用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-azure-foundations-6-1-1-10命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-azure-foundations-6.1.1.10 |
| description | Ensure Intune logs are captured and sent to Log Analytics |
| category | cis-azure-foundations |
| version | 5.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","logging","monitoring","intune","endpoint-management"] |
| cis_id | 6.1.1.10 |
| cis_benchmark | CIS Microsoft Azure Foundations Benchmark v5.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | ["cis-azure-foundations-6.1.1.9"] |
| prerequisites | [] |
| severity_boost | {} |
Ensure that Intune logs are captured and fed into a central log analytics workspace.
Intune includes built-in logs that provide information about your environments. Sending logs to a Log Analytics workspace enables centralized analysis, correlation, and alerting for faster threat detection and response.
A Microsoft Intune plan is required to access Intune. The amount of data logged and, thus, the cost incurred can vary significantly depending on the tenant size.
Intune.Reports.Azure monitor, click Diagnostic settings.Edit setting, and review the selected log categories and destination details.AuditLogsOperationalLogsDeviceComplianceOrgDevicesWindows365AuditLogsAt least one Intune diagnostic setting should exist that sends AuditLogs, OperationalLogs, DeviceComplianceOrg, Devices, and Windows365AuditLogs to a Log Analytics workspace.
Intune.Reports.Azure monitor, click Diagnostic settings.+ Add diagnostic setting.Diagnostic setting name.Logs > Categories, check the box next to each of the following logs:
AuditLogsOperationalLogsDeviceComplianceOrgDevicesWindows365AuditLogsDestination details, check the box next to Send to Log Analytics workspace.SubscriptionLog Analytics workspace.Save.By default, Intune diagnostic settings do not exist.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 8.2 Collect Audit Logs | x | x | x |
| v7 | 6.2 Activate audit logging | x | x | x |
Level 2 | Manual