cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ T1596 Search Open Technical Databases · cyberstrikeusAdversaries may search freely available technical databases for information about victims that can be used during targeting.
- ▌
- ▌
- ▌
- ▌ Policy And Procedures 03 15 01 Policy And Procedures · cyberstrikeusDevelop, document, and disseminate to organizational personnel or roles the policies and procedures needed to satisfy the security requirements for...
- ▌
- ▌ Ac 16 10 Attribute Configuration By Authorized Individuals · cyberstrikeusProvide authorized individuals the capability to define or change the type and value of security and privacy attributes available for association with
- ▌ Ac 17 5 Monitoring For Unauthorized Connections · cyberstrikeusMonitoring for Unauthorized Connections
- ▌ Ac 19 4 Restrictions For Classified Information · cyberstrikeusProhibit the use of unclassified mobile devices in facilities containing systems processing, storing, or transmitting classified information unless...
- ▌ Ac 21 1 Automated Decision Support · cyberstrikeusEmploy [organization-defined] to enforce information-sharing decisions by authorized users based on access authorizations of sharing partners and acce
- ▌ Ac 3 11 Restrict Access To Specific Information Types · cyberstrikeusRestrict access to data repositories containing [organization-defined].
- ▌ Ac 3 15 Discretionary And Mandatory Access Control · cyberstrikeusEnforce [organization-defined] over the set of covered subjects and objects specified in the policy;
- ▌
- ▌ Ac 4 24 Internal Normalized Format · cyberstrikeusWhen transferring information between different security domains, parse incoming data into an internal normalized format and regenerate the data to be
- ▌ Ac 6 1 Authorize Access To Security Functions · cyberstrikeusAuthorize access for [organization-defined] to: [organization-defined] ; and [organization-defined].
- ▌ Ac 6 3 Network Access To Privileged Commands · cyberstrikeusAuthorize network access to [organization-defined] only for [organization-defined] and document the rationale for such access in the security plan for
- ▌ Ac 6 4 Separate Processing Domains · cyberstrikeusProvide separate processing domains to enable finer-grained allocation of user privileges.
- ▌ Ac 7 2 Purge Or Wipe Mobile Device · cyberstrikeusPurge or wipe information from [organization-defined] based on [organization-defined] after [organization-defined] consecutive, unsuccessful device lo
- ▌ At 2 1 Practical Exercises · cyberstrikeusProvide practical exercises in literacy training that simulate events and incidents.
- ▌ At 3 3 Practical Exercises · cyberstrikeusProvide practical exercises in security and privacy training that reinforce training objectives.
- ▌ Au 10 3 Chain Of Custody · cyberstrikeusMaintain reviewer or releaser credentials within the established chain of custody for information reviewed or released.
- ▌ Au 16 3 Disassociability · cyberstrikeusImplement [organization-defined] to disassociate individuals from audit information transmitted across organizational boundaries.
- ▌ Au 6 7 Permitted Actions · cyberstrikeusSpecify the permitted actions for each [organization-defined] associated with the review, analysis, and reporting of audit record information.
- ▌
- ▌
- ▌ Cp 10 2 Transaction Recovery · cyberstrikeusImplement transaction recovery for systems that are transaction-based.
- ▌ Cp 10 6 Component Protection · cyberstrikeusProtect system components used for recovery and reconstitution.
- ▌ Cp 4 Contingency Plan Testing · cyberstrikeusTest the contingency plan for the system [organization-defined] using the following tests to determine the effectiveness of the plan and the readin...
- ▌ Ir 4 8 Correlation With External Organizations · cyberstrikeusCoordinate with [organization-defined] to correlate and share [organization-defined] to achieve a cross-organization perspective on incident awareness
- ▌ Ir 4 3 Continuity Of Operations · cyberstrikeusIdentify [organization-defined] and take the following actions in response to those incidents to ensure continuation of organizational mission and bus
- ▌ Ma 5 1 Individuals Without Appropriate Access · cyberstrikeusImplement procedures for the use of maintenance personnel that lack appropriate security clearances or are not U.S.
