From e57a460bae4459c471909f2f916257dd00f9ed3f Mon Sep 17 00:00:00 2001 From: Prowler Bot Date: Tue, 17 Sep 2024 18:15:34 +0200 Subject: [PATCH] chore(AWS): match all AWS resource types with SecurityHub supported types in metadata (#5064) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Co-authored-by: Rubén De la Torre Vico --- ...i_client_certificate_enabled.metadata.json | 2 +- ...eway_restapi_logging_enabled.metadata.json | 2 +- ...way_restapi_waf_acl_attached.metadata.json | 2 +- ...ult_internet_access_disabled.metadata.json | 2 +- ...eet_maximum_session_duration.metadata.json | 2 +- ...t_session_disconnect_timeout.metadata.json | 2 +- ...sion_idle_disconnect_timeout.metadata.json | 2 +- .../athena_workgroup_encryption.metadata.json | 2 +- ...kgroup_enforce_configuration.metadata.json | 2 +- ...ets_ec2_launch_configuration.metadata.json | 2 +- ...utoscaling_group_multiple_az.metadata.json | 2 +- .../backup_reportplans_exist.metadata.json | 2 +- ...tions_custom_ssl_certificate.metadata.json | 32 +++++++++++++++++ ...ibutions_default_root_object.metadata.json | 30 ++++++++++++++++ ...tributions_https_sni_enabled.metadata.json | 32 +++++++++++++++++ ...l_s3_dataevents_read_enabled.metadata.json | 2 +- ..._s3_dataevents_write_enabled.metadata.json | 2 +- ...etwork_acls_alarm_configured.metadata.json | 2 +- ...rk_gateways_alarm_configured.metadata.json | 2 +- ...oute_tables_alarm_configured.metadata.json | 2 +- ...ges_to_vpcs_alarm_configured.metadata.json | 2 +- ...oss_account_sharing_disabled.metadata.json | 2 +- ...group_kms_encryption_enabled.metadata.json | 2 +- ...log_group_no_secrets_in_logs.metadata.json | 2 +- ...onfiguration_changes_enabled.metadata.json | 2 +- ...onfiguration_changes_enabled.metadata.json | 2 +- ...lter_authentication_failures.metadata.json | 2 +- ...er_aws_organizations_changes.metadata.json | 2 +- ...cheduled_deletion_of_kms_cmk.metadata.json | 2 +- ...for_s3_bucket_policy_changes.metadata.json | 2 +- ...metric_filter_policy_changes.metadata.json | 2 +- ...log_metric_filter_root_usage.metadata.json | 2 +- ...ilter_security_group_changes.metadata.json | 2 +- ...c_filter_sign_in_without_mfa.metadata.json | 2 +- ...ilter_unauthorized_api_calls.metadata.json | 2 +- ...y_pool_guest_access_disabled.metadata.json | 30 ++++++++++++++++ ...ctory_log_forwarding_enabled.metadata.json | 2 +- ...ectory_monitor_notifications.metadata.json | 2 +- ...ce_directory_snapshots_limit.metadata.json | 2 +- ..._ldap_certificate_expiration.metadata.json | 2 +- ...ius_server_security_protocol.metadata.json | 2 +- ...supported_mfa_radius_enabled.metadata.json | 2 +- ...luster_cloudwatch_log_export.metadata.json | 30 ++++++++++++++++ ..._cluster_deletion_protection.metadata.json | 30 ++++++++++++++++ ...ntdb_cluster_public_snapshot.metadata.json | 30 ++++++++++++++++ ...db_cluster_storage_encrypted.metadata.json | 32 +++++++++++++++++ ...r_cluster_encryption_enabled.metadata.json | 2 +- ...b_table_cross_account_access.metadata.json | 34 +++++++++++++++++++ ...s_kms_cmk_encryption_enabled.metadata.json | 2 +- ...dynamodb_tables_pitr_enabled.metadata.json | 2 +- .../ec2_ebs_public_snapshot.metadata.json | 2 +- ..._account_block_public_access.metadata.json | 34 +++++++++++++++++++ .../ec2_ebs_snapshots_encrypted.metadata.json | 2 +- ...emcached_exposed_to_internet.metadata.json | 34 +++++++++++++++++++ ..._scan_images_on_push_enabled.metadata.json | 2 +- ...s_encryption_at_rest_enabled.metadata.json | 2 +- .../efs_have_backup_enabled.metadata.json | 2 +- .../efs_not_publicly_accessible.metadata.json | 2 +- ...e_cluster_uses_public_subnet.metadata.json | 2 +- ..._auto_minor_version_upgrades.metadata.json | 30 ++++++++++++++++ ...r_automatic_failover_enabled.metadata.json | 30 ++++++++++++++++ ...redis_cluster_backup_enabled.metadata.json | 30 ++++++++++++++++ ...n_transit_encryption_enabled.metadata.json | 32 +++++++++++++++++ ...dis_cluster_multi_az_enabled.metadata.json | 30 ++++++++++++++++ ...ster_rest_encryption_enabled.metadata.json | 32 +++++++++++++++++ ..._zone_load_balancing_enabled.metadata.json | 30 ++++++++++++++++ .../elbv2_deletion_protection.metadata.json | 2 +- ...elbv2_desync_mitigation_mode.metadata.json | 2 +- .../elbv2_insecure_ssl_ciphers.metadata.json | 2 +- .../elbv2_internet_facing.metadata.json | 2 +- .../elbv2_is_in_multiple_az.metadata.json | 30 ++++++++++++++++ .../elbv2_listeners_underneath.metadata.json | 2 +- .../elbv2_logging_enabled.metadata.json | 2 +- .../elbv2_ssl_listeners.metadata.json | 2 +- .../elbv2_waf_acl_attached.metadata.json | 2 +- ...account_public_block_enabled.metadata.json | 2 +- ...er_master_nodes_no_public_ip.metadata.json | 2 +- ...r_cluster_publicly_accesible.metadata.json | 2 +- ..._vaults_policy_public_access.metadata.json | 2 +- ...passwords_encryption_enabled.metadata.json | 2 +- ..._metadata_encryption_enabled.metadata.json | 2 +- ...base_connections_ssl_enabled.metadata.json | 2 +- ...atch_logs_encryption_enabled.metadata.json | 2 +- ..._bookmark_encryption_enabled.metadata.json | 2 +- ...points_s3_encryption_enabled.metadata.json | 2 +- ...amazon_s3_encryption_enabled.metadata.json | 2 +- ...atch_logs_encryption_enabled.metadata.json | 2 +- ..._bookmark_encryption_enabled.metadata.json | 2 +- .../guardduty_centrally_managed.metadata.json | 2 +- ..._allows_privilege_escalation.metadata.json | 33 ++++++++++++++++++ ...no_administrative_privileges.metadata.json | 4 +-- ...d_server_certificates_stored.metadata.json | 2 +- .../iam_no_root_access_key.metadata.json | 2 +- ...words_within_90_days_or_less.metadata.json | 2 +- ...am_password_policy_lowercase.metadata.json | 2 +- ...ord_policy_minimum_length_14.metadata.json | 2 +- .../iam_password_policy_number.metadata.json | 2 +- ...iam_password_policy_reuse_24.metadata.json | 2 +- .../iam_password_policy_symbol.metadata.json | 2 +- ...am_password_policy_uppercase.metadata.json | 2 +- ...ached_only_to_group_or_roles.metadata.json | 2 +- ...am_rotate_access_key_90_days.metadata.json | 2 +- ..._no_setup_initial_access_key.metadata.json | 2 +- ..._encryption_at_rest_uses_cmk.metadata.json | 32 +++++++++++++++++ ..._enhanced_monitoring_enabled.metadata.json | 30 ++++++++++++++++ ...n_transit_encryption_enabled.metadata.json | 32 +++++++++++++++++ .../kafka_cluster_is_public.metadata.json | 30 ++++++++++++++++ ...l_tls_authentication_enabled.metadata.json | 30 ++++++++++++++++ ...unrestricted_access_disabled.metadata.json | 30 ++++++++++++++++ ..._cluster_uses_latest_version.metadata.json | 32 +++++++++++++++++ .../lightsail_database_public.metadata.json | 34 +++++++++++++++++++ ...instance_automated_snapshots.metadata.json | 32 +++++++++++++++++ .../lightsail_instance_public.metadata.json | 30 ++++++++++++++++ .../lightsail_static_ip_unused.metadata.json | 30 ++++++++++++++++ .../macie_is_enabled.metadata.json | 2 +- ...tune_cluster_public_snapshot.metadata.json | 30 ++++++++++++++++ ...ne_cluster_storage_encrypted.metadata.json | 30 ++++++++++++++++ ...e_cluster_uses_public_subnet.metadata.json | 2 +- ...firewall_deletion_protection.metadata.json | 30 ++++++++++++++++ .../networkfirewall_in_all_vpc.metadata.json | 2 +- ...omains_audit_logging_enabled.metadata.json | 2 +- ...s_cloudwatch_logging_enabled.metadata.json | 2 +- ...s_encryption_at_rest_enabled.metadata.json | 2 +- ...ttps_communications_enforced.metadata.json | 2 +- ...ternal_user_database_enabled.metadata.json | 2 +- ...e_to_node_encryption_enabled.metadata.json | 2 +- ...ains_not_publicly_accessible.metadata.json | 2 +- ...est_service_software_version.metadata.json | 2 +- ...to_authentication_for_kibana.metadata.json | 2 +- ...ds_cluster_backtrack_enabled.metadata.json | 30 ++++++++++++++++ ..._critical_event_subscription.metadata.json | 32 +++++++++++++++++ ...ngling_ip_subdomain_takeover.metadata.json | 2 +- ...s_privacy_protection_enabled.metadata.json | 2 +- ...domains_transferlock_enabled.metadata.json | 2 +- ...t_level_public_access_blocks.metadata.json | 2 +- ...ls_network_isolation_enabled.metadata.json | 2 +- ...dels_vpc_settings_configured.metadata.json | 2 +- ...container_encryption_enabled.metadata.json | 2 +- ...bs_network_isolation_enabled.metadata.json | 2 +- ...nd_output_encryption_enabled.metadata.json | 2 +- ...jobs_vpc_settings_configured.metadata.json | 2 +- .../securityhub_enabled.metadata.json | 2 +- ...on_in_classic_load_balancers.metadata.json | 2 +- ...ction_in_global_accelerators.metadata.json | 2 +- ...ternet_facing_load_balancers.metadata.json | 2 +- ...tion_in_route53_hosted_zones.metadata.json | 2 +- ...ion_not_using_http_endpoints.metadata.json | 32 +++++++++++++++++ ...m_managed_compliant_patching.metadata.json | 2 +- ...fileshare_encryption_enabled.metadata.json | 32 +++++++++++++++++ ...connections_trust_boundaries.metadata.json | 2 +- ...vpc_endpoint_for_ec2_enabled.metadata.json | 30 ++++++++++++++++ ...pc_vpn_connection_tunnels_up.metadata.json | 34 +++++++++++++++++++ ...es_volume_encryption_enabled.metadata.json | 2 +- ...2private_1public_subnets_nat.metadata.json | 2 +- 154 files changed, 1362 insertions(+), 115 deletions(-) create mode 100644 prowler/providers/aws/services/cloudfront/cloudfront_distributions_custom_ssl_certificate/cloudfront_distributions_custom_ssl_certificate.metadata.json create mode 100644 prowler/providers/aws/services/cloudfront/cloudfront_distributions_default_root_object/cloudfront_distributions_default_root_object.metadata.json create mode 100644 prowler/providers/aws/services/cloudfront/cloudfront_distributions_https_sni_enabled/cloudfront_distributions_https_sni_enabled.metadata.json create mode 100644 prowler/providers/aws/services/cognito/cognito_identity_pool_guest_access_disabled/cognito_identity_pool_guest_access_disabled.metadata.json create mode 100644 prowler/providers/aws/services/documentdb/documentdb_cluster_cloudwatch_log_export/documentdb_cluster_cloudwatch_log_export.metadata.json create mode 100644 prowler/providers/aws/services/documentdb/documentdb_cluster_deletion_protection/documentdb_cluster_deletion_protection.metadata.json create mode 100644 prowler/providers/aws/services/documentdb/documentdb_cluster_public_snapshot/documentdb_cluster_public_snapshot.metadata.json create mode 100644 prowler/providers/aws/services/documentdb/documentdb_cluster_storage_encrypted/documentdb_cluster_storage_encrypted.metadata.json create mode 100644 prowler/providers/aws/services/dynamodb/dynamodb_table_cross_account_access/dynamodb_table_cross_account_access.metadata.json create mode 100644 prowler/providers/aws/services/ec2/ec2_ebs_snapshot_account_block_public_access/ec2_ebs_snapshot_account_block_public_access.metadata.json create mode 100644 prowler/providers/aws/services/ec2/ec2_instance_port_memcached_exposed_to_internet/ec2_instance_port_memcached_exposed_to_internet.metadata.json create mode 100644 prowler/providers/aws/services/elasticache/elasticache_redis_cluster_auto_minor_version_upgrades/elasticache_redis_cluster_auto_minor_version_upgrades.metadata.json create mode 100644 prowler/providers/aws/services/elasticache/elasticache_redis_cluster_automatic_failover_enabled/elasticache_redis_cluster_automatic_failover_enabled.metadata.json create mode 100644 prowler/providers/aws/services/elasticache/elasticache_redis_cluster_backup_enabled/elasticache_redis_cluster_backup_enabled.metadata.json create mode 100644 prowler/providers/aws/services/elasticache/elasticache_redis_cluster_in_transit_encryption_enabled/elasticache_redis_cluster_in_transit_encryption_enabled.metadata.json create mode 100644 prowler/providers/aws/services/elasticache/elasticache_redis_cluster_multi_az_enabled/elasticache_redis_cluster_multi_az_enabled.metadata.json create mode 100644 prowler/providers/aws/services/elasticache/elasticache_redis_cluster_rest_encryption_enabled/elasticache_redis_cluster_rest_encryption_enabled.metadata.json create mode 100644 prowler/providers/aws/services/elb/elb_cross_zone_load_balancing_enabled/elb_cross_zone_load_balancing_enabled.metadata.json create mode 100644 prowler/providers/aws/services/elbv2/elbv2_is_in_multiple_az/elbv2_is_in_multiple_az.metadata.json create mode 100644 prowler/providers/aws/services/iam/iam_inline_policy_allows_privilege_escalation/iam_inline_policy_allows_privilege_escalation.metadata.json create mode 100644 prowler/providers/aws/services/kafka/kafka_cluster_encryption_at_rest_uses_cmk/kafka_cluster_encryption_at_rest_uses_cmk.metadata.json create mode 100644 prowler/providers/aws/services/kafka/kafka_cluster_enhanced_monitoring_enabled/kafka_cluster_enhanced_monitoring_enabled.metadata.json create mode 100644 prowler/providers/aws/services/kafka/kafka_cluster_in_transit_encryption_enabled/kafka_cluster_in_transit_encryption_enabled.metadata.json create mode 100644 prowler/providers/aws/services/kafka/kafka_cluster_is_public/kafka_cluster_is_public.metadata.json create mode 100644 prowler/providers/aws/services/kafka/kafka_cluster_mutual_tls_authentication_enabled/kafka_cluster_mutual_tls_authentication_enabled.metadata.json create mode 100644 prowler/providers/aws/services/kafka/kafka_cluster_unrestricted_access_disabled/kafka_cluster_unrestricted_access_disabled.metadata.json create mode 100644 prowler/providers/aws/services/kafka/kafka_cluster_uses_latest_version/kafka_cluster_uses_latest_version.metadata.json create mode 100644 prowler/providers/aws/services/lightsail/lightsail_database_public/lightsail_database_public.metadata.json create mode 100644 prowler/providers/aws/services/lightsail/lightsail_instance_automated_snapshots/lightsail_instance_automated_snapshots.metadata.json create mode 100644 prowler/providers/aws/services/lightsail/lightsail_instance_public/lightsail_instance_public.metadata.json create mode 100644 prowler/providers/aws/services/lightsail/lightsail_static_ip_unused/lightsail_static_ip_unused.metadata.json create mode 100644 prowler/providers/aws/services/neptune/neptune_cluster_public_snapshot/neptune_cluster_public_snapshot.metadata.json create mode 100644 prowler/providers/aws/services/neptune/neptune_cluster_storage_encrypted/neptune_cluster_storage_encrypted.metadata.json create mode 100644 prowler/providers/aws/services/networkfirewall/networkfirewall_deletion_protection/networkfirewall_deletion_protection.metadata.json create mode 100644 prowler/providers/aws/services/rds/rds_cluster_backtrack_enabled/rds_cluster_backtrack_enabled.metadata.json create mode 100644 prowler/providers/aws/services/rds/rds_cluster_critical_event_subscription/rds_cluster_critical_event_subscription.metadata.json create mode 100644 prowler/providers/aws/services/sns/sns_subscription_not_using_http_endpoints/sns_subscription_not_using_http_endpoints.metadata.json create mode 100644 prowler/providers/aws/services/storagegateway/storagegateway_fileshare_encryption_enabled/storagegateway_fileshare_encryption_enabled.metadata.json create mode 100644 prowler/providers/aws/services/vpc/vpc_endpoint_for_ec2_enabled/vpc_endpoint_for_ec2_enabled.metadata.json create mode 100644 prowler/providers/aws/services/vpc/vpc_vpn_connection_tunnels_up/vpc_vpn_connection_tunnels_up.metadata.json diff --git a/prowler/providers/aws/services/apigateway/apigateway_restapi_client_certificate_enabled/apigateway_restapi_client_certificate_enabled.metadata.json b/prowler/providers/aws/services/apigateway/apigateway_restapi_client_certificate_enabled/apigateway_restapi_client_certificate_enabled.metadata.json index 77c5734ff8..36f095f0e8 100644 --- a/prowler/providers/aws/services/apigateway/apigateway_restapi_client_certificate_enabled/apigateway_restapi_client_certificate_enabled.metadata.json +++ b/prowler/providers/aws/services/apigateway/apigateway_restapi_client_certificate_enabled/apigateway_restapi_client_certificate_enabled.metadata.json @@ -12,7 +12,7 @@ "SubServiceName": "rest_api", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsApiGatewayStage", + "ResourceType": "AwsApiGatewayRestApi", "Description": "Check if API Gateway Stage has client certificate enabled to access your backend endpoint.", "Risk": "Possible man in the middle attacks and other similar risks.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/apigateway/apigateway_restapi_logging_enabled/apigateway_restapi_logging_enabled.metadata.json b/prowler/providers/aws/services/apigateway/apigateway_restapi_logging_enabled/apigateway_restapi_logging_enabled.metadata.json index accc6102e0..1d79e8c083 100644 --- a/prowler/providers/aws/services/apigateway/apigateway_restapi_logging_enabled/apigateway_restapi_logging_enabled.metadata.json +++ b/prowler/providers/aws/services/apigateway/apigateway_restapi_logging_enabled/apigateway_restapi_logging_enabled.metadata.json @@ -12,7 +12,7 @@ "SubServiceName": "rest_api", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsApiGatewayStage", + "ResourceType": "AwsApiGatewayRestApi", "Description": "Check if API Gateway Stage has logging enabled.", "Risk": "If not enabled, monitoring of service use is not possible. Real-time monitoring of API calls can be achieved by directing CloudTrail Logs to CloudWatch Logs and establishing corresponding metric filters and alarms.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/apigateway/apigateway_restapi_waf_acl_attached/apigateway_restapi_waf_acl_attached.metadata.json b/prowler/providers/aws/services/apigateway/apigateway_restapi_waf_acl_attached/apigateway_restapi_waf_acl_attached.metadata.json index 62ba94c68a..ba097a6df1 100644 --- a/prowler/providers/aws/services/apigateway/apigateway_restapi_waf_acl_attached/apigateway_restapi_waf_acl_attached.metadata.json +++ b/prowler/providers/aws/services/apigateway/apigateway_restapi_waf_acl_attached/apigateway_restapi_waf_acl_attached.metadata.json @@ -12,7 +12,7 @@ "SubServiceName": "rest_api", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsApiGatewayStage", + "ResourceType": "AwsApiGatewayRestApi", "Description": "Check if API Gateway Stage has a WAF ACL attached.", "Risk": "Potential attacks and / or abuse of service, more even for even for internet reachable services.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/appstream/appstream_fleet_default_internet_access_disabled/appstream_fleet_default_internet_access_disabled.metadata.json b/prowler/providers/aws/services/appstream/appstream_fleet_default_internet_access_disabled/appstream_fleet_default_internet_access_disabled.metadata.json index ab72954b83..8e4c94a601 100644 --- a/prowler/providers/aws/services/appstream/appstream_fleet_default_internet_access_disabled/appstream_fleet_default_internet_access_disabled.metadata.json +++ b/prowler/providers/aws/services/appstream/appstream_fleet_default_internet_access_disabled/appstream_fleet_default_internet_access_disabled.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id", "Severity": "medium", - "ResourceType": "AppStream", + "ResourceType": "Other", "Description": "Ensure default Internet Access from your Amazon AppStream fleet streaming instances should remain unchecked.", "Risk": "Default Internet Access from your fleet streaming instances should be controlled using a NAT gateway in the VPC.", "RelatedUrl": "https://docs.aws.amazon.com/appstream2/latest/developerguide/set-up-stacks-fleets.html", diff --git a/prowler/providers/aws/services/appstream/appstream_fleet_maximum_session_duration/appstream_fleet_maximum_session_duration.metadata.json b/prowler/providers/aws/services/appstream/appstream_fleet_maximum_session_duration/appstream_fleet_maximum_session_duration.metadata.json index 0057d829c6..bb623a8dd8 100644 --- a/prowler/providers/aws/services/appstream/appstream_fleet_maximum_session_duration/appstream_fleet_maximum_session_duration.metadata.json +++ b/prowler/providers/aws/services/appstream/appstream_fleet_maximum_session_duration/appstream_fleet_maximum_session_duration.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id", "Severity": "medium", - "ResourceType": "AppStream", + "ResourceType": "Other", "Description": "Ensure user maximum session duration is no longer than 10 hours.", "Risk": "Having a session duration lasting longer than 10 hours should not be necessary and if running for any malicious reasons provides a greater time for usage than should be allowed.", "RelatedUrl": "https://docs.aws.amazon.com/appstream2/latest/developerguide/set-up-stacks-fleets.html", diff --git a/prowler/providers/aws/services/appstream/appstream_fleet_session_disconnect_timeout/appstream_fleet_session_disconnect_timeout.metadata.json b/prowler/providers/aws/services/appstream/appstream_fleet_session_disconnect_timeout/appstream_fleet_session_disconnect_timeout.metadata.json index 58d6856939..b73618e6a7 100644 --- a/prowler/providers/aws/services/appstream/appstream_fleet_session_disconnect_timeout/appstream_fleet_session_disconnect_timeout.metadata.json +++ b/prowler/providers/aws/services/appstream/appstream_fleet_session_disconnect_timeout/appstream_fleet_session_disconnect_timeout.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id", "Severity": "medium", - "ResourceType": "AppStream", + "ResourceType": "Other", "Description": "Ensure session disconnect timeout is set to 5 minutes or less", "Risk": "Disconnect timeout in minutes, is the amount of of time that a streaming session remains active after users disconnect.", "RelatedUrl": "https://docs.aws.amazon.com/appstream2/latest/developerguide/set-up-stacks-fleets.html", diff --git a/prowler/providers/aws/services/appstream/appstream_fleet_session_idle_disconnect_timeout/appstream_fleet_session_idle_disconnect_timeout.metadata.json b/prowler/providers/aws/services/appstream/appstream_fleet_session_idle_disconnect_timeout/appstream_fleet_session_idle_disconnect_timeout.metadata.json index cbe7cf1d39..d8a5b4935a 100644 --- a/prowler/providers/aws/services/appstream/appstream_fleet_session_idle_disconnect_timeout/appstream_fleet_session_idle_disconnect_timeout.metadata.json +++ b/prowler/providers/aws/services/appstream/appstream_fleet_session_idle_disconnect_timeout/appstream_fleet_session_idle_disconnect_timeout.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:appstream:region:account-id:fleet/resource-id", "Severity": "medium", - "ResourceType": "AppStream", + "ResourceType": "Other", "Description": "Ensure session idle disconnect timeout is set to 10 minutes or less.", "Risk": "Idle disconnect timeout in minutes is the amount of time that users can be inactive before they are disconnected from their streaming session and the Disconnect timeout in minutes time begins.", "RelatedUrl": "https://docs.aws.amazon.com/appstream2/latest/developerguide/set-up-stacks-fleets.html", diff --git a/prowler/providers/aws/services/athena/athena_workgroup_encryption/athena_workgroup_encryption.metadata.json b/prowler/providers/aws/services/athena/athena_workgroup_encryption/athena_workgroup_encryption.metadata.json index 197ce59b67..80f55ec0ba 100644 --- a/prowler/providers/aws/services/athena/athena_workgroup_encryption/athena_workgroup_encryption.metadata.json +++ b/prowler/providers/aws/services/athena/athena_workgroup_encryption/athena_workgroup_encryption.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:athena:region:account-id:workgroup/resource-id", "Severity": "medium", - "ResourceType": "WorkGroup", + "ResourceType": "AwsAthenaWorkGroup", "Description": "Ensure that encryption at rest is enabled for Amazon Athena query results stored in Amazon S3 in order to secure data and meet compliance requirements for data-at-rest encryption.", "Risk": "If not enabled sensitive information at rest is not protected.", "RelatedUrl": "https://docs.aws.amazon.com/athena/latest/ug/encryption.html", diff --git a/prowler/providers/aws/services/athena/athena_workgroup_enforce_configuration/athena_workgroup_enforce_configuration.metadata.json b/prowler/providers/aws/services/athena/athena_workgroup_enforce_configuration/athena_workgroup_enforce_configuration.metadata.json index 46f2e305f2..0888fe3d22 100644 --- a/prowler/providers/aws/services/athena/athena_workgroup_enforce_configuration/athena_workgroup_enforce_configuration.metadata.json +++ b/prowler/providers/aws/services/athena/athena_workgroup_enforce_configuration/athena_workgroup_enforce_configuration.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:athena:region:account-id:workgroup/resource-id", "Severity": "medium", - "ResourceType": "WorkGroup", + "ResourceType": "AwsAthenaWorkGroup", "Description": "Ensure that workgroup configuration is enforced so it cannot be overriden by client-side settings.", "Risk": "If workgroup configuration is not enforced security settings like encryption can be overriden by client-side settings.", "RelatedUrl": "https://docs.aws.amazon.com/athena/latest/ug/workgroups-settings-override.html", diff --git a/prowler/providers/aws/services/autoscaling/autoscaling_find_secrets_ec2_launch_configuration/autoscaling_find_secrets_ec2_launch_configuration.metadata.json b/prowler/providers/aws/services/autoscaling/autoscaling_find_secrets_ec2_launch_configuration/autoscaling_find_secrets_ec2_launch_configuration.metadata.json index b2a6140728..184c719458 100644 --- a/prowler/providers/aws/services/autoscaling/autoscaling_find_secrets_ec2_launch_configuration/autoscaling_find_secrets_ec2_launch_configuration.metadata.json +++ b/prowler/providers/aws/services/autoscaling/autoscaling_find_secrets_ec2_launch_configuration/autoscaling_find_secrets_ec2_launch_configuration.