用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-azure-compute-2-1-12命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
| name | cis-azure-compute-2.1.12 |
| description | Ensure 'App Service authentication' is set to 'Enabled' |
| category | cis-azure-compute |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","app-service","authentication","identity","access-control"] |
| cis_id | 2.1.12 |
| cis_benchmark | CIS Microsoft Azure Compute Services Benchmark v2.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
App Service authentication can prevent anonymous HTTP requests from reaching an app, or authenticate those with tokens before they reach the app. If an anonymous request is received from a browser, App Service will redirect to a login page. To handle the login process, a choice from a set of identity providers can be made, or a custom authentication mechanism can be implemented.
By enabling authentication, every incoming HTTP request passes through it before being handled by the application code. It also handles authentication of users with the specified provider (Entra ID, Facebook, Google, Microsoft Account, and Twitter), validation, storage and refreshing of tokens, managing the authenticated sessions, and injecting identity information into request headers.
This is only required for apps that require authentication. Enabling it on a site like a marketing or support website will prevent unauthenticated access, which would be undesirable.
Adding an authentication requirement will increase costs and require additional security components to facilitate the authentication.
App Services.Settings, click Authentication.App Service authentication is set to Enabled.Run the following command to list apps:
az webapp list
For each app, run the following command to get the authentication setting:
For v1 auth commands:
az webapp auth show --resource-group <resource-group-name> --name <app-name> --query enabled
For v2 auth commands:
az webapp auth show --resource-group <resource-group-name> --name <app-name> --query properties.platform.enabled
Ensure that true is returned.
Not specifically documented for this control.
App Service authentication should be enabled (true).
App Services.Settings, click Authentication.Add identity provider.Add.App Service authentication is set to Disabled:
Enable authentication.For each app requiring remediation, run the following command to enable authentication:
az webapp auth update --resource-group <resource-group-name> --name <app-name> --enabled true
Note: In order to access App Service authentication settings for an app using the Microsoft API, the Website Contributor permission at the subscription level is required. A custom role can be created instead of Website Contributor to provide more specific permissions and maintain the principle of least privilege access.
Not specifically documented for this control.
By default, App Service authentication is set to Disabled.
Level 2 | Automated