소스 정보
- 저장소
- CyberStrikeus/CyberStrike
- 최근 소스 활동
- 2026년 4월 22일 14:54
- 감지된 SKILL.md 언어
- 영어
- 스타
- 1,653
- 포크
- 254
설치 방법
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
소스 파일 검토
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
메뉴
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-bind-v100-9-6명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
SOC 직업 분류 기준
SKILL.md 표시 중
| name | cis-bind-v100-9-6 |
| description | Ensure Signing Keys are Scheduled to be Replaced Periodically (Automated) |
| category | cis-bind |
| version | 1.0 |
| author | cyberstrike-official |
| tags | ["cis","bind","dns","isc-bind","bind9","operations","dnssec"] |
| cis_id | 9.6 |
| cis_benchmark | CIS ISC BIND DNS Server 9.11 Benchmark v1.0.0 |
| tech_stack | ["bind","isc-bind","dns","linux"] |
| cwe_ids | ["CWE-324"] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Implement a periodic key rollover process for both the Zone Signing Keys (ZSK) and the Key Signing Keys (KSK). The ZSK should be replaced within 2 years or less. The KSK should be replaced within 6 years or less. Keys are replaced by generating a new key before the existing key expires, and scheduling a rollover date when the new key will phase out and replace the old key.
Cryptographic keys like passwords need to be periodically replaced. By using strong key algorithms and appropriately long bit lengths, the lifetime for keys can be longer than a generally recommended for passwords. Typically, the Zone Signing Keys are rolled over more frequently than the Key Signing Keys.
Not specified.
Perform the following steps to determine if the recommended state is implemented:
256 key code using the following command.# ZKEYS=$(find $KEYDIR -name '*.key' | xargs grep -l 'DNSKEY 256 3' )
dnssec-settime to report the date in seconds since the start of the UNIX epoch.# for zk in $ZKEYS; do echo -n "$zk: "; dnssec-settime -pA $zk; done
./Kcisecurity.com.+013+45248.key: Activate: Mon Mar 2 16:35:58 2020
257 key code using the following command.# KKEYS=$(find $KEYDIR -name '*.key' | xargs grep -l 'DNSKEY 257 3' )
# for kk in $KKEYS; do echo -n "$kk: "; dnssec-settime -pA $kk; done
./Kcisecurity.com.+013+45248.key: Activate: Mon Mar 2 16:35:58 2020
If all ZSK activation dates are less than two years prior, and the KSK activation dates are less than six years prior, than the server is compliant.
To replace an aged key, perform the following:
dnssec-keygen and one of the recommended algorithms. An example command is shown below:# dnssec-keygen -a ED25519 example.org
# dnssec-keygen -a ED25519 -f KSK example.org
# dnssec-settime -I +30d -D +60d Kexample.org.+013+46651.key
Signing key rollover is NOT implemented by default.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v7 | N/A | N | N | N |
| Tactic | Technique |
|---|---|
| Credential Access | T1552 Unsecured Credentials |