← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 37 of 72

  1. Cis Ocp V190 4 1 6 · cyberstrikeus
    Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
    0 installs
  2. Cis Ocp V190 4 1 7 · cyberstrikeus
    Ensure that the certificate authorities file permissions are set to 644 or more restrictive (Automated)
    0 installs
  3. Cis Ocp V190 4 1 8 · cyberstrikeus
    Ensure that the client certificate authorities file ownership is set to root:root (Automated)
    0 installs
  4. Cis Ocp V190 4 1 9 · cyberstrikeus
    Ensure that the kubelet --config configuration file has permissions set to 600 or more restrictive (Automated)
    0 installs
  5. Cis Ocp V190 4 2 1 · cyberstrikeus
    Activate Garbage collection in OpenShift Container Platform 4, as appropriate (Manual)
    0 installs
  6. Cis Ocp V190 4 2 2 · cyberstrikeus
    Ensure that the --anonymous-auth argument is set to false (Automated)
    0 installs
  7. Cis Ocp V190 4 2 3 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0 installs
  8. Cis Ocp V190 4 2 4 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Automated)
    0 installs
  9. Cis Ocp V190 4 2 5 · cyberstrikeus
    Verify that the read only port is not used or is set to 0 (Automated)
    0 installs
  10. Cis Ocp V190 4 2 6 · cyberstrikeus
    Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
    0 installs
  11. Cis Ocp V190 4 2 7 · cyberstrikeus
    Ensure that the --make-iptables-util-chains argument is set to true (Manual)
    0 installs
  12. Cis Ocp V190 4 2 8 · cyberstrikeus
    Ensure that the kubeAPIQPS [--event-qps] argument is set to a level which ensures appropriate event capture (Manual)
    0 installs
  13. Cis Ocp V190 4 2 9 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
    0 installs
  14. Cis Ocp V190 5 1 1 · cyberstrikeus
    Ensure that the cluster-admin role is only used where required (Manual)
    0 installs
  15. Cis Ocp V190 5 1 2 · cyberstrikeus
    Minimize access to secrets (Manual)
    0 installs
  16. Cis Ocp V190 5 1 3 · cyberstrikeus
    Minimize wildcard use in Roles and ClusterRoles (Manual)
    0 installs
  17. Cis Ocp V190 5 1 4 · cyberstrikeus
    Minimize access to create pods (Manual)
    0 installs
  18. Cis Ocp V190 5 1 5 · cyberstrikeus
    Ensure that default service accounts are not actively used (Manual)
    0 installs
  19. Cis Ocp V190 5 1 6 · cyberstrikeus
    Ensure that Service Account Tokens are only mounted where necessary (Manual)
    0 installs
  20. Cis Ocp V190 5 2 1 · cyberstrikeus
    Minimize the admission of privileged containers (Manual)
    0 installs
  21. Cis Ocp V190 5 2 2 · cyberstrikeus
    Minimize the admission of containers wishing to share the host process ID namespace (Manual)
    0 installs
  22. Cis Ocp V190 5 2 3 · cyberstrikeus
    Minimize the admission of containers wishing to share the host IPC namespace (Manual)
    0 installs
  23. Cis Ocp V190 5 2 4 · cyberstrikeus
    Minimize the admission of containers wishing to share the host network namespace (Manual)
    0 installs
  24. Cis Ocp V190 5 2 5 · cyberstrikeus
    Minimize the admission of containers with allowPrivilegeEscalation (Manual)
    0 installs
  25. Cis Ocp V190 5 2 6 · cyberstrikeus
    Minimize the admission of root containers (Manual)
    0 installs
  26. Cis Ocp V190 5 2 7 · cyberstrikeus
    Minimize the admission of containers with the NET_RAW capability (Manual)
    0 installs
  27. Cis Ocp V190 5 2 8 · cyberstrikeus
    Minimize the admission of containers with added capabilities (Manual)
    0 installs
  28. Cis Ocp V190 5 2 9 · cyberstrikeus
    Minimize the admission of containers with capabilities assigned (Manual)
    0 installs
  29. Cis Ocp V190 5 3 1 · cyberstrikeus
    Ensure that the CNI in use supports Network Policies (Manual)
    0 installs
  30. Cis Ocp V190 5 3 2 · cyberstrikeus
    Ensure that all Namespaces have Network Policies defined (Manual)
    0 installs
  31. Cis Ocp V190 5 4 1 · cyberstrikeus
    Prefer using secrets as files over secrets as environment variables (Manual)
    0 installs
  32. Cis Ocp V190 5 4 2 · cyberstrikeus
    Consider external secret storage (Manual)
    0 installs
  33. Cis Ocp V190 5 5 1 · cyberstrikeus
    Configure Image Provenance using image controller configuration parameters (Manual)
    0 installs
  34. Cis Ocp V190 5 7 1 · cyberstrikeus
    Create administrative boundaries between resources using namespaces (Manual)
    0 installs
  35. Cis Ocp V190 5 7 2 · cyberstrikeus
    Ensure that the seccomp profile is set to docker/default in your pod definitions (Manual)
    0 installs
  36. Cis Ocp V190 5 7 3 · cyberstrikeus
    Apply Security Context to Your Pods and Containers (Manual)
