← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 31 of 72

  1. Cis Aks V170 4 1 4 · cyberstrikeus
    Minimize access to create pods (Automated)
    0 installs
  2. Cis Aks V170 4 1 5 · cyberstrikeus
    Ensure that default service accounts are not actively used (Automated)
    0 installs
  3. Cis Aks V170 4 1 6 · cyberstrikeus
    Ensure Service Account Tokens are only mounted where necessary (Automated)
    0 installs
  4. Cis Aks V170 4 2 1 · cyberstrikeus
    Minimize the admission of privileged containers (Automated)
    0 installs
  5. Cis Aks V170 4 2 2 · cyberstrikeus
    Minimize the admission of containers wishing to share the host process ID namespace (Automated)
    0 installs
  6. Cis Aks V170 4 2 3 · cyberstrikeus
    Minimize the admission of containers wishing to share the host IPC namespace (Automated)
    0 installs
  7. Cis Aks V170 4 2 4 · cyberstrikeus
    Minimize the admission of containers wishing to share the host network namespace (Automated)
    0 installs
  8. Cis Aks V170 4 2 5 · cyberstrikeus
    Minimize the admission of containers with allowPrivilegeEscalation (Automated)
    0 installs
  9. Cis Aks V170 4 4 1 · cyberstrikeus
    Ensure latest CNI version is used (Manual)
    0 installs
  10. Cis Aks V170 4 4 2 · cyberstrikeus
    Ensure all Namespaces have Network Policies defined (Automated)
    0 installs
  11. Cis Aks V170 4 5 1 · cyberstrikeus
    Prefer using secrets as files over secrets as environment variables (Automated)
    0 installs
  12. Cis Aks V170 4 5 2 · cyberstrikeus
    Consider external secret storage (Manual)
    0 installs
  13. Cis Aks V170 4 6 1 · cyberstrikeus
    Create administrative boundaries between resources using namespaces (Manual)
    0 installs
  14. Cis Aks V170 4 6 2 · cyberstrikeus
    Apply Security Context to Your Pods and Containers (Manual)
    0 installs
  15. Cis Aks V170 4 6 3 · cyberstrikeus
    The default namespace should not be used (Automated)
    0 installs
  16. Cis Aks V170 5 1 1 · cyberstrikeus
    Ensure Image Vulnerability Scanning using Microsoft Defender for Cloud (MDC) image scanning or a third party provider (Automated)
    0 installs
  17. Cis Aks V170 5 1 2 · cyberstrikeus
    Minimize user access to Azure Container Registry (ACR) (Manual)
    0 installs
  18. Cis Aks V170 5 1 3 · cyberstrikeus
    Minimize cluster access to read-only for Azure Container Registry (ACR) (Manual)
    0 installs
  19. Cis Aks V170 5 1 4 · cyberstrikeus
    Minimize Container Registries to only those approved (Manual)
    0 installs
  20. Cis Aks V170 5 2 1 · cyberstrikeus
    Prefer using dedicated AKS Service Accounts (Manual)
    0 installs
  21. Cis Aks V170 5 3 1 · cyberstrikeus
    Ensure Kubernetes Secrets are encrypted (Manual)
    0 installs
  22. Cis Aks V170 5 4 1 · cyberstrikeus
    Restrict Access to the Control Plane Endpoint (Automated)
    0 installs
  23. Cis Aks V170 5 4 2 · cyberstrikeus
    Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
    0 installs
  24. Cis Aks V170 5 4 3 · cyberstrikeus
    Ensure clusters are created with Private Nodes (Automated)
    0 installs
  25. Cis Aks V170 5 4 4 · cyberstrikeus
    Ensure Network Policy is Enabled and set as appropriate (Automated)
    0 installs
  26. Cis Aks V170 5 4 5 · cyberstrikeus
    Encrypt traffic to HTTPS load balancers with TLS certificates (Manual)
    0 installs
  27. Cis Aks V170 5 5 1 · cyberstrikeus
    Manage Kubernetes RBAC users with Azure AD (Manual)
    0 installs
  28. Cis Aks V170 5 5 2 · cyberstrikeus
    Use Azure RBAC for Kubernetes Authorization (Manual)
    0 installs
  29. Cis Ocp V160 1 1 10 · cyberstrikeus
    Ensure that the Container Network Interface file ownership is set to root:root (Manual)
    0 installs
  30. Cis Ocp V160 1 1 11 · cyberstrikeus
    Ensure that the etcd data directory permissions are set to 700 or more restrictive (Manual)
    0 installs
  31. Cis Ocp V160 1 1 12 · cyberstrikeus
    Ensure that the etcd data directory ownership is set to etcd:etcd (Manual)
    0 installs
  32. Cis Ocp V160 1 1 13 · cyberstrikeus
    Ensure that the kubeconfig file permissions are set to 600 or more restrictive (Manual)
    0 installs
  33. Cis Ocp V160 1 1 14 · cyberstrikeus
    Ensure that the kubeconfig file ownership is set to root:root (Manual)
    0 installs
