Audits service accounts across Active Directory, AWS, Azure, GCP, databases, and apps to identify orphaned, over-privileged, and non-compliant accounts with missing owners or poor credential rotation. For IAM governance and compliance like SOX/PCI.
npx claudepluginhub killvxk/cybersecurity-skills-zhThis skill uses the workspace's default tool permissions.
审计企业基础设施中的服务账户,识别孤立账户、过度特权账户和不合规账户。本技能涵盖在 Active Directory、云平台、数据库和应用程序中发现服务账户,评估权限级别,识别缺失负责人,执行生命周期策略。
Audits service accounts in AD, AWS, Azure, GCP, databases, and apps to detect orphaned, over-privileged, and non-compliant accounts for security reviews.
Audits service accounts across Active Directory, AWS, Azure, GCP, databases, and apps to identify orphaned, over-privileged, and non-compliant ones. Useful for security assessments, compliance audits, and incident response.
Conducts systematic reviews of privileged accounts in PAM setups, verifying access permissions, identifying excesses, and enforcing least privilege across AD, AWS, Azure, GCP, and databases. Useful for compliance audits.
Share bugs, ideas, or general feedback.
审计企业基础设施中的服务账户,识别孤立账户、过度特权账户和不合规账户。本技能涵盖在 Active Directory、云平台、数据库和应用程序中发现服务账户,评估权限级别,识别缺失负责人,执行生命周期策略。
ServicePrincipalName 的账户PasswordNeverExpires 标志的账户| 控制项 | NIST 800-53 | 描述 |
|---|---|---|
| 账户管理 | AC-2 | 服务账户生命周期 |
| 账户审查 | AC-2(3) | 账户定期审查 |
| 最小权限 | AC-6 | 最低服务账户权限 |
| 认证器管理 | IA-5 | 服务凭据轮换 |
| 审计审查 | AU-6 | 审查服务账户活动 |