Ensure CloudTrail logs are encrypted at rest using KMS CMKs
Skills in this repository
CyberStrikeus/CyberStrike - Page 2
SkillsMP has collected 7,248 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,248 collected skills.
Ensure rotation for customer-created symmetric CMKs is enabled
Ensure VPC flow logging is enabled in all VPCs
Ensure that object-level logging for write events is enabled for S3 buckets
Ensure that object-level logging for read events is enabled for S3 buckets
Ensure unauthorized API calls are monitored
Ensure security group changes are monitored
Ensure Network Access Control List (NACL) changes are monitored
Ensure changes to network gateways are monitored
Ensure route table changes are monitored
Ensure VPC changes are monitored
Ensure AWS Organizations changes are monitored
Ensure AWS Security Hub is enabled
Ensure management console sign-in without MFA is monitored
Ensure usage of the 'root' account is monitored
Ensure IAM policy changes are monitored
Ensure CloudTrail configuration changes are monitored
Ensure AWS Management Console authentication failures are monitored
Ensure disabling or scheduled deletion of customer created CMKs is monitored
Ensure S3 bucket policy changes are monitored
Ensure AWS Config configuration changes are monitored
Ensure EBS volume encryption is enabled in all regions
Ensure CIFS access is restricted to trusted networks to prevent unauthorized access
Ensure no Network ACLs allow ingress from 0.0.0.0/0 to remote server administration ports
Ensure no security groups allow ingress from 0.0.0.0/0 to remote server administration ports
Ensure no security groups allow ingress from ::/0 to remote server administration ports
Ensure the default security group of every VPC restricts all traffic
Ensure routing tables for VPC peering are least access
Ensure that the EC2 Metadata Service only allows IMDSv2
Ensure VPC Endpoints are used for access to AWS Services
Ensure Managed Platform updates is configured
Ensure Persistent logs is setup and configured to S3
Ensure access logs are enabled
Ensure that HTTPS is enabled on load balancer
Ensure customer-managed keys are used to encrypt AWS Fargate ephemeral storage data for Amazon ECS
Ensure AWS Config is Enabled for Lambda and Serverless
Ensure Lambda functions do not allow unknown cross account access via permission policies
Ensure that the runtime environment versions used for your Lambda functions do not have end of support dates
Ensure encryption in transit is enabled for Lambda environment variables
Ensure Cloudwatch Lambda insights is enabled