
Claude Skills by CyberStrikeus
github.com/CyberStrikeusEnsure system warns when audit logs are low on space
Ensure changes to system administration scope (sudoers) is collected
Ensure successful file system mounts are collected
Ensure session initiation information is collected
Ensure login and logout events are collected
Ensure file deletion events by users are collected
Ensure events that modify the system's Mandatory Access Controls are collected
Ensure successful and unsuccessful attempts to use the chcon command are collected
Ensure successful and unsuccessful attempts to use the setfacl command are collected
**Control:** Ensure successful and unsuccessful attempts to use the chacl command are collected **Profile Applicability:** Level 2 - Server, Level 2 - Workstation **Description:** The operating system must generate audit records for successful/unsuccessful uses of the chacl command. chacl is an IRIX-compatibility command, and is maintained for those users who are familiar with its use from either XFS or IRIX. **Rationale:** chacl changes the ACL(s) for a file or directory. Without generating ...
**Control:** Ensure successful and unsuccessful attempts to use the usermod command are collected **Profile Applicability:** Level 2 - Server, Level 2 - Workstation **Description:** The operating system must generate audit records for successful/unsuccessful uses of the usermod command. **Rationale:** The usermod command modifies the system account files to reflect the changes that are specified on the command line. Without generating audit records that are specific to the security and missio...
**Control:** Ensure kernel module loading unloading and modification is collected **Profile Applicability:** Level 2 - Server, Level 2 - Workstation **Description:** Monitor the loading and unloading of kernel modules. All the loading / listing / dependency checking of modules is done by kmod via symbolic links. The following system calls control loading and unloading of modules: - init_module - load a module - finit_module - load a module (used when the overhead of using cryptographically si...
Ensure actions as another user are always logged
**Control:** Ensure the audit configuration is immutable **Profile Applicability:** Level 2 - Server, Level 2 - Workstation **Description:** Set system audit so that audit rules cannot be modified with auditctl. Setting the flag "-e 2" forces audit to be put in immutable mode. Audit changes can only be made on system reboot. Note: This setting will require the system to be rebooted to update the active auditd configuration settings. **Rationale:** In immutable mode, unauthorized users cannot ...
**Control:** Ensure the running and on disk configuration is the same **Profile Applicability:** Level 2 - Server, Level 2 - Workstation **Description:** Verify that the on disk and running audit configurations are the same to ensure that audit logging is consistent and captures all expected events. **Rationale:** Ensuring the on disk and running configurations match prevents situations where audit rules are configured but not active, potentially missing critical security events. Discrepancie...
Ensure events that modify the sudo log file are collected
Ensure events that modify date and time information are collected
Ensure events that modify the system's network environment are collected
Ensure use of privileged commands are collected
Ensure unsuccessful file access attempts are collected
Ensure events that modify user/group information are collected
Ensure discretionary access control permission modification events are collected
- Level 2 - Server - Level 2 - Workstation
- Level 2 - Server - Level 2 - Workstation
- Level 2 - Server - Level 2 - Workstation
- Level 2 - Server - Level 2 - Workstation
- Level 2 - Server - Level 2 - Workstation
- Level 2 - Server - Level 2 - Workstation
- Level 2 - Server - Level 2 - Workstation
- Level 2 - Server - Level 2 - Workstation
- Level 2 - Server - Level 2 - Workstation
- Level 2 - Server - Level 2 - Workstation
Ensure access to /etc/passwd is configured
Ensure access to /etc/security/opasswd is configured
Ensure world writable files and directories are secured
Ensure no files or directories without an owner and a group exist
Ensure SUID and SGID files are reviewed
Ensure access to /etc/passwd- is configured
Ensure access to /etc/group is configured
Ensure access to /etc/group- is configured
Ensure access to /etc/shadow is configured
Ensure access to /etc/shadow- is configured
Ensure access to /etc/gshadow is configured
Ensure access to /etc/gshadow- is configured
Ensure access to /etc/shells is configured
Ensure accounts in /etc/passwd use shadowed passwords
Ensure local interactive user dot files access is configured
Ensure /etc/shadow password fields are not empty
Ensure all groups in /etc/passwd exist in /etc/group
Ensure shadow group is empty