Skill Claude CodeCodex
Ensure Secrets and Sensitive Data are not stored directly in EC2 User Data.
Open-source AI-powered offensive security harness for automated penetration testing.
CyberStrike is an open-source AI security harness that automates penetration testing by using language models as agents for reconnaissance, vulnerability discovery, exploitation, and reporting. Security practitioners use it to test systems from a terminal, and the catalogue contains skills and settings for its workflow.
This repository also configures its own agents. See what CyberStrike tells them →
Skill Claude CodeCodex
Ensure Secrets and Sensitive Data are not stored directly in EC2 User Data.
Skill Claude CodeCodex
Ensure EC2 Auto Scaling Groups Propagate Tags to EC2 Instances that it launches.
Skill Claude CodeCodex
Ensure EBS volume encryption is enabled.
Skill Claude CodeCodex
Ensure Public Access to EBS Snapshots is Disabled.
Skill Claude CodeCodex
Ensure EBS volume snapshots are encrypted.
Skill Claude CodeCodex
Ensure unused EBS volumes are removed.
Skill Claude CodeCodex
Ensure Tag Policies are Enabled.
Skill Claude CodeCodex
Ensure an Organizational EC2 Tag Policy has been Created.
Skill Claude CodeCodex
Ensure no AWS EC2 Instances are Older than 180 days.
Skill Claude CodeCodex
Ensure detailed monitoring is enabled for production EC2 Instances.
Skill Claude CodeCodex
Ensure Default EC2 Security groups are not being used.
Skill Claude CodeCodex
Ensure the Use of IMDSv2 is Enforced on All Existing Instances.
Skill Claude CodeCodex
Ensure use of AWS Systems Manager to manage EC2 instances.
Skill Claude CodeCodex
Ensure Amazon ECS task definitions using 'host' network mode do not allow privileged or root user access to the host.
Skill Claude CodeCodex
Ensure Amazon ECS services are tagged.
Skill Claude CodeCodex
Ensure Amazon ECS clusters are tagged.
Skill Claude CodeCodex
Ensure Amazon ECS task definitions are tagged.
Skill Claude CodeCodex
Ensure only trusted images are used with Amazon ECS.
Skill Claude CodeCodex
Ensure 'assignPublicIp' is set to 'DISABLED' for Amazon ECS task sets.
Skill Claude CodeCodex
Ensure 'assignPublicIp' is set to 'DISABLED' for Amazon ECS services.
Skill Claude CodeCodex
Ensure Amazon ECS task definitions do not have 'pidMode' set to 'host'.
Skill Claude CodeCodex
Ensure Amazon ECS task definitions do not have 'privileged' set to 'true'.
Skill Claude CodeCodex
Ensure 'readonlyRootFilesystem' is set to 'true' for Amazon ECS task definitions.
Skill Claude CodeCodex
Ensure secrets are not passed as container environment variables in Amazon ECS task definitions.
At most 3 mods per repository are shown here, and a mod shipped inside a plugin is left to that plugin's page — the rest are on their repository pages: