mirror of
https://github.com/prowler-cloud/prowler.git
synced 2026-07-24 13:01:56 +00:00
feat(metadata): update checks medatada services/subservices
This commit is contained in:
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"IAM"
|
||||
],
|
||||
"ServiceName": "accessanalyzer",
|
||||
"ServiceName": "AccessAnalyzer",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id",
|
||||
"Severity": "low",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"IAM"
|
||||
],
|
||||
"ServiceName": "accessanalyzer",
|
||||
"ServiceName": "AccessAnalyzer",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id",
|
||||
"Severity": "low",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"IAM"
|
||||
],
|
||||
"ServiceName": "account",
|
||||
"ServiceName": "Account",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"IAM"
|
||||
],
|
||||
"ServiceName": "account",
|
||||
"ServiceName": "Account",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"IAM"
|
||||
],
|
||||
"ServiceName": "account",
|
||||
"ServiceName": "Account",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"IAM"
|
||||
],
|
||||
"ServiceName": "account",
|
||||
"ServiceName": "Account",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"Data Protection"
|
||||
],
|
||||
"ServiceName": "acm",
|
||||
"ServiceName": "ACM",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:acm:region:account-id:certificate/resource-id",
|
||||
"Severity": "high",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"Logging and Monitoring"
|
||||
],
|
||||
"ServiceName": "acm",
|
||||
"ServiceName": "ACM",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:acm:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+2
-2
@@ -8,8 +8,8 @@
|
||||
"CheckType": [
|
||||
"IAM"
|
||||
],
|
||||
"ServiceName": "apigateway",
|
||||
"SubServiceName": "rest_api",
|
||||
"ServiceName": "APIGateway",
|
||||
"SubServiceName": "RestApi",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsApiGatewayRestApi",
|
||||
|
||||
+2
-2
@@ -8,8 +8,8 @@
|
||||
"CheckType": [
|
||||
"Data Protection"
|
||||
],
|
||||
"ServiceName": "apigateway",
|
||||
"SubServiceName": "rest_api",
|
||||
"ServiceName": "APIGateway",
|
||||
"SubServiceName": "RestApi",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsApiGatewayStage",
|
||||
|
||||
+2
-2
@@ -8,8 +8,8 @@
|
||||
"CheckType": [
|
||||
"Logging and Monitoring"
|
||||
],
|
||||
"ServiceName": "apigateway",
|
||||
"SubServiceName": "rest_api",
|
||||
"ServiceName": "APIGateway",
|
||||
"SubServiceName": "RestApi",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsApiGatewayStage",
|
||||
|
||||
+2
-2
@@ -8,8 +8,8 @@
|
||||
"CheckType": [
|
||||
"Infrastructure Security"
|
||||
],
|
||||
"ServiceName": "apigateway",
|
||||
"SubServiceName": "rest_api",
|
||||
"ServiceName": "APIGateway",
|
||||
"SubServiceName": "RestApi",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsApiGatewayRestApi",
|
||||
|
||||
+2
-2
@@ -8,8 +8,8 @@
|
||||
"CheckType": [
|
||||
"Infrastructure Security"
|
||||
],
|
||||
"ServiceName": "apigateway",
|
||||
"SubServiceName": "rest_api",
|
||||
"ServiceName": "APIGateway",
|
||||
"SubServiceName": "RestApi",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsApiGatewayRestApi",
|
||||
|
||||
+2
-2
@@ -8,8 +8,8 @@
|
||||
"CheckType": [
|
||||
"Infrastructure Security"
|
||||
],
|
||||
"ServiceName": "apigateway",
|
||||
"SubServiceName": "rest_api",
|
||||
"ServiceName": "APIGateway",
|
||||
"SubServiceName": "RestApi",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsApiGatewayStage",
|
||||
|
||||
+1
-1
@@ -8,7 +8,7 @@
|
||||
"CheckType": [
|
||||
"IAM"
|
||||
],
|
||||
"ServiceName": "apigateway",
|
||||
"ServiceName": "APIGatewayV2",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -8,7 +8,7 @@
|
||||
"CheckType": [
|
||||
"Logging and Monitoring"
|
||||
],
|
||||
"ServiceName": "apigateway",
|
||||
"ServiceName": "APIGatewayV2",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -7,7 +7,7 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "appstream",
|
||||
"ServiceName": "AppStream",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"Infrastructure Security"
|
||||
],
|
||||
"ServiceName": "appstream",
|
||||
"ServiceName": "AppStream",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -7,7 +7,7 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "appstream",
|
||||
"ServiceName": "AppStream",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -7,7 +7,7 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "appstream",
|
||||
"ServiceName": "AppStream",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks"
|
||||
],
|
||||
"ServiceName": "athena",
|
||||
"ServiceName": "Athena",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:athena:region:account-id:workgroup/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks"
|
||||
],
|
||||
"ServiceName": "athena",
|
||||
"ServiceName": "Athena",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:athena:region:account-id:workgroup/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"IAM"
|
||||
],
|
||||
"ServiceName": "autoscaling",
|
||||
"ServiceName": "AutoScaling",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:autoscaling:region:account-id:autoScalingGroupName/resource-name",
|
||||
"Severity": "critical",
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
"CheckID": "autoscaling_group_multiple_az",
|
||||
"CheckTitle": "EC2 Auto Scaling Group should use multiple Availability Zones",
|
||||
"CheckType": [],
|
||||
"ServiceName": "autoscaling",
|
||||
"ServiceName": "AutoScaling",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:autoscaling:region:account-id:autoScalingGroupName/resource-name",
|
||||
"Severity": "medium",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "awslambda_function_invoke_api_operations_cloudtrail_logging_enabled",
|
||||
