用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-foundations-2-20命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-foundations-2.20 |
| description | Ensure access to AWSCloudShellFullAccess is restricted |
| category | cis-iam |
| version | 7.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","iam","cloudshell","data-exfiltration","least-privilege","policies"] |
| cis_id | 2.20 |
| cis_benchmark | CIS AWS Foundations Benchmark v7.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-foundations-2.14","cis-aws-foundations-2.13"] |
| prerequisites | [] |
| severity_boost | {} |
AWS CloudShell is a convenient way of running CLI commands against AWS services. The managed IAM policy AWSCloudShellFullAccess provides full access to CloudShell, including file upload and download capability between a user's local system and the CloudShell environment. Within the CloudShell environment, a user has sudo permissions and can access the internet. It is therefore possible to install software and transfer data to external systems.
Access to this policy should be restricted, as it presents a potential channel for data exfiltration by privileged users. AWS documentation provides guidance on creating more restrictive policies that limit file transfer capabilities.
Unrestricted access to CloudShell may allow users to transfer data outside the AWS environment, increasing the risk of data exfiltration and loss of sensitive information.
PoliciesAWSCloudShellFullAccessEntities attached tabaws iam list-entities-for-policy --policy-arn arn:aws:iam::aws:policy/AWSCloudShellFullAccess
Example:
PolicyRoles: [ ]
The AWSCloudShellFullAccess policy should not be attached to any users, groups, or roles. All three lists (PolicyUsers, PolicyRoles, PolicyGroups) should be empty.
PoliciesAWSCloudShellFullAccessEntities attached tabFrom Command Line (optional automation):
POLICY_ARN="arn:aws:iam::aws:policy/AWSCloudShellFullAccess"
# Detach from users
for u in $(aws iam list-entities-for-policy --policy-arn "$POLICY_ARN" --query "PolicyUsers[].UserName" --output text); do
echo "Detaching from user: $u"
aws iam detach-user-policy --user-name "$u" --policy-arn "$POLICY_ARN"
done
# Detach from roles
for r in $(aws iam list-entities-for-policy --policy-arn "$POLICY_ARN" --query "PolicyRoles[].RoleName" --output text); do
echo "Detaching from role: $r"
aws iam detach-role-policy --role-name "$r" --policy-arn "$POLICY_ARN"
done
# Detach from groups
for g in $(aws iam list-entities-for-policy --policy-arn "$POLICY_ARN" --query "PolicyGroups[].GroupName" --output text); do
echo "Detaching from group: $g"
aws iam detach-group-policy --group-name "$g" --policy-arn "$POLICY_ARN"
done
By default, the AWS managed policy AWSCloudShellFullAccess exists but is not attached to any users, groups, or roles. It must be explicitly assigned to grant permissions.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 6.1 Establish an Access Granting Process - Establish and follow a process, preferably automated, for granting access to enterprise assets upon new hire, rights grant, or role change of a user. | x | x | x |
| v7 | 14.1 Segment the Network Based on Sensitivity - Segment the network based on the label or classification level of the information stored on the servers, locate all sensitive information on separated Virtual Local Area Networks (VLANs). | x | x |
| Techniques / Sub-techniques | Tactics | Mitigations |
|---|---|---|
| T1078.004 | TA0009, TA0010, TA0043 | M1018, M1047, M1050 |
Level 1 | Manual