoming client certificates are enabled and required (if in use)
- ▌
- ▌
- ▌ Cis Azure Compute 2 2 14 · cyberstrikeusEnsure deployment slot is integrated with a virtual network
- ▌ Cis Azure Compute 2 2 15 · cyberstrikeusEnsure configuration is routed through the virtual network integration
- ▌
- ▌ Cis Azure Compute 2 2 17 · cyberstrikeusEnsure cross-origin resource sharing does not allow all origins
- ▌ Cis Azure Compute 2 3 10 · cyberstrikeusEnsure incoming client certificates are enabled and required (if in use)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Azure Compute 2 3 15 · cyberstrikeusEnsure configuration is routed through the virtual network integration
- ▌
- ▌ Cis Azure Compute 2 3 17 · cyberstrikeusEnsure cross-origin resource sharing does not allow all origins
- ▌ Cis Azure Compute 2 4 10 · cyberstrikeusEnsure incoming client certificates are enabled and required (if in use)
- ▌
- ▌
- ▌ Cis Azure Compute 2 4 13 · cyberstrikeusEnsure deployment slot is integrated with a virtual network
- ▌ Cis Azure Compute 2 4 14 · cyberstrikeusEnsure configuration is routed through the virtual network integration
- ▌
- ▌ Cis Azure Compute 2 4 16 · cyberstrikeusEnsure cross-origin resource sharing does not allow all origins
- ▌
- ▌ Cis Azure Database 6 10 · cyberstrikeusEnsure server parameter 'require_secure_transport' is set to 'ON' for PostgreSQL server
- ▌ Cis Azure Database 6 11 · cyberstrikeusEnsure server parameter 'ssl_min_protocol_version' is set to 'TLSv1.2' or higher for PostgreSQL server
- ▌ Cis Azure Foundations 6 1 1 1 · cyberstrikeusEnsure that a 'Diagnostic Setting' exists for Subscription Activity Logs
- ▌ Cis Azure Foundations 6 1 1 2 · cyberstrikeusEnsure Diagnostic Setting captures appropriate categories
- ▌ Cis Azure Foundations 6 1 1 3 · cyberstrikeusEnsure storage account containing activity logs is encrypted with CMK
- ▌
- ▌ Cis Azure Foundations 6 1 1 5 · cyberstrikeusEnsure Network Security Group Flow logs are captured and sent to Log Analytics
- ▌ Cis Azure Foundations 6 1 1 6 · cyberstrikeusEnsure logging for Azure AppService 'HTTP logs' is enabled
- ▌ Cis Azure Foundations 6 1 1 7 · cyberstrikeusEnsure virtual network flow logs are captured and sent to Log Analytics
- ▌ Cis Azure Foundations 6 1 1 8 · cyberstrikeusEnsure Microsoft Entra diagnostic setting exists to send Microsoft Graph activity logs
- ▌ Cis Azure Foundations 6 1 1 9 · cyberstrikeusEnsure Microsoft Entra diagnostic setting exists to send Microsoft Entra activity logs
- ▌ Cis Azure Foundations 6 1 2 1 · cyberstrikeusEnsure Activity Log Alert exists for Create Policy Assignment
- ▌ Cis Azure Foundations 6 1 2 2 · cyberstrikeusEnsure Activity Log Alert exists for Delete Policy Assignment
- ▌ Cis Azure Foundations 6 1 2 3 · cyberstrikeusEnsure Activity Log Alert exists for Create or Update Network Security Group
- ▌ Cis Azure Foundations 6 1 2 4 · cyberstrikeusEnsure Activity Log Alert exists for Delete Network Security Group
- ▌ Cis Azure Foundations 6 1 2 5 · cyberstrikeusEnsure Activity Log Alert exists for Create or Update Security Solution
- ▌ Cis Azure Foundations 6 1 2 6 · cyberstrikeusEnsure Activity Log Alert exists for Delete Security Solution
- ▌ Cis Azure Foundations 6 1 2 7 · cyberstrikeusEnsure Activity Log Alert exists for Create or Update SQL Server Firewall Rule
- ▌ Cis Azure Foundations 6 1 2 8 · cyberstrikeusEnsure Activity Log Alert exists for Delete SQL Server Firewall Rule
- ▌ Cis Azure Foundations 6 1 2 9 · cyberstrikeusEnsure Activity Log Alert exists for Create or Update Public IP Address rule
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Azure Foundations 8 1 3 2 · cyberstrikeusEnsure 'Vulnerability assessment for machines' component status is set to 'On'