"CheckTitle": "Check if Lambda functions invoke API operations are being recorded by CloudTrail.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "lambda",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Lambda",
|
||||
"SubServiceName": "Functions",
|
||||
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsLambdaFunction",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "awslambda_function_no_secrets_in_code",
|
||||
"CheckTitle": "Find secrets in Lambda functions code.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "lambda",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Lambda",
|
||||
"SubServiceName": "Functions",
|
||||
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
|
||||
"Severity": "critical",
|
||||
"ResourceType": "AwsLambdaFunction",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "awslambda_function_no_secrets_in_variables",
|
||||
"CheckTitle": "Find secrets in Lambda functions variables.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "lambda",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Lambda",
|
||||
"SubServiceName": "Functions",
|
||||
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
|
||||
"Severity": "critical",
|
||||
"ResourceType": "AwsLambdaFunction",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "awslambda_function_not_publicly_accessible",
|
||||
"CheckTitle": "Check if Lambda functions have resource-based policy set as Public.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "lambda",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Lambda",
|
||||
"SubServiceName": "Functions",
|
||||
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
|
||||
"Severity": "critical",
|
||||
"ResourceType": "AwsLambdaFunction",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "awslambda_function_url_cors_policy",
|
||||
"CheckTitle": "Check Lambda Function URL CORS configuration.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "lambda",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Lambda",
|
||||
"SubServiceName": "Functions",
|
||||
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsLambdaFunction",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "awslambda_function_url_public",
|
||||
"CheckTitle": "Check Public Lambda Function URL.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "lambda",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Lambda",
|
||||
"SubServiceName": "Functions",
|
||||
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
|
||||
"Severity": "high",
|
||||
"ResourceType": "AwsLambdaFunction",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "awslambda_function_using_supported_runtimes",
|
||||
"CheckTitle": "Find obsolete Lambda runtimes.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "lambda",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Lambda",
|
||||
"SubServiceName": "Functions",
|
||||
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsLambdaFunction",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Resilience",
|
||||
"Backup"
|
||||
],
|
||||
"ServiceName": "backup",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Backup",
|
||||
"SubServiceName": "Plans",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:backup-plan:backup-plan-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsBackupBackupPlan",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Resilience",
|
||||
"Backup"
|
||||
],
|
||||
"ServiceName": "backup",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Backup",
|
||||
"SubServiceName": "ReportPlan",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:backup-report-plan:backup-report-plan-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "Other",
|
||||
|
||||
+2
-2
@@ -8,8 +8,8 @@
|
||||
"Backup",
|
||||
"Data Protection"
|
||||
],
|
||||
"ServiceName": "backup",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Backup",
|
||||
"SubServiceName": "Vaults",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:backup-vault:backup-vault-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsBackupBackupVault",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Resilience",
|
||||
"Backup"
|
||||
],
|
||||
"ServiceName": "backup",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Backup",
|
||||
"SubServiceName": "Vaults",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:backup-vault:backup-vault-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsBackupBackupVault",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cloudformation_stack_outputs_find_secrets",
|
||||
"CheckTitle": "Find secrets in CloudFormation outputs",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cloudformation",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudFormation",
|
||||
"SubServiceName": "Stacks",
|
||||
"ResourceIdTemplate": "arn:partition:cloudformation:region:account-id:stack/resource-id",
|
||||
"Severity": "critical",
|
||||
"ResourceType": "AwsCloudFormationStack",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cloudformation_stacks_termination_protection_enabled",
|
||||
"CheckTitle": "Enable termination protection for Cloudformation Stacks",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cloudformation",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudFormation",
|
||||
"SubServiceName": "Stacks",
|
||||
"ResourceIdTemplate": "arn:partition:cloudformation:region:account-id:stack/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudFormationStack",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cloudfront_distributions_field_level_encryption_enabled",
|
||||
"CheckTitle": "Check if CloudFront distributions have Field Level Encryption enabled.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cloudfront",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudFront",
|
||||
"SubServiceName": "Distributions",
|
||||
