← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 47 of 72

  1. Mp 6 1 Review Approve Track Document And Verify · cyberstrikeus
    Review, approve, track, document, and verify media sanitization and disposal actions.
    0 installs
  2. Pm 11 Mission And Business Process Definition · cyberstrikeus
    Define organizational mission and business processes with consideration for information security and privacy and the resulting risk to organization...
    0 installs
  3. Pm 30 Supply Chain Risk Management Strategy · cyberstrikeus
    Develop an organization-wide strategy for managing supply chain risks associated with the development, acquisition, maintenance, and disposal of sy...
    0 installs
  4. Pm 4 Plan Of Action And Milestones Process · cyberstrikeus
    Implement a process to ensure that plans of action and milestones for the information security, privacy, and supply chain risk management programs and
    0 installs
  5. Ra 5 3 Breadth And Depth Of Coverage · cyberstrikeus
    Define the breadth and depth of vulnerability scanning coverage.
    0 installs
  6. Sa 13 Trustworthiness · cyberstrikeus
    Trustworthiness
    0 installs
  7. Sa 8 33 Minimization · cyberstrikeus
    Implement the privacy principle of minimization using [organization-defined].
    0 installs
  8. Sc 25 Thin Nodes · cyberstrikeus
    Employ minimal functionality and information storage on the following system components: [organization-defined].
    0 installs
  9. Si 11 Error Handling · cyberstrikeus
    Generate error messages that provide information necessary for corrective actions without revealing information that could be exploited;
    0 installs
  10. Si 8 Spam Protection · cyberstrikeus
    Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages;
    0 installs
  11. Sr 12 Component Disposal · cyberstrikeus
    Dispose of [organization-defined] using the following techniques and methods: [organization-defined].
    0 installs
  12. T0869 Standard Application Layer Protocol · cyberstrikeus
    Adversaries may establish command and control capabilities over commonly used application layer protocols such as HTTP(S), OPC, RDP, telnet, DNP3, and modbus.
    0 installs
  13. T0866 Exploitation Of Remote Services · cyberstrikeus
    Adversaries may exploit a software vulnerability to take advantage of a programming error in a program, service, or within the operating system software or kernel itself to enable remote service ab...
    0 installs
  14. T1629 003 Disable Or Modify Tools · cyberstrikeus
    Adversaries may disable security tools to avoid potential detection of their tools and activities.
    0 installs
  15. T1422 001 Internet Connection Discovery · cyberstrikeus
    Adversaries may check for Internet connectivity on compromised systems.
    0 installs
  16. T1623 Command And Scripting Interpreter · cyberstrikeus
    Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries.
    0 installs
  17. T1658 Exploitation For Client Execution · cyberstrikeus
    Adversaries may exploit software vulnerabilities in client applications to execute code.
    0 installs
  18. T1055 001 Dynamic Link Library Injection · cyberstrikeus
    Adversaries may inject dynamic-link libraries (DLLs) into processes in order to evade process-based defenses as well as possibly elevate privileges.
    0 installs
  19. T1070 002 Clear Linux Or Mac System Logs · cyberstrikeus
    Adversaries may clear system logs to hide evidence of an intrusion.
    0 installs
  20. T1562 003 Impair Command History Logging · cyberstrikeus
    Adversaries may impair command history logging to hide commands they run on a compromised system.
    0 installs
  21. T1555 Credentials From Password Stores · cyberstrikeus
    Adversaries may search for common password storage locations to obtain user credentials.
    0 installs
  22. T1071 005 Publishsubscribe Protocols · cyberstrikeus
    Adversaries may communicate using publish/subscribe (pub/sub) application layer protocols to avoid detection/network filtering by blending in with existing traffic.
    0 installs
  23. T1095 Non Application Layer Protocol · cyberstrikeus
    Adversaries may use an OSI non-application layer protocol for communication between host and C2 server or among infected hosts within a network.
    0 installs
  24. T1587 002 Code Signing Certificates · cyberstrikeus
    Adversaries may create self-signed code signing certificates that can be used during targeting.
