All authors

Claude Skills by CyberStrikeus
github.com/CyberStrikeus7,689 skills0 installs16,544 views
- Cis K8s V1120 4.2.8Ensure that the eventRecordQPS argument is set to a level which ensures appropriate event capture (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 4.2.9Ensure that the --tls-cert-file and --tls-private-key-file arguments are set as appropriate (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 4.3.1Ensure that the kube-proxy metrics service is bound to localhost (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.1Ensure that the cluster-admin role is only used where required (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.10Minimize access to the proxy sub-resource of nodes (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.11Minimize access to the approval sub-resource of certificatesigningrequests objects (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.12Minimize access to webhook configuration objects (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.13Minimize access to the service account token creation (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.2Minimize access to secrets (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.3Minimize wildcard use in Roles and ClusterRoles (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.4Minimize access to create pods (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.5Ensure that default service accounts are not actively used (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.6Ensure that Service Account Tokens are only mounted where necessary (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.7Avoid use of system:masters group (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.8Limit use of the Bind, Impersonate and Escalate permissions in the Kubernetes cluster (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.1.9Minimize access to create persistent volumes (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.1Ensure that the cluster has at least one active policy control mechanism in place (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.10Minimize the admission of Windows HostProcess Containers (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.11Minimize the admission of HostPath volumes (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.12Minimize the admission of containers which use HostPorts (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.2Minimize the admission of privileged containers (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.3Minimize the admission of containers wishing to share the host process ID namespace (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.4Minimize the admission of containers wishing to share the host IPC namespace (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.5Minimize the admission of containers wishing to share the host network namespace (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.6Minimize the admission of containers with allowPrivilegeEscalation (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.7Minimize the admission of root containers (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.8Minimize the admission of containers with the NET_RAW capability (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.2.9Minimize the admission of containers with capabilities assigned (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.3.1Ensure that the CNI in use supports Network Policies (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.3.2Ensure that all Namespaces have Network Policies defined (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.4.1Prefer using secrets as files over secrets as environment variables (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.4.2Consider external secret storage (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.5.1Configure Image Provenance using ImagePolicyWebhook admission controller (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.6.1Create administrative boundaries between resources using namespaces (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.6.2Ensure that the seccomp profile is set to docker/default in your pod definitions (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.6.3Apply Security Context to Your Pods and Containers (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V1120 5.6.4The default namespace should not be used (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.1Ensure that the API server pod specification file permissions are set to 600 or more restrictive (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.10Ensure that the Container Network Interface file ownership is set to root:root (Manual)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.11Ensure that the etcd data directory permissions are set to 700 or more restrictive (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.12Ensure that the etcd data directory ownership is set to etcd:etcd (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.13Ensure that the default administrative credential file permissions are set to 600 (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.14Ensure that the default administrative credential file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.15Ensure that the scheduler.conf file permissions are set to 600 or more restrictive (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.16Ensure that the scheduler.conf file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.17Ensure that the controller-manager.conf file permissions are set to 600 or more restrictive (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.18Ensure that the controller-manager.conf file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.19Ensure that the Kubernetes PKI directory and file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.2Ensure that the API server pod specification file ownership is set to root:root (Automated)Votes: 0GitHub stars: 2,182
- Cis K8s V200 1.1.20Ensure that the Kubernetes PKI certificate file permissions are set to 644 or more restrictive (Manual)Votes: 0GitHub stars: 2,182