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsCloudFrontDistribution",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cloudfront_distributions_geo_restrictions_enabled",
|
||||
"CheckTitle": "Check if Geo restrictions are enabled in CloudFront distributions.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cloudfront",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudFront",
|
||||
"SubServiceName": "Distributions",
|
||||
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsCloudFrontDistribution",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cloudfront_distributions_https_enabled",
|
||||
"CheckTitle": "Check if CloudFront distributions are set to HTTPS.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cloudfront",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudFront",
|
||||
"SubServiceName": "Distributions",
|
||||
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudFrontDistribution",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cloudfront_distributions_logging_enabled",
|
||||
"CheckTitle": "Check if CloudFront distributions have logging enabled.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cloudfront",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudFront",
|
||||
"SubServiceName": "Distributions",
|
||||
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudFrontDistribution",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cloudfront_distributions_using_deprecated_ssl_protocols",
|
||||
"CheckTitle": "Check if CloudFront distributions are using deprecated SSL protocols.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cloudfront",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudFront",
|
||||
"SubServiceName": "Distributions",
|
||||
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsCloudFrontDistribution",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"IAM"
|
||||
],
|
||||
"ServiceName": "cloudfront",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudFront",
|
||||
"SubServiceName": "Distributions",
|
||||
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudFrontDistribution",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Insights",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "critical",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -7,8 +7,8 @@
|
||||
"Industry and Regulatory Standards",
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "high",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Logging and Monitoring"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsS3Bucket",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Logging and Monitoring"
|
||||
],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "low",
|
||||
"ResourceType": "AwsS3Bucket",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cloudtrail_threat_detection_enumeration",
|
||||
"CheckTitle": "Ensure there are no potential enumeration threats in CloudTrail",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "critical",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cloudtrail_threat_detection_privilege_escalation",
|
||||
"CheckTitle": "Ensure there are no potential privilege escalation threats in CloudTrail",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cloudtrail",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudTrail",
|
||||
"SubServiceName": "Trails",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "critical",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Alarms",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Alarms",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Alarms",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Alarms",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+1
-1
@@ -5,7 +5,7 @@
|
||||
"CheckType": [
|
||||
"Logging and Monitoring"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Data Protection"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "logs",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsLogsLogGroup",
|
||||
|
||||
+2
-2
@@ -6,8 +6,8 @@
|
||||
"Protect",
|
||||
"Secure development"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:log-group/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailLogGroup",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Data Retention"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "logs",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsLogsLogGroup",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
|
||||
],
|
||||
"ServiceName": "cloudwatch",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CloudWatch",
|
||||
"SubServiceName": "Logs",
|
||||
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCloudTrailTrail",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "codeartifact_packages_external_public_publishing_disabled",
|
||||
"CheckTitle": "Ensure CodeArtifact internal packages do not allow external public source publishing.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "codeartifact",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CodeArtifact",
|
||||
"SubServiceName": "Repositories",
|
||||
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:repository/repository-name",
|
||||
"Severity": "critical",
|
||||
"ResourceType": "Other",
|
||||
|
||||
+2
-2
@@ -6,8 +6,8 @@
|
||||
"Software and Configuration Checks",
|
||||
"Industry and Regulatory Standards"
|
||||
],
|
||||
"ServiceName": "codebuild",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CodeBuild",
|
||||
"SubServiceName": "Projects",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCodeBuildProject",
|
||||
|
||||
+2
-2
@@ -6,8 +6,8 @@
|
||||
"Software and Configuration Checks",
|
||||
"Industry and Regulatory Standards"
|
||||
],
|
||||
"ServiceName": "codebuild",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "CodeBuild",
|
||||
"SubServiceName": "Projects",
|
||||
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCodeBuildProject",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_identity_pool_guest_access_disabled",
