cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌
- ▌
- ▌ Cis Gworkspace 3 1 3 7 2 · cyberstrikeusEnsure 'Send email over a secure TLS connection' Is Enabled
- ▌ Cis Gworkspace 3 1 4 1 1 · cyberstrikeusEnsure external filesharing in Google Chat and Hangouts is disabled
- ▌ Cis Gworkspace 3 1 4 1 2 · cyberstrikeusEnsure internal filesharing in Google Chat and Hangouts is disabled
- ▌ Cis Gworkspace 3 1 4 2 1 · cyberstrikeusEnsure Google Chat externally is restricted to allowed domains
- ▌ Cis Gworkspace 3 1 4 3 1 · cyberstrikeusEnsure external spaces in Google Chat and Hangouts are restricted
- ▌
- ▌ Cis Gworkspace 3 1 4 4 2 · cyberstrikeusEnsure allow users to add and use incoming webhooks is disabled
- ▌ Cis Gworkspace 3 1 9 1 1 · cyberstrikeusEnsure users access to Google Workspace Marketplace apps is restricted
- ▌
- ▌ Cis Azure Compute 2 6 · cyberstrikeusEnsure App Service Environment is deployed with an internal load balancer
- ▌ Cis Azure Compute 2 7 · cyberstrikeusEnsure App Service Environment is provisioned with v3 or higher
- ▌ Cis Azure Compute 2 8 · cyberstrikeusEnsure App Service Environment has internal encryption enabled
- ▌
- ▌ Cis Azure Compute 3 1 · cyberstrikeusEnsure Private Virtual Networks are used for Container Instances
- ▌ Cis Azure Compute 3 2 · cyberstrikeusEnsure a Managed Identity is used for interactions with other Azure services
- ▌ Cis Azure Compute 3 3 · cyberstrikeusEnsure the principle of least privilege is used when assigning roles to a Managed Identity
- ▌
- ▌ Cis Azure Foundations 5 10 · cyberstrikeusEnsure 'Notify users on password resets?' is set to 'Yes'
- ▌ Cis Azure Foundations 5 11 · cyberstrikeusEnsure 'Notify all admins when other admins reset their password?' is set to 'Yes'
- ▌ Cis Azure Foundations 5 12 · cyberstrikeusEnsure 'User consent for applications' is set to 'Do not allow user consent'
- ▌ Cis Azure Foundations 5 13 · cyberstrikeusEnsure 'User consent for applications' is set to 'Allow user consent for apps from verified publishers, for selected permissions'
- ▌
- ▌ Cis Azure Foundations 5 15 · cyberstrikeusEnsure 'Guest users access restrictions' is set to 'Guest user access is restricted to properties and memberships of their own directory objects'
- ▌ Cis Azure Foundations 5 16 · cyberstrikeusEnsure 'Guest invite restrictions' is set to 'Only users assigned to specific admin roles can invite guest users' or 'No one in the organization can invite guest users'
- ▌ Cis Azure Foundations 5 17 · cyberstrikeusEnsure 'Restrict access to Microsoft Entra admin center' is set to 'Yes'
- ▌ Cis Azure Foundations 5 18 · cyberstrikeusEnsure 'Restrict user ability to access groups features in My Groups' is set to 'Yes'
- ▌ Cis Azure Foundations 5 19 · cyberstrikeusEnsure 'Users can create security groups in Azure portals, API or PowerShell' is set to 'No'
- ▌ Cis Azure Foundations 5 20 · cyberstrikeusEnsure 'Owners can manage group membership requests in My Groups' is set to 'No'
- ▌ Cis Azure Foundations 5 21 · cyberstrikeusEnsure 'Users can create Microsoft 365 groups in Azure portals, API or PowerShell' is set to 'No'
- ▌ Cis Azure Foundations 5 22 · cyberstrikeusEnsure 'Require Multifactor Authentication to register or join devices with Microsoft Entra' is set to 'Yes'
- ▌
- ▌ Cis Azure Foundations 5 24 · cyberstrikeusEnsure a custom role is assigned permissions for administering resource locks
- ▌ Cis Azure Foundations 5 25 · cyberstrikeusEnsure 'Subscription leaving/entering Microsoft Entra tenant' is set to 'Permit no one'
- ▌ Cis Azure Foundations 5 26 · cyberstrikeusEnsure fewer than 5 users have global administrator assignment
- ▌
- ▌ Cis Azure Foundations 5 28 · cyberstrikeusEnsure passwordless authentication methods are considered
- ▌ Cis Azure Foundations 7 10 · cyberstrikeusEnsure Azure Web Application Firewall (WAF) is enabled on Azure Application Gateway
- ▌ Cis Azure Foundations 7 11 · cyberstrikeusEnsure subnets are associated with network security groups
- ▌ Cis Azure Foundations 7 12 · cyberstrikeusEnsure the SSL policy's 'Min protocol version' is set to 'TLSv1_2' or higher on Azure Application Gateway
