用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-aws-storage-2-1命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-aws-storage-2.1 |
| description | Ensure creating EC2 instance with EBS |
| category | cis-storage-services |
| version | 1.0.0 |
| author | cyberstrike-official |
| tags | ["cis","aws","storage","ebs","ec2","block-storage","encryption"] |
| cis_id | 2.1 |
| cis_benchmark | CIS AWS Storage Services Benchmark v1.0.0 |
| tech_stack | ["aws"] |
| cwe_ids | [] |
| chains_with | ["cis-aws-storage-2.2","cis-aws-storage-2.3","cis-aws-storage-2.4","cis-aws-storage-2.5"] |
| prerequisites | [] |
| severity_boost | {} |
EBS are storage volumes that you attach to Amazon EC2 instances. After you attach a volume to an instance, you can use it in the same way you would use a local hard drive attached to a computer, for example to store files or to install applications.
Amazon EBS (Elastic Block Store) provides persistent block-level storage for EC2 instances, which is essential for:
Properly configuring EC2 instances with EBS ensures data availability, durability, and security.
Not properly creating EC2 instances with EBS volumes can lead to:
Creating EC2 instance with Volume:
To create an EC2 instance with a volume in AWS, you can follow these general steps:
Initializing a Secure EC2 Instance
Naming the EC2 instance
Configure the operating system
Create a key pair
Add Storage:
# Launch an EC2 instance with EBS volume
aws ec2 run-instances \
--image-id ami-xxxxxxxxx \
--instance-type t2.micro \
--key-name my-key-pair \
--security-group-ids sg-xxxxxxxxx \
--block-device-mappings '[
{
"DeviceName": "/dev/sda1",
"Ebs": {
"VolumeSize": 20,
"VolumeType": "gp3",
"Encrypted": true,
"DeleteOnTermination": false
}
}
]'
# List EC2 instances with their EBS volumes
aws ec2 describe-instances \
--query 'Reservations[].Instances[].[InstanceId,BlockDeviceMappings[]]' \
--output table
# Describe volumes attached to an instance
aws ec2 describe-volumes \
--filters Name=attachment.instance-id,Values=i-xxxxxxxxx
Launch New Instance with EBS
Add Volume to Existing Instance
See audit procedure for creation commands.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 3.11 Encrypt Sensitive Data at Rest | ● | ● | ● |
| v7 | 14.8 Encrypt Sensitive Information at Rest | ● |
CIS Control v8 - 3.11 Encrypt Sensitive Data at Rest: Encrypt sensitive data at rest on servers, applications, and databases containing sensitive data. Storage-layer encryption, also known as server-side encryption, meets the minimum requirement of this Safeguard. Additional encryption methods may include application-layer encryption, also known as client-side encryption, where access to the data storage device(s) does not permit access to the plain-text data.
CIS Control v7 - 14.8 Encrypt Sensitive Information at Rest: Encrypt all sensitive information at rest using a tool that requires a secondary authentication mechanism not integrated into the operating system, in order to access the information.