소스 정보
- 저장소
- CyberStrikeus/CyberStrike
- 최근 소스 활동
- 2026년 4월 22일 14:54
- 감지된 SKILL.md 언어
- 영어
- 스타
- 1,653
- 포크
- 254
설치 방법
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
소스 파일 검토
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
메뉴
기본적으로 소스를 먼저 확인하는 Prompt가 선택됩니다. 직접 명령으로 전환하거나 로컬 사본을 다운로드할 수도 있습니다.
설치 여부를 결정하기 전에 SKILL.md와 SkillsMP에 표시된 보조 파일을 읽어 보세요.
Codex 또는 Claude로 설치 이 Prompt를 복사해 Codex, Claude 또는 다른 어시스턴트에 붙여 넣으면 Skill 페이지를 검토하고 설치를 진행할 수 있습니다.
직접 명령은 검토 Prompt를 거치지 않습니다. 실행하기 전에 소스를 확인하세요.
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-nginx-v300-3-2명령은 한 줄로 유지됩니다. 복사하기 전에 가로로 스크롤해 전체 내용을 확인하세요.
로컬 사본을 원하시나요? SkillsMP에서 현재 제공할 수 있는 파일을 다운로드하세요.
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
SOC 직업 분류 기준
SKILL.md 표시 중
| name | cis-nginx-v300-3-2 |
| description | Ensure access logging is enabled (Manual) |
| category | cis-nginx |
| version | 3.0 |
| author | cyberstrike-official |
| tags | ["cis","nginx","web-server","reverse-proxy","logging"] |
| cis_id | 3.2 |
| cis_benchmark | CIS NGINX Benchmark v3.0.0 |
| tech_stack | ["nginx","linux","web-server"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
The access_log directive enables the logging of client requests. While NGINX enables this by default, it allows granular control per server or location context. Based on enterprise requirements, the log should be enriched with relevant variables or converted to structured JSON format for modern SIEM integration. Refer to Recommendation 3.1 for detailed configuration of log formats and variables. Ensure that access logging is active for all critical services.
Access logs are the primary record of system usage, detailing who accessed what resources and when and general troubleshooting. Without active access logs, incident responders are blind to web-based attacks (such as SQL injection, XSS probing, or Brute Force attempts) and auditors cannot verify compliance or user activity. Disabling logs globally (access_log off;) effectively destroys the forensic chain of custody for security events.
Enabling detailed access logging increases disk space usage significantly. Without proper log rotation (e.g., logrotate) and monitoring, log files can rapidly consume available disk space, potentially causing the server to stop processing requests or crash. Ensure sufficient storage capacity and retention policies are in place.
1. Verify Configuration:
Inspect the fully loaded configuration for log settings:
nginx -T 2>/dev/null | grep -i "access_log"
Evaluation:
access_log directives point to a valid local file path (e.g., /var/log/nginx/access.json) for ingestion by log shippers.access_log off;.access_log off; is absent, or strictly limited to non-critical assets (e.g., location = /favicon.ico, static assets, or internal health checks).access_log off; is applied globally in the http block or to server blocks handling business logic.Enable access logging in the http block to set a secure global default, or configure it explicitly within specific blocks. It is recommended to use the detailed log format defined in Recommendation 3.1.
serverConfiguration Example:
http {
# Enable global logging using the detailed JSON format from Rec 3.1
access_log /var/log/nginx/access.json main_access_json;
server {
# Inherits the global log setting, or can be overridden:
access_log /var/log/nginx/example.com.access.json main_access_json;
location / {
# ...
}
# Exception: Disable logging for favicon to reduce noise (Optional)
location = /favicon.ico {
access_log off;
log_not_found off;
}
}
}
Access logging is enabled by default, typically logging to logs/access.log or /var/log/nginx/access.log using the standard combined format.
Embedded Variables for NGINX
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 8.5 Collect Detailed Audit Logs | N | Y | Y |
| v7 | 6.3 Enable Detailed Logging | N | Y | Y |
| Tactic | Technique |
|---|---|
| Defense Evasion | T1070 - Indicator Removal |
| Discovery | T1082 - System Information Discovery |