cyberstrikeus
- 7.2k skills
- 0 followers
- 1 day ago last updated
- ▌ Cis Azure Foundations 8 3 8 · cyberstrikeusEnsure Automatic Key Rotation is Enabled Within Azure Key Vault for the Supported Services
- ▌ Cis Azure Foundations 8 3 9 · cyberstrikeusEnsure Azure Key Vault Managed HSM is Used for Key Encryption
- ▌
- ▌
- ▌ Cis Azure Foundations 9 1 2 · cyberstrikeusEnsure 'SMB protocol version' is set to 'SMB 3.1.1' or higher for SMB file shares
- ▌ Cis Azure Foundations 9 1 3 · cyberstrikeusEnsure 'SMB channel encryption' is set to 'AES-256-GCM' or higher for SMB file shares
- ▌ Cis Azure Foundations 9 2 1 · cyberstrikeusEnsure soft delete for blobs on Azure Blob Storage storage accounts is Enabled
- ▌ Cis Azure Foundations 9 2 2 · cyberstrikeusEnsure soft delete for containers on Azure Blob Storage storage accounts is Enabled
- ▌ Cis Azure Foundations 9 2 3 · cyberstrikeusEnsure 'Versioning' is set to 'Enabled' on Azure Blob Storage storage accounts
- ▌
- ▌ Cis Azure Foundations 9 3 5 · cyberstrikeusEnsure 'Allow Azure services on the trusted services list to access this storage account' is Enabled for Storage Account Access
- ▌ Cis Azure Foundations 9 3 6 · cyberstrikeusEnsure the 'Minimum TLS version' for storage accounts is set to 'Version 1.2'
- ▌
- ▌ Cis Azure Foundations 9 3 8 · cyberstrikeusEnsure 'Allow Blob Anonymous Access' is set to 'Disabled'
- ▌ Cis Azure Foundations 9 3 9 · cyberstrikeusEnsure Azure Resource Manager Delete locks are applied to Azure Storage Accounts
- ▌ Cis Azure Storage 10 1 · cyberstrikeusEnsure 'Encryption key source' is set to 'Customer Managed Key' for Azure NetApp Files accounts
- ▌ Cis Azure Storage 11 1 · cyberstrikeusEnsure 'Allowed Protocols' for shared access signature (SAS) tokens is set to 'HTTPS Only'
- ▌ Cis Azure Storage 11 2 · cyberstrikeusEnsure that shared access signature (SAS) tokens expire within an hour
- ▌ Cis Azure Storage 11 3 · cyberstrikeusEnsure that soft delete for blobs on Azure Blob Storage storage accounts is Enabled
- ▌ Cis Azure Storage 11 4 · cyberstrikeusEnsure stored access policies (SAP) are used when generating shared access signature (SAS) tokens
- ▌ Cis Azure Storage 11 5 · cyberstrikeusEnsure 'Versioning' is set to 'Enabled' on Azure Blob Storage storage accounts
- ▌ Cis Azure Storage 11 6 · cyberstrikeusEnsure locked immutability policies are used for containers storing business-critical blob data
- ▌ Cis Azure Storage 12 1 · cyberstrikeusEnsure double encryption is used for Azure Data Box in high-security environments
- ▌ Cis Azure Storage 15 1 · cyberstrikeusEnsure 'Public network access' is set to 'Disabled' on Azure Elastic SAN
- ▌ Cis Azure Storage 15 2 · cyberstrikeusEnsure customer-managed keys (CMK) are used to encrypt data at rest on Azure Elastic SAN volume groups
- ▌ Cis Azure Storage 16 1 · cyberstrikeusEnsure 'Allowed Protocols' for shared access signature (SAS) tokens is set to 'HTTPS Only'
- ▌ Cis Azure Storage 16 2 · cyberstrikeusEnsure that shared access signature (SAS) tokens expire within an hour
- ▌ Cis Azure Storage 16 3 · cyberstrikeusEnsure stored access policies (SAP) are used when generating shared access signature (SAS) tokens
- ▌
- ▌ Cis Azure Storage 17 5 · cyberstrikeusEnsure that 'Enable Infrastructure Encryption' for Each Storage Account in Azure Storage is Set to 'enabled'
- ▌ Cis Azure Storage 17 6 · cyberstrikeusEnsure 'Allow Azure services on the trusted services list to access this storage account' is Enabled for Storage Account Access
- ▌ Cis Azure Storage 17 7 · cyberstrikeusEnsure Soft Delete is Enabled for Azure Containers and Blob Storage
- ▌ Cis Azure Storage 17 8 · cyberstrikeusEnsure Storage Logging is Enabled for Queue Service for 'Read', 'Write', and 'Delete' requests
- ▌ Cis Azure Storage 17 9 · cyberstrikeusEnsure Storage logging is Enabled for Blob Service for 'Read', 'Write', and 'Delete' requests
- ▌ Cis Azure Storage 18 1 · cyberstrikeusEnsure that shared access signature (SAS) tokens expire within an hour
