← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 27 of 72

  1. Cis Ubuntu 14 04 Lts 3 2 3 Ensure Secure Icmp Redirects Are · cyberstrikeus
    Verify that secure ICMP redirects are not accepted to prevent routing table manipulation from known gateways
    0 installs
  2. Cis Ubuntu 14 04 Lts 3 2 4 Ensure Suspicious Packets Are Log · cyberstrikeus
    Verify that packets with un-routable source addresses are logged for investigation
    0 installs
  3. Cis Ubuntu 14 04 Lts 3 2 5 Ensure Broadcast Icmp Requests Ar · cyberstrikeus
    Verify that broadcast ICMP echo and timestamp requests are ignored to prevent Smurf attacks
    0 installs
  4. Cis Ubuntu 14 04 Lts 3 2 6 Ensure Bogus Icmp Responses Are I · cyberstrikeus
    Verify that bogus ICMP error responses are ignored to prevent log file pollution
    0 installs
  5. Cis Ubuntu 14 04 Lts 3 2 7 Ensure Reverse Path Filtering Is · cyberstrikeus
    Verify that reverse path filtering is enabled to prevent IP spoofing
    0 installs
  6. Cis Ubuntu 14 04 Lts 3 2 8 Ensure Tcp Syn Cookies Is Enabled · cyberstrikeus
    Verify that TCP SYN Cookies are enabled to protect against SYN flood attacks
    0 installs
  7. Cis Ubuntu 14 04 Lts 3 3 1 Ensure Ipv6 Router Advertisements · cyberstrikeus
    Verify that IPv6 router advertisements are not accepted to prevent routing to compromised machines
    0 installs
  8. Cis Ubuntu 14 04 Lts 3 3 2 Ensure Ipv6 Redirects Are Not Acc · cyberstrikeus
    Verify that IPv6 ICMP redirects are not accepted to prevent routing to compromised machines
    0 installs
  9. Cis Ubuntu 14 04 Lts 3 3 3 Ensure Ipv6 Is Disabled · cyberstrikeus
    Verify that IPv6 is disabled if not required to reduce the attack surface
    0 installs
  10. Cis Ubuntu 14 04 Lts 3 4 1 Ensure Tcp Wrappers Is Installed · cyberstrikeus
    Verify that TCP Wrappers is installed for host-based access control
    0 installs
  11. Cis Ubuntu 14 04 Lts 3 4 2 Ensure Etc Hosts Allow Is Configu · cyberstrikeus
    Verify that /etc/hosts.allow is configured to permit authorized network access
    0 installs
  12. Cis Ubuntu 14 04 Lts 3 4 3 Ensure Etc Hosts Deny Is Configur · cyberstrikeus
    Verify that /etc/hosts.deny is configured to deny all unauthorized network access
    0 installs
  13. Cis Ubuntu 14 04 Lts 3 4 4 Ensure Permissions On Etc Hosts A · cyberstrikeus
    Verify that /etc/hosts.allow has correct ownership and permissions (root:root 644)
    0 installs
  14. Cis Ubuntu 14 04 Lts 3 4 5 Ensure Permissions On Etc Hosts D · cyberstrikeus
    Verify that /etc/hosts.deny has correct ownership and permissions (root:root 644)
    0 installs
  15. Cis Ubuntu 14 04 Lts 3 5 1 Ensure Dccp Is Disabled · cyberstrikeus
    Verify that the DCCP protocol kernel module is disabled to reduce attack surface
    0 installs
  16. Cis Ubuntu 14 04 Lts 3 5 2 Ensure Sctp Is Disabled · cyberstrikeus
    Verify that the SCTP protocol kernel module is disabled to reduce attack surface
    0 installs
  17. Cis Ubuntu 14 04 Lts 3 5 3 Ensure Rds Is Disabled · cyberstrikeus
    Verify that the RDS protocol kernel module is disabled to reduce attack surface
    0 installs
  18. Cis Ubuntu 14 04 Lts 3 5 4 Ensure Tipc Is Disabled · cyberstrikeus
    Verify that the TIPC protocol kernel module is disabled to reduce attack surface
    0 installs
  19. Cis Ubuntu 14 04 Lts 3 6 1 Ensure Iptables Is Installed · cyberstrikeus
    Verify that iptables is installed for firewall management and configuration
    0 installs
  20. Cis Ubuntu 14 04 Lts 3 6 2 Ensure Default Deny Firewall Poli · cyberstrikeus
    Verify that default deny firewall policy is configured for INPUT, OUTPUT, and FORWARD chains
    0 installs
  21. Cis Ubuntu 14 04 Lts 3 6 3 Ensure Loopback Traffic Is Config · cyberstrikeus
