Implement the following host-based monitoring mechanisms at [organization-defined]: [organization-defined].
Skills in this repository
CyberStrikeus/CyberStrike - Page 143
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Discover, collect, and distribute to [organization-defined] , indicators of compromise provided by [organization-defined].
Provide visibility into network traffic at external and key internal system interfaces to optimize the effectiveness of monitoring devices.
Employ automated tools and mechanisms to integrate intrusion detection tools and mechanisms into access control and flow control mechanisms.
Determine criteria for unusual or unauthorized activities or conditions for inbound and outbound communications traffic;
Alert [organization-defined] when the following system-generated indications of compromise or potential compromise occur: [organization-defined].
Restrict Non-privileged Users
Notify [organization-defined] of detected suspicious events;
Protection of Monitoring Information
Test intrusion-monitoring tools and mechanisms [organization-defined].
Monitor the system to detect: Attacks and indicators of potential attacks in accordance with the following monitoring objectives: [organization-define
Broadcast security alert and advisory information throughout the organization using [organization-defined].
Receive system security alerts, advisories, and directives from [organization-defined] on an ongoing basis;
Notification of Failed Security Tests
Implement automated mechanisms to support the management of distributed security and privacy function testing.
Report the results of security and privacy function verification to [organization-defined].
Verify the correct operation of [organization-defined];
Perform an integrity check of [organization-defined] [organization-defined].
Implement the following mechanisms to protect the integrity of boot firmware in [organization-defined]: [organization-defined].
Confined Environments with Limited Privileges
Require that the integrity of the following user-installed software be verified prior to execution: [organization-defined].
Code Execution in Protected Environments
Binary or Machine Executable Code
Implement cryptographic mechanisms to authenticate the following software or firmware components prior to installation: [organization-defined].
Prohibit processes from executing without supervision for more than [organization-defined].
Implement [organization-defined] for application self-protection at runtime.
Employ automated tools that provide notification to [organization-defined] upon discovering discrepancies during integrity verification.
Employ centrally managed integrity verification tools.
Tamper-evident Packaging
Automatically [organization-defined] when integrity violations are discovered.
Implement cryptographic mechanisms to detect unauthorized changes to software, firmware, and information.
Incorporate the detection of the following unauthorized changes into the organizational incident response capability: [organization-defined].
Upon detection of a potential integrity violation, provide the capability to audit the event and initiate the following actions: [organization-defined
Verify the integrity of the boot process of the following system components: [organization-defined].
Employ integrity verification tools to detect unauthorized changes to the following software, firmware, and information: [organization-defined] ;
Central Management
Automatically update spam protection mechanisms [organization-defined].
Implement spam protection mechanisms with a learning capability to more effectively identify legitimate communications traffic.
Employ spam protection mechanisms at system entry and exit points to detect and act on unsolicited messages;
Information Input Restrictions