    0 installs
  25. T1588 003 Code Signing Certificates · cyberstrikeus
    Adversaries may buy and/or steal code signing certificates that can be used during targeting.
    0 installs
  26. Transmission And Storage Confidentiality 03 13 08 Transmissi · cyberstrikeus
    Transmission and Storage Confidentiality
    0 installs
  27. Account Management 03 01 01 Account Management · cyberstrikeus
    Define the types of system accounts allowed and prohibited.
    0 installs
  28. Maintenance Tools 03 07 04 Maintenance Tools · cyberstrikeus
    Approve, control, and monitor the use of system maintenance tools.
    0 installs
  29. Nonlocal Maintenance 03 07 05 Nonlocal Maintenance · cyberstrikeus
    Approve and monitor nonlocal maintenance and diagnostic activities.
    0 installs
  30. Media Sanitization 03 08 03 Media Sanitization · cyberstrikeus
    Media Sanitization
    0 installs
  31. Ac 17 4 Privileged Commands And Access · cyberstrikeus
    Authorize the execution of privileged commands and access to security-relevant information via remote access only in a format that provides assessa...
    0 installs
  32. Ac 18 5 Antennas And Transmission Power Levels · cyberstrikeus
    Select radio antennas and calibrate transmission power levels to reduce the probability that signals from wireless access points can be received outsi
    0 installs
  33. Ac 19 Access Control For Mobile Devices · cyberstrikeus
    Establish configuration requirements, connection requirements, and implementation guidance for organization-controlled mobile devices, to include w...
    0 installs
  34. Ac 19 3 Use Of Portable Storage Devices With No Identifiable · cyberstrikeus
    Use of Portable Storage Devices with No Identifiable Owner
    0 installs
  35. Ac 2 12 Account Monitoring For Atypical Usage · cyberstrikeus
    Monitor system accounts for [organization-defined] ;
    0 installs
  36. Ac 3 13 Attribute Based Access Control · cyberstrikeus
    Enforce attribute-based access control policy over defined subjects and objects and control access based upon [organization-defined].
    0 installs
  37. Ac 6 9 Log Use Of Privileged Functions · cyberstrikeus
    Log the execution of privileged functions.
    0 installs
  38. Ac 9 3 Notification Of Account Changes · cyberstrikeus
    Notify the user, upon successful logon, of changes to [organization-defined] during [organization-defined].
    0 installs
  39. Au 12 Audit Record Generation · cyberstrikeus
    Provide audit record generation capability for the event types the system is capable of auditing as defined in [AU-2a](#au-2_smt.a) on [organizatio...
    0 installs
  40. Au 12 3 Changes By Authorized Individuals · cyberstrikeus
    Provide and implement the capability for [organization-defined] to change the logging to be performed on [organization-defined] based on [organization
    0 installs
  41. Au 12 2 Standardized Formats · cyberstrikeus
    Produce a system-wide (logical or physical) audit trail composed of audit records in a standardized format.
    0 installs
  42. Au 3 Content Of Audit Records · cyberstrikeus
    Ensure that audit records contain information that establishes the following: What type of event occurred; When the event occurred; Where the event oc
    0 installs
  43. Au 6 3 Correlate Audit Record Repositories · cyberstrikeus
    Analyze and correlate audit records across different repositories to gain organization-wide situational awareness.
    0 installs
  44. Ca 3 Information Exchange · cyberstrikeus
    Approve and manage the exchange of information between the system and other systems using [organization-defined];
    0 installs
  45. Ca 9 1 Compliance Checks · cyberstrikeus
    Perform security and privacy compliance checks on constituent system components prior to the establishment of the internal connection.
    0 installs
  46. Cm 10 1 Open Source Software · cyberstrikeus
    Establish the following restrictions on the use of open-source software: [organization-defined].
