Lock the BIND User Account (Automated)
Skills in this repository
CyberStrikeus/CyberStrike - Page 36
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Set root Ownership of BIND Directories (Automated)
Set root Ownership of BIND Configuration Files (Automated)
Set Group named or root for BIND Directories and Files (Automated)
Set Group Read-Only for BIND Files and Non-Runtime Directories (Automated)
Set Other Permissions Read-Only for All BIND Directories and Files (Automated)
Isolate BIND with chroot'ed Subdirectory (Automated)
Ignore Erroneous or Unwanted Queries (Automated)
Restrict Recursive Queries (Automated)
Restrict Query Origins (Manual)
Restrict Queries of the Cache (Automated)
Use TSIG Keys 256 Bits in Length (Automated)
Include Cryptographic Key Files (Automated)
Use Unique Keys for Each Pair of Hosts (Automated)
Restrict Access to All Key Files (Automated)
Protect TSIG Key Files During Deployment (Manual)
Securely Authenticate Zone Transfers (Automated)
Securely Authenticate Dynamic Updates (Automated)
Securely Authenticate Update Forwarding (Automated)
Hide BIND Version String (Automated)
Hide Nameserver ID (Automated)
Do Not Define a Static Source Port (Automated)
Enable DNSSEC Validation (Automated)
Disable the dnssec-accept-expired Option (Automated)
Ensure Either SPF or DKIM DNS Records are Configured (Automated)
Install the Haveged Package for Enhanced Entropy (Automated)
Ensure Signing Keys are Generated with a Secure Algorithm (Automated)
Ensure Any Signing Keys using RSA Have a Length of 2048 or Greater (Automated)
Restrict Access to Zone and Key Signing Keys (Automated)
Ensure each Zone has a Valid Digital Signature (Manual)
Ensure Full Digital Chain of Trust can be Validated (Automated)
Ensure Signing Keys are Unique (Automated)
Ensure Zones are Signed with NSEC or NSEC3 (Automated)
Apply Applicable Updates (Automated)
Configure a Logging File Channel (Automated)
Configure a Logging Syslog Channel (Automated)
Disable the HTTP Statistics Server (Automated)
Response Rate Limiting and DDOS Mitigation (Automated)
Ensure Signing Keys are Scheduled to be Replaced Periodically (Automated)
Use a Split-Horizon Architecture (Manual)