  34. Cis Ocp V160 1 1 15 · cyberstrikeus
    Ensure that the Scheduler kubeconfig file permissions are set to 600 or more restrictive (Manual)
    0 installs
  35. Cis Ocp V160 1 1 16 · cyberstrikeus
    Ensure that the Scheduler kubeconfig file ownership is set to root:root (Manual)
    0 installs
  36. Cis Ocp V160 1 1 17 · cyberstrikeus
    Ensure that the Controller Manager kubeconfig file permissions are set to 600 or more restrictive (Manual)
    2 installs
  37. Cis Ocp V160 1 1 18 · cyberstrikeus
    Ensure that the Controller Manager kubeconfig file ownership is set to root:root (Manual)
    0 installs
  38. Cis Ocp V160 1 1 19 · cyberstrikeus
    Ensure that the OpenShift PKI directory and file ownership is set to root:root (Manual)
    0 installs
  39. Cis Ocp V160 1 1 20 · cyberstrikeus
    Ensure that the OpenShift PKI certificate file permissions are set to 600 or more restrictive (Manual)
    0 installs
  40. Cis Ocp V160 1 1 21 · cyberstrikeus
    Ensure that the OpenShift PKI key file permissions are set to 600 (Manual)
    0 installs
  41. Cis Ocp V160 1 2 10 · cyberstrikeus
    Ensure that the admission control plugin AlwaysAdmit is not set (Manual)
    0 installs
  42. Cis Ocp V160 1 2 11 · cyberstrikeus
    Ensure that the admission control plugin AlwaysPullImages is not set (Manual)
    0 installs
  43. Cis Ocp V160 1 2 12 · cyberstrikeus
    Ensure that the admission control plugin ServiceAccount is set (Manual)
    0 installs
  44. Cis Ocp V160 1 2 13 · cyberstrikeus
    Ensure that the admission control plugin NamespaceLifecycle is set (Manual)
    0 installs
  45. Cis Ocp V160 1 2 14 · cyberstrikeus
    Ensure that the admission control plugin SecurityContextConstraint is set (Manual)
    0 installs
  46. Cis Ocp V160 1 2 15 · cyberstrikeus
    Ensure that the admission control plugin NodeRestriction is set (Manual)
    0 installs
  47. Cis Ocp V160 1 2 16 · cyberstrikeus
    Ensure that the --insecure-bind-address argument is not set (Manual)
    0 installs
  48. Cis Ocp V180 1 2 2 · cyberstrikeus
    Use https for kubelet connections (Manual)
    0 installs
  49. Cis Ocp V180 1 2 3 · cyberstrikeus
    Ensure that the kubelet uses certificates to authenticate (Manual)
    0 installs
  50. Cis Ocp V180 1 2 4 · cyberstrikeus
    Verify that the kubelet certificate authority is set as appropriate (Manual)
    0 installs
  51. Cis Ocp V180 1 2 5 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Manual)
    0 installs
  52. Cis Ocp V180 1 2 6 · cyberstrikeus
    Verify that RBAC is enabled (Manual)
    0 installs
  53. Cis Ocp V180 1 2 7 · cyberstrikeus
    Ensure that the APIPriorityAndFairness feature gate is enabled (Manual)
    0 installs
  54. Cis Ocp V180 1 2 8 · cyberstrikeus
    Ensure that the admission control plugin AlwaysAdmit is not set (Manual)
    0 installs
  55. Cis Ocp V180 1 2 9 · cyberstrikeus
    Ensure that the admission control plugin AlwaysPullImages is not set (Manual)
    0 installs
  56. Cis Ocp V180 1 3 1 · cyberstrikeus
    Ensure controller manager healthz endpoints protected by RBAC (Manual)
    0 installs
  57. Cis Ocp V180 1 3 2 · cyberstrikeus
    Ensure --use-service-account-credentials set to true (Manual)
    0 installs
  58. Cis Ocp V180 1 3 3 · cyberstrikeus
    Ensure --service-account-private-key-file set (Manual)
    0 installs
  59. Cis Ocp V180 1 3 4 · cyberstrikeus
    Ensure --root-ca-file set as appropriate (Manual)
    0 installs
  60. Cis Ocp V180 1 4 1 · cyberstrikeus
    Ensure healthz endpoints for scheduler protected by RBAC (Manual)
    0 installs
  61. Cis Ocp V180 1 4 2 · cyberstrikeus
    Verify scheduler API service protected by RBAC (Manual)
    0 installs
  62. Cis Ocp V180 3 1 1 · cyberstrikeus
    Client certificate authentication should not be used for users (Manual)
    0 installs
  63. Cis Ocp V180 3 2 1 · cyberstrikeus
    Ensure minimal audit policy created (Manual)
    0 installs
  64. Cis Ocp V180 3 2 2 · cyberstrikeus
    Ensure audit policy covers key security concerns (Manual)
    0 installs
  65. Cis Ocp V180 4 1 1 · cyberstrikeus
    Ensure that the kubelet service file permissions are set to 644 or more restrictive (Automated)
    0 installs
  66. Cis Ocp V180 4 1 2 · cyberstrikeus
    Ensure that the kubelet service file ownership is set to root:root (Automated)
