Wartiva evaluates these checks on its cloud mirror every time an endpoint changes, with zero endpoint load, and turns every failure into a finding with captured evidence. How Wartiva works →
All 31 checks on this page
- 2.1 Configure Server Services
- Ensure autofs services are not in use
- Ensure avahi daemon services are not in use
- Ensure dhcp server services are not in use
- Ensure dns server services are not in use
- Ensure dnsmasq services are not in use
- Ensure ftp server services are not in use
- Ensure ldap server services are not in use
- Ensure message access server services are not in use
- Ensure network file system services are not in use
- Ensure nis server services are not in use
- Ensure print server services are not in use
- Ensure rpcbind services are not in use
- Ensure rsync services are not in use
- Ensure samba file server services are not in use
- Ensure snmp services are not in use
- Ensure telnet server services are not in use
- Ensure tftp server services are not in use
- Ensure web proxy server services are not in use
- Ensure web server services are not in use
- Ensure X window server services are not in use
- Ensure xinetd services are not in use
- 2.2 Configure Client Services
- Ensure ftp client is not installed
- Ensure ldap client is not installed
- Ensure nis client is not installed
- Ensure rsh client is not installed
- Ensure talk client is not installed
- Ensure telnet client is not installed
- 2.3 Configure Time Synchronization
- Ensure systemd-timesyncd is enabled and running
- Ensure chrony is enabled and running
- Ensure chrony is running as user _chrony
- 2.4 Job Schedulers
- Ensure cron daemon is enabled and active
2.1 Configure Server Services
Ensure autofs services are not in use
Finding: Autofs service is in use.
Checks that the autofs automounting service is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Automounting lets anyone with physical access attach removable media and have its contents mounted without explicit permission, widening the attack surface.
Impact: Automatic mounting of configured removable media stops; media must be mounted manually.
Remediation
From the command line:
systemctl stop autofs.service
systemctl mask autofs.service
- Framework mappings
- CIS Controls v8: 10.3 Disable Autorun and Autoplay for Removable Media
- NIST SP 800-53 Rev. 5: MP-7 Media Use
- NIST SP 800-171 Rev. 2: 3.8.7 Control the use of removable media on system components
- CMMC 2.0 Level 2: MP.L2-3.8.7 Control the use of removable media on system components
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure avahi daemon services are not in use
Finding: Avahi daemon service is in use.
Checks that the avahi-daemon service and socket are masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Avahi zeroconf service discovery is rarely needed and publishes/advertises services on the local network, expanding attack surface.
Impact: Automatic discovery of local network services and printers via mDNS/DNS-SD stops.
Remediation
From the command line:
systemctl stop avahi-daemon.socket avahi-daemon.service
systemctl mask avahi-daemon.socket avahi-daemon.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure dhcp server services are not in use
Finding: Dhcp server service is in use.
Checks that the kea DHCPv4/DHCPv6/DDNS server services are masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: A rogue or misconfigured DHCP server can disrupt the network by handing out incorrect addresses, DNS servers, or gateways; unless the host is a DHCP server the kea services should not run.
Impact: The system can no longer serve DHCP leases.
Remediation
From the command line:
systemctl stop kea-dhcp-ddns-server.service kea-dhcp4-server.service kea-dhcp6-server.service
systemctl mask kea-dhcp-ddns-server.service kea-dhcp4-server.service kea-dhcp6-server.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure dns server services are not in use
Finding: Dns server service is in use.
Checks that the bind9 DNS server (named.service) is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Unless the host is a designated DNS server, the bind9 package/service should not run so as to reduce attack surface.
Impact: The system can no longer serve DNS.
Remediation
From the command line:
systemctl stop named.service
systemctl mask named.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure dnsmasq services are not in use
Finding: Dnsmasq service is in use.
Checks that the dnsmasq service is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: dnsmasq provides DNS caching/forwarding and DHCP; unless required it should not run.
Impact: Local DNS caching/forwarding and DHCP via dnsmasq stop.
Remediation
From the command line:
systemctl stop dnsmasq.service
systemctl mask dnsmasq.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure ftp server services are not in use
Finding: Ftp server service is in use.
Checks that the vsftpd FTP server service is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: FTP transmits data and credentials in the clear; unless an FTP server is required, vsftpd should not run.