    0 installs
  47. Cm 11 User Installed Software · cyberstrikeus
    Establish [organization-defined] governing the installation of software by users;
    0 installs
  48. Cis K8S V1111 1 1 18 · cyberstrikeus
    Ensure that the controller-manager.conf file ownership is set to root:root (Automated)
    0 installs
  49. Cis K8S V1111 1 1 19 · cyberstrikeus
    Ensure that the Kubernetes PKI directory and file ownership is set to root:root (Automated)
    0 installs
  50. Cis K8S V1111 1 1 20 · cyberstrikeus
    Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual)
    0 installs
  51. Cis K8S V1111 1 1 21 · cyberstrikeus
    Ensure that the Kubernetes PKI key file permissions are set to 600 (Manual)
    0 installs
  52. Cis K8S V1111 1 2 10 · cyberstrikeus
    Ensure that the admission control plugin AlwaysAdmit is not set (Automated)
    0 installs
  53. Cis K8S V1111 1 2 11 · cyberstrikeus
    Ensure that the admission control plugin AlwaysPullImages is set (Manual)
    0 installs
  54. Cis K8S V1111 1 2 12 · cyberstrikeus
    Ensure that the admission control plugin ServiceAccount is set (Automated)
    2 installs
  55. Cis K8S V1111 1 2 13 · cyberstrikeus
    Ensure that the admission control plugin NamespaceLifecycle is set (Automated)
    0 installs
  56. Cis K8S V1111 1 2 14 · cyberstrikeus
    Ensure that the admission control plugin NodeRestriction is set (Automated)
    0 installs
  57. Cis K8S V1111 1 2 15 · cyberstrikeus
    Ensure that the --profiling argument is set to false (Automated)
    0 installs
  58. Cis K8S V1111 1 2 16 · cyberstrikeus
    Ensure that the --audit-log-path argument is set (Automated)
    0 installs
  59. Cis K8S V1111 1 2 17 · cyberstrikeus
    Ensure that the --audit-log-maxage argument is set to 30 or as appropriate (Automated)
    0 installs
  60. Cis K8S V1111 1 2 18 · cyberstrikeus
    Ensure that the --audit-log-maxbackup argument is set to 10 or as appropriate (Automated)
    0 installs
  61. Cis K8S V1111 1 2 19 · cyberstrikeus
    Ensure that the --audit-log-maxsize argument is set to 100 or as appropriate (Automated)
    0 installs
  62. Cis K8S V1111 1 2 20 · cyberstrikeus
    Ensure that the --request-timeout argument is set as appropriate (Manual)
    0 installs
  63. Cis K8S V1111 1 2 21 · cyberstrikeus
    Ensure that the --service-account-lookup argument is set to true (Automated)
    0 installs
  64. Cis K8S V1111 1 2 22 · cyberstrikeus
    Ensure that the --service-account-key-file argument is set as appropriate (Automated)
    0 installs
  65. Cis K8S V1111 1 2 23 · cyberstrikeus
    Ensure that the --etcd-certfile and --etcd-keyfile arguments are set as appropriate (Automated)
    0 installs
  66. Cis K8S V1111 1 2 24 · cyberstrikeus
    Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
    0 installs
  67. Cis K8S V1111 1 2 25 · cyberstrikeus
    Ensure that the --client-ca-file argument is set as appropriate (Automated)
    0 installs
  68. Cis K8S V1111 1 2 26 · cyberstrikeus
    Ensure that the --etcd-cafile argument is set as appropriate (Automated)
    0 installs
  69. Cis K8S V1111 1 2 27 · cyberstrikeus
    Ensure that the --encryption-provider-config argument is set as appropriate (Manual)
    0 installs
  70. Cis K8S V1111 1 2 28 · cyberstrikeus
    Ensure that encryption providers are appropriately configured (Manual)
    1 install
  71. Cis K8S V1111 1 2 29 · cyberstrikeus
    Ensure that the API Server only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  72. Cis K8S V1111 1 2 30 · cyberstrikeus
    Ensure that the --service-account-extend-token-expiration parameter is set to false (Automated)
    0 installs
  73. Cis K8S V1111 4 2 10 · cyberstrikeus
    Ensure that the --rotate-certificates argument is not set to false (Automated)
