← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 45 of 72

  1. Cis K8S V1111 5 3 1 · cyberstrikeus
    Ensure that the CNI in use supports Network Policies (Manual)
    0 installs
  2. Cis K8S V1111 5 3 2 · cyberstrikeus
    Ensure that all Namespaces have Network Policies defined (Manual)
    0 installs
  3. Cis K8S V1111 5 4 1 · cyberstrikeus
    Prefer using secrets as files over secrets as environment variables (Manual)
    0 installs
  4. Cis K8S V1111 5 4 2 · cyberstrikeus
    Consider external secret storage (Manual)
    0 installs
  5. Cis K8S V1111 5 5 1 · cyberstrikeus
    Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)
    0 installs
  6. Cis K8S V1111 5 6 1 · cyberstrikeus
    Create administrative boundaries between resources using namespaces (Manual)
    0 installs
  7. Cis K8S V1111 5 6 2 · cyberstrikeus
    Ensure that the seccomp profile is set to docker/default in your pod definitions (Manual)
    0 installs
  8. Cis K8S V1111 5 6 3 · cyberstrikeus
    Apply Security Context to Your Pods and Containers (Manual)
    0 installs
  9. Cis K8S V1111 5 6 4 · cyberstrikeus
    The default namespace should not be used (Manual)
    0 installs
  10. Cis K8S V1120 1 1 1 · cyberstrikeus
    Ensure that the API server pod specification file permissions are set to 600 or more restrictive (Automated)
    0 installs
  11. Cis K8S V1120 1 1 2 · cyberstrikeus
    Ensure that the API server pod specification file ownership is set to root:root (Automated)
    0 installs
  12. Cis K8S V1120 1 1 3 · cyberstrikeus
    Ensure that the controller manager pod specification file permissions are set to 600 or more restrictive (Automated)
    0 installs
  13. Cis K8S V1120 1 1 4 · cyberstrikeus
    Ensure that the controller manager pod specification file ownership is set to root:root (Automated)
    0 installs
  14. Cis K8S V1120 1 1 5 · cyberstrikeus
    Ensure that the scheduler pod specification file permissions are set to 600 or more restrictive (Automated)
    0 installs
  15. Cis K8S V1120 1 1 6 · cyberstrikeus
    Ensure that the scheduler pod specification file ownership is set to root:root (Automated)
    0 installs
  16. Cis K8S V1120 1 1 7 · cyberstrikeus
    Ensure that the etcd pod specification file permissions are set to 600 or more restrictive (Automated)
    0 installs
  17. Cis K8S V1120 1 1 8 · cyberstrikeus
    Ensure that the etcd pod specification file ownership is set to root:root (Automated)
    0 installs
  18. Cis K8S V1120 1 1 9 · cyberstrikeus
    Ensure that the Container Network Interface file permissions are set to 600 or more restrictive (Manual)
    0 installs
  19. Cis K8S V1120 1 2 1 · cyberstrikeus
    Ensure that the --anonymous-auth argument is set to false (Manual)
    0 installs
  20. Cis K8S V1120 1 2 2 · cyberstrikeus
    Ensure that the --token-auth-file parameter is not set (Automated)
    0 installs
  21. Cis K8S V1120 1 2 3 · cyberstrikeus
    Ensure that the DenyServiceExternalIPs is set (Manual)
    0 installs
  22. Cis K8S V1120 1 2 4 · cyberstrikeus
    Ensure that the --kubelet-client-certificate and --kubelet-client-key arguments are set as appropriate (Automated)
    0 installs
  23. Cis K8S V1120 1 2 5 · cyberstrikeus
    Ensure that the --kubelet-certificate-authority argument is set as appropriate (Automated)
    0 installs
  24. Cis K8S V1120 1 2 6 · cyberstrikeus
    Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
    0 installs
  25. Cis K8S V1120 1 2 7 · cyberstrikeus
    Ensure that the --authorization-mode argument includes Node (Automated)
    0 installs
  26. Cis K8S V1120 1 2 8 · cyberstrikeus
    Ensure that the --authorization-mode argument includes RBAC (Automated)
    0 installs
  27. Cis K8S V1120 1 2 9 · cyberstrikeus
    Ensure that the admission control plugin EventRateLimit is set (Manual)
    0 installs