Impact: The system can no longer act as an FTP server.
Remediation
From the command line:
systemctl stop vsftpd.service
systemctl mask vsftpd.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure ldap server services are not in use
Finding: Ldap server service is in use.
Checks that the slapd OpenLDAP server service is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Unless the host is an LDAP server, slapd should not run so as to reduce attack surface.
Impact: The system can no longer serve LDAP directory queries.
Remediation
From the command line:
systemctl stop slapd.service
systemctl mask slapd.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure message access server services are not in use
Finding: Message access server service is in use.
Checks that the dovecot IMAP/POP3 server service and socket are masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Unless the host provides IMAP/POP3 mail access, the dovecot service should not run so as to reduce attack surface.
Impact: IMAP/POP3 message access served by dovecot stops.
Remediation
From the command line:
systemctl stop dovecot.socket dovecot.service
systemctl mask dovecot.socket dovecot.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure network file system services are not in use
Finding: Network file system service is in use.
Checks that the NFS server service (nfs-server.service) is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: If the host does not export NFS shares, the nfs-kernel-server service should not run so as to reduce the remote attack surface.
Impact: The system can no longer export NFS shares.
Remediation
From the command line:
systemctl stop nfs-server.service
systemctl mask nfs-server.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure nis server services are not in use
Finding: Nis server service is in use.
Checks that the ypserv NIS server service is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: NIS is inherently insecure (weak authentication, DoS and buffer-overflow history) and has been superseded by LDAP; ypserv should not run.
Impact: The system can no longer serve NIS maps.
Remediation
From the command line:
systemctl stop ypserv.service
systemctl mask ypserv.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure print server services are not in use
Finding: Print server service is in use.
Checks that the CUPS print service and socket are masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: CUPS accepts local and remote print jobs and offers web-based admin; unless printing is needed it should not run.
Impact: Printing (including accepting remote print jobs) stops.
Remediation
From the command line:
systemctl stop cups.socket cups.service
systemctl mask cups.socket cups.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure rpcbind services are not in use
Finding: Rpcbind service is in use.
Checks that the rpcbind (portmapper) service and socket are masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: The portmapper is a UDP amplification vector suited to DDoS attacks; unless RPC services are required, rpcbind should not run.
Impact: RPC-based services (e.g. NFS) that depend on rpcbind will not function.
Remediation
From the command line:
systemctl stop rpcbind.socket rpcbind.service
systemctl mask rpcbind.socket rpcbind.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure rsync services are not in use
Finding: Rsync service is in use.
Checks that the rsync daemon service is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: The rsync protocol is unencrypted; the rsync daemon should not run so as to reduce attack surface.
Impact: Serving files via the rsync daemon stops (rsync-over-ssh is unaffected).
Remediation
From the command line:
systemctl stop rsync.service
systemctl mask rsync.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure samba file server services are not in use
Finding: Samba file server service is in use.
Checks that the Samba file server service (smbd.service) is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Unless SMB file/directory sharing to Windows clients is needed, smbd should not run so as to reduce attack surface.
Impact: SMB file/print sharing stops.
Remediation
From the command line:
systemctl stop smbd.service
systemctl mask smbd.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure snmp services are not in use
Finding: Snmp service is in use.
Checks that the SNMP server service (snmpd.service) is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: SNMPv1/v2 transmit community strings and data in the clear; unless SNMP is required (and hardened to v3), snmpd should not run.
Impact: SNMP monitoring of the host stops.
Remediation
From the command line:
systemctl stop snmpd.service
systemctl mask snmpd.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure telnet server services are not in use
Finding: Telnet server service is in use.
Checks that the telnet server service (inetutils-inetd.service serving telnetd) is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Telnet is unencrypted; anyone able to sniff traffic can capture credentials. The telnet server should not run.
Impact: Inbound telnet logins stop; use SSH instead.
Remediation
From the command line:
systemctl stop inetutils-inetd.service
systemctl mask inetutils-inetd.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure tftp server services are not in use
Finding: Tftp server service is in use.
Checks that the TFTP server service (tftpd-hpa.service) is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: TFTP has no encryption, access control, or authentication; unless required (e.g. PXE boot) the TFTP server should not run.
Impact: TFTP file serving (including network boot support) stops.
