← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 28 of 72

  1. Cis Eks V160 4 2 4 · cyberstrikeus
    Minimize the admission of containers wishing to share the host network namespace (Automated)
    0 installs
  2. Cis Eks V160 4 2 5 · cyberstrikeus
    Minimize the admission of containers with allowPrivilegeEscalation (Automated)
    0 installs
  3. Cis Eks V160 4 3 1 · cyberstrikeus
    Ensure CNI plugin supports network policies (Manual)
    0 installs
  4. Cis Eks V160 4 3 2 · cyberstrikeus
    Ensure that all Namespaces have Network Policies defined (Automated)
    0 installs
  5. Cis Eks V160 4 4 1 · cyberstrikeus
    Prefer using secrets as files over secrets as environment variables (Automated)
    0 installs
  6. Cis Eks V160 4 4 2 · cyberstrikeus
    Consider external secret storage (Manual)
    0 installs
  7. Cis Eks V160 4 5 1 · cyberstrikeus
    Create administrative boundaries between resources using namespaces (Manual)
    0 installs
  8. Cis Eks V160 4 5 2 · cyberstrikeus
    The default namespace should not be used (Automated)
    0 installs
  9. Cis Eks V160 5 1 1 · cyberstrikeus
    Ensure Image Vulnerability Scanning using Amazon ECR image scanning or a third party provider (Automated)
    0 installs
  10. Cis Eks V160 5 1 2 · cyberstrikeus
    Minimize user access to Amazon ECR (Manual)
    0 installs
  11. Cis Eks V160 5 1 3 · cyberstrikeus
    Minimize cluster access to read-only for Amazon ECR (Manual)
    0 installs
  12. Cis Eks V160 5 1 4 · cyberstrikeus
    Minimize Container Registries to only those approved (Manual)
    0 installs
  13. Cis Eks V160 5 2 1 · cyberstrikeus
    Prefer using dedicated EKS Service Accounts (Automated)
    0 installs
  14. Cis Eks V160 5 3 1 · cyberstrikeus
    Ensure Kubernetes Secrets are encrypted using Customer Master Keys (CMKs) managed in AWS KMS (Manual)
    0 installs
  15. Cis Eks V160 5 4 1 · cyberstrikeus
    Restrict Access to the Control Plane Endpoint (Automated)
    0 installs
  16. Cis Eks V160 5 4 2 · cyberstrikeus
    Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
    0 installs
  17. Cis Eks V160 5 4 3 · cyberstrikeus
    Ensure clusters are created with Private Nodes (Automated)
    0 installs
  18. Cis Eks V160 5 4 4 · cyberstrikeus
    Ensure Network Policy is Enabled and set as appropriate (Automated)
    0 installs
  19. Cis Eks V160 5 4 5 · cyberstrikeus
    Encrypt traffic to HTTPS load balancers with TLS certificates (Manual)
    0 installs
  20. Cis Eks V160 5 5 1 · cyberstrikeus
    Manage Kubernetes RBAC users with AWS IAM Authenticator for Kubernetes or Upgrade to AWS CLI v1.16.156 or greater (Manual)
    0 installs
  21. Cis Eks V180 4 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Manual)
    0 installs
  22. Cis Eks V180 4 1 2 · cyberstrikeus
    Minimize access to secrets (Manual)
    0 installs
  23. Cis Eks V180 4 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Manual)
    0 installs
  24. Cis Eks V180 4 1 4 · cyberstrikeus
    Minimize access to create pods (Manual)
    0 installs
  25. Cis Eks V180 4 1 5 · cyberstrikeus
    Ensure that default service accounts are not actively used (Manual)
    0 installs
  26. Cis Eks V180 4 1 6 · cyberstrikeus
    Ensure that Service Account Tokens are only mounted where necessary (Manual)
    0 installs
  27. Cis Eks V180 4 1 9 · cyberstrikeus
    Minimize access to create persistent volumes (Manual)
    0 installs
  28. Cis Eks V180 4 2 1 · cyberstrikeus
    Minimize the admission of privileged containers (Manual)
    0 installs
  29. Cis Eks V180 4 2 2 · cyberstrikeus
    Minimize the admission of containers wishing to share the host process ID namespace (Manual)
    0 installs
  30. Cis Eks V180 4 2 3 · cyberstrikeus
    Minimize the admission of containers wishing to share the host IPC namespace (Manual)
    0 installs
  31. Cis Eks V180 4 2 4 · cyberstrikeus
    Minimize the admission of containers wishing to share the host network namespace (Manual)
    0 installs
  32. Cis Eks V180 4 2 5 · cyberstrikeus
    Minimize the admission of containers with allowPrivilegeEscalation (Manual)
    0 installs
  33. Cis Eks V180 4 3 2 · cyberstrikeus
    Ensure that all Namespaces have Network Policies defined (Manual)
    0 installs
  34. Cis Eks V180 5 4 4 · cyberstrikeus
    Ensure AmazonEKSNetworkingPolicy is Enabled and set as appropriate (Automated)
    0 installs
  35. Cis K8S V1110 2 1 · cyberstrikeus
