From ed427c1352db113313560eb7ecaec15fa48dca7a Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?V=C3=ADctor=20Fern=C3=A1ndez=20Poyatos?= Date: Fri, 18 Oct 2024 13:56:07 +0200 Subject: [PATCH] chore(Scan, Finding): PRWLR-5056 Adjust finding information storing when performing a scan (#57) * chore: PRWLR-5056 update Prowler dependency * feat(Scan): PRWLR-5056 adapt scan task code to sdk breaking changes * test(Scan): PRWLR-5056 fix unit tests * chore: PRWLR-5056 update fixtures * chore: PRWLR-5056 update Prowler dependency --- poetry.lock | 2 +- src/backend/api/fixtures/2_dev_providers.json | 29 + src/backend/api/fixtures/3_dev_scans.json | 49 + src/backend/api/fixtures/4_dev_resources.json | 323 +- src/backend/api/fixtures/5_dev_findings.json | 2674 +++++++++++++++-- src/backend/api/models.py | 2 +- src/backend/api/v1/serializers.py | 2 +- src/backend/conftest.py | 3 +- src/backend/tasks/jobs/scan.py | 16 +- src/backend/tasks/tests/test_scan.py | 12 +- 10 files changed, 2851 insertions(+), 261 deletions(-) diff --git a/poetry.lock b/poetry.lock index ef3f1dfdc9..a443cc28ff 100644 --- a/poetry.lock +++ b/poetry.lock @@ -3285,7 +3285,7 @@ tzlocal = "5.2" type = "git" url = "https://github.com/prowler-cloud/prowler.git" reference = "master" -resolved_reference = "03a26ec507b2b93b6787be4b0516950d6ab3c092" +resolved_reference = "23a20a582e90deeb34b160532e01bfeac81cb281" [[package]] name = "psutil" diff --git a/src/backend/api/fixtures/2_dev_providers.json b/src/backend/api/fixtures/2_dev_providers.json index afd5464803..a4d73950cc 100644 --- a/src/backend/api/fixtures/2_dev_providers.json +++ b/src/backend/api/fixtures/2_dev_providers.json @@ -106,6 +106,22 @@ "scanner_args": {} } }, + { + "model": "api.provider", + "pk": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:45:26.352Z", + "updated_at": "2024-10-18T11:16:23.533Z", + "provider": "aws", + "uid": "106908755759", + "alias": "real testing aws provider", + "connected": true, + "connection_last_checked_at": "2024-10-18T11:16:23.503Z", + "metadata": {}, + "scanner_args": {} + } + }, { "model": "api.providersecret", "pk": "11491b47-75ae-4f71-ad8d-3e630a72182e", @@ -144,5 +160,18 @@ "_secret": "Z0FBQUFBQm5DTnI4Y1RyV19UWEJzc3kzQUExcU5tdlQzbFVLeDdZMWd1MzkwWkl2UF9oZGhiVEJHVWpSMXV4MjYyN3g2OVpvNVpkQUQ3S0VGaGdQLTFhQWE3MkpWZUt2cnVhODc4d3FpY3FVZkpwdHJzNUJPeFRwZ3N4bGpPZTlkNWRNdFlwTHU3aTNWR3JjSzJwLWRITHdfQWpXb1F0c1l3bVFxbnFrTEpPTGgxcnF1VUprSzZ5dGRQU2VGYmZhTTlwbVpsNFBNWlFhVW9RbjJyYnZ5N0oweE5kV0ZEaUdpUUpNVExOa3oyQ2dNREVSenJ0TEFZc0RrRWpXNUhyMmtybGNLWDVOR0FabEl4QVR1bkZyb2hBLWc1MFNIekVyeXI0SmVreHBjRnJ1YUlVdXpVbW9JZkk0aEgxYlM1VGhSRlhtcS14YzdTYUhXR2xodElmWjZuNUVwaHozX1RVTG1QWHdPZWd4clNHYnAyOTBsWEl5UU83RGxZb0RKWjdadjlsTmJtSHQ0Yl9uaDJoODB0QV9sWmFYbFAxcjA1bmhNVlNqc2xEeHlvcUJFbVZvY250ZENnMnZLT1psb1JDclB3WVR6NGdZb2pzb3U4Ny04QlB0UTZub0dMOXZEUTZEcVJhZldCWEZZSDdLTy02UVZqck5zVTZwS3pObGlOejNJeHUzbFRabFM2V2xaekZVRjZtX3VzZlplendnOWQzT01WMFd3ejNadHVlTFlqRGR2dk5Da29zOFYwOUdOaEc4OHhHRnJFMmJFMk12VDNPNlBBTGlsXy13cUM1QkVYb0o1Z2U4ZXJnWXpZdm1sWjA5bzQzb2NFWC1xbmIycGZRbGtCaGNaOWlkX094UUNNampwbkZoREctNWI4QnZRaE8zM3BEQ1BwNzA1a3BzOGczZXdIM2s1NHFGN1ZTbmJhZkc4RVdfM0ZIZU5udTBYajd1RGxpWXZpRWdSMmhHa2RKOEIzbmM0X2F1OGxrN2p6LW9UVldDOFVpREoxZ1UzcTBZX19OQ0xJb0syWlhNSlQ4MzQwdzRtVG94Y01GS3FMLV95UVlxOTFORk8zdjE5VGxVaXdhbGlzeHdoYWNzazZWai1GUGtUM2gzR0ZWTTY4SThWeVFnZldIaklOTTJqTTg1VkhEYW5wNmdEVllXMmJCV2tpVmVYeUV2c0E1T00xbHJRNzgzVG9wb0Q1cV81UEhqYUFsQ2p1a0VpRDVINl9SVkpyZVRNVnVXQUxwY3NWZnJrNmRVREpiLWNHYUpXWmxkQlhNbWhuR1NmQ1BaVDlidUxCWHJMaHhZbk1FclVBaEVZeWg1ZlFoenZzRHlKbV8wa3lmMGZrd3NmTDZjQkE0UXNSUFhpTWtUUHBrX29BVzc4QzEtWEJIQW1GMGFuZVlXQWZIOXJEamloeGFCeHpYMHNjMFVfNXpQdlJfSkk2bzFROU5NU0c1SHREWW1nbkFNZFZ0UjdPRGdjaF96RGplY1hjdFFzLVR6MTVXYlRjbHIxQ2JRejRpVko5NWhBU0ZHR3ZvczU5elljRGpHRTdIc0FsSm5fUHEwT1gtTS1lN3M3X3ZZRnlkYUZoZXRQeEJsZlhLdFdTUzU1NUl4a29aOWZIdTlPM0Fnak1xYWVkYTNiMmZXUHlXS2lwUVBZLXQyaUxuRmtQNFFieE9SVmdZVW9WTHlzbnBPZlNIdGVHOE1LNVNESjN3cGtVSHVpT1NJWHE1ZzNmUTVTOC0xX3NGSmJqU19IbjZfQWtMRG1YNUQtRy13TUJIZFlyOXJkQzFQbkdZVXVzM2czbS1HWHFBT1pXdVd3N09tcG82SVhnY1ZtUWxqTEg2UzJCUmllb2pweVN2aGwwS1FVRUhjNEN2amRMc3MwVU4zN3dVMWM5Slg4SERtenFaQk1yMWx0LWtxVWtLZVVtbU4yejVEM2h6TEt0RGdfWE09", "provider": "1b59e032-3eb6-4694-93a5-df84cd9b3ce2" } + }, + { + "model": "api.providersecret", + "pk": "ae48ecde-75cd-4814-92ab-18f48719e5d9", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:45:26.412Z", + "updated_at": "2024-10-18T10:45:26.412Z", + "name": "Valid AWS Credentials", + "secret_type": "static", + "_secret": "Z0FBQUFBQm5FanhHa3dXS0I3M2NmWm56SktiaGNqdDZUN0xQU1QwUi15QkhLZldFUmRENk1BXzlscG9JSUxVSTF5ekxuMkdEanlJNjhPUS1VSV9wVTBvU2l4ZnNGOVJhYW93RC1LTEhmc2pyOTJvUWwyWnpFY19WN1pRQk5IdDYwYnBDQnF1eU9nUzdwTGU3QU5qMGFyX1E4SXdpSk9paGVLcVpOVUhwb3duaXgxZ0ZxME5Pcm40QzBGWEZKY2lmRVlCMGFuVFVzemxuVjVNalZVQ2JsY2ZqNWt3Z01IYUZ0dk92YkdtSUZ5SlBvQWZoVU5DWlRFWmExNnJGVEY4Q1Bnd2VJUW9TSWdRcG9rSDNfREQwRld3Q1RYVnVYWVJLWWIxZmpsWGpwd0xQM0dtLTlYUjdHOVhhNklLWXFGTHpFQUVyVmNhYW9CU0tocGVyX3VjMkVEcVdjdFBfaVpsLTBzaUxrWTlta3dpelNtTG9xYVhBUHUzNUE4RnI1WXdJdHcxcFVfaG1XRHhDVFBKamxJb1FaQ2lsQ3FzRmxZbEJVemVkT1E2aHZfbDJqWDJPT3ViOWJGYzQ3eTNWNlFQSHBWRDFiV2tneDM4SmVqMU9Bd01TaXhPY2dmWG5RdENURkM2b2s5V3luVUZQcnFKNldnWEdYaWE2MnVNQkEwMHd6cUY5cVJkcGw4bHBtNzhPeHhkREdwSXNEc1JqQkxUR1FYRTV0UFNwbVlVSWF5LWgtbVhJZXlPZ0Q4cG9HX2E0Qld0LTF1TTFEVy1XNGdnQTRpLWpQQmFJUEdaOFJGNDVoUVJnQ25YVU5DTENMaTY4YmxtYWJFRERXTjAydVN2YnBDb3RkUE0zSDRlN1A3TXc4d2h1Wmd0LWUzZEcwMUstNUw2YnFyS2Z0NEVYMXllQW5GLVBpeU55SkNhczFIeFhrWXZpVXdwSFVrTDdiQjQtWHZJdERXVThzSnJsT2FNZzJDaUt6Y2NXYUZhUlo3VkY0R1BrSHNHNHprTmxjYmp1TXVKakRha0VtNmRFZWRmZHJWdnRCOVNjVGFVWjVQM3RwWWl4SkNmOU1pb2xqMFdOblhNY3Y3aERpOHFlWjJRc2dtRDkzZm1Qc29wdk5OQmJPbGk5ZUpGM1I2YzRJN2gxR3FEMllXR1pma1k0emVqSjZyMUliMGZsc3NfSlVDbGt4QzJTc3hHOU9FRHlZb09zVnlvcDR6WC1uclRSenI0Yy13WlFWNzJWRkwydjhmSjFZdnZ5X3NmZVF6UWRNMXo5STVyV3B0d09UUlFtOURITGhXSDVIUl9zYURJc05KWUNxekVyYkxJclNFNV9leEk4R2xsMGJod3lYeFIwaXR2dllwLTZyNWlXdDRpRkxVYkxWZFdvYUhKck5aeElBZUtKejNKS2tYVW1rTnVrRjJBQmdlZmV6ckozNjNwRmxLS1FaZzRVTTBZYzFFYi1idjBpZkQ3bWVvbEdRZXJrWFNleWZmSmFNdG1wQlp0YmxjWDV5T0tEbHRsYnNHbjRPRjl5MkttOUhRWlJtd1pmTnY4Z1lPRlZoTzFGVDdTZ0RDY1ByV0RndTd5LUNhcHNXUnNIeXdLMEw3WS1tektRTWFLQy1zakpMLWFiM3FOakE1UWU4LXlOX2VPbmd4MTZCRk9OY3Z4UGVDSWxhRlg4eHI4X1VUTDZZM0pjV0JDVi1UUjlTUl85cm1LWlZ0T1dzU0lpdWUwbXgtZ0l6eHNSNExRTV9MczJ6UkRkVElnRV9Rc0RoTDFnVHRZSEFPb2paX200TzZiRzVmRE5hOW5CTjh5Qi1WaEtueEpqRzJDY1luVWZtX1pseUpQSE5lQ0RrZ05EbWo5cU9MZ0ZkcXlqUll4UUkyejRfY2p4RXdEeC1PS1JIQVNUcmNIdkRJbzRiUktMWEQxUFM3aGNzeVFWUDdtcm5xNHlOYUU9", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555" + } } ] diff --git a/src/backend/api/fixtures/3_dev_scans.json b/src/backend/api/fixtures/3_dev_scans.json index e34c047b86..d03f4ac07b 100644 --- a/src/backend/api/fixtures/3_dev_scans.json +++ b/src/backend/api/fixtures/3_dev_scans.json @@ -165,5 +165,54 @@ "inserted_at": "2024-09-02T19:29:27.050Z", "updated_at": "2024-09-02T19:29:27.050Z" } + }, + { + "model": "api.scan", + "pk": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "name": "real scan 1", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "trigger": "manual", + "state": "completed", + "unique_resource_count": 19, + "progress": 100, + "scanner_args": { + "checks_to_execute": [ + "accessanalyzer_enabled" + ] + }, + "duration": 