Check Docker Hardening Configurations - Administrator Guide - Cortex XSIAM - Cortex - Security Operations

Cortex XSIAM Administrator Guide

Product
Cortex XSIAM
Creation date
2024-02-26
Last date published
2024-04-25
Category
Administrator Guide
Abstract

Check Docker hardening configurations on an engine by running the !DockerHardeningCheck command in the Incident/Alert War Room CLI.

Check your Docker hardening configurations on an engine by running the !DockerHardeningCheck command in the Incident/Alert War Room CLI. The results show the following:

  • Non-root User

  • Memory

  • File Descriptors

  • CPUs

  • PIDs

Before running the command, ensure that your engine is up and running.

  1. Update the DockerHardeningCheck script to run on the engine.

    Note

    By default, the DockerHardeningScript runs on the Cortex XSIAM tenant.

    1. Go to Incident ResponseAutomationScriptsDockerHardeningCheckSettings.

    2. In the Run on field select Single engine and from the drop-down list, select the engine you want to run the script.

    3. Save the script.

  2. Verify the Docker container has been hardened according to recommended settings, in the Incident/Alert War Room CLI, run the !DockerHardeningCheck command.