CLAUDE CODE MARKETPLACES
SkillsCyberStrikeus/CyberStrikeAT-3(4)_suspicious-communications-and-anomalous-system-behavior

AT-3(4)_suspicious-communications-and-anomalous-system-behavior

Suspicious Communications and Anomalous System Behavior

npx skills add https://github.com/CyberStrikeus/CyberStrike --skill AT-3(4)_suspicious-communications-and-anomalous-system-behavior
SKILL.md

AT-3(4) Suspicious Communications and Anomalous System Behavior

Enhancement of: AT-3

High-Level Description

Family: Awareness and Training (AT) Framework: NIST SP 800-53 Rev 5

No description available.

What to Check

  • Verify AT-3(4) Suspicious Communications and Anomalous System Behavior is documented in SSP
  • Confirm control is operating effectively
  • Review evidence of continuous monitoring for AT-3(4)
  • Verify enhancement builds upon base control AT-3

How to Test

Step 1: Review Documentation

Examine the System Security Plan (SSP) and related artifacts for AT-3(4) implementation details. Verify the organization has documented how this control is satisfied.

Step 2: Validate Implementation

# For cloud environments, use cloud-audit-mcp tools
# For on-premises, review system configurations directly

# Example: Check if account management policies exist
grep -r "account.management\|access.control" /etc/security/ 2>/dev/null

Step 3: Test Operating Effectiveness

Verify the control is actively functioning, not just documented. Check logs, configurations, and operational evidence.

Tools

ToolPurposeUsage
Manual ReviewDocumentation and interview-basedN/A

Remediation Guide

Control Statement

Refer to NIST SP 800-53 Rev 5 for the full control statement.

Implementation Guidance

Implement this control per organizational risk assessment and system categorization.

Risk Assessment

FindingSeverityImpact
AT-3(4) Suspicious Communications and Anomalous System Behavior not implementedMediumAwareness and Training
AT-3(4) partially implementedLowIncomplete Awareness and Training

CWE Categories

CWE IDTitle
N/ANo direct CWE mapping

References

Checklist

  • Control documented in SSP
  • Implementation evidence collected
  • Operating effectiveness validated
  • Continuous monitoring in place
  • Related controls (none) reviewed