用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-euc-2-5命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-euc-2.5 |
| description | Ensure WorkSpaces traffic is controlled and routed through a NAT Gateway |
| category | cis-end-user-compute |
| version | 1.2.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","end-user-compute","workspaces","nat-gateway","routing","network-traffic"] |
| cis_id | 2.5 |
| cis_benchmark | CIS AWS End User Compute Services Benchmark v1.2.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-euc-2.4","cis-aws-euc-2.6"] |
| prerequisites | [] |
| severity_boost | {} |
A network address translation (NAT) gateway enables instances in a private subnet to connect to the internet or other AWS services, but prevents the internet from initiating a direct connection with those instances.
WorkSpaces must have access to the internet so that you can install updates to the operating system and deploy applications.
None specified in the benchmark.
Perform the following steps to verify a NAT Gateway is configured and utilized:
If the Route tables aren't set for one route for local traffic and another route that sends all other traffic to the internet gateway for the VPC refer to the remediation procedure below.
Perform the following steps to create a NAT gateway:
Login to the VPC console at https://console.aws.amazon.com/vpc/
In the left pane, click NAT Gateways
Click Create NAT Gateway
For NAT Gateway settings:
Click Create a NAT Gateway
The NAT gateway will display in the console and after a few moments, its status will change to Available.
If the NAT gateway goes to a status of Failed, there was an error during creation.
After you've created your NAT gateway, you must update your route tables for your private subnets to point internet traffic to the NAT gateway.
To create a route for a NAT gateway:
Log in to the VPC console at https://console.aws.amazon.com/vpc/
In the left pane, Click Route Tables
Select the route table associated with your private subnet
Click Routes tab
Click Edit routes
Click Add route
For Edit routes:
Click Save routes
By default, No NAT Gateways are created for a VPC.
Note: In some multi-account AWS architectures organizations may choose to leverage a centralized internet egress pattern. This could be due to appliances running in the centralized pattern which are being used to enforce controls and could include DLP or category filtering on internet egress traffic. In this case the relevant audit procedure is ensuring the workspaces VPC has a route to the internet (either via proxy server configuration on the workspace instances themselves or the default route on the workspace instance VPC subnet)
v8:
v7: