feat(metadata): update checks medatada services/subservices

This commit is contained in:
pedrooot
2024-05-16 11:18:56 +02:00
parent 8b5a089a32
commit b14cfe14e4
325 changed files with 562 additions and 562 deletions
@@ -5,7 +5,7 @@
"CheckType": [
"IAM"
],
"ServiceName": "accessanalyzer",
"ServiceName": "AccessAnalyzer",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id",
"Severity": "low",
@@ -5,7 +5,7 @@
"CheckType": [
"IAM"
],
"ServiceName": "accessanalyzer",
"ServiceName": "AccessAnalyzer",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id",
"Severity": "low",
@@ -5,7 +5,7 @@
"CheckType": [
"IAM"
],
"ServiceName": "account",
"ServiceName": "Account",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id",
"Severity": "medium",
@@ -5,7 +5,7 @@
"CheckType": [
"IAM"
],
"ServiceName": "account",
"ServiceName": "Account",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id",
"Severity": "medium",
@@ -5,7 +5,7 @@
"CheckType": [
"IAM"
],
"ServiceName": "account",
"ServiceName": "Account",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id",
"Severity": "medium",
@@ -5,7 +5,7 @@
"CheckType": [
"IAM"
],
"ServiceName": "account",
"ServiceName": "Account",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id",
"Severity": "medium",
@@ -5,7 +5,7 @@
"CheckType": [
"Data Protection"
],
"ServiceName": "acm",
"ServiceName": "ACM",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:acm:region:account-id:certificate/resource-id",
"Severity": "high",
@@ -5,7 +5,7 @@
"CheckType": [
"Logging and Monitoring"
],
"ServiceName": "acm",
"ServiceName": "ACM",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:acm:region:account-id:certificate/resource-id",
"Severity": "medium",
@@ -8,8 +8,8 @@
"CheckType": [
"IAM"
],
"ServiceName": "apigateway",
"SubServiceName": "rest_api",
"ServiceName": "APIGateway",
"SubServiceName": "RestApi",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsApiGatewayRestApi",
@@ -8,8 +8,8 @@
"CheckType": [
"Data Protection"
],
"ServiceName": "apigateway",
"SubServiceName": "rest_api",
"ServiceName": "APIGateway",
"SubServiceName": "RestApi",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsApiGatewayStage",
@@ -8,8 +8,8 @@
"CheckType": [
"Logging and Monitoring"
],
"ServiceName": "apigateway",
"SubServiceName": "rest_api",
"ServiceName": "APIGateway",
"SubServiceName": "RestApi",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsApiGatewayStage",
@@ -8,8 +8,8 @@
"CheckType": [
"Infrastructure Security"
],
"ServiceName": "apigateway",
"SubServiceName": "rest_api",
"ServiceName": "APIGateway",
"SubServiceName": "RestApi",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsApiGatewayRestApi",
@@ -8,8 +8,8 @@
"CheckType": [
"Infrastructure Security"
],
"ServiceName": "apigateway",
"SubServiceName": "rest_api",
"ServiceName": "APIGateway",
"SubServiceName": "RestApi",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsApiGatewayRestApi",
@@ -8,8 +8,8 @@
"CheckType": [
"Infrastructure Security"
],
"ServiceName": "apigateway",
"SubServiceName": "rest_api",
"ServiceName": "APIGateway",
"SubServiceName": "RestApi",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsApiGatewayStage",
@@ -8,7 +8,7 @@
"CheckType": [
"IAM"
],
"ServiceName": "apigateway",
"ServiceName": "APIGatewayV2",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
@@ -8,7 +8,7 @@
"CheckType": [
"Logging and Monitoring"
],
"ServiceName": "apigateway",
"ServiceName": "APIGatewayV2",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
@@ -7,7 +7,7 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "appstream",
"ServiceName": "AppStream",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id",
"Severity": "medium",
@@ -5,7 +5,7 @@
"CheckType": [
"Infrastructure Security"
],
"ServiceName": "appstream",
"ServiceName": "AppStream",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id",
"Severity": "medium",
@@ -7,7 +7,7 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "appstream",
"ServiceName": "AppStream",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id",
"Severity": "medium",
@@ -7,7 +7,7 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "appstream",
"ServiceName": "AppStream",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id",
"Severity": "medium",
@@ -5,7 +5,7 @@
"CheckType": [
"Software and Configuration Checks"
],
"ServiceName": "athena",
"ServiceName": "Athena",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:athena:region:account-id:workgroup/resource-id",
"Severity": "medium",
@@ -5,7 +5,7 @@
"CheckType": [
"Software and Configuration Checks"
],
"ServiceName": "athena",
"ServiceName": "Athena",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:athena:region:account-id:workgroup/resource-id",
"Severity": "medium",
@@ -5,7 +5,7 @@
"CheckType": [
"IAM"
],
"ServiceName": "autoscaling",
"ServiceName": "AutoScaling",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:autoscaling:region:account-id:autoScalingGroupName/resource-name",
"Severity": "critical",
@@ -3,7 +3,7 @@
"CheckID": "autoscaling_group_multiple_az",
"CheckTitle": "EC2 Auto Scaling Group should use multiple Availability Zones",
"CheckType": [],
"ServiceName": "autoscaling",
"ServiceName": "AutoScaling",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:autoscaling:region:account-id:autoScalingGroupName/resource-name",
"Severity": "medium",
@@ -3,8 +3,8 @@
"CheckID": "awslambda_function_invoke_api_operations_cloudtrail_logging_enabled",
"CheckTitle": "Check if Lambda functions invoke API operations are being recorded by CloudTrail.",
"CheckType": [],
"ServiceName": "lambda",
"SubServiceName": "",
"ServiceName": "Lambda",
"SubServiceName": "Functions",
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
"Severity": "low",
"ResourceType": "AwsLambdaFunction",
@@ -3,8 +3,8 @@
"CheckID": "awslambda_function_no_secrets_in_code",
"CheckTitle": "Find secrets in Lambda functions code.",
"CheckType": [],
"ServiceName": "lambda",
"SubServiceName": "",
"ServiceName": "Lambda",
"SubServiceName": "Functions",
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
"Severity": "critical",
"ResourceType": "AwsLambdaFunction",
@@ -3,8 +3,8 @@
"CheckID": "awslambda_function_no_secrets_in_variables",
"CheckTitle": "Find secrets in Lambda functions variables.",
"CheckType": [],
"ServiceName": "lambda",
"SubServiceName": "",
"ServiceName": "Lambda",
"SubServiceName": "Functions",
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
"Severity": "critical",
"ResourceType": "AwsLambdaFunction",
@@ -3,8 +3,8 @@
"CheckID": "awslambda_function_not_publicly_accessible",
"CheckTitle": "Check if Lambda functions have resource-based policy set as Public.",
"CheckType": [],
"ServiceName": "lambda",
"SubServiceName": "",
"ServiceName": "Lambda",
"SubServiceName": "Functions",
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
"Severity": "critical",
"ResourceType": "AwsLambdaFunction",
@@ -3,8 +3,8 @@
"CheckID": "awslambda_function_url_cors_policy",
"CheckTitle": "Check Lambda Function URL CORS configuration.",
"CheckType": [],
"ServiceName": "lambda",
"SubServiceName": "",
"ServiceName": "Lambda",
"SubServiceName": "Functions",
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
"Severity": "medium",
"ResourceType": "AwsLambdaFunction",
@@ -3,8 +3,8 @@
"CheckID": "awslambda_function_url_public",
"CheckTitle": "Check Public Lambda Function URL.",
"CheckType": [],
"ServiceName": "lambda",
"SubServiceName": "",
"ServiceName": "Lambda",
"SubServiceName": "Functions",
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
"Severity": "high",
"ResourceType": "AwsLambdaFunction",
@@ -3,8 +3,8 @@
"CheckID": "awslambda_function_using_supported_runtimes",
"CheckTitle": "Find obsolete Lambda runtimes.",
"CheckType": [],
"ServiceName": "lambda",
"SubServiceName": "",
"ServiceName": "Lambda",
"SubServiceName": "Functions",
"ResourceIdTemplate": "arn:partition:lambda:region:account-id:function/function-name",
"Severity": "medium",
"ResourceType": "AwsLambdaFunction",
@@ -7,8 +7,8 @@
"Resilience",
"Backup"
],
"ServiceName": "backup",
"SubServiceName": "",
"ServiceName": "Backup",
"SubServiceName": "Plans",
"ResourceIdTemplate": "arn:partition:service:region:account-id:backup-plan:backup-plan-id",
"Severity": "low",
"ResourceType": "AwsBackupBackupPlan",
@@ -7,8 +7,8 @@
"Resilience",
"Backup"
],
"ServiceName": "backup",
"SubServiceName": "",
"ServiceName": "Backup",
"SubServiceName": "ReportPlan",
"ResourceIdTemplate": "arn:partition:service:region:account-id:backup-report-plan:backup-report-plan-id",
"Severity": "low",
"ResourceType": "Other",
@@ -8,8 +8,8 @@
"Backup",
"Data Protection"
],
"ServiceName": "backup",
"SubServiceName": "",
"ServiceName": "Backup",
"SubServiceName": "Vaults",
"ResourceIdTemplate": "arn:partition:service:region:account-id:backup-vault:backup-vault-id",
