← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 34 of 72

  1. Cis Docker V170 5 3 · cyberstrikeus
    Ensure that, if applicable, SELinux security options are set
    0 installs
  2. Cis Docker V170 5 4 · cyberstrikeus
    Ensure that Linux kernel capabilities are restricted within containers
    0 installs
  3. Cis Docker V170 5 5 · cyberstrikeus
    Ensure that privileged containers are not used
    0 installs
  4. Cis Docker V170 5 6 · cyberstrikeus
    Ensure sensitive host system directories are not mounted on containers
    0 installs
  5. Cis Docker V170 5 7 · cyberstrikeus
    Ensure sshd is not run within containers
    0 installs
  6. Cis Docker V170 5 8 · cyberstrikeus
    Ensure privileged ports are not mapped within containers
    0 installs
  7. Cis Docker V170 5 9 · cyberstrikeus
    Ensure that only needed ports are open on the container
    0 installs
  8. Cis Docker V170 6 1 · cyberstrikeus
    Ensure that image sprawl is avoided
    0 installs
  9. Cis Docker V170 6 2 · cyberstrikeus
    Ensure that container sprawl is avoided
    0 installs
  10. Cis Docker V170 7 1 · cyberstrikeus
    Ensure that the minimum number of manager nodes have been created in a swarm
    0 installs
  11. Cis Docker V170 7 2 · cyberstrikeus
    Ensure that swarm services are bound to a specific host interface
    0 installs
  12. Cis Docker V170 7 3 · cyberstrikeus
    Ensure that all Docker swarm overlay networks are encrypted
    0 installs
  13. Cis Docker V170 7 4 · cyberstrikeus
    Ensure that Docker's secret management commands are used for managing secrets in a swarm cluster
    0 installs
  14. Cis Docker V170 7 5 · cyberstrikeus
    Ensure that swarm manager is run in auto-lock mode
    0 installs
  15. Cis Docker V170 7 6 · cyberstrikeus
    Ensure that the swarm manager auto-lock key is rotated periodically
    0 installs
  16. Cis Docker V170 7 7 · cyberstrikeus
    Ensure that node certificates are rotated as appropriate
    0 installs
  17. Cis Docker V170 7 8 · cyberstrikeus
    Ensure that CA certificates are rotated as appropriate
    0 installs
  18. Cis Docker V170 7 9 · cyberstrikeus
    Ensure that management plane traffic is separated from data plane traffic
    0 installs
  19. Cis Gke V170 3 1 1 · cyberstrikeus
    Ensure that the proxy kubeconfig file permissions are set to 644 or more restrictive (Automated)
    0 installs
  20. Cis Gke V170 3 1 2 · cyberstrikeus
    Ensure that the proxy kubeconfig file ownership is set to root:root (Automated)
    0 installs
  21. Cis Gke V170 3 1 3 · cyberstrikeus
    Ensure that the kubelet configuration file has permissions set to 644 (Automated)
    0 installs
  22. Cis Gke V170 3 1 4 · cyberstrikeus
    Ensure that the kubelet configuration file ownership is set to root:root (Automated)
    0 installs
  23. Cis Gke V170 3 2 1 · cyberstrikeus
    Ensure that the Anonymous Auth is Not Enabled Draft (Automated)
    0 installs
  24. Cis Gke V170 3 2 2 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0 installs
  25. Cis Gke V170 3 2 3 · cyberstrikeus
    Ensure that a Client CA File is Configured (Automated)
    0 installs
  26. Cis Gke V170 3 2 4 · cyberstrikeus
    Ensure that the --read-only-port is disabled (Automated)
    0 installs
  27. Cis Gke V170 3 2 5 · cyberstrikeus
    Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
    0 installs
  28. Cis Gke V170 3 2 6 · cyberstrikeus
    Ensure that the --make-iptables-util-chains argument is set to true (Automated)
    0 installs
  29. Cis Gke V170 3 2 7 · cyberstrikeus
    Ensure that the --eventRecordQPS argument is set to 0 or a level which ensures appropriate event capture (Automated)
    0 installs
  30. Cis Gke V170 3 2 8 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not present or is set to true (Automated)
    0 installs
  31. Cis Gke V170 3 2 9 · cyberstrikeus
    Ensure that the RotateKubeletServerCertificate argument is set to true (Automated)
    0 installs
  32. Cis Gke V170 4 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Automated)
    0 installs
  33. Cis Gke V170 4 1 2 · cyberstrikeus
    Minimize access to secrets (Automated)
