Verify that packets with un-routable source addresses are logged for investigation
原文语言:英语
菜单
这个仓库中的 skills
SkillsMP 已收集 CyberStrikeus/CyberStrike 中的 7,442 个 Skill。打开任一 Skill 可查看来源和详情。
CyberStrikeus/CyberStrike已展示 40 / 7,442 个已收集 Skill。
Verify that packets with un-routable source addresses are logged for investigation
原文语言:英语
Verify that TCP SYN Cookies are enabled to protect against SYN flood attacks
原文语言:英语
Verify that IPv6 is disabled if not required to reduce the attack surface
原文语言:英语
Verify that TCP Wrappers is installed for host-based access control
原文语言:英语
Verify that /etc/hosts.allow is configured to permit authorized network access
原文语言:英语
Verify that /etc/hosts.deny is configured to deny all unauthorized network access
原文语言:英语
Verify that iptables is installed for firewall management and configuration
原文语言:英语
Verify that default deny firewall policy is configured for INPUT, OUTPUT, and FORWARD chains
原文语言:英语
Verify that loopback interface accepts traffic and other interfaces deny loopback network traffic
原文语言:英语
Verify that wireless interfaces are disabled to reduce the attack surface
原文语言:英语
Enable the auditd daemon to record system events for security monitoring
原文语言:英语
Enable the rsyslog service to ensure system logging is active
原文语言:英语
Configure rsyslog to capture appropriate logging for all facilities
原文语言:英语
Enable the syslog-ng service to ensure system logging is active
原文语言:英语
Configure syslog-ng to capture appropriate logging for all facilities
原文语言:英语
Configure logrotate to ensure logs are rotated regularly to prevent disk exhaustion
原文语言:英语
Verify the cron daemon is enabled to execute scheduled batch jobs on the system
原文语言:英语
Verify SSH access is limited using AllowUsers, AllowGroups, DenyUsers, or DenyGroups directives
原文语言:英语
Verify SSH is configured to use Protocol version 2 only
原文语言:英语
Verify SSH X11 forwarding is disabled to prevent remote graphic connection tunneling
原文语言:英语
Verify SSH IgnoreRhosts is set to yes to prevent .rhosts-based authentication
原文语言:英语
Verify SSH PermitRootLogin is set to no to prevent direct root login over SSH
原文语言:英语
Verify PAM is configured to remember at least 5 previous passwords to prevent reuse
原文语言:英语
Verify system accounts have non-login shells and are locked to prevent interactive access
原文语言:英语
Find and remediate world writable files across all local filesystems
原文语言:英语
Identify and review all SUID executables to ensure they are legitimate
原文语言:英语
Identify and review all SGID executables to ensure they are legitimate
原文语言:英语
Verify all accounts in /etc/shadow have a password or are locked
原文语言:英语
Verify no users have .forward files in their home directories
原文语言:英语
Verify no users have .netrc files in their home directories
原文语言:英语
Verify no users have .rhosts files in their home directories
原文语言:英语
Verify no duplicate User IDs exist in /etc/passwd
原文语言:英语
Verify no duplicate Group IDs exist in /etc/group
原文语言:英语
Verify no duplicate user names exist in /etc/passwd
原文语言:英语
Verify the shadow group has no users assigned to it
原文语言:英语
Verify that only the root account has UID 0
原文语言:英语
Verify root PATH does not contain writable or non-root-owned directories
原文语言:英语
Ensure mounting of cramfs filesystems is disabled
原文语言:英语
Ensure mounting of freevxfs filesystems is disabled
原文语言:英语
Ensure mounting of jffs2 filesystems is disabled
原文语言:英语