Remediation
From the command line:
systemctl stop tftpd-hpa.service
systemctl mask tftpd-hpa.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure web proxy server services are not in use
Finding: Web proxy server service is in use.
Checks that the Squid web proxy service is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Unless the host is a designated proxy server, the squid service should not run so as to reduce attack surface.
Impact: Web proxying via squid stops.
Remediation
From the command line:
systemctl stop squid.service
systemctl mask squid.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure web server services are not in use
Finding: Web server service is in use.
Checks that the apache2 and nginx web server services/sockets are masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: Web servers add listening network services that process untrusted remote input and expose extra attack surface via modules; they should not run unless hosting web content.
Impact: The host can no longer serve web content from apache2 or nginx.
Remediation
From the command line:
systemctl stop apache2.socket apache2.service
systemctl mask apache2.socket apache2.service
systemctl stop nginx.service
systemctl mask nginx.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure X window server services are not in use
Finding: X window server package is installed.
Checks that the X Window System server package (xserver-common) is not installed.
This rule fails when the installed package name is one of the prohibited packages.
Rationale: Servers typically do not need a graphical X session; removing the X server reduces attack surface.
Impact: Graphical X sessions become unavailable; a GDM in use may depend on this package and should be reviewed first.
Remediation
From the command line:
apt purge xserver-common
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure xinetd services are not in use
Finding: Xinetd service is in use.
Checks that the xinetd super-daemon service is masked or stopped.
This rule fails when the service unit is loaded (not masked) and RUNNING.
Rationale: xinetd launches on-demand network daemons; unless xinetd services are required it should not run so as to reduce attack surface.
Impact: Any services launched via xinetd will no longer start on demand.
Remediation
From the command line:
systemctl stop xinetd.service
systemctl mask xinetd.service
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
2.2 Configure Client Services
Ensure ftp client is not installed
Finding: Ftp client package is installed.
Checks that neither the ftp nor tnftp client package is installed.
This rule fails when the installed package name is one of the prohibited packages.
Rationale: FTP is a cleartext protocol; unless required, the FTP client should be removed to reduce attack surface.
Impact: The ftp/tnftp client commands become unavailable; use SFTP instead.
Remediation
From the command line:
apt purge ftp
apt purge tnftp
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure ldap client is not installed
Finding: Ldap client package is installed.
Checks that the ldap-utils client package is not installed.
This rule fails when the installed package name is one of the prohibited packages.
Rationale: If the host does not need to act as an LDAP client, removing ldap-utils reduces attack surface.
Impact: LDAP client utilities become unavailable, which may inhibit LDAP-based authentication.
Remediation
From the command line:
apt purge ldap-utils
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure nis client is not installed
Finding: Nis client package is installed.
Checks that the nis client package is not installed.
This rule fails when the installed package name is one of the prohibited packages.
Rationale: NIS is insecure (weak authentication, DoS/buffer-overflow history) and superseded by LDAP; the client should be removed to prevent misuse.
Impact: NIS client lookups become unavailable.
Remediation
From the command line:
apt purge nis
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure rsh client is not installed
Finding: Rsh client package is installed.
Checks that the rsh-client package (rsh, rcp, rlogin) is not installed.
This rule fails when the installed package name is one of the prohibited packages.
Rationale: The rsh family sends credentials in the clear and has numerous exposures; removing the client prevents users from inadvertently exposing credentials.
Impact: The rsh, rcp, and rlogin commands become unavailable; use SSH/SCP instead.
Remediation
From the command line:
apt purge rsh-client
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Credential Access (TA0006)
Ensure talk client is not installed
Finding: Talk client package is installed.
Checks that the talk client package is not installed.
This rule fails when the installed package name is one of the prohibited packages.
Rationale: talk uses unencrypted protocols and presents a security risk; the client should be removed unless required.
Impact: The talk messaging command becomes unavailable.
Remediation
From the command line:
apt purge talk
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Initial Access (TA0001)
Ensure telnet client is not installed
Finding: Telnet client package is installed.
Checks that neither the telnet nor inetutils-telnet client package is installed.
This rule fails when the installed package name is one of the prohibited packages.
Rationale: The telnet protocol is unencrypted; the client should be removed so credentials cannot be exposed over telnet. Use SSH instead.