    0 installs
  34. Cis Gke V170 4 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Automated)
    0 installs
  35. Cis Gke V170 4 1 4 · cyberstrikeus
    Ensure that default service accounts are not actively used (Automated)
    0 installs
  36. Cis Gke V170 4 1 5 · cyberstrikeus
    Ensure that Service Account Tokens are only mounted where necessary (Automated)
    0 installs
  37. Cis Gke V170 4 1 6 · cyberstrikeus
    Avoid use of system:masters group (Automated)
    0 installs
  38. Cis Gke V170 4 1 7 · cyberstrikeus
    Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
    0 installs
  39. Cis Gke V170 4 1 8 · cyberstrikeus
    Avoid bindings to system:anonymous (Automated)
    0 installs
  40. Cis Gke V170 4 1 9 · cyberstrikeus
    Avoid non-default bindings to system:unauthenticated (Automated)
    0 installs
  41. Cis Gke V170 4 2 1 · cyberstrikeus
    Ensure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)
    0 installs
  42. Cis Gke V170 4 3 1 · cyberstrikeus
    Ensure that the CNI in use supports Network Policies (Manual)
    0 installs
  43. Cis Gke V170 4 3 2 · cyberstrikeus
    Ensure that all Namespaces have Network Policies defined (Automated)
    0 installs
  44. Cis Gke V170 4 4 1 · cyberstrikeus
    Prefer using secrets as files over secrets as environment variables (Automated)
    0 installs
  45. Cis Gke V170 4 4 2 · cyberstrikeus
    Consider external secret storage (Manual)
    0 installs
  46. Cis Gke V170 4 5 1 · cyberstrikeus
    Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
    0 installs
  47. Cis Gke V170 4 6 1 · cyberstrikeus
    Create administrative boundaries between resources using namespaces (Manual)
    0 installs
  48. Cis Gke V170 4 6 2 · cyberstrikeus
    Ensure that the seccomp profile is set to RuntimeDefault in the pod definitions (Automated)
    0 installs
  49. Cis Gke V170 4 6 3 · cyberstrikeus
    Apply Security Context to Pods and Containers (Manual)
    0 installs
  50. Cis Gke V170 4 6 4 · cyberstrikeus
    The default namespace should not be used (Automated)
    0 installs
  51. Cis Gke V170 5 1 1 · cyberstrikeus
    Ensure Image Vulnerability Scanning is enabled (Automated)
    0 installs
  52. Cis Gke V170 5 1 2 · cyberstrikeus
    Minimize user access to Container Image repositories (Manual)
    0 installs
  53. Cis Gke V170 5 1 3 · cyberstrikeus
    Minimize cluster access to read-only for Container Image repositories (Manual)
    0 installs
  54. Cis Gke V170 5 1 4 · cyberstrikeus
    Ensure only trusted container images are used (Manual)
    0 installs
  55. Cis Gke V170 5 2 1 · cyberstrikeus
    Ensure GKE clusters are not running using the Compute Engine default service account (Automated)
    0 installs
  56. Cis Gke V170 5 2 2 · cyberstrikeus
    Prefer using dedicated GCP Service Accounts and Workload Identity (Manual)
    0 installs
  57. Cis Gke V170 5 3 1 · cyberstrikeus
    Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
    0 installs
  58. Cis Gke V170 5 4 1 · cyberstrikeus
    Ensure the GKE Metadata Server is Enabled (Automated)
    0 installs
  59. Cis Gke V170 5 5 1 · cyberstrikeus
    Ensure Container-Optimized OS (cos_containerd) is used for GKE node images (Automated)
    2 installs
  60. Cis Gke V170 5 5 2 · cyberstrikeus
    Ensure Node Auto-Repair is enabled for GKE nodes (Automated)
    0 installs
  61. Cis Gke V170 5 5 3 · cyberstrikeus
    Ensure Node Auto-Upgrade is enabled for GKE nodes (Automated)
    0 installs
  62. Cis Gke V170 5 5 4 · cyberstrikeus
    When creating New Clusters - Automate GKE version management using Release Channels (Automated)
    0 installs
  63. Cis Gke V170 5 5 5 · cyberstrikeus
    Ensure Shielded GKE Nodes are Enabled (Automated)
    0 installs
  64. Cis Gke V170 5 5 6 · cyberstrikeus
    Ensure Integrity Monitoring for Shielded GKE Nodes is Enabled (Automated)
    0 installs
  65. Cis Gke V170 5 5 7 · cyberstrikeus
    Ensure Secure Boot for Shielded GKE Nodes is Enabled (Automated)
    0 installs
  66. Cis Gke V170 5 6 1 · cyberstrikeus
    Enable VPC Flow Logs and Intranode Visibility (Automated)
    0 installs
