用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-foundations-4-1命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-foundations-4.1 |
| description | Ensure CloudTrail is enabled in all regions |
| category | cis-logging |
| version | 7.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","logging","cloudtrail","multi-region","management-events"] |
| cis_id | 4.1 |
| cis_benchmark | CIS AWS Foundations Benchmark v7.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-foundations-4.2","cis-aws-foundations-4.3","cis-aws-foundations-4.4","cis-aws-foundations-4.5"] |
| prerequisites | [] |
| severity_boost | {} |
AWS CloudTrail is a web service that records AWS API calls for your account and delivers log files to you. The recorded information includes the identity of the API caller, the time of the API call, the source IP address of the API caller, the request parameters, and the response elements returned by the AWS service. CloudTrail provides a history of AWS API calls for an account, including API calls made via the Management Console, SDKs, command line tools, and higher-level AWS services (such as CloudFormation).
The AWS API call history produced by CloudTrail enables security analysis, resource change tracking, and compliance auditing. Additionally,
S3 lifecycle features can be used to manage the accumulation and management of logs over time. See the following AWS resource for more information on these features:
Trails in the left navigation paneYes specified in the Multi-region trail columnName columnLogging is set to ONMulti-region trail is set to YesManagement Events, ensure that API activity set to ALLaws cloudtrail describe-trails
IsMultiRegionTrail is set to true:aws cloudtrail get-trail-status --name <trail-name>
IsLogging is set to true:aws cloudtrail get-event-selectors --trail-name <trail-name>
fieldSelector for a trail that equals Management:true or false is returned, one of the checkboxes (read or write) is not selected.Example of correct output:
"TrailARN": "<your_trail_ARN>",
"AdvancedEventSelectors": [
{
"Name": "Management events selector",
"FieldSelectors": [
{
"Field": "eventCategory",
"Equals": [
"Management"
]
}
]
}
]
At least one multi-region trail exists with IsMultiRegionTrail set to true, IsLogging set to true, and management events configured for all read/write types.
Trails in the left navigation pane.Get Started Now if it is presented, then:
Add new trail.Trail name box.
S3 bucket box.Log file SSE-KMS encryption section, or create a new key.Next.Management events check box is selected.Read and Write are checked under API activity.Next.Create trail.Create a multi-region trail:
aws cloudtrail create-trail --name <trail-name> --bucket-name <s3-bucket-for-cloudtrail> --is-multi-region-trail
Enable multi-region on an existing trail:
aws cloudtrail update-trail --name <trail-name> --is-multi-region-trail
Note: Creating a CloudTrail trail via the CLI without providing any overriding options configures all read and write Management Events to be logged by default.
By default, CloudTrail is not enabled in any region.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 8.5 Collect Detailed Audit Logs - Configure detailed audit logging for enterprise assets containing sensitive data. Include event source, date, username, timestamp, source addresses, destination addresses, and other useful elements that could assist in a forensic investigation. | x | x | |
| v7 | 6.2 Activate audit logging - Ensure that local logging has been enabled on all systems and networking devices. | x | x | x |
| Techniques / Sub-techniques | Tactics | Mitigations |
|---|---|---|
| T1535 | TA0005 | M1047, M1054 |
Level 1 | Manual