"Severity": "medium",
"ResourceType": "AwsBackupBackupVault",
@@ -7,8 +7,8 @@
"Resilience",
"Backup"
],
"ServiceName": "backup",
"SubServiceName": "",
"ServiceName": "Backup",
"SubServiceName": "Vaults",
"ResourceIdTemplate": "arn:partition:service:region:account-id:backup-vault:backup-vault-id",
"Severity": "low",
"ResourceType": "AwsBackupBackupVault",
@@ -3,8 +3,8 @@
"CheckID": "cloudformation_stack_outputs_find_secrets",
"CheckTitle": "Find secrets in CloudFormation outputs",
"CheckType": [],
"ServiceName": "cloudformation",
"SubServiceName": "",
"ServiceName": "CloudFormation",
"SubServiceName": "Stacks",
"ResourceIdTemplate": "arn:partition:cloudformation:region:account-id:stack/resource-id",
"Severity": "critical",
"ResourceType": "AwsCloudFormationStack",
@@ -3,8 +3,8 @@
"CheckID": "cloudformation_stacks_termination_protection_enabled",
"CheckTitle": "Enable termination protection for Cloudformation Stacks",
"CheckType": [],
"ServiceName": "cloudformation",
"SubServiceName": "",
"ServiceName": "CloudFormation",
"SubServiceName": "Stacks",
"ResourceIdTemplate": "arn:partition:cloudformation:region:account-id:stack/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudFormationStack",
@@ -3,8 +3,8 @@
"CheckID": "cloudfront_distributions_field_level_encryption_enabled",
"CheckTitle": "Check if CloudFront distributions have Field Level Encryption enabled.",
"CheckType": [],
"ServiceName": "cloudfront",
"SubServiceName": "",
"ServiceName": "CloudFront",
"SubServiceName": "Distributions",
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
"Severity": "low",
"ResourceType": "AwsCloudFrontDistribution",
@@ -3,8 +3,8 @@
"CheckID": "cloudfront_distributions_geo_restrictions_enabled",
"CheckTitle": "Check if Geo restrictions are enabled in CloudFront distributions.",
"CheckType": [],
"ServiceName": "cloudfront",
"SubServiceName": "",
"ServiceName": "CloudFront",
"SubServiceName": "Distributions",
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
"Severity": "low",
"ResourceType": "AwsCloudFrontDistribution",
@@ -3,8 +3,8 @@
"CheckID": "cloudfront_distributions_https_enabled",
"CheckTitle": "Check if CloudFront distributions are set to HTTPS.",
"CheckType": [],
"ServiceName": "cloudfront",
"SubServiceName": "",
"ServiceName": "CloudFront",
"SubServiceName": "Distributions",
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudFrontDistribution",
@@ -3,8 +3,8 @@
"CheckID": "cloudfront_distributions_logging_enabled",
"CheckTitle": "Check if CloudFront distributions have logging enabled.",
"CheckType": [],
"ServiceName": "cloudfront",
"SubServiceName": "",
"ServiceName": "CloudFront",
"SubServiceName": "Distributions",
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudFrontDistribution",
@@ -3,8 +3,8 @@
"CheckID": "cloudfront_distributions_using_deprecated_ssl_protocols",
"CheckTitle": "Check if CloudFront distributions are using deprecated SSL protocols.",
"CheckType": [],
"ServiceName": "cloudfront",
"SubServiceName": "",
"ServiceName": "CloudFront",
"SubServiceName": "Distributions",
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
"Severity": "low",
"ResourceType": "AwsCloudFrontDistribution",
@@ -5,8 +5,8 @@
"CheckType": [
"IAM"
],
"ServiceName": "cloudfront",
"SubServiceName": "",
"ServiceName": "CloudFront",
"SubServiceName": "Distributions",
"ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudFrontDistribution",
@@ -7,8 +7,8 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -7,8 +7,8 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "low",
"ResourceType": "AwsCloudTrailTrail",
@@ -7,8 +7,8 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Insights",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "low",
"ResourceType": "AwsCloudTrailTrail",
@@ -7,8 +7,8 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -7,8 +7,8 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -7,8 +7,8 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -7,8 +7,8 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "critical",
"ResourceType": "AwsCloudTrailTrail",
@@ -7,8 +7,8 @@
"Industry and Regulatory Standards",
"CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "high",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "low",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Logging and Monitoring"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "low",