  67. Cis Gke V170 5 6 2 · cyberstrikeus
    Ensure use of VPC-native clusters (Automated)
    0 installs
  68. Cis Gke V170 5 6 3 · cyberstrikeus
    Ensure Control Plane Authorized Networks is Enabled (Automated)
    0 installs
  69. Cis Gke V170 5 6 4 · cyberstrikeus
    Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
    0 installs
  70. Cis Gke V170 5 6 5 · cyberstrikeus
    Ensure clusters are created with Private Nodes (Automated)
    0 installs
  71. Cis Gke V170 5 6 6 · cyberstrikeus
    Consider firewalling GKE worker nodes (Manual)
    0 installs
  72. Cis Gke V170 5 6 7 · cyberstrikeus
    Ensure use of Google-managed SSL Certificates (Automated)
    0 installs
  73. Cis Gke V170 5 7 1 · cyberstrikeus
    Ensure Logging and Cloud Monitoring is Enabled (Automated)
    0 installs
  74. Cis Gke V170 5 7 2 · cyberstrikeus
    Enable Linux auditd logging (Manual)
    0 installs
  75. Cis Gke V170 5 8 1 · cyberstrikeus
    Ensure authentication using Client Certificates is Disabled (Automated)
    0 installs
  76. Cis Gke V170 5 8 2 · cyberstrikeus
    Manage Kubernetes RBAC users with Google Groups for GKE (Manual)
    0 installs
  77. Cis Gke V170 5 8 3 · cyberstrikeus
    Ensure Legacy Authorization (ABAC) is Disabled (Automated)
    0 installs
  78. Cis Gke V170 5 9 1 · cyberstrikeus
    Enable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)
    0 installs
  79. Cis Gke V170 5 9 2 · cyberstrikeus
    Enable Customer-Managed Encryption Keys (CMEK) for Boot Disks (Automated)
    0 installs
  80. Cis Gke V180 3 1 1 · cyberstrikeus
    Ensure that the kubeconfig file permissions are set to 644 or more restrictive (Automated)
    0 installs
  81. Cis Gke V180 3 1 2 · cyberstrikeus
    Ensure that the kubelet kubeconfig file ownership is set to root:root (Automated)
    0 installs
  82. Cis Gke V180 3 1 3 · cyberstrikeus
    Ensure that the kubelet configuration file has permissions set to 644 (Automated)
    0 installs
  83. Cis Gke V180 3 1 4 · cyberstrikeus
    Ensure that the kubelet configuration file ownership is set to root:root (Automated)
    0 installs
  84. Cis Gke V180 4 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Automated)
    0 installs
  85. Cis Gke V180 4 1 2 · cyberstrikeus
    Minimize access to secrets (Automated)
    0 installs
  86. Cis Gke V180 4 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Automated)
    0 installs
  87. Cis Gke V180 4 1 9 · cyberstrikeus
    Avoid non-default bindings to system:unauthenticated (Automated)
    0 installs
  88. Cis Gke V180 4 2 1 · cyberstrikeus
    Ensure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)
    0 installs
  89. Cis Gke V180 4 3 2 · cyberstrikeus
    Ensure that all Namespaces have Network Policies defined (Automated)
    0 installs
  90. Cis Gke V180 4 5 1 · cyberstrikeus
    Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
    0 installs
  91. Cis Gke V180 4 6 1 · cyberstrikeus
    Create administrative boundaries between resources using namespaces (Manual)
    0 installs
  92. Cis Gke V180 4 6 4 · cyberstrikeus
    The default namespace should not be used (Automated)
    0 installs
  93. Cis Gke V180 5 1 1 · cyberstrikeus
    Ensure Image Vulnerability Scanning is enabled (Automated)
    0 installs
  94. Cis Gke V180 5 1 2 · cyberstrikeus
    Minimize user access to Container Image repositories (Manual)
    0 installs
  95. Cis Gke V180 5 1 3 · cyberstrikeus
    Minimize cluster access to read-only for Container Image repositories (Manual)
    0 installs
  96. Cis Gke V180 5 1 4 · cyberstrikeus
    Ensure only trusted container images are used (Manual)
    0 installs
  97. Cis Gke V180 5 2 1 · cyberstrikeus
    Ensure GKE clusters are not running using the Compute Engine default service account (Automated)
    0 installs
  98. Cis Gke V180 5 2 2 · cyberstrikeus
    Prefer using dedicated GCP Service Accounts and Workload Identity (Manual)
    0 installs
  99. Cis Gke V180 5 3 1 · cyberstrikeus
    Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
    0 installs
  100. Cis Gke V180 5 4 1 · cyberstrikeus
    Ensure the GKE Metadata Server is Enabled (Automated)
    0 installs