Skip to main content

Skills in this repository

CyberStrikeus/CyberStrike - Page 61

SkillsMP has collected 7,442 skills from CyberStrikeus/CyberStrike. Open a skill to review its source and details.

CyberStrikeus/CyberStrike

Showing 40 of 7,442 collected skills.

occupation
Information Security Analysts
description

Ensure that default service accounts are not actively used (Manual)

updated
occupation
Information Security Analysts
description

Ensure that Service Account Tokens are only mounted where necessary (Manual)

updated
occupation
Information Security Analysts
description

Avoid use of system:masters group (Manual)

updated
occupation
Information Security Analysts
description

Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)

updated
occupation
Information Security Analysts
description

Minimize access to create persistent volumes (Manual)

updated
occupation
Information Security Analysts
description

Ensure that the cluster has at least one active policy control mechanism in place (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of containers with capabilities assigned (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of Windows HostProcess Containers (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of HostPath volumes (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of containers which use HostPorts (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of privileged containers (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of containers wishing to share the host process ID namespace (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of containers wishing to share the host IPC namespace (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of containers wishing to share the host network namespace (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of containers with allowPrivilegeEscalation (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of root containers (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of containers with the NET_RAW capability (Manual)

updated
occupation
Information Security Analysts
description

Minimize the admission of containers with added capabilities (Manual)

updated
occupation
Information Security Analysts
description

Ensure that the CNI in use supports Network Policies (Manual)

updated
occupation
Information Security Analysts
description

Ensure that all Namespaces have Network Policies defined (Manual)

updated
occupation
Information Security Analysts
description

Prefer using secrets as files over secrets as environment variables (Manual)

updated
occupation
Information Security Analysts
description

Consider external secret storage (Manual)

updated
occupation
Information Security Analysts
description

Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)

updated
occupation
Information Security Analysts
description

Create administrative boundaries between resources using namespaces (Manual)

updated
occupation
Information Security Analysts
description

Ensure that the seccomp profile is set to docker/default in your pod definitions (Manual)

updated
occupation
Information Security Analysts
description

Apply Security Context to Your Pods and Containers (Manual)

updated
occupation
Information Security Analysts
description

The default namespace should not be used (Manual)

updated
occupation
Information Security Analysts
description

Ensure that the API server pod specification file permissions are set to 600 or more restrictive (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the Container Network Interface file ownership is set to root:root (Manual)

updated
occupation
Information Security Analysts
description

Ensure that the etcd data directory permissions are set to 700 or more restrictive (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the etcd data directory ownership is set to etcd:etcd (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the default administrative credential file permissions are set to 600 (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the default administrative credential file ownership is set to root:root (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the scheduler.conf file ownership is set to root:root (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the controller-manager.conf file permissions are set to 600 or more restrictive (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the controller-manager.conf file ownership is set to root:root (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the Kubernetes PKI directory and file ownership is set to root:root (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the API server pod specification file ownership is set to root:root (Automated)

updated
occupation
Information Security Analysts
description

Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual)

updated
Showing 40 of 7,442 collected skills.