  28. Cis K8S V1120 1 3 1 · cyberstrikeus
    Ensure that the --terminated-pod-gc-threshold argument is set as appropriate (Manual)
    0 installs
  29. Cis K8S V1120 1 3 2 · cyberstrikeus
    Ensure that the --profiling argument is set to false (Automated)
    0 installs
  30. Cis K8S V1120 1 3 3 · cyberstrikeus
    Ensure that the --use-service-account-credentials argument is set to true (Automated)
    0 installs
  31. Cis K8S V1120 1 3 4 · cyberstrikeus
    Ensure that the --service-account-private-key-file argument is set as appropriate (Automated)
    0 installs
  32. Cis K8S V1120 1 3 5 · cyberstrikeus
    Ensure that the --root-ca-file argument is set as appropriate (Automated)
    0 installs
  33. Cis K8S V1120 1 3 6 · cyberstrikeus
    Ensure that the RotateKubeletServerCertificate argument is set to true (Automated)
    0 installs
  34. Cis K8S V1120 1 3 7 · cyberstrikeus
    Ensure that the --bind-address argument is set to 127.0.0.1 (Automated)
    0 installs
  35. Cis K8S V1120 1 4 1 · cyberstrikeus
    Ensure that the --profiling argument is set to false (Automated)
    0 installs
  36. Cis K8S V1120 1 4 2 · cyberstrikeus
    Ensure that the --bind-address argument is set to 127.0.0.1 (Automated)
    0 installs
  37. Cis K8S V1120 3 1 1 · cyberstrikeus
    Client certificate authentication should not be used for users (Manual)
    0 installs
  38. Cis K8S V1120 3 1 2 · cyberstrikeus
    Service account token authentication should not be used for users (Manual)
    0 installs
  39. Cis K8S V1120 3 1 3 · cyberstrikeus
    Bootstrap token authentication should not be used for users (Manual)
    0 installs
  40. Cis K8S V1120 3 2 1 · cyberstrikeus
    Ensure that a minimal audit policy is created (Manual)
    0 installs
  41. Cis K8S V1120 3 2 2 · cyberstrikeus
    Ensure that the audit policy covers key security concerns (Manual)
    0 installs
  42. Cis K8S V1120 4 1 1 · cyberstrikeus
    Ensure that the kubelet service file permissions are set to 600 or more restrictive (Automated)
    0 installs
  43. Cis K8S V1120 4 1 2 · cyberstrikeus
    Ensure that the kubelet service file ownership is set to root:root (Automated)
    0 installs
  44. Cis K8S V1120 4 1 3 · cyberstrikeus
    If proxy kubeconfig file exists ensure permissions are set to 600 or more restrictive (Manual)
    0 installs
  45. Cis K8S V1120 4 1 4 · cyberstrikeus
    If proxy kubeconfig file exists ensure ownership is set to root:root (Manual)
    0 installs
  46. Cis K8S V1120 4 1 5 · cyberstrikeus
    Ensure that the --kubeconfig kubelet.conf file permissions are set to 600 or more restrictive (Automated)
    0 installs
  47. Cis K8S V1120 4 1 6 · cyberstrikeus
    Ensure that the --kubeconfig kubelet.conf file ownership is set to root:root (Automated)
    0 installs
  48. T1055 004 Asynchronous Procedure Call · cyberstrikeus
    Adversaries may inject malicious code into processes via the asynchronous procedure call (APC) queue in order to evade process-based defenses as well as possibly elevate privileges.
    0 installs
  49. T1535 Unusedunsupported Cloud Regions · cyberstrikeus
    Adversaries may create cloud instances in unused geographic service regions in order to evade detection.
    0 installs
  50. T1599 001 Network Address Translation Traversal · cyberstrikeus
    Adversaries may bridge network boundaries by modifying a network device’s Network Address Translation (NAT) configuration.
    0 installs
  51. T1666 Modify Cloud Resource Hierarchy · cyberstrikeus
    Adversaries may attempt to modify hierarchical structures in infrastructure-as-a-service (IaaS) environments in order to evade defenses.
    0 installs
  52. T1003 005 Cached Domain Credentials · cyberstrikeus
    Adversaries may attempt to access cached domain credentials used to allow authentication to occur in the event a domain controller is unavailable.