7, + "scheduled_at": null, + "inserted_at": "2024-10-18T10:45:57.678Z", + "updated_at": "2024-10-18T10:46:05.127Z", + "started_at": "2024-10-18T10:45:57.909Z", + "completed_at": "2024-10-18T10:46:05.127Z" + } + }, + { + "model": "api.scan", + "pk": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "name": "real scan 2", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "trigger": "manual", + "state": "completed", + "unique_resource_count": 20, + "progress": 100, + "scanner_args": { + "checks_to_execute": [ + "accessanalyzer_enabled", + "account_security_contact_information_is_registered" + ] + }, + "duration": 4, + "scheduled_at": null, + "inserted_at": "2024-10-18T11:16:21.358Z", + "updated_at": "2024-10-18T11:16:26.060Z", + "started_at": "2024-10-18T11:16:21.593Z", + "completed_at": "2024-10-18T11:16:26.060Z" + } } ] diff --git a/src/backend/api/fixtures/4_dev_resources.json b/src/backend/api/fixtures/4_dev_resources.json index f76501eed4..30044acfa2 100644 --- a/src/backend/api/fixtures/4_dev_resources.json +++ b/src/backend/api/fixtures/4_dev_resources.json @@ -1,49 +1,322 @@ [ { "model": "api.resource", - "pk": "a3ba9470-a240-49a6-8196-9230a267a220", + "pk": "0234477d-0b8e-439f-87d3-ce38dff3a434", "fields": { "tenant": "12646005-9067-4d2a-a098-8bb378604362", - "provider": "37b065f8-26b0-4218-a665-0b23d07b27d9", - "uid": "unique-1", - "name": "testing 1", - "region": "eu-west-1", - "service": "ec2", - "inserted_at": "2024-08-01T17:20:27.050Z", - "updated_at": "2024-08-01T17:20:27.050Z" + "inserted_at": "2024-10-18T10:46:04.772Z", + "updated_at": "2024-10-18T11:16:24.466Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "eu-south-2", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'2':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'eu':7C 'eu-south':6C 'iam':3A 'other':11 'root':5A 'south':8C" } }, { "model": "api.resource", - "pk": "85f18c25-4deb-460e-87e2-12548f2508ed", + "pk": "17ce30a3-6e77-42a5-bb08-29dfcad7396a", "fields": { "tenant": "12646005-9067-4d2a-a098-8bb378604362", - "provider": "37b065f8-26b0-4218-a665-0b23d07b27d9", - "uid": "unique-2", - "name": "testing 2", + "inserted_at": "2024-10-18T10:46:04.882Z", + "updated_at": "2024-10-18T11:16:24.533Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", "region": "eu-west-1", - "service": "ec2", - "inserted_at": "2024-08-01T17:20:27.050Z", - "updated_at": "2024-08-01T17:20:27.050Z" + "service": "accessanalyzer", + "type": "Other", + "text_search": "'1':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'eu':7C 'eu-west':6C 'iam':3A 'other':11 'root':5A 'west':8C" } }, { - "model": "api.resourcetag", - "pk": "057c38c5-94aa-46ee-98bb-9ec5b0886bbf", + "model": "api.resource", + "pk": "1f9de587-ba5b-415a-b9b0-ceed4c6c9f32", "fields": { "tenant": "12646005-9067-4d2a-a098-8bb378604362", - "key": "key", - "value": "tag value", - "inserted_at": "2024-08-01T17:20:27.050Z", - "updated_at": "2024-08-01T17:20:27.050Z" + "inserted_at": "2024-10-18T10:46:05.091Z", + "updated_at": "2024-10-18T11:16:24.637Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "ap-northeast-2", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'2':9C '112233445566':4A 'accessanalyzer':10 'ap':7C 'ap-northeast':6C 'arn':1A 'aws':2A 'iam':3A 'northeast':8C 'other':11 'root':5A" } }, { - "model": "api.resourcetagmapping", + "model": "api.resource", + "pk": "29b35668-6dad-411d-bfec-492311889892", "fields": { - "tag": "057c38c5-94aa-46ee-98bb-9ec5b0886bbf", - "resource": "85f18c25-4deb-460e-87e2-12548f2508ed", - "tenant": "12646005-9067-4d2a-a098-8bb378604362" + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.008Z", + "updated_at": "2024-10-18T11:16:24.600Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "us-west-2", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'2':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'iam':3A 'other':11 'root':5A 'us':7C 'us-west':6C 'west':8C" + } + }, + { + "model": "api.resource", + "pk": "30505514-01d4-42bb-8b0c-471bbab27460", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:26.014Z", + "updated_at": "2024-10-18T11:16:26.023Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "us-east-1", + "service": "account", + "type": "Other", + "text_search": "'1':9C '112233445566':4A 'account':10 'arn':1A 'aws':2A 'east':8C 'iam':3A 'other':11 'root':5A 'us':7C 'us-east':6C" + } + }, + { + "model": "api.resource", + "pk": "372932f0-e4df-4968-9721-bb4f6236fae4", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.848Z", + "updated_at": "2024-10-18T11:16:24.516Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "eu-west-3", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'3':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'eu':7C 'eu-west':6C 'iam':3A 'other':11 'root':5A 'west':8C" + } + }, + { + "model": "api.resource", + "pk": "3a37d124-7637-43f6-9df7-e9aa7ef98c53", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.979Z", + "updated_at": "2024-10-18T11:16:24.585Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "sa-east-1", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'1':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'east':8C 'iam':3A 'other':11 'root':5A 'sa':7C 'sa-east':6C" + } + }, + { + "model": "api.resource", + "pk": "3c49318e-03c6-4f12-876f-40451ce7de3d", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.072Z", + "updated_at": "2024-10-18T11:16:24.630Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "ap-southeast-2", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'2':9C '112233445566':4A 'accessanalyzer':10 'ap':7C 'ap-southeast':6C 'arn':1A 'aws':2A 'iam':3A 'other':11 'root':5A 'southeast':8C" + } + }, + { + "model": "api.resource", + "pk": "430bf313-8733-4bc5-ac70-5402adfce880", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.994Z", + "updated_at": "2024-10-18T11:16:24.593Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "eu-north-1", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'1':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'eu':7C 'eu-north':6C 'iam':3A 'north':8C 'other':11 'root':5A" + } + }, + { + "model": "api.resource", + "pk": "78bd2a52-82f9-45df-90a9-4ad78254fdc4", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.055Z", + "updated_at": "2024-10-18T11:16:24.622Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "ap-northeast-1", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'1':9C '112233445566':4A 'accessanalyzer':10 'ap':7C 'ap-northeast':6C 'arn':1A 'aws':2A 'iam':3A 'northeast':8C 'other':11 'root':5A" + } + }, + { + "model": "api.resource", + "pk": "7973e332-795e-4a74-b4d4-a53a21c98c80", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.896Z", + "updated_at": "2024-10-18T11:16:24.542Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "us-east-2", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'2':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'east':8C 'iam':3A 'other':11 'root':5A 'us':7C 'us-east':6C" + } + }, + { + "model": "api.resource", + "pk": "8ca0a188-5699-436e-80fd-e566edaeb259", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.938Z", + "updated_at": "2024-10-18T11:16:24.565Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "ca-central-1", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'1':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'ca':7C 