    Verify that loopback interface accepts traffic and other interfaces deny loopback network traffic
    0 installs
  22. Cis Ubuntu 14 04 Lts 3 6 4 Ensure Outbound And Established C · cyberstrikeus
    Verify that firewall rules for outbound and established connections are configured
    0 installs
  23. Cis Ubuntu 14 04 Lts 3 6 5 Ensure Firewall Rules Exist For A · cyberstrikeus
    Verify that firewall rules exist for all open ports on non-loopback addresses
    0 installs
  24. Cis Ubuntu 14 04 Lts 4 1 2 Ensure Auditd Service Is Enabled · cyberstrikeus
    Enable the auditd daemon to record system events for security monitoring
    0 installs
  25. Cis Ubuntu 14 04 Lts 4 1 3 Ensure Auditing For Processes Tha · cyberstrikeus
    Configure grub to enable auditing for processes that start before auditd
    0 installs
  26. Cis Ubuntu 14 04 Lts 4 1 4 Ensure Events That Modify Date An · cyberstrikeus
    Collect audit events for system date and time modifications to detect tampering
    0 installs
  27. Cis Ubuntu 14 04 Lts 4 1 5 Ensure Events That Modify User Gr · cyberstrikeus
    Collect audit events for modifications to user and group identity files
    0 installs
  28. Cis Ubuntu 14 04 Lts 4 1 6 Ensure Events That Modify The Sys · cyberstrikeus
    Collect audit events for changes to network environment files and system calls
    0 installs
  29. Cis Ubuntu 14 04 Lts 4 1 7 Ensure Events That Modify The Sys · cyberstrikeus
    Collect audit events for modifications to SELinux/AppArmor mandatory access controls
    0 installs
  30. Cis Ubuntu 14 04 Lts 4 1 8 Ensure Login And Logout Events Ar · cyberstrikeus
    Collect audit events for login and logout activity from faillog, lastlog, and tallylog
    0 installs
  31. Cis Ubuntu 14 04 Lts 4 1 9 Ensure Session Initiation Informa · cyberstrikeus
    Collect audit events for session initiation from utmp, wtmp, and btmp files
    0 installs
  32. Cis Ubuntu 14 04 Lts 4 2 3 Ensure Rsyslog Or Syslog Ng Is In · cyberstrikeus
    Ensure either rsyslog or syslog-ng is installed for system logging
    0 installs
  33. Cis Ubuntu 14 04 Lts 4 2 4 Ensure Permissions On All Logfile · cyberstrikeus
    Ensure restrictive permissions on all log files in /var/log to protect sensitive data
    0 installs
  34. Cis Ubuntu 14 04 Lts 5 1 1 Ensure Cron Daemon Is Enabled · cyberstrikeus
    Verify the cron daemon is enabled to execute scheduled batch jobs on the system
    0 installs
  35. Cis Ubuntu 14 04 Lts 5 1 2 Ensure Permissions On Etc Crontab · cyberstrikeus
    Verify /etc/crontab ownership and permissions are restricted to root with no group/other access
    0 installs
  36. Cis Ubuntu 14 04 Lts 5 1 3 Ensure Permissions On Etc Cron Ho · cyberstrikeus
    Verify /etc/cron.hourly ownership and permissions are restricted to root with no group/other access
    0 installs
  37. Cis Ubuntu 14 04 Lts 5 1 4 Ensure Permissions On Etc Cron Da · cyberstrikeus
    Verify /etc/cron.daily ownership and permissions are restricted to root with no group/other access
    0 installs
  38. Cis Ubuntu 14 04 Lts 5 1 5 Ensure Permissions On Etc Cron We · cyberstrikeus
    Verify /etc/cron.weekly ownership and permissions are restricted to root with no group/other access
    0 installs
  39. Cis Ubuntu 14 04 Lts 5 1 6 Ensure Permissions On Etc Cron Mo · cyberstrikeus
    Verify /etc/cron.monthly ownership and permissions are restricted to root with no group/other access
    0 installs
  40. Cis Ubuntu 14 04 Lts 5 1 7 Ensure Permissions On Etc Cron D · cyberstrikeus
    Verify /etc/cron.d ownership and permissions are restricted to root with no group/other access
    0 installs
  41. Cis Ubuntu 14 04 Lts 5 1 8 Ensure At Cron Is Restricted To A · cyberstrikeus
