用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-azure-foundations-7-13命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-azure-foundations-7.13 |
| description | Ensure 'HTTP2' is set to 'Enabled' on Azure Application Gateway |
| category | cis-azure-foundations |
| version | 5.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","networking","application-gateway"] |
| cis_id | 7.13 |
| cis_benchmark | CIS Microsoft Azure Foundations Benchmark v5.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | ["cis-azure-foundations-7.10","cis-azure-foundations-7.12"] |
| prerequisites | [] |
| severity_boost | {} |
Enable HTTP/2 for improved performance, efficiency, and security.
HTTP/2 protocol support is available to clients that connect to application gateway listeners only. Communication with backend server pools is always HTTP/1.1.
Enabling HTTP/2 supports use of modern encrypted connections.
Clients and backend services that do not support HTTP/2 will fall back to HTTP/1.1.
Application gateways.Settings, click Configuration.HTTP2 is set to Enabled.Run the following command to list application gateways:
az network application-gateway list
For each application gateway, run the following command to get the HTTP2 setting:
az network application-gateway show --resource-group <resource-group> --name <application-gateway> --query enableHttp2
Ensure true is returned.
Run the following command to list application gateways:
Get-AzApplicationGateway
Run the following command to get the application gateway in a resource group with a given name:
$gateway = Get-AzApplicationGateway -ResourceGroupName <resource-group> -Name <application-gateway>
Run the following command to get the HTTP2 setting:
$gateway.EnableHttp2
Ensure True is returned.
Repeat for each application gateway.
All Application Gateways should have HTTP2 set to Enabled (enableHttp2 = true).
Application gateways.Settings, click Configuration.HTTP2, click .EnabledSave.For each application gateway requiring remediation, run the following command to enable HTTP2:
az network application-gateway update --resource-group <resource-group> --name <application-gateway> --http2 Enabled
Run the following command to get the application gateway in a resource group with a given name:
$gateway = Get-AzApplicationGateway -ResourceGroupName <resource-group> -Name <application-gateway>
Run the following command to enable HTTP2:
$gateway.EnableHttp2 = $true
Run the following command to apply the update:
Set-AzApplicationGateway -ApplicationGateway $gateway
Repeat for each application gateway requiring remediation.
HTTP2 is enabled by default.
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 2.2 Ensure Authorized Software is Currently Supported | x | x | x |
| v7 | 2.2 Ensure Software is Supported by Vendor | x | x | x |
Level 1 | Automated