cyberstrikeus
- 7.2k skills
- 0 followers
- 2 days ago last updated
- ▌ Cis K8S V1110 1 2 5 · cyberstrikeusEnsure that the --kubelet-certificate-authority argument is set as appropriate (Automated)
- ▌ Cis K8S V1110 1 3 1 · cyberstrikeusEnsure that the --terminated-pod-gc-threshold argument is set as appropriate (Manual)
- ▌ Cis K8S V1110 1 3 2 · cyberstrikeusEnsure that the --profiling argument is set to false (Automated)
- ▌ Cis K8S V1110 1 3 3 · cyberstrikeusEnsure that the --use-service-account-credentials argument is set to true (Automated)
- ▌ Cis K8S V1110 1 3 4 · cyberstrikeusEnsure that the --service-account-private-key-file argument is set as appropriate (Automated)
- ▌ Cis K8S V1110 1 3 5 · cyberstrikeusEnsure that the --root-ca-file argument is set as appropriate (Automated)
- ▌ Cis K8S V1110 1 3 6 · cyberstrikeusEnsure that the RotateKubeletServerCertificate argument is set to true (Automated)
- ▌ Cis K8S V1110 1 3 7 · cyberstrikeusEnsure that the --bind-address argument is set to 127.0.0.1 (Automated)
- ▌ Cis K8S V1110 1 4 1 · cyberstrikeusEnsure that the --profiling argument is set to false (Automated)
- ▌ Cis K8S V1110 1 4 2 · cyberstrikeusEnsure that the --bind-address argument is set to 127.0.0.1 (Automated)
- ▌ Cis K8S V1110 3 1 1 · cyberstrikeusClient certificate authentication should not be used for users (Manual)
- ▌ Cis K8S V1110 3 1 2 · cyberstrikeusService account token authentication should not be used for users (Manual)
- ▌ Cis K8S V1110 3 1 3 · cyberstrikeusBootstrap token authentication should not be used for users (Manual)
- ▌
- ▌ Cis K8S V1110 3 2 2 · cyberstrikeusEnsure that the audit policy covers key security concerns (Manual)
- ▌ Cis K8S V1110 4 1 1 · cyberstrikeusEnsure that the kubelet service file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1110 4 1 2 · cyberstrikeusEnsure that the kubelet service file ownership is set to root:root (Automated)
- ▌ Cis K8S V1110 4 1 3 · cyberstrikeusIf proxy kubeconfig file exists ensure permissions are set to 600 or more restrictive (Manual)
- ▌ Cis K8S V1110 4 1 4 · cyberstrikeusIf proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
- ▌ Cis K8S V1110 4 1 5 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1110 4 1 6 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
- ▌ Cis K8S V1110 4 1 7 · cyberstrikeusEnsure that the certificate authorities file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis K8S V1110 4 1 8 · cyberstrikeusEnsure that the client certificate authorities file ownership is set to root:root (Manual)
- ▌ Cis K8S V1110 4 1 9 · cyberstrikeusIf the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1110 4 2 1 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌ Cis K8S V1110 4 2 2 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis K8S V1110 4 2 3 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌
- ▌ Cis K8S V1110 4 2 5 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Manual)
- ▌ Cis K8S V1110 4 2 6 · cyberstrikeusEnsure that the --make-iptables-util-chains argument is set to true (Automated)
- ▌ Cis K8S V1110 4 2 7 · cyberstrikeusEnsure that the --hostname-override argument is not set (Manual)
- ▌ Cis K8S V1110 4 2 8 · cyberstrikeusEnsure that the eventRecordQPS argument is set to a level which ensures appropriate event capture (Manual)
- ▌ Cis K8S V1110 4 2 9 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
- ▌ Cis K8S V1110 4 3 1 · cyberstrikeusEnsure that the kube-proxy metrics service is bound to localhost (Manual)
- ▌
- ▌
- ▌
- ▌ Cis K8S V1110 5 1 5 · cyberstrikeusEnsure that default service accounts are not actively used (Manual)
- ▌ Cis K8S V1110 5 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host IPC namespace (Manual)
- ▌ Cis K8S V1110 5 2 5 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Manual)
- ▌ Cis K8S V1110 5 2 9 · cyberstrikeusMinimize the admission of containers with added capabilities (Manual)
- ▌
- ▌ Cis K8S V1110 5 4 1 · cyberstrikeusPrefer using secrets as files over secrets as environment variables (Manual)
- ▌
- ▌ Cis K8S V1110 5 7 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌ Cis K8S V1110 5 7 2 · cyberstrikeusEnsure that the seccomp profile is set to docker/default in your pod definitions (Manual)
- ▌
- ▌
- ▌ Cis K8S V1111 1 1 1 · cyberstrikeusEnsure that the API server pod specification file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1111 1 1 2 · cyberstrikeusEnsure that the API server pod specification file ownership is set to root:root (Automated)