    0 installs
  67. Cis Ocp V180 4 1 3 · cyberstrikeus
    If proxy kube proxy configuration file exists ensure permissions are set to 644 or more restrictive (Manual)
    0 installs
  68. Cis Ocp V180 4 1 4 · cyberstrikeus
    If proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
    0 installs
  69. Cis Ocp V180 4 1 5 · cyberstrikeus
    Ensure that the --kubeconfig kubelet.conf file permissions are set to 644 or more restrictive (Automated)
    0 installs
  70. Cis Ocp V180 4 1 6 · cyberstrikeus
    Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
    0 installs
  71. Cis Ocp V180 4 1 7 · cyberstrikeus
    Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Automated)
    0 installs
  72. Cis Ocp V180 4 1 8 · cyberstrikeus
    Ensure that the client certificate authorities file ownership is set to root:root (Automated)
    0 installs
  73. Cis Ocp V180 4 1 9 · cyberstrikeus
    Ensure that the kubelet --config configuration file has permissions set to 600 or more restrictive (Automated)
    0 installs
  74. Cis Ocp V180 4 2 1 · cyberstrikeus
    Activate Garbage collection in OpenShift Container Platform 4, as appropriate (Manual)
    0 installs
  75. Cis Ocp V180 4 2 2 · cyberstrikeus
    Ensure that the --anonymous-auth argument is set to false (Automated)
    0 installs
  76. Cis Ocp V180 4 2 3 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0 installs
  77. Cis Ocp V180 4 2 4 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Automated)
    0 installs
  78. Cis Ocp V180 4 2 5 · cyberstrikeus
    Verify that the read only port is not used or is set to 0 (Automated)
    0 installs
  79. Cis Ocp V180 4 2 6 · cyberstrikeus
    Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
    0 installs
  80. Cis Ocp V180 4 2 7 · cyberstrikeus
    Ensure that the --make-iptables-util-chains argument is set to true (Manual)
    0 installs
  81. Cis Ocp V180 4 2 8 · cyberstrikeus
    Ensure that the kubeAPIQPS [--event-qps] argument is set to 0 or a level which ensures appropriate event capture (Manual)
    0 installs
  82. Cis Ocp V180 4 2 9 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
    0 installs
  83. Cis Ocp V180 5 1 1 · cyberstrikeus
    Ensure cluster-admin role only used where required (Manual)
    0 installs
  84. Cis Ocp V180 5 1 2 · cyberstrikeus
    Minimize access to secrets (Manual)
    0 installs
  85. Cis Ocp V180 5 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Manual)
    0 installs
  86. Cis Ocp V180 5 1 4 · cyberstrikeus
    Minimize access to create pods (Manual)
    0 installs
  87. Cis Ocp V180 5 1 5 · cyberstrikeus
    Ensure default service accounts not actively used (Manual)
    0 installs
  88. Cis Ocp V180 5 1 6 · cyberstrikeus
    Ensure Service Account Tokens only mounted where necessary (Manual)
    0 installs
  89. Cis Ocp V180 5 2 1 · cyberstrikeus
    Minimize admission of privileged containers (Manual)
    0 installs
  90. Cis Ocp V180 5 2 2 · cyberstrikeus
    Minimize admission of containers sharing host process ID namespace (Manual)
    0 installs
  91. Cis Ocp V180 5 2 3 · cyberstrikeus
    Minimize admission of containers sharing host IPC namespace (Manual)
    0 installs
  92. Cis Ocp V180 5 2 4 · cyberstrikeus
    Minimize admission of containers sharing host network namespace (Manual)
    0 installs
  93. Cis Ocp V180 5 2 5 · cyberstrikeus
    Minimize admission of containers with allowPrivilegeEscalation (Manual)
    0 installs
  94. Cis Ocp V180 5 2 6 · cyberstrikeus
    Minimize admission of root containers (Manual)
    0 installs
  95. Cis Ocp V180 5 2 7 · cyberstrikeus
    Minimize admission of containers with NET_RAW capability (Manual)
    0 installs
  96. Cis Ocp V180 5 2 8 · cyberstrikeus
    Minimize admission of containers with added capabilities (Manual)
    0 installs
  97. Cis Ocp V180 5 2 9 · cyberstrikeus
    Minimize admission of containers with capabilities assigned (Manual)
    0 installs
  98. Cis Ocp V180 5 3 1 · cyberstrikeus
    Ensure CNI in use supports Network Policies (Manual)
    0 installs
  99. Cis Ocp V180 5 3 2 · cyberstrikeus
    Ensure all Namespaces have Network Policies defined (Manual)
    1 install
  100. Cis Ocp V180 5 4 1 · cyberstrikeus
    Prefer using secrets as files over secrets as environment variables (Manual)
    0 installs