Ensure unused ENIs are removed
Skills in this repository
CyberStrikeus/CyberStrike - Page 180
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Ensure instances stopped for over 90 days are removed
Ensure EBS volumes attached to an EC2 instance are marked for deletion upon instance termination
Ensure Secrets and Sensitive Data are not stored directly in EC2 User Data
Ensure EC2 Auto Scaling Groups Propagate Tags to EC2 Instances that it launches
Ensure EBS volume encryption is enabled
Ensure Public Access to EBS Snapshots is Disabled
Ensure EBS volume snapshots are encrypted
Ensure unused EBS volumes are removed
Ensure Tag Policies are Enabled
Ensure an Organizational EC2 Tag Policy has been Created
Ensure no AWS EC2 Instances are Older than 180 days
Ensure detailed monitoring is enabled for production EC2 Instances
Ensure Default EC2 Security groups are not being used
Ensure the Use of IMDSv2 is Enforced on All Existing Instances
Ensure use of AWS Systems Manager to manage EC2 instances
Ensure Amazon ECS task definitions using 'host' network mode do not allow privileged or root user access to the host
Ensure Amazon ECS services are tagged
Ensure Amazon ECS clusters are tagged
Ensure Amazon ECS task definitions are tagged
Ensure only trusted images are used with Amazon ECS
Ensure 'assignPublicIp' is set to 'DISABLED' for Amazon ECS task sets
Ensure 'assignPublicIp' is set to 'DISABLED' for Amazon ECS services
Ensure Amazon ECS task definitions do not have 'pidMode' set to 'host'
Ensure Amazon ECS task definitions do not have 'privileged' set to 'true'
Ensure 'readonlyRootFilesystem' is set to 'true' for Amazon ECS task definitions
Ensure secrets are not passed as container environment variables in Amazon ECS task definitions
Ensure logging is configured for Amazon ECS task definitions
Ensure Amazon ECS Fargate services are using the latest Fargate platform version
Ensure monitoring is enabled for Amazon ECS clusters
Apply updates to any apps running in Lightsail
Enable storage bucket access logging
Ensure your Windows Server based lightsail instances are updated with the latest security patches
Change the auto-generated password for Windows based instances
Change default Administrator login names and passwords for applications
Disable SSH and RDP ports for Lightsail instances when not needed
Ensure SSH is restricted to only IP address that should have this access
Ensure RDP is restricted to only IP address that should have this access
Disable IPv6 Networking if not in use within your organization
Ensure you are using an IAM policy to manage access to buckets in Lightsail