'ca-central':6C 'central':8C 'iam':3A 'other':11 'root':5A" + } + }, + { + "model": "api.resource", + "pk": "8fe4514f-71d7-46ab-b0dc-70cef23b4d13", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.965Z", + "updated_at": "2024-10-18T11:16:24.578Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "eu-west-2", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'2':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'eu':7C 'eu-west':6C 'iam':3A 'other':11 'root':5A 'west':8C" + } + }, + { + "model": "api.resource", + "pk": "9ab35225-dc7c-4ebd-bbc0-d81fb5d9de77", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.909Z", + "updated_at": "2024-10-18T11:16:24.549Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "ap-south-1", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'1':9C '112233445566':4A 'accessanalyzer':10 'ap':7C 'ap-south':6C 'arn':1A 'aws':2A 'iam':3A 'other':11 'root':5A 'south':8C" + } + }, + { + "model": "api.resource", + "pk": "9be26c1d-adf0-4ba8-9ca9-c740f4a0dc4e", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.863Z", + "updated_at": "2024-10-18T11:16:24.524Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "eu-central-2", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'2':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'central':8C 'eu':7C 'eu-central':6C 'iam':3A 'other':11 'root':5A" + } + }, + { + "model": "api.resource", + "pk": "ba108c01-bcad-44f1-b211-c1d8985da89d", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.110Z", + "updated_at": "2024-10-18T11:16:24.644Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "ap-northeast-3", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'3':9C '112233445566':4A 'accessanalyzer':10 'ap':7C 'ap-northeast':6C 'arn':1A 'aws':2A 'iam':3A 'northeast':8C 'other':11 'root':5A" + } + }, + { + "model": "api.resource", + "pk": "dc6cfb5d-6835-4c7b-9152-c18c734a6eaa", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.038Z", + "updated_at": "2024-10-18T11:16:24.615Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "eu-central-1", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'1':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'central':8C 'eu':7C 'eu-central':6C 'iam':3A 'other':11 'root':5A" + } + }, + { + "model": "api.resource", + "pk": "e0664164-cfda-44a4-b743-acee1c69386c", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.924Z", + "updated_at": "2024-10-18T11:16:24.557Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "us-west-1", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'1':9C '112233445566':4A 'accessanalyzer':10 'arn':1A 'aws':2A 'iam':3A 'other':11 'root':5A 'us':7C 'us-west':6C 'west':8C" + } + }, + { + "model": "api.resource", + "pk": "e1929daa-a984-4116-8131-492a48321dba", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.023Z", + "updated_at": "2024-10-18T11:16:24.607Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:iam::112233445566:root", + "name": "", + "region": "ap-southeast-1", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'1':9C '112233445566':4A 'accessanalyzer':10 'ap':7C 'ap-southeast':6C 'arn':1A 'aws':2A 'iam':3A 'other':11 'root':5A 'southeast':8C" + } + }, + { + "model": "api.resource", + "pk": "e37bb1f1-1669-4bb3-be86-e3378ddfbcba", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.952Z", + "updated_at": "2024-10-18T11:16:24.571Z", + "provider": "15fce1fa-ecaa-433f-a9dc-62553f3a2555", + "uid": "arn:aws:access-analyzer:us-east-1:112233445566:analyzer/ConsoleAnalyzer-83b66ad7-d024-454e-b851-52d11cc1cf7c", + "name": "", + "region": "us-east-1", + "service": "accessanalyzer", + "type": "Other", + "text_search": "'1':9A,15C '112233445566':10A 'access':4A 'access-analyzer':3A 'accessanalyzer':16 'analyzer':5A 'analyzer/consoleanalyzer-83b66ad7-d024-454e-b851-52d11cc1cf7c':11A 'arn':1A 'aws':2A 'east':8A,14C 'other':17 'us':7A,13C 'us-east':6A,12C" } } ] diff --git a/src/backend/api/fixtures/5_dev_findings.json b/src/backend/api/fixtures/5_dev_findings.json index 57a9e7694e..8a02b6c2ed 100644 --- a/src/backend/api/fixtures/5_dev_findings.json +++ b/src/backend/api/fixtures/5_dev_findings.json @@ -1,258 +1,2498 @@ [ { "model": "api.finding", - "pk": "01920bdb-faf8-7cb1-ba66-dee96f78f048", + "pk": "01929f3c-0917-75ff-ba43-08b857227015", "fields": { "tenant": "12646005-9067-4d2a-a098-8bb378604362", - "scan": "0191e280-9d2f-71c8-9b18-487a23ba185e", - "uid": "prowler-aws-accessanalyzer_enabled-123456789012-eu-west-1-11111111", + "inserted_at": "2024-10-18T10:46:04.823Z", + "updated_at": "2024-10-18T10:46:04.841Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-south-2-112233445566", + "delta": "new", "status": "FAIL", - "status_extended": "test status extended", - "impact": "low", - "impact_extended": "test impact extended", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, "check_id": "accessanalyzer_enabled", "check_metadata": { - "check_id": "accessanalyzer_enabled", - "metadata": { - "Categories": [], - "CheckID": "accessanalyzer_enabled", - "CheckTitle": "Check if IAM Access Analyzer is enabled", - "CheckType": [ - "IAM" - ], - "DependsOn": [], - "Description": "Check if IAM Access Analyzer is enabled", - "Notes": "", - "Provider": "aws", - "RelatedTo": [], - "RelatedUrl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", - "Remediation": { - "Code": { - "CLI": "aws accessanalyzer create-analyzer --analyzer-name --type ", - "NativeIaC": "", - "Other": "", - "Terraform": "" - }, - "Recommendation": { - "Text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost).", - "Url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html" - } + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" }, - "ResourceIdTemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id", - "ResourceType": "Other", - "Risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", - "ServiceName": "accessanalyzer", - "Severity": "low", - "SubServiceName": "" - } + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" }, - "raw_result": { - "status": "FAIL", - "impact": "critical", - "severity": "critical" - }, - "inserted_at": "2024-09-19T19:56:59.590Z", - "updated_at": "2024-09-19T19:56:59.590Z" - } - }, - { - "model": "api.resourcefindingmapping", - "fields": { - "finding": "01920bdb-faf8-7cb1-ba66-dee96f78f048", - "resource": "a3ba9470-a240-49a6-8196-9230a267a220", - "tenant": "12646005-9067-4d2a-a098-8bb378604362" + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" } }, { "model": "api.finding", - "pk": "01920bdb-faf8-7fbd-9aa4-ae144d4b4b91", + "pk": "01929f3c-0936-7cef-b923-55639a76763a", "fields": { "tenant": "12646005-9067-4d2a-a098-8bb378604362", - "uid": "prowler-aws-workspaces_vpc_2private_1public_subnets_nat-123456789012-eu-west-1-11111112", - "scan": "01920573-aa9c-73c9-bcda-f2e35c9b19d2", - "status": "PASS", - "status_extended": "test status extended", - "impact": "medium", - "impact_extended": "test impact