Ensure centralized root access in AWS Organizations
CyberStrikeus/CyberStrike
SkillsMP has collected 7,248 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
- Latest recorded source activity
- SkillsMP catalog refreshed
- skills collected
- 7,248
- GitHub stars
- 2,879
- GitHub forks
- 449
Install with an AI assistant
Copy this prompt into the AI assistant you're using.
Follow https://skillsmp.com/skill-install/prompt.md to install Agent Skills from https://github.com/CyberStrikeus/CyberStrike.Skills in this repository
Showing 40 of 7,248 collected skills.
Ensure authorization guardrails for all AWS Organization accounts
Ensure Organizations management account is not used for workloads
Ensure Organizational Units are structured by environment and sensitivity
Ensure delegated admin manages AWS Organizations policies
Ensure delegated admins manage AWS Organizations-integrated services
Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
Ensure credentials unused for 45 days or more are disabled
Ensure access keys are rotated every 90 days or less
Ensure IAM users receive permissions only through groups
Ensure IAM policies that allow full "*:*" administrative privileges are not attached
Ensure a support role has been created to manage incidents with AWS Support
Ensure IAM instance roles are used for AWS resource access from instances
Ensure that all expired SSL/TLS certificates stored in AWS IAM are removed
Ensure that IAM External Access Analyzer is enabled for all regions
Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
Maintain current AWS account contact details
Ensure access to AWSCloudShellFullAccess is restricted
Ensure AWS resource policies do not allow unrestricted access using "Principal": "*"
Ensure security contact information is registered
Ensure no 'root' user account access key exists
Ensure MFA is enabled for the 'root' user account
Ensure hardware MFA is enabled for the 'root' user account
Eliminate use of the 'root' user for administrative and daily tasks
Ensure IAM password policy requires minimum length of 14 or greater
Ensure IAM password policy prevents password reuse
Ensure S3 Bucket Policy is set to deny HTTP requests
Ensure MFA Delete is enabled on S3 buckets
Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
Ensure that S3 is configured with 'Block Public Access' enabled
Ensure that encryption-at-rest is enabled for RDS instances
Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances
Ensure that RDS instances are not publicly accessible
Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
Ensure that encryption is enabled for EFS file systems
Ensure CloudTrail is enabled in all regions
Ensure all AWS-managed web front-end services have access logging enabled
Ensure CloudTrail log file validation is enabled
Ensure AWS Config is enabled in all regions
Ensure that server access logging is enabled on the CloudTrail S3 bucket