← all publishers

cyberstrikeus

@cyberstrikeus source repo

7171 published skills · page 51 of 72

  1. Cis Nginx V300 5 2 1 · cyberstrikeus
    Ensure timeout values for reading the client header and body are set correctly (Manual)
    0 installs
  2. Cis Nginx V300 5 2 2 · cyberstrikeus
    Ensure the maximum request body size is set correctly (Manual)
    0 installs
  3. Cis Nginx V300 5 2 3 · cyberstrikeus
    Ensure the maximum buffer size for URIs is defined (Manual)
    0 installs
  4. Cis Nginx V300 5 2 4 · cyberstrikeus
    Ensure the number of connections per IP address is limited (Manual)
    0 installs
  5. Cis Nginx V300 5 2 5 · cyberstrikeus
    Ensure rate limits by IP address are set (Manual)
    0 installs
  6. Cis Nginx V300 5 3 1 · cyberstrikeus
    Ensure X-Content-Type-Options header is configured and enabled (Manual)
    0 installs
  7. Cis Nginx V300 5 3 2 · cyberstrikeus
    Ensure that Content Security Policy (CSP) is enabled and configured properly (Manual)
    0 installs
  8. Cis Nginx V300 5 3 3 · cyberstrikeus
    Ensure the Referrer Policy is enabled and configured properly (Manual)
    0 installs
  9. T1481 002 Bidirectional Communication · cyberstrikeus
    Adversaries may use an existing, legitimate external Web service channel as a means for sending commands to and receiving output from a compromised system.
    0 installs
  10. Audit Record Reduction And Report Generation 03 03 06 Audit · cyberstrikeus
    Implement an audit record reduction and report generation capability that supports audit record review, analysis, reporting requirements, and after...
    0 installs
  11. Response To Audit Logging Process Failures 03 03 04 Response · cyberstrikeus
    Alert organizational personnel or roles within [organization-defined] in the event of an audit logging process failure.
    0 installs
  12. Alternate Work Site 03 10 06 Alternate Work Site · cyberstrikeus
    Determine alternate work sites allowed for use by employees.
    0 installs
  13. Define And Use Criteria For Software Security Checks Po 4 De · cyberstrikeus
    Help ensure that the software resulting from the SDLC meets the organization’s expectations by defining and using criteria for checking the software’s
    0 installs
  14. Implement Supporting Toolchains Po 3 Implement Supporting To · cyberstrikeus
    Use automation to reduce human effort and improve the accuracy, reproducibility, usability, and comprehensiveness of security practices throughout ...
    0 installs
  15. Au 14 3 Remote Viewing And Listening · cyberstrikeus
    Provide and implement the capability for authorized users to remotely view and hear content related to an established user session in real time.
    0 installs
  16. Au 16 2 Sharing Of Audit Information · cyberstrikeus
    Provide cross-organizational audit information to [organization-defined] based on [organization-defined].
    0 installs
  17. Au 4 1 Transfer To Alternate Storage · cyberstrikeus
    Transfer audit logs [organization-defined] to a different system, system component, or media other than the system or system component conducting the
    0 installs
  18. Au 6 Audit Record Review Analysis And Reporting · cyberstrikeus
    Review and analyze system audit records [organization-defined] for indications of [organization-defined] and the potential impact of the inappropri...
    0 installs
  19. Au 6 1 Automated Process Integration · cyberstrikeus
    Integrate audit record review, analysis, and reporting processes using [organization-defined].
    0 installs
  20. Au 9 4 Access By Subset Of Privileged Users · cyberstrikeus
    Authorize access to management of audit logging functionality to only [organization-defined].
    0 installs
  21. Cm 6 3 Unauthorized Change Detection · cyberstrikeus
    Unauthorized Change Detection
    0 installs
  22. Ia 13 Identity Providers And Authorization Servers · cyberstrikeus
    Employ identity providers and authorization servers to manage user, device, and non-person entity (NPE) identities, attributes, and access rights supp
    0 installs
  23. Ia 4 4 Identify User Status · cyberstrikeus
    Manage individual identifiers by uniquely identifying each individual as [organization-defined].
