Item Search

NameAudit NamePluginCategory
1.19 Ensure 'Improve harmful app detection' is set to 'Enabled'MobileIron - CIS Google Android v1.3.0 L1MDM
1.21 Ensure 'Improve harmful app detection' is set to EnabledMobileIron - CIS Google Android 7 v1.0.0 L1MDM
1.21 Ensure 'Improve harmful app detection' is set to EnabledAirWatch - CIS Google Android 7 v1.0.0 L1MDM
3.1.1.1.4 Ensure use enhanced weak password detection is set to enabledCIS Zoom L2 v1.0.0Zoom

CONFIGURATION MANAGEMENT

4.6.2 Ensure BFD Authentication is Not Set to Loose-CheckCIS Juniper OS Benchmark v2.1.0 L2Juniper

CONFIGURATION MANAGEMENT

6.7 Ensure the OWASP ModSecurity Core Rule Set Is Installed and EnabledCIS Apache HTTP Server 2.4 v2.2.0 L2Unix

SECURITY ASSESSMENT AND AUTHORIZATION, SYSTEM AND COMMUNICATIONS PROTECTION

6.7 Ensure the OWASP ModSecurity Core Rule Set Is Installed and Enabled - Active RulesCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

6.7 Ensure the OWASP ModSecurity Core Rule Set Is Installed and Enabled - Active RulesCIS Apache HTTP Server 2.2 L2 v3.6.0 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

6.7 Ensure the OWASP ModSecurity Core Rule Set Is Installed and Enabled - Inbound Anomaly ThresholdCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

6.7 Ensure the OWASP ModSecurity Core Rule Set Is Installed and Enabled - Inbound Anomaly ThresholdCIS Apache HTTP Server 2.2 L2 v3.6.0 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

6.7 Ensure the OWASP ModSecurity Core Rule Set Is Installed and Enabled - Outbound Anomaly ThresholdCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

6.7 Ensure the OWASP ModSecurity Core Rule Set Is Installed and Enabled - Outbound Anomaly ThresholdCIS Apache HTTP Server 2.2 L2 v3.6.0 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

6.7 Ensure the OWASP ModSecurity Core Rule Set Is Installed and Enabled - Paranoia LevelCIS Apache HTTP Server 2.2 L2 v3.6.0Unix

SYSTEM AND COMMUNICATIONS PROTECTION

6.7 Ensure the OWASP ModSecurity Core Rule Set Is Installed and Enabled - Paranoia LevelCIS Apache HTTP Server 2.2 L2 v3.6.0 MiddlewareUnix

SYSTEM AND COMMUNICATIONS PROTECTION

6.20 Ensure that User Credential Submission uses the action of 'block' or 'continue' on the URL categories - continue on the URL categoriesCIS Palo Alto Firewall 9 v1.1.0 L1Palo_Alto

ACCESS CONTROL, CONFIGURATION MANAGEMENT

CASA-FW-000300 - The Cisco ASA must be configured to generate an alert that can be forwarded to organization-defined personnel and/or the firewall administrator when denial-of-service (DoS) incidents are detected - scanning-threatDISA STIG Cisco ASA FW v2r1Cisco

SYSTEM AND INFORMATION INTEGRITY

Configure detection for potentially unwanted applicationsMSCT Windows 10 1903 v1.19.9Windows

CONFIGURATION MANAGEMENT

Configure detection for potentially unwanted applicationsMSCT Windows 10 v2004 v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure detection for potentially unwanted applicationsMSCT Windows 11 v23H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

Configure detection for potentially unwanted applicationsMSCT Windows 11 v24H2 v1.0.0Windows

CONFIGURATION MANAGEMENT

DTBI715 - Crash Detection must be enforced.DISA STIG Microsoft Internet Explorer 9 v1r15Windows

CONFIGURATION MANAGEMENT

Ensure 'threat-detection statistics' is set to 'tcp-intercept'Tenable Cisco Firepower Threat Defense Best Practices AuditCisco_Firepower

SYSTEM AND COMMUNICATIONS PROTECTION

Ensure 'threat-detection statistics' is set to 'tcp-intercept'Tenable Cisco Firepower Best Practices AuditCisco

SYSTEM AND COMMUNICATIONS PROTECTION

JUSX-VN-000022 - The Juniper SRX Services Gateway VPN must terminate all network connections associated with a communications session at the end of the session.DISA Juniper SRX Services Gateway VPN v3r2Juniper

SYSTEM AND COMMUNICATIONS PROTECTION

SonicWALL - Detection Prevention - ICMP packetsTNS SonicWALL v5.9SonicWALL

SYSTEM AND COMMUNICATIONS PROTECTION

SonicWALL - Detection Prevention - IP TTL DecrementTNS SonicWALL v5.9SonicWALL

SYSTEM AND COMMUNICATIONS PROTECTION

SonicWALL - Security Services - Client AV - EnabledTNS SonicWALL v5.9SonicWALL

SYSTEM AND INFORMATION INTEGRITY

SonicWALL - Security Services - Gateway AV - ActivatedTNS SonicWALL v5.9SonicWALL

SYSTEM AND INFORMATION INTEGRITY

SYMP-AG-000540 - Symantec ProxySG must block outbound traffic containing known and unknown denial-of-service (DoS) attacks to protect against the use of internal information systems to launch any DoS attacks against other networks or endpoints.DISA Symantec ProxySG Benchmark ALG v1r3BlueCoat

SYSTEM AND COMMUNICATIONS PROTECTION

SYMP-NM-000320 - Symantec ProxySG must enable Attack Detection.DISA Symantec ProxySG Benchmark NDM v1r2BlueCoat

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000001 - Microsoft Defender AV must be configured to block the Potentially Unwanted Application (PUA) feature.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000003 - Microsoft Defender AV must be configured to automatically take action on all detected tasks.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000006 - Microsoft Defender AV must be configured to not exclude files opened by specified processes.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000011 - Microsoft Defender AV must be configured to only send safe samples for MAPS telemetry.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000012 - Microsoft Defender AV must be configured for protocol recognition for network protection.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000017 - Microsoft Defender AV Group Policy settings must take priority over the local preference settings.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000020 - Microsoft Defender AV must be configured to scan all downloaded files and attachments.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000023 - Microsoft Defender AV must be configured to process scanning when real-time protection is enabled.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY

WNDF-AV-000032 - Microsoft Defender AV must be configured to block executable content from email client and webmail.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000033 - Microsoft Defender AV must be configured block Office applications from creating child processes.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000034 - Microsoft Defender AV must be configured block Office applications from creating executable content.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000035 - Microsoft Defender AV must be configured to block Office applications from injecting into other processes.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000036 - Microsoft Defender AV must be configured to impede JavaScript and VBScript to launch executables.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000038 - Microsoft Defender AV must be configured to block Win32 imports from macro code in Office.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000039 - Microsoft Defender AV must be configured to prevent user and apps from accessing dangerous websites.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000044 - Microsoft Defender AV must block credential stealing from the Windows local security authority subsystem.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000045 - Microsoft Defender AV must block untrusted and unsigned processes that run from USB.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000047 - Microsoft Defender AV must block process creations originating from PSExec and WMI commands.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000054 - Microsoft Defender AV must control whether exclusions are visible to Local Admins.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND COMMUNICATIONS PROTECTION

WNDF-AV-000065 - Microsoft Defender AV must enable real-time protection and Security Intelligence Updates during OOBE.DISA Microsoft Defender Antivirus STIG v2r6Windows

SYSTEM AND INFORMATION INTEGRITY