Ensure Only Necessary Authentication and Authorization Modules Are Enabled
Skills in this repository
CyberStrikeus/CyberStrike - Page 177
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Ensure the Log Config Module Is Enabled
Ensure the WebDAV Modules Are Disabled
Ensure the Status Module Is Disabled
Ensure the Autoindex Module Is Disabled
Ensure the Proxy Modules Are Disabled
Ensure the User Directories Module Is Disabled
Ensure the Info Module Is Disabled
Ensure the Basic and Digest Authentication Modules are Disabled
Ensure Access to .ht* Files Is Restricted
Ensure Default HTML Content Is Removed
Ensure Applicable Patches Are Applied
Ensure ModSecurity Is Installed and Enabled
Ensure the OWASP ModSecurity Core Rule Set Is Installed and Enabled
Ensure mod_ssl and/or mod_nss Is Installed
Ensure Only Cipher Suites That Provide Forward Secrecy Are Enabled
Ensure a Valid Trusted Certificate Is Installed
Ensure the Server's Private Key Is Protected
Ensure Weak SSL Protocols Are Disabled
Ensure Weak SSL/TLS Ciphers Are Disabled
Ensure Insecure SSL Renegotiation Is Not Enabled
Ensure the TimeOut Is Set Properly
Ensure KeepAlive Is Enabled
Ensure MaxKeepAliveRequests Is Set Properly
Ensure the KeepAliveTimeout Is Set Properly
Ensure the Timeout Limits for Request Headers is Set to 40 or Less
Ensure Timeout Limits for the Request Body Are Set Properly
Ensure centralized root access in AWS Organizations
Ensure authorization guardrails for all AWS Organization accounts
Ensure Organizations management account is not used for workloads
Ensure Organizational Units are structured by environment and sensitivity
Ensure delegated admin manages AWS Organizations policies
Ensure delegated admins manage AWS Organizations-integrated services
Ensure multi-factor authentication (MFA) is enabled for all IAM users that have a console password
Ensure credentials unused for 45 days or more are disabled
Ensure access keys are rotated every 90 days or less
Ensure IAM users receive permissions only through groups
Ensure IAM policies that allow full "*:*" administrative privileges are not attached
Ensure a support role has been created to manage incidents with AWS Support
Ensure IAM instance roles are used for AWS resource access from instances