All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs318 views
Cis Nginx V300 4 1 1A

Ensure HTTP is redirected to HTTPS (Manual)

securityrustgo
0
291
Cis Nginx V300 4 1 10A

Ensure the upstream traffic server certificate is trusted (Manual)

securityrustgo
0
291
Cis Nginx V300 4 1 11A

Ensure Secure Session Resumption is Enabled (Manual)

securitygobash
0
291
Cis Nginx V300 4 1 12A

Ensure HTTP/3.0 is used (Manual)

securitygobash
0
291
Cis Nginx V300 4 1 2A

Ensure a trusted certificate and trust chain is installed (Manual)

securityrustgo
0
291
Cis Nginx V300 4 1 3A

Ensure private key permissions are restricted (Manual)

securitygobash
0
291
Cis Nginx V300 4 1 4A

Ensure only modern TLS protocols are used (Manual)

securitygobash
0
291
Cis Nginx V300 4 1 5A

Disable weak ciphers (Manual)

securitygobash
0
291
Cis Nginx V300 4 1 6A

Ensure awareness of TLS 1.3 new Diffie-Hellman parameters (Manual)

securitygo
0
291
Cis Nginx V300 4 1 7A

Ensure Online Certificate Status Protocol (OCSP) stapling is enabled (Manual)

securityrustgo
0
291
Cis Nginx V300 4 1 8A

Ensure HTTP Strict Transport Security (HSTS) is enabled (Manual)

securitygobash
0
291
Cis Nginx V300 4 1 9A

Ensure upstream server traffic is authenticated with a client certificate (Manual)

securityrustgo
0
291
Cis Nginx V300 5 1 1A

Ensure allow and deny filters limit access to specific IP addresses (Manual)

securityrustgo
0
291
Cis Nginx V300 5 1 2A

Ensure only approved HTTP methods are allowed (Manual)

securitygobash
0
291
Cis Nginx V300 5 2 1A

Ensure timeout values for reading the client header and body are set correctly (Manual)

securitygobash
0
291
Cis Nginx V300 5 2 2A

Ensure the maximum request body size is set correctly (Manual)

securitygobash
0
291
Cis Nginx V300 5 2 3A

Ensure the maximum buffer size for URIs is defined (Manual)

securitygobash
0
291
Cis Nginx V300 5 2 4A

Ensure the number of connections per IP address is limited (Manual)

securitygobash
0
291
Cis Nginx V300 5 2 5A

Ensure rate limits by IP address are set (Manual)

securitygobash
0
291
Cis Nginx V300 5 3 1A

Ensure X-Content-Type-Options header is configured and enabled (Manual)

securityjavascriptgo
0
291
Cis Nginx V300 5 3 2A

Ensure that Content Security Policy (CSP) is enabled and configured properly (Manual)

securityjavascriptgo
0
291
Cis Nginx V300 5 3 3A

Ensure the Referrer Policy is enabled and configured properly (Manual)

securitygobash
0
291
Adverse Event Analysis (DE.AE) Adverse Event AnalysisA

Anomalies, indicators of compromise, and other potentially adverse events are analyzed to characterize the events and detect cybersecurity incidents

securitygoaws
0
291
Continuous Monitoring (DE.CM) Continuous MonitoringA

Assets are monitored to find anomalies, indicators of compromise, and other potentially adverse events

securitygoaws
0
291
DE.AE 01 Deae 01A

A baseline of network operations and expected data flows for users and systems is established and managed

securitygoaws
0
291
DE.AE 02 Deae 02A

Potentially adverse events are analyzed to better understand associated activities

securitygoaws
0
291
DE.AE 03 Deae 03A

Information is correlated from multiple sources

securitygoaws
0
291
DE.AE 04 Deae 04A

The estimated impact and scope of adverse events are understood

securitygoaws
0
291
DE.AE 05 Deae 05A

Incident alert thresholds are established

securitygoaws
0
291
DE.AE 06 Deae 06A

Information on adverse events is provided to authorized staff and tools

securitygoaws
0
291
DE.AE 07 Deae 07A

Cyber threat intelligence and other contextual information are integrated into the analysis

securitygoaws
0
291
DE.AE 08 Deae 08A

Incidents are declared when adverse events meet the defined incident criteria

securitygoaws
0
291
DE.CM 01 Decm 01A

Networks and network services are monitored to find potentially adverse events

securitygoaws
0
291
DE.CM 02 Decm 02A

The physical environment is monitored to find potentially adverse events

securitygoaws
0
291
DE.CM 03 Decm 03A

Personnel activity and technology usage are monitored to find potentially adverse events

securitygoaws
0
291
DE.CM 04 Decm 04A

Malicious code is detected

securitygoaws
0
291
DE.CM 05 Decm 05A

Unauthorized mobile code is detected

securitygoaws
0
291
DE.CM 06 Decm 06A

External service provider activities and services are monitored to find potentially adverse events

securitygoaws
0
291
DE.CM 07 Decm 07A

Monitoring for unauthorized personnel, connections, devices, and software is performed

securitygoaws
0
291
DE.CM 08 Decm 08A

Vulnerability scans are performed

securitygoaws
0
291
DE.CM 09 Decm 09A

Computing hardware and software, runtime environments, and their data are monitored to find potentially adverse events

securitygoaws
0
291
DE.DP 01 Dedp 01A

Roles and responsibilities for detection are well defined to ensure accountability

securitygoaws
0
291
DE.DP 02 Dedp 02A

Detection activities comply with all applicable requirements

securitygoaws
0
291
DE.DP 03 Dedp 03A

Detection processes are tested

securitygoaws
0
291
DE.DP 04 Dedp 04A

Event detection information is communicated

securitygoaws
0
291
DE.DP 05 Dedp 05A

Detection processes are continuously improved

securitygoaws
0
291
Detection Processes (DE.DP) Detection ProcessesA

Detection Processes

securitygoaws
0
291
Cybersecurity Supply Chain Risk Management (GV.SC) Cybersecurity Supply Chain Risk ManagementA

Cyber supply chain risk management processes are identified, established, managed, monitored, and improved by organizational stakeholders

securitygosecurity
0
291
GV.OC 01 Gvoc 01A

The organizational mission is understood and informs cybersecurity risk management

securitygosecurity
0
291
GV.OC 02 Gvoc 02A

Internal and external stakeholders are understood, and their needs and expectations regarding cybersecurity risk management are understood and conside

securitygosecurity
0
291