    Ensure that the --cert-file and --key-file arguments are set as appropriate (Automated)
    0 installs
  36. Cis K8S V1110 2 2 · cyberstrikeus
    Ensure that the --cert-file and --key-file arguments are set as appropriate (Automated)
    0 installs
  37. Cis K8S V1110 2 3 · cyberstrikeus
    Ensure that the --client-cert-auth argument is set to true (Automated)
    0 installs
  38. Cis K8S V1110 2 4 · cyberstrikeus
    Ensure that the --auto-tls argument is not set to true (Automated)
    0 installs
  39. Cis K8S V1110 2 5 · cyberstrikeus
    Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Automated)
    0 installs
  40. Cis K8S V1110 2 6 · cyberstrikeus
    Ensure that the --peer-client-cert-auth argument is set to true (Automated)
    0 installs
  41. Cis K8S V1110 2 7 · cyberstrikeus
    Ensure that the --peer-auto-tls argument is not set to true (Automated)
    0 installs
  42. Cis K8S V1110 2 8 · cyberstrikeus
    Ensure that a unique Certificate Authority is used for etcd (Manual)
    0 installs
  43. Cis K8S V1111 2 1 · cyberstrikeus
    Ensure that the --cert-file and --key-file arguments are set as appropriate (Automated)
    0 installs
  44. Cis K8S V1111 2 2 · cyberstrikeus
    Ensure that the --cert-file and --key-file arguments are set as appropriate (Automated)
    0 installs
  45. Cis K8S V1111 2 5 · cyberstrikeus
    Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Automated)
    0 installs
  46. Cis K8S V1111 2 6 · cyberstrikeus
    Ensure that the --peer-client-cert-auth argument is set to true (Automated)
    0 installs
  47. Cis K8S V1111 2 7 · cyberstrikeus
    Ensure that the --peer-auto-tls argument is not set to true (Automated)
    0 installs
  48. Cis K8S V1111 2 8 · cyberstrikeus
    Ensure that a unique Certificate Authority is used for etcd (Manual)
    0 installs
  49. Cis K8S V1120 2 1 · cyberstrikeus
    Ensure that the --cert-file and --key-file arguments are set as appropriate (Automated)
    0 installs
  50. Cis K8S V1120 2 2 · cyberstrikeus
    Ensure that the --client-cert-auth argument is set to true (Automated)
    0 installs
  51. Cis K8S V1120 2 3 · cyberstrikeus
    Ensure that the --auto-tls argument is not set to true (Automated)
    0 installs
  52. Cis K8S V1120 2 4 · cyberstrikeus
    Ensure that the --peer-cert-file and --peer-key-file arguments are set as appropriate (Automated)
    0 installs
  53. Cis K8S V1120 2 5 · cyberstrikeus
    Ensure that the --peer-client-cert-auth argument is set to true (Automated)
    0 installs
  54. Cis K8S V1120 2 6 · cyberstrikeus
    Ensure that the --peer-auto-tls argument is not set to true (Automated)
    0 installs
  55. Cis K8S V1120 2 7 · cyberstrikeus
    Ensure that a unique Certificate Authority is used for etcd (Manual)
    0 installs
  56. Cis K8S V200 1 1 1 · cyberstrikeus
    Ensure that the API server pod specification file permissions are set to 600 or more restrictive (Automated)
    0 installs
  57. Cis K8S V200 1 1 2 · cyberstrikeus
    Ensure that the API server pod specification file ownership is set to root:root (Automated)
    0 installs
  58. Cis K8S V200 1 1 3 · cyberstrikeus
    Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive (Automated)
    0 installs
  59. Cis K8S V200 1 1 4 · cyberstrikeus
    Ensure that the controller manager pod specification file ownership is set to root:root (Automated)
    0 installs
  60. Cis K8S V200 1 1 5 · cyberstrikeus
    Ensure that the scheduler pod specification file permissions are set to 600 or more restrictive (Automated)
    0 installs
  61. Cis K8S V200 1 1 6 · cyberstrikeus
    Ensure that the scheduler pod specification file ownership is set to root:root (Automated)
    0 installs
  62. Cis K8S V200 1 1 7 · cyberstrikeus
    Ensure that the etcd pod specification file permissions are set to 600 or more restrictive (Automated)
    0 installs
  63. Cis K8S V200 1 1 8 · cyberstrikeus
    Ensure that the etcd pod specification file ownership is set to root:root (Automated)
    0 installs
  64. Cis K8S V200 1 1 9 · cyberstrikeus
    Ensure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)
    0 installs
  65. Cis K8S V200 1 2 1 · cyberstrikeus
    Ensure that the --anonymous-auth argument is set to false (Manual)
    0 installs
  66. Cis K8S V200 1 2 2 · cyberstrikeus
    Ensure that the --token-auth-file parameter is not set (Automated)
    0 installs
  67. Cis K8S V200 1 2 3 · cyberstrikeus