    0 installs
  53. T1556 Modify Authentication Process · cyberstrikeus
    Adversaries may modify authentication mechanisms and processes to access user credentials or enable otherwise unwarranted access to accounts.
    0 installs
  54. T1649 Steal Or Forge Authentication Certificates · cyberstrikeus
    Adversaries may steal or forge certificates used for authentication to access remote systems or resources.
    0 installs
  55. T1071 002 File Transfer Protocols · cyberstrikeus
    Adversaries may communicate using application layer protocols associated with transferring files to avoid detection/network filtering by blending in with existing traffic.
    0 installs
  56. T1219 002 Remote Desktop Software · cyberstrikeus
    An adversary may use legitimate desktop support software to establish an interactive command and control channel to target systems within networks.
    0 installs
  57. T1573 002 Asymmetric Cryptography · cyberstrikeus
    Adversaries may employ a known asymmetric encryption algorithm to conceal command and control traffic rather than relying on any inherent protections provided by a communication protocol.
    0 installs
  58. T1583 003 Virtual Private Server · cyberstrikeus
    Adversaries may rent Virtual Private Servers (VPSs) that can be used during targeting.
    0 installs
  59. T1584 003 Virtual Private Server · cyberstrikeus
    Adversaries may compromise third-party Virtual Private Servers (VPSs) that can be used during targeting.
    0 installs
  60. T1591 001 Determine Physical Locations · cyberstrikeus
    Adversaries may gather the victim's physical location(s) that can be used during targeting.
    0 installs
  61. Media Use 03 08 07 Media Use · cyberstrikeus
    Restrict or prohibit the use of [organization-defined].
    0 installs
  62. Archive And Protect Each Software Release Ps 3 Archive And P · cyberstrikeus
    Preserve software releases in order to help identify, analyze, and eliminate vulnerabilities discovered in the software after release.
    0 installs
  63. Provide A Mechanism For Verifying Software Release Integrity · cyberstrikeus
    Help software acquirers ensure that the software they acquire is legitimate and has not been tampered with.
    0 installs
  64. Ac 16 4 Association Of Attributes By Authorized Individuals · cyberstrikeus
    Provide the capability to associate [organization-defined] with [organization-defined] by authorized individuals (or processes acting on behalf of ind
    0 installs
  65. Ac 18 3 Disable Wireless Networking · cyberstrikeus
    Disable, when not intended for use, wireless networking capabilities embedded within system components prior to issuance and deployment.
    0 installs
  66. Ac 19 1 Use Of Writable And Portable Storage Devices · cyberstrikeus
    Use of Writable and Portable Storage Devices
    0 installs
  67. Ac 2 9 Restrictions On Use Of Shared And Group Accounts · cyberstrikeus
    Only permit the use of shared and group accounts that meet [organization-defined].
    0 installs
  68. Ac 2 6 Dynamic Privilege Management · cyberstrikeus
    Implement [organization-defined].
    0 installs
  69. Ac 24 2 No User Or Process Identity · cyberstrikeus
    Enforce access control decisions based on [organization-defined] that do not include the identity of the user or process acting on behalf of the user.
    0 installs
  70. Ac 3 6 Protection Of User And System Information · cyberstrikeus
    Protection of User and System Information
    0 installs
  71. Ac 3 4 Discretionary Access Control · cyberstrikeus
    Enforce [organization-defined] over the set of covered subjects and objects specified in the policy, and where the policy specifies that a subject tha
    0 installs
  72. Ac 4 11 Configuration Of Security Or Privacy Policy Filters · cyberstrikeus
    Provide the capability for privileged administrators to configure [organization-defined] to support different security or privacy policies.
    0 installs
  73. Ac 9 4 Additional Logon Information · cyberstrikeus
    Notify the user, upon successful logon, of the following additional information: [organization-defined].
    0 installs
  74. At 3 5 Processing Personally Identifiable Information · cyberstrikeus
    Provide [organization-defined] with initial and [organization-defined] training in the employment and operation of personally identifiable information
    0 installs
  75. Au 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] audit and accountability policy that: Procedures to facilitate th
    0 installs
  76. Au 9 5 Dual Authorization · cyberstrikeus
    Enforce dual authorization for [organization-defined] of [organization-defined].