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:autoscaling:region:account-id:autoScalingGroupName/resource-name", "Severity": "critical", - "ResourceType": "Other", + "ResourceType": "AwsAutoScalingLaunchConfiguration", "Description": "Find secrets in EC2 Auto Scaling Launch Configuration", "Risk": "The use of a hard-coded password increases the possibility of password guessing. If hard-coded passwords are used, it is possible that malicious users gain access through the account in question.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/autoscaling/autoscaling_group_multiple_az/autoscaling_group_multiple_az.metadata.json b/prowler/providers/aws/services/autoscaling/autoscaling_group_multiple_az/autoscaling_group_multiple_az.metadata.json index cdd1b58fd7..1b04b2463a 100644 --- a/prowler/providers/aws/services/autoscaling/autoscaling_group_multiple_az/autoscaling_group_multiple_az.metadata.json +++ b/prowler/providers/aws/services/autoscaling/autoscaling_group_multiple_az/autoscaling_group_multiple_az.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:autoscaling:region:account-id:autoScalingGroupName/resource-name", "Severity": "medium", - "ResourceType": "Other", + "ResourceType": "AwsAutoScalingAutoScalingGroup", "Description": "EC2 Auto Scaling Group should use multiple Availability Zones", "Risk": "In case of a failure in a single Availability Zone, the Auto Scaling Group will not be able to launch new instances to replace the failed ones.", "RelatedUrl": "https://docs.aws.amazon.com/autoscaling/ec2/userguide/as-add-availability-zone.html", diff --git a/prowler/providers/aws/services/backup/backup_reportplans_exist/backup_reportplans_exist.metadata.json b/prowler/providers/aws/services/backup/backup_reportplans_exist/backup_reportplans_exist.metadata.json index 0e84b55f3a..c600682e1d 100644 --- a/prowler/providers/aws/services/backup/backup_reportplans_exist/backup_reportplans_exist.metadata.json +++ b/prowler/providers/aws/services/backup/backup_reportplans_exist/backup_reportplans_exist.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:backup-report-plan:backup-report-plan-id", "Severity": "low", - "ResourceType": "Other", + "ResourceType": "AwsBackupBackupPlan", "Description": "This check ensures that there is at least one backup report plan in place.", "Risk": "Without a backup report plan, an organization may lack visibility into the success or failure of backup operations.", "RelatedUrl": "https://docs.aws.amazon.com/aws-backup/latest/devguide/create-report-plan-console.html", diff --git a/prowler/providers/aws/services/cloudfront/cloudfront_distributions_custom_ssl_certificate/cloudfront_distributions_custom_ssl_certificate.metadata.json b/prowler/providers/aws/services/cloudfront/cloudfront_distributions_custom_ssl_certificate/cloudfront_distributions_custom_ssl_certificate.metadata.json new file mode 100644 index 0000000000..9ef0cfca0a --- /dev/null +++ b/prowler/providers/aws/services/cloudfront/cloudfront_distributions_custom_ssl_certificate/cloudfront_distributions_custom_ssl_certificate.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "cloudfront_distributions_custom_ssl_certificate", + "CheckTitle": "CloudFront distributions should use custom SSL/TLS certificates.", + "CheckType": [], + "ServiceName": "cloudfront", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "medium", + "ResourceType": "AwsCloudFrontDistribution", + "Description": "Ensure that your Amazon CloudFront distributions are configured to use a custom SSL/TLS certificate instead of the default one.", + "Risk": "Using the default SSL/TLS certificate provided by CloudFront can limit your ability to use custom domain names and may not align with your organization's security policies or branding requirements.", + "RelatedUrl": "https://aws.amazon.com/what-is/ssl-certificate/", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "https://docs.prowler.com/checks/aws/networking-policies/ensure-aws-cloudfront-distribution-uses-custom-ssl-certificate/", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-7", + "Terraform": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/CloudFront/cloudfront-distro-custom-tls.html" + }, + "Recommendation": { + "Text": "Configure your CloudFront distributions to use a custom SSL/TLS certificate to enable secure access via your own domain names and meet specific security and branding needs. This allows for more control over encryption and authentication settings.", + "Url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/CNAMEs.html#CreatingCNAME" + } + }, + "Categories": [ + "encryption" + ], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/cloudfront/cloudfront_distributions_default_root_object/cloudfront_distributions_default_root_object.metadata.json b/prowler/providers/aws/services/cloudfront/cloudfront_distributions_default_root_object/cloudfront_distributions_default_root_object.metadata.json new file mode 100644 index 0000000000..d8247d0ff6 --- /dev/null +++ b/prowler/providers/aws/services/cloudfront/cloudfront_distributions_default_root_object/cloudfront_distributions_default_root_object.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "cloudfront_distributions_default_root_object", + "CheckTitle": "Check if CloudFront distributions have a default root object.", + "CheckType": [], + "ServiceName": "cloudfront", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id", + "Severity": "high", + "ResourceType": "AwsCloudFrontDistribution", + "Description": "Check if CloudFront distributions have a default root object.", + "Risk": "Without a default root object, requests to the root URL may result in an error or expose unintended content, leading to potential security risks and a poor user experience.", + "RelatedUrl": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/DefaultRootObject.html#DefaultRootObjectHow", + "Remediation": { + "Code": { + "CLI": "aws cloudfront update-distribution --id --default-root-object ", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-1", + "Terraform": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/CloudFront/cloudfront-default-object.html" + }, + "Recommendation": { + "Text": "Configure a default root object for your CloudFront distribution to ensure that a specific file (such as index.html) is returned when users access the root URL. This improves user experience and ensures that sensitive content isn't accidentally exposed.", + "Url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/DefaultRootObject.html#DefaultRootObjectHowToDefine" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/cloudfront/cloudfront_distributions_https_sni_enabled/cloudfront_distributions_https_sni_enabled.metadata.json b/prowler/providers/aws/services/cloudfront/cloudfront_distributions_https_sni_enabled/cloudfront_distributions_https_sni_enabled.metadata.json new file mode 100644 index 0000000000..6a4deed4cc --- /dev/null +++ b/prowler/providers/aws/services/cloudfront/cloudfront_distributions_https_sni_enabled/cloudfront_distributions_https_sni_enabled.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "cloudfront_distributions_https_sni_enabled", + "CheckTitle": "Check if CloudFront distributions are using SNI to serve HTTPS requests.", + "CheckType": [], + "ServiceName": "cloudfront", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:cloudfront:region:account-id:distribution/resource-id", + "Severity": "low", + "ResourceType": "AwsCloudFrontDistribution", + "Description": "Check if CloudFront distributions are using SNI to serve HTTPS requests.", + "Risk": "If SNI is not used, CloudFront will allocate a dedicated IP address for each SSL certificate, leading to higher costs and inefficient IP address utilization. This could also complicate scaling and managing multiple distributions, especially if your domain requires multiple SSL certificates.", + "RelatedUrl": "https://www.cloudflare.com/es-es/learning/ssl/what-is-sni/", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/cloudfront-controls.html#cloudfront-8", + "Terraform": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/CloudFront/cloudfront-sni.html" + }, + "Recommendation": { + "Text": "Ensure that your CloudFront distributions are configured to use Server Name Indication (SNI) when serving HTTPS requests with custom SSL/TLS certificates. This is the recommended approach for reducing costs and optimizing IP address usage.", + "Url": "https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/cnames-https-dedicated-ip-or-sni.html#cnames-https-sni" + } + }, + "Categories": [ + "encryption" + ], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/cloudtrail/cloudtrail_s3_dataevents_read_enabled/cloudtrail_s3_dataevents_read_enabled.metadata.json b/prowler/providers/aws/services/cloudtrail/cloudtrail_s3_dataevents_read_enabled/cloudtrail_s3_dataevents_read_enabled.metadata.json index 46114f4b3e..8edadb3124 100644 --- a/prowler/providers/aws/services/cloudtrail/cloudtrail_s3_dataevents_read_enabled/cloudtrail_s3_dataevents_read_enabled.metadata.json +++ b/prowler/providers/aws/services/cloudtrail/cloudtrail_s3_dataevents_read_enabled/cloudtrail_s3_dataevents_read_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "low", - "ResourceType": "AwsS3Bucket", + "ResourceType": "AwsCloudTrailTrail", "Description": "Ensure that all your AWS CloudTrail trails are configured to log Data events in order to record S3 object-level API operations, such as GetObject, DeleteObject and PutObject, for individual S3 buckets or for all current and future S3 buckets provisioned in your AWS account.", "Risk": "If logs are not enabled, monitoring of service use and threat analysis is not possible.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/cloudtrail/cloudtrail_s3_dataevents_write_enabled/cloudtrail_s3_dataevents_write_enabled.metadata.json b/prowler/providers/aws/services/cloudtrail/cloudtrail_s3_dataevents_write_enabled/cloudtrail_s3_dataevents_write_enabled.metadata.json index dfb30b54ba..f74e2f9b50 100644 --- a/prowler/providers/aws/services/cloudtrail/cloudtrail_s3_dataevents_write_enabled/cloudtrail_s3_dataevents_write_enabled.metadata.json +++ b/prowler/providers/aws/services/cloudtrail/cloudtrail_s3_dataevents_write_enabled/cloudtrail_s3_dataevents_write_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "low", - "ResourceType": "AwsS3Bucket", + "ResourceType": "AwsCloudTrailTrail", "Description": "Ensure that all your AWS CloudTrail trails are configured to log Data events in order to record S3 object-level API operations, such as GetObject, DeleteObject and PutObject, for individual S3 buckets or for all current and future S3 buckets provisioned in your AWS account.", "Risk": "If logs are not enabled, monitoring of service use and threat analysis is not possible.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_acls_alarm_configured/cloudwatch_changes_to_network_acls_alarm_configured.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_acls_alarm_configured/cloudwatch_changes_to_network_acls_alarm_configured.metadata.json index d88b650108..c1aa9d9ef1 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_acls_alarm_configured/cloudwatch_changes_to_network_acls_alarm_configured.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_acls_alarm_configured/cloudwatch_changes_to_network_acls_alarm_configured.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for changes to Network Access Control Lists (NACL).", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_gateways_alarm_configured/cloudwatch_changes_to_network_gateways_alarm_configured.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_gateways_alarm_configured/cloudwatch_changes_to_network_gateways_alarm_configured.metadata.json index 51d7c54e96..8b7a76ab68 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_gateways_alarm_configured/cloudwatch_changes_to_network_gateways_alarm_configured.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_gateways_alarm_configured/cloudwatch_changes_to_network_gateways_alarm_configured.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for changes to network gateways.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_route_tables_alarm_configured/cloudwatch_changes_to_network_route_tables_alarm_configured.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_route_tables_alarm_configured/cloudwatch_changes_to_network_route_tables_alarm_configured.metadata.json index 0430c46cd5..61994d1564 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_route_tables_alarm_configured/cloudwatch_changes_to_network_route_tables_alarm_configured.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_network_route_tables_alarm_configured/cloudwatch_changes_to_network_route_tables_alarm_configured.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Real-time monitoring of API calls can be achieved by directing Cloud Trail Logs to CloudWatch Logs, or an external Security information and event management (SIEM)environment, and establishing corresponding metric filters and alarms. Routing tablesare used to route network traffic between subnets and to network gateways. It isrecommended that a metric filter and alarm be established for changes to route tables.", "Risk": "CloudWatch is an AWS native service that allows you to ob serve and monitor resources and applications. CloudTrail Logs can also be sent to an external Security informationand event management (SIEM) environment for monitoring and alerting.Monitoring changes to route tables will help ensure that all VPC traffic flows through anexpected path and prevent any accidental or intentional modifications that may lead touncontrolled network traffic. An alarm should be triggered every time an AWS API call isperformed to create, replace, delete, or disassociate a Route Table.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_vpcs_alarm_configured/cloudwatch_changes_to_vpcs_alarm_configured.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_vpcs_alarm_configured/cloudwatch_changes_to_vpcs_alarm_configured.metadata.json index d280c58eed..c0ccb4d86d 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_vpcs_alarm_configured/cloudwatch_changes_to_vpcs_alarm_configured.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_changes_to_vpcs_alarm_configured/cloudwatch_changes_to_vpcs_alarm_configured.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for VPC changes.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_cross_account_sharing_disabled/cloudwatch_cross_account_sharing_disabled.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_cross_account_sharing_disabled/cloudwatch_cross_account_sharing_disabled.metadata.json index 6a0a5215ca..a6a9e1839c 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_cross_account_sharing_disabled/cloudwatch_cross_account_sharing_disabled.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_cross_account_sharing_disabled/cloudwatch_cross_account_sharing_disabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudWatch", + "ResourceType": "AwsAccount", "Description": "Check if CloudWatch has allowed cross-account sharing.", "Risk": "Cross-Account access to CloudWatch could increase the risk of compromising information between accounts.", "RelatedUrl": "https://docs.aws.amazon.com/AmazonCloudWatch/latest/monitoring/Cross-Account-Cross-Region.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_group_kms_encryption_enabled/cloudwatch_log_group_kms_encryption_enabled.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_group_kms_encryption_enabled/cloudwatch_log_group_kms_encryption_enabled.metadata.json index dcfff3163a..c4a6601f6f 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_group_kms_encryption_enabled/cloudwatch_log_group_kms_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_group_kms_encryption_enabled/cloudwatch_log_group_kms_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "logs", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsLogsLogGroup", + "ResourceType": "Other", "Description": "Check if CloudWatch log groups are protected by AWS KMS.", "Risk": "Using customer managed KMS to encrypt CloudWatch log group provide additional confidentiality and control over the log data.", "RelatedUrl": "https://docs.aws.amazon.com/cli/latest/reference/logs/associate-kms-key.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_group_no_secrets_in_logs/cloudwatch_log_group_no_secrets_in_logs.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_group_no_secrets_in_logs/cloudwatch_log_group_no_secrets_in_logs.metadata.json index 6536ad95c4..087b16a89f 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_group_no_secrets_in_logs/cloudwatch_log_group_no_secrets_in_logs.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_group_no_secrets_in_logs/cloudwatch_log_group_no_secrets_in_logs.metadata.json @@ -10,7 +10,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:log-group/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailLogGroup", + "ResourceType": "Other", "Description": "Check if secrets exists in CloudWatch logs", "Risk": "Storing sensitive data in CloudWatch logs could allow an attacker with read-only access to escalate their privileges or gain unauthorised access to systems.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled/cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled/cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled.metadata.json index 78dc472dfb..51df80cbed 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled/cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled/cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for AWS Config configuration changes.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled/cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled/cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled.metadata.json index 902f1454d3..a960fc4cb6 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled/cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled/cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for CloudTrail configuration changes.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_authentication_failures/cloudwatch_log_metric_filter_authentication_failures.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_authentication_failures/cloudwatch_log_metric_filter_authentication_failures.metadata.json index 5926234887..44cd9074c5 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_authentication_failures/cloudwatch_log_metric_filter_authentication_failures.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_authentication_failures/cloudwatch_log_metric_filter_authentication_failures.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for AWS Management Console authentication failures.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_aws_organizations_changes/cloudwatch_log_metric_filter_aws_organizations_changes.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_aws_organizations_changes/cloudwatch_log_metric_filter_aws_organizations_changes.metadata.json index c53926e924..bc182ce688 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_aws_organizations_changes/cloudwatch_log_metric_filter_aws_organizations_changes.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_aws_organizations_changes/cloudwatch_log_metric_filter_aws_organizations_changes.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for AWS Organizations changes.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk/cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk/cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk.metadata.json index b7b749897e..482d15b56c 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk/cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk/cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for disabling or scheduled deletion of customer created KMS CMKs.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_for_s3_bucket_policy_changes/cloudwatch_log_metric_filter_for_s3_bucket_policy_changes.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_for_s3_bucket_policy_changes/cloudwatch_log_metric_filter_for_s3_bucket_policy_changes.metadata.json index 01ec5890ac..764e31cf6e 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_for_s3_bucket_policy_changes/cloudwatch_log_metric_filter_for_s3_bucket_policy_changes.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_for_s3_bucket_policy_changes/cloudwatch_log_metric_filter_for_s3_bucket_policy_changes.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for S3 bucket policy changes.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_policy_changes/cloudwatch_log_metric_filter_policy_changes.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_policy_changes/cloudwatch_log_metric_filter_policy_changes.metadata.json index a8adb8ae6a..36c4d42234 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_policy_changes/cloudwatch_log_metric_filter_policy_changes.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_policy_changes/cloudwatch_log_metric_filter_policy_changes.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for IAM policy changes.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_root_usage/cloudwatch_log_metric_filter_root_usage.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_root_usage/cloudwatch_log_metric_filter_root_usage.metadata.json index 6596d01a6e..fed23762ed 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_root_usage/cloudwatch_log_metric_filter_root_usage.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_root_usage/cloudwatch_log_metric_filter_root_usage.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for usage of root account.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_security_group_changes/cloudwatch_log_metric_filter_security_group_changes.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_security_group_changes/cloudwatch_log_metric_filter_security_group_changes.metadata.json index 5195617961..6041c493ce 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_security_group_changes/cloudwatch_log_metric_filter_security_group_changes.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_security_group_changes/cloudwatch_log_metric_filter_security_group_changes.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for security group changes.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_sign_in_without_mfa/cloudwatch_log_metric_filter_sign_in_without_mfa.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_sign_in_without_mfa/cloudwatch_log_metric_filter_sign_in_without_mfa.metadata.json index 2f3c4459f9..1d605dde4b 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_sign_in_without_mfa/cloudwatch_log_metric_filter_sign_in_without_mfa.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_sign_in_without_mfa/cloudwatch_log_metric_filter_sign_in_without_mfa.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for Management Console sign-in without MFA.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_unauthorized_api_calls/cloudwatch_log_metric_filter_unauthorized_api_calls.metadata.json b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_unauthorized_api_calls/cloudwatch_log_metric_filter_unauthorized_api_calls.metadata.json index 63ca78288f..c143c09770 100644 --- a/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_unauthorized_api_calls/cloudwatch_log_metric_filter_unauthorized_api_calls.metadata.json +++ b/prowler/providers/aws/services/cloudwatch/cloudwatch_log_metric_filter_unauthorized_api_calls/cloudwatch_log_metric_filter_unauthorized_api_calls.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:cloudwatch:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsCloudTrailTrail", + "ResourceType": "AwsCloudWatchAlarm", "Description": "Ensure a log metric filter and alarm exist for unauthorized API calls.", "Risk": "Monitoring unauthorized API calls will help reveal application errors and may reduce time to detect malicious activity.", "RelatedUrl": "https://docs.aws.amazon.com/awscloudtrail/latest/userguide/cloudwatch-alarms-for-cloudtrail.html", diff --git a/prowler/providers/aws/services/cognito/cognito_identity_pool_guest_access_disabled/cognito_identity_pool_guest_access_disabled.metadata.json b/prowler/providers/aws/services/cognito/cognito_identity_pool_guest_access_disabled/cognito_identity_pool_guest_access_disabled.metadata.json new file mode 100644 index 0000000000..382ceaf26f --- /dev/null +++ b/prowler/providers/aws/services/cognito/cognito_identity_pool_guest_access_disabled/cognito_identity_pool_guest_access_disabled.