    0 installs
  74. Cis K8S V1111 4 2 12 · cyberstrikeus
    Ensure that the Kubelet only makes use of Strong Cryptographic Ciphers (Manual)
    0 installs
  75. Cis K8S V1111 4 2 13 · cyberstrikeus
    Ensure that a limit is set on pod PIDs (Manual)
    0 installs
  76. Cis K8S V1111 4 2 14 · cyberstrikeus
    Ensure that the --seccomp-default parameter is set to true (Manual)
    0 installs
  77. Cis K8S V1111 4 2 15 · cyberstrikeus
    Ensure that the --IPAddressDeny is set to any (Manual)
    0 installs
  78. Cis K8S V1111 5 1 10 · cyberstrikeus
    Minimize access to the proxy sub-resource of nodes (Manual)
    0 installs
  79. Cis K8S V1111 5 1 11 · cyberstrikeus
    Minimize access to the approval sub-resource of certificatesigningrequests objects (Manual)
    0 installs
  80. Cis K8S V1111 5 1 12 · cyberstrikeus
    Minimize access to webhook configuration objects (Manual)
    0 installs
  81. Cis K8S V1111 5 1 13 · cyberstrikeus
    Minimize access to the service account token creation (Manual)
    0 installs
  82. Cis K8S V1111 5 2 10 · cyberstrikeus
    Minimize the admission of containers with capabilities assigned (Manual)
    0 installs
  83. Cis K8S V1111 5 2 11 · cyberstrikeus
    Minimize the admission of Windows HostProcess Containers (Manual)
    0 installs
  84. Cis K8S V1111 5 2 12 · cyberstrikeus
    Minimize the admission of HostPath volumes (Manual)
    0 installs
  85. Cis K8S V1111 5 2 13 · cyberstrikeus
    Minimize the admission of containers which use HostPorts (Manual)
    0 installs
  86. Cis K8S V1120 1 1 10 · cyberstrikeus
    Ensure that the Container Network Interface file ownership is set to root:root (Manual)
    0 installs
  87. Cis K8S V1120 1 1 11 · cyberstrikeus
    Ensure that the etcd data directory permissions are set to 700 or more restrictive (Automated)
    0 installs
  88. Cis K8S V1120 1 1 12 · cyberstrikeus
    Ensure that the etcd data directory ownership is set to etcd:etcd (Automated)
    0 installs
  89. Cis K8S V1120 1 1 13 · cyberstrikeus
    Ensure that the default administrative credential file permissions are set to 600 (Automated)
    0 installs
  90. Cis K8S V1120 1 1 14 · cyberstrikeus
    Ensure that the default administrative credential file ownership is set to root:root (Automated)
    0 installs
  91. Cis K8S V1120 1 1 15 · cyberstrikeus
    Ensure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)
    0 installs
  92. Cis K8S V1120 1 1 16 · cyberstrikeus
    Ensure that the scheduler.conf file ownership is set to root:root (Automated)
    0 installs
  93. Cis K8S V1120 1 1 17 · cyberstrikeus
    Ensure that the controller-manager.conf file permissions are set to 600 or more restrictive (Automated)
    0 installs
  94. Cis K8S V1120 1 1 18 · cyberstrikeus
    Ensure that the controller-manager.conf file ownership is set to root:root (Automated)
    0 installs
  95. Cis K8S V1120 1 1 19 · cyberstrikeus
    Ensure that the Kubernetes PKI directory and file ownership is set to root:root (Automated)
    0 installs
  96. Cis K8S V1120 1 1 20 · cyberstrikeus
    Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual)
    0 installs
  97. Cis K8S V1120 1 1 21 · cyberstrikeus
    Ensure that the Kubernetes PKI key file permissions are set to 600 (Manual)
    0 installs
  98. Cis K8S V1120 1 2 10 · cyberstrikeus
    Ensure that the admission control plugin AlwaysAdmit is not set (Automated)
    0 installs
  99. Cis K8S V1120 1 2 11 · cyberstrikeus
    Ensure that the admission control plugin AlwaysPullImages is set (Manual)
    0 installs
  100. Cis K8S V1120 1 2 12 · cyberstrikeus
    Ensure that the admission control plugin ServiceAccount is set (Automated)
    0 installs