    0 installs
  24. Ia 5 11 Hardware Token Based Authentication · cyberstrikeus
    Hardware Token-based Authentication
    0 installs
  25. Ia 5 13 Expiration Of Cached Authenticators · cyberstrikeus
    Prohibit the use of cached authenticators after [organization-defined].
    0 installs
  26. Ia 6 Authentication Feedback · cyberstrikeus
    Obscure feedback of authentication information during the authentication process to protect the information from possible exploitation and use by unau
    0 installs
  27. Ia 9 1 Information Exchange · cyberstrikeus
    Information Exchange
    0 installs
  28. Pe 12 Emergency Lighting · cyberstrikeus
    Employ and maintain automatic emergency lighting for the system that activates in the event of a power outage or disruption and that covers emergency
    0 installs
  29. Pe 3 4 Lockable Casings · cyberstrikeus
    Use lockable physical casings to protect [organization-defined] from unauthorized physical access.
    0 installs
  30. Pt 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] personally identifiable information processing and transparency p
    0 installs
  31. Sa 11 8 Dynamic Code Analysis · cyberstrikeus
    Require the developer of the system, system component, or system service to employ dynamic code analysis tools to identify common flaws and document t
    0 installs
  32. Sa 17 3 Formal Correspondence · cyberstrikeus
    Require the developer of the system, system component, or system service to: Produce, as an integral part of the development process, a formal top-lev
    0 installs
  33. Sa 17 6 Structure For Testing · cyberstrikeus
    Require the developer of the system, system component, or system service to structure security-relevant hardware, software, and firmware to facilitate
    0 installs
  34. Sa 8 19 Continuous Protection · cyberstrikeus
    Implement the security design principle of continuous protection in [organization-defined].
    0 installs
  35. Sa 8 2 Least Common Mechanism · cyberstrikeus
    Implement the security design principle of least common mechanism in [organization-defined].
    0 installs
  36. Sa 9 4 Consistent Interests Of Consumers And Providers · cyberstrikeus
    Take the following actions to verify that the interests of [organization-defined] are consistent with and reflect organizational interests: [organizat
    0 installs
  37. Sa 9 6 Organization Controlled Cryptographic Keys · cyberstrikeus
    Maintain exclusive control of cryptographic keys for encrypted material stored or transmitted through an external system.
    0 installs
  38. Sa 9 7 Organization Controlled Integrity Checking · cyberstrikeus
    Provide the capability to check the integrity of information while it resides in the external system.
    0 installs
  39. Sc 12 4 Pki Certificates · cyberstrikeus
    PKI Certificates
    0 installs
  40. Sc 24 Fail In Known State · cyberstrikeus
    Fail to a [organization-defined] for the following failures on the indicated components while preserving [organization-defined] in failure: [organizat
    0 installs
  41. Sc 32 System Partitioning · cyberstrikeus
    Partition the system into [organization-defined] residing in separate [organization-defined] domains or environments based on [organization-defined].
    0 installs
  42. Sc 38 Operations Security · cyberstrikeus
    Employ the following operations security controls to protect key organizational information throughout the system development life cycle: [organizatio
    0 installs
  43. Sc 44 Detonation Chambers · cyberstrikeus
    Employ a detonation chamber capability within [organization-defined].
    0 installs
  44. Sc 7 11 Restrict Incoming Communications Traffic · cyberstrikeus
    Only allow incoming communications from [organization-defined] to be routed to [organization-defined].
    0 installs
  45. Si 10 3 Predictable Behavior · cyberstrikeus
    Verify that the system behaves in a predictable and documented manner when invalid inputs are received.
    0 installs
  46. Si 10 6 Injection Prevention · cyberstrikeus
    Prevent untrusted data injections.
    0 installs
  47. Si 12 3 Information Disposal · cyberstrikeus
    Use the following techniques to dispose of, destroy, or erase information following the retention period: [organization-defined].
    0 installs
  48. Cm 2 4 Unauthorized Software · cyberstrikeus
    Unauthorized Software
    0 installs
  49. Cm 3 2 Testing Validation And Documentation Of Changes · cyberstrikeus
    Test, validate, and document changes to the system before finalizing the implementation of the changes.
