Skill Claude CodeCodex
Ensure IAM password policy requires minimum length of 14 or greater.
Open-source AI-powered offensive security harness for automated penetration testing.
CyberStrike is an open-source AI security harness that automates penetration testing by using language models as agents for reconnaissance, vulnerability discovery, exploitation, and reporting. Security practitioners use it to test systems from a terminal, and the catalogue contains skills and settings for its workflow.
This repository also configures its own agents. See what CyberStrike tells them →
Skill Claude CodeCodex
Ensure IAM password policy requires minimum length of 14 or greater.
Skill Claude CodeCodex
Ensure IAM password policy prevents password reuse.
Skill Claude CodeCodex
Ensure S3 Bucket Policy is set to deny HTTP requests.
Skill Claude CodeCodex
Ensure MFA Delete is enabled on S3 buckets.
Skill Claude CodeCodex
Ensure all data in Amazon S3 has been discovered, classified, and secured when necessary.
Skill Claude CodeCodex
Ensure that S3 is configured with 'Block Public Access' enabled.
Skill Claude CodeCodex
Ensure that encryption-at-rest is enabled for RDS instances.
Skill Claude CodeCodex
Ensure the Auto Minor Version Upgrade feature is enabled for RDS instances.
Skill Claude CodeCodex
Ensure that RDS instances are not publicly accessible.
Skill Claude CodeCodex
Ensure Multi-AZ deployments are used for enhanced availability in Amazon RDS.
Skill Claude CodeCodex
Ensure that encryption is enabled for EFS file systems.
Skill Claude CodeCodex
Ensure CloudTrail is enabled in all regions.
Skill Claude CodeCodex
Ensure all AWS-managed web front-end services have access logging enabled.
Skill Claude CodeCodex
Ensure CloudTrail log file validation is enabled.
Skill Claude CodeCodex
Ensure AWS Config is enabled in all regions.
Skill Claude CodeCodex
Ensure that server access logging is enabled on the CloudTrail S3 bucket.
Skill Claude CodeCodex
Ensure CloudTrail logs are encrypted at rest using KMS CMKs.
Skill Claude CodeCodex
Ensure rotation for customer-created symmetric CMKs is enabled.
Skill Claude CodeCodex
Ensure VPC flow logging is enabled in all VPCs.
Skill Claude CodeCodex
Ensure that object-level logging for write events is enabled for S3 buckets.
Skill Claude CodeCodex
Ensure that object-level logging for read events is enabled for S3 buckets.
Skill Claude CodeCodex
Ensure unauthorized API calls are monitored.
Skill Claude CodeCodex
Ensure security group changes are monitored.
Skill Claude CodeCodex
Ensure Network Access Control List (NACL) changes are monitored.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: