用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-storage-1-5命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-storage-1.5 |
| description | Ensure to create IAM roles for Backup |
| category | cis-storage-services |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","storage","backup","iam","iam-role","service-role","least-privilege"] |
| cis_id | 1.5 |
| cis_benchmark | CIS AWS Storage Services Benchmark v1.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | ["CWE-284"] |
| chains_with | ["cis-aws-storage-1.4","cis-aws-storage-1.6"] |
| prerequisites | ["cis-aws-storage-1.1","cis-aws-storage-1.4"] |
| severity_boost | {} |
An AWS Identity and Access Management (IAM) role is similar to a user, in that it is an AWS identity with permissions policies that determine what the identity can and cannot do in AWS. However, instead of being uniquely associated with one person, a role is intended to be assumable by anyone who needs it.
While Service Linked Roles offer quick deployment, using default configurations isn't recommended for security best practices.
Creating custom IAM roles for AWS Backup allows you to:
Not properly configuring IAM roles for AWS Backup can result in:
To create a role for AWS Backup, follow these steps:
# List IAM roles related to backup
aws iam list-roles | grep -i backup
# Get details of a specific backup role
aws iam get-role --role-name <ROLE_NAME>
# List policies attached to the backup role
aws iam list-attached-role-policies --role-name <ROLE_NAME>
# Get the trust relationship (assume role policy)
aws iam get-role --role-name <ROLE_NAME> \
--query 'Role.AssumeRolePolicyDocument'
Create Custom IAM Role for Backup
Attach Appropriate Policies
AWSBackupServiceRolePolicyForBackupAWSBackupServiceRolePolicyForRestoresConfigure Trust Relationship
Name the Role Appropriately
CustomBackupServiceRole or ProdBackupRole# Create trust policy document for AWS Backup service
cat > backup-trust-policy.json <<EOF
{
"Version": "2012-10-17",
"Statement": [
{
"Effect": "Allow",
"Principal": {
"Service": "backup.amazonaws.com"
},
"Action": "sts:AssumeRole"
}
]
}
EOF
# Create the IAM role
aws iam create-role \
--role-name CustomAWSBackupRole \
--assume-role-policy-document file://backup-trust-policy.json \
--description "Custom IAM role for AWS Backup operations"
# Attach AWS managed backup policy
aws iam attach-role-policy \
--role-name CustomAWSBackupRole \
--policy-arn arn:aws:iam::aws:policy/service-role/AWSBackupServiceRolePolicyForBackup
# Attach restore policy
aws iam attach-role-policy \
--role-name CustomAWSBackupRole \
--policy-arn arn:aws:iam::aws:policy/service-role/AWSBackupServiceRolePolicyForRestores
When using the AWS Backup console for the first time, you can choose to have AWS Backup create a default service role for you. This role has the permissions that AWS Backup needs to create and restore backups on your behalf.
The default service-linked role is created automatically but may have broader permissions than necessary for your specific use case.
Not mapped to specific CIS Controls v7 or v8 in the provided documentation.