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "cognito_identity_pool_guest_access_disabled", + "CheckTitle": "Ensure Cognito Identity Pool has guest access disabled", + "CheckType": [], + "ServiceName": "cognito", + "SubServiceName": "", + "ResourceIdTemplate": "arn:aws:cognito-idp:region:account:identitypool/identitypool-id", + "Severity": "medium", + "ResourceType": "Other", + "Description": "Guest access allows unauthenticated users to access your identity pool. This is useful for public websites that allow users to sign in with a social identity provider, but it can also be a security risk. If you don't need guest access, you should disable it.", + "Risk": "If guest access is enabled, unauthenticated users can access your identity pool. This can be a security risk if you don't need guest access.", + "RelatedUrl": "https://docs.aws.amazon.com/location/latest/developerguide/authenticating-using-cognito.html", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "Gues access should be disabled for Cognito Identity Pool. To disable guest access, follow the steps in the Amazon Cognito documentation.", + "Url": "https://docs.aws.amazon.com/location/latest/developerguide/authenticating-using-cognito.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/directoryservice/directoryservice_directory_log_forwarding_enabled/directoryservice_directory_log_forwarding_enabled.metadata.json b/prowler/providers/aws/services/directoryservice/directoryservice_directory_log_forwarding_enabled/directoryservice_directory_log_forwarding_enabled.metadata.json index 01cfbd12f8..f0fc8b8cf1 100644 --- a/prowler/providers/aws/services/directoryservice/directoryservice_directory_log_forwarding_enabled/directoryservice_directory_log_forwarding_enabled.metadata.json +++ b/prowler/providers/aws/services/directoryservice/directoryservice_directory_log_forwarding_enabled/directoryservice_directory_log_forwarding_enabled.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id", "Severity": "medium", - "ResourceType": "AwsDirectoryService", + "ResourceType": "Other", "Description": "Directory Service monitoring with CloudWatch logs.", "Risk": "As a best practice, monitor your organization to ensure that changes are logged. This helps you to ensure that any unexpected change can be investigated and unwanted changes can be rolled back.", "RelatedUrl": "https://docs.aws.amazon.com/directoryservice/latest/admin-guide/incident-response.html", diff --git a/prowler/providers/aws/services/directoryservice/directoryservice_directory_monitor_notifications/directoryservice_directory_monitor_notifications.metadata.json b/prowler/providers/aws/services/directoryservice/directoryservice_directory_monitor_notifications/directoryservice_directory_monitor_notifications.metadata.json index f79827ae12..55d1c393c0 100644 --- a/prowler/providers/aws/services/directoryservice/directoryservice_directory_monitor_notifications/directoryservice_directory_monitor_notifications.metadata.json +++ b/prowler/providers/aws/services/directoryservice/directoryservice_directory_monitor_notifications/directoryservice_directory_monitor_notifications.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id", "Severity": "medium", - "ResourceType": "AwsDirectoryService", + "ResourceType": "Other", "Description": "Directory Service has SNS Notifications enabled.", "Risk": "As a best practice, monitor status of Directory Service. This helps to avoid late actions to fix Directory Service issues.", "RelatedUrl": "https://docs.aws.amazon.com/directoryservice/latest/admin-guide/ms_ad_enable_notifications.html", diff --git a/prowler/providers/aws/services/directoryservice/directoryservice_directory_snapshots_limit/directoryservice_directory_snapshots_limit.metadata.json b/prowler/providers/aws/services/directoryservice/directoryservice_directory_snapshots_limit/directoryservice_directory_snapshots_limit.metadata.json index 33f96a8263..7693461252 100644 --- a/prowler/providers/aws/services/directoryservice/directoryservice_directory_snapshots_limit/directoryservice_directory_snapshots_limit.metadata.json +++ b/prowler/providers/aws/services/directoryservice/directoryservice_directory_snapshots_limit/directoryservice_directory_snapshots_limit.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id", "Severity": "low", - "ResourceType": "AwsDirectoryService", + "ResourceType": "Other", "Description": "Directory Service Manual Snapshots limit reached.", "Risk": "A limit reached can bring unwanted results. The maximum number of manual snapshots is a hard limit.", "RelatedUrl": "https://docs.aws.amazon.com/general/latest/gr/ds_region.html", diff --git a/prowler/providers/aws/services/directoryservice/directoryservice_ldap_certificate_expiration/directoryservice_ldap_certificate_expiration.metadata.json b/prowler/providers/aws/services/directoryservice/directoryservice_ldap_certificate_expiration/directoryservice_ldap_certificate_expiration.metadata.json index 30f023d786..982ab9091f 100644 --- a/prowler/providers/aws/services/directoryservice/directoryservice_ldap_certificate_expiration/directoryservice_ldap_certificate_expiration.metadata.json +++ b/prowler/providers/aws/services/directoryservice/directoryservice_ldap_certificate_expiration/directoryservice_ldap_certificate_expiration.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id", "Severity": "medium", - "ResourceType": "AwsDirectoryService", + "ResourceType": "Other", "Description": "Directory Service Manual Snapshots limit reached.", "Risk": "Expired certificates can impact service availability.", "RelatedUrl": "https://docs.aws.amazon.com/directoryservice/latest/admin-guide/ms_ad_ldap.html", diff --git a/prowler/providers/aws/services/directoryservice/directoryservice_radius_server_security_protocol/directoryservice_radius_server_security_protocol.metadata.json b/prowler/providers/aws/services/directoryservice/directoryservice_radius_server_security_protocol/directoryservice_radius_server_security_protocol.metadata.json index 3fc929a8d8..a3f04834e3 100644 --- a/prowler/providers/aws/services/directoryservice/directoryservice_radius_server_security_protocol/directoryservice_radius_server_security_protocol.metadata.json +++ b/prowler/providers/aws/services/directoryservice/directoryservice_radius_server_security_protocol/directoryservice_radius_server_security_protocol.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id", "Severity": "medium", - "ResourceType": "AwsDirectoryService", + "ResourceType": "Other", "Description": "Ensure Radius server in DS is using the recommended security protocol.", "Risk": "As a best practice, you might need to configure the authentication protocol between the Microsoft AD DCs and the RADIUS/MFA server. Supported protocols are PAP, CHAP MS-CHAPv1, and MS-CHAPv2. MS-CHAPv2 is recommended because it provides the strongest security of the three options.", "RelatedUrl": "https://aws.amazon.com/blogs/security/how-to-enable-multi-factor-authentication-for-amazon-workspaces-and-amazon-quicksight-by-using-microsoft-ad-and-on-premises-credentials/", diff --git a/prowler/providers/aws/services/directoryservice/directoryservice_supported_mfa_radius_enabled/directoryservice_supported_mfa_radius_enabled.metadata.json b/prowler/providers/aws/services/directoryservice/directoryservice_supported_mfa_radius_enabled/directoryservice_supported_mfa_radius_enabled.metadata.json index d2185cace3..a5db8db7ad 100644 --- a/prowler/providers/aws/services/directoryservice/directoryservice_supported_mfa_radius_enabled/directoryservice_supported_mfa_radius_enabled.metadata.json +++ b/prowler/providers/aws/services/directoryservice/directoryservice_supported_mfa_radius_enabled/directoryservice_supported_mfa_radius_enabled.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:codeartifact:region:account-id:directory/directory-id", "Severity": "medium", - "ResourceType": "AwsDirectoryService", + "ResourceType": "Other", "Description": "Ensure Multi-Factor Authentication (MFA) using Radius Server is enabled in DS.", "Risk": "Multi-Factor Authentication (MFA) adds an extra layer of authentication assurance beyond traditional username and password.", "RelatedUrl": "https://docs.aws.amazon.com/directoryservice/latest/admin-guide/ms_ad_mfa.html", diff --git a/prowler/providers/aws/services/documentdb/documentdb_cluster_cloudwatch_log_export/documentdb_cluster_cloudwatch_log_export.metadata.json b/prowler/providers/aws/services/documentdb/documentdb_cluster_cloudwatch_log_export/documentdb_cluster_cloudwatch_log_export.metadata.json new file mode 100644 index 0000000000..6e0bc5cf96 --- /dev/null +++ b/prowler/providers/aws/services/documentdb/documentdb_cluster_cloudwatch_log_export/documentdb_cluster_cloudwatch_log_export.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "documentdb_cluster_cloudwatch_log_export", + "CheckTitle": "Check if DocumentDB clusters are using the log export feature.", + "CheckType": [], + "ServiceName": "documentdb", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "medium", + "ResourceType": "AwsRdsDbCluster", + "Description": "Check if DocumentDB clusters are using the log export feature.", + "Risk": "Ensure that all your Amazon DocumentDB clusters are using the Log Exports feature in order to publish audit logs directly to CloudWatch Logs. The events recorded by Log Exports include events such as successful and failed authentication attempts, creating indexes, or dropping collections in DocumentDB databases.", + "RelatedUrl": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-4", + "Remediation": { + "Code": { + "CLI": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/DocumentDB/enable-profiler.html", + "NativeIaC": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/DocumentDB/enable-profiler.html", + "Other": "", + "Terraform": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/DocumentDB/enable-profiler.html" + }, + "Recommendation": { + "Text": "Enabled DocumentDB Log export functionality to analyze, monitor, and archive auditing events for security and compliance requirements.", + "Url": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-4" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/documentdb/documentdb_cluster_deletion_protection/documentdb_cluster_deletion_protection.metadata.json b/prowler/providers/aws/services/documentdb/documentdb_cluster_deletion_protection/documentdb_cluster_deletion_protection.metadata.json new file mode 100644 index 0000000000..c5bec6df50 --- /dev/null +++ b/prowler/providers/aws/services/documentdb/documentdb_cluster_deletion_protection/documentdb_cluster_deletion_protection.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "documentdb_cluster_deletion_protection", + "CheckTitle": "Check if DocumentDB Clusters has deletion protection enabled.", + "CheckType": [], + "ServiceName": "documentdb", + "SubServiceName": "", + "ResourceIdTemplate": "arn:aws:rds:region:account-id:db-cluster", + "Severity": "medium", + "ResourceType": "AwsRdsDbCluster", + "Description": "Check if DocumentDB Clusters has deletion protection enabled.", + "Risk": "Enabling cluster deletion protection offers an additional layer of protection against accidental database deletion or deletion by an unauthorized user. A DocumentDB cluster can't be deleted while deletion protection is enabled. You must first disable deletion protection before a delete request can succeed.", + "RelatedUrl": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-5", + "Remediation": { + "Code": { + "CLI": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/DocumentDB/deletion-protection.html#", + "NativeIaC": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/DocumentDB/deletion-protection.html#", + "Other": "", + "Terraform": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/DocumentDB/deletion-protection.html#" + }, + "Recommendation": { + "Text": "Enable deletion protection for production DocumentDB Clusters.", + "Url": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-5" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/documentdb/documentdb_cluster_public_snapshot/documentdb_cluster_public_snapshot.metadata.json b/prowler/providers/aws/services/documentdb/documentdb_cluster_public_snapshot/documentdb_cluster_public_snapshot.metadata.json new file mode 100644 index 0000000000..cff48d521b --- /dev/null +++ b/prowler/providers/aws/services/documentdb/documentdb_cluster_public_snapshot/documentdb_cluster_public_snapshot.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "documentdb_cluster_public_snapshot", + "CheckTitle": "Check if DocumentDB manual cluster snapshot is public.", + "CheckType": [], + "ServiceName": "documentdb", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "critical", + "ResourceType": "AwsRdsDbClusterSnapshot", + "Description": "Check if DocumentDB manual cluster snapshot is public.", + "Risk": "If you share an unencrypted manual snapshot as public, the snapshot is available to all AWS accounts. Public snapshots may result in unintended data exposure.", + "RelatedUrl": "https://docs.aws.amazon.com/config/latest/developerguide/docdb-cluster-snapshot-public-prohibited.html", + "Remediation": { + "Code": { + "CLI": "aws docdb modify-db-snapshot-attribute --db-snapshot-identifier --attribute-name restore --values-to-remove all", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-3", + "Terraform": "" + }, + "Recommendation": { + "Text": "To remove public access from a manual snapshot, follow the Sharing a snapshot tutorial.", + "Url": "https://docs.aws.amazon.com/documentdb/latest/developerguide/backup_restore-share_cluster_snapshots.html#backup_restore-share_snapshots" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/documentdb/documentdb_cluster_storage_encrypted/documentdb_cluster_storage_encrypted.metadata.json b/prowler/providers/aws/services/documentdb/documentdb_cluster_storage_encrypted/documentdb_cluster_storage_encrypted.metadata.json new file mode 100644 index 0000000000..421f9e5019 --- /dev/null +++ b/prowler/providers/aws/services/documentdb/documentdb_cluster_storage_encrypted/documentdb_cluster_storage_encrypted.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "documentdb_cluster_storage_encrypted", + "CheckTitle": "Check if DocumentDB cluster storage is encrypted.", + "CheckType": [ + "Data Protection" + ], + "ServiceName": "documentdb", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "medium", + "ResourceType": "AwsRdsDbCluster", + "Description": "Check if DocumentDB cluster storage is encrypted.", + "Risk": "Ensure that encryption of data at rest is enabled for your Amazon DocumentDB (with MongoDB compatibility) database clusters for additional data security and regulatory compliance.", + "RelatedUrl": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-1", + "Remediation": { + "Code": { + "CLI": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_28/", + "NativeIaC": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/DocumentDB/encryption-enabled.html#", + "Other": "", + "Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_28/" + }, + "Recommendation": { + "Text": "Enable Encryption. Use a CMK where possible. It will provide additional management and privacy benefits.", + "Url": "https://docs.aws.amazon.com/securityhub/latest/userguide/documentdb-controls.html#documentdb-1" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/dynamodb/dynamodb_accelerator_cluster_encryption_enabled/dynamodb_accelerator_cluster_encryption_enabled.metadata.json b/prowler/providers/aws/services/dynamodb/dynamodb_accelerator_cluster_encryption_enabled/dynamodb_accelerator_cluster_encryption_enabled.metadata.json index bcc04b54e0..69fd5cf87d 100644 --- a/prowler/providers/aws/services/dynamodb/dynamodb_accelerator_cluster_encryption_enabled/dynamodb_accelerator_cluster_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/dynamodb/dynamodb_accelerator_cluster_encryption_enabled/dynamodb_accelerator_cluster_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:dynamodb:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsDaxCluster", + "ResourceType": "Other", "Description": "Check if DynamoDB DAX Clusters are encrypted at rest.", "Risk": "Encryption at rest provides an additional layer of data protection by securing your data from unauthorized access to the underlying storage.", "RelatedUrl": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/DAXEncryptionAtRest.html", diff --git a/prowler/providers/aws/services/dynamodb/dynamodb_table_cross_account_access/dynamodb_table_cross_account_access.metadata.json b/prowler/providers/aws/services/dynamodb/dynamodb_table_cross_account_access/dynamodb_table_cross_account_access.metadata.json new file mode 100644 index 0000000000..1ab8b56140 --- /dev/null +++ b/prowler/providers/aws/services/dynamodb/dynamodb_table_cross_account_access/dynamodb_table_cross_account_access.metadata.json @@ -0,0 +1,34 @@ +{ + "Provider": "aws", + "CheckID": "dynamodb_table_cross_account_access", + "CheckTitle": "DynamoDB tables should not be accessible from other AWS accounts", + "CheckType": [ + "Infrastructure Security" + ], + "ServiceName": "dynamodb", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:dynamodb:region:account-id:table/resource-id", + "Severity": "medium", + "ResourceType": "AwsDynamoDbTable", + "Description": "This check determines if the DynamoDB table is accessible from other AWS accounts.", + "Risk": "If the DynamoDB table is accessible from other AWS accounts, it may lead to unauthorized access to the data stored in the table.", + "RelatedUrl": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/access-control-resource-based.html", + "Remediation": { + "Code": { + "CLI": "aws dynamodb delete-resource-policy --resource-arn ", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "Ensure that the DynamoDB table is not accessible from other AWS accounts.", + "Url": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/rbac-bpa-rbp.html" + } + }, + "Categories": [ + "trustboundaries" + ], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/dynamodb/dynamodb_tables_kms_cmk_encryption_enabled/dynamodb_tables_kms_cmk_encryption_enabled.metadata.json b/prowler/providers/aws/services/dynamodb/dynamodb_tables_kms_cmk_encryption_enabled/dynamodb_tables_kms_cmk_encryption_enabled.metadata.json index 35321b6555..db93936b6b 100644 --- a/prowler/providers/aws/services/dynamodb/dynamodb_tables_kms_cmk_encryption_enabled/dynamodb_tables_kms_cmk_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/dynamodb/dynamodb_tables_kms_cmk_encryption_enabled/dynamodb_tables_kms_cmk_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:dynamodb:region:account-id:table/resource-id", "Severity": "medium", - "ResourceType": "AwsDynamoDBTable", + "ResourceType": "AwsDynamoDbTable", "Description": "Check if DynamoDB table has encryption at rest enabled using CMK KMS.", "Risk": "All user data stored in Amazon DynamoDB is fully encrypted at rest. This functionality helps reduce the operational burden and complexity involved in protecting sensitive data.", "RelatedUrl": "https://docs.aws.amazon.com/amazondynamodbdb/latest/developerguide/EncryptionAtRest.html", diff --git a/prowler/providers/aws/services/dynamodb/dynamodb_tables_pitr_enabled/dynamodb_tables_pitr_enabled.metadata.json b/prowler/providers/aws/services/dynamodb/dynamodb_tables_pitr_enabled/dynamodb_tables_pitr_enabled.metadata.json index 2304877659..3ec092d370 100644 --- a/prowler/providers/aws/services/dynamodb/dynamodb_tables_pitr_enabled/dynamodb_tables_pitr_enabled.metadata.json +++ b/prowler/providers/aws/services/dynamodb/dynamodb_tables_pitr_enabled/dynamodb_tables_pitr_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:dynamodb:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsDynamoDBTable", + "ResourceType": "AwsDynamoDbTable", "Description": "Check if DynamoDB tables point-in-time recovery (PITR) is enabled.", "Risk": "If the DynamoDB Table does not have point-in-time recovery enabled, it is vulnerable to accidental write or delete operations.", "RelatedUrl": "https://docs.aws.amazon.com/amazondynamodb/latest/developerguide/PointInTimeRecovery_Howitworks.html", diff --git a/prowler/providers/aws/services/ec2/ec2_ebs_public_snapshot/ec2_ebs_public_snapshot.metadata.json b/prowler/providers/aws/services/ec2/ec2_ebs_public_snapshot/ec2_ebs_public_snapshot.metadata.json index d0324b5816..e2f759d999 100644 --- a/prowler/providers/aws/services/ec2/ec2_ebs_public_snapshot/ec2_ebs_public_snapshot.metadata.json +++ b/prowler/providers/aws/services/ec2/ec2_ebs_public_snapshot/ec2_ebs_public_snapshot.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "snapshot", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "critical", - "ResourceType": "AwsEc2Snapshot", + "ResourceType": "Other", "Description": "Ensure there are no EBS Snapshots set as Public.", "Risk": "When you share a snapshot, you are giving others access to all of the data on the snapshot. Share snapshots only with people with whom you want to share all of your snapshot data.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/ec2/ec2_ebs_snapshot_account_block_public_access/ec2_ebs_snapshot_account_block_public_access.metadata.json b/prowler/providers/aws/services/ec2/ec2_ebs_snapshot_account_block_public_access/ec2_ebs_snapshot_account_block_public_access.metadata.json new file mode 100644 index 0000000000..ab44f43b47 --- /dev/null +++ b/prowler/providers/aws/services/ec2/ec2_ebs_snapshot_account_block_public_access/ec2_ebs_snapshot_account_block_public_access.metadata.json @@ -0,0 +1,34 @@ +{ + "Provider": "aws", + "CheckID": "ec2_ebs_snapshot_account_block_public_access", + "CheckTitle": "Ensure that public access to EBS snapshots is disabled", + "CheckType": [ + "Data Protection" + ], + "ServiceName": "ec2", + "SubServiceName": "snapshot", + "ResourceIdTemplate": "arn:partition:service:region:account-id", + "Severity": "high", + "ResourceType": "Other", + "Description": "EBS snapshots can be shared with other AWS accounts or made public. By default, EBS snapshots are private and only the AWS account that created the snapshot can access it. If an EBS snapshot is shared with another AWS account or made public, the data in the snapshot can be accessed by the other account or by anyone on the internet. Ensure that public access to EBS snapshots is disabled.", + "Risk": "If public access to EBS snapshots is enabled, the data in the snapshot can be accessed by anyone on the internet.", + "RelatedUrl": "https://docs.aws.amazon.com/ebs/latest/userguide/block-public-access-snapshots-work.html#block-public-access-snapshots-enable", + "Remediation": { + "Code": { + "CLI": "aws ec2 enable-snapshot-block-public-access --state block-all-sharing", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "Use the following procedures to configure and monitor block public access for snapshots.", + "Url": "https://docs.aws.amazon.com/ebs/latest/userguide/block-public-access-snapshots-work.html#block-public-access-snapshots-enable" + } + }, + "Categories": [ + "internet-exposed" + ], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/ec2/ec2_ebs_snapshots_encrypted/ec2_ebs_snapshots_encrypted.metadata.json b/prowler/providers/aws/services/ec2/ec2_ebs_snapshots_encrypted/ec2_ebs_snapshots_encrypted.metadata.json index d50e3a933a..d44b9c95e2 100644 --- a/prowler/providers/aws/services/ec2/ec2_ebs_snapshots_encrypted/ec2_ebs_snapshots_encrypted.metadata.json +++ b/prowler/providers/aws/services/ec2/ec2_ebs_snapshots_encrypted/ec2_ebs_snapshots_encrypted.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "snapshot", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsEc2Snapshot", + "ResourceType": "Other", "Description": "Check if EBS snapshots are encrypted.", "Risk": "Data encryption at rest prevents data visibility in the event of its unauthorized access or theft.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/ec2/ec2_instance_port_memcached_exposed_to_internet/ec2_instance_port_memcached_exposed_to_internet.metadata.json b/prowler/providers/aws/services/ec2/ec2_instance_port_memcached_exposed_to_internet/ec2_instance_port_memcached_exposed_to_internet.metadata.json new file mode 100644 index 0000000000..a55e794e77 --- /dev/null +++ b/prowler/providers/aws/services/ec2/ec2_instance_port_memcached_exposed_to_internet/ec2_instance_port_memcached_exposed_to_internet.metadata.json @@ -0,0 +1,34 @@ +{ + "Provider": "aws", + "CheckID": "ec2_instance_port_memcached_exposed_to_internet", + "CheckTitle": "Ensure no EC2 instances allow ingress from the internet to TCP port 11211 (Memcached).", + "CheckType": [ + "Infrastructure Security" + ], + "ServiceName": "ec2", + "SubServiceName": "instance", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "critical", + "ResourceType": "AwsEc2SecurityGroup", + "Description": "Ensure no EC2 instances allow ingress from the internet to TCP port 11211 (Memcached).", + "Risk": "Memcached is an open-source, high-performance, distributed memory object caching system. It is often used to speed up dynamic database-driven websites by caching data and objects in RAM to reduce the number of times an external data source must be read. Memcached is designed to be used in trusted environments and should not be exposed to the internet. If Memcached is exposed to the internet, it can be exploited by attackers to perform distributed denial-of-service (DDoS) attacks, data exfiltration, and other malicious activities.", + "RelatedUrl": "", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "Modify the security group associated with the EC2 instance to remove the rule that allows ingress from the internet to TCP port 11211 (Memcached).", + "Url": "https://docs.aws.amazon.com/vpc/latest/userguide/VPC_SecurityGroups.html" + } + }, + "Categories": [ + "internet-exposed" + ], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/ecr/ecr_registry_scan_images_on_push_enabled/ecr_registry_scan_images_on_push_enabled.metadata.json b/prowler/providers/aws/services/ecr/ecr_registry_scan_images_on_push_enabled/ecr_registry_scan_images_on_push_enabled.metadata.json index 2549b6826b..3055d2263b 100644 --- a/prowler/providers/aws/services/ecr/ecr_registry_scan_images_on_push_enabled/ecr_registry_scan_images_on_push_enabled.metadata.json +++ b/prowler/providers/aws/services/ecr/ecr_registry_scan_images_on_push_enabled/ecr_registry_scan_images_on_push_enabled.metadata.json @@ -10,7 +10,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:ecr:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsEcrRegistry", + "ResourceType": "Other", "Description": "Check if ECR Registry has scan on push enabled", "Risk": "Amazon ECR image scanning helps in identifying software vulnerabilities in your container images. Amazon ECR uses the Common Vulnerabilities and Exposures (CVEs) database from the open-source Clair project and provides a list of scan findings. ", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/efs/efs_encryption_at_rest_enabled/efs_encryption_at_rest_enabled.metadata.json b/prowler/providers/aws/services/efs/efs_encryption_at_rest_enabled/efs_encryption_at_rest_enabled.metadata.json index 23938f0390..b6c6b8a207 100644 --- a/prowler/providers/aws/services/efs/efs_encryption_at_rest_enabled/efs_encryption_at_rest_enabled.metadata.json +++ b/prowler/providers/aws/services/efs/efs_encryption_at_rest_enabled/efs_encryption_at_rest_enabled.