    Verify at and cron access is restricted using allow files with proper ownership and permissions
    0 installs
  42. Cis Ubuntu 14 04 Lts 5 2 1 Ensure Permissions On Etc Ssh Ssh · cyberstrikeus
    Verify /etc/ssh/sshd_config ownership and permissions are restricted to root with no group/other access
    0 installs
  43. Cis Ubuntu 14 04 Lts 5 2 2 Ensure Ssh Protocol Is Set To 2 · cyberstrikeus
    Verify SSH is configured to use Protocol version 2 only
    0 installs
  44. Cis Ubuntu 14 04 Lts 5 2 3 Ensure Ssh Loglevel Is Set To Inf · cyberstrikeus
    Verify SSH LogLevel is configured to INFO for adequate logging of login activity
    0 installs
  45. Cis Ubuntu 14 04 Lts 5 2 4 Ensure Ssh X11 Forwarding Is Disa · cyberstrikeus
    Verify SSH X11 forwarding is disabled to prevent remote graphic connection tunneling
    0 installs
  46. Cis Ubuntu 14 04 Lts 5 2 5 Ensure Ssh Maxauthtries Is Set To · cyberstrikeus
    Verify SSH MaxAuthTries is set to 4 or less to limit brute force attack risk
    0 installs
  47. Cis Ubuntu 14 04 Lts 5 2 6 Ensure Ssh Ignorerhosts Is Enable · cyberstrikeus
    Verify SSH IgnoreRhosts is set to yes to prevent .rhosts-based authentication
    0 installs
  48. Cis Bind9 V301 2 4 · cyberstrikeus
    Set root Ownership of BIND Directories (Automated)
    0 installs
  49. Cis Bind9 V301 2 5 · cyberstrikeus
    Set root Ownership of BIND Configuration Files (Automated)
    0 installs
  50. Cis Bind9 V301 2 6 · cyberstrikeus
    Set Group named or root for BIND Directories and Files (Automated)
    0 installs
  51. Cis Bind9 V301 2 7 · cyberstrikeus
    Set Group and Other Permissions Read-Only for BIND Non-Runtime Directories (Automated)
    0 installs
  52. Cis Bind9 V301 2 8 · cyberstrikeus
    Set Group and Other Permissions Read-Only for All BIND Files (Automated)
    0 installs
  53. Cis Bind9 V301 2 9 · cyberstrikeus
    Isolate BIND with chroot'ed Subdirectory (Automated)
    0 installs
  54. Cis Bind9 V301 3 1 · cyberstrikeus
    Ignore Erroneous or Unwanted Queries (Automated)
    0 installs
  55. Cis Bind9 V301 3 2 · cyberstrikeus
    Restrict Recursive Queries (Automated)
    0 installs
  56. Cis Bind9 V301 3 3 · cyberstrikeus
    Restrict Query Origins (Manual)
    0 installs
  57. Cis Bind9 V301 3 4 · cyberstrikeus
    Restrict Queries of the Cache (Automated)
    0 installs
  58. Cis Bind9 V301 4 1 · cyberstrikeus
    Use TSIG Keys 256 Bits in Length (Scored)
    0 installs
  59. Cis Bind9 V301 4 2 · cyberstrikeus
    Include Cryptographic Key Files (Scored)
    0 installs
  60. Cis Bind9 V301 4 3 · cyberstrikeus
    Use Unique Keys for Each Pair of Hosts (Scored)
    0 installs
  61. Cis Bind9 V301 4 4 · cyberstrikeus
    Restrict Access to All Key Files (Scored)
    0 installs
  62. Cis Bind9 V301 4 5 · cyberstrikeus
    Protect TSIG Key Files During Deployment (Not Scored)
    0 installs
  63. Cis Bind9 V301 5 1 · cyberstrikeus
    Securely Authenticate Zone Transfers (Scored)
    0 installs
  64. Cis Bind9 V301 5 2 · cyberstrikeus
    Securely Authenticate Dynamic Updates (Scored)
    0 installs
  65. Cis Bind9 V301 5 3 · cyberstrikeus
    Securely Authenticate Update Forwarding (Scored)
    0 installs
  66. Cis Bind9 V301 6 1 · cyberstrikeus
    Hide BIND Version String (Scored)
    0 installs
  67. Cis Bind9 V301 6 2 · cyberstrikeus
    Hide Nameserver ID (Scored)
    0 installs
  68. Cis Bind9 V301 7 1 · cyberstrikeus
    Do Not Define a Static Source Port (Scored)
    0 installs
  69. Cis Bind9 V301 7 2 · cyberstrikeus
    Enable DNSSEC Validation (Scored)
    0 installs
  70. Cis Bind9 V301 7 3 · cyberstrikeus
    Disable the dnssec-accept-expired Option (Scored)
    0 installs
