用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-azure-compute-2-1-16命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-azure-compute-2.1.16 |
| description | Ensure private endpoints are used to access App Service apps |
| category | cis-azure-compute |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","app-service","private-endpoint","private-link","network-security","vnet"] |
| cis_id | 2.1.16 |
| cis_benchmark | CIS Microsoft Azure Compute Services Benchmark v2.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Use private endpoints to allow clients and services to securely access data located over a network via an encrypted Private Link. To do this, the private endpoint uses an IP address from the VNet for each service. Network traffic between disparate services securely traverses encrypted over the VNet. This VNet can also link addressing space, extending your network and accessing resources on it. Similarly, it can be a tunnel through public networks to connect remote infrastructures together. This creates further security through segmenting network traffic and preventing outside sources from accessing it.
Securing traffic between services through encryption protects the data from easy interception and reading.
If an Azure Virtual Network is not implemented correctly, this may result in the loss of critical network traffic.
Private endpoints are charged per hour of use. Refer to https://azure.microsoft.com/en-us/pricing/details/private-link/ and https://azure.microsoft.com/en-us/pricing/calculator/ to estimate potential costs.
App Services.Settings, click Networking.Inbound traffic configuration, click the link next to Private endpoints.Connection state of Approved.Run the following command to list apps IDs:
az webapp list --query [*].id
Run the following command to list private link service IDs and connection states:
az network private-endpoint list --query [*].privateLinkServiceConnections[*].[privateLinkServiceId,privateLinkServiceConnectionState.status]
Ensure that a private endpoint exists for each app with a connection state of Approved.
Not specifically documented for this control.
At least one private endpoint should exist for each app with a connection state of Approved.
App Services.Settings, click Networking.Inbound traffic configuration, click the link next to Private endpoints.+ Add.Express or Advanced.Express:
Name, and select a Subscription, Virtual network, and Subnet.OK.Advanced:
Subscription and Resource group, provide an instance Name and Network Interface Name, and select a Region.Next : Resource >.Target sub-resource.Next : Virtual Network >.Virtual network and a Subnet.Next : DNS >.Next : Tags >.Next : Review + create >.Create.For each app requiring remediation, run the following command to create a private endpoint:
az network private-endpoint create --resource-group <resource-group-name> --location <location> --name <private-endpoint-name> --vnet-name <virtual-network-name> --subnet <subnet-name> --private-connection-resource-id <fully-qualified-app-id> --connection-name <connection-name> --group-id sites
Not specifically documented for this control.
By default, private endpoints are not configured for apps.
Level 2 | Automated