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsEFSFileSystem", + "ResourceType": "AwsEfsFileSystem", "Description": "Check if EFS protects sensitive data with encryption at rest", "Risk": "EFS should be encrypted at rest to prevent exposure of sensitive data to bad actors", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/efs/efs_have_backup_enabled/efs_have_backup_enabled.metadata.json b/prowler/providers/aws/services/efs/efs_have_backup_enabled/efs_have_backup_enabled.metadata.json index 9bb2816148..d1b62abbb0 100644 --- a/prowler/providers/aws/services/efs/efs_have_backup_enabled/efs_have_backup_enabled.metadata.json +++ b/prowler/providers/aws/services/efs/efs_have_backup_enabled/efs_have_backup_enabled.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsEFSFileSystem", + "ResourceType": "AwsEfsFileSystem", "Description": "Check if EFS File systems have backup enabled", "Risk": "If backup is not enabled, data is vulnerable. Human error or bad actors could erase or modify data.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/efs/efs_not_publicly_accessible/efs_not_publicly_accessible.metadata.json b/prowler/providers/aws/services/efs/efs_not_publicly_accessible/efs_not_publicly_accessible.metadata.json index a20ee155cb..8b99804160 100644 --- a/prowler/providers/aws/services/efs/efs_not_publicly_accessible/efs_not_publicly_accessible.metadata.json +++ b/prowler/providers/aws/services/efs/efs_not_publicly_accessible/efs_not_publicly_accessible.metadata.json @@ -10,7 +10,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsEFSFileSystem", + "ResourceType": "AwsEfsFileSystem", "Description": "Check if EFS have policies which allow access to any client within the VPC", "Risk": "Restricting access to EFS file systems is a security best practice. Allowing access to any client within the VPC can lead to unauthorized access to the file system.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/elasticache/elasticache_cluster_uses_public_subnet/elasticache_cluster_uses_public_subnet.metadata.json b/prowler/providers/aws/services/elasticache/elasticache_cluster_uses_public_subnet/elasticache_cluster_uses_public_subnet.metadata.json index e6b0e497c3..8c29c80813 100644 --- a/prowler/providers/aws/services/elasticache/elasticache_cluster_uses_public_subnet/elasticache_cluster_uses_public_subnet.metadata.json +++ b/prowler/providers/aws/services/elasticache/elasticache_cluster_uses_public_subnet/elasticache_cluster_uses_public_subnet.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AWSElastiCacheCacheCluster", + "ResourceType": "Other", "Description": "Ensure Elasticache Cluster is not using a public subnet", "Risk": "There is a risk of exposing sensitive data if Elasticache Cluster uses a public subnet.", "RelatedUrl": "https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/VPCs.html", diff --git a/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_auto_minor_version_upgrades/elasticache_redis_cluster_auto_minor_version_upgrades.metadata.json b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_auto_minor_version_upgrades/elasticache_redis_cluster_auto_minor_version_upgrades.metadata.json new file mode 100644 index 0000000000..88148ce229 --- /dev/null +++ b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_auto_minor_version_upgrades/elasticache_redis_cluster_auto_minor_version_upgrades.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "elasticache_redis_cluster_auto_minor_version_upgrades", + "CheckTitle": "Ensure Elasticache Redis cache clusters have automatic minor upgrades enabled.", + "CheckType": [], + "ServiceName": "elasticache", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "high", + "ResourceType": "Other", + "Description": "Ensure Elasticache Redis cache clusters have automatic minor upgrades enabled.", + "Risk": "Not enabling automatic minor version upgrades can expose your Redis cluster to security vulnerabilities, performance issues, and increased operational overhead due to the need for manual updates.", + "RelatedUrl": "https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/VersionManagement.html", + "Remediation": { + "Code": { + "CLI": "aws elasticache modify-cache-cluster --cache-cluster-id --apply-immediately --auto-minor-version-upgrade", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-2", + "Terraform": "" + }, + "Recommendation": { + "Text": "Ensure Elasticache clusters have automatic minor upgrades enabled.", + "Url": "https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/Clusters.html#Modify" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_automatic_failover_enabled/elasticache_redis_cluster_automatic_failover_enabled.metadata.json b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_automatic_failover_enabled/elasticache_redis_cluster_automatic_failover_enabled.metadata.json new file mode 100644 index 0000000000..d0c0cc9333 --- /dev/null +++ b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_automatic_failover_enabled/elasticache_redis_cluster_automatic_failover_enabled.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "elasticache_redis_cluster_automatic_failover_enabled", + "CheckTitle": "Ensure Elasticache Redis clusters have automatic failover enabled.", + "CheckType": [], + "ServiceName": "elasticache", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "medium", + "ResourceType": "Other", + "Description": "Ensure Elasticache Redis OSS cache clusters use automatic failover.", + "Risk": "If automatic failover is not enabled, a failure in the primary node could result in significant downtime, impacting the availability and resilience of your application.", + "RelatedUrl": "https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/AutoFailover.html", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-3", + "Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-aws-elasticache-redis-cluster-with-multi-az-automatic-failover-feature-set-to-enabled/" + }, + "Recommendation": { + "Text": "Enable automatic failover for ElastiCache (Redis OSS) clusters to ensure high availability and minimize downtime during failures.", + "Url": "https://redis.io/blog/highly-available-in-memory-cloud-datastores/" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_backup_enabled/elasticache_redis_cluster_backup_enabled.metadata.json b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_backup_enabled/elasticache_redis_cluster_backup_enabled.metadata.json new file mode 100644 index 0000000000..bf8762ee6b --- /dev/null +++ b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_backup_enabled/elasticache_redis_cluster_backup_enabled.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "elasticache_redis_cluster_backup_enabled", + "CheckTitle": "Ensure Elasticache Redis cache cluster has automatic backups enabled.", + "CheckType": [], + "ServiceName": "elasticache", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "high", + "ResourceType": "Other", + "Description": "Ensure Elasticache Redis cache cluster has automatic backups enabled.", + "Risk": "Ensure that your Amazon ElastiCache Redis cache clusters have a sufficient backup retention period set in order to fulfill your organization's compliance requirements. The retention period represents the number of days for which Amazon ElastiCache service retains automatic Redis cluster backups before deleting them.", + "RelatedUrl": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-1", + "Remediation": { + "Code": { + "CLI": "aws elasticache modify-replication-group --region --replication-group-id --snapshot-retention-limit --apply-immediately", + "NativeIaC": "", + "Other": "", + "Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-that-amazon-elasticache-redis-clusters-have-automatic-backup-turned-on/" + }, + "Recommendation": { + "Text": "Ensure Elasticache Cluster has automatic backups enabled.", + "Url": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-1" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_in_transit_encryption_enabled/elasticache_redis_cluster_in_transit_encryption_enabled.metadata.json b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_in_transit_encryption_enabled/elasticache_redis_cluster_in_transit_encryption_enabled.metadata.json new file mode 100644 index 0000000000..891fdd4112 --- /dev/null +++ b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_in_transit_encryption_enabled/elasticache_redis_cluster_in_transit_encryption_enabled.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "elasticache_redis_cluster_in_transit_encryption_enabled", + "CheckTitle": "Ensure Elasticache Redis cache clusters have in transit encryption enabled.", + "CheckType": [], + "ServiceName": "elasticache", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "medium", + "ResourceType": "Other", + "Description": "Ensure Elasticache Redis cache clusters have in transit encryption enabled.", + "Risk": "There is a risk of exposing sensitive data if Elasticache Redis cache cluster does not have in transit encryption enabled.", + "RelatedUrl": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-5", + "Remediation": { + "Code": { + "CLI": "https://docs.prowler.com/checks/aws/general-policies/general_10/", + "NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/general_10/", + "Other": "", + "Terraform": "https://docs.prowler.com/checks/aws/general-policies/general_10/" + }, + "Recommendation": { + "Text": "Ensure your Elasticache Redis cache clusters have in transit encryption enabled.", + "Url": "https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/in-transit-encryption.html" + } + }, + "Categories": [ + "encryption" + ], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_multi_az_enabled/elasticache_redis_cluster_multi_az_enabled.metadata.json b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_multi_az_enabled/elasticache_redis_cluster_multi_az_enabled.metadata.json new file mode 100644 index 0000000000..054cdf948c --- /dev/null +++ b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_multi_az_enabled/elasticache_redis_cluster_multi_az_enabled.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "elasticache_redis_cluster_multi_az_enabled", + "CheckTitle": "Ensure Elasticache Elasticache Redis cache cluster has Multi-AZ enabled.", + "CheckType": [], + "ServiceName": "elasticache", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "medium", + "ResourceType": "Other", + "Description": "Ensure Elasticache Elasticache Redis cache cluster has Multi-AZ enabled.", + "Risk": "Ensure that your Amazon ElastiCache Redis cache clusters has Multi-AZ enabled.", + "RelatedUrl": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/ElastiCache/elasticache-multi-az.html#", + "Remediation": { + "Code": { + "CLI": "aws elasticache modify-replication-group --region --replication-group-id --multi-az-enabled --apply-immediately", + "NativeIaC": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/ElastiCache/elasticache-multi-az.html#", + "Other": "", + "Terraform": "https://docs.prowler.com/checks/aws/general-policies/ensure-aws-elasticache-redis-cluster-with-multi-az-automatic-failover-feature-set-to-enabled/" + }, + "Recommendation": { + "Text": "Ensure Elasticache Elasticache Redis cache cluster has Multi-AZ enabled.", + "Url": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/ElastiCache/elasticache-multi-az.html#" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_rest_encryption_enabled/elasticache_redis_cluster_rest_encryption_enabled.metadata.json b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_rest_encryption_enabled/elasticache_redis_cluster_rest_encryption_enabled.metadata.json new file mode 100644 index 0000000000..bacef75443 --- /dev/null +++ b/prowler/providers/aws/services/elasticache/elasticache_redis_cluster_rest_encryption_enabled/elasticache_redis_cluster_rest_encryption_enabled.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "elasticache_redis_cluster_rest_encryption_enabled", + "CheckTitle": "Ensure Elasticache Redis cache clusters have at rest encryption enabled.", + "CheckType": [], + "ServiceName": "elasticache", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "medium", + "ResourceType": "Other", + "Description": "Ensure Elasticache Redis cache clusters have at rest encryption enabled.", + "Risk": "There is a risk of exposing sensitive data if Elasticache Redis cache clusters does not have at rest encryption enabled.", + "RelatedUrl": "https://docs.aws.amazon.com/securityhub/latest/userguide/elasticache-controls.html#elasticache-4", + "Remediation": { + "Code": { + "CLI": "https://docs.prowler.com/checks/aws/general-policies/general_9/", + "NativeIaC": "https://docs.prowler.com/checks/aws/general-policies/general_9/", + "Other": "", + "Terraform": "https://docs.prowler.com/checks/aws/general-policies/general_9/" + }, + "Recommendation": { + "Text": "Ensure your Elasticache Redis cache clusters have at rest encryption enabled.", + "Url": "https://docs.aws.amazon.com/AmazonElastiCache/latest/red-ug/at-rest-encryption.html#at-rest-encryption-enable" + } + }, + "Categories": [ + "encryption" + ], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/elb/elb_cross_zone_load_balancing_enabled/elb_cross_zone_load_balancing_enabled.metadata.json b/prowler/providers/aws/services/elb/elb_cross_zone_load_balancing_enabled/elb_cross_zone_load_balancing_enabled.metadata.json new file mode 100644 index 0000000000..f107add36c --- /dev/null +++ b/prowler/providers/aws/services/elb/elb_cross_zone_load_balancing_enabled/elb_cross_zone_load_balancing_enabled.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "elb_cross_zone_load_balancing_enabled", + "CheckTitle": "Ensure Cross-Zone Load Balancing is Enabled for Classic Load Balancers (CLBs)", + "CheckType": [], + "ServiceName": "elb", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "medium", + "ResourceType": "AwsElbLoadBalancer", + "Description": "Checks whether cross-zone load balancing is enabled for Classic Load Balancers (CLBs). Cross-zone load balancing ensures even distribution of traffic across all registered targets in all Availability Zones, improving fault tolerance and load distribution.", + "Risk": "If cross-zone load balancing is not enabled, traffic may not be evenly distributed across Availability Zones, leading to over-utilization of resources in certain zones and potential application performance degradation or outages.", + "RelatedUrl": "https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/enable-disable-crosszone-lb.html", + "Remediation": { + "Code": { + "CLI": "aws elb modify-load-balancer-attributes --load-balancer-name --load-balancer-attributes \"CrossZoneLoadBalancing={Enabled=true}\"", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-9", + "Terraform": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/ELB/elb-cross-zone-load-balancing-enabled.html" + }, + "Recommendation": { + "Text": "Enable cross-zone load balancing for Classic Load Balancers to ensure even traffic distribution and enhance fault tolerance across Availability Zones.", + "Url": "https://docs.aws.amazon.com/elasticloadbalancing/latest/classic/enable-disable-crosszone-lb.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/elbv2/elbv2_deletion_protection/elbv2_deletion_protection.metadata.json b/prowler/providers/aws/services/elbv2/elbv2_deletion_protection/elbv2_deletion_protection.metadata.json index 4f5f5784f0..a07f838e9d 100644 --- a/prowler/providers/aws/services/elbv2/elbv2_deletion_protection/elbv2_deletion_protection.metadata.json +++ b/prowler/providers/aws/services/elbv2/elbv2_deletion_protection/elbv2_deletion_protection.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsElasticLoadBalancingV2LoadBalancer", + "ResourceType": "AwsElbv2LoadBalancer", "Description": "Check if Elastic Load Balancers have deletion protection enabled.", "Risk": "If deletion protection is not enabled, the resource is not protected against deletion.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/elbv2/elbv2_desync_mitigation_mode/elbv2_desync_mitigation_mode.metadata.json b/prowler/providers/aws/services/elbv2/elbv2_desync_mitigation_mode/elbv2_desync_mitigation_mode.metadata.json index e86e1064ee..cb492905b2 100644 --- a/prowler/providers/aws/services/elbv2/elbv2_desync_mitigation_mode/elbv2_desync_mitigation_mode.metadata.json +++ b/prowler/providers/aws/services/elbv2/elbv2_desync_mitigation_mode/elbv2_desync_mitigation_mode.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsElasticLoadBalancingV2LoadBalancer", + "ResourceType": "AwsElbv2LoadBalancer", "Description": "Check whether the Application Load Balancer is configured with strictest desync mitigation mode, if not check if at least is configured with the drop_invalid_header_fields attribute", "Risk": "HTTP Desync issues can lead to request smuggling and make your applications vulnerable to request queue or cache poisoning, which could lead to credential hijacking or execution of unauthorized commands.", "RelatedUrl": "https://docs.aws.amazon.com/elasticloadbalancing/latest/application/application-load-balancers.html#desync-mitigation-mode", diff --git a/prowler/providers/aws/services/elbv2/elbv2_insecure_ssl_ciphers/elbv2_insecure_ssl_ciphers.metadata.json b/prowler/providers/aws/services/elbv2/elbv2_insecure_ssl_ciphers/elbv2_insecure_ssl_ciphers.metadata.json index aa2686ac75..f8b47367d5 100644 --- a/prowler/providers/aws/services/elbv2/elbv2_insecure_ssl_ciphers/elbv2_insecure_ssl_ciphers.metadata.json +++ b/prowler/providers/aws/services/elbv2/elbv2_insecure_ssl_ciphers/elbv2_insecure_ssl_ciphers.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsElasticLoadBalancingV2LoadBalancer", + "ResourceType": "AwsElbv2LoadBalancer", "Description": "Check if Elastic Load Balancers have insecure SSL ciphers.", "Risk": "Using insecure ciphers could affect privacy of in transit information.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/elbv2/elbv2_internet_facing/elbv2_internet_facing.metadata.json b/prowler/providers/aws/services/elbv2/elbv2_internet_facing/elbv2_internet_facing.metadata.json index 66b5db75a4..2aea137671 100644 --- a/prowler/providers/aws/services/elbv2/elbv2_internet_facing/elbv2_internet_facing.metadata.json +++ b/prowler/providers/aws/services/elbv2/elbv2_internet_facing/elbv2_internet_facing.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsElasticLoadBalancingV2LoadBalancer", + "ResourceType": "AwsElbv2LoadBalancer", "Description": "Check for internet facing Elastic Load Balancers.", "Risk": "Publicly accessible load balancers could expose sensitive data to bad actors.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/elbv2/elbv2_is_in_multiple_az/elbv2_is_in_multiple_az.metadata.json b/prowler/providers/aws/services/elbv2/elbv2_is_in_multiple_az/elbv2_is_in_multiple_az.metadata.json new file mode 100644 index 0000000000..aa83988cff --- /dev/null +++ b/prowler/providers/aws/services/elbv2/elbv2_is_in_multiple_az/elbv2_is_in_multiple_az.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "elbv2_is_in_multiple_az", + "CheckTitle": "Elastic Load Balancer V2 (ELBv2) is Configured Across Multiple Availability Zones (AZs)", + "CheckType": [], + "ServiceName": "elbv2", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "medium", + "ResourceType": "AwsElbv2LoadBalancer", + "Description": "Ensure whether Elastic Load Balancer V2 (Application, Network, or Gateway Load Balancer) is configured to operate across multiple Availability Zones (AZs). Ensuring that your load balancer is spread across at least two AZs helps maintain high availability and fault tolerance in case of an AZ failure.", + "Risk": "If an ELBv2 is not configured across multiple AZs, there is a risk that an Availability Zone failure could lead to downtime for your application. This could result in a single point of failure, impacting the availability and reliability of your services.", + "RelatedUrl": "https://docs.aws.amazon.com/elasticloadbalancing/latest/userguide/how-elastic-load-balancing-works.html#availability-zones", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/elb-controls.html#elb-13", + "Terraform": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/ELBv2/enable-multi-az.html" + }, + "Recommendation": { + "Text": "It is recommended to configure your ELBv2 to operate across at least two Availability Zones to enhance fault tolerance and availability.", + "Url": "https://docs.aws.amazon.com/elasticloadbalancing/latest/application/load-balancer-subnets.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/elbv2/elbv2_listeners_underneath/elbv2_listeners_underneath.metadata.json b/prowler/providers/aws/services/elbv2/elbv2_listeners_underneath/elbv2_listeners_underneath.metadata.json index 2841e8e3c8..9b7a297221 100644 --- a/prowler/providers/aws/services/elbv2/elbv2_listeners_underneath/elbv2_listeners_underneath.metadata.json +++ b/prowler/providers/aws/services/elbv2/elbv2_listeners_underneath/elbv2_listeners_underneath.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsElasticLoadBalancingV2LoadBalancer", + "ResourceType": "AwsElbv2LoadBalancer", "Description": "Check if ELBV2 has listeners underneath.", "Risk": "The rules that are defined for a listener determine how the load balancer routes requests to its registered targets.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/elbv2/elbv2_logging_enabled/elbv2_logging_enabled.metadata.json b/prowler/providers/aws/services/elbv2/elbv2_logging_enabled/elbv2_logging_enabled.metadata.json index fe9a89e3e1..3117bbb6c5 100644 --- a/prowler/providers/aws/services/elbv2/elbv2_logging_enabled/elbv2_logging_enabled.metadata.json +++ b/prowler/providers/aws/services/elbv2/elbv2_logging_enabled/elbv2_logging_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsElasticLoadBalancingV2LoadBalancer", + "ResourceType": "AwsElbv2LoadBalancer", "Description": "Check if Elastic Load Balancers have logging enabled.", "Risk": "If logs are not enabled monitoring of service use and threat analysis is not possible.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/elbv2/elbv2_ssl_listeners/elbv2_ssl_listeners.metadata.json b/prowler/providers/aws/services/elbv2/elbv2_ssl_listeners/elbv2_ssl_listeners.metadata.json index 22dbe8e79b..dbb8c13850 100644 --- a/prowler/providers/aws/services/elbv2/elbv2_ssl_listeners/elbv2_ssl_listeners.metadata.json +++ b/prowler/providers/aws/services/elbv2/elbv2_ssl_listeners/elbv2_ssl_listeners.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsElasticLoadBalancingV2LoadBalancer", + "ResourceType": "AwsElbv2LoadBalancer", "Description": "Check if Elastic Load Balancers have SSL listeners.", "Risk": "Clear text communication could affect privacy of information in transit.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/elbv2/elbv2_waf_acl_attached/elbv2_waf_acl_attached.metadata.json b/prowler/providers/aws/services/elbv2/elbv2_waf_acl_attached/elbv2_waf_acl_attached.metadata.json index 2dd6140424..677e9059f4 100644 --- a/prowler/providers/aws/services/elbv2/elbv2_waf_acl_attached/elbv2_waf_acl_attached.metadata.json +++ b/prowler/providers/aws/services/elbv2/elbv2_waf_acl_attached/elbv2_waf_acl_attached.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsElasticLoadBalancingV2LoadBalancer", + "ResourceType": "AwsElbv2LoadBalancer", "Description": "Check if Application Load Balancer has a WAF ACL attached.", "Risk": "If not WAF ACL is attached risk of web attacks increases.