All authors
CyberStrikeus avatar

Claude Skills by CyberStrikeus

github.com/CyberStrikeus
1,315 skillsA× 1,256B× 57D× 20 installs317 views
Cis Ubuntu2004 V300 6 3 2 4A

Ensure system warns when audit logs are low on space

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 1B

Ensure changes to system administration scope (sudoers) is collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 10A

Ensure successful file system mounts are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 11A

Ensure session initiation information is collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 12A

Ensure login and logout events are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 13A

Ensure file deletion events by users are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 14A

Ensure events that modify the system's Mandatory Access Controls are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 15A

Ensure successful and unsuccessful attempts to use the chcon command are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 16A

Ensure successful and unsuccessful attempts to use the setfacl command are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 17A

**Control:** Ensure successful and unsuccessful attempts to use the chacl command are collected **Profile Applicability:** Level 2 - Server, Level 2 - Workstation **Description:** The operating system must generate audit records for successful/unsuccessful uses of the chacl command. chacl is an IRIX-compatibility command, and is maintained for those users who are familiar with its use from either XFS or IRIX. **Rationale:** chacl changes the ACL(s) for a file or directory. Without generating ...

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 18A

**Control:** Ensure successful and unsuccessful attempts to use the usermod command are collected **Profile Applicability:** Level 2 - Server, Level 2 - Workstation **Description:** The operating system must generate audit records for successful/unsuccessful uses of the usermod command. **Rationale:** The usermod command modifies the system account files to reflect the changes that are specified on the command line. Without generating audit records that are specific to the security and missio...

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 19A

**Control:** Ensure kernel module loading unloading and modification is collected **Profile Applicability:** Level 2 - Server, Level 2 - Workstation **Description:** Monitor the loading and unloading of kernel modules. All the loading / listing / dependency checking of modules is done by kmod via symbolic links. The following system calls control loading and unloading of modules: - init_module - load a module - finit_module - load a module (used when the overhead of using cryptographically si...

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 2A

Ensure actions as another user are always logged

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 20A

**Control:** Ensure the audit configuration is immutable **Profile Applicability:** Level 2 - Server, Level 2 - Workstation **Description:** Set system audit so that audit rules cannot be modified with auditctl. Setting the flag "-e 2" forces audit to be put in immutable mode. Audit changes can only be made on system reboot. Note: This setting will require the system to be rebooted to update the active auditd configuration settings. **Rationale:** In immutable mode, unauthorized users cannot ...

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 21A

**Control:** Ensure the running and on disk configuration is the same **Profile Applicability:** Level 2 - Server, Level 2 - Workstation **Description:** Verify that the on disk and running audit configurations are the same to ensure that audit logging is consistent and captures all expected events. **Rationale:** Ensuring the on disk and running configurations match prevents situations where audit rules are configured but not active, potentially missing critical security events. Discrepancie...

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 3B

Ensure events that modify the sudo log file are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 4A

Ensure events that modify date and time information are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 5B

Ensure events that modify the system's network environment are collected

securitygoswift
0
291
Cis Ubuntu2004 V300 6 3 3 6A

Ensure use of privileged commands are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 7A

Ensure unsuccessful file access attempts are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 8B

Ensure events that modify user/group information are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 3 9A

Ensure discretionary access control permission modification events are collected

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 4 1A

- Level 2 - Server - Level 2 - Workstation

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 4 10A

- Level 2 - Server - Level 2 - Workstation

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 4 2A

- Level 2 - Server - Level 2 - Workstation

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 4 3A

- Level 2 - Server - Level 2 - Workstation

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 4 4A

- Level 2 - Server - Level 2 - Workstation

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 4 5A

- Level 2 - Server - Level 2 - Workstation

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 4 6A

- Level 2 - Server - Level 2 - Workstation

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 4 7A

- Level 2 - Server - Level 2 - Workstation

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 4 8A

- Level 2 - Server - Level 2 - Workstation

securitygobash
0
291
Cis Ubuntu2004 V300 6 3 4 9A

- Level 2 - Server - Level 2 - Workstation

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 1B

Ensure access to /etc/passwd is configured

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 10A

Ensure access to /etc/security/opasswd is configured

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 11A

Ensure world writable files and directories are secured

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 12A

Ensure no files or directories without an owner and a group exist

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 13A

Ensure SUID and SGID files are reviewed

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 2B

Ensure access to /etc/passwd- is configured

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 3A

Ensure access to /etc/group is configured

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 4A

Ensure access to /etc/group- is configured

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 5B

Ensure access to /etc/shadow is configured

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 6B

Ensure access to /etc/shadow- is configured

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 7A

Ensure access to /etc/gshadow is configured

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 8A

Ensure access to /etc/gshadow- is configured

securitygobash
0
291
Cis Ubuntu2004 V300 7 1 9A

Ensure access to /etc/shells is configured

securitygoshell
0
291
Cis Ubuntu2004 V300 7 2 1B

Ensure accounts in /etc/passwd use shadowed passwords

securitygobash
0
291
Cis Ubuntu2004 V300 7 2 10B

Ensure local interactive user dot files access is configured

securityrustgo
0
291
Cis Ubuntu2004 V300 7 2 2B

Ensure /etc/shadow password fields are not empty

securitygobash
0
291
Cis Ubuntu2004 V300 7 2 3B

Ensure all groups in /etc/passwd exist in /etc/group

securitygobash
0
291
Cis Ubuntu2004 V300 7 2 4B

Ensure shadow group is empty

securitygobash
0
291