Impact: The telnet client command becomes unavailable.
Remediation
From the command line:
apt purge telnet inetutils-telnet
- Framework mappings
- CIS Controls v8: 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- NIST SP 800-53 Rev. 5: CM-6 Configuration Settings; CM-7 Least Functionality
- NIST SP 800-171 Rev. 2: 3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- CMMC 2.0 Level 2: CM.L2-3.4.7 Restrict, disable, or prevent the use of nonessential programs, functions, ports, protocols, and services
- PCI DSS v4.0.1: 1.2.5 Approve and justify each allowed port, protocol, and service; 2.2.4 Enable only required services and remove unneeded functionality; 6.4.1 Assess or shield public-facing web applications against known attacks
- Risk
- External Attack Surface
- MITRE ATT&CK tactic
- Credential Access (TA0006)
2.3 Configure Time Synchronization
Ensure systemd-timesyncd is enabled and running
Finding: systemd-timesyncd is not enabled and running.
Checks that systemd-timesyncd.service is enabled and active, treating a masked unit (chrony chosen instead) as compliant.
This rule fails when the time-sync service is neither masked nor enabled-and-running.
Rationale: Accurate, synchronized time underpins time-sensitive security controls and consistent log timestamps for forensics.
Impact: None; enables the system time synchronization client.
Remediation
From the command line:
systemctl unmask systemd-timesyncd.service
systemctl --now enable systemd-timesyncd.service
- Framework mappings
- CIS Controls v8: 8.4 Standardize Time Synchronization
- NIST SP 800-53 Rev. 5: AU-8 Time Stamps; AU-12 Audit Record Generation
- NIST SP 800-171 Rev. 2: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- CMMC 2.0 Level 2: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- PCI DSS v4.0.1: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure chrony is enabled and running
Finding: Chrony is not enabled and running.
Checks that chrony.service is enabled and active, treating a masked unit (systemd-timesyncd chosen instead) as compliant.
This rule fails when the time-sync service is neither masked nor enabled-and-running.
Rationale: Accurate, synchronized time underpins time-sensitive security controls and consistent log timestamps for forensics.
Impact: None; enables the chrony time synchronization daemon.
Remediation
From the command line:
systemctl unmask chrony.service
systemctl --now enable chrony.service
- Framework mappings
- CIS Controls v8: 8.4 Standardize Time Synchronization
- NIST SP 800-53 Rev. 5: AU-8 Time Stamps; AU-12 Audit Record Generation
- NIST SP 800-171 Rev. 2: 3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- CMMC 2.0 Level 2: AU.L2-3.3.7 Provide a system capability that compares and synchronizes internal system clocks with an authoritative source to generate time stamps for audit records
- PCI DSS v4.0.1: 10.6.1 Deploy time-sync technology to align all system clocks; 10.6.2 Use designated central time servers for correct, consistent time; 10.6.3 Restrict who can reach time data and log time setting changes
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)
Ensure chrony is running as user _chrony
Finding: Chrony is not running as user _chrony.
Checks that the chrony time daemon runs under the dedicated _chrony account rather than root, using the service unit userName field.
This rule fails when chrony.service runs as a user other than _chrony.
Rationale: Running chronyd with only the required privileges limits the impact of a compromise of the time daemon.
Impact: None; chronyd continues to function under its dedicated account.
Remediation
From the command line:
# add or edit in /etc/chrony/chrony.conf (or a .conf drop-in under /etc/chrony/conf.d/):
# user _chrony
systemctl restart chrony.service
- Risk
- Unprotected Principal
- MITRE ATT&CK tactic
- Privilege Escalation (TA0004)
2.4 Job Schedulers
Ensure cron daemon is enabled and active
Finding: Cron daemon is not enabled and active.
Checks that the cron daemon (cron.service) is enabled and active so scheduled system and security maintenance jobs run.
This rule fails when cron.service is masked, disabled, or not RUNNING.
Rationale: Cron runs scheduled maintenance and security-monitoring jobs; if the daemon is not enabled and running those jobs will not execute.
Impact: None; ensures scheduled jobs continue to run.
Remediation
From the command line:
systemctl unmask cron.service
systemctl --now enable cron.service
- Risk
- Reliability Impact
- MITRE ATT&CK tactic
- Defense Evasion (TA0005)