소스 정보
- 저장소
- CyberStrikeus/CyberStrike
- 최근 소스 활동
- 2026년 4월 13일 11:05
- 감지된 SKILL.md 언어
- 영어
- 스타
- 1,653
- 포크
- 254
설치 방법
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
소스 파일 검토
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
메뉴
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-azure-foundations-8-3-5명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
SOC 직업 분류 기준
SKILL.md 표시 중
| name | cis-azure-foundations-8.3.5 |
| description | Ensure the Key Vault is Recoverable |
| category | cis-azure-foundations |
| version | 5.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","security","key-vault","soft-delete","purge-protection"] |
| cis_id | 8.3.5 |
| cis_benchmark | CIS Microsoft Azure Foundations Benchmark v5.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Ensure that Azure Key Vaults are configured with both soft delete and purge protection enabled, making the Key Vault and its objects recoverable in the event of accidental or malicious deletion.
Azure Key Vault stores critical cryptographic keys, secrets, and certificates. Accidental or malicious deletion of a Key Vault or its contents can have catastrophic consequences, including data loss and service outages. Soft delete enables recovery of deleted vaults and vault objects for a configurable retention period (default 90 days). Purge protection prevents permanent deletion during the retention period, even by administrators. Together, these features provide a safety net against both accidental and malicious destruction of key material.
Enabling soft delete and purge protection means that deleted Key Vaults and their objects cannot be permanently removed until the retention period expires. This may impact organizations that need to rapidly reclaim Key Vault names or immediately remove sensitive data. The retention period is configurable between 7 and 90 days. Note that soft delete is now enforced by Azure for all new Key Vaults and cannot be disabled.
From Azure Portal:
Key vaults.Settings, click Properties.Soft delete is shown as enabled.Purge protection is shown as enabled.From Azure CLI:
az keyvault list --query "[].{Name:name, SoftDelete:properties.enableSoftDelete, PurgeProtection:properties.enablePurgeProtection}" -o table
Ensure both SoftDelete and PurgeProtection are true for all Key Vaults.
For a specific vault:
az keyvault show --name {vaultName} --query "{SoftDelete:properties.enableSoftDelete, PurgeProtection:properties.enablePurgeProtection}"
From PowerShell:
Get-AzKeyVault | ForEach-Object {
Get-AzKeyVault -VaultName $_.VaultName | Select-Object VaultName, EnableSoftDelete, EnablePurgeProtection
}
Ensure both EnableSoftDelete and EnablePurgeProtection are True.
All Key Vaults should have both soft delete and purge protection enabled.
From Azure Portal:
Key vaults.Settings, click Properties.Enable purge protection.Save.From Azure CLI:
az keyvault update --name {vaultName} --enable-purge-protection true
Note: Soft delete is now enforced by Azure and cannot be disabled.
From PowerShell:
Update-AzKeyVault -VaultName {vaultName} -EnablePurgeProtection
Soft delete is enabled by default and enforced for all new Key Vaults. Purge protection is not enabled by default and must be explicitly configured.