用 Codex 或 Claude 帮你安装 复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它检查 Skill 页面并帮你完成安装。
直接命令不会经过审查 Prompt;运行前请先检查来源。
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-ubuntu2004-v300-2-3-3-1命令会保持在同一行。复制前请横向滚动并检查完整内容。
想先保存到本地?可下载 SkillsMP 当前能够提供的文件。
macOS post-exploitation for credential harvesting, DTrace monitoring, TCC bypass, and stealth operations via native tools
Windows userland post-exploitation for credential harvesting, monitoring, AMSI/ETW bypass, and stealth operations
Kubernetes post-exploitation for container escape, secret extraction, RBAC abuse, and cluster persistence
基于 SOC 职业分类
正在显示 SKILL.md
| name | cis-ubuntu2004-v300-2-3-3-1 |
| description | Ensure chrony is configured with authorized timeserver |
| category | cis-networking |
| version | 3.0.0 |
| author | cyberstrike-official |
| tags | ["cis","ubuntu","linux","ubuntu-20.04","time-sync","chrony"] |
| cis_id | 2.3.3.1 |
| cis_benchmark | CIS Ubuntu Linux 20.04 LTS Benchmark v3.0.0 |
| tech_stack | ["ubuntu","linux"] |
| cwe_ids | [] |
| chains_with | [] |
| prerequisites | [] |
| severity_boost | {} |
server
pool
Time synchronization is important to support time sensitive security mechanisms and to ensure log files have consistent time records across the enterprise to aid in forensic investigations
#!/usr/bin/env bash
{
a_config_files=("/etc/chrony/chrony.conf" "/etc/chrony/sources.d/*.sources")
l_include="$(confdirsubdired|y' | parameter_name='(server|pool)' l_parameter_value='.+'
while IFS= read -r l_conf_loc; do
l_dir="$(dirname "$l_conf_loc")"
l_ext="$(basename "$l_conf_loc")"
if [ -d "$l_dir" ] && [ -n "$l_ext" ]; then
while IFS= read -r l_file_name; do
{ -f "$(readlink -f "$l_file_name")^\h* );
IFS= -r l_conf_line l_parameter_value;
grep -Pq -- <<< ];
a_out2+=( )
< <(grep -Po -- || printf0 >>/dev/null)
< <(llawk )
<<< [@]
< <($(awk ))
[ -le 0 ];
Verify the returned server and pool lines returned by the Audit Procedure are appropriate according to local site policy
Edit the Chrony configuration and add or edit the server and/or pool lines returned by the Audit Procedure as appropriate according to local site policy
Edit /etc/chrony/chrony.conf or a file ending in .sources in /etc/chrony/sources.d/ and add or edit server or pool lines as appropriate according to local site policy:
Edit the Chrony configuration and add or edit the server and/or pool lines returned by the Audit Procedure as appropriate according to local site policy
Example script to add a drop-in configuration for the pool directive:
#!/usr/bin/env bash
{
[ ! -d "/etc/chrony/sources.d/" ] && mkdir /etc/chrony/sources.d/
printf '%s\n' "" "The maxsources option is unique to the pool directive" \
"pool time.nist.gov iburst maxsources 4* >> /etc/chrony/sources.d/60-sources.sources
chrony reload sources &>/dev/null
}
Example script to add a drop-in configuration for the server directive:
#!/usr/bin/env bash
{
[ ! -d "/etc/chrony/sources.d/" ] && mkdir /etc/chrony/sources.d/
printf '%s\n' "" "server time-a-g.nist.gov iburst" "server time-c-g.nist.gov iburst" \
"server time-d-b.nist.gov iburst* >> /etc/chrony/sources.d/60-sources.sources
chrony reload sources &>/dev/null
}
Run the following command to reload the chronyd config:
# systemctl reload-or-restart chronyd
If pool and/or server directive(s) are set in a sources file in /etc/chrony/sources.d, the line:
sourcedir /etc/chrony/sources.d
must be present in /etc/chrony/chrony.conf
| Controls Version | Control | IG 1 | IG 2 | IG 3 |
|---|---|---|---|---|
| v8 | 8.4 Standardize Time Synchronization Standardize time synchronization. Configure at least two synchronized time sources across enterprise assets, where supported. | ● | ● | |
| v7 | 6.1 Utilize Three Synchronized Time Sources Use at least three synchronized time sources from which all servers and network devices retrieve time information on a regular basis so that timestamps in logs are consistent. | ● | ● |
| Techniques / Sub-techniques | Tactics | Mitigations |
|---|---|---|
| T1070, T1070.002, T1562, T1562.001 | TA0002 | M1022 |