- ▌ Cis Azure Foundations 8 1 3 3 · cyberstrikeusEnsure 'Endpoint protection' component status is set to 'On'
- ▌ Cis Azure Foundations 8 1 3 4 · cyberstrikeusEnsure 'Agentless scanning for machines' component status is set to 'On'
- ▌ Cis Azure Foundations 8 1 3 5 · cyberstrikeusEnsure 'File Integrity Monitoring' component status is set to 'On'
- ▌ Cis Azure Foundations 8 1 4 1 · cyberstrikeusEnsure That Microsoft Defender for Containers Is Set To 'On'
- ▌ Cis Azure Foundations 8 1 5 1 · cyberstrikeusEnsure That Microsoft Defender for Storage Is Set To 'On'
- ▌ Cis Azure Foundations 8 1 5 2 · cyberstrikeusEnsure Advanced Threat Protection Alerts for Storage Accounts Are Monitored
- ▌ Cis Azure Foundations 8 1 6 1 · cyberstrikeusEnsure That Microsoft Defender for App Services Is Set To 'On'
- ▌ Cis Azure Foundations 8 1 7 1 · cyberstrikeusEnsure That Microsoft Defender for Azure Cosmos DB Is Set To 'On'
- ▌ Cis Azure Foundations 8 1 7 2 · cyberstrikeusEnsure That Microsoft Defender for Open-Source Relational Databases Is Set To 'On'
- ▌ Cis Azure Foundations 8 1 7 3 · cyberstrikeusEnsure That Microsoft Defender for Azure SQL Databases Is Set To 'On'
- ▌ Cis Azure Foundations 8 1 7 4 · cyberstrikeusEnsure That Microsoft Defender for SQL Servers on Machines Is Set To 'On'
- ▌ Cis Azure Foundations 8 1 8 1 · cyberstrikeusEnsure That Microsoft Defender for Key Vault Is Set To 'On'
- ▌
- ▌ Cis Azure Foundations 9 3 1 1 · cyberstrikeusEnsure 'Enable key rotation reminders' is enabled for each Storage Account
- ▌ Cis Azure Foundations 9 3 1 2 · cyberstrikeusEnsure Storage Account access keys are periodically regenerated
- ▌ Cis Azure Foundations 9 3 1 3 · cyberstrikeusEnsure 'Allow storage account key access' for Azure Storage Accounts is 'Disabled'
- ▌ Cis Azure Foundations 9 3 2 1 · cyberstrikeusEnsure Private Endpoints are used to access Storage Accounts
- ▌ Cis Azure Foundations 9 3 2 2 · cyberstrikeusEnsure 'Public Network Access' is 'Disabled' for storage accounts
- ▌ Cis Azure Foundations 9 3 2 3 · cyberstrikeusEnsure default network access rule for storage accounts is set to deny
- ▌ Cis Azure Foundations 9 3 3 1 · cyberstrikeusEnsure 'Default to Microsoft Entra authorization in the Azure portal' is set to 'Enabled'
- ▌ Cis Azure Storage 17 1 1 · cyberstrikeusEnsure that 'Enable key rotation reminders' is enabled for each Storage Account
- ▌ Cis Azure Storage 17 1 2 · cyberstrikeusEnsure 'Allowed Protocols' for shared access signature (SAS) tokens is set to 'HTTPS Only'
- ▌ Cis Azure Storage 17 1 3 · cyberstrikeusEnsure that Storage Account Access Keys are Periodically Regenerated
- ▌ Cis Azure Storage 17 1 4 · cyberstrikeusEnsure that shared access signature (SAS) tokens expire within an hour
- ▌ Cis Azure Storage 17 1 5 · cyberstrikeusEnsure 'Allow storage account key access' for Azure Storage Accounts is 'Disabled'
- ▌ Cis Azure Storage 17 1 6 · cyberstrikeusEnsure Storage for Critical Data are Encrypted with Customer Managed Keys (CMK)
- ▌ Cis Azure Storage 17 2 1 · cyberstrikeusEnsure Private Endpoints are used to access Storage Accounts
- ▌ Cis Azure Storage 17 2 2 · cyberstrikeusEnsure that 'Public Network Access' is 'Disabled' for storage accounts
- ▌ Cis Azure Storage 17 2 3 · cyberstrikeusEnsure Default Network Access Rule for Storage Accounts is Set to Deny
- ▌
- ▌
- ▌ Cis Ubuntu1804 V220 5 2 3 10 · cyberstrikeusEnsure unsuccessful unauthorized file access attempts are collected
- ▌
- ▌
- ▌
- ▌ Cis Ubuntu1804 V220 5 2 3 14 · cyberstrikeusEnsure events that modify the system's Mandatory Access Controls are collected
- ▌ Cis Ubuntu1804 V220 5 2 3 15 · cyberstrikeusEnsure successful and unsuccessful attempts to use the chcon command are recorded