Item Search

NameAudit NamePluginCategory
1.1.7 Ensure nodev option set on /var/tmp partitionCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

ACCESS CONTROL

1.1.8 Ensure nosuid option set on /var/tmp partitionCIS Ubuntu Linux 14.04 LTS Workstation L1 v2.1.0Unix

ACCESS CONTROL

1.1.15 Ensure nosuid option set on /run/shm partitionCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

ACCESS CONTROL

1.1.16 Ensure noexec option set on /run/shm partitionCIS Ubuntu Linux 14.04 LTS Server L1 v2.1.0Unix

ACCESS CONTROL

1.5.1 Ensure core dumps are restricted - hard core 0CIS SUSE Linux Enterprise Server 11 L1 v2.1.1Unix

ACCESS CONTROL

3.1 Restrict Core Dumps to Protected Directory - global core file contentCIS Solaris 11.1 L1 v1.0.0Unix

ACCESS CONTROL

3.1 Restrict Core Dumps to Protected Directory - init core file contentCIS Solaris 11.2 L1 v1.1.0Unix

ACCESS CONTROL

3.1 Restrict Core Dumps to Protected Directory - per-process setid core dumps = disabledCIS Solaris 11 L1 v1.1.0Unix

ACCESS CONTROL

3.2 Restrict Core Dumps to Protected Directory - Check if COREADM_GLOB_PATTERN is set to /var/cores/core_%n_%f_%u_%g_%t_%pCIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.9 Restrict at/cron To Authorized Users - should pass if 'root' exists in /etc/cron.d/cron.allow.CIS Solaris 10 L1 v5.2Unix

ACCESS CONTROL

6.13 Restrict at/cron to Authorized Users - /etc/cron.d/at.allowCIS Solaris 11 L1 v1.1.0Unix

ACCESS CONTROL

6.13 Restrict at/cron to Authorized Users - /etc/cron.d/cron.allowCIS Solaris 11 L1 v1.1.0Unix

ACCESS CONTROL

9.5 Restrict Access to the su Command - '/etc/pam.d/su contents'CIS Ubuntu 12.04 LTS Benchmark L1 v1.1.0Unix

ACCESS CONTROL

10.1 SN.1 Restrict access to suspend featureCIS Solaris 11 L2 v1.1.0Unix

ACCESS CONTROL

Allow user control over installsMSCT Windows 11 v1.0.0Windows

ACCESS CONTROL

Always install with elevated privilegesMSCT MSCT Windows Server 2022 DC v1.0.0Windows

ACCESS CONTROL

Always install with elevated privilegesMSCT Windows Server 2022 v1.0.0Windows

ACCESS CONTROL

Always install with elevated privileges - AlwaysInstallElevatedMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Configure Windows Defender SmartScreen - ShellSmartScreenLevelMSCT Windows Server v1909 MS v1.0.0Windows

ACCESS CONTROL

Configure Windows Defender SmartScreen - ShellSmartScreenLevelMSCT MSCT Windows Server 2022 DC v1.0.0Windows

ACCESS CONTROL

Configure Windows Defender SmartScreen - ShellSmartScreenLevelMSCT Windows Server v20H2 MS v1.0.0Windows

ACCESS CONTROL

Disable AutoRepublishMSCT Office 2016 v1.0.0Windows

ACCESS CONTROL

Disable AutoRepublishMSCT Office 365 ProPlus 1908 v1.0.0Windows

ACCESS CONTROL

Disallow WinRM from storing RunAs credentialsMSCT Windows 11 v1.0.0Windows

ACCESS CONTROL

Do not show AutoRepublish warning alertMSCT Office 2016 v1.0.0Windows

ACCESS CONTROL

Enable local admin password managementMSCT Windows 10 v21H1 v1.0.0Windows

ACCESS CONTROL

Join Microsoft MAPSMSCT Windows 10 1809 v1.0.0Windows

ACCESS CONTROL

Join Microsoft MAPSMSCT Windows 10 1909 v1.0.0Windows

ACCESS CONTROL

Join Microsoft MAPSMSCT Windows 10 v21H1 v1.0.0Windows

ACCESS CONTROL

Join Microsoft MAPSMSCT Windows Server 1903 DC v1.19.9Windows

ACCESS CONTROL

Join Microsoft MAPSMSCT Windows Server 2016 DC v1.0.0Windows

ACCESS CONTROL

Join Microsoft MAPSMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Management Services Security - Configure read-only access; use read-write only when required - usmJuniper Hardening JunOS 12 Devices ChecklistJuniper

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accountsMSCT Windows 10 v21H1 v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accounts - RestrictAnonymousSAMMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Network access: Do not allow anonymous enumeration of SAM accounts and shares - RestrictAnonymousMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL

Network access: Restrict anonymous access to Named Pipes and SharesMSCT Windows 11 v1.0.0Windows

ACCESS CONTROL

Network security: Allow LocalSystem NULL session fallbackMSCT Windows 10 v21H1 v1.0.0Windows

ACCESS CONTROL

Network security: Allow LocalSystem NULL session fallbackMSCT Windows Server 2022 v1.0.0Windows

ACCESS CONTROL

Network security: Allow LocalSystem NULL session fallback - allownullsessionfallbackMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

Turn off toast notifications on the lock screenMSCT Windows 10 v21H1 v1.0.0Windows

ACCESS CONTROL

Turn on PowerShell Script Block Logging - EnableScriptBlockInvocationLoggingMSCT Windows 10 v2004 v1.0.0Windows

ACCESS CONTROL

Turn on PowerShell Script Block Logging - EnableScriptBlockInvocationLoggingMSCT Windows 11 v1.0.0Windows

ACCESS CONTROL

Turn on PowerShell Script Block Logging - EnableScriptBlockInvocationLoggingMSCT Windows Server 1903 MS v1.19.9Windows

ACCESS CONTROL

Turn on PowerShell Script Block Logging - EnableScriptBlockInvocationLoggingMSCT Windows Server v2004 DC v1.0.0Windows

ACCESS CONTROL

Turn on PowerShell Script Block Logging - EnableScriptBlockInvocationLoggingMSCT Windows Server v2004 MS v1.0.0Windows

ACCESS CONTROL

Turn on PowerShell Script Block Logging - EnableScriptBlockInvocationLoggingMSCT MSCT Windows Server 2022 DC v1.0.0Windows

ACCESS CONTROL

Turn on PowerShell Script Block Logging - EnableScriptBlockLoggingMSCT MSCT Windows Server 2022 DC v1.0.0Windows

ACCESS CONTROL

Turn on PowerShell Script Block Logging - EnableScriptBlockLoggingMSCT Windows Server 2025 DC v1.0.0Windows

ACCESS CONTROL

User Account Control: Behavior of the elevation prompt for standard users - ConsentPromptBehaviorUserMSCT Windows Server 2025 MS v1.0.0Windows

ACCESS CONTROL