用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-foundations-2-7命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-foundations-2.7 |
| description | Eliminate use of the 'root' user for administrative and daily tasks |
| category | cis-iam |
| version | 7.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","iam","root","least-privilege","credential-management"] |
| cis_id | 2.7 |
| cis_benchmark | CIS AWS Foundations Benchmark v7.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-foundations-2.4","cis-aws-foundations-2.5","cis-aws-foundations-2.6"] |
| prerequisites | [] |
| severity_boost | {} |
With the creation of an AWS account, a 'root user' is created that cannot be disabled or deleted. This user has unrestricted access to and control over all resources in the AWS account. It is highly recommended that the use of this account be avoided for everyday tasks.
The 'root user' has unrestricted access to and control over all account resources. Use of this account is inconsistent with the principles of least privilege and separation of duties and can lead to unnecessary harm due to user error or account compromise.
Use of the root account for routine activities increases the risk of accidental or unauthorized changes, potentially resulting in full account compromise.
Credential Report.Download Report.root user under the user column.password_last_usedaccess_key_1_last_used_dateaccess_key_2_last_used_datemfa_active field is set to TRUE or the password_enabled field is set to FALSE.aws iam generate-credential-report
aws iam get-credential-report --query 'Content' --output text | base64 -d | cut -d, -f1,5,11,16 | grep -B1 '<root_account>'
password_last_usedaccess_key_1_last_used_dateaccess_key_2_last_used_dateNote: There are limited scenarios where use of the 'root' user is required. Refer to AWS documentation for a complete list.
The root user should show no recent usage for administrative or daily tasks. password_last_used, access_key_1_last_used_date, and access_key_2_last_used_date should indicate infrequent or no recent use.
If the 'root' user account is being used for daily activities or administrative tasks that do not require root access:
aws iam delete-login-profile
This removes the password associated with the root account and prevents console authentication using the root user.
By default, the AWS root user is created with full administrative privileges and no restrictions. The root account remains permanently enabled and can perform all actions unless access is limited through IAM users and roles.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 5.4 Restrict Administrator Privileges to Dedicated Administrator Accounts | x | x | x |
| v7 | 4.3 Ensure the Use of Dedicated Administrative Accounts | x | x | x |
| Techniques / Sub-techniques | Tactics | Mitigations |
|---|---|---|
| T1078.004 | TA0001, TA0004 | M1036 |
Level 1 | Manual