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/emr/emr_cluster_account_public_block_enabled/emr_cluster_account_public_block_enabled.metadata.json b/prowler/providers/aws/services/emr/emr_cluster_account_public_block_enabled/emr_cluster_account_public_block_enabled.metadata.json index a9f1ff8e63..e7b123c22d 100644 --- a/prowler/providers/aws/services/emr/emr_cluster_account_public_block_enabled/emr_cluster_account_public_block_enabled.metadata.json +++ b/prowler/providers/aws/services/emr/emr_cluster_account_public_block_enabled/emr_cluster_account_public_block_enabled.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:emr:region:account-id", "Severity": "high", - "ResourceType": "AwsEMR", + "ResourceType": "AwsAccount", "Description": "EMR Account Public Access Block enabled.", "Risk": "EMR Clusters must have Account Public Access Block enabled.", "RelatedUrl": "https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-block-public-access.html", diff --git a/prowler/providers/aws/services/emr/emr_cluster_master_nodes_no_public_ip/emr_cluster_master_nodes_no_public_ip.metadata.json b/prowler/providers/aws/services/emr/emr_cluster_master_nodes_no_public_ip/emr_cluster_master_nodes_no_public_ip.metadata.json index c913fc534a..0cc84e87a6 100644 --- a/prowler/providers/aws/services/emr/emr_cluster_master_nodes_no_public_ip/emr_cluster_master_nodes_no_public_ip.metadata.json +++ b/prowler/providers/aws/services/emr/emr_cluster_master_nodes_no_public_ip/emr_cluster_master_nodes_no_public_ip.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:emr:region:account-id", "Severity": "medium", - "ResourceType": "AwsEMR", + "ResourceType": "Other", "Description": "EMR Cluster without Public IP.", "Risk": "EMR Cluster should not have Public IP.", "RelatedUrl": "https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-block-public-access.html", diff --git a/prowler/providers/aws/services/emr/emr_cluster_publicly_accesible/emr_cluster_publicly_accesible.metadata.json b/prowler/providers/aws/services/emr/emr_cluster_publicly_accesible/emr_cluster_publicly_accesible.metadata.json index a207a575ba..623f403343 100644 --- a/prowler/providers/aws/services/emr/emr_cluster_publicly_accesible/emr_cluster_publicly_accesible.metadata.json +++ b/prowler/providers/aws/services/emr/emr_cluster_publicly_accesible/emr_cluster_publicly_accesible.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:emr:region:account-id", "Severity": "medium", - "ResourceType": "AwsEMR", + "ResourceType": "Other", "Description": "Publicly accessible EMR Cluster.", "Risk": "EMR Clusters should not be publicly accessible.", "RelatedUrl": "https://docs.aws.amazon.com/emr/latest/ManagementGuide/emr-block-public-access.html", diff --git a/prowler/providers/aws/services/glacier/glacier_vaults_policy_public_access/glacier_vaults_policy_public_access.metadata.json b/prowler/providers/aws/services/glacier/glacier_vaults_policy_public_access/glacier_vaults_policy_public_access.metadata.json index 2e8333cd68..7ff3cf6921 100644 --- a/prowler/providers/aws/services/glacier/glacier_vaults_policy_public_access/glacier_vaults_policy_public_access.metadata.json +++ b/prowler/providers/aws/services/glacier/glacier_vaults_policy_public_access/glacier_vaults_policy_public_access.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:glacier:region:account-id:vaults/vault-name", "Severity": "critical", - "ResourceType": "AwsGlacierVault", + "ResourceType": "Other", "Description": "Ensure CodeArtifact internal packages do not allow external public source publishing.", "Risk": "Vaults accessible to everyone could expose sensitive data to bad actors.", "RelatedUrl": "https://docs.aws.amazon.com/amazonglacier/latest/dev/access-control-overview.html", diff --git a/prowler/providers/aws/services/glue/glue_data_catalogs_connection_passwords_encryption_enabled/glue_data_catalogs_connection_passwords_encryption_enabled.metadata.json b/prowler/providers/aws/services/glue/glue_data_catalogs_connection_passwords_encryption_enabled/glue_data_catalogs_connection_passwords_encryption_enabled.metadata.json index 202daa40ba..3079c2e9b2 100644 --- a/prowler/providers/aws/services/glue/glue_data_catalogs_connection_passwords_encryption_enabled/glue_data_catalogs_connection_passwords_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/glue/glue_data_catalogs_connection_passwords_encryption_enabled/glue_data_catalogs_connection_passwords_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:glue:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsGlue", + "ResourceType": "Other", "Description": "Check if Glue data catalog settings have encrypt connection password enabled.", "Risk": "If not enabled sensitive information at rest is not protected.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/glue/glue_data_catalogs_metadata_encryption_enabled/glue_data_catalogs_metadata_encryption_enabled.metadata.json b/prowler/providers/aws/services/glue/glue_data_catalogs_metadata_encryption_enabled/glue_data_catalogs_metadata_encryption_enabled.metadata.json index 5653ae151e..1f3af4b0fb 100644 --- a/prowler/providers/aws/services/glue/glue_data_catalogs_metadata_encryption_enabled/glue_data_catalogs_metadata_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/glue/glue_data_catalogs_metadata_encryption_enabled/glue_data_catalogs_metadata_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:glue:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsGlue", + "ResourceType": "Other", "Description": "Check if Glue data catalog settings have metadata encryption enabled.", "Risk": "If not enabled sensitive information at rest is not protected.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/glue/glue_database_connections_ssl_enabled/glue_database_connections_ssl_enabled.metadata.json b/prowler/providers/aws/services/glue/glue_database_connections_ssl_enabled/glue_database_connections_ssl_enabled.metadata.json index 40869ae64b..66500dee38 100644 --- a/prowler/providers/aws/services/glue/glue_database_connections_ssl_enabled/glue_database_connections_ssl_enabled.metadata.json +++ b/prowler/providers/aws/services/glue/glue_database_connections_ssl_enabled/glue_database_connections_ssl_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:glue:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsGlue", + "ResourceType": "Other", "Description": "Check if Glue database connection has SSL connection enabled.", "Risk": "Data exfiltration could happen if information is not protected in transit.", "RelatedUrl": "https://docs.aws.amazon.com/glue/latest/dg/encryption-in-transit.html", diff --git a/prowler/providers/aws/services/glue/glue_development_endpoints_cloudwatch_logs_encryption_enabled/glue_development_endpoints_cloudwatch_logs_encryption_enabled.metadata.json b/prowler/providers/aws/services/glue/glue_development_endpoints_cloudwatch_logs_encryption_enabled/glue_development_endpoints_cloudwatch_logs_encryption_enabled.metadata.json index dbba2e8f5a..622bb6c6fb 100644 --- a/prowler/providers/aws/services/glue/glue_development_endpoints_cloudwatch_logs_encryption_enabled/glue_development_endpoints_cloudwatch_logs_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/glue/glue_development_endpoints_cloudwatch_logs_encryption_enabled/glue_development_endpoints_cloudwatch_logs_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:glue:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsGlue", + "ResourceType": "Other", "Description": "Check if Glue development endpoints have CloudWatch logs encryption enabled.", "Risk": "If not enabled sensitive information at rest is not protected.", "RelatedUrl": "https://docs.aws.amazon.com/glue/latest/dg/console-security-configurations.html", diff --git a/prowler/providers/aws/services/glue/glue_development_endpoints_job_bookmark_encryption_enabled/glue_development_endpoints_job_bookmark_encryption_enabled.metadata.json b/prowler/providers/aws/services/glue/glue_development_endpoints_job_bookmark_encryption_enabled/glue_development_endpoints_job_bookmark_encryption_enabled.metadata.json index d62d2be5c1..eb724b942c 100644 --- a/prowler/providers/aws/services/glue/glue_development_endpoints_job_bookmark_encryption_enabled/glue_development_endpoints_job_bookmark_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/glue/glue_development_endpoints_job_bookmark_encryption_enabled/glue_development_endpoints_job_bookmark_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:glue:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsGlue", + "ResourceType": "Other", "Description": "Check if Glue development endpoints have Job bookmark encryption enabled.", "Risk": "If not enabled sensitive information at rest is not protected.", "RelatedUrl": "https://docs.aws.amazon.com/glue/latest/dg/console-security-configurations.html", diff --git a/prowler/providers/aws/services/glue/glue_development_endpoints_s3_encryption_enabled/glue_development_endpoints_s3_encryption_enabled.metadata.json b/prowler/providers/aws/services/glue/glue_development_endpoints_s3_encryption_enabled/glue_development_endpoints_s3_encryption_enabled.metadata.json index 56931fad5f..9b958b4d6a 100644 --- a/prowler/providers/aws/services/glue/glue_development_endpoints_s3_encryption_enabled/glue_development_endpoints_s3_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/glue/glue_development_endpoints_s3_encryption_enabled/glue_development_endpoints_s3_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:glue:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsGlue", + "ResourceType": "Other", "Description": "Check if Glue development endpoints have S3 encryption enabled.", "Risk": "Data exfiltration could happen if information is not protected. KMS keys provide additional security level to IAM policies.", "RelatedUrl": "https://docs.aws.amazon.com/glue/latest/dg/encryption-security-configuration.html", diff --git a/prowler/providers/aws/services/glue/glue_etl_jobs_amazon_s3_encryption_enabled/glue_etl_jobs_amazon_s3_encryption_enabled.metadata.json b/prowler/providers/aws/services/glue/glue_etl_jobs_amazon_s3_encryption_enabled/glue_etl_jobs_amazon_s3_encryption_enabled.metadata.json index 2bbcf97789..6b23dffecf 100644 --- a/prowler/providers/aws/services/glue/glue_etl_jobs_amazon_s3_encryption_enabled/glue_etl_jobs_amazon_s3_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/glue/glue_etl_jobs_amazon_s3_encryption_enabled/glue_etl_jobs_amazon_s3_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:glue:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsGlue", + "ResourceType": "AwsGlueJob", "Description": "Check if Glue ETL Jobs have S3 encryption enabled.", "Risk": "If not enabled sensitive information at rest is not protected.", "RelatedUrl": "https://docs.aws.amazon.com/glue/latest/dg/console-security-configurations.html", diff --git a/prowler/providers/aws/services/glue/glue_etl_jobs_cloudwatch_logs_encryption_enabled/glue_etl_jobs_cloudwatch_logs_encryption_enabled.metadata.json b/prowler/providers/aws/services/glue/glue_etl_jobs_cloudwatch_logs_encryption_enabled/glue_etl_jobs_cloudwatch_logs_encryption_enabled.metadata.json index 99130b8bc3..0686c7e290 100644 --- a/prowler/providers/aws/services/glue/glue_etl_jobs_cloudwatch_logs_encryption_enabled/glue_etl_jobs_cloudwatch_logs_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/glue/glue_etl_jobs_cloudwatch_logs_encryption_enabled/glue_etl_jobs_cloudwatch_logs_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:glue:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsGlue", + "ResourceType": "AwsGlueJob", "Description": "Check if Glue ETL Jobs have CloudWatch Logs encryption enabled.", "Risk": "If not enabled sensitive information at rest is not protected.", "RelatedUrl": "https://docs.aws.amazon.com/glue/latest/dg/console-security-configurations.html", diff --git a/prowler/providers/aws/services/glue/glue_etl_jobs_job_bookmark_encryption_enabled/glue_etl_jobs_job_bookmark_encryption_enabled.metadata.json b/prowler/providers/aws/services/glue/glue_etl_jobs_job_bookmark_encryption_enabled/glue_etl_jobs_job_bookmark_encryption_enabled.metadata.json index 70673bc0c0..78a1757509 100644 --- a/prowler/providers/aws/services/glue/glue_etl_jobs_job_bookmark_encryption_enabled/glue_etl_jobs_job_bookmark_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/glue/glue_etl_jobs_job_bookmark_encryption_enabled/glue_etl_jobs_job_bookmark_encryption_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:glue:region:account-id:certificate/resource-id", "Severity": "medium", - "ResourceType": "AwsGlue", + "ResourceType": "AwsGlueJob", "Description": "Check if Glue ETL Jobs have Job bookmark encryption enabled.", "Risk": "If not enabled sensitive information at rest is not protected.", "RelatedUrl": "https://docs.aws.amazon.com/glue/latest/dg/console-security-configurations.html", diff --git a/prowler/providers/aws/services/guardduty/guardduty_centrally_managed/guardduty_centrally_managed.metadata.json b/prowler/providers/aws/services/guardduty/guardduty_centrally_managed/guardduty_centrally_managed.metadata.json index 473fecce17..e0298b1fef 100644 --- a/prowler/providers/aws/services/guardduty/guardduty_centrally_managed/guardduty_centrally_managed.metadata.json +++ b/prowler/providers/aws/services/guardduty/guardduty_centrally_managed/guardduty_centrally_managed.metadata.json @@ -9,7 +9,7 @@ "Severity": "medium", "ResourceType": "AwsGuardDutyDetector", "Description": "GuardDuty is centrally managed", - "Risk": "If GuardDuty is not centrally managed, it is not possible to centrally manage the GuardDuty findings, settings, and member accounts.", + "Risk": "If GuardDuty is not centrally managed, it is not possible to centrally manage the GuardDuty findings, settings, and member accounts.", "RelatedUrl": "https://docs.aws.amazon.com/guardduty/latest/ug/guardduty_accounts.html", "Remediation": { "Code": { diff --git a/prowler/providers/aws/services/iam/iam_inline_policy_allows_privilege_escalation/iam_inline_policy_allows_privilege_escalation.metadata.json b/prowler/providers/aws/services/iam/iam_inline_policy_allows_privilege_escalation/iam_inline_policy_allows_privilege_escalation.metadata.json new file mode 100644 index 0000000000..47f43cda3d --- /dev/null +++ b/prowler/providers/aws/services/iam/iam_inline_policy_allows_privilege_escalation/iam_inline_policy_allows_privilege_escalation.metadata.json @@ -0,0 +1,33 @@ +{ + "Provider": "aws", + "CheckID": "iam_inline_policy_allows_privilege_escalation", + "CheckTitle": "Ensure no IAM Inline policies allow actions that may lead into Privilege Escalation", + "CheckType": [ + "Software and Configuration Checks", + "Industry and Regulatory Standards" + ], + "ServiceName": "iam", + "SubServiceName": "inline_policy", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "high", + "ResourceType": "AwsIamPolicy", + "Description": "Ensure no Inline IAM policies allow actions that may lead into Privilege Escalation", + "Risk": "Users with some IAM permissions are allowed to elevate their privileges up to administrator rights.", + "RelatedUrl": "", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "Grant usage permission on a per-resource basis and applying least privilege principle.", + "Url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/best-practices.html#grant-least-privilege" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/iam/iam_inline_policy_no_administrative_privileges/iam_inline_policy_no_administrative_privileges.metadata.json b/prowler/providers/aws/services/iam/iam_inline_policy_no_administrative_privileges/iam_inline_policy_no_administrative_privileges.metadata.json index 20eb42eb41..68cd1c4898 100644 --- a/prowler/providers/aws/services/iam/iam_inline_policy_no_administrative_privileges/iam_inline_policy_no_administrative_privileges.metadata.json +++ b/prowler/providers/aws/services/iam/iam_inline_policy_no_administrative_privileges/iam_inline_policy_no_administrative_privileges.metadata.json @@ -1,7 +1,7 @@ { "Provider": "aws", "CheckID": "iam_inline_policy_no_administrative_privileges", - "CheckTitle": "Ensure inline policies that allow full \"*:*\" administrative privileges are not associated to IAM identities", + "CheckTitle": "Ensure IAM inline policies that allow full \"*:*\" administrative privileges are not associated to IAM identities", "CheckType": [ "Software and Configuration Checks", "Industry and Regulatory Standards", @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "high", - "ResourceType": "AwsIamRole", + "ResourceType": "AwsIamPolicy", "Description": "Ensure inline policies that allow full \"*:*\" administrative privileges are not associated to IAM identities", "Risk": "IAM policies are the means by which privileges are granted to users, groups or roles. It is recommended and considered a standard security advice to grant least privilege—that is, granting only the permissions required to perform a task. Determine what users need to do and then craft policies for them that let the users perform only those tasks instead of allowing full administrative privileges. Providing full administrative privileges instead of restricting to the minimum set of permissions that the user is required to do exposes the resources to potentially unwanted actions.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_no_expired_server_certificates_stored/iam_no_expired_server_certificates_stored.metadata.json b/prowler/providers/aws/services/iam/iam_no_expired_server_certificates_stored/iam_no_expired_server_certificates_stored.metadata.json index aa2582927b..744ca0b276 100644 --- a/prowler/providers/aws/services/iam/iam_no_expired_server_certificates_stored/iam_no_expired_server_certificates_stored.metadata.json +++ b/prowler/providers/aws/services/iam/iam_no_expired_server_certificates_stored/iam_no_expired_server_certificates_stored.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "critical", - "ResourceType": "AwsIamUser", + "ResourceType": "Other", "Description": "Ensure that all the expired SSL/TLS certificates stored in AWS IAM are removed.", "Risk": "Removing expired SSL/TLS certificates eliminates the risk that an invalid certificate will be deployed accidentally to a resource such as AWS Elastic Load Balancer (ELB), which can damage the credibility of the application/website behind the ELB.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_no_root_access_key/iam_no_root_access_key.metadata.json b/prowler/providers/aws/services/iam/iam_no_root_access_key/iam_no_root_access_key.metadata.json index bc7173a3b1..933ffee047 100644 --- a/prowler/providers/aws/services/iam/iam_no_root_access_key/iam_no_root_access_key.metadata.json +++ b/prowler/providers/aws/services/iam/iam_no_root_access_key/iam_no_root_access_key.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "critical", - "ResourceType": "AwsIamUser", + "ResourceType": "AwsIamAccessKey", "Description": "Ensure no root account access key exists", "Risk": "The root account is the most privileged user in an AWS account. AWS Access Keys provide programmatic access to a given AWS account. It is recommended that all access keys associated with the root account be removed. Removing access keys associated with the root account limits vectors by which the account can be compromised. Removing the root access keys encourages the creation and use of role based accounts that are least privileged.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_password_policy_expires_passwords_within_90_days_or_less/iam_password_policy_expires_passwords_within_90_days_or_less.metadata.json b/prowler/providers/aws/services/iam/iam_password_policy_expires_passwords_within_90_days_or_less/iam_password_policy_expires_passwords_within_90_days_or_less.metadata.json index ac112cea19..1f30be3869 100644 --- a/prowler/providers/aws/services/iam/iam_password_policy_expires_passwords_within_90_days_or_less/iam_password_policy_expires_passwords_within_90_days_or_less.metadata.json +++ b/prowler/providers/aws/services/iam/iam_password_policy_expires_passwords_within_90_days_or_less/iam_password_policy_expires_passwords_within_90_days_or_less.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsIamPasswordPolicy", + "ResourceType": "Other", "Description": "Ensure IAM password policy expires passwords within 90 days or less", "Risk": "Password policies are used to enforce password complexity requirements. IAM password policies can be used to ensure password are comprised of different character sets. It is recommended that the password policy require at least one uppercase letter.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_password_policy_lowercase/iam_password_policy_lowercase.metadata.json b/prowler/providers/aws/services/iam/iam_password_policy_lowercase/iam_password_policy_lowercase.metadata.json index b9a90107f5..da7f9ca9e5 100644 --- a/prowler/providers/aws/services/iam/iam_password_policy_lowercase/iam_password_policy_lowercase.metadata.json +++ b/prowler/providers/aws/services/iam/iam_password_policy_lowercase/iam_password_policy_lowercase.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsIamPasswordPolicy", + "ResourceType": "Other", "Description": "Ensure IAM password policy requires at least one uppercase letter", "Risk": "Password policies are used to enforce password complexity requirements. IAM password policies can be used to ensure password are comprised of different character sets. It is recommended that the password policy require at least one lowercase letter.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_password_policy_minimum_length_14/iam_password_policy_minimum_length_14.metadata.json b/prowler/providers/aws/services/iam/iam_password_policy_minimum_length_14/iam_password_policy_minimum_length_14.metadata.json index 7eb4cc024e..e4ef273d94 100644 --- a/prowler/providers/aws/services/iam/iam_password_policy_minimum_length_14/iam_password_policy_minimum_length_14.metadata.json +++ b/prowler/providers/aws/services/iam/iam_password_policy_minimum_length_14/iam_password_policy_minimum_length_14.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsIamPasswordPolicy", + "ResourceType": "Other", "Description": "Ensure IAM password policy requires minimum length of 14 or greater", "Risk": "Password policies are used to enforce password complexity requirements. IAM password policies can be used to ensure password are comprised of different character sets. It is recommended that the password policy require minimum length of 14 or greater.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_password_policy_number/iam_password_policy_number.metadata.json b/prowler/providers/aws/services/iam/iam_password_policy_number/iam_password_policy_number.metadata.json index 300922184f..98d9e50426 100644 --- a/prowler/providers/aws/services/iam/iam_password_policy_number/iam_password_policy_number.metadata.json +++ b/prowler/providers/aws/services/iam/iam_password_policy_number/iam_password_policy_number.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsIamPasswordPolicy", + "ResourceType": "Other", "Description": "Ensure IAM password policy require at least one number", "Risk": "Password policies are used to enforce password complexity requirements. IAM password policies can be used to ensure password are comprised of different character sets. It is recommended that the password policy require at least one number.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_password_policy_reuse_24/iam_password_policy_reuse_24.metadata.json b/prowler/providers/aws/services/iam/iam_password_policy_reuse_24/iam_password_policy_reuse_24.metadata.json index 79d49e146a..321008db6b 100644 --- a/prowler/providers/aws/services/iam/iam_password_policy_reuse_24/iam_password_policy_reuse_24.metadata.json +++ b/prowler/providers/aws/services/iam/iam_password_policy_reuse_24/iam_password_policy_reuse_24.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsIamPasswordPolicy", + "ResourceType": "Other", "Description": "Ensure IAM password policy prevents password reuse: 24 or greater", "Risk": "Password policies are used to enforce password complexity requirements. IAM password policies can be used to ensure password are comprised of different character sets. It is recommended that the password policy prevents at least password reuse of 24 or greater.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_password_policy_symbol/iam_password_policy_symbol.metadata.json b/prowler/providers/aws/services/iam/iam_password_policy_symbol/iam_password_policy_symbol.metadata.json index a8d41bb9c0..45645479a7 100644 --- a/prowler/providers/aws/services/iam/iam_password_policy_symbol/iam_password_policy_symbol.metadata.json +++ b/prowler/providers/aws/services/iam/iam_password_policy_symbol/iam_password_policy_symbol.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsIamPasswordPolicy", + "ResourceType": "Other", "Description": "Ensure IAM password policy require at least one symbol", "Risk": "Password policies are used to enforce password complexity requirements. IAM password policies can be used to ensure password are comprised of different character sets. It is recommended that the password policy require at least one non-alphanumeric character.