extended", - "severity": "medium", - "check_id": "workspaces_vpc_2private_1public_subnets_nat", - "check_metadata": { - "check_id": "workspaces_vpc_2private_1public_subnets_nat", - "metadata": { - "Categories": [], - "CheckID": "workspaces_vpc_2private_1public_subnets_nat", - "CheckTitle": "Ensure that the Workspaces VPC are deployed following the best practices using 1 public subnet and 2 private subnets with a NAT Gateway attached", - "CheckType": [], - "DependsOn": [], - "Description": "Ensure that the Workspaces VPC are deployed following the best practices using 1 public subnet and 2 private subnets with a NAT Gateway attached", - "Notes": "", - "Provider": "aws", - "RelatedTo": [], - "RelatedUrl": "https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-vpc.html", - "Remediation": { - "Code": { - "CLI": "", - "NativeIaC": "", - "Other": "", - "Terraform": "" - }, - "Recommendation": { - "Text": "Follow the documentation and deploy Workspaces VPC using 1 public subnet and 2 private subnets with a NAT Gateway attached", - "Url": "https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-vpc.html" - } - }, - "ResourceIdTemplate": "arn:aws:workspaces:region:account-id:workspace", - "ResourceType": "AwsWorkspaces", - "Risk": "Proper network segmentation is a key security best practice. Workspaces VPC should be deployed using 1 public subnet and 2 private subnets with a NAT Gateway attached", - "ServiceName": "workspaces", - "Severity": "medium", - "SubServiceName": "" - } - }, - "raw_result": { - "status": "FAIL", - "impact": "critical", - "severity": "critical" - }, - "inserted_at": "2024-09-19T19:56:59.596Z", - "updated_at": "2024-09-19T19:56:59.596Z" - } - }, - { - "model": "api.resourcefindingmapping", - "fields": { - "finding": "01920bdb-faf8-7fbd-9aa4-ae144d4b4b91", - "resource": "a3ba9470-a240-49a6-8196-9230a267a220", - "tenant": "12646005-9067-4d2a-a098-8bb378604362" - } - }, - { - "model": "api.finding", - "pk": "01920bdf-8150-7630-a385-62a80cdc75b5", - "fields": { - "tenant": "12646005-9067-4d2a-a098-8bb378604362", - "uid": "prowler-aws-accessanalyzer_enabled-123456789012-eu-west-1-11111113", - "scan": "01920573-ea5b-77fd-a93f-1ed2ae12f728", + "inserted_at": "2024-10-18T10:46:04.855Z", + "updated_at": "2024-10-18T10:46:04.858Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-west-3-112233445566", + "delta": "new", "status": "FAIL", - "status_extended": "test status extended", - "impact": "low", - "impact_extended": "test impact extended", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, "check_id": "accessanalyzer_enabled", "check_metadata": { - "check_id": "accessanalyzer_enabled", - "metadata": { - "Categories": [], - "CheckID": "accessanalyzer_enabled", - "CheckTitle": "Check if IAM Access Analyzer is enabled", - "CheckType": [ - "IAM" - ], - "DependsOn": [], - "Description": "Check if IAM Access Analyzer is enabled", - "Notes": "", - "Provider": "aws", - "RelatedTo": [], - "RelatedUrl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", - "Remediation": { - "Code": { - "CLI": "aws accessanalyzer create-analyzer --analyzer-name --type ", - "NativeIaC": "", - "Other": "", - "Terraform": "" - }, - "Recommendation": { - "Text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost).", - "Url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html" - } + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" }, - "ResourceIdTemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id", - "ResourceType": "Other", - "Risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", - "ServiceName": "accessanalyzer", - "Severity": "low", - "SubServiceName": "" - } + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" }, - "raw_result": { - "status": "FAIL", - "impact": "critical", - "severity": "critical" - }, - "inserted_at": "2024-09-19T20:00:50.354Z", - "updated_at": "2024-09-19T20:00:50.354Z" - } - }, - { - "model": "api.resourcefindingmapping", - "fields": { - "finding": "01920bdf-8150-7630-a385-62a80cdc75b5", - "resource": "a3ba9470-a240-49a6-8196-9230a267a220", - "tenant": "12646005-9067-4d2a-a098-8bb378604362" + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" } }, { "model": "api.finding", - "pk": "01920be0-8320-75ce-a9a2-f927821769fa", + "pk": "01929f3c-0944-7bcf-8fe4-65df82f0de3a", "fields": { "tenant": "12646005-9067-4d2a-a098-8bb378604362", - "uid": "prowler-aws-workspaces_vpc_2private_1public_subnets_nat-123456789012-eu-west-1-11111115", - "scan": "01920573-ea5b-77fd-a93f-1ed2ae12f728", - "status": "PASS", - "status_extended": "test status extended", - "impact": "medium", - "impact_extended": "test impact extended", - "severity": "medium", - "check_id": "workspaces_vpc_2private_1public_subnets_nat", + "inserted_at": "2024-10-18T10:46:04.869Z", + "updated_at": "2024-10-18T10:46:04.876Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-central-2-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", "check_metadata": { - "check_id": "workspaces_vpc_2private_1public_subnets_nat", - "metadata": { - "Categories": [], - "CheckID": "workspaces_vpc_2private_1public_subnets_nat", - "CheckTitle": "Ensure that the Workspaces VPC are deployed following the best practices using 1 public subnet and 2 private subnets with a NAT Gateway attached", - "CheckType": [], - "DependsOn": [], - "Description": "Ensure that the Workspaces VPC are deployed following the best practices using 1 public subnet and 2 private subnets with a NAT Gateway attached", - "Notes": "", - "Provider": "aws", - "RelatedTo": [], - "RelatedUrl": "https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-vpc.html", - "Remediation": { - "Code": { - "CLI": "", - "NativeIaC": "", - "Other": "", - "Terraform": "" - }, - "Recommendation": { - "Text": "Follow the documentation and deploy Workspaces VPC using 1 public subnet and 2 private subnets with a NAT Gateway attached", - "Url": "https://docs.aws.amazon.com/workspaces/latest/adminguide/amazon-workspaces-vpc.html" - } + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" }, - "ResourceIdTemplate": "arn:aws:workspaces:region:account-id:workspace", - "ResourceType": "AwsWorkspaces", - "Risk": "Proper network segmentation is a key security best practice. Workspaces VPC should be deployed using 1 public subnet and 2 private subnets with a NAT Gateway attached", - "ServiceName": "workspaces", - "Severity": "medium", - "SubServiceName": "" - } + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" }, - "raw_result": { - "status": "FAIL", - "impact": "critical", - "severity": "critical" + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-0958-7e15-8cac-0df0a67fd3a6", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.888Z", + "updated_at": "2024-10-18T10:46:04.892Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-west-1-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" }, - "inserted_at": "2024-09-19T20:01:56.306Z", - "updated_at": "2024-09-19T20:01:56.306Z" + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-0965-7290-9b5d-f4a84e26feb0", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.901Z", + "updated_at": "2024-10-18T10:46:04.905Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-us-east-2-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-0973-75c7-8bb3-d7f73491dbd2", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.915Z", + "updated_at": "2024-10-18T10:46:04.919Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-south-1-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-0981-71ff-8b66-1b23f7cdd1f8", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.929Z", + "updated_at": "2024-10-18T10:46:04.934Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-us-west-1-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-0990-7a50-a72e-e6686cd74116", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.944Z", + "updated_at": "2024-10-18T10:46:04.947Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ca-central-1-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-099d-7d97-8c57-34ee4740c9e5", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.957Z", + "updated_at": "2024-10-18T10:46:04.962Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-us-east-1-ConsoleAnalyzer-83b66ad7-d024-454e-b851-52d11cc1cf7c", + "delta": "new", + "status": "PASS", + "status_extended": "IAM