"ResourceType": "AwsS3Bucket",
@@ -5,8 +5,8 @@
"CheckType": [
"Logging and Monitoring"
],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "low",
"ResourceType": "AwsS3Bucket",
@@ -3,8 +3,8 @@
"CheckID": "cloudtrail_threat_detection_enumeration",
"CheckTitle": "Ensure there are no potential enumeration threats in CloudTrail",
"CheckType": [],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "critical",
"ResourceType": "AwsCloudTrailTrail",
@@ -3,8 +3,8 @@
"CheckID": "cloudtrail_threat_detection_privilege_escalation",
"CheckTitle": "Ensure there are no potential privilege escalation threats in CloudTrail",
"CheckType": [],
"ServiceName": "cloudtrail",
"SubServiceName": "",
"ServiceName": "CloudTrail",
"SubServiceName": "Trails",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "critical",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Alarms",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Alarms",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Alarms",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Alarms",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,7 +5,7 @@
"CheckType": [
"Logging and Monitoring"
],
"ServiceName": "cloudwatch",
"ServiceName": "CloudWatch",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
@@ -5,8 +5,8 @@
"CheckType": [
"Data Protection"
],
"ServiceName": "cloudwatch",
"SubServiceName": "logs",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsLogsLogGroup",
@@ -6,8 +6,8 @@
"Protect",
"Secure development"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:log-group/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailLogGroup",
@@ -5,8 +5,8 @@
"CheckType": [
"Data Retention"
],
"ServiceName": "cloudwatch",
"SubServiceName": "logs",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsLogsLogGroup",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -5,8 +5,8 @@
"CheckType": [
"Software and Configuration Checks/Industry and Regulatory Standards/CIS AWS Foundations Benchmark"
],
"ServiceName": "cloudwatch",
"SubServiceName": "",
"ServiceName": "CloudWatch",
"SubServiceName": "Logs",
"ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id",
"Severity": "medium",
"ResourceType": "AwsCloudTrailTrail",
@@ -3,8 +3,8 @@
"CheckID": "codeartifact_packages_external_public_publishing_disabled",
"CheckTitle": "Ensure CodeArtifact internal packages do not allow external public source publishing.",
"CheckType": [],
"ServiceName": "codeartifact",
"SubServiceName": "",
"ServiceName": "CodeArtifact",
"SubServiceName": "Repositories",
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:repository/repository-name",
"Severity": "critical",
"ResourceType": "Other",
@@ -6,8 +6,8 @@
"Software and Configuration Checks",
"Industry and Regulatory Standards"
],
"ServiceName": "codebuild",
"SubServiceName": "",
"ServiceName": "CodeBuild",
"SubServiceName": "Projects",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsCodeBuildProject",
@@ -6,8 +6,8 @@
"Software and Configuration Checks",
"Industry and Regulatory Standards"
],
"ServiceName": "codebuild",
"SubServiceName": "",
"ServiceName": "CodeBuild",
"SubServiceName": "Projects",
"ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id",
"Severity": "medium",
"ResourceType": "AwsCodeBuildProject",
@@ -3,8 +3,8 @@
"CheckID": "cognito_identity_pool_guest_access_disabled",
"CheckTitle": "Ensure Cognito Identity Pool has guest access disabled",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "IdentityPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:identitypool/identitypool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoIdentityPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_advanced_security_enabled",
"CheckTitle": "Ensure cognito user pools has advanced security enabled with full-function",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_blocks_compromised_credentials_sign_in_attempts",
"CheckTitle": "Ensure that advanced security features are enabled for Amazon Cognito User Pools to block sign-in by users with suspected compromised credentials",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_blocks_potential_malicious_sign_in_attempts",
"CheckTitle": "Ensure that your Amazon Cognito user pool blocks potential malicious sign-in attempts",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_client_prevent_user_existence_errors",