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_password_policy_uppercase/iam_password_policy_uppercase.metadata.json b/prowler/providers/aws/services/iam/iam_password_policy_uppercase/iam_password_policy_uppercase.metadata.json index 16964a0cdc..a1653fddb5 100644 --- a/prowler/providers/aws/services/iam/iam_password_policy_uppercase/iam_password_policy_uppercase.metadata.json +++ b/prowler/providers/aws/services/iam/iam_password_policy_uppercase/iam_password_policy_uppercase.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsIamPasswordPolicy", + "ResourceType": "Other", "Description": "Ensure IAM password policy requires at least one uppercase letter", "Risk": "Password policies are used to enforce password complexity requirements. IAM password policies can be used to ensure password are comprised of different character sets. It is recommended that the password policy require at least one uppercase letter.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_policy_attached_only_to_group_or_roles/iam_policy_attached_only_to_group_or_roles.metadata.json b/prowler/providers/aws/services/iam/iam_policy_attached_only_to_group_or_roles/iam_policy_attached_only_to_group_or_roles.metadata.json index 0796299558..bfd435bb16 100644 --- a/prowler/providers/aws/services/iam/iam_policy_attached_only_to_group_or_roles/iam_policy_attached_only_to_group_or_roles.metadata.json +++ b/prowler/providers/aws/services/iam/iam_policy_attached_only_to_group_or_roles/iam_policy_attached_only_to_group_or_roles.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "low", - "ResourceType": "AwsIamUser", + "ResourceType": "AwsIamPolicy", "Description": "Ensure IAM policies are attached only to groups or roles", "Risk": "By default IAM users, groups, and roles have no access to AWS resources. IAM policies are the means by which privileges are granted to users, groups, or roles. It is recommended that IAM policies be applied directly to groups and roles but not users. Assigning privileges at the group or role level reduces the complexity of access management as the number of users grow. Reducing access management complexity may in-turn reduce opportunity for a principal to inadvertently receive or retain excessive privileges.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_rotate_access_key_90_days/iam_rotate_access_key_90_days.metadata.json b/prowler/providers/aws/services/iam/iam_rotate_access_key_90_days/iam_rotate_access_key_90_days.metadata.json index 2f7044a6a4..ff99046fd9 100644 --- a/prowler/providers/aws/services/iam/iam_rotate_access_key_90_days/iam_rotate_access_key_90_days.metadata.json +++ b/prowler/providers/aws/services/iam/iam_rotate_access_key_90_days/iam_rotate_access_key_90_days.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsIamUser", + "ResourceType": "AwsIamAccessKey", "Description": "Ensure access keys are rotated every 90 days or less", "Risk": "Access keys consist of an access key ID and secret access key which are used to sign programmatic requests that you make to AWS. AWS users need their own access keys to make programmatic calls to AWS from the AWS Command Line Interface (AWS CLI)- Tools for Windows PowerShell- the AWS SDKs- or direct HTTP calls using the APIs for individual AWS services. It is recommended that all access keys be regularly rotated.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/iam/iam_user_no_setup_initial_access_key/iam_user_no_setup_initial_access_key.metadata.json b/prowler/providers/aws/services/iam/iam_user_no_setup_initial_access_key/iam_user_no_setup_initial_access_key.metadata.json index 6bce20df15..971870b6a9 100644 --- a/prowler/providers/aws/services/iam/iam_user_no_setup_initial_access_key/iam_user_no_setup_initial_access_key.metadata.json +++ b/prowler/providers/aws/services/iam/iam_user_no_setup_initial_access_key/iam_user_no_setup_initial_access_key.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsIamUser", + "ResourceType": "AwsIamAccessKey", "Description": "Do not setup access keys during initial user setup for all IAM users that have a console password", "Risk": "AWS console defaults the checkbox for creating access keys to enabled. This results in many access keys being generated unnecessarily. In addition to unnecessary credentials, it also generates unnecessary management work in auditing and rotating these keys. Requiring that additional steps be taken by the user after their profile has been created will give a stronger indication of intent that access keys are (a) necessary for their work and (b) once the access key is established on an account that the keys may be in use somewhere in the organization.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/kafka/kafka_cluster_encryption_at_rest_uses_cmk/kafka_cluster_encryption_at_rest_uses_cmk.metadata.json b/prowler/providers/aws/services/kafka/kafka_cluster_encryption_at_rest_uses_cmk/kafka_cluster_encryption_at_rest_uses_cmk.metadata.json new file mode 100644 index 0000000000..9154bfd8d0 --- /dev/null +++ b/prowler/providers/aws/services/kafka/kafka_cluster_encryption_at_rest_uses_cmk/kafka_cluster_encryption_at_rest_uses_cmk.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "kafka_cluster_encryption_at_rest_uses_cmk", + "CheckTitle": "Ensure Kafka Cluster Encryption at Rest Uses Customer Managed Keys (CMK)", + "CheckType": [ + "Infrastructure Security" + ], + "ServiceName": "kafka", + "SubServiceName": "Kafka Cluster", + "ResourceIdTemplate": "arn:partition:kafka:region:account-id:cluster", + "Severity": "medium", + "ResourceType": "AwsMskCluster", + "Description": "Kafka Cluster data stored at rest should be encrypted using Customer Managed Keys (CMK) for enhanced security and control over the encryption process.", + "Risk": "Using default AWS-managed encryption keys might not meet certain compliance or regulatory requirements. With CMKs, you have more control over the encryption process and can rotate keys, define access policies, and enable key auditing.", + "RelatedUrl": "https://docs.aws.amazon.com/msk/latest/developerguide/msk-encryption.html", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/MSK/msk-encryption-at-rest-with-cmk.html", + "Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_32/#terraform" + }, + "Recommendation": { + "Text": "It is recommended to use Customer Managed Keys (CMK) for Kafka Cluster encryption at rest to maintain control and flexibility over the encryption process.", + "Url": "https://docs.aws.amazon.com/msk/latest/developerguide/msk-working-with-encryption.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/kafka/kafka_cluster_enhanced_monitoring_enabled/kafka_cluster_enhanced_monitoring_enabled.metadata.json b/prowler/providers/aws/services/kafka/kafka_cluster_enhanced_monitoring_enabled/kafka_cluster_enhanced_monitoring_enabled.metadata.json new file mode 100644 index 0000000000..007644fa7c --- /dev/null +++ b/prowler/providers/aws/services/kafka/kafka_cluster_enhanced_monitoring_enabled/kafka_cluster_enhanced_monitoring_enabled.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "kafka_cluster_enhanced_monitoring_enabled", + "CheckTitle": "Ensure Enhanced Monitoring is Enabled for MSK (Kafka) Brokers", + "CheckType": [], + "ServiceName": "kafka", + "SubServiceName": "cluster", + "ResourceIdTemplate": "arn:partition:kafka:region:account-id:cluster", + "Severity": "medium", + "ResourceType": "AwsMskCluster", + "Description": "Enhanced monitoring provides additional visibility into the performance and behavior of MSK (Kafka) brokers. By enabling enhanced monitoring, you can gain insights into potential issues and optimize the performance of your Kafka clusters.", + "Risk": "Without enhanced monitoring, you may have limited visibility into the performance and health of your MSK brokers, which could lead to undetected issues and potential performance degradation.", + "RelatedUrl": "https://docs.aws.amazon.com/msk/latest/developerguide/monitoring.html", + "Remediation": { + "Code": { + "CLI": "aws kafka update-monitoring --region region_cluster --cluster-arn arn_cluster --current-version version_cluster --enhanced-monitoring PER_BROKER", + "NativeIaC": "", + "Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/MSK/enable-enhanced-monitoring-for-apache-kafka-brokers.html#", + "Terraform": "" + }, + "Recommendation": { + "Text": "It is recommended to enable enhanced monitoring for MSK (Kafka) brokers to gain deeper insights into the performance and behavior of your clusters.", + "Url": "https://docs.aws.amazon.com/msk/latest/developerguide/metrics-details.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/kafka/kafka_cluster_in_transit_encryption_enabled/kafka_cluster_in_transit_encryption_enabled.metadata.json b/prowler/providers/aws/services/kafka/kafka_cluster_in_transit_encryption_enabled/kafka_cluster_in_transit_encryption_enabled.metadata.json new file mode 100644 index 0000000000..bce398462f --- /dev/null +++ b/prowler/providers/aws/services/kafka/kafka_cluster_in_transit_encryption_enabled/kafka_cluster_in_transit_encryption_enabled.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "kafka_cluster_in_transit_encryption_enabled", + "CheckTitle": "Ensure Kafka Cluster Encryption in Transit is Enabled", + "CheckType": [ + "Infrastructure Security" + ], + "ServiceName": "kafka", + "SubServiceName": "cluster", + "ResourceIdTemplate": "arn:partition:kafka:region:account-id:cluster", + "Severity": "medium", + "ResourceType": "AwsMskCluster", + "Description": "Kafka clusters should have encryption in transit enabled to protect data as it travels across the network. This ensures that data is encrypted when transmitted between clients and brokers, preventing unauthorized access or data breaches.", + "Risk": "If encryption in transit is not enabled, data transmitted over the network could be vulnerable to eavesdropping or man-in-the-middle attacks.", + "RelatedUrl": "https://docs.aws.amazon.com/msk/latest/developerguide/msk-encryption.html", + "Remediation": { + "Code": { + "CLI": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_32/#cli", + "NativeIaC": "", + "Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/MSK/encryption-in-transit-for-msk.html", + "Terraform": "https://docs.prowler.com/checks/aws/general-policies/bc_aws_general_32/#terraform" + }, + "Recommendation": { + "Text": "It is recommended to enable encryption in transit for Kafka clusters to protect data confidentiality and integrity.", + "Url": "https://docs.aws.amazon.com/msk/latest/developerguide/msk-working-with-encryption.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/kafka/kafka_cluster_is_public/kafka_cluster_is_public.metadata.json b/prowler/providers/aws/services/kafka/kafka_cluster_is_public/kafka_cluster_is_public.metadata.json new file mode 100644 index 0000000000..1a03ed835e --- /dev/null +++ b/prowler/providers/aws/services/kafka/kafka_cluster_is_public/kafka_cluster_is_public.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "kafka_cluster_is_public", + "CheckTitle": "Kafka Cluster Exposed to the Public", + "CheckType": [], + "ServiceName": "kafka", + "SubServiceName": "cluster", + "ResourceIdTemplate": "arn:partition:kafka:region:account-id:cluster", + "Severity": "high", + "ResourceType": "AwsMskCluster", + "Description": "The Kafka cluster is publicly accessible, which can expose sensitive data and increase the attack surface.", + "Risk": "Exposing the Kafka cluster to the public can lead to unauthorized access, data breaches, and potential security threats.", + "RelatedUrl": "https://docs.aws.amazon.com/msk/latest/developerguide/client-access.html", + "Remediation": { + "Code": { + "CLI": "aws kafka update-connectivity --cluster-arn cluster_arn --current-version kafka_version --connectivity-info '{\"PublicAccess\": {\"Type\": \"DISABLED\"}}'", + "NativeIaC": "", + "Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/MSK/public-access-msk-cluster.html", + "Terraform": "" + }, + "Recommendation": { + "Text": "It is recommended to restrict access to the Kafka cluster to only authorized entities. Enable encryption for data in transit and at rest to protect sensitive information.", + "Url": "https://docs.aws.amazon.com/msk/latest/developerguide/public-access.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/kafka/kafka_cluster_mutual_tls_authentication_enabled/kafka_cluster_mutual_tls_authentication_enabled.metadata.json b/prowler/providers/aws/services/kafka/kafka_cluster_mutual_tls_authentication_enabled/kafka_cluster_mutual_tls_authentication_enabled.metadata.json new file mode 100644 index 0000000000..5f995fde9b --- /dev/null +++ b/prowler/providers/aws/services/kafka/kafka_cluster_mutual_tls_authentication_enabled/kafka_cluster_mutual_tls_authentication_enabled.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "kafka_cluster_mutual_tls_authentication_enabled", + "CheckTitle": "Ensure Mutual TLS Authentication is Enabled for Kafka Cluster", + "CheckType": [], + "ServiceName": "kafka", + "SubServiceName": "cluster", + "ResourceIdTemplate": "arn:partition:kafka:region:account-id:cluster", + "Severity": "medium", + "ResourceType": "AwsMskCluster", + "Description": "Mutual TLS Authentication ensures that both the client and the server are authenticated, providing an additional layer of security for communication within the Kafka cluster.", + "Risk": "Without Mutual TLS Authentication, the cluster is vulnerable to man-in-the-middle attacks, and unauthorized clients may be able to access the cluster.", + "RelatedUrl": "https://docs.aws.amazon.com/msk/latest/developerguide/msk-authentication.html", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/MSK/enable-mutual-tls-authentication-for-kafka-clients.html", + "Terraform": "" + }, + "Recommendation": { + "Text": "It is recommended to enable Mutual TLS Authentication for your Kafka cluster to ensure secure communication between clients and brokers.", + "Url": "https://docs.aws.amazon.com/msk/latest/developerguide/msk-update-security.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/kafka/kafka_cluster_unrestricted_access_disabled/kafka_cluster_unrestricted_access_disabled.metadata.json b/prowler/providers/aws/services/kafka/kafka_cluster_unrestricted_access_disabled/kafka_cluster_unrestricted_access_disabled.metadata.json new file mode 100644 index 0000000000..bbe59cc8c1 --- /dev/null +++ b/prowler/providers/aws/services/kafka/kafka_cluster_unrestricted_access_disabled/kafka_cluster_unrestricted_access_disabled.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "kafka_cluster_unrestricted_access_disabled", + "CheckTitle": "Ensure Kafka Cluster has unrestricted access disabled", + "CheckType": [], + "ServiceName": "kafka", + "SubServiceName": "cluster", + "ResourceIdTemplate": "arn:partition:kafka:region:account-id:cluster", + "Severity": "high", + "ResourceType": "AwsMskCluster", + "Description": "Kafka Clusters should not have unrestricted access enabled. Unrestricted access allows anyone to access the Kafka Cluster without any authentication. It is recommended to disable unrestricted access to prevent unauthorized access to the Kafka Cluster.", + "Risk": "Unrestricted access to Kafka Clusters can lead to unauthorized access to the cluster and its data. It is recommended to restrict access to Kafka Clusters to only authorized entities.", + "RelatedUrl": "https://docs.aws.amazon.com/msk/latest/developerguide/msk-configure-security.html", + "Remediation": { + "Code": { + "CLI": "aws kafka update-security --region region_name --cluster-arn cluster_arn --current-version kafka_version_of_cluster --client-authentication 'Unauthenticated={Enabled=false}'", + "NativeIaC": "", + "Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/MSK/unrestricted-access-to-brokers.html", + "Terraform": "" + }, + "Recommendation": { + "Text": "It is recommended to restrict access to Kafka Clusters to only authorized entities. Ensure that the Kafka Cluster's security settings are properly configured to prevent unauthorized access.", + "Url": "https://docs.aws.amazon.com/msk/latest/developerguide/security.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/kafka/kafka_cluster_uses_latest_version/kafka_cluster_uses_latest_version.metadata.json b/prowler/providers/aws/services/kafka/kafka_cluster_uses_latest_version/kafka_cluster_uses_latest_version.metadata.json new file mode 100644 index 0000000000..37f9accdd2 --- /dev/null +++ b/prowler/providers/aws/services/kafka/kafka_cluster_uses_latest_version/kafka_cluster_uses_latest_version.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "kafka_cluster_uses_latest_version", + "CheckTitle": "MSK cluster should use the latest version.", + "CheckType": [ + "Infrastructure Security" + ], + "ServiceName": "kafka", + "SubServiceName": "cluster", + "ResourceIdTemplate": "arn:partition:kafka:region:account-id:cluster", + "Severity": "medium", + "ResourceType": "AwsMskCluster", + "Description": "Ensure that your Amazon Managed Streaming for Apache Kafka (MSK) cluster is using the latest version to benefit from the latest security features, bug fixes, and performance improvements.", + "Risk": "Running an outdated version of Amazon MSK may expose your cluster to security vulnerabilities, bugs, and performance issues.", + "RelatedUrl": "https://docs.aws.amazon.com/lightsail/latest/userguide/amazon-lightsail-databases.html", + "Remediation": { + "Code": { + "CLI": "aws kafka update-cluster-configuration --cluster-arn --current-version --target-version ", + "NativeIaC": "", + "Other": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/MSK/enable-apache-kafka-latest-security-features.html", + "Terraform": "" + }, + "Recommendation": { + "Text": "To upgrade your Amazon MSK cluster to the latest version, use the AWS Management Console, AWS CLI, or SDKs to update the cluster configuration. For more information, refer to the official Amazon MSK documentation.", + "Url": "https://docs.aws.amazon.com/msk/latest/developerguide/version-support.html#version-upgrades" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/lightsail/lightsail_database_public/lightsail_database_public.metadata.json b/prowler/providers/aws/services/lightsail/lightsail_database_public/lightsail_database_public.metadata.json new file mode 100644 index 0000000000..e01e15ceec --- /dev/null +++ b/prowler/providers/aws/services/lightsail/lightsail_database_public/lightsail_database_public.metadata.json @@ -0,0 +1,34 @@ +{ + "Provider": "aws", + "CheckID": "lightsail_database_public", + "CheckTitle": "Check if the database has the public mode.", + "CheckType": [ + "Infrastructure Security" + ], + "ServiceName": "lightsail", + "SubServiceName": "database", + "ResourceIdTemplate": "arn:partition:lightsail:region:account:RelationalDatabase/database-id", + "Severity": "high", + "ResourceType": "Other", + "Description": "The database is in public mode, which means it is exposed to the internet.", + "Risk": "This can lead to unauthorized access to the database.", + "RelatedUrl": "https://docs.aws.amazon.com/lightsail/latest/userguide/amazon-lightsail-databases.html", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "Change the database to private mode.", + "Url": "" + } + }, + "Categories": [ + "internet-exposed" + ], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/lightsail/lightsail_instance_automated_snapshots/lightsail_instance_automated_snapshots.metadata.json b/prowler/providers/aws/services/lightsail/lightsail_instance_automated_snapshots/lightsail_instance_automated_snapshots.metadata.json new file mode 100644 index 0000000000..fb25928b31 --- /dev/null +++ b/prowler/providers/aws/services/lightsail/lightsail_instance_automated_snapshots/lightsail_instance_automated_snapshots.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "lightsail_instance_automated_snapshots", + "CheckTitle": "Check if instances have automated snapshots enabled", + "CheckType": [ + "Infrastructure Security" + ], + "ServiceName": "lightsail", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:lightsail:region:account:Instance/instance-id", + "Severity": "medium", + "ResourceType": "Other", + "Description": "Amazon Lightsail automatically creates daily snapshots of your instances. These snapshots are used for automatic backups and are stored at no additional cost. It is recommended to enable automatic snapshots for your Lightsail instances.", + "Risk": "If automatic snapshots are not enabled, you may lose data in case of accidental deletion or corruption.", + "RelatedUrl": "https://docs.aws.amazon.com/lightsail/latest/userguide/amazon-lightsail-configuring-automatic-snapshots.html", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "The automatic snapshot is a best practice to protect your data. It is recommended to enable automatic snapshots for your Lightsail instances.", + "Url": "https://docs.aws.amazon.com/lightsail/latest/userguide/amazon-lightsail-changing-automatic-snapshot-time.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/lightsail/lightsail_instance_public/lightsail_instance_public.metadata.json b/prowler/providers/aws/services/lightsail/lightsail_instance_public/lightsail_instance_public.metadata.json new file mode 100644 index 0000000000..24e4933a85 --- /dev/null +++ b/prowler/providers/aws/services/lightsail/lightsail_instance_public/lightsail_instance_public.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "lightsail_instance_public", + "CheckTitle": "Ensure that Lightsail instances are not publicly accessible", + "CheckType": [], + "ServiceName": "lightsail", + "SubServiceName": "instance", + "ResourceIdTemplate": "arn:partition:lightsail:region:account:Instance/instance-id", + "Severity": "high", + "ResourceType": "Other", + "Description": "Ensure that Lightsail instances are not publicly accessible", + "Risk": "If an instance is publicly accessible, it can be accessed by anyone on the internet. This can lead to unauthorized access to the instance and its data.", + "RelatedUrl": "https://docs.aws.amazon.com/lightsail/latest/userguide/understanding-public-ip-and-private-ip-addresses-in-amazon-lightsail.html#ipv4-addresses", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "We recommend that you disable public access to the instance and use a VPN or a bastion host to access the instance securely.", + "Url": "" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/lightsail/lightsail_static_ip_unused/lightsail_static_ip_unused.metadata.json b/prowler/providers/aws/services/lightsail/lightsail_static_ip_unused/lightsail_static_ip_unused.metadata.json new file mode 100644 index 0000000000..7c708eda18 --- /dev/null +++ b/prowler/providers/aws/services/lightsail/lightsail_static_ip_unused/lightsail_static_ip_unused.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "lightsail_static_ip_unused", + "CheckTitle": "Static IP are allocated but not attached to any instance", + "CheckType": [], + "ServiceName": "lightsail", + "SubServiceName": "static_ip", + "ResourceIdTemplate": "arn:partition:lightsail:region:account:static-ip/static-ip-id", + "Severity": "low", + "ResourceType": "Other", + "Description": "Static IPs that are allocated but not attached to any instance are wasting resources and may pose a security risk if left unused for extended periods.", + "Risk": "Unattached static IPs can be potential entry points for unauthorized access or DDoS attacks if not properly secured.", + "RelatedUrl": "https://docs.aws.amazon.com/lightsail/latest/userguide/understanding-public-ip-and-private-ip-addresses-in-amazon-lightsail.html", + "Remediation": { + "Code": { + "CLI": "aws lightsail release-static-ip --static-ip-name static-ip-name", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "Release or attach any unused static IPs to ensure efficient resource utilization and minimize potential security risks.", + "Url": "" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/macie/macie_is_enabled/macie_is_enabled.metadata.json b/prowler/providers/aws/services/macie/macie_is_enabled/macie_is_enabled.metadata.json index 411e635efb..034a9e0f8e 100644 --- a/prowler/providers/aws/services/macie/macie_is_enabled/macie_is_enabled.metadata.json +++ b/prowler/providers/aws/services/macie/macie_is_enabled/macie_is_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id", "Severity": "low", - "ResourceType": "AwsMacieSession", + "ResourceType": "Other", "Description": "Check if Amazon Macie is enabled.", "Risk": "Amazon Macie is a fully managed data security and data privacy service that uses machine learning and pattern matching to help you discover, monitor and protect your sensitive data in AWS.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/neptune/neptune_cluster_public_snapshot/neptune_cluster_public_snapshot.metadata.json b/prowler/providers/aws/services/neptune/neptune_cluster_public_snapshot/neptune_cluster_public_snapshot.metadata.json new file mode 100644 index 0000000000..5a3468e439 --- /dev/null +++ b/prowler/providers/aws/services/neptune/neptune_cluster_public_snapshot/neptune_cluster_public_snapshot.