ワンクリックで
ra-5-9-penetration-testing-and-analyses
Penetration Testing and Analyses
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
メニュー
Penetration Testing and Analyses
Codex または Claude でインストール この Prompt をコピーして Codex、Claude、または他のアシスタントに貼り付けると、Skill ページを確認してインストールできます。
SOC 職業分類に基づく
eBPF-based post-exploitation for kernel-level credential harvesting, process hiding, and traffic interception on Linux
AWS post-exploitation for IAM privilege escalation, data exfiltration, persistence, and operational security via boto3
Azure/Entra ID post-exploitation for tenant compromise, Key Vault extraction, managed identity abuse, and token manipulation
CI/CD pipeline attacks for secret extraction, pipeline injection, and supply chain compromise via GitHub/Jenkins/GitLab
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
| name | RA-5(9)_penetration-testing-and-analyses |
| description | Penetration Testing and Analyses |
| category | information-gathering |
| version | 5.2.0 |
| author | cyberstrike-official |
| tags | ["nist","sp800-53","rev5","ra-5-9","ra","enhancement"] |
| tech_stack | ["any"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | ["RA-5"] |
| severity_boost | {} |
Enhancement of: RA-5
Family: Risk Assessment (RA) Framework: NIST SP 800-53 Rev 5
No description available.
Examine the System Security Plan (SSP) and related artifacts for RA-5(9) implementation details. Verify the organization has documented how this control is satisfied.
# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly
# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null
Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.
| Tool | Purpose | Usage |
|---|---|---|
| Manual Review | Documentation and interview-based | N/A |
Refer to NIST SP 800-53 Rev 5 for the full control statement.
Implement this control per organizational risk assessment and system categorization.
| Finding | Severity | Impact |
|---|---|---|
| RA-5(9) Penetration Testing and Analyses not implemented | Medium | Risk Assessment |
| RA-5(9) partially implemented | Low | Incomplete Risk Assessment |
| CWE ID | Title |
|---|---|
| N/A | No direct CWE mapping |