    Ensure that the DenyServiceExternalIPs is set (Manual)
    0 installs
  68. Cis K8S V200 1 2 4 · cyberstrikeus
    Ensure that the --kubelet-client-certificate and --kubelet-client-key arguments are set as appropriate (Automated)
    0 installs
  69. Cis K8S V200 1 2 5 · cyberstrikeus
    Ensure that the --kubelet-certificate-authority argument is set as appropriate (Automated)
    0 installs
  70. Cis K8S V200 1 2 6 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0 installs
  71. Cis K8S V200 1 2 7 · cyberstrikeus
    Ensure that the --authorization-mode argument includes Node (Automated)
    0 installs
  72. Cis K8S V200 1 2 8 · cyberstrikeus
    Ensure that the --authorization-mode argument includes RBAC (Automated)
    0 installs
  73. Cis K8S V200 1 2 9 · cyberstrikeus
    Ensure that the admission control plugin EventRateLimit is set (Manual)
    0 installs
  74. Cis K8S V200 1 3 1 · cyberstrikeus
    Ensure that the --terminated-pod-gc-threshold argument is set as appropriate (Manual)
    0 installs
  75. Cis K8S V200 1 3 2 · cyberstrikeus
    Ensure that the --profiling argument is set to false (Automated)
    0 installs
  76. Cis K8S V200 1 3 3 · cyberstrikeus
    Ensure that the --use-service-account-credentials argument is set to true (Automated)
    0 installs
  77. Cis K8S V200 1 3 4 · cyberstrikeus
    Ensure that the --service-account-private-key-file argument is set as appropriate (Automated)
    0 installs
  78. Cis K8S V200 1 3 5 · cyberstrikeus
    Ensure that the --root-ca-file argument is set as appropriate (Automated)
    0 installs
  79. Cis K8S V200 1 3 6 · cyberstrikeus
    Ensure that the RotateKubeletServerCertificate argument is set to true (Automated)
    0 installs
  80. Cis K8S V200 1 3 7 · cyberstrikeus
    Ensure that the --bind-address argument is set to 127.0.0.1 (Automated)
    0 installs
  81. Cis K8S V200 1 4 1 · cyberstrikeus
    Ensure that the --profiling argument is set to false (Automated)
    0 installs
  82. Cis K8S V200 1 4 2 · cyberstrikeus
    Ensure that the --bind-address argument is set to 127.0.0.1 (Automated)
    0 installs
  83. Cis K8S V200 3 1 1 · cyberstrikeus
    Client certificate authentication should not be used for users (Manual)
    0 installs
  84. Cis K8S V200 3 1 2 · cyberstrikeus
    Service account token authentication should not be used for users (Manual)
    0 installs
  85. Cis K8S V200 3 1 3 · cyberstrikeus
    Bootstrap token authentication should not be used for users (Manual)
    0 installs
  86. Cis K8S V200 3 2 1 · cyberstrikeus
    Ensure that a minimal audit policy is created (Manual)
    0 installs
  87. Cis K8S V200 3 2 2 · cyberstrikeus
    Ensure that the audit policy covers key security concerns (Manual)
    0 installs
  88. Cis K8S V200 4 1 1 · cyberstrikeus
    Ensure that the kubelet service file permissions are set to 600 or more restrictive (Automated)
    0 installs
  89. Cis K8S V200 4 1 2 · cyberstrikeus
    Ensure that the kubelet service file ownership is set to root:root (Automated)
    0 installs
  90. Cis K8S V200 4 1 3 · cyberstrikeus
    If proxy kubeconfig file exists ensure permissions are set to 600 or more restrictive (Manual)
    0 installs
  91. Cis K8S V200 4 1 4 · cyberstrikeus
    If proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
    0 installs
  92. Cis K8S V200 4 1 5 · cyberstrikeus
    Ensure that the --kubeconfig kubelet.conf file permissions are set to 600 or more restrictive (Automated)
    0 installs
  93. Cis K8S V200 4 1 6 · cyberstrikeus
    Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
    0 installs
  94. Cis K8S V200 4 1 7 · cyberstrikeus
    Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Manual)
    0 installs
  95. Cis K8S V200 4 1 8 · cyberstrikeus
    Ensure that the client certificate authorities file ownership is set to root:root (Manual)
    0 installs
  96. Cis K8S V200 4 1 9 · cyberstrikeus
    If the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictive (Automated)
    0 installs
  97. Cis K8S V200 4 2 1 · cyberstrikeus
    Ensure that the --anonymous-auth argument is set to false (Automated)
    0 installs
  98. Cis K8S V200 4 2 2 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0 installs
  99. Cis K8S V200 4 2 3 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Automated)
    0 installs
  100. Cis K8S V200 4 2 4 · cyberstrikeus
    Verify that if defined, readOnlyPort is set to 0 (Manual)
    0 installs