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "neptune_cluster_public_snapshot", + "CheckTitle": "Check if NeptuneDB manual cluster snapshot is public.", + "CheckType": [], + "ServiceName": "neptune", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "critical", + "ResourceType": "AwsRdsDbClusterSnapshot", + "Description": "Check if NeptuneDB manual cluster snapshot is public.", + "Risk": "If you share an unencrypted manual snapshot as public, the snapshot is available to all AWS accounts. Public snapshots may result in unintended data exposure.", + "RelatedUrl": "https://docs.aws.amazon.com/neptune/latest/userguide/security-considerations.html", + "Remediation": { + "Code": { + "CLI": "aws neptune modify-db-cluster-snapshot-attribute --db-cluster-snapshot-identifier --attribute-name restore --values-to-remove all", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-3", + "Terraform": "" + }, + "Recommendation": { + "Text": "To remove public access from a manual snapshot, follow the AWS documentation on NeptuneDB snapshots.", + "Url": "https://docs.aws.amazon.com/neptune/latest/userguide/security-considerations.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/neptune/neptune_cluster_storage_encrypted/neptune_cluster_storage_encrypted.metadata.json b/prowler/providers/aws/services/neptune/neptune_cluster_storage_encrypted/neptune_cluster_storage_encrypted.metadata.json new file mode 100644 index 0000000000..71e238dfb8 --- /dev/null +++ b/prowler/providers/aws/services/neptune/neptune_cluster_storage_encrypted/neptune_cluster_storage_encrypted.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "neptune_cluster_storage_encrypted", + "CheckTitle": "Check if Neptune Clusters storage is encrypted at rest.", + "CheckType": [], + "ServiceName": "neptune", + "SubServiceName": "", + "ResourceIdTemplate": "arn:aws:rds:region:account-id:db-cluster", + "Severity": "high", + "ResourceType": "AwsRdsDbCluster", + "Description": "Check if Neptune Clusters storage is encrypted at rest.", + "Risk": "Ensure that the data available on your Amazon Neptune database instances is encrypted in order to meet regulatory requirements and prevent unauthorized users from accessing sensitive information. Encryption provides an additional layer of protection by securing your Neptune databases from unauthorized access to the underlying storage. Neptune is a fast, scalable, highly secure and fully-managed graph database service that makes it easy to build and run applications that work with deeply connected datasets.", + "RelatedUrl": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-1", + "Remediation": { + "Code": { + "CLI": "https://docs.prowler.com/checks/aws/general-policies/general_18/", + "NativeIaC": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/Neptune/encryption-enabled.html", + "Other": "", + "Terraform": "https://docs.prowler.com/checks/aws/general-policies/general_18/" + }, + "Recommendation": { + "Text": "Enable Encryption. Use a CMK where possible. It will provide additional management and privacy benefits.", + "Url": "https://docs.aws.amazon.com/securityhub/latest/userguide/neptune-controls.html#neptune-1" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/neptune/neptune_cluster_uses_public_subnet/neptune_cluster_uses_public_subnet.metadata.json b/prowler/providers/aws/services/neptune/neptune_cluster_uses_public_subnet/neptune_cluster_uses_public_subnet.metadata.json index 86f9cc0bb7..b13e2111ce 100644 --- a/prowler/providers/aws/services/neptune/neptune_cluster_uses_public_subnet/neptune_cluster_uses_public_subnet.metadata.json +++ b/prowler/providers/aws/services/neptune/neptune_cluster_uses_public_subnet/neptune_cluster_uses_public_subnet.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:rds:::cluster:", "Severity": "medium", - "ResourceType": "AWSNeptuneDBCluster", + "ResourceType": "AwsRdsDbCluster", "Description": "Ensure Neptune Cluster is not using a public subnet", "Risk": "There is a risk of exposing sensitive data if Neptune Cluster uses a public subnet.", "RelatedUrl": "https://docs.aws.amazon.com/neptune/latest/userguide/get-started-vpc.html", diff --git a/prowler/providers/aws/services/networkfirewall/networkfirewall_deletion_protection/networkfirewall_deletion_protection.metadata.json b/prowler/providers/aws/services/networkfirewall/networkfirewall_deletion_protection/networkfirewall_deletion_protection.metadata.json new file mode 100644 index 0000000000..4346c2ee8d --- /dev/null +++ b/prowler/providers/aws/services/networkfirewall/networkfirewall_deletion_protection/networkfirewall_deletion_protection.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "networkfirewall_deletion_protection", + "CheckTitle": "Ensure that Deletion Protection safety feature is enabled for your Amazon VPC network firewalls.", + "CheckType": [], + "ServiceName": "network-firewall", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:network-firewall::account-id:firewall/firewall-name", + "Severity": "medium", + "ResourceType": "AwsNetworkFirewallFirewall", + "Description": "Ensure that Deletion Protection safety feature is enabled for your Amazon VPC network firewalls in order to protect the firewalls from being accidentally deleted. By default, Deletion Protection is disabled for VPC network firewalls.", + "Risk": "Without a network firewall, it can be difficult to monitor and control traffic within the VPC. This can make it harder to detect and prevent attacks or unauthorized access to resources.", + "RelatedUrl": "https://docs.aws.amazon.com/securityhub/latest/userguide/networkfirewall-controls.html#networkfirewall-9", + "Remediation": { + "Code": { + "CLI": "aws network-firewall update-firewall-delete-protection --region --firewall-name --delete-protection", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "Ensure that Deletion Protection safety feature is enabled for your Amazon VPC network firewalls.", + "Url": "https://docs.aws.amazon.com/securityhub/latest/userguide/networkfirewall-controls.html#networkfirewall-9" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/networkfirewall/networkfirewall_in_all_vpc/networkfirewall_in_all_vpc.metadata.json b/prowler/providers/aws/services/networkfirewall/networkfirewall_in_all_vpc/networkfirewall_in_all_vpc.metadata.json index c627fcf2af..7806387317 100644 --- a/prowler/providers/aws/services/networkfirewall/networkfirewall_in_all_vpc/networkfirewall_in_all_vpc.metadata.json +++ b/prowler/providers/aws/services/networkfirewall/networkfirewall_in_all_vpc/networkfirewall_in_all_vpc.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:network-firewall::account-id:firewall/firewall-name", "Severity": "medium", - "ResourceType": "Other", + "ResourceType": "AwsEc2Vpc", "Description": "Ensure all VPCs have Network Firewall enabled", "Risk": "Without a network firewall, it can be difficult to monitor and control traffic within the VPC. This can make it harder to detect and prevent attacks or unauthorized access to resources.", "RelatedUrl": "https://docs.aws.amazon.com/network-firewall/latest/developerguide/setting-up.html", diff --git a/prowler/providers/aws/services/opensearch/opensearch_service_domains_audit_logging_enabled/opensearch_service_domains_audit_logging_enabled.metadata.json b/prowler/providers/aws/services/opensearch/opensearch_service_domains_audit_logging_enabled/opensearch_service_domains_audit_logging_enabled.metadata.json index ed067062ee..91fba0e956 100644 --- a/prowler/providers/aws/services/opensearch/opensearch_service_domains_audit_logging_enabled/opensearch_service_domains_audit_logging_enabled.metadata.json +++ b/prowler/providers/aws/services/opensearch/opensearch_service_domains_audit_logging_enabled/opensearch_service_domains_audit_logging_enabled.metadata.json @@ -10,7 +10,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "low", - "ResourceType": "AwsOpenSearchDomain", + "ResourceType": "AwsOpenSearchServiceDomain", "Description": "Check if Amazon Elasticsearch/Opensearch Service domains have audit logging enabled", "Risk": "If logs are not enabled, monitoring of service use and threat analysis is not possible.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/opensearch/opensearch_service_domains_cloudwatch_logging_enabled/opensearch_service_domains_cloudwatch_logging_enabled.metadata.json b/prowler/providers/aws/services/opensearch/opensearch_service_domains_cloudwatch_logging_enabled/opensearch_service_domains_cloudwatch_logging_enabled.metadata.json index 0a127e6bb5..fe9f312a34 100644 --- a/prowler/providers/aws/services/opensearch/opensearch_service_domains_cloudwatch_logging_enabled/opensearch_service_domains_cloudwatch_logging_enabled.metadata.json +++ b/prowler/providers/aws/services/opensearch/opensearch_service_domains_cloudwatch_logging_enabled/opensearch_service_domains_cloudwatch_logging_enabled.metadata.json @@ -10,7 +10,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsOpenSearchDomain", + "ResourceType": "AwsOpenSearchServiceDomain", "Description": "Check if Amazon Elasticsearch/Opensearch Service domains have logging enabled", "Risk": "Amazon ES exposes four Elasticsearch/Opensearch logs through Amazon CloudWatch Logs: error logs, search slow logs, index slow logs, and audit logs.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/opensearch/opensearch_service_domains_encryption_at_rest_enabled/opensearch_service_domains_encryption_at_rest_enabled.metadata.json b/prowler/providers/aws/services/opensearch/opensearch_service_domains_encryption_at_rest_enabled/opensearch_service_domains_encryption_at_rest_enabled.metadata.json index 3099f98f41..d8aa1cd206 100644 --- a/prowler/providers/aws/services/opensearch/opensearch_service_domains_encryption_at_rest_enabled/opensearch_service_domains_encryption_at_rest_enabled.metadata.json +++ b/prowler/providers/aws/services/opensearch/opensearch_service_domains_encryption_at_rest_enabled/opensearch_service_domains_encryption_at_rest_enabled.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsOpenSearchDomain", + "ResourceType": "AwsOpenSearchServiceDomain", "Description": "Check if Amazon Elasticsearch/Opensearch Service domains have encryption at-rest enabled", "Risk": "If not enable unauthorized access to your data could risk increases.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/opensearch/opensearch_service_domains_https_communications_enforced/opensearch_service_domains_https_communications_enforced.metadata.json b/prowler/providers/aws/services/opensearch/opensearch_service_domains_https_communications_enforced/opensearch_service_domains_https_communications_enforced.metadata.json index c6478288bc..79f696feac 100644 --- a/prowler/providers/aws/services/opensearch/opensearch_service_domains_https_communications_enforced/opensearch_service_domains_https_communications_enforced.metadata.json +++ b/prowler/providers/aws/services/opensearch/opensearch_service_domains_https_communications_enforced/opensearch_service_domains_https_communications_enforced.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsOpenSearchDomain", + "ResourceType": "AwsOpenSearchServiceDomain", "Description": "Check if Amazon Elasticsearch/Opensearch Service domains have enforce HTTPS enabled", "Risk": "If not enable unauthorized access to your data could risk increases.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/opensearch/opensearch_service_domains_internal_user_database_enabled/opensearch_service_domains_internal_user_database_enabled.metadata.json b/prowler/providers/aws/services/opensearch/opensearch_service_domains_internal_user_database_enabled/opensearch_service_domains_internal_user_database_enabled.metadata.json index a4ec40e05e..2e1b2da9be 100644 --- a/prowler/providers/aws/services/opensearch/opensearch_service_domains_internal_user_database_enabled/opensearch_service_domains_internal_user_database_enabled.metadata.json +++ b/prowler/providers/aws/services/opensearch/opensearch_service_domains_internal_user_database_enabled/opensearch_service_domains_internal_user_database_enabled.metadata.json @@ -10,7 +10,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsOpenSearchDomain", + "ResourceType": "AwsOpenSearchServiceDomain", "Description": "Check if Amazon Elasticsearch/Opensearch Service domains have internal user database enabled", "Risk": "Internal User Database is convenient for demos, for production environment use Federated authentication.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/opensearch/opensearch_service_domains_node_to_node_encryption_enabled/opensearch_service_domains_node_to_node_encryption_enabled.metadata.json b/prowler/providers/aws/services/opensearch/opensearch_service_domains_node_to_node_encryption_enabled/opensearch_service_domains_node_to_node_encryption_enabled.metadata.json index 8085f11d2b..b505352460 100644 --- a/prowler/providers/aws/services/opensearch/opensearch_service_domains_node_to_node_encryption_enabled/opensearch_service_domains_node_to_node_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/opensearch/opensearch_service_domains_node_to_node_encryption_enabled/opensearch_service_domains_node_to_node_encryption_enabled.metadata.json @@ -11,7 +11,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsOpenSearchDomain", + "ResourceType": "AwsOpenSearchServiceDomain", "Description": "Check if Amazon Elasticsearch/Opensearch Service domains have node-to-node encryption enabled", "Risk": "Node-to-node encryption provides an additional layer of security on top of the default features of Amazon ES. This architecture prevents potential attackers from intercepting traffic between Elasticsearch nodes and keeps the cluster secure.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/opensearch/opensearch_service_domains_not_publicly_accessible/opensearch_service_domains_not_publicly_accessible.metadata.json b/prowler/providers/aws/services/opensearch/opensearch_service_domains_not_publicly_accessible/opensearch_service_domains_not_publicly_accessible.metadata.json index 4d6d5263c2..2a71338586 100644 --- a/prowler/providers/aws/services/opensearch/opensearch_service_domains_not_publicly_accessible/opensearch_service_domains_not_publicly_accessible.metadata.json +++ b/prowler/providers/aws/services/opensearch/opensearch_service_domains_not_publicly_accessible/opensearch_service_domains_not_publicly_accessible.metadata.json @@ -10,7 +10,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "critical", - "ResourceType": "AwsOpenSearchDomain", + "ResourceType": "AwsOpenSearchServiceDomain", "Description": "Check if Amazon Opensearch/Elasticsearch domains are set as Public or if it has open policy access", "Risk": "Publicly accessible services could expose sensitive data to bad actors.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/opensearch/opensearch_service_domains_updated_to_the_latest_service_software_version/opensearch_service_domains_updated_to_the_latest_service_software_version.metadata.json b/prowler/providers/aws/services/opensearch/opensearch_service_domains_updated_to_the_latest_service_software_version/opensearch_service_domains_updated_to_the_latest_service_software_version.metadata.json index 6f7a1189d2..ea2b9d705f 100644 --- a/prowler/providers/aws/services/opensearch/opensearch_service_domains_updated_to_the_latest_service_software_version/opensearch_service_domains_updated_to_the_latest_service_software_version.metadata.json +++ b/prowler/providers/aws/services/opensearch/opensearch_service_domains_updated_to_the_latest_service_software_version/opensearch_service_domains_updated_to_the_latest_service_software_version.metadata.json @@ -10,7 +10,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "low", - "ResourceType": "AwsOpenSearchDomain", + "ResourceType": "AwsOpenSearchServiceDomain", "Description": "Check if Amazon Elasticsearch/Opensearch Service domains have updates available", "Risk": "Amazon ES regularly releases system software updates that add features or otherwise improve your domains.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/opensearch/opensearch_service_domains_use_cognito_authentication_for_kibana/opensearch_service_domains_use_cognito_authentication_for_kibana.metadata.json b/prowler/providers/aws/services/opensearch/opensearch_service_domains_use_cognito_authentication_for_kibana/opensearch_service_domains_use_cognito_authentication_for_kibana.metadata.json index 57b47ffe24..dd4eab9f61 100644 --- a/prowler/providers/aws/services/opensearch/opensearch_service_domains_use_cognito_authentication_for_kibana/opensearch_service_domains_use_cognito_authentication_for_kibana.metadata.json +++ b/prowler/providers/aws/services/opensearch/opensearch_service_domains_use_cognito_authentication_for_kibana/opensearch_service_domains_use_cognito_authentication_for_kibana.metadata.json @@ -10,7 +10,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "high", - "ResourceType": "AwsOpenSearchDomain", + "ResourceType": "AwsOpenSearchServiceDomain", "Description": "Check if Amazon Elasticsearch/Opensearch Service domains has Amazon Cognito or SAML authentication for Kibana enabled", "Risk": "Not enabling Amazon Cognito or SAML authentication for Kibana in AWS Elasticsearch/OpenSearch Service domains increases the likelihood of unauthorized access to sensitive data, potentially compromising system integrity.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/rds/rds_cluster_backtrack_enabled/rds_cluster_backtrack_enabled.metadata.json b/prowler/providers/aws/services/rds/rds_cluster_backtrack_enabled/rds_cluster_backtrack_enabled.metadata.json new file mode 100644 index 0000000000..a630b8fd5f --- /dev/null +++ b/prowler/providers/aws/services/rds/rds_cluster_backtrack_enabled/rds_cluster_backtrack_enabled.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "rds_cluster_backtrack_enabled", + "CheckTitle": "Check if RDS Aurora MySQL Clusters have backtrack enabled.", + "CheckType": [], + "ServiceName": "rds", + "SubServiceName": "", + "ResourceIdTemplate": "arn:aws:rds:region:account-id:db-cluster", + "Severity": "medium", + "ResourceType": "AwsRdsDbCluster", + "Description": "Ensure that the Backtrack feature is enabled for your Amazon Aurora (with MySQL compatibility) database clusters in order to backtrack your clusters to a specific time, without using backups. Backtrack is an Amazon RDS feature that allows you to specify the amount of time that an Aurora MySQL database cluster needs to retain change records, in order to have a fast way to recover from user errors, such as dropping the wrong table or deleting the wrong row by moving your MySQL database to a prior point in time without the need to restore from a recent backup.", + "Risk": "Once the Backtrack feature is enabled, Amazon RDS can quickly 'rewind' your Aurora MySQL database cluster to a point in time that you specify. In contrast to the backup and restore method, with Backtrack you can easily undo a destructive action, such as a DELETE query without a WHERE clause, with minimal downtime, you can rewind your Aurora cluster in just few minutes, and you can repeatedly backtrack a database cluster back and forth in time to help determine when a particular data change occurred.", + "RelatedUrl": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-14", + "Remediation": { + "Code": { + "CLI": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/RDS/backtrack.html#", + "NativeIaC": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/RDS/backtrack.html#", + "Other": "", + "Terraform": "https://www.trendmicro.com/cloudoneconformity/knowledge-base/aws/RDS/backtrack.html#" + }, + "Recommendation": { + "Text": "Backups help you to recover more quickly from a security incident. They also strengthens the resilience of your systems. Aurora backtracking reduces the time to recover a database to a point in time. It does not require a database restore to do so. You cannot enable backtracking on an existing cluster. Instead, you can create a clone that has backtracking enabled.", + "Url": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-14" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/rds/rds_cluster_critical_event_subscription/rds_cluster_critical_event_subscription.metadata.json b/prowler/providers/aws/services/rds/rds_cluster_critical_event_subscription/rds_cluster_critical_event_subscription.metadata.json new file mode 100644 index 0000000000..a035222b2e --- /dev/null +++ b/prowler/providers/aws/services/rds/rds_cluster_critical_event_subscription/rds_cluster_critical_event_subscription.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "rds_cluster_critical_event_subscription", + "CheckTitle": "Check if RDS Cluster critical events are subscribed.", + "CheckType": [ + "Software and Configuration Checks, AWS Security Best Practices" + ], + "ServiceName": "rds", + "SubServiceName": "", + "ResourceIdTemplate": "arn:aws:rds:region:account-id:db-cluster", + "Severity": "low", + "ResourceType": "AwsRdsDbCluster", + "Description": "Ensure that Amazon RDS event notification subscriptions are enabled for database cluster events, particularly maintenance and failure.", + "Risk": "Without event subscriptions for critical events, such as maintenance and failures, you may not be aware of issues affecting your RDS clusters, leading to downtime or security vulnerabilities.", + "RelatedUrl": "https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_Events.html", + "Remediation": { + "Code": { + "CLI": "aws rds create-event-subscription --source-type db-cluster --event-categories 'failure' 'maintenance' --sns-topic-arn ", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/rds-controls.html#rds-19", + "Terraform": "" + }, + "Recommendation": { + "Text": "To subscribe to RDS cluster event notifications, see Subscribing to Amazon RDS event notification in the Amazon RDS User Guide.", + "Url": "https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_Events.Subscribing.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/route53/route53_dangling_ip_subdomain_takeover/route53_dangling_ip_subdomain_takeover.metadata.json b/prowler/providers/aws/services/route53/route53_dangling_ip_subdomain_takeover/route53_dangling_ip_subdomain_takeover.metadata.json index fb0e3e5d43..8185b26780 100644 --- a/prowler/providers/aws/services/route53/route53_dangling_ip_subdomain_takeover/route53_dangling_ip_subdomain_takeover.metadata.json +++ b/prowler/providers/aws/services/route53/route53_dangling_ip_subdomain_takeover/route53_dangling_ip_subdomain_takeover.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "", "Severity": "high", - "ResourceType": "AWSRoute53RecordSet", + "ResourceType": "Other", "Description": "Check if Route53 Records contains dangling IPs.", "Risk": "When an ephemeral AWS resource such as an Elastic IP (EIP) is released into the Amazon's Elastic IP pool, an attacker may acquire the EIP resource and effectively control the domain/subdomain associated with that EIP in your Route 53 DNS records.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/route53/route53_domains_privacy_protection_enabled/route53_domains_privacy_protection_enabled.metadata.json b/prowler/providers/aws/services/route53/route53_domains_privacy_protection_enabled/route53_domains_privacy_protection_enabled.metadata.json index 78928f3efb..cf1524157a 100644 --- a/prowler/providers/aws/services/route53/route53_domains_privacy_protection_enabled/route53_domains_privacy_protection_enabled.metadata.json +++ b/prowler/providers/aws/services/route53/route53_domains_privacy_protection_enabled/route53_domains_privacy_protection_enabled.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "", "Severity": "medium", - "ResourceType": "AwsRoute53Domain", + "ResourceType": "Other", "Description": "Enable Privacy Protection for for a Route53 Domain.", "Risk": "Without privacy protection enabled, ones personal information is published to the public WHOIS database.", "RelatedUrl": "https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/domain-privacy-protection.html", diff --git a/prowler/providers/aws/services/route53/route53_domains_transferlock_enabled/route53_domains_transferlock_enabled.metadata.json b/prowler/providers/aws/services/route53/route53_domains_transferlock_enabled/route53_domains_transferlock_enabled.metadata.json index 76942fea27..046dd65060 100644 --- a/prowler/providers/aws/services/route53/route53_domains_transferlock_enabled/route53_domains_transferlock_enabled.metadata.json +++ b/prowler/providers/aws/services/route53/route53_domains_transferlock_enabled/route53_domains_transferlock_enabled.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "", "Severity": "medium", - "ResourceType": "AwsRoute53Domain", + "ResourceType": "Other", "Description": "Enable Transfer Lock for a Route53 Domain.", "Risk": "Without transfer lock enabled, a domain name could be incorrectly moved to a new registrar.", "RelatedUrl": "https://docs.aws.amazon.com/Route53/latest/DeveloperGuide/domain-lock.html", diff --git a/prowler/providers/aws/services/s3/s3_account_level_public_access_blocks/s3_account_level_public_access_blocks.metadata.json b/prowler/providers/aws/services/s3/s3_account_level_public_access_blocks/s3_account_level_public_access_blocks.metadata.json index 4aa5332b1b..96745af0d0 100644 --- a/prowler/providers/aws/services/s3/s3_account_level_public_access_blocks/s3_account_level_public_access_blocks.metadata.json +++ b/prowler/providers/aws/services/s3/s3_account_level_public_access_blocks/s3_account_level_public_access_blocks.