
Claude Skills by CyberStrikeus
github.com/CyberStrikeusEnsure HTTP is redirected to HTTPS (Manual)
Ensure the upstream traffic server certificate is trusted (Manual)
Ensure Secure Session Resumption is Enabled (Manual)
Ensure HTTP/3.0 is used (Manual)
Ensure a trusted certificate and trust chain is installed (Manual)
Ensure private key permissions are restricted (Manual)
Ensure only modern TLS protocols are used (Manual)
Disable weak ciphers (Manual)
Ensure awareness of TLS 1.3 new Diffie-Hellman parameters (Manual)
Ensure Online Certificate Status Protocol (OCSP) stapling is enabled (Manual)
Ensure HTTP Strict Transport Security (HSTS) is enabled (Manual)
Ensure upstream server traffic is authenticated with a client certificate (Manual)
Ensure allow and deny filters limit access to specific IP addresses (Manual)
Ensure only approved HTTP methods are allowed (Manual)
Ensure timeout values for reading the client header and body are set correctly (Manual)
Ensure the maximum request body size is set correctly (Manual)
Ensure the maximum buffer size for URIs is defined (Manual)
Ensure the number of connections per IP address is limited (Manual)
Ensure rate limits by IP address are set (Manual)
Ensure X-Content-Type-Options header is configured and enabled (Manual)
Ensure that Content Security Policy (CSP) is enabled and configured properly (Manual)
Ensure the Referrer Policy is enabled and configured properly (Manual)
Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents
Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events
A baseline of network operations and expected data flows for users and systems is established and managed
Potentially adverse events are analyzed to better understand associated activities
Information is correlated from multiple sources
The estimated impact and scope of adverse events are understood
Incident alert thresholds are established
Information on adverse events is provided to authorized staff and tools
Cyber threat intelligence and other contextual information are integrated into the analysis
Incidents are declared when adverse events meet the defined incident criteria
Networks and network services are monitored to find potentially adverse events
The physical environment is monitored to find potentially adverse events
Personnel activity and technology usage are monitored to find potentially adverse events
Malicious code is detected
Unauthorized mobile code is detected
External service provider activities and services are monitored to find potentially adverse events
Monitoring for unauthorized personnel, connections, devices, and software is performed
Vulnerability scans are performed
Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events
Roles and responsibilities for detection are well defined to ensure accountability
Detection activities comply with all applicable requirements
Detection processes are tested
Event detection information is communicated
Detection processes are continuously improved
Detection Processes
Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders
The organizational mission is understood and informs cybersecurity risk management
Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and conside