  71. Cis Bind9 V301 8 1 · cyberstrikeus
    Apply Applicable Updates (Scored)
    0 installs
  72. Cis Bind9 V301 8 2 · cyberstrikeus
    Configure a Logging File Channel (Scored)
    0 installs
  73. Cis Bind9 V301 8 3 · cyberstrikeus
    Configure a Logging Syslog Channel (Scored)
    0 installs
  74. Cis Bind9 V301 8 4 · cyberstrikeus
    Disable the HTTP Statistics Server (Scored)
    0 installs
  75. Cis Eks V160 2 1 1 · cyberstrikeus
    Enable audit Logs (Automated)
    0 installs
  76. Cis Eks V160 2 1 2 · cyberstrikeus
    Ensure audit logs are collected and managed (Manual)
    0 installs
  77. Cis Eks V160 3 1 1 · cyberstrikeus
    Ensure that the kubeconfig file permissions are set to 644 or more restrictive (Automated)
    0 installs
  78. Cis Eks V160 3 1 2 · cyberstrikeus
    Ensure that the kubelet kubeconfig file ownership is set to root:root (Automated)
    0 installs
  79. Cis Eks V160 3 1 3 · cyberstrikeus
    Ensure that the kubelet configuration file has permissions set to 644 or more restrictive (Automated)
    0 installs
  80. Cis Eks V160 3 1 4 · cyberstrikeus
    Ensure that the kubelet configuration file ownership is set to root:root (Automated)
    0 installs
  81. Cis Eks V160 3 2 1 · cyberstrikeus
    Ensure that the Anonymous Auth is Not Enabled (Automated)
    0 installs
  82. Cis Eks V160 3 2 2 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0 installs
  83. Cis Eks V160 3 2 3 · cyberstrikeus
    Ensure that a Client CA File is Configured (Automated)
    0 installs
  84. Cis Eks V160 3 2 4 · cyberstrikeus
    Ensure that the --read-only-port is disabled (Automated)
    0 installs
  85. Cis Eks V160 3 2 5 · cyberstrikeus
    Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
    0 installs
  86. Cis Eks V160 3 2 6 · cyberstrikeus
    Ensure that the --make-iptables-util-chains argument is set to true (Automated)
    0 installs
  87. Cis Eks V160 3 2 7 · cyberstrikeus
    Ensure that the --eventRecordQPS argument is set to 0 or a level which ensures appropriate event capture (Automated)
    0 installs
  88. Cis Eks V160 3 2 8 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not present or is set to true (Automated)
    0 installs
  89. Cis Eks V160 3 2 9 · cyberstrikeus
    Ensure that the RotateKubeletServerCertificate argument is set to true (Automated)
    0 installs
  90. Cis Eks V160 4 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Automated)
    0 installs
  91. Cis Eks V160 4 1 2 · cyberstrikeus
    Minimize access to secrets (Automated)
    0 installs
  92. Cis Eks V160 4 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Automated)
    0 installs
  93. Cis Eks V160 4 1 4 · cyberstrikeus
    Minimize access to create pods (Automated)
    0 installs
  94. Cis Eks V160 4 1 5 · cyberstrikeus
    Ensure that default service accounts are not actively used (Automated)
    0 installs
  95. Cis Eks V160 4 1 6 · cyberstrikeus
    Ensure that Service Account Tokens are only mounted where necessary (Automated)
    0 installs
  96. Cis Eks V160 4 1 7 · cyberstrikeus
    Cluster Access Manager API to streamline and enhance the management of access controls within EKS clusters (Automated)
    0 installs
  97. Cis Eks V160 4 1 8 · cyberstrikeus
    Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
    0 installs
  98. Cis Eks V160 4 2 1 · cyberstrikeus
    Minimize the admission of privileged containers (Automated)
    0 installs
  99. Cis Eks V160 4 2 2 · cyberstrikeus
    Minimize the admission of containers wishing to share the host process ID namespace (Automated)
    0 installs
  100. Cis Eks V160 4 2 3 · cyberstrikeus
    Minimize the admission of containers wishing to share the host IPC namespace (Automated)
    0 installs