"CheckTitle": "Amazon Cognito User Pool should prevent user existence errors",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPoolClient",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_client_token_revocation_enabled",
"CheckTitle": "Ensure that token revocation is enabled for Amazon Cognito User Pools",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPoolClient",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_deletion_protection_enabled",
"CheckTitle": "Ensure cognito user pools deletion protection enabled to prevent accidental deletion",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_mfa_enabled",
"CheckTitle": "Ensure Multi-Factor Authentication (MFA) is enabled for Amazon Cognito User Pools",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_password_policy_lowercase",
"CheckTitle": "Ensure Cognito User Pool has password policy to require at least one lowercase letter",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_password_policy_minimum_length_14",
"CheckTitle": "Ensure that the password policy for your user pools require a minimum length of 14 or greater",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_password_policy_number",
"CheckTitle": "Ensure that the password policy for your user pool requires a number",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_password_policy_symbol",
"CheckTitle": "Ensure that the password policy for your Amazon Cognito user pool requires at least one symbol.",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_password_policy_uppercase",
"CheckTitle": "Ensure that the password policy for your user pool requires at least one uppercase letter",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_self_registration_disabled",
"CheckTitle": "Ensure self registration is disabled for Amazon Cognito User Pools",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_temporary_password_expiration",
"CheckTitle": "Ensure that the user pool has a temporary password expiration period of 7 days or less",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -3,8 +3,8 @@
"CheckID": "cognito_user_pool_waf_acl_attached",
"CheckTitle": "Ensure that Amazon Cognito User Pool is associated with a WAF Web ACL",
"CheckType": [],
"ServiceName": "cognito",
"SubServiceName": "",
"ServiceName": "Cognito",
"SubServiceName": "UserPool",
"ResourceIdTemplate": "arn:aws:cognito-idp:region:account:userpool/userpool-id",
"Severity": "medium",
"ResourceType": "AwsCognitoUserPool",
@@ -5,8 +5,8 @@
"CheckType": [
"Logging and Monitoring"
],
"ServiceName": "config",
"SubServiceName": "",
"ServiceName": "Config",
"SubServiceName": "Recorder",
"ResourceIdTemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id",
"Severity": "medium",
"ResourceType": "Other",
@@ -3,7 +3,7 @@
"CheckID": "directoryservice_directory_log_forwarding_enabled",
"CheckTitle": "Directory Service monitoring with CloudWatch logs.",
"CheckType": [],
"ServiceName": "directoryservice",
"ServiceName": "DirectoryService",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id",
"Severity": "medium",
@@ -3,7 +3,7 @@
"CheckID": "directoryservice_directory_monitor_notifications",
"CheckTitle": "Directory Service has SNS Notifications enabled.",
"CheckType": [],
"ServiceName": "directoryservice",
"ServiceName": "DirectoryService",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id",
"Severity": "medium",
@@ -3,7 +3,7 @@
"CheckID": "directoryservice_directory_snapshots_limit",
"CheckTitle": "Directory Service Manual Snapshots limit reached.",
"CheckType": [],
"ServiceName": "directoryservice",
"ServiceName": "DirectoryService",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id",
"Severity": "low",
@@ -3,7 +3,7 @@
"CheckID": "directoryservice_ldap_certificate_expiration",
"CheckTitle": "Directory Service LDAP Certificates expiration.",
"CheckType": [],
"ServiceName": "directoryservice",
"ServiceName": "DirectoryService",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id",
"Severity": "medium",
@@ -3,7 +3,7 @@
"CheckID": "directoryservice_radius_server_security_protocol",
"CheckTitle": "Ensure Radius server in DS is using the recommended security protocol.",
"CheckType": [],
"ServiceName": "directoryservice",
"ServiceName": "DirectoryService",
"SubServiceName": "",
"ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id",
"Severity": "medium",

Some files were not shown because too many files have changed in this diff Show More