- ▌ Cis Azure Storage 18 2 · cyberstrikeusEnsure stored access policies (SAP) are used when generating shared access signature (SAS) tokens
- ▌
- ▌ Cis Ubuntu 14 04 Lts 1 1 10 Ensure Separate Partition Exists · cyberstrikeusEnsure a separate partition exists for /var/log to protect log data
- ▌ Cis Ubuntu 14 04 Lts 1 1 11 Ensure Separate Partition Exists · cyberstrikeusEnsure a separate partition exists for /var/log/audit to protect audit data
- ▌ Cis Ubuntu 14 04 Lts 1 1 12 Ensure Separate Partition Exists · cyberstrikeusEnsure a separate partition exists for /home to protect user data
- ▌ Cis Ubuntu 14 04 Lts 1 1 13 Ensure Nodev Option Set On Home · cyberstrikeusEnsure nodev option is set on /home partition to prevent special device access
- ▌ Cis Ubuntu 14 04 Lts 1 1 14 Ensure Nodev Option Set On Run S · cyberstrikeusEnsure nodev option is set on /run/shm partition to prevent special device access
- ▌ Cis Ubuntu 14 04 Lts 1 1 15 Ensure Nosuid Option Set On Run · cyberstrikeusEnsure nosuid option is set on /run/shm partition to prevent privileged programs
- ▌ Cis Ubuntu 14 04 Lts 1 1 16 Ensure Noexec Option Set On Run · cyberstrikeusEnsure noexec option is set on /run/shm partition to prevent executable binaries
- ▌ Cis Ubuntu 14 04 Lts 1 1 17 Ensure Nodev Option Set On Remov · cyberstrikeusEnsure nodev option is set on removable media partitions to prevent special device access
- ▌ Cis Ubuntu 14 04 Lts 1 1 18 Ensure Nosuid Option Set On Remo · cyberstrikeusEnsure nosuid option is set on removable media partitions to prevent privileged programs
- ▌ Cis Ubuntu 14 04 Lts 1 1 19 Ensure Noexec Option Set On Remo · cyberstrikeusEnsure noexec option is set on removable media partitions to prevent executable binaries
- ▌ Cis Ubuntu 14 04 Lts 1 1 20 Ensure Sticky Bit Is Set On All · cyberstrikeusEnsure sticky bit is set on all world-writable directories to prevent unauthorized file deletion
- ▌ Cis Ubuntu 14 04 Lts 1 1 21 Disable Automounting · cyberstrikeusDisable autofs to prevent automatic mounting of removable media devices
- ▌ Cis Ubuntu 14 04 Lts 2 1 10 Ensure Xinetd Is Not Enabled · cyberstrikeusVerify that the xinetd super daemon is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 1 11 Ensure Openbsd Inetd Is Not Inst · cyberstrikeusVerify that openbsd-inetd package is not installed on the system
- ▌ Cis Ubuntu 14 04 Lts 2 2 10 Ensure HTTP Server Is Not Enable · cyberstrikeusVerify that Apache HTTP server is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 11 Ensure Imap And Pop3 Server Is N · cyberstrikeusVerify that dovecot IMAP/POP3 server is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 12 Ensure Samba Is Not Enabled · cyberstrikeusVerify that Samba SMB file sharing service is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 13 Ensure HTTP Proxy Server Is Not · cyberstrikeusVerify that Squid HTTP proxy server is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 14 Ensure Snmp Server Is Not Enable · cyberstrikeusVerify that SNMP server is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 15 Ensure Mail Transfer Agent Is Co · cyberstrikeusVerify that MTA is configured to only listen on loopback address
- ▌ Cis Ubuntu 14 04 Lts 2 2 16 Ensure Rsync Service Is Not Enab · cyberstrikeusVerify that rsync service is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 2 2 17 Ensure Nis Server Is Not Enabled · cyberstrikeusVerify that NIS (ypserv) server is disabled when not required
- ▌ Cis Ubuntu 14 04 Lts 4 1 10 Ensure Discretionary Access Cont · cyberstrikeusCollect audit events for file permission, ownership, and attribute changes
- ▌ Cis Ubuntu 14 04 Lts 4 1 11 Ensure Unsuccessful Unauthorized · cyberstrikeusCollect audit events for failed file access attempts indicating unauthorized access
- ▌ Cis Ubuntu 14 04 Lts 4 1 12 Ensure Use Of Privileged Command · cyberstrikeusCollect audit events for execution of setuid and setgid privileged programs
- ▌ Cis Ubuntu 14 04 Lts 4 1 13 Ensure Successful File System Mo · cyberstrikeusCollect audit events for mount system calls to detect media export activity