- ▌ Cis K8S V1111 1 1 3 · cyberstrikeusEnsure that the controller manager pod specification file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1111 1 1 4 · cyberstrikeusEnsure that the controller manager pod specification file ownership is set to root:root (Automated)
- ▌ Cis K8S V1111 1 1 5 · cyberstrikeusEnsure that the scheduler pod specification file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1111 1 1 6 · cyberstrikeusEnsure that the scheduler pod specification file ownership is set to root:root (Automated)
- ▌ Cis K8S V1111 1 1 7 · cyberstrikeusEnsure that the etcd pod specification file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1111 1 1 8 · cyberstrikeusEnsure that the etcd pod specification file ownership is set to root:root (Automated)
- ▌ Cis K8S V1111 1 1 9 · cyberstrikeusEnsure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)
- ▌ Cis K8S V1111 1 2 1 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Manual)
- ▌ Cis K8S V1111 1 2 2 · cyberstrikeusEnsure that the --token-auth-file parameter is not set (Automated)
- ▌
- ▌ Cis K8S V1111 1 2 4 · cyberstrikeusEnsure that the --kubelet-client-certificate and --kubelet-client-key arguments are set as appropriate (Automated)
- ▌ Cis K8S V1111 1 2 5 · cyberstrikeusEnsure that the --kubelet-certificate-authority argument is set as appropriate (Automated)
- ▌ Cis K8S V1111 1 2 6 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis K8S V1111 1 2 7 · cyberstrikeusEnsure that the --authorization-mode argument includes Node (Automated)
- ▌ Cis K8S V1111 1 2 8 · cyberstrikeusEnsure that the --authorization-mode argument includes RBAC (Automated)
- ▌ Cis K8S V1111 1 2 9 · cyberstrikeusEnsure that the admission control plugin EventRateLimit is set (Manual)
- ▌ Cis K8S V1111 1 3 1 · cyberstrikeusEnsure that the --terminated-pod-gc-threshold argument is set as appropriate (Manual)
- ▌ Cis K8S V1111 1 3 7 · cyberstrikeusEnsure that the --bind-address argument is set to 127.0.0.1 (Automated)
- ▌ Cis K8S V1111 1 4 2 · cyberstrikeusEnsure that the --bind-address argument is set to 127.0.0.1 (Automated)
- ▌ Cis K8S V1111 3 1 1 · cyberstrikeusClient certificate authentication should not be used for users (Manual)
- ▌ Cis K8S V1111 3 1 2 · cyberstrikeusService account token authentication should not be used for users (Manual)
- ▌ Cis K8S V1111 3 1 3 · cyberstrikeusBootstrap token authentication should not be used for users (Manual)
- ▌ Cis K8S V1111 3 2 2 · cyberstrikeusEnsure that the audit policy covers key security concerns (Manual)
- ▌ Cis K8S V1111 4 1 3 · cyberstrikeusIf proxy kubeconfig file exists ensure permissions are set to 600 or more restrictive (Manual)
- ▌ Cis K8S V1111 4 1 5 · cyberstrikeusEnsure that the --kubeconfig kubelet.conf file permissions are set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1111 4 1 7 · cyberstrikeusEnsure that the certificate authorities file permissions are set to 644 or more restrictive (Manual)
- ▌ Cis K8S V1111 4 1 9 · cyberstrikeusIf the kubelet config.yaml configuration file is being used validate permissions set to 600 or more restrictive (Automated)
- ▌ Cis K8S V1111 4 2 1 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌
- ▌ Cis K8S V1111 4 2 5 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Manual)
- ▌ Cis K8S V1111 4 2 7 · cyberstrikeusEnsure that the --hostname-override argument is not set (Manual)
- ▌ Cis K8S V1111 4 2 9 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)
- ▌ Cis K8S V1111 5 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Manual)
- ▌
- ▌
- ▌
- ▌ Cis K8S V1111 5 1 5 · cyberstrikeusEnsure that default service accounts are not actively used (Manual)
- ▌ Cis K8S V1111 5 1 6 · cyberstrikeusEnsure that Service Account Tokens are only mounted where necessary (Manual)
- ▌
- ▌ Cis K8S V1111 5 1 8 · cyberstrikeusLimit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
- ▌
- ▌ Cis K8S V1111 5 2 1 · cyberstrikeusEnsure that the cluster has at least one active policy control mechanism in place (Manual)
- ▌
- ▌ Cis K8S V1111 5 2 3 · cyberstrikeusMinimize the admission of containers wishing to share the host process ID namespace (Manual)
- ▌ Cis K8S V1111 5 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host IPC namespace (Manual)
- ▌ Cis K8S V1111 5 2 5 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Manual)
- ▌ Cis K8S V1111 5 2 6 · cyberstrikeusMinimize the admission of containers with allowPrivilegeEscalation (Manual)
- ▌
- ▌ Cis K8S V1111 5 2 8 · cyberstrikeusMinimize the admission of containers with the NET_RAW capability (Manual)
- ▌ Cis K8S V1111 5 2 9 · cyberstrikeusMinimize the admission of containers with added capabilities (Manual)