Access Analyzer ConsoleAnalyzer-83b66ad7-d024-454e-b851-52d11cc1cf7c is enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':107,131 '454e':8B '52d11cc1cf7c':10B '83b66ad7':6B 'a':55,62,84 'access':2B,15,47,59,80,100,112,135,150,166 'access-analyzer':165 'accessanalyzer':88,118,159 'account':126,170 'account-id':169 'accounts':26,139 'action':144 'additional':156 'all':78,138 'allowed':82 'amazon':29 'an':39 'analysis':66 'analyz':3B 'analyzer':16,60,101,113,121,123,136,141,151,167 'analyzer-name':122 'analyzer/resource-id':172 'and':25,51,73,142 'applies':71 'are':36 'arn':163 'as':28 'at':154 'automated':68 'available':153 'aws':13,91,117 'b851':9B 'buckets':31 'by':83 'called':67 'check':97,109 'consoleanalyz':5B 'consoleanalyzer-83b66ad7-d024-454e-b851-52d11cc1cf7c':4B 'cost':157 'create':120,140 'create-analyzer':119 'd024':7B 'data':52 'determine':77 'docs.aws.amazon.com':106,130 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':105,129 'enabl':12B 'enable':133 'enabled':89,103,115 'entity':41 'external':40 'for':137 'form':63 'helps':17 'iam':1B,14,33,58,95,99,111,134,149 'id':171 'identify':19,45 'if':98,110 'in':22 'inference':75 'is':54,102,114,147,152 'it':146 'lets':43 'logic':72 'low':93 'mathematical':65,74 'name':124 'no':155 'of':64 'or':32 'organization':24,127 'other':161 'over':145 'partition':164 'paths':81 'policy':86 'possible':79 'reasoning':69 'recommendations':148 'region':168 'resource':85 'resources':21,50 'risk':57 'roles':34 's3':30 'security':56 'shared':37 'such':27 'take':143 'that':35 'the':20 'this':42 'to':48,76 'type':125 'unintended':46 'uses':61 'which':53,70 'with':38 'you':18,44 'your':23,49" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-09ab-728a-a4a9-5a9a0693b0c1", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.971Z", + "updated_at": "2024-10-18T10:46:04.975Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-west-2-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-09b8-757a-89c2-411e0c7309d4", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.984Z", + "updated_at": "2024-10-18T10:46:04.989Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-sa-east-1-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-09c7-71c9-a483-4d207cd464b7", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:04.999Z", + "updated_at": "2024-10-18T10:46:05.003Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-north-1-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-09d5-7fe3-bb36-19e0c1b90a9d", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.013Z", + "updated_at": "2024-10-18T10:46:05.018Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-us-west-2-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-09e4-70a7-949d-aba3a0f93fb1", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.029Z", + "updated_at": "2024-10-18T10:46:05.033Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-southeast-1-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-09f5-79f9-9ee7-17c87e43d87b", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.045Z", + "updated_at": "2024-10-18T10:46:05.050Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-central-1-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-0a05-7426-980d-bdfeeb70a008", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.061Z", + "updated_at": "2024-10-18T10:46:05.065Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-northeast-1-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-0a17-7694-9920-7233a71fcdbe", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.080Z", + "updated_at": "2024-10-18T10:46:05.085Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-southeast-2-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-0a2a-7ba7-8e43-26cb937c8df7", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.099Z", + "updated_at": "2024-10-18T10:46:05.104Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-northeast-2-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f3c-0a3b-784a-930e-e363d60f3586", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T10:46:05.115Z", + "updated_at": "2024-10-18T10:46:05.121Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-northeast-3-112233445566", + "delta": "new", + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f3b-ed2e-7623-ad63-7c37cd37828f", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd29-7499-80c3-18cfa227c7b6", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.489Z", + "updated_at": "2024-10-18T11:16:24.506Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-south-2-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd46-7ff5-800f-483b7ee71cd6", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.518Z", + "updated_at": "2024-10-18T11:16:24.521Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-west-3-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd4e-75db-a9f5-1c95776cead6", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.526Z", + "updated_at": "2024-10-18T11:16:24.529Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-central-2-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd57-7560-b55e-ad2e7d660509", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.535Z", + "updated_at": "2024-10-18T11:16:24.538Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-west-1-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd60-7a7d-ba1b-37affc11176a", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.544Z", + "updated_at": "2024-10-18T11:16:24.546Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-us-east-2-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd67-79ba-af2f-ce6d0fd3c846", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.551Z", + "updated_at": "2024-10-18T11:16:24.554Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-south-1-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd70-79ec-a176-9d606bdf68fb", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.560Z", + "updated_at": "2024-10-18T11:16:24.562Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-us-west-1-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd76-7817-aab2-c283b44082ec", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.567Z", + "updated_at": "2024-10-18T11:16:24.569Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ca-central-1-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd7d-740c-921d-9400d1fde3e2", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.573Z", + "updated_at": "2024-10-18T11:16:24.575Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-us-east-1-ConsoleAnalyzer-83b66ad7-d024-454e-b851-52d11cc1cf7c", + "delta": null, + "status": "PASS", + "status_extended": "IAM