cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌
- ▌ Cis Aks V170 4 1 5 · cyberstrikeusEnsure that default service accounts are not actively used (Automated)
- ▌ Cis Aks V170 4 1 6 · cyberstrikeusEnsure Service Account Tokens are only mounted where necessary (Automated)
- ▌
- ▌ Cis Aks V170 4 2 2 · cyberstrikeusMinimize the admission of containers wishing to share the host process ID namespace (Automated)
- ▌ Cis Aks V170 4 2 3 · cyberstrikeusMinimize the admission of containers wishing to share the host IPC namespace (Automated)
- ▌ Cis Aks V170 4 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Automated)
- ▌ Cis Aks V170 4 2 5 · cyberstrikeusMinimize the admission of containers with allowPrivilegeEscalation (Automated)
- ▌
- ▌
- ▌ Cis Aks V170 4 5 1 · cyberstrikeusPrefer using secrets as files over secrets as environment variables (Automated)
- ▌
- ▌ Cis Aks V170 4 6 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌
- ▌
- ▌ Cis Aks V170 5 1 1 · cyberstrikeusEnsure Image Vulnerability Scanning using Microsoft Defender for Cloud (MDC) image scanning or a third party provider (Automated)
- ▌
- ▌ Cis Aks V170 5 1 3 · cyberstrikeusMinimize cluster access to read-only for Azure Container Registry (ACR) (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Aks V170 5 4 2 · cyberstrikeusEnsure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
- ▌
- ▌ Cis Aks V170 5 4 4 · cyberstrikeusEnsure Network Policy is Enabled and set as appropriate (Automated)
- ▌ Cis Aks V170 5 4 5 · cyberstrikeusEncrypt traffic to HTTPS load balancers with TLS certificates (Manual)
- ▌
- ▌
- ▌ Cis Ocp V160 1 1 10 · cyberstrikeusEnsure that the Container Network Interface file ownership is set to root:root (Manual)
- ▌ Cis Ocp V160 1 1 11 · cyberstrikeusEnsure that the etcd data directory permissions are set to 700 or more restrictive (Manual)
- ▌ Cis Ocp V160 1 1 12 · cyberstrikeusEnsure that the etcd data directory ownership is set to etcd:etcd (Manual)
- ▌ Cis Ocp V160 1 1 13 · cyberstrikeusEnsure that the kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V160 1 1 14 · cyberstrikeusEnsure that the kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V160 1 1 15 · cyberstrikeusEnsure that the Scheduler kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V160 1 1 16 · cyberstrikeusEnsure that the Scheduler kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V160 1 1 17 · cyberstrikeusEnsure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V160 1 1 18 · cyberstrikeusEnsure that the Controller Manager kubeconfig file ownership is set to root:root (Manual)
- ▌ Cis Ocp V160 1 1 19 · cyberstrikeusEnsure that the OpenShift PKI directory and file ownership is set to root:root (Manual)
- ▌ Cis Ocp V160 1 1 20 · cyberstrikeusEnsure that the OpenShift PKI certificate file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis Ocp V160 1 1 21 · cyberstrikeusEnsure that the OpenShift PKI key file permissions are set to 600 (Manual)
- ▌ Cis Ocp V160 1 2 10 · cyberstrikeusEnsure that the admission control plugin AlwaysAdmit is not set (Manual)
- ▌ Cis Ocp V160 1 2 11 · cyberstrikeusEnsure that the admission control plugin AlwaysPullImages is not set (Manual)
- ▌ Cis Ocp V160 1 2 12 · cyberstrikeusEnsure that the admission control plugin ServiceAccount is set (Manual)
- ▌ Cis Ocp V160 1 2 13 · cyberstrikeusEnsure that the admission control plugin NamespaceLifecycle is set (Manual)
- ▌ Cis Ocp V160 1 2 14 · cyberstrikeusEnsure that the admission control plugin SecurityContextConstraint is set (Manual)
- ▌ Cis Ocp V160 1 2 15 · cyberstrikeusEnsure that the admission control plugin NodeRestriction is set (Manual)
- ▌ Cis Ocp V160 1 2 16 · cyberstrikeusEnsure that the --insecure-bind-address argument is not set (Manual)
- ▌
- ▌ Cis Ocp V180 1 2 3 · cyberstrikeusEnsure that the kubelet uses certificates to authenticate (Manual)
