用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-database-2-3命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-database-2.3 |
| description | Ensure Data in Transit Encryption is Enforced |
| category | cis-database |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","database","aurora","encryption","tls","ssl","data-in-transit"] |
| cis_id | 2.3 |
| cis_benchmark | CIS AWS Database Services Benchmark v2.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-database-2.2"] |
| prerequisites | [] |
| severity_boost | {} |
Use TLS (Transport Layer Security) to secure data in transit. Aurora supports TLS-encrypted connections between your application and your DB instance, and this configuration can be enforced so non-TLS connections are prohibited.
Encrypting data in transit protects sensitive information from interception and tampering by unauthorized parties. Aurora supports TLS for securing client connections, however it is essential to ensure that client applications are properly configured to use TLS and that the database enforces encrypted connections.
Disabling or failing to properly configure TLS can expose the data to be compromised by malicious actors, potentially resulting in data breaches, credential theft, or other security compromises.
rds.force_ssl = 1require_secure_transport = ON (Only applicable for Aurora MySQL versions 2 and 3)Notes:
rds.force_ssl should be set to 1require_secure_transport should be set to ONrds.force_ssl = 1require_secure_transport = ON (applicable to Aurora MySQL versions 2 and 3 only).For MySQL-compatible Aurora, Amazon provides an SSL certificate that you can download from their documentation. PostgreSQL-compatible Aurora uses the default PostgreSQL SSL certificate.
Once you have the appropriate certificate, you must configure your client application to use SSL/TLS. For example, in MySQL, you might use a command like this:
mysql -h <myinstance.123456789012.us-east-1.rds.amazonaws.com> --ssl-ca=</path_to_certificate/rds-combined-ca-bundle.pem> --ssl-mode=VERIFY_IDENTITY
For PostgreSQL, you might use a command like this:
psql "host=<myinstance.123456789012.us-east-1.rds.amazonaws.com> sslmode=verify-ca sslrootcert=</path_to_certificate/rds-combined-ca-bundle.pem>"
Replace <myinstance.123456789012.us-east-1.rds.amazonaws.com> with the endpoint for your DB instance, and replace </path_to_certificate/rds-combined-ca-bundle.pem> with the path to the SSL certificate on your local machine.
SHOW STATUS LIKE 'Ssl_cipher';
In PostgreSQL, you can run the following command:
SHOW ssl;
In both cases, if SSL is enabled, you should see a non-empty cipher suite or on as a result.
Aurora supports TLS connections by default, but enforcement of TLS-only connections requires explicit configuration of the cluster parameter group.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 3.10 Encrypt Sensitive Data in Transit - Encrypt sensitive data in transit. Example implementations can include: Transport Layer Security (TLS) and Open Secure Shell (OpenSSH). | x | x | |
| v7 | 14.4 Encrypt All Sensitive Information in Transit - Encrypt all sensitive information in transit. | x | x |
Level 1 | Manual