    0 installs
  37. Cis Ocp V190 5 7 4 · cyberstrikeus
    The default namespace should not be used (Manual)
    0 installs
  38. Cis Ocp V180 1 1 1 · cyberstrikeus
    Ensure that the API server pod specification file permissions are set to 600 or more restrictive (Manual)
    0 installs
  39. Cis Ocp V180 1 1 2 · cyberstrikeus
    Ensure that the API server pod specification file ownership is set to root:root (Manual)
    0 installs
  40. Cis Ocp V180 1 1 3 · cyberstrikeus
    Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive (Manual)
    0 installs
  41. Cis Ocp V180 1 1 4 · cyberstrikeus
    Ensure that the controller manager pod specification file ownership is set to root:root (Manual)
    0 installs
  42. Cis Ocp V180 1 1 5 · cyberstrikeus
    Ensure that the scheduler pod specification file permissions are set to 600 or more restrictive (Manual)
    0 installs
  43. Cis Ocp V180 1 1 6 · cyberstrikeus
    Ensure that the scheduler pod specification file ownership is set to root:root (Manual)
    0 installs
  44. Cis Ocp V180 1 1 7 · cyberstrikeus
    Ensure that the etcd pod specification file permissions are set to 600 or more restrictive (Manual)
    0 installs
  45. Cis Ocp V180 1 1 8 · cyberstrikeus
    Ensure that the etcd pod specification file ownership is set to root:root (Manual)
    0 installs
  46. Cis Ocp V180 1 1 9 · cyberstrikeus
    Ensure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)
    0 installs
  47. Cis Ocp V180 1 2 1 · cyberstrikeus
    Ensure that anonymous requests are authorized (Manual)
    2 installs
  48. Cis Docker 4 4 · cyberstrikeus
    Ensure images are scanned and rebuilt to include security patches
    0 installs
  49. Cis Docker 4 5 · cyberstrikeus
    Ensure Content trust for Docker is Enabled
    0 installs
  50. Cis Docker 4 6 · cyberstrikeus
    Ensure that HEALTHCHECK instructions have been added to container images
    0 installs
  51. Cis Docker 4 7 · cyberstrikeus
    Ensure update instructions are not used alone in Dockerfiles
    0 installs
  52. Cis Docker 4 8 · cyberstrikeus
    Ensure setuid and setgid permissions are removed
    0 installs
  53. Cis Docker 4 9 · cyberstrikeus
    Ensure that COPY is used instead of ADD in Dockerfiles
    0 installs
  54. Cis Docker 5 1 · cyberstrikeus
    Ensure swarm mode is not Enabled, if not needed
    0 installs
  55. Cis Docker 5 2 · cyberstrikeus
    Ensure that, if applicable, an AppArmor Profile is enabled
    0 installs
  56. Cis Docker 5 3 · cyberstrikeus
    Ensure that, if applicable, SELinux security options are set
    0 installs
  57. Cis Docker 5 4 · cyberstrikeus
    Ensure that Linux kernel capabilities are restricted within containers
    0 installs
  58. Cis Docker 5 5 · cyberstrikeus
    Ensure that privileged containers are not used
    0 installs
  59. Cis Docker 5 6 · cyberstrikeus
    Ensure sensitive host system directories are not mounted on containers
    0 installs
  60. Cis Docker 5 7 · cyberstrikeus
    Ensure sshd is not run within containers
    0 installs
  61. Cis Docker 5 8 · cyberstrikeus
    Ensure privileged ports are not mapped within containers
    0 installs
  62. Cis Docker 5 9 · cyberstrikeus
    Ensure that only needed ports are open on the container
    0 installs
  63. Cis Docker 6 1 · cyberstrikeus
    Ensure that image sprawl is avoided
    0 installs
  64. Cis Docker 6 2 · cyberstrikeus
    Ensure that container sprawl is avoided
    0 installs
  65. Cis Docker 7 1 · cyberstrikeus
    Ensure that the minimum number of manager nodes have been created in a swarm
    0 installs
  66. Cis Docker 7 2 · cyberstrikeus
    Ensure that swarm services are bound to a specific host interface
    0 installs
  67. Cis Docker 7 3 · cyberstrikeus
    Ensure that all Docker swarm overlay networks are encrypted
    0 installs
  68. Cis Docker 7 4 · cyberstrikeus
    Ensure that Docker's secret management commands are used for managing secrets in a swarm cluster
    0 installs
  69. Cis Docker 7 5 · cyberstrikeus
    Ensure that swarm manager is run in auto-lock mode
    0 installs
  70. Cis Docker 7 6 · cyberstrikeus
    Ensure that the swarm manager auto-lock key is rotated periodically
    1 install
  71. Cis Docker 7 7 · cyberstrikeus
    Ensure that node certificates are rotated as appropriate
    0 installs
  72. Cis Docker 7 8 · cyberstrikeus
    Ensure that CA certificates are rotated as appropriate
    0 installs
  73. Cis Docker 7 9 · cyberstrikeus
    Ensure that management plane traffic is separated from data plane traffic
    0 installs
  74. T1404 Exploitation For Privilege Escalation · cyberstrikeus
    Adversaries may exploit software vulnerabilities in order to elevate privileges.
