Ensure management console sign-in without MFA is monitored
Skills in this repository
CyberStrikeus/CyberStrike - Page 179
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Ensure usage of the 'root' account is monitored
Ensure IAM policy changes are monitored
Ensure CloudTrail configuration changes are monitored
Ensure AWS Management Console authentication failures are monitored
Ensure disabling or scheduled deletion of customer created CMKs is monitored
Ensure S3 bucket policy changes are monitored
Ensure AWS Config configuration changes are monitored
Ensure EBS volume encryption is enabled in all regions
Ensure CIFS access is restricted to trusted networks to prevent unauthorized access
Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
Ensure no security groups allow ingress from ::/0 to remote server administration ports
Ensure the default security group of every VPC restricts all traffic
Ensure routing tables for VPC peering are least access
Ensure that the EC2 Metadata Service only allows IMDSv2
Ensure VPC Endpoints are used for access to AWS Services
Ensure Managed Platform updates is configured
Ensure Persistent logs is setup and configured to S3
Ensure access logs are enabled
Ensure that HTTPS is enabled on load balancer
Ensure customer-managed keys are used to encrypt AWS Fargate ephemeral storage data for Amazon ECS
Ensure AWS Config is Enabled for Lambda and Serverless
Ensure Lambda functions do not allow unknown cross account access via permission policies
Ensure that the runtime environment versions used for your Lambda functions do not have end of support dates
Ensure encryption in transit is enabled for Lambda environment variables
Ensure Cloudwatch Lambda insights is enabled
Ensure AWS Secrets manager is configured and being used by Lambda for databases
Ensure least privilege is used with Lambda function access
Ensure every Lambda function has its own IAM Role
Ensure Lambda functions are not exposed to everyone
Ensure Lambda functions are referencing active execution roles
Ensure that Code Signing is enabled for Lambda functions
Ensure there are no Lambda functions with admin privileges within your AWS account
Ensure communications between your applications and clients is encrypted
Ensure Consistent Naming Convention is used for Organizational AMI
Ensure Amazon Machine Images (AMIs) are encrypted
Ensure Only Approved Amazon Machine Images (AMIs) are Used
Ensure Images (AMI) are not older than 90 days
Ensure Images are not Publicly Available