用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-euc-2-18命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-euc-2.18 |
| description | Ensure Radius server is using the recommended security protocol |
| category | cis-end-user-compute |
| version | 1.2.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","end-user-compute","workspaces","radius","mfa","authentication"] |
| cis_id | 2.18 |
| cis_benchmark | CIS AWS End User Compute Services Benchmark v1.2.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
The authentication protocol between the Microsoft AD DCs and the RADIUS server supported are PAP, CHAP, MS-CHAPv1, and MS-CHAPv2.
MS-CHAPv2 provides the strongest security of the options supported.
None
Perform the steps to check multi-factor authentication using the radius server protocol is set to MS-CHAP v2.
If it is not set to MS-CHAPv2 refer to the remediation steps below.
The RADIUS server protocol is configured to use MS-CHAPv2 for multi-factor authentication.
Perform the steps below to set the protocol to MS-CHAPv2 for multi-factor authentication.
By default, this is dependent on your RADIUS server.
Controls Version v8:
Controls Version v7:
Level 2