- ▌ Cis Azure Foundations 7 13 · cyberstrikeusEnsure 'HTTP2' is set to 'Enabled' on Azure Application Gateway
- ▌ Cis Azure Foundations 7 14 · cyberstrikeusEnsure request body inspection is enabled in Azure WAF policy on Azure Application Gateway
- ▌ Cis Azure Foundations 7 15 · cyberstrikeusEnsure bot protection is enabled in Azure WAF policy on Azure Application Gateway
- ▌ Cis Azure Foundations 7 16 · cyberstrikeusEnsure Azure Network Security Perimeter is used to secure Azure PaaS resources
- ▌ Cis Azure Storage 4 1 · cyberstrikeusEnsure 'Key encryption key' is set to a customer-managed key for Azure Managed Lustre file systems
- ▌
- ▌
- ▌ Cis Azure Storage 8 3 · cyberstrikeusEnsure 'SMB protocol version' is set to 'SMB 3.1.1' or higher for SMB file shares
- ▌ Cis Azure Storage 8 4 · cyberstrikeusEnsure 'SMB channel encryption' is set to 'AES-256-GCM' or higher for SMB file shares
- ▌
- ▌
- ▌
- ▌ Cis Ubuntu 14 04 Lts 1 1 2 Ensure Separate Partition Exists · cyberstrikeusEnsure a separate partition exists for /tmp to prevent resource exhaustion
- ▌ Cis Ubuntu 14 04 Lts 1 1 3 Ensure Nodev Option Set On Tmp Pa · cyberstrikeusEnsure nodev option is set on /tmp partition to prevent special device access
- ▌ Cis Ubuntu 14 04 Lts 1 1 4 Ensure Nosuid Option Set On Tmp P · cyberstrikeusEnsure nosuid option is set on /tmp partition to prevent setuid file creation
- ▌ Cis Ubuntu 14 04 Lts 1 1 5 Ensure Separate Partition Exists · cyberstrikeusEnsure a separate partition exists for /var to prevent resource exhaustion
- ▌ Cis Ubuntu 14 04 Lts 1 1 6 Ensure Separate Partition Exists · cyberstrikeusEnsure a separate partition exists for /var/tmp to prevent resource exhaustion
- ▌ Cis Ubuntu 14 04 Lts 1 1 7 Ensure Nodev Option Set On Var Tm · cyberstrikeusEnsure nodev option is set on /var/tmp partition to prevent special device access
- ▌ Cis Ubuntu 14 04 Lts 1 1 8 Ensure Nosuid Option Set On Var T · cyberstrikeusEnsure nosuid option is set on /var/tmp partition to prevent setuid file creation
- ▌ Cis Ubuntu 14 04 Lts 1 1 9 Ensure Noexec Option Set On Var T · cyberstrikeusEnsure noexec option is set on /var/tmp partition to prevent executable binaries
- ▌ Cis Ubuntu 14 04 Lts 1 2 1 Ensure Package Manager Repositori · cyberstrikeusVerify that package manager repositories are properly configured to receive latest patches and updates
- ▌ Cis Ubuntu 14 04 Lts 1 2 2 Ensure Gpg Keys Are Configured · cyberstrikeusVerify that GPG keys are configured for package manager to ensure package integrity
- ▌ Cis Ubuntu 14 04 Lts 1 3 1 Ensure Aide Is Installed · cyberstrikeusVerify that AIDE file integrity checking tool is installed for filesystem monitoring
- ▌ Cis Ubuntu 14 04 Lts 1 3 2 Ensure Filesystem Integrity Is Re · cyberstrikeusVerify that filesystem integrity checking is scheduled via cron to detect unauthorized changes
- ▌ Cis Ubuntu 14 04 Lts 1 4 1 Ensure Permissions On Bootloader · cyberstrikeusVerify that permissions on grub bootloader configuration are restricted to root only
- ▌ Cis Ubuntu 14 04 Lts 1 4 2 Ensure Bootloader Password Is Set · cyberstrikeusVerify that a bootloader password is set to prevent unauthorized boot parameter changes
- ▌ Cis Ubuntu 14 04 Lts 1 4 3 Ensure Authentication Required Fo · cyberstrikeusVerify that authentication is required when booting into single user mode
- ▌ Cis Ubuntu 14 04 Lts 1 5 1 Ensure Core Dumps Are Restricted · cyberstrikeusVerify that core dumps are restricted to prevent information disclosure from memory dumps
- ▌ Cis Ubuntu 14 04 Lts 1 5 2 Ensure Xd Nx Support Is Enabled · cyberstrikeusVerify that XD/NX (Execute Disable/No Execute) CPU protection is enabled to prevent buffer overflow exploitation
- ▌ Cis Ubuntu 14 04 Lts 1 5 3 Ensure Address Space Layout Rando · cyberstrikeusVerify that ASLR is enabled to randomize process memory layout and mitigate exploits
- ▌ Cis Ubuntu 14 04 Lts 1 5 4 Ensure Prelink Is Disabled · cyberstrikeusVerify that prelink is disabled to prevent interference with AIDE integrity checking