    0 installs
  50. Cm 3 7 Review System Changes · cyberstrikeus
    Review changes to the system [organization-defined] or when [organization-defined] to determine whether unauthorized changes have occurred.
    0 installs
  51. Cm 5 2 Review System Changes · cyberstrikeus
    Review System Changes
    0 installs
  52. Cm 7 9 Prohibiting The Use Of Unauthorized Hardware · cyberstrikeus
    Identify [organization-defined];
    0 installs
  53. Cm 8 2 Automated Maintenance · cyberstrikeus
    Maintain the currency, completeness, accuracy, and availability of the inventory of system components using [organization-defined].
    0 installs
  54. Cp 10 1 Contingency Plan Testing · cyberstrikeus
    Contingency Plan Testing
    0 installs
  55. Cp 4 2 Alternate Processing Site · cyberstrikeus
    Test the contingency plan at the alternate processing site: To familiarize contingency personnel with the facility and available resources; and To eva
    0 installs
  56. Cp 8 4 Provider Contingency Plan · cyberstrikeus
    Require primary and alternate telecommunications service providers to have contingency plans;
    0 installs
  57. Ir 4 11 Integrated Incident Response Team · cyberstrikeus
    Establish and maintain an integrated incident response team that can be deployed to any location identified by the organization in [organization-defin
    0 installs
  58. Pm 16 1 Automated Means For Sharing Threat Intelligence · cyberstrikeus
    Employ automated mechanisms to maximize the effectiveness of sharing threat intelligence information.
    0 installs
  59. Pt 2 2 Automation · cyberstrikeus
    Manage enforcement of the authorized processing of personally identifiable information using [organization-defined].
    0 installs
  60. Pt 3 2 Automation · cyberstrikeus
    Track processing purposes of personally identifiable information using [organization-defined].
    0 installs
  61. Pt 4 3 Revocation · cyberstrikeus
    Implement [organization-defined] for individuals to revoke consent to the processing of their personally identifiable information.
    0 installs
  62. Ra 3 2 Use Of All Source Intelligence · cyberstrikeus
    Use all-source intelligence to assist in the analysis of risk.
    0 installs
  63. Sa 17 8 Orchestration · cyberstrikeus
    Design [organization-defined] with coordinated behavior to implement the following capabilities: [organization-defined].
    0 installs
  64. Sa 8 21 Self Analysis · cyberstrikeus
    Implement the security design principle of self-analysis in [organization-defined].
    0 installs
  65. Sc 18 Mobile Code · cyberstrikeus
    Define acceptable and unacceptable mobile code and mobile code technologies;
    0 installs
  66. Si 14 Non Persistence · cyberstrikeus
    Implement non-persistent [organization-defined] that are initiated in a known state and terminated [organization-defined].
    0 installs
  67. Si 2 Flaw Remediation · cyberstrikeus
    Identify, report, and correct system flaws;
    0 installs
  68. T0803 Block Command Message · cyberstrikeus
    Adversaries may block a command message from reaching its intended target to prevent command execution.
    0 installs
  69. T0838 Modify Alarm Settings · cyberstrikeus
    Adversaries may modify alarm settings to prevent alerts that may inform operators of their presence or to prevent responses to dangerous and unintended scenarios.
    0 installs
  70. T0890 Exploitation For Privilege Escalation · cyberstrikeus
    Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
    0 installs
  71. T1458 Replication Through Removable Media · cyberstrikeus
    Adversaries may move onto devices by exploiting or copying malware to devices connected via USB.
    0 installs
  72. T1625 001 System Runtime API Hijacking · cyberstrikeus
    Adversaries may execute their own malicious payloads by hijacking the way an operating system runs applications.
    0 installs
  73. T1407 Download New Code At Runtime · cyberstrikeus
    Adversaries may download and execute dynamic code not included in the original application package after installation.
    0 installs
  74. T1628 003 Conceal Multimedia Files · cyberstrikeus
    Adversaries may attempt to hide multimedia files from the user.
    0 installs
  75. T1655 001 Match Legitimate Name Or Location · cyberstrikeus
    Adversaries may match or approximate the name or location of legitimate files or resources when naming/placing them.
    0 installs
  76. T1555 003 Credentials From Web Browsers · cyberstrikeus
    Adversaries may acquire credentials from web browsers by reading files specific to the target browser.
