用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-azure-database-3-3命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-azure-database-3.3 |
| description | Ensure that 'disableLocalAuth' is set to 'true' |
| category | cis-azure-database |
| version | 2.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","cosmos-db","nosql"] |
| cis_id | 3.3 |
| cis_benchmark | CIS Microsoft Azure Database Services Benchmark v2.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Ensure that key-based authentication (including resource owner password credential authentication) is disabled for Azure Cosmos DB accounts by setting disableLocalAuth to true. Instead, use Microsoft Entra ID for authentication, as it provides stronger security through managed credentials, multi-factor authentication (MFA), centralized access control, and seamless integration with Azure RBAC.
Disabling key-based authorization ensures that access to your Azure Cosmos DB account relies on the more secure Microsoft Entra ID authentication, reducing the risk of credential misuse and unauthorized access.
Administrative overhead in configuring, managing, and monitoring Entra ID authentication and role-based access.
Run the following command to get the disableLocalAuth setting for each Cosmos DB account:
az cosmosdb list --query "[].{name:name, resourceGroup:resourceGroup, disableLocalAuth:disableLocalAuth}"
Ensure that disableLocalAuth is set to true for each Cosmos DB account.
Run the following command to list Cosmos DB accounts in a resource group:
Get-AzCosmosDBAccount -ResourceGroupName <resource-group>
Run the following command to get the Cosmos DB account in a resource group with a given name:
$cosmosdb = Get-AzResource -ResourceType Microsoft.DocumentDB/databaseAccounts -ResourceGroupName <resource-group> -ResourceName <cosmosdb-account>
Run the following command to get the disableLocalAuth setting for the Cosmos DB account:
$cosmosdb.Properties.disableLocalAuth
Ensure that the command returns True.
Repeat for each Cosmos DB account.
5450f5bd-9c72-4390-a9c4-a7aba4edfdd2 - Name: 'Cosmos DB database accounts should have local authentication methods disabled'disableLocalAuth should be set to true for each Cosmos DB account.
Map all the resources that currently have access to the Azure Cosmos DB account with keys or access tokens.
Create an Entra ID identity for each of these resources:
When all resources work correctly with the new identities, continue to the next step.
For each Cosmos DB account requiring remediation, run the following command to set disableLocalAuth to true:
az resource update --resource-group <resource-group> --name <cosmosdb-account> --resource-type Microsoft.DocumentDB/databaseAccounts --set properties.disableLocalAuth=true
For each Cosmos DB account requiring remediation, run the following commands to set disableLocalAuth to True:
$cosmosdb = Get-AzResource -ResourceType Microsoft.DocumentDB/databaseAccounts -ResourceGroupName <resource-group> -ResourceName <cosmosdb-account>
$cosmosdb.Properties.disableLocalAuth = "True"
$cosmosdb | Set-AzResource -Force
By default, disableLocalAuth is set to false.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 6.7 Centralize Access Control | X | X | |
| v7 | 16.2 Configure Centralized Point of Authentication | X | X |
| Techniques / Sub-techniques | Tactics | Mitigations |
|---|---|---|
| T1190 |