    0 installs
  77. Ca 7 3 Trend Analyses · cyberstrikeus
    Employ trend analyses to determine if control implementations, the frequency of continuous monitoring activities, and the types of activities used in
    0 installs
  78. Cm 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] configuration management policy that: Procedures to facilitate th
    0 installs
  79. Cm 12 Information Location · cyberstrikeus
    Identify and document the location of [organization-defined] and the specific system components on which the information is processed and stored;
    0 installs
  80. Cm 3 8 Prevent Or Restrict Configuration Changes · cyberstrikeus
    Prevent or restrict changes to the configuration of the system under the following circumstances: [organization-defined].
    0 installs
  81. Cm 5 4 Dual Authorization · cyberstrikeus
    Enforce dual authorization for implementing changes to [organization-defined].
    0 installs
  82. Cp 7 Alternate Processing Site · cyberstrikeus
    Establish an alternate processing site, including necessary agreements to permit the transfer and resumption of [organization-defined] for essentia...
    0 installs
  83. Ir 6 2 Vulnerabilities Related To Incidents · cyberstrikeus
    Report system vulnerabilities associated with reported incidents to [organization-defined].
    0 installs
  84. Ir 6 3 Supply Chain Coordination · cyberstrikeus
    Provide incident information to the provider of the product or service and other organizations involved in the supply chain or supply chain governance
    0 installs
  85. Ir 7 Incident Response Assistance · cyberstrikeus
    Provide an incident response support resource, integral to the organizational incident response capability, that offers advice and assistance to users
    0 installs
  86. Ir 7 2 Coordination With External Providers · cyberstrikeus
    Establish a direct, cooperative relationship between its incident response capability and external providers of system protection capability;
    0 installs
  87. Ma 4 4 Authentication And Separation Of Maintenance Sessions · cyberstrikeus
    Protect nonlocal maintenance sessions by: Employing [organization-defined] ; and Separating the maintenance sessions from other network sessions with
    0 installs
  88. Ma 6 3 Automated Support For Predictive Maintenance · cyberstrikeus
    Transfer predictive maintenance data to a maintenance management system using [organization-defined].
    0 installs
  89. Mp 6 8 Remote Purging Or Wiping Of Information · cyberstrikeus
    Provide the capability to purge or wipe information from [organization-defined] [organization-defined].
    0 installs
  90. Mp 7 1 Prohibit Use Without Owner · cyberstrikeus
    Prohibit Use Without Owner
    0 installs
  91. Pm 25 Minimization Of Personally Identifiable Information Us · cyberstrikeus
    Develop, document, and implement policies and procedures that address the use of personally identifiable information for internal testing, training...
    0 installs
  92. Pm 30 1 Suppliers Of Critical Or Mission Essential Items · cyberstrikeus
    Identify, prioritize, and assess suppliers of critical or mission-essential technologies, products, and services.
    0 installs
  93. Ps 3 4 Citizenship Requirements · cyberstrikeus
    Verify that individuals accessing a system processing, storing, or transmitting [organization-defined] meet [organization-defined].
    0 installs
  94. Ps 7 External Personnel Security · cyberstrikeus
    Establish personnel security requirements, including security roles and responsibilities for external providers;
    0 installs
  95. Ra 2 1 Impact Level Prioritization · cyberstrikeus
    Conduct an impact-level prioritization of organizational systems to obtain additional granularity on system impact levels.
    0 installs
  96. Ra 5 2 Update Vulnerabilities To Be Scanned · cyberstrikeus
    Update the system vulnerabilities to be scanned [organization-defined].
    0 installs
  97. Sa 5 5 Source Code · cyberstrikeus
    Source Code
    0 installs
  98. Si 18 2 Data Tags · cyberstrikeus
    Employ data tags to automate the correction or deletion of personally identifiable information across the information life cycle within organizational
    0 installs
  99. Si 19 2 Archiving · cyberstrikeus
    Prohibit archiving of personally identifiable information elements if those elements in a dataset will not be needed after the dataset is archived.
    0 installs
  100. T0847 Replication Through Removable Media · cyberstrikeus
    Adversaries may move onto systems, such as those separated from the enterprise network, by copying malware to removable media which is inserted into the control systems environment.
    0 installs