
Claude Skills by CyberStrikeus
github.com/CyberStrikeusApply Security Context to Your Pods and Containers (Manual)
The default namespace should not be used (Manual)
Restrict GPU and USB pass through to approved devices (Manual)
Restrict namespace administrator access to migration tools (Manual)
Restrict exec access to the pods (Manual)
Restrict VNC access to cluster workloads (Manual)
Restrict access to create and modify the Virtual Machine Cluster Instance and Preference Types (Manual)
Restrict update access to the CDI CR (Manual)
Enable nonRoot feature gate in OCPvirt prior to 4.18 (Automated)
Disable persistentReservations feature gate (Automated)
Disable downwardMetrics feature gate (Automated)
Enforce the use of trusted registries using TLS (Automated)
Restrict patching operations in the annotations for Hyperconverged (Manual)
Ensure KSM is disabled (Automated)
Ensure kubevirt seccomp profile file permission is set to 700 or more restrictive (Automated)
Ensure kubevirt cache directory permission is set to 755 or more restrictive (Automated)
Restrict pass through of GPUs and Host devices to the Virtual Machine (Manual)
Disable overcommitting guest memory (Manual)
Restrict access to cross datavolumes cloning (Manual)
Disable Shareable disks (Automated)
Ensure errorPolicy is not set to ignore (Manual)
Use dedicated VLANs to segment network traffic (Automated)
Enable MAC spoof filtering (Automated)
Use multi-network policies (Manual)
Disable Intel Trusted Execution Technology (TXT) (Manual)
Disable nested virtualization (Manual)
Enable vCPU metrics (Manual)
Ensure all CPU vulnerabilities are mitigated (Manual)
Ensure NGINX is installed (Manual)
Ensure package manager repositories are properly configured (Manual)
Ensure the latest software package is installed (Manual)
Ensure only required dynamic modules are loaded (Manual)
Ensure that NGINX is run using a non-privileged, dedicated service account (Manual)
Ensure the NGINX service account is locked (Manual)
Ensure the NGINX service account has an invalid shell (Manual)
Ensure NGINX directories and files are owned by root (Manual)
Ensure access to NGINX directories and files is restricted (Manual)
Ensure the NGINX process ID (PID) file is secured (Manual)
Ensure NGINX only listens for network connections on authorized ports (Manual)
Ensure requests for unknown host names are rejected (Manual)
Ensure keepalive_timeout is 10 seconds or less, but not 0 (Manual)
Ensure send_timeout is set to 10 seconds or less, but not 0 (Manual)
Ensure server_tokens directive is set to off (Manual)
Ensure default error and index.html pages do not reference NGINX (Manual)
Ensure hidden file serving is disabled (Manual)
Ensure the NGINX reverse proxy does not enable information disclosure (Manual)
Ensure detailed logging is enabled (Manual)
Ensure access logging is enabled (Manual)
Ensure error logging is enabled and set to the info logging level (Manual)
Ensure proxies pass source IP information (Manual)