用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu2004-v300-1-7-3命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-ubuntu2004-v300-1-7-3 |
| description | Ensure GDM disable-user-list option is enabled |
| category | cis-networking |
| version | 3.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-20.04","gnome","gdm","user-list","login"] |
| cis_id | 1.7.3 |
| cis_benchmark | CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
GDM is the GNOME Display Manager which handles graphical login for GNOME based systems.
The disable-user-list option controls if a list of users is displayed on the login screen.
Displaying the user list eliminates half of the Userid/Password equation that an unauthorized person would need to log on.
Run the following command to verify that a user profile exists:
# grep -Psi "user-db|system-db" /etc/dconf/profile/*/*
/etc/dconf/profile/local:user-db:user
/etc/dconf/profile/local:system-db:local
Run the following command and to verify that the disable-user-list option is enabled:
# gsettings get org.gnome.login-screen disable-user-list
true
disable-user-list should be truedisable-user-list:# gsettings set org.gnome.login-screen disable-user-list true
Note:
gsettings commands in this section MUST be done from a command window on a graphical desktop or an error will be returned.
The system must be restarted after all gsettings configurations have been set in order for CIS-CAT Assessor to appropriately assess.
OR/IF - A user profile does not exist:
/etc/dconf/profile/gdm with the following lines:user-db:user
system-db:gdm
file-db:/usr/share/gdm/greeter-dconf-defaults
Note: gdm is the name of a dconf database.
/etc/dconf/db/gdm.d/00-login-screen:[org/gnome/login-screen]
# Do not show the user list
disable-user-list=true
# dconf update
Note: When the user profile is created or changed, the user will need to log out and log in again before the changes will be applied.
false
If a different GUI login service is in use and required on the system, consult your documentation to disable displaying the user list.
MITRE ATT&CK Mappings: T1078, T1078.001, T1078.002, T1078.003, T1087, T1087.001, T1087.002 | TA0007 | M1028