    0 installs
  77. T1556 004 Network Device Authentication · cyberstrikeus
    Adversaries may use Patch System Image to hard code a password in the operating system, thus bypassing of native authentication mechanisms for local accounts on network devices.
    0 installs
  78. T1557 001 Llmnrnbt Ns Poisoning And Smb Relay · cyberstrikeus
    By responding to LLMNR/NBT-NS network traffic, adversaries may spoof an authoritative source for name resolution to force communication with an adversary controlled system.
    0 installs
  79. T1092 Communication Through Removable Media · cyberstrikeus
    Adversaries can perform command and control between compromised hosts on potentially disconnected networks using removable media to transfer commands from system to system.
    0 installs
  80. T1102 002 Bidirectional Communication · cyberstrikeus
    Adversaries may use an existing, legitimate external Web service as a means for sending commands to and receiving output from a compromised system over the Web service channel.
    0 installs
  81. Publicly Accessible Content 03 01 22 Publicly Accessible Con · cyberstrikeus
    Train authorized individuals to ensure that publicly accessible information does not contain CUI.
    0 installs
  82. Session Termination 03 01 11 Session Termination · cyberstrikeus
    Session Termination
    0 installs
  83. Unsuccessful Logon Attempts 03 01 08 Unsuccessful Logon Atte · cyberstrikeus
    Enforce a limit of [organization-defined] consecutive invalid logon attempts by a user during a [organization-defined].
    0 installs
  84. Sp 800 171 03 03 09 030309 · cyberstrikeus
    03.03.09
    0 installs
  85. Sp 800 171 03 04 07 030407 · cyberstrikeus
    03.04.07
    0 installs
  86. Sp 800 171 03 04 09 030409 · cyberstrikeus
    03.04.09
    0 installs
  87. Incident Monitoring Reporting And Response Assistance 03 06 · cyberstrikeus
    Track and document system security incidents.
    0 installs
  88. Implement And Maintain Secure Environments For Software Deve · cyberstrikeus
    Ensure that all components of the environments for software development are strongly protected from internal and external threats to prevent compro...
    0 installs
  89. Ac 18 4 Restrict Configurations By Users · cyberstrikeus
    Identify and explicitly authorize users allowed to independently configure wireless networking capabilities.
    0 installs
  90. Ac 21 2 Information Search And Retrieval · cyberstrikeus
    Implement information search and retrieval services that enforce [organization-defined].
    0 installs
  91. Ac 4 3 Dynamic Information Flow Control · cyberstrikeus
    Enforce [organization-defined].
    0 installs
  92. At 2 6 Cyber Threat Environment · cyberstrikeus
    Provide literacy training on the cyber threat environment;
    0 installs
  93. Au 16 1 Identity Preservation · cyberstrikeus
    Preserve the identity of individuals in cross-organizational audit trails.
    0 installs
  94. Au 5 5 Alternate Audit Logging Capability · cyberstrikeus
    Provide an alternate audit logging capability in the event of a failure in primary audit logging capability that implements [organization-defined].
    0 installs
  95. Au 9 7 Store On Component With Different Operating System · cyberstrikeus
    Store audit information on a component running a different operating system than the system or component being audited.
    0 installs
  96. Ca 1 Policy And Procedures · cyberstrikeus
    Develop, document, and disseminate to [organization-defined]: [organization-defined] assessment, authorization, and monitoring policy that: Procedures
    0 installs
  97. Ca 7 Continuous Monitoring · cyberstrikeus
    Develop a system-level continuous monitoring strategy and implement continuous monitoring in accordance with the organization-level continuous monitor
    0 installs
  98. Ca 8 2 Red Team Exercises · cyberstrikeus
    Employ the following red-team exercises to simulate attempts by adversaries to compromise organizational systems in accordance with applicable rules o
    0 installs
  99. Cm 3 1 Automated Documentation Notification And Prohibition · cyberstrikeus
    Use [organization-defined] to: Document proposed changes to the system; Notify [organization-defined] of proposed changes to the system and request ch
    0 installs
  100. Cm 8 7 Centralized Repository · cyberstrikeus
    Provide a centralized repository for the inventory of system components.
    0 installs