Editor's Note
cis-tomcat10-v110-1.1
Remove extraneous files and directories (Manual)
Install
npx skills add https://github.com/CyberStrikeus/CyberStrike --skill cis-tomcat10-v110-1.1SKILL.md
Remove extraneous files and directories (Manual)
Description
The installation may provide example applications, documentation, and other directories which may not serve a production use.
Rationale
Removing sample resources is a defense in depth measure that reduces potential exposures introduced by these resources.
Audit Procedure
Perform the following to determine the existence of extraneous resources:
$ ls -l $CATALINA_HOME/webapps/examples \
$CATALINA_HOME/webapps/docs \
$CATALINA_HOME/webapps/ROOT \
$CATALINA_HOME/webapps/host-manager \
$CATALINA_HOME/webapps/manager
No output implies no sample resources are present.
Remediation
Perform the following to remove extraneous resources:
$ rm -rf $CATALINA_HOME/webapps/docs \
$CATALINA_HOME/webapps/examples \
$CATALINA_HOME/webapps/ROOT
If the Manager and HOST-Manager application are not utilized, also remove the following resources:
$ rm -rf $CATALINA_HOME/webapps/host-manager \
$CATALINA_HOME/webapps/manager
Default Value
docs, examples, ROOT, manager and host-manager are default web applications shipped with Tomcat.
References
CIS Controls
v8:
- 4.8 Uninstall or Disable Unnecessary Services on Enterprise Assets and Software
- Uninstall or disable unnecessary services on enterprise assets and software, such as an unused file sharing service, web application module, or service function.
v7:
- 2.6 Address unapproved software
- Ensure that unauthorized software is either removed or the inventory is updated in a timely manner
Profile Applicability
- Level 2
Installs0
GitHub Stars1.2k
LanguageTypeScript
AddedJul 14, 2026
Categories
Related ai-agent Skills
View all