用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-azure-foundations-8-1-7-1命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-azure-foundations-8.1.7.1 |
| description | Ensure That Microsoft Defender for Azure Cosmos DB Is Set To 'On' |
| category | cis-azure-foundations |
| version | 5.0.0 |
| author | cyberstrike-official |
| tags | ["cis","azure","security","defender","databases","cosmos-db"] |
| cis_id | 8.1.7.1 |
| cis_benchmark | CIS Microsoft Azure Foundations Benchmark v5.0.0 |
| tech_stack | ["azure"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
Microsoft Defender for Azure Cosmos DB scans all incoming network requests for threats to your Azure Cosmos DB resources.
In scanning Azure Cosmos DB requests within a subscription, requests are compared to a heuristic list of potential security threats. These threats could be a result of a security breach within your services, thus scanning for them could prevent a potential security threat from being introduced.
Enabling Microsoft Defender for Azure Cosmos DB requires enabling Microsoft Defender for your subscription. Both will incur additional charges.
From Azure Portal:
Microsoft Defender for Cloud.Management, select Environment Settings.Defender plans blade.Database row click on Select types >.Azure Cosmos DB is set to On.From Azure CLI:
az security pricing show -n CosmosDbs --query pricingTier
From PowerShell:
Get-AzSecurityPricing -Name 'CosmosDbs' | Select-Object Name,PricingTier
Ensure output of -PricingTier is Standard.
From Azure Policy:
adbe85b5-83e6-4350-ab58-bf3a4f736e5e - Name: 'Microsoft Defender for Azure Cosmos DB should be enabled'The pricing tier for CosmosDbs should be Standard.
From Azure Portal:
Microsoft Defender for Cloud.Management, select Environment Settings.Defender plans blade.Database row click on Select types >.Azure Cosmos DB to .OnContinue.Save.From Azure CLI:
az security pricing create -n 'CosmosDbs' --tier 'standard'
From PowerShell:
Set-AzSecurityPricing -Name 'CosmosDbs' -PricingTier 'Standard'
By default, Microsoft Defender for Azure Cosmos DB is not enabled.