Item Search

NameAudit NamePluginCategory
1.1.10 Set 'aaa accounting network'CIS Cisco IOS 12 L2 v4.0.0Cisco

AUDIT AND ACCOUNTABILITY

1.36 SOL-11.1-020040CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.36 SOL-11.1-020040CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.37 SOL-11.1-020050CIS Solaris 11 X86 STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.39 SOL-11.1-020080CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

AUDIT AND ACCOUNTABILITY

1.73 (L1) Ensure 'Configure the list of names that will bypass the HSTS policy check' is set to 'Disabled'CIS Microsoft Intune for Edge v1.0.0 L1Windows

CONFIGURATION MANAGEMENT

1.108 SOL-11.1-040400CIS Solaris 11 SPARC STIG v1.0.0 CAT IIUnix

CONFIGURATION MANAGEMENT

2.1.2.2 Ensure show H.323 contacts is set to disabledCIS Zoom L2 v1.0.0Zoom

CONFIGURATION MANAGEMENT

2.2.1 Ensure emergency access account activity is monitoredCIS Microsoft 365 Foundations v7.0.0 L1 E5microsoft_azure

AUDIT AND ACCOUNTABILITY

3.19 (L1) Host must have an accurate Exception Users listCIS VMware ESXi 8.0 v1.3.0 L1 VMwareVMware

ACCESS CONTROL, MEDIA PROTECTION

5.1 Do Not Specify Passwords in the Command LineCIS PostgreSQL 14 OS v 1.3.0Unix

ACCESS CONTROL, IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.4.3 Ensure password hashing algorithm is SHA-512CIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.4.3 Ensure password hashing algorithm is SHA-512 - password-authCIS Red Hat Enterprise Linux 7 STIG v2.0.0 L1 ServerUnix

IDENTIFICATION AND AUTHENTICATION, SYSTEM AND COMMUNICATIONS PROTECTION

5.4.7 Ensure minimum and maximum requirements are set for password changes - difokCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.4.7 Ensure minimum and maximum requirements are set for password changes - minclassCIS Red Hat Enterprise Linux 7 STIG v2.0.0 STIGUnix

IDENTIFICATION AND AUTHENTICATION

5.12 Ensure changes to network gateways are monitoredCIS Amazon Web Services Foundations v7.0.0 L1amazon_aws

AUDIT AND ACCOUNTABILITY

6.2.3.11 Ensure events that modify /etc/group information are collectedCIS Debian Linux 12 v2.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.11 Ensure events that modify /etc/group information are collectedCIS Debian Linux 12 v2.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.11 Ensure events that modify /etc/group information are collectedCIS Ubuntu Linux 24.04 LTS v2.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.12 Ensure events that modify /etc/passwd information are collectedCIS Ubuntu Linux 24.04 LTS v2.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.12 Ensure events that modify /etc/passwd information are collectedCIS Debian Linux 12 v2.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

6.2.3.15 Ensure events that modify /etc/nsswitch.conf file are collectedCIS Debian Linux 12 v2.0.0 L2 WorkstationUnix

AUDIT AND ACCOUNTABILITY

6.2.3.15 Ensure events that modify /etc/nsswitch.conf file are collectedCIS Ubuntu Linux 24.04 LTS v2.0.0 L2 ServerUnix

AUDIT AND ACCOUNTABILITY

17.9.1 Ensure 'Audit IPsec Driver' is set to 'Success and Failure'CIS Microsoft Windows 8.1 v2.4.1 L1Windows

AUDIT AND ACCOUNTABILITY

Enable port locking by default on the VM guest networkTNS Citrix HypervisorUnix

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure 'logging to monitor' is disabled - show loggingTenable Cisco Firepower Threat Defense Best Practices AuditCisco_Firepower

AUDIT AND ACCOUNTABILITY

Ensure events that modify the system's network environment are collected - auditctl b64 sethostnameTenable Cisco Firepower Management Center OS Best Practices AuditUnix