Access Analyzer ConsoleAnalyzer-83b66ad7-d024-454e-b851-52d11cc1cf7c is enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':107,131 '454e':8B '52d11cc1cf7c':10B '83b66ad7':6B 'a':55,62,84 'access':2B,15,47,59,80,100,112,135,150,166 'access-analyzer':165 'accessanalyzer':88,118,159 'account':126,170 'account-id':169 'accounts':26,139 'action':144 'additional':156 'all':78,138 'allowed':82 'amazon':29 'an':39 'analysis':66 'analyz':3B 'analyzer':16,60,101,113,121,123,136,141,151,167 'analyzer-name':122 'analyzer/resource-id':172 'and':25,51,73,142 'applies':71 'are':36 'arn':163 'as':28 'at':154 'automated':68 'available':153 'aws':13,91,117 'b851':9B 'buckets':31 'by':83 'called':67 'check':97,109 'consoleanalyz':5B 'consoleanalyzer-83b66ad7-d024-454e-b851-52d11cc1cf7c':4B 'cost':157 'create':120,140 'create-analyzer':119 'd024':7B 'data':52 'determine':77 'docs.aws.amazon.com':106,130 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':105,129 'enabl':12B 'enable':133 'enabled':89,103,115 'entity':41 'external':40 'for':137 'form':63 'helps':17 'iam':1B,14,33,58,95,99,111,134,149 'id':171 'identify':19,45 'if':98,110 'in':22 'inference':75 'is':54,102,114,147,152 'it':146 'lets':43 'logic':72 'low':93 'mathematical':65,74 'name':124 'no':155 'of':64 'or':32 'organization':24,127 'other':161 'over':145 'partition':164 'paths':81 'policy':86 'possible':79 'reasoning':69 'recommendations':148 'region':168 'resource':85 'resources':21,50 'risk':57 'roles':34 's3':30 'security':56 'shared':37 'such':27 'take':143 'that':35 'the':20 'this':42 'to':48,76 'type':125 'unintended':46 'uses':61 'which':53,70 'with':38 'you':18,44 'your':23,49" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd84-7154-aaf3-3d57bc9fec6c", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.580Z", + "updated_at": "2024-10-18T11:16:24.582Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-west-2-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd8b-79ee-97a2-66fb8d53bcfc", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.587Z", + "updated_at": "2024-10-18T11:16:24.589Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-sa-east-1-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd93-72a1-82bb-6247e5b05f5c", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.595Z", + "updated_at": "2024-10-18T11:16:24.597Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-north-1-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cd9a-7574-a8bd-2eb085c1c1d4", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.602Z", + "updated_at": "2024-10-18T11:16:24.604Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-us-west-2-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cda2-7bb6-b303-ccf5c68e3b7e", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.610Z", + "updated_at": "2024-10-18T11:16:24.612Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-southeast-1-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cda9-716d-9824-9bdaf894ba46", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.617Z", + "updated_at": "2024-10-18T11:16:24.620Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-eu-central-1-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cdb0-7eef-84d9-13ff9bd5405d", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.625Z", + "updated_at": "2024-10-18T11:16:24.627Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-northeast-1-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cdb8-72c4-923a-13dbebc6347b", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.632Z", + "updated_at": "2024-10-18T11:16:24.634Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-southeast-2-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cdbf-7d43-b0f0-c82b8c0f6bca", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.639Z", + "updated_at": "2024-10-18T11:16:24.642Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-northeast-2-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-cdc6-70e9-b025-30f1f8b5efbe", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:24.646Z", + "updated_at": "2024-10-18T11:16:24.648Z", + "uid": "prowler-aws-accessanalyzer_enabled-112233445566-ap-northeast-3-112233445566", + "delta": null, + "status": "FAIL", + "status_extended": "IAM Access Analyzer in account 112233445566 is not enabled.", + "severity": "low", + "impact": "low", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "accessanalyzer_enabled", + "check_metadata": { + "risk": "AWS IAM Access Analyzer helps you identify the resources in your organization and accounts, such as Amazon S3 buckets or IAM roles, that are shared with an external entity. This lets you identify unintended access to your resources and data, which is a security risk. IAM Access Analyzer uses a form of mathematical analysis called automated reasoning, which applies logic and mathematical inference to determine all possible access paths allowed by a resource policy.", + "notes": "", + "checkid": "accessanalyzer_enabled", + "provider": "aws", + "severity": "low", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Check if IAM Access Analyzer is enabled", + "compliance": null, + "relatedurl": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "description": "Check if IAM Access Analyzer is enabled", + "remediation": { + "code": { + "cli": "aws accessanalyzer create-analyzer --analyzer-name --type ", + "other": "", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/IAM/latest/UserGuide/what-is-access-analyzer.html", + "text": "Enable IAM Access Analyzer for all accounts, create analyzer and take action over it is recommendations (IAM Access Analyzer is available at no additional cost)." + } + }, + "servicename": "accessanalyzer", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-analyzer:region:account-id:analyzer/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/iam/latest/userguide/what-is-access-analyzer.html':104,128 '112233445566':6B 'a':52,59,81 'access':2B,12,44,56,77,97,109,132,147,163 'access-analyzer':162 'accessanalyzer':85,115,156 'account':5B,123,167 'account-id':166 'accounts':23,136 'action':141 'additional':153 'all':75,135 'allowed':79 'amazon':26 'an':36 'analysis':63 'analyz':3B 'analyzer':13,57,98,110,118,120,133,138,148,164 'analyzer-name':119 'analyzer/resource-id':169 'and':22,48,70,139 'applies':68 'are':33 'arn':160 'as':25 'at':151 'automated':65 'available':150 'aws':10,88,114 'buckets':28 'by':80 'called':64 'check':94,106 'cost':154 'create':117,137 'create-analyzer':116 'data':49 'determine':74 'docs.aws.amazon.com':103,127 'docs.aws.amazon.com/iam/latest/userguide/what-is-access-analyzer.html':102,126 'enabl':9B 'enable':130 'enabled':86,100,112 'entity':38 'external':37 'for':134 'form':60 'helps':14 'iam':1B,11,30,55,92,96,108,131,146 