- ▌ Mp 6 3 Nondestructive Techniques · cyberstrikeusApply nondestructive sanitization techniques to portable storage devices prior to connecting such devices to the system under the following circumstan
- ▌ Pm 21 Accounting Of Disclosures · cyberstrikeusDevelop and maintain an accurate accounting of disclosures of personally identifiable information, including: Date, nature, and purpose of each disclo
- ▌ Ra 3 4 Predictive Cyber Analytics · cyberstrikeusEmploy the following advanced automation and analytics capabilities to predict and identify risks to [organization-defined]: [organization-defined].
- ▌ Ra 5 11 Public Disclosure Program · cyberstrikeusEstablish a public reporting channel for receiving reports of vulnerabilities in organizational systems and system components.
- ▌ Ra 5 8 Review Historic Audit Logs · cyberstrikeusReview historic audit logs to determine if a vulnerability identified in a [organization-defined] has been previously exploited within an [organizatio
- ▌ T0814 Denial Of Service · cyberstrikeusAdversaries may perform Denial-of-Service (DoS) attacks to disrupt expected device functionality.
- ▌ T0878 Alarm Suppression · cyberstrikeusAdversaries may target protection function alarms to prevent them from notifying operators of critical conditions.
- ▌ T0892 Change Credential · cyberstrikeusAdversaries may modify software and device credentials to prevent operator and responder access.
- ▌ T1398 Boot Or Logon Initialization Scripts · cyberstrikeusAdversaries may use scripts automatically executed at boot or logon initialization to establish persistence.
- ▌ T1641 001 Transmitted Data Manipulation · cyberstrikeusAdversaries may alter data en route to storage or other systems in order to manipulate external outcomes or hide activity.
- ▌ T1068 Exploitation For Privilege Escalation · cyberstrikeusAdversaries may exploit software vulnerabilities in an attempt to elevate privileges.
- ▌ T1546 015 Component Object Model Hijacking · cyberstrikeusAdversaries may establish persistence by executing malicious content triggered by hijacked references to Component Object Model (COM) objects.
- ▌ T1546 008 Accessibility Features · cyberstrikeusAdversaries may establish persistence and/or elevate privileges by executing malicious content triggered by accessibility features.
- ▌ T1027 Obfuscated Files Or Information · cyberstrikeusAdversaries may attempt to make an executable or file difficult to discover or analyze by encrypting, encoding, or otherwise obfuscating its contents on the system or in transit.
- ▌ T1036 003 Rename Legitimate Utilities · cyberstrikeusAdversaries may rename legitimate / system utilities to try to evade security mechanisms concerning the usage of those utilities.
- ▌ T1036 011 Overwrite Process Arguments · cyberstrikeusAdversaries may modify a process's in-memory arguments to change its name in order to appear as a legitimate or benign process.
- ▌ Cis Oke V150 4 1 6 · cyberstrikeusEnsure that Service Account Tokens are only mounted where necessary (Automated)
- ▌
- ▌ Cis Oke V150 4 2 2 · cyberstrikeusMinimize the admission of containers wishing to share the host process ID namespace (Automated)
- ▌ Cis Oke V150 4 2 3 · cyberstrikeusMinimize the admission of containers wishing to share the host IPC namespace (Automated)
- ▌ Cis Oke V150 4 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Automated)
- ▌ Cis Oke V150 4 2 5 · cyberstrikeusMinimize the admission of containers with allowPrivilegeEscalation (Automated)
- ▌
- ▌ Cis Oke V150 4 3 2 · cyberstrikeusEnsure that all Namespaces have Network Policies defined (Automated)
- ▌ Cis Oke V150 4 4 1 · cyberstrikeusPrefer using secrets as files over secrets as environment variables (Manual)