AUDIT AND ACCOUNTABILITY

Ensure events that modify the system's network environment are collected - b64 sethostnameTenable Cisco Firepower Management Center OS Best Practices AuditUnix

AUDIT AND ACCOUNTABILITY

ESXI-06-000075 - The connectivity between VSAN Health Check and public Hardware Compatibility List must be disabled or restricted by use of an external proxy server.DISA VMware vSphere ESXi 6.0 STIG v1r5VMware

CONFIGURATION MANAGEMENT

ESXI-80-000201 - The ESXi host lockdown mode exception users list must be verified.DISA VMware vSphere 8.0 ESXi STIG v2r3 VMwareVMware

CONFIGURATION MANAGEMENT

F5BI-AP-300059 - The F5 BIG-IP appliance providing content filtering must employ rate-based attack prevention behavior analysis.DISA F5 BIG-IP TMOS ALG STIG v1r3F5

SYSTEM AND COMMUNICATIONS PROTECTION

IIST-SI-000216 - The IIS 10.0 website must have resource mappings set to disable the serving of certain file types.DISA IIS 10.0 Site v2r14Windows

CONFIGURATION MANAGEMENT

IISW-SI-000215 - Mappings to unused and vulnerable scripts on the IIS 8.5 website must be removed.DISA IIS 8.5 Site v2r9Windows

CONFIGURATION MANAGEMENT

Management Access Policy - HTTPS - Cipher ConfigurationTenable Cisco ACICisco_ACI
Monitor file and program activity on your computerMSCT Windows 11 v25H2 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

Monitor file and program activity on your computerMSCT Windows 11 v24H2 v1.0.0Windows

SYSTEM AND INFORMATION INTEGRITY

OL6-00-000198 - The audit system must be configured to audit all use of setuid and setgid programs.DISA STIG Oracle Linux 6 v2r7Unix

ACCESS CONTROL

RHEL-07-010344 - The Red Hat Enterprise Linux operating system must not be configured to bypass password requirements for privilege escalation.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

IDENTIFICATION AND AUTHENTICATION

RHEL-07-020021 - The Red Hat Enterprise Linux operating system must confine SELinux users to roles that conform to least privilege.DISA Red Hat Enterprise Linux 7 STIG v3r15Unix

ACCESS CONTROL

SLEM-05-611070 - SLEM 5 must employ user passwords with a maximum lifetime of 60 days.DISA SUSE Linux Enterprise Micro SLEM 5 STIG v1r4Unix

IDENTIFICATION AND AUTHENTICATION

SOL-11.1-020030 - The operating system must protect audit tools from unauthorized access.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020030 - The operating system must protect audit tools from unauthorized access.DISA Solaris 11 X86 STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020040 - The operating system must protect audit tools from unauthorized modification.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020050 - The operating system must protect audit tools from unauthorized deletion.DISA Solaris 11 X86 STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020080 - System packages must be configured with the vendor-provided files, permissions, and ownerships.DISA Solaris 11 SPARC STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-020080 - System packages must be configured with the vendor-provided files, permissions, and ownerships.DISA Solaris 11 X86 STIG v3r6Unix

AUDIT AND ACCOUNTABILITY

SOL-11.1-040400 - The use of FTP must be restricted.DISA Solaris 11 SPARC STIG v3r6Unix

CONFIGURATION MANAGEMENT

SOL-11.1-040400 - The use of FTP must be restricted.DISA Solaris 11 X86 STIG v3r6Unix

CONFIGURATION MANAGEMENT

SP13-00-000055 - SharePoint must allow designated organizational personnel to select which auditable events are to be audited by specific components of the system.DISA Microsoft SharePoint 2013 STIG v2r4Windows

AUDIT AND ACCOUNTABILITY

VCWN-06-000053 - The connectivity between VSAN Health Check and public Hardware Compatibility List must be disabled or restricted.DISA VMware vSphere vCenter Server Version 6 STIG v1r4VMware

CONFIGURATION MANAGEMENT