SOC 직업 분류 기준
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-bind-v100-3-3명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SKILL.md 표시 중
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
| name | cis-bind-v100-3-3 |
| description | Restrict Query Origins (Manual) |
| category | cis-bind |
| version | 1.0 |
| author | cyberstrike-official |
| tags | ["cis","bind","dns","isc-bind","bind9","restricting-queries"] |
| cis_id | 3.3 |
| cis_benchmark | CIS ISC BIND DNS Server 9.11 Benchmark v1.0.0 |
| tech_stack | ["bind","isc-bind","dns","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
BIND can be configured to restrict access to its query services based on source IP address. It is recommended that the allow-query option be used to restrict access to only the networks authorized to use the name server. For an external authoritative only name server, the authorized networks may include all networks, however for internal authoritative or caching name servers the authorized networks should be explicitly configured.
Using allow-query in conjunction with an ACL of trusted networks will reduce the risk of unauthorized access to name services content. Additionally, the exposure of vulnerabilities present in BIND's query handlers is reduced by this configuration as requests with an untrusted source will be rejected before the request is fully parsed by named. Keep in mind however, that the source IP addresses can be easily spoofed, and the firewall and network architecture also needs to protect internal name servers from external spoofed requests.
Not specified in the PDF.
Verify that the BIND configuration files contain a global allow-query option with only the predefined ACL localhost and an ACL of the explicitly authorized networks. For an external authoritative only name server, the authorized networks may be the ACL any which represents any IPv4 or IPV6 host, but for caching and internal name servers, the authorized_networks should be an ACL with an explicit list of networks. The name of the ACL does not have to be authorized_networks.
$ grep allow-query $CONFIG_FILES
allow-query { localhost; authorized_networks };
For an external authoritative only name server:
$ grep allow-query $CONFIG_FILES
allow-query { any };
For remediation:
named.conf file.acl authorized_networks { 10.10.32.0/24; 10.10.34.0/24; . . . };
named.conf file with the localhost ACL and the authorized trusted networks ACL.allow-query { localhost; authorized_networks };
The default package install allows queries only from localhost.
Not specified in the PDF.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v6 | 9 Limitation and Control of Network Ports, Protocols, and Services | Y | Y | Y |
| v7 | 14.7 Enforce Access Control to Data through Automated Tools | N | N | Y |
| Tactic | Technique |
|---|---|
| Discovery | T1590 - Gather Victim Network Information |
| Initial Access | T1190 - Exploit Public-Facing Application |