Ensure Image Vulnerability Scanning is enabled (Automated)
Skills in this repository
CyberStrikeus/CyberStrike - Page 51
SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.
CyberStrikeus/CyberStrikeShowing 40 of 7,442 collected skills.
Minimize user access to Container Image repositories (Manual)
Minimize cluster access to read-only for Container Image repositories (Manual)
Ensure only trusted container images are used (Automated)
Ensure GKE clusters are not running using the Compute Engine default service account (Automated)
Ensure Kubernetes Secrets are encrypted using keys managed in Cloud KMS (Automated)
Enable VPC Flow Logs and Intranode Visibility (Automated)
Ensure Control Plane Authorized Networks is Enabled (Manual)
Ensure clusters are created with Private Endpoint Enabled and Public Access Disabled (Automated)
Ensure clusters are created with Private Nodes (Automated)
Ensure use of Google-managed SSL Certificates (Automated)
Manage Kubernetes RBAC users with Google Groups for GKE (Manual)
Enable Customer-Managed Encryption Keys (CMEK) for GKE Persistent Disks (PD) (Manual)
Enable Security Posture (Automated)
Ensure that the proxy kubeconfig file permissions are set to 644 or more restrictive (Automated)
Ensure that the proxy kubeconfig file ownership is set to root:root (Automated)
Ensure that the kubelet configuration file has permissions set to 644 (Automated)
Ensure that the kubelet configuration file ownership is set to root:root (Automated)
Ensure that the Anonymous Auth is Not Enabled Draft (Automated)
Ensure that the --authorization-mode argument is not set to AlwaysAllow (Automated)
Ensure that a Client CA File is Configured (Automated)
Ensure that the --read-only-port is disabled (Automated)
Ensure that the --streaming-connection-idle-timeout argument is not set to 0 (Automated)
Ensure that the --make-iptables-util-chains argument is set to true (Automated)
Ensure that the --eventRecordQPS argument is set to 0 or a level which ensures appropriate event capture (Automated)
Ensure that the --rotate-certificates argument is not present or is set to true (Automated)
Ensure that the RotateKubeletServerCertificate argument is set to true (Automated)
Ensure that the cluster-admin role is only used where required (Automated)
Avoid non-default bindings to system:authenticated (Automated)
Minimize access to secrets (Automated)
Minimize wildcard use in Roles and ClusterRoles (Automated)
Ensure that default service accounts are not actively used (Automated)
Ensure that Service Account Tokens are only mounted where necessary (Automated)
Avoid use of system:masters group (Automated)
Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)
Avoid bindings to system:anonymous (Automated)
Avoid non-default bindings to system:unauthenticated (Automated)
Ensure that the cluster enforces Pod Security Standard Baseline profile or stricter for all namespaces (Manual)
Ensure that the CNI in use supports Network Policies (Manual)
Ensure that all Namespaces have Network Policies defined (Automated)