用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-foundations-2-4命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-foundations-2.4 |
| description | Ensure no 'root' user account access key exists |
| category | cis-iam |
| version | 7.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","iam","root","access-key","credentials"] |
| cis_id | 2.4 |
| cis_benchmark | CIS AWS Foundations Benchmark v7.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-foundations-2.5","cis-aws-foundations-2.6","cis-aws-foundations-2.7"] |
| prerequisites | [] |
| severity_boost | {} |
The 'root' user account is the most privileged user in an AWS account. AWS access keys provide programmatic access to a given AWS account. It is recommended that all access keys associated with the 'root' user account be deleted.
Deleting access keys associated with the 'root' user account limits the vectors by which the account can be compromised. Additionally, removing 'root' access keys encourages the use of role-based access with least privilege.
Root access keys significantly increase the risk of account compromise, as they provide unrestricted programmatic access with no built-in scope limitations.
Credential Report..csv file which contains credential usage for all IAM users within an AWS Account.root user, ensure the access_key_1_active and access_key_2_active fields are set to FALSE.aws iam get-account-summary | grep "AccountAccessKeysPresent"
"AccountAccessKeysPresent": 0,"AccountAccessKeysPresent": 0 -- no root access keys exist.
<root_account> at the top right and select Security Credentials from the drop down list.Access Keys (Access Key ID and Secret Access Key).Status.Delete (Deleted keys cannot be recovered).Note: While a key can be made inactive, it will still appear in CLI audit output and may result in a false positive. Keys should be deleted to ensure compliance.
There is no AWS CLI command to delete root access keys. This must be done via the AWS Console.
By default, the AWS root user has no access keys created. Access keys are only present if they have been explicitly generated by the account owner.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts | x | x | x |
| v8 | 6.8 Define and Maintain Role-Based Access Control | x | ||
| v7 | 4.3 Ensure the Use of Dedicated Administrative Accounts | x | x | x |
| Techniques / Sub-techniques | Tactics | Mitigations |
|---|---|---|
| T1078.004 | TA0001, TA0004 | M1026 |
Level 1 | Automated