- ▌ Cis Ocp V180 1 2 4 · cyberstrikeusVerify that the kubelet certificate authority is set as appropriate (Manual)
- ▌ Cis Ocp V180 1 2 5 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Manual)
- ▌
- ▌ Cis Ocp V180 1 2 7 · cyberstrikeusEnsure that the APIPriorityAndFairness feature gate is enabled (Manual)
- ▌ Cis Ocp V180 1 2 8 · cyberstrikeusEnsure that the admission control plugin AlwaysAdmit is not set (Manual)
- ▌ Cis Ocp V180 1 2 9 · cyberstrikeusEnsure that the admission control plugin AlwaysPullImages is not set (Manual)
- ▌ Cis Ocp V180 1 3 1 · cyberstrikeusEnsure controller manager healthz endpoints protected by RBAC (Manual)
- ▌
- ▌
- ▌
- ▌ Cis Ocp V180 1 4 1 · cyberstrikeusEnsure healthz endpoints for scheduler protected by RBAC (Manual)
- ▌
- ▌ Cis Ocp V180 3 1 1 · cyberstrikeusClient certificate authentication should not be used for users (Manual)
- ▌
- ▌
- ▌ Cis Ocp V180 4 1 1 · cyberstrikeusEnsure that the kubelet service file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Ocp V180 4 1 2 · cyberstrikeusEnsure that the kubelet service file ownership is set to root:root (Automated)
- ▌ Cis Ocp V180 4 1 3 · cyberstrikeusIf proxy kube proxy configuration file exists ensure permissions are set to 644 or more restrictive (Manual)
- ▌ Cis Ocp V180 4 1 4 · cyberstrikeusIf proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
- ▌ Cis Ocp V180 4 1 5 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Ocp V180 4 1 6 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
- ▌ Cis Ocp V180 4 1 7 · cyberstrikeusEnsure that the certificate authorities file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Ocp V180 4 1 8 · cyberstrikeusEnsure that the client certificate authorities file ownership is set to root:root (Automated)
- ▌ Cis Ocp V180 4 1 9 · cyberstrikeusEnsure that the kubelet --config configuration file has permissions set to 600 or more restrictive (Automated)
- ▌ Cis Ocp V180 4 2 1 · cyberstrikeusActivate Garbage collection in OpenShift Container Platform 4, as appropriate (Manual)
- ▌ Cis Ocp V180 4 2 2 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌ Cis Ocp V180 4 2 3 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis Ocp V180 4 2 4 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌ Cis Ocp V180 4 2 5 · cyberstrikeusVerify that the read only port is not used or is set to 0 (Automated)
- ▌ Cis Ocp V180 4 2 6 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
- ▌ Cis Ocp V180 4 2 7 · cyberstrikeusEnsure that the --make-iptables-util-chains argument is set to true (Manual)
- ▌ Cis Ocp V180 4 2 8 · cyberstrikeusEnsure that the kubeAPIQPS [--event-qps] argument is set to 0 or a level which ensures appropriate event capture (Manual)
- ▌ Cis Ocp V180 4 2 9 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌ Cis Ocp V180 5 1 6 · cyberstrikeusEnsure Service Account Tokens only mounted where necessary (Manual)
- ▌
- ▌ Cis Ocp V180 5 2 2 · cyberstrikeusMinimize admission of containers sharing host process ID namespace (Manual)
- ▌ Cis Ocp V180 5 2 3 · cyberstrikeusMinimize admission of containers sharing host IPC namespace (Manual)
- ▌ Cis Ocp V180 5 2 4 · cyberstrikeusMinimize admission of containers sharing host network namespace (Manual)
- ▌ Cis Ocp V180 5 2 5 · cyberstrikeusMinimize admission of containers with allowPrivilegeEscalation (Manual)
- ▌
- ▌ Cis Ocp V180 5 2 7 · cyberstrikeusMinimize admission of containers with NET_RAW capability (Manual)
- ▌ Cis Ocp V180 5 2 8 · cyberstrikeusMinimize admission of containers with added capabilities (Manual)
- ▌ Cis Ocp V180 5 2 9 · cyberstrikeusMinimize admission of containers with capabilities assigned (Manual)
- ▌
- ▌
- ▌ Cis Ocp V180 5 4 1 · cyberstrikeusPrefer using secrets as files over secrets as environment variables (Manual)