CIS_Amazon_Linux_2_Benchmarks

Ensure TIPC Kernel Module Is Not Available
Profile Applicability:  • Level 2 Description:  The Transparent Inter-Process Communication (TIPC) kernel module provides network communication between clu...
Wed, 28 May, 2025 at 2:59 AM
Ensure RDS Kernel Module Is Not Available
Profile Applicability:  • Level 2 Description:  The Reliable Datagram Sockets (RDS) kernel module provides a high-performance, low-latency communication pr...
Wed, 28 May, 2025 at 3:04 AM
Ensure SCTP Kernel Module Is Not Available
Profile Applicability:  • Level 2 Description:  The Stream Control Transmission Protocol (SCTP) kernel module supports a transport layer protocol used in t...
Wed, 28 May, 2025 at 3:09 AM
Ensure IP Forwarding Is Disabled
Profile Applicability:  • Level 1 Description:  IP forwarding allows a system to forward network packets between interfaces, effectively acting as a router...
Wed, 28 May, 2025 at 3:14 AM
Ensure Packet Redirect Sending Is Disabled
Profile Applicability:  • Level 1 Description:  Packet redirect sending allows a host to inform other hosts of a better route for sending packets. Disablin...
Wed, 28 May, 2025 at 3:19 AM
Ensure Bogus ICMP Responses Are Ignored
Profile Applicability:  • Level 1 Description:  Bogus ICMP responses, such as ICMP redirect messages from unauthorized sources, can be exploited to mislead...
Wed, 28 May, 2025 at 3:25 AM
Ensure Broadcast ICMP Requests Are Ignored
Profile Applicability:  • Level 1 Description:  Broadcast ICMP requests can be exploited in denial-of-service (DoS) attacks by amplifying network traffic. ...
Wed, 28 May, 2025 at 3:31 AM
Ensure ICMP Redirects Are Not Accepted
Profile Applicability:  • Level 1 Description:  ICMP redirect messages inform a host of a better route for sending packets. Accepting these redirects can a...
Wed, 28 May, 2025 at 4:29 AM
Ensure Secure ICMP Redirects Are Not Accepted
Profile Applicability:  • Level 1 Description:  Secure ICMP redirects are a variant of ICMP redirect messages used in IPsec environments. Accepting these r...
Wed, 28 May, 2025 at 4:34 AM
Ensure Reverse Path Filtering Is Enabled
Profile Applicability:  • Level 1 Description: Reverse path filtering helps prevent IP spoofing by verifying that incoming packets are received on the inte...
Wed, 28 May, 2025 at 4:38 AM