基于 SOC 职业分类
用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-azure-foundations-8-1-3-2命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
正在显示 SKILL.md
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
| name | cis-azure-foundations-8.1.3.2 |
| description | Ensure 'Vulnerability assessment for machines' component status is set to 'On' |
| category | cis-azure-foundations |
| version | 5.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","security","defender","servers","vulnerability-assessment"] |
| cis_id | 8.1.3.2 |
| cis_benchmark | CIS Microsoft Azure Foundations Benchmark v5.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Enable vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.
Vulnerability assessment for machines scans for various security-related configurations and events such as system updates, OS vulnerabilities, and endpoint protection, then produces alerts on threat and vulnerability findings.
Microsoft Defender for Servers plan 2 licensing is required, and configuration of Azure Arc introduces complexity beyond this recommendation.
From Azure Portal:
Microsoft Defender for Cloud.Management, select Environment Settings.Settings & monitoring.Vulnerability assessment for machines is set to On.Repeat the above for any additional subscriptions.
From Azure Policy:
501541f7-f7e7-4cd6-868c-4190fdad3ac9 - Name: 'A vulnerability assessment solution should be enabled on your virtual machines'Vulnerability assessment for machines should be set to On.
From Azure Portal:
Microsoft Defender for Cloud.Management, select Environment Settings.Settings & Monitoring.Status of Vulnerability assessment for machines to On.Continue.Repeat the above for any additional subscriptions.
By default, Automatic provisioning of monitoring agent is set to Off.