- ▌ Cis Ubuntu 14 04 Lts 4 1 14 Ensure File Deletion Events By U · cyberstrikeusCollect audit events for file deletion system calls to detect unauthorized removal
- ▌ Cis Ubuntu 14 04 Lts 4 1 15 Ensure Changes To System Adminis · cyberstrikeusCollect audit events for modifications to sudoers configuration files
- ▌ Cis Ubuntu 14 04 Lts 4 1 16 Ensure System Administrator Acti · cyberstrikeusCollect audit events for sudo command execution via the sudo log file
- ▌ Cis Ubuntu 14 04 Lts 4 1 17 Ensure Kernel Module Loading And · cyberstrikeusCollect audit events for kernel module loading and unloading operations
- ▌ Cis Ubuntu 14 04 Lts 4 1 18 Ensure The Audit Configuration I · cyberstrikeusSet audit configuration to immutable mode requiring reboot for changes
- ▌ Cis Ubuntu 14 04 Lts 5 2 10 Ensure Ssh Permituserenvironment · cyberstrikeusVerify SSH PermitUserEnvironment is set to no to prevent users from setting environment options
- ▌ Cis Ubuntu 14 04 Lts 5 2 11 Ensure Only Approved Mac Algorit · cyberstrikeusVerify SSH is configured to use only approved MAC algorithms to prevent weak cipher attacks
- ▌ Cis Ubuntu 14 04 Lts 5 2 12 Ensure Ssh Idle Timeout Interval · cyberstrikeusVerify SSH ClientAliveInterval and ClientAliveCountMax are configured for idle session timeout
- ▌ Cis Ubuntu 14 04 Lts 5 2 13 Ensure Ssh Logingracetime Is Set · cyberstrikeusVerify SSH LoginGraceTime is set to 60 seconds or less to limit unauthenticated connections
- ▌ Cis Ubuntu 14 04 Lts 5 2 14 Ensure Ssh Access Is Limited · cyberstrikeusVerify SSH access is limited using AllowUsers, AllowGroups, DenyUsers, or DenyGroups directives
- ▌ Cis Ubuntu 14 04 Lts 5 2 15 Ensure Ssh Warning Banner Is Con · cyberstrikeusVerify SSH Banner is configured to display a warning message before authentication
- ▌ Cis Ubuntu 14 04 Lts 6 1 10 Ensure No World Writable Files E · cyberstrikeusFind and remediate world writable files across all local filesystems
- ▌ Cis Ubuntu 14 04 Lts 6 1 11 Ensure No Unowned Files Or Direc · cyberstrikeusFind and remediate files and directories without a valid owner
- ▌ Cis Ubuntu 14 04 Lts 6 1 12 Ensure No Ungrouped Files Or Dir · cyberstrikeusFind and remediate files and directories without a valid group owner
- ▌ Cis Ubuntu 14 04 Lts 6 1 13 Audit Suid Executables · cyberstrikeusIdentify and review all SUID executables to ensure they are legitimate
- ▌ Cis Ubuntu 14 04 Lts 6 1 14 Audit Sgid Executables · cyberstrikeusIdentify and review all SGID executables to ensure they are legitimate
- ▌ Cis Ubuntu 14 04 Lts 6 2 10 Ensure Users Dot Files Are Not G · cyberstrikeusVerify user dot files do not have group or world write permissions
- ▌ Cis Ubuntu 14 04 Lts 6 2 11 Ensure No Users Have Forward Fil · cyberstrikeusVerify no users have .forward files in their home directories
- ▌ Cis Ubuntu 14 04 Lts 6 2 12 Ensure No Users Have Netrc Files · cyberstrikeusVerify no users have .netrc files in their home directories
- ▌ Cis Ubuntu 14 04 Lts 6 2 13 Ensure Users Netrc Files Are Not · cyberstrikeusVerify .netrc files are not accessible by group or world
- ▌ Cis Ubuntu 14 04 Lts 6 2 14 Ensure No Users Have Rhosts File · cyberstrikeusVerify no users have .rhosts files in their home directories
- ▌ Cis Ubuntu 14 04 Lts 6 2 15 Ensure All Groups In Etc Passwd · cyberstrikeusVerify all groups referenced in /etc/passwd exist in /etc/group
- ▌ Cis Ubuntu 14 04 Lts 6 2 16 Ensure No Duplicate Uids Exist · cyberstrikeusVerify no duplicate User IDs exist in /etc/passwd
- ▌ Cis Ubuntu 14 04 Lts 6 2 17 Ensure No Duplicate Gids Exist · cyberstrikeusVerify no duplicate Group IDs exist in /etc/group
- ▌ Cis Ubuntu 14 04 Lts 6 2 18 Ensure No Duplicate User Names E · cyberstrikeusVerify no duplicate user names exist in /etc/passwd
- ▌ Cis Ubuntu 14 04 Lts 6 2 19 Ensure No Duplicate Group Names · cyberstrikeusVerify no duplicate group names exist in /etc/group
- ▌ Cis Ubuntu 14 04 Lts 6 2 20 Ensure Shadow Group Is Empty · cyberstrikeusVerify the shadow group has no users assigned to it
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌
- ▌