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:s3:::bucket_name", "Severity": "high", - "ResourceType": "AwsS3Bucket", + "ResourceType": "AwsS3AccountPublicAccessBlock", "Description": "Check S3 Account Level Public Access Block.", "Risk": "Public access policies may be applied to sensitive data buckets.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/sagemaker/sagemaker_models_network_isolation_enabled/sagemaker_models_network_isolation_enabled.metadata.json b/prowler/providers/aws/services/sagemaker/sagemaker_models_network_isolation_enabled/sagemaker_models_network_isolation_enabled.metadata.json index ca8608f54d..fdb7175757 100644 --- a/prowler/providers/aws/services/sagemaker/sagemaker_models_network_isolation_enabled/sagemaker_models_network_isolation_enabled.metadata.json +++ b/prowler/providers/aws/services/sagemaker/sagemaker_models_network_isolation_enabled/sagemaker_models_network_isolation_enabled.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:sagemaker:region:account-id:model", "Severity": "medium", - "ResourceType": "AwsSageMakerModel", + "ResourceType": "Other", "Description": "Check if Amazon SageMaker Models have network isolation enabled", "Risk": "This could provide an avenue for unauthorized access to your data.", "RelatedUrl": "https://docs.aws.amazon.com/sagemaker/latest/dg/studio-notebooks-and-internet-access.html", diff --git a/prowler/providers/aws/services/sagemaker/sagemaker_models_vpc_settings_configured/sagemaker_models_vpc_settings_configured.metadata.json b/prowler/providers/aws/services/sagemaker/sagemaker_models_vpc_settings_configured/sagemaker_models_vpc_settings_configured.metadata.json index 9e1b3ae591..4e932ba4ef 100644 --- a/prowler/providers/aws/services/sagemaker/sagemaker_models_vpc_settings_configured/sagemaker_models_vpc_settings_configured.metadata.json +++ b/prowler/providers/aws/services/sagemaker/sagemaker_models_vpc_settings_configured/sagemaker_models_vpc_settings_configured.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:sagemaker:region:account-id:model", "Severity": "medium", - "ResourceType": "AwsSageMakerModel", + "ResourceType": "Other", "Description": "Check if Amazon SageMaker Models have VPC settings configured", "Risk": "This could provide an avenue for unauthorized access to your data.", "RelatedUrl": "https://docs.aws.amazon.com/sagemaker/latest/dg/studio-notebooks-and-internet-access.html", diff --git a/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_intercontainer_encryption_enabled/sagemaker_training_jobs_intercontainer_encryption_enabled.metadata.json b/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_intercontainer_encryption_enabled/sagemaker_training_jobs_intercontainer_encryption_enabled.metadata.json index fbb9ca4d42..7e3d6f30ed 100644 --- a/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_intercontainer_encryption_enabled/sagemaker_training_jobs_intercontainer_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_intercontainer_encryption_enabled/sagemaker_training_jobs_intercontainer_encryption_enabled.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:sagemaker:region:account-id:training-job", "Severity": "medium", - "ResourceType": "AwsSageMakerTrainingJob", + "ResourceType": "Other", "Description": "Check if Amazon SageMaker Training jobs have intercontainer encryption enabled", "Risk": "If not restricted unintended access could happen.", "RelatedUrl": "https://docs.aws.amazon.com/sagemaker/latest/dg/interface-vpc-endpoint.html", diff --git a/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_network_isolation_enabled/sagemaker_training_jobs_network_isolation_enabled.metadata.json b/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_network_isolation_enabled/sagemaker_training_jobs_network_isolation_enabled.metadata.json index f3a07bba23..7f1c2cd943 100644 --- a/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_network_isolation_enabled/sagemaker_training_jobs_network_isolation_enabled.metadata.json +++ b/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_network_isolation_enabled/sagemaker_training_jobs_network_isolation_enabled.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:sagemaker:region:account-id:training-job", "Severity": "medium", - "ResourceType": "AwsSageMakerTrainingJob", + "ResourceType": "Other", "Description": "Check if Amazon SageMaker Training jobs have network isolation enabled", "Risk": "This could provide an avenue for unauthorized access to your data.", "RelatedUrl": "https://docs.aws.amazon.com/sagemaker/latest/dg/interface-vpc-endpoint.html", diff --git a/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_volume_and_output_encryption_enabled/sagemaker_training_jobs_volume_and_output_encryption_enabled.metadata.json b/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_volume_and_output_encryption_enabled/sagemaker_training_jobs_volume_and_output_encryption_enabled.metadata.json index aa17f24e18..03bbb7e573 100644 --- a/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_volume_and_output_encryption_enabled/sagemaker_training_jobs_volume_and_output_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_volume_and_output_encryption_enabled/sagemaker_training_jobs_volume_and_output_encryption_enabled.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:sagemaker:region:account-id:training-job", "Severity": "medium", - "ResourceType": "AwsSageMakerTrainingJob", + "ResourceType": "Other", "Description": "Check if Amazon SageMaker Training jobs have volume and output with KMS encryption enabled", "Risk": "Data exfiltration could happen if information is not protected. KMS keys provide additional security level to IAM policies.", "RelatedUrl": "https://docs.aws.amazon.com/sagemaker/latest/dg/key-management.html", diff --git a/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_vpc_settings_configured/sagemaker_training_jobs_vpc_settings_configured.metadata.json b/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_vpc_settings_configured/sagemaker_training_jobs_vpc_settings_configured.metadata.json index 9d4b4995c3..4366126d38 100644 --- a/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_vpc_settings_configured/sagemaker_training_jobs_vpc_settings_configured.metadata.json +++ b/prowler/providers/aws/services/sagemaker/sagemaker_training_jobs_vpc_settings_configured/sagemaker_training_jobs_vpc_settings_configured.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:sagemaker:region:account-id:training-job", "Severity": "medium", - "ResourceType": "AwsSageMakerTrainingJob", + "ResourceType": "Other", "Description": "Check if Amazon SageMaker Training job have VPC settings configured.", "Risk": "This could provide an avenue for unauthorized access to your data.", "RelatedUrl": "https://docs.aws.amazon.com/sagemaker/latest/dg/interface-vpc-endpoint.html", diff --git a/prowler/providers/aws/services/securityhub/securityhub_enabled/securityhub_enabled.metadata.json b/prowler/providers/aws/services/securityhub/securityhub_enabled/securityhub_enabled.metadata.json index 00bcea51fa..87a279ce6d 100644 --- a/prowler/providers/aws/services/securityhub/securityhub_enabled/securityhub_enabled.metadata.json +++ b/prowler/providers/aws/services/securityhub/securityhub_enabled/securityhub_enabled.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:partition:securityhub:region:account-id:hub/hub-id", "Severity": "medium", - "ResourceType": "AwsSecurityHubHub", + "ResourceType": "Other", "Description": "Check if Security Hub is enabled and its standard subscriptions.", "Risk": "AWS Security Hub gives you a comprehensive view of your security alerts and security posture across your AWS accounts.", "RelatedUrl": "https://docs.aws.amazon.com/securityhub/latest/userguide/securityhub-standards-enable-disable.html", diff --git a/prowler/providers/aws/services/shield/shield_advanced_protection_in_classic_load_balancers/shield_advanced_protection_in_classic_load_balancers.metadata.json b/prowler/providers/aws/services/shield/shield_advanced_protection_in_classic_load_balancers/shield_advanced_protection_in_classic_load_balancers.metadata.json index b6ab21f618..20a31de19a 100644 --- a/prowler/providers/aws/services/shield/shield_advanced_protection_in_classic_load_balancers/shield_advanced_protection_in_classic_load_balancers.metadata.json +++ b/prowler/providers/aws/services/shield/shield_advanced_protection_in_classic_load_balancers/shield_advanced_protection_in_classic_load_balancers.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "", "Severity": "medium", - "ResourceType": "AwsElasticLoadBalancingLoadBalancer", + "ResourceType": "AwsElbLoadBalancer", "Description": "Check if Classic Load Balancers are protected by AWS Shield Advanced.", "Risk": "AWS Shield Advanced provides expanded DDoS attack protection for your resources.", "RelatedUrl": "https://docs.aws.amazon.com/waf/latest/developerguide/configure-new-protection.html", diff --git a/prowler/providers/aws/services/shield/shield_advanced_protection_in_global_accelerators/shield_advanced_protection_in_global_accelerators.metadata.json b/prowler/providers/aws/services/shield/shield_advanced_protection_in_global_accelerators/shield_advanced_protection_in_global_accelerators.metadata.json index 19c07e8574..48c1225b52 100644 --- a/prowler/providers/aws/services/shield/shield_advanced_protection_in_global_accelerators/shield_advanced_protection_in_global_accelerators.metadata.json +++ b/prowler/providers/aws/services/shield/shield_advanced_protection_in_global_accelerators/shield_advanced_protection_in_global_accelerators.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "", "Severity": "medium", - "ResourceType": "AwsGlobalAccelerator", + "ResourceType": "Other", "Description": "Check if Global Accelerators are protected by AWS Shield Advanced.", "Risk": "AWS Shield Advanced provides expanded DDoS attack protection for your resources.", "RelatedUrl": "https://docs.aws.amazon.com/waf/latest/developerguide/configure-new-protection.html", diff --git a/prowler/providers/aws/services/shield/shield_advanced_protection_in_internet_facing_load_balancers/shield_advanced_protection_in_internet_facing_load_balancers.metadata.json b/prowler/providers/aws/services/shield/shield_advanced_protection_in_internet_facing_load_balancers/shield_advanced_protection_in_internet_facing_load_balancers.metadata.json index 914fc88044..f31e8ef29a 100644 --- a/prowler/providers/aws/services/shield/shield_advanced_protection_in_internet_facing_load_balancers/shield_advanced_protection_in_internet_facing_load_balancers.metadata.json +++ b/prowler/providers/aws/services/shield/shield_advanced_protection_in_internet_facing_load_balancers/shield_advanced_protection_in_internet_facing_load_balancers.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "", "Severity": "medium", - "ResourceType": "AwsElasticLoadBalancingV2LoadBalancer", + "ResourceType": "AwsElbv2LoadBalancer", "Description": "Check if internet-facing Application Load Balancers are protected by AWS Shield Advanced.", "Risk": "AWS Shield Advanced provides expanded DDoS attack protection for your resources.", "RelatedUrl": "https://docs.aws.amazon.com/waf/latest/developerguide/configure-new-protection.html", diff --git a/prowler/providers/aws/services/shield/shield_advanced_protection_in_route53_hosted_zones/shield_advanced_protection_in_route53_hosted_zones.metadata.json b/prowler/providers/aws/services/shield/shield_advanced_protection_in_route53_hosted_zones/shield_advanced_protection_in_route53_hosted_zones.metadata.json index 27f6b2a3a0..8fbf144d42 100644 --- a/prowler/providers/aws/services/shield/shield_advanced_protection_in_route53_hosted_zones/shield_advanced_protection_in_route53_hosted_zones.metadata.json +++ b/prowler/providers/aws/services/shield/shield_advanced_protection_in_route53_hosted_zones/shield_advanced_protection_in_route53_hosted_zones.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "", "Severity": "medium", - "ResourceType": "AwsRoute53Domain", + "ResourceType": "AwsRoute53HostedZone", "Description": "Check if Route53 hosted zones are protected by AWS Shield Advanced.", "Risk": "AWS Shield Advanced provides expanded DDoS attack protection for your resources.", "RelatedUrl": "https://docs.aws.amazon.com/waf/latest/developerguide/configure-new-protection.html", diff --git a/prowler/providers/aws/services/sns/sns_subscription_not_using_http_endpoints/sns_subscription_not_using_http_endpoints.metadata.json b/prowler/providers/aws/services/sns/sns_subscription_not_using_http_endpoints/sns_subscription_not_using_http_endpoints.metadata.json new file mode 100644 index 0000000000..ecf858163d --- /dev/null +++ b/prowler/providers/aws/services/sns/sns_subscription_not_using_http_endpoints/sns_subscription_not_using_http_endpoints.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "sns_subscription_not_using_http_endpoints", + "CheckTitle": "Ensure there are no SNS subscriptions using HTTP endpoints", + "CheckType": [], + "ServiceName": "sns", + "SubServiceName": "", + "ResourceIdTemplate": "arn:aws:sns:region:account-id:topic", + "Severity": "high", + "ResourceType": "AwsSnsTopic", + "Description": "Ensure there are no SNS subscriptions using HTTP endpoints", + "Risk": "When you use HTTPS, messages are automatically encrypted during transit, even if the SNS topic itself isn't encrypted. Without HTTPS, a network-based attacker can eavesdrop on network traffic or manipulate it using an attack such as man-in-the-middle.", + "RelatedUrl": "https://docs.aws.amazon.com/sns/latest/dg/sns-security-best-practices.html#enforce-encryption-data-in-transit", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "", + "Terraform": "" + }, + "Recommendation": { + "Text": "To enforce only encrypted connections over HTTPS, add the aws:SecureTransport condition in the IAM policy that's attached to unencrypted SNS topics. This forces message publishers to use HTTPS instead of HTTP", + "Url": "https://docs.aws.amazon.com/sns/latest/dg/sns-security-best-practices.html#enforce-encryption-data-in-transit" + } + }, + "Categories": [ + "encryption" + ], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/ssm/ssm_managed_compliant_patching/ssm_managed_compliant_patching.metadata.json b/prowler/providers/aws/services/ssm/ssm_managed_compliant_patching/ssm_managed_compliant_patching.metadata.json index 38f33ebb15..a6c6b037d5 100644 --- a/prowler/providers/aws/services/ssm/ssm_managed_compliant_patching/ssm_managed_compliant_patching.metadata.json +++ b/prowler/providers/aws/services/ssm/ssm_managed_compliant_patching/ssm_managed_compliant_patching.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:ec2:region:account-id:instance/instance-id", "Severity": "high", - "ResourceType": "AwsEc2Instance", + "ResourceType": "AwsSsmPatchCompliance", "Description": "Check if EC2 instances managed by Systems Manager are compliant with patching requirements.", "Risk": "Without the most recent security patches your system is potentially vulnerable to cyberattacks. Even the best-designed software can not anticipate every future threat to cybersecurity. Poor patch management can leave an organizations data exposed subjecting them to malware and ransomware attacks.", "RelatedUrl": "https://docs.aws.amazon.com/systems-manager/latest/userguide/patch-compliance-identify.html", diff --git a/prowler/providers/aws/services/storagegateway/storagegateway_fileshare_encryption_enabled/storagegateway_fileshare_encryption_enabled.metadata.json b/prowler/providers/aws/services/storagegateway/storagegateway_fileshare_encryption_enabled/storagegateway_fileshare_encryption_enabled.metadata.json new file mode 100644 index 0000000000..1d4409704e --- /dev/null +++ b/prowler/providers/aws/services/storagegateway/storagegateway_fileshare_encryption_enabled/storagegateway_fileshare_encryption_enabled.metadata.json @@ -0,0 +1,32 @@ +{ + "Provider": "aws", + "CheckID": "storagegateway_fileshare_encryption_enabled", + "CheckTitle": "Check if AWS StorageGateway File Shares are encrypted with KMS CMK.", + "CheckType": [ + "Security" + ], + "ServiceName": "storagegateway", + "SubServiceName": "filegateway", + "ResourceIdTemplate": "arn:aws:storagegateway:region:account-id:share", + "Severity": "low", + "ResourceType": "Other", + "Description": "Ensure that Amazon Storage Gateway service is using AWS KMS Customer Master Keys (CMKs) instead of AWS managed-keys (i.e. default keys) for file share data encryption, in order to have a fine-grained control over data-at-rest encryption/decryption process and meet compliance requirements. An AWS Storage Gateway file share is a file system mount point backed by Amazon S3 cloud storage.", + "Risk": "This could provide an avenue for unauthorized access to your data by not having fine-grained control over data-at-rest encryption/decryption process and meet compliance requirements.", + "RelatedUrl": "https://docs.aws.amazon.com/filegateway/latest/files3/encrypt-objects-stored-by-file-gateway-in-amazon-s3.html", + "Remediation": { + "Code": { + "CLI": "aws storagegateway update-nfs-file-share --region us-east-1 --file-share-arn arn:aws:storagegateway:us-east-1:123456789012:share/share-abcd1234 --kms-encrypted --kms-key arn:aws:kms:us-east-1:123456789012:key/abcdabcd-1234-1234-1234-abcdabcdabcd", + "NativeIaC": "", + "Other": "https://www.trendmicro.com/cloudoneconformity-staging/knowledge-base/aws/StorageGateway/file-shares-encrypted-with-cmk.html#", + "Terraform": "" + }, + "Recommendation": { + "Text": "Ensure that Amazon Storage Gateway service is using AWS KMS Customer Master Keys (CMKs).", + "Url": "https://docs.aws.amazon.com/filegateway/latest/files3/encrypt-objects-stored-by-file-gateway-in-amazon-s3.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/vpc/vpc_endpoint_connections_trust_boundaries/vpc_endpoint_connections_trust_boundaries.metadata.json b/prowler/providers/aws/services/vpc/vpc_endpoint_connections_trust_boundaries/vpc_endpoint_connections_trust_boundaries.metadata.json index 18c8c12945..23bee8a441 100644 --- a/prowler/providers/aws/services/vpc/vpc_endpoint_connections_trust_boundaries/vpc_endpoint_connections_trust_boundaries.metadata.json +++ b/prowler/providers/aws/services/vpc/vpc_endpoint_connections_trust_boundaries/vpc_endpoint_connections_trust_boundaries.metadata.json @@ -9,7 +9,7 @@ "SubServiceName": "endpoint", "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", "Severity": "medium", - "ResourceType": "AwsEc2Vpc", + "ResourceType": "AwsEc2VpcEndpointService", "Description": "Find trust boundaries in VPC endpoint connections.", "Risk": "Account VPC could be linked to other accounts.", "RelatedUrl": "", diff --git a/prowler/providers/aws/services/vpc/vpc_endpoint_for_ec2_enabled/vpc_endpoint_for_ec2_enabled.metadata.json b/prowler/providers/aws/services/vpc/vpc_endpoint_for_ec2_enabled/vpc_endpoint_for_ec2_enabled.metadata.json new file mode 100644 index 0000000000..2a12db3c4e --- /dev/null +++ b/prowler/providers/aws/services/vpc/vpc_endpoint_for_ec2_enabled/vpc_endpoint_for_ec2_enabled.metadata.json @@ -0,0 +1,30 @@ +{ + "Provider": "aws", + "CheckID": "vpc_endpoint_for_ec2_enabled", + "CheckTitle": "Amazon EC2 should be configured to use VPC endpoints that are created for the Amazon EC2 service.", + "CheckType": [], + "ServiceName": "ec2", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:resource-id", + "Severity": "medium", + "ResourceType": "AwsEc2VpcEndpointService", + "Description": "Ensure that a service endpoint for Amazon EC2 is created for each VPC. The check fails if a VPC does not have a VPC endpoint created for the Amazon EC2 service.", + "Risk": "Without VPC endpoints, network traffic between your VPC and Amazon EC2 may traverse the public internet, increasing the risk of unintended access or data exposure.", + "RelatedUrl": "https://docs.aws.amazon.com/config/latest/developerguide/service-vpc-endpoint-enabled.html", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-10", + "Terraform": "" + }, + "Recommendation": { + "Text": "To improve the security posture of your VPC, configure Amazon EC2 to use an interface VPC endpoint powered by AWS PrivateLink.", + "Url": "https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/interface-vpc-endpoints.html" + } + }, + "Categories": [], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/vpc/vpc_vpn_connection_tunnels_up/vpc_vpn_connection_tunnels_up.metadata.json b/prowler/providers/aws/services/vpc/vpc_vpn_connection_tunnels_up/vpc_vpn_connection_tunnels_up.metadata.json new file mode 100644 index 0000000000..969f975df5 --- /dev/null +++ b/prowler/providers/aws/services/vpc/vpc_vpn_connection_tunnels_up/vpc_vpn_connection_tunnels_up.metadata.json @@ -0,0 +1,34 @@ +{ + "Provider": "aws", + "CheckID": "vpc_vpn_connection_tunnels_up", + "CheckTitle": "Both VPN tunnels for an AWS Site-to-Site VPN connection should be up", + "CheckType": [ + "Software and Configuration Checks/AWS Security Best Practices" + ], + "ServiceName": "vpc", + "SubServiceName": "", + "ResourceIdTemplate": "arn:partition:service:region:account-id:vpn-connection/resource-id", + "Severity": "medium", + "ResourceType": "AwsEc2ClientVpnEndpoint", + "Description": "A VPN tunnel is an encrypted link where data can pass from the customer network to or from AWS within an AWS Site-to-Site VPN connection. Each VPN connection includes two VPN tunnels which you can simultaneously use for high availability. Ensuring that both VPN tunnels are up for a VPN connection is important for confirming a secure and highly available connection between an AWS VPC and your remote network.", + "Risk": "If one or both VPN tunnels are down, it can compromise the security and availability of the connection between your AWS VPC and your remote network. This could result in connectivity issues and potential data exposure or loss during the downtime, affecting business operations and overall network security.", + "RelatedUrl": "https://docs.aws.amazon.com/config/latest/developerguide/vpc-vpn-2-tunnels-up.html", + "Remediation": { + "Code": { + "CLI": "", + "NativeIaC": "", + "Other": "https://docs.aws.amazon.com/securityhub/latest/userguide/ec2-controls.html#ec2-20", + "Terraform": "" + }, + "Recommendation": { + "Text": "To modify VPN tunnel options, see Modifying Site-to-Site VPN tunnel options in the AWS Site-to-Site VPN User Guide.", + "Url": "https://docs.aws.amazon.com/vpn/latest/s2svpn/modify-vpn-tunnel-options.html" + } + }, + "Categories": [ + "redundancy" + ], + "DependsOn": [], + "RelatedTo": [], + "Notes": "" +} diff --git a/prowler/providers/aws/services/workspaces/workspaces_volume_encryption_enabled/workspaces_volume_encryption_enabled.metadata.json b/prowler/providers/aws/services/workspaces/workspaces_volume_encryption_enabled/workspaces_volume_encryption_enabled.metadata.json index 4b152769d3..fd251b5431 100644 --- a/prowler/providers/aws/services/workspaces/workspaces_volume_encryption_enabled/workspaces_volume_encryption_enabled.metadata.json +++ b/prowler/providers/aws/services/workspaces/workspaces_volume_encryption_enabled/workspaces_volume_encryption_enabled.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:workspaces:region:account-id:workspace", "Severity": "high", - "ResourceType": "AwsWorkspaces", + "ResourceType": "AwsWorkSpacesWorkspace", "Description": "Ensure that your Amazon WorkSpaces storage volumes are encrypted in order to meet security and compliance requirements", "Risk": "If the value listed in the Volume Encryption column is Disabled the selected AWS WorkSpaces instance volumes (root and user volumes) are not encrypted. Therefore your data-at-rest is not protected from unauthorized access and does not meet the compliance requirements regarding data encryption.", "RelatedUrl": "https://docs.aws.amazon.com/workspaces/latest/adminguide/encrypt-workspaces.html", diff --git a/prowler/providers/aws/services/workspaces/workspaces_vpc_2private_1public_subnets_nat/workspaces_vpc_2private_1public_subnets_nat.metadata.json b/prowler/providers/aws/services/workspaces/workspaces_vpc_2private_1public_subnets_nat/workspaces_vpc_2private_1public_subnets_nat.metadata.json index f46a6f9943..f6568e5ee2 100644 --- a/prowler/providers/aws/services/workspaces/workspaces_vpc_2private_1public_subnets_nat/workspaces_vpc_2private_1public_subnets_nat.metadata.json +++ b/prowler/providers/aws/services/workspaces/workspaces_vpc_2private_1public_subnets_nat/workspaces_vpc_2private_1public_subnets_nat.metadata.json @@ -7,7 +7,7 @@ "SubServiceName": "", "ResourceIdTemplate": "arn:aws:workspaces:region:account-id:workspace", "Severity": "medium", - "ResourceType": "AwsWorkspaces", + "ResourceType": "AwsWorkSpacesWorkspace", "Description": "Ensure that the Workspaces VPC are deployed following the best practices using 1 public subnet and 2 private subnets with a NAT Gateway attached", "Risk": "Proper network segmentation is a key security best practice. Workspaces VPC should be deployed using 1 public subnet and 2 private subnets with a NAT Gateway attached", "RelatedUrl": "https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-vpc.html",