|
||||
"CheckTitle": "Ensure Cognito Identity Pool has guest access disabled",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "IdentityPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:identitypool/identitypool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoIdentityPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_advanced_security_enabled",
|
||||
"CheckTitle": "Ensure cognito user pools has advanced security enabled with full-function",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_blocks_compromised_credentials_sign_in_attempts",
|
||||
"CheckTitle": "Ensure that advanced security features are enabled for Amazon Cognito User Pools to block sign-in by users with suspected compromised credentials",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_blocks_potential_malicious_sign_in_attempts",
|
||||
"CheckTitle": "Ensure that your Amazon Cognito user pool blocks potential malicious sign-in attempts",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_client_prevent_user_existence_errors",
|
||||
"CheckTitle": "Amazon Cognito User Pool should prevent user existence errors",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPoolClient",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_client_token_revocation_enabled",
|
||||
"CheckTitle": "Ensure that token revocation is enabled for Amazon Cognito User Pools",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPoolClient",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_deletion_protection_enabled",
|
||||
"CheckTitle": "Ensure cognito user pools deletion protection enabled to prevent accidental deletion",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_mfa_enabled",
|
||||
"CheckTitle": "Ensure Multi-Factor Authentication (MFA) is enabled for Amazon Cognito User Pools",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_password_policy_lowercase",
|
||||
"CheckTitle": "Ensure Cognito User Pool has password policy to require at least one lowercase letter",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_password_policy_minimum_length_14",
|
||||
"CheckTitle": "Ensure that the password policy for your user pools require a minimum length of 14 or greater",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_password_policy_number",
|
||||
"CheckTitle": "Ensure that the password policy for your user pool requires a number",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_password_policy_symbol",
|
||||
"CheckTitle": "Ensure that the password policy for your Amazon Cognito user pool requires at least one symbol.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_password_policy_uppercase",
|
||||
"CheckTitle": "Ensure that the password policy for your user pool requires at least one uppercase letter",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_self_registration_disabled",
|
||||
"CheckTitle": "Ensure self registration is disabled for Amazon Cognito User Pools",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_temporary_password_expiration",
|
||||
"CheckTitle": "Ensure that the user pool has a temporary password expiration period of 7 days or less",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -3,8 +3,8 @@
|
||||
"CheckID": "cognito_user_pool_waf_acl_attached",
|
||||
"CheckTitle": "Ensure that Amazon Cognito User Pool is associated with a WAF Web ACL",
|
||||
"CheckType": [],
|
||||
"ServiceName": "cognito",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Cognito",
|
||||
"SubServiceName": "UserPool",
|
||||
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "AwsCognitoUserPool",
|
||||
|
||||
+2
-2
@@ -5,8 +5,8 @@
|
||||
"CheckType": [
|
||||
"Logging and Monitoring"
|
||||
],
|
||||
"ServiceName": "config",
|
||||
"SubServiceName": "",
|
||||
"ServiceName": "Config",
|
||||
"SubServiceName": "Recorder",
|
||||
"ResourceIdTemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id",
|
||||
"Severity": "medium",
|
||||
"ResourceType": "Other",
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
"CheckID": "directoryservice_directory_log_forwarding_enabled",
|
||||
"CheckTitle": "Directory Service monitoring with CloudWatch logs.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "directoryservice",
|
||||
"ServiceName": "DirectoryService",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
"CheckID": "directoryservice_directory_monitor_notifications",
|
||||
"CheckTitle": "Directory Service has SNS Notifications enabled.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "directoryservice",
|
||||
"ServiceName": "DirectoryService",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
"CheckID": "directoryservice_directory_snapshots_limit",
|
||||
"CheckTitle": "Directory Service Manual Snapshots limit reached.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "directoryservice",
|
||||
"ServiceName": "DirectoryService",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id",
|
||||
"Severity": "low",
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
"CheckID": "directoryservice_ldap_certificate_expiration",
|
||||
"CheckTitle": "Directory Service LDAP Certificates expiration.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "directoryservice",
|
||||
"ServiceName": "DirectoryService",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id",
|
||||
"Severity": "medium",
|
||||
|
||||
+1
-1
@@ -3,7 +3,7 @@
|
||||
"CheckID": "directoryservice_radius_server_security_protocol",
|
||||
"CheckTitle": "Ensure Radius server in DS is using the recommended security protocol.",
|
||||
"CheckType": [],
|
||||
"ServiceName": "directoryservice",
|
||||
"ServiceName": "DirectoryService",
|
||||
"SubServiceName": "",
|
||||
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id",
|
||||
"Severity": "medium",
|
||||
|
||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user