- ▌
- ▌ Cis Oke V150 4 5 1 · cyberstrikeusCreate administrative boundaries between resources using namespaces (Manual)
- ▌
- ▌
- ▌ Cis Oke V150 5 1 1 · cyberstrikeusEnsure Image Vulnerability Scanning using Oracle Vulnerability Scanning Service (Manual)
- ▌ Cis Oke V150 5 1 2 · cyberstrikeusMinimize user access to Oracle Cloud Infrastructure Container Registry (OCIR) (Manual)
- ▌ Cis Oke V150 5 1 3 · cyberstrikeusMinimize cluster access to read-only for Oracle Cloud Infrastructure Container Registry (OCIR) (Manual)
- ▌
- ▌ Cis Oke V150 5 2 1 · cyberstrikeusPrefer using dedicated OCI tenancies to manage OKE clusters (Manual)
- ▌
- ▌
- ▌ Cis Oke V150 5 4 2 · cyberstrikeusEnsure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
- ▌
- ▌ Cis Oke V150 5 4 4 · cyberstrikeusEnsure Network Policy is Enabled and set as appropriate (Automated)
- ▌ Cis Oke V150 5 4 5 · cyberstrikeusEncrypt traffic to HTTPS load balancers with TLS certificates (Manual)
- ▌ Cis Oke V150 5 5 1 · cyberstrikeusManage Kubernetes RBAC users with Oracle Cloud Infrastructure Identity and Access Management (IAM) (Manual)
- ▌ Cis Oke V170 2 1 1 · cyberstrikeusClient certificate authentication should not be used for users (Manual)
- ▌
- ▌ Cis Oke V170 3 1 1 · cyberstrikeusEnsure that the kubelet-config.json file permissions are set to 644 or more restrictive (Automated)
- ▌ Cis Oke V170 3 1 2 · cyberstrikeusEnsure that the kubelet-config.json file ownership is set to root:root (Automated)
- ▌ Cis Oke V170 3 1 3 · cyberstrikeusEnsure that the kubelet configuration file has permissions set to 644 or more restrictive (Automated)
- ▌ Cis Oke V170 3 1 4 · cyberstrikeusEnsure that the kubelet configuration file ownership is set to root:root (Automated)
- ▌ Cis Oke V170 3 2 1 · cyberstrikeusEnsure that the --anonymous-auth argument is set to false (Automated)
- ▌ Cis Oke V170 3 2 2 · cyberstrikeusEnsure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
- ▌ Cis Oke V170 3 2 3 · cyberstrikeusEnsure that the --client-ca-file argument is set as appropriate (Automated)
- ▌ Cis Oke V170 3 2 4 · cyberstrikeusEnsure that the --read-only-port argument is set to 0 (Automated)
- ▌ Cis Oke V170 3 2 5 · cyberstrikeusEnsure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
- ▌ Cis Oke V170 3 2 6 · cyberstrikeusEnsure that the --make-iptables-util-chains argument is set to true (Automated)
- ▌ Cis Oke V170 3 2 7 · cyberstrikeusEnsure that the --event-qps argument is set to 0 or a level which ensures appropriate event capture (Automated)
- ▌ Cis Oke V170 3 2 8 · cyberstrikeusEnsure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Automated)
- ▌ Cis Oke V170 3 2 9 · cyberstrikeusEnsure that the --rotate-certificates argument is not set to false (Automated)
- ▌ Cis Oke V170 4 1 1 · cyberstrikeusEnsure that the cluster-admin role is only used where required (Automated)
- ▌
- ▌
- ▌
- ▌ Cis Oke V170 4 1 5 · cyberstrikeusEnsure that default service accounts are not actively used (Automated)
- ▌ Cis Oke V170 4 1 6 · cyberstrikeusEnsure that Service Account Tokens are only mounted where necessary (Automated)
- ▌
- ▌ Cis Oke V170 4 2 2 · cyberstrikeusMinimize the admission of containers wishing to share the host process ID namespace (Automated)
- ▌ Cis Oke V170 4 2 3 · cyberstrikeusMinimize the admission of containers wishing to share the host IPC namespace (Automated)
- ▌ Cis Oke V170 4 2 4 · cyberstrikeusMinimize the admission of containers wishing to share the host network namespace (Automated)
- ▌ Cis Oke V170 4 2 5 · cyberstrikeusMinimize the admission of containers with allowPrivilegeEscalation (Automated)
- ▌
- ▌ Cis Oke V170 4 3 2 · cyberstrikeusEnsure that all Namespaces have Network Policies defined (Automated)