- ▌ Cis Ubuntu 14 04 Lts 1 6 3 Ensure Selinux Or Apparmor Are In · cyberstrikeusVerify that either SELinux or AppArmor mandatory access control system is installed
- ▌ Cis Ubuntu 14 04 Lts 1 7 2 Ensure Gdm Login Banner Is Config · cyberstrikeusVerify that GDM graphical login banner is configured with appropriate warning message
- ▌ Cis Ubuntu 14 04 Lts 2 1 1 Ensure Chargen Services Are Not E · cyberstrikeusVerify that chargen inetd services are disabled to reduce attack surface
- ▌ Cis Ubuntu 14 04 Lts 2 1 2 Ensure Daytime Services Are Not E · cyberstrikeusVerify that daytime inetd services are disabled to reduce attack surface
- ▌ Cis Ubuntu 14 04 Lts 2 1 3 Ensure Discard Services Are Not E · cyberstrikeusVerify that discard inetd services are disabled to reduce attack surface
- ▌ Cis Ubuntu 14 04 Lts 2 1 4 Ensure Echo Services Are Not Enab · cyberstrikeusVerify that echo inetd services are disabled to reduce attack surface
- ▌ Cis Ubuntu 14 04 Lts 2 1 5 Ensure Time Services Are Not Enab · cyberstrikeusVerify that time inetd services are disabled to reduce attack surface
- ▌ Cis Ubuntu 14 04 Lts 2 1 6 Ensure Rsh Server Is Not Enabled · cyberstrikeusVerify that rsh, rlogin, and rexec inetd services are disabled
- ▌ Cis Ubuntu 14 04 Lts 2 1 7 Ensure Talk Server Is Not Enabled · cyberstrikeusVerify that talk inetd services are disabled to reduce attack surface
- ▌ Cis Ubuntu 14 04 Lts 2 1 8 Ensure Telnet Server Is Not Enabl · cyberstrikeusVerify that telnet inetd service is disabled to prevent cleartext credential exposure
- ▌ Cis Ubuntu 14 04 Lts 2 1 9 Ensure Tftp Server Is Not Enabled · cyberstrikeusVerify that tftp inetd service is disabled to prevent unauthenticated file transfers
- ▌ Cis Ubuntu 14 04 Lts 2 2 2 Ensure X Window System Is Not Ins · cyberstrikeusVerify that X Window System packages are not installed on servers
- ▌ Cis Ubuntu 14 04 Lts 2 2 3 Ensure Avahi Server Is Not Enable · cyberstrikeusVerify that Avahi mDNS/DNS-SD daemon is disabled to reduce attack surface
- ▌ Cis Ubuntu 14 04 Lts 2 2 4 Ensure Cups Is Not Enabled · cyberstrikeusVerify that CUPS print service is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 5 Ensure Dhcp Server Is Not Enabled · cyberstrikeusVerify that DHCP server service is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 6 Ensure Ldap Server Is Not Enabled · cyberstrikeusVerify that slapd LDAP server is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 7 Ensure Nfs And Rpc Are Not Enable · cyberstrikeusVerify that NFS and RPC services are disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 8 Ensure Dns Server Is Not Enabled · cyberstrikeusVerify that BIND DNS server is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 9 Ensure Ftp Server Is Not Enabled · cyberstrikeusVerify that vsftpd FTP server is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 3 1 Ensure Nis Client Is Not Installe · cyberstrikeusVerify that the NIS client (ypbind) package is not installed
- ▌ Cis Ubuntu 14 04 Lts 2 3 2 Ensure Rsh Client Is Not Installe · cyberstrikeusVerify that the rsh client package is not installed
- ▌ Cis Ubuntu 14 04 Lts 2 3 3 Ensure Talk Client Is Not Install · cyberstrikeusVerify that the talk client package is not installed
- ▌ Cis Ubuntu 14 04 Lts 2 3 4 Ensure Telnet Client Is Not Insta · cyberstrikeusVerify that the telnet client package is not installed
- ▌ Cis Ubuntu 14 04 Lts 2 3 5 Ensure Ldap Client Is Not Install · cyberstrikeusVerify that the LDAP client (ldap-utils) package is not installed
- ▌ Cis Ubuntu 14 04 Lts 3 1 1 Ensure Ip Forwarding Is Disabled · cyberstrikeusVerify that IP forwarding is disabled to prevent the system from acting as a router
- ▌ Cis Ubuntu 14 04 Lts 3 1 2 Ensure Packet Redirect Sending Is · cyberstrikeusVerify that ICMP packet redirect sending is disabled to prevent routing information disclosure
- ▌ Cis Ubuntu 14 04 Lts 3 2 1 Ensure Source Routed Packets Are · cyberstrikeusVerify that source routed packets are not accepted to prevent source routing attacks
- ▌ Cis Ubuntu 14 04 Lts 3 2 2 Ensure Icmp Redirects Are Not Acc · cyberstrikeusVerify that ICMP redirects are not accepted to prevent routing table manipulation