Ensure that all expired SSL/TLS certificates stored in AWS IAM are removed
Skills in this repository
CyberStrikeus/CyberStrike - Page 178
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Ensure that IAM External Access Analyzer is enabled for all regions
Ensure IAM users are managed centrally via identity federation or AWS Organizations for multi-account environments
Maintain current AWS account contact details
Ensure access to AWSCloudShellFullAccess is restricted
Ensure AWS resource policies do not allow unrestricted access using "Principal": "*"
Ensure security contact information is registered
Ensure no 'root' user account access key exists
Ensure MFA is enabled for the 'root' user account
Ensure hardware MFA is enabled for the 'root' user account
Eliminate use of the 'root' user for administrative and daily tasks
Ensure IAM password policy requires minimum length of 14 or greater
Ensure IAM password policy prevents password reuse
Ensure S3 Bucket Policy is set to deny HTTP requests
Ensure MFA Delete is enabled on S3 buckets
Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary
Ensure that S3 is configured with 'Block Public Access' enabled
Ensure that encryption-at-rest is enabled for RDS instances
Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances
Ensure that RDS instances are not publicly accessible
Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS
Ensure that encryption is enabled for EFS file systems
Ensure CloudTrail is enabled in all regions
Ensure all AWS-managed web front-end services have access logging enabled
Ensure CloudTrail log file validation is enabled
Ensure AWS Config is enabled in all regions
Ensure that server access logging is enabled on the CloudTrail S3 bucket
Ensure CloudTrail logs are encrypted at rest using KMS CMKs
Ensure rotation for customer-created symmetric CMKs is enabled
Ensure VPC flow logging is enabled in all VPCs
Ensure that object-level logging for write events is enabled for S3 buckets
Ensure that object-level logging for read events is enabled for S3 buckets
Ensure unauthorized API calls are monitored
Ensure security group changes are monitored
Ensure Network Access Control List (NACL) changes are monitored
Ensure changes to network gateways are monitored
Ensure route table changes are monitored
Ensure VPC changes are monitored
Ensure AWS Organizations changes are monitored
Ensure AWS Security Hub is enabled