    0 installs
  75. T1406 Obfuscated Files Or Information · cyberstrikeus
    Adversaries may attempt to make a payload or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the device or in transit.
    0 installs
  76. T1629 001 Prevent Application Removal · cyberstrikeus
    Adversaries may abuse the Android device administration API to prevent the user from uninstalling a target application.
    0 installs
  77. T1521 002 Asymmetric Cryptography · cyberstrikeus
    Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic, rather than relying on any inherent protections provided by a communication protocol.
    0 installs
  78. T1548 Abuse Elevation Control Mechanism · cyberstrikeus
    Adversaries may circumvent mechanisms designed to control elevate privileges to gain higher-level permissions.
    0 installs
  79. Access Control For Mobile Devices 03 01 18 Access Control Fo · cyberstrikeus
    Establish usage restrictions, configuration requirements, and connection requirements for mobile devices.
    0 installs
  80. Least Privilege Privileged Functions 03 01 07 Least Privileg · cyberstrikeus
    Prevent non-privileged users from executing privileged functions.
    0 installs
  81. System Use Notification 03 01 09 System Use Notification · cyberstrikeus
    System Use Notification
    0 installs
  82. Use Of External Systems 03 01 20 Use Of External Systems · cyberstrikeus
    Prohibit the use of external systems unless the systems are specifically authorized.
    0 installs
  83. Information Location 03 04 11 Information Location · cyberstrikeus
    Identify and document the location of CUI and the system components on which the information is processed and stored.
    0 installs
  84. Risk Response 03 11 04 Risk Response · cyberstrikeus
    Risk Response
    0 installs
  85. Define Security Requirements For Software Development Po 1 D · cyberstrikeus
    Ensure that security requirements for software development are known at all times so that they can be taken into account throughout the SDLC and du...
    0 installs
  86. Au 12 4 Query Parameter Audits Of Personally Identifiable In · cyberstrikeus
    Provide and implement the capability for auditing the parameters of user query events for data sets containing personally identifiable information.
    0 installs
  87. Au 6 2 Automated Security Alerts · cyberstrikeus
    Automated Security Alerts
    0 installs
  88. Au 7 2 Automatic Sort And Search · cyberstrikeus
    Automatic Sort and Search
    0 installs
  89. Au 9 2 Store On Separate Physical Systems Or Components · cyberstrikeus
    Store audit records [organization-defined] in a repository that is part of a physically different system or system component than the system or compon
    0 installs
  90. Au 9 1 Hardware Write Once Media · cyberstrikeus
    Write audit trails to hardware-enforced, write-once media.
    0 installs
  91. Ca 2 1 Independent Assessors · cyberstrikeus
    Employ independent assessors or assessment teams to conduct control assessments.
    0 installs
  92. Cm 10 Software Usage Restrictions · cyberstrikeus
    Use software and associated documentation in accordance with contract agreements and copyright laws;
    0 installs
  93. Cm 11 3 Automated Enforcement And Monitoring · cyberstrikeus
    Enforce and monitor compliance with software installation policies using [organization-defined].
    0 installs
  94. Cm 3 Configuration Change Control · cyberstrikeus
    Determine and document the types of changes to the system that are configuration-controlled;
    0 installs
  95. Cm 6 4 Conformance Demonstration · cyberstrikeus
    Conformance Demonstration
    0 installs
  96. Cm 7 6 Confined Environments With Limited Privileges · cyberstrikeus
    Require that the following user-installed software execute in a confined physical or virtual machine environment with limited privileges: [organizatio
    0 installs
  97. Cm 7 2 Prevent Program Execution · cyberstrikeus
    Prevent program execution in accordance with [organization-defined].
    0 installs
  98. Cm 8 5 No Duplicate Accounting Of Components · cyberstrikeus
    No Duplicate Accounting of Components
    0 installs
  99. Cp 13 Alternative Security Mechanisms · cyberstrikeus
    Employ [organization-defined] for satisfying [organization-defined] when the primary means of implementing the security function is unavailable or com
    0 installs
  100. Cp 2 1 Coordinate With Related Plans · cyberstrikeus
    Coordinate contingency plan development with organizational elements responsible for related plans.
    0 installs