'id':168 'identify':16,42 'if':95,107 'in':19 'inference':72 'is':51,99,111,144,149 'it':143 'lets':40 'logic':69 'low':90 'mathematical':62,71 'name':121 'no':152 'of':61 'or':29 'organization':21,124 'other':158 'over':142 'partition':161 'paths':78 'policy':83 'possible':76 'reasoning':66 'recommendations':145 'region':165 'resource':82 'resources':18,47 'risk':54 'roles':31 's3':27 'security':53 'shared':34 'such':24 'take':140 'that':32 'the':17 'this':39 'to':45,73 'type':122 'unintended':43 'uses':58 'which':50,67 'with':35 'you':15,41 'your':20,46" + } + }, + { + "model": "api.finding", + "pk": "01929f57-d331-73f2-b5c2-8e75148b99e7", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "inserted_at": "2024-10-18T11:16:26.033Z", + "updated_at": "2024-10-18T11:16:26.045Z", + "uid": "prowler-aws-account_security_contact_information_is_registered-112233445566-us-east-1-112233445566", + "delta": "new", + "status": "MANUAL", + "status_extended": "Login to the AWS Console. Choose your account name on the top right of the window -> My Account -> Alternate Contacts -> Security Section.", + "severity": "medium", + "impact": "medium", + "impact_extended": null, + "raw_result": {}, + "tags": {}, + "check_id": "account_security_contact_information_is_registered", + "check_metadata": { + "risk": "AWS provides customers with the option of specifying the contact information for accounts security team. It is recommended that this information be provided. Specifying security-specific contact information will help ensure that security advisories sent by AWS reach the team in your organization that is best equipped to respond to them.", + "notes": "", + "checkid": "account_security_contact_information_is_registered", + "provider": "aws", + "severity": "medium", + "checktype": [ + "IAM" + ], + "dependson": [], + "relatedto": [], + "categories": [], + "checktitle": "Ensure security contact information is registered.", + "compliance": null, + "relatedurl": "", + "description": "Ensure security contact information is registered.", + "remediation": { + "code": { + "cli": "No command available.", + "other": "https://docs.prowler.com/checks/aws/iam-policies/iam_19#aws-console", + "nativeiac": "", + "terraform": "" + }, + "recommendation": { + "url": "https://docs.aws.amazon.com/accounts/latest/reference/manage-acct-update-contact.html", + "text": "Go to the My Account section and complete alternate contacts." + } + }, + "servicename": "account", + "checkaliases": [], + "resourcetype": "Other", + "subservicename": "", + "resourceidtemplate": "arn:partition:access-recorder:region:account-id:recorder/resource-id" + }, + "scan": "01929f57-c0ee-7553-be0b-cbde006fb6f7", + "text_search": "'/accounts/latest/reference/manage-acct-update-contact.html':113 '/checks/aws/iam-policies/iam_19#aws-console':109 'access':133 'access-recorder':132 'account':8B,18B,76,119,126,137 'account-id':136 'accounts':35 'advisories':57 'altern':19B 'alternate':123 'and':121 'arn':130 'available':105 'aw':4B 'aws':23,60,83 'be':44 'best':69 'by':59 'choos':6B 'command':104 'complete':122 'consol':5B 'contact':20B,32,50,78,91,98 'contacts':124 'customers':25 'docs.aws.amazon.com':112 'docs.aws.amazon.com/accounts/latest/reference/manage-acct-update-contact.html':111 'docs.prowler.com':108 'docs.prowler.com/checks/aws/iam-policies/iam_19#aws-console':107 'ensure':54,89,96 'equipped':70 'for':34 'go':115 'help':53 'iam':87 'id':138 'in':64 'information':33,43,51,79,92,99 'is':39,68,80,93,100 'it':38 'login':1B 'medium':85 'my':118 'name':9B 'no':103 'of':29 'option':28 'organization':66 'other':128 'partition':131 'provided':45 'provides':24 'reach':61 'recommended':40 'recorder':134 'recorder/resource-id':139 'region':135 'registered':81,94,101 'respond':72 'right':13B 'section':22B,120 'secur':21B 'security':36,48,56,77,90,97 'security-specific':47 'sent':58 'specific':49 'specifying':30,46 'team':37,63 'that':41,55,67 'the':27,31,62,117 'them':74 'this':42 'to':71,73,116 'top':12B 'will':52 'window':16B 'with':26 'your':65" } }, { "model": "api.resourcefindingmapping", + "pk": "00841d38-1319-4fe4-b38e-4f00bf6246d5", "fields": { - "finding": "01920be0-8320-75ce-a9a2-f927821769fa", - "resource": "a3ba9470-a240-49a6-8196-9230a267a220", - "tenant": "12646005-9067-4d2a-a098-8bb378604362" + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "372932f0-e4df-4968-9721-bb4f6236fae4", + "finding": "01929f57-cd46-7ff5-800f-483b7ee71cd6" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "013595e9-0388-4a65-950b-fab01c2a4c68", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "78bd2a52-82f9-45df-90a9-4ad78254fdc4", + "finding": "01929f3c-0a05-7426-980d-bdfeeb70a008" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "0943d22d-db70-47a1-b8a2-0a1f6925b16b", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "8ca0a188-5699-436e-80fd-e566edaeb259", + "finding": "01929f57-cd76-7817-aab2-c283b44082ec" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "0f508071-6989-41da-aec9-23934eb4d9b0", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "372932f0-e4df-4968-9721-bb4f6236fae4", + "finding": "01929f3c-0936-7cef-b923-55639a76763a" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "0fbc8dd3-c505-4804-887c-16026632c8e7", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "ba108c01-bcad-44f1-b211-c1d8985da89d", + "finding": "01929f3c-0a3b-784a-930e-e363d60f3586" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "214b1027-292b-4e04-93f9-72acb2784345", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "3a37d124-7637-43f6-9df7-e9aa7ef98c53", + "finding": "01929f3c-09b8-757a-89c2-411e0c7309d4" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "24496c6f-b0ee-4dd5-b566-77283c3d625c", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "e37bb1f1-1669-4bb3-be86-e3378ddfbcba", + "finding": "01929f57-cd7d-740c-921d-9400d1fde3e2" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "24a5a1bc-f211-4074-b687-61c994d48ea3", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "8fe4514f-71d7-46ab-b0dc-70cef23b4d13", + "finding": "01929f57-cd84-7154-aaf3-3d57bc9fec6c" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "25161d3f-bf2c-43ce-821b-237456f1846b", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "17ce30a3-6e77-42a5-bb08-29dfcad7396a", + "finding": "01929f57-cd57-7560-b55e-ad2e7d660509" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "254d9f93-cae5-4aee-a063-9c30e9e1fce5", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "9ab35225-dc7c-4ebd-bbc0-d81fb5d9de77", + "finding": "01929f57-cd67-79ba-af2f-ce6d0fd3c846" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "2d492826-662d-4f0b-8545-ac374d433399", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "dc6cfb5d-6835-4c7b-9152-c18c734a6eaa", + "finding": "01929f3c-09f5-79f9-9ee7-17c87e43d87b" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "2e6d8623-5656-4118-ad85-128ed9f22edb", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "3c49318e-03c6-4f12-876f-40451ce7de3d", + "finding": "01929f3c-0a17-7694-9920-7233a71fcdbe" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "324d5b45-7975-4792-a8f2-3a66c87d2542", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "0234477d-0b8e-439f-87d3-ce38dff3a434", + "finding": "01929f3c-0917-75ff-ba43-08b857227015" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "55c94cc1-65db-4e6d-b4ae-9461d067e73c", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "3c49318e-03c6-4f12-876f-40451ce7de3d", + "finding": "01929f57-cdb8-72c4-923a-13dbebc6347b" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "596ac4dd-f10f-4dfb-b1d3-47a5f9a831c8", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "8ca0a188-5699-436e-80fd-e566edaeb259", + "finding": "01929f3c-0990-7a50-a72e-e6686cd74116" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "61e8d4c2-a043-47cc-b959-3d412830b637", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "e37bb1f1-1669-4bb3-be86-e3378ddfbcba", + "finding": "01929f3c-099d-7d97-8c57-34ee4740c9e5" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "62e9ed60-c79d-44fa-b2ea-357185b1ef26", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "dc6cfb5d-6835-4c7b-9152-c18c734a6eaa", + "finding": "01929f57-cda9-716d-9824-9bdaf894ba46" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "6946200f-10b5-469b-95df-bee6369a38ef", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "78bd2a52-82f9-45df-90a9-4ad78254fdc4", + "finding": "01929f57-cdb0-7eef-84d9-13ff9bd5405d" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "6ab286d0-e155-4ca1-a6eb-696abb240014", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "e1929daa-a984-4116-8131-492a48321dba", + "finding": "01929f3c-09e4-70a7-949d-aba3a0f93fb1" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "6fda097d-0541-4dfc-b966-7a83346e1b73", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "430bf313-8733-4bc5-ac70-5402adfce880", + "finding": "01929f57-cd93-72a1-82bb-6247e5b05f5c" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "71d037ac-9fc6-44d3-8684-3e561b3161a8", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "7973e332-795e-4a74-b4d4-a53a21c98c80", + "finding": "01929f3c-0965-7290-9b5d-f4a84e26feb0" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "738db92d-87bb-4f44-b00c-111308327167", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "0234477d-0b8e-439f-87d3-ce38dff3a434", + "finding": "01929f57-cd29-7499-80c3-18cfa227c7b6" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "746abf14-2c00-41c5-9017-9f9c63596a0d", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "1f9de587-ba5b-415a-b9b0-ceed4c6c9f32", + "finding": "01929f57-cdbf-7d43-b0f0-c82b8c0f6bca" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "7513f701-68b2-4737-8781-9bff9fee83aa", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "e1929daa-a984-4116-8131-492a48321dba", + "finding": "01929f57-cda2-7bb6-b303-ccf5c68e3b7e" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "7f044f9f-f665-4d58-a3f3-c21388221653", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "430bf313-8733-4bc5-ac70-5402adfce880", + "finding": "01929f3c-09c7-71c9-a483-4d207cd464b7" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "81b13739-f130-4617-b944-1fcc4e319c1a", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "9ab35225-dc7c-4ebd-bbc0-d81fb5d9de77", + "finding": "01929f3c-0973-75c7-8bb3-d7f73491dbd2" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "99d3ad31-0f49-4a97-8c1e-4d57a8cb284b", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "ba108c01-bcad-44f1-b211-c1d8985da89d", + "finding": "01929f57-cdc6-70e9-b025-30f1f8b5efbe" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "b2285b6f-8b1b-44f3-b4b2-c1e15dd72fa9", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "1f9de587-ba5b-415a-b9b0-ceed4c6c9f32", + "finding": "01929f3c-0a2a-7ba7-8e43-26cb937c8df7" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "b97a46b3-a1a5-4c00-a9fc-d7788b1b977d", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "8fe4514f-71d7-46ab-b0dc-70cef23b4d13", + "finding": "01929f3c-09ab-728a-a4a9-5a9a0693b0c1" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "d07f4f57-4a98-4ee0-82ed-c6f22499ea2d", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "29b35668-6dad-411d-bfec-492311889892", + "finding": "01929f57-cd9a-7574-a8bd-2eb085c1c1d4" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "d6ae9224-4197-48ec-bdef-c8c8b1d5d0b0", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "9be26c1d-adf0-4ba8-9ca9-c740f4a0dc4e", + "finding": "01929f3c-0944-7bcf-8fe4-65df82f0de3a" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "d7375f9d-2741-42c1-841e-daf8d777fb57", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "e0664164-cfda-44a4-b743-acee1c69386c", + "finding": "01929f3c-0981-71ff-8b66-1b23f7cdd1f8" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "dca80342-2431-4eda-b083-58aa7627b2c7", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "29b35668-6dad-411d-bfec-492311889892", + "finding": "01929f3c-09d5-7fe3-bb36-19e0c1b90a9d" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "dd37c0f2-174c-4b41-8655-67f70ad1f77b", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "9be26c1d-adf0-4ba8-9ca9-c740f4a0dc4e", + "finding": "01929f57-cd4e-75db-a9f5-1c95776cead6" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "e185e5bc-31cf-4a1e-b587-1ed909721590", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "17ce30a3-6e77-42a5-bb08-29dfcad7396a", + "finding": "01929f3c-0958-7e15-8cac-0df0a67fd3a6" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "e7c09b00-a6c4-4f9a-a685-d5f5bc586d94", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "30505514-01d4-42bb-8b0c-471bbab27460", + "finding": "01929f57-d331-73f2-b5c2-8e75148b99e7" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "eab724f9-bca4-4ed2-81e9-470bcf735c7e", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "3a37d124-7637-43f6-9df7-e9aa7ef98c53", + "finding": "01929f57-cd8b-79ee-97a2-66fb8d53bcfc" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "f159cb58-10df-4b9d-88d4-09de62888e14", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "e0664164-cfda-44a4-b743-acee1c69386c", + "finding": "01929f57-cd70-79ec-a176-9d606bdf68fb" + } + }, + { + "model": "api.resourcefindingmapping", + "pk": "f3d0d704-78e1-4329-af60-ade4dac73a8d", + "fields": { + "tenant": "12646005-9067-4d2a-a098-8bb378604362", + "resource": "7973e332-795e-4a74-b4d4-a53a21c98c80", + "finding": "01929f57-cd60-7a7d-ba1b-37affc11176a" } } ] diff --git a/src/backend/api/models.py b/src/backend/api/models.py index 00b6c499e3..e87ce7cb41 100644 --- a/src/backend/api/models.py +++ b/src/backend/api/models.py @@ -11,7 +11,7 @@ from django.core.validators import MinLengthValidator from django.db import models from django.utils.translation import gettext_lazy as _ from django_celery_results.models import TaskResult -from prowler.lib.outputs.finding import Severity +from prowler.lib.check.models import Severity from psqlextra.models import PostgresPartitionedModel from psqlextra.types import PostgresPartitioningMethod from uuid6 import uuid7 diff --git a/src/backend/api/v1/serializers.py b/src/backend/api/v1/serializers.py index ec82401d0d..753152c95b 100644 --- a/src/backend/api/v1/serializers.py +++ b/src/backend/api/v1/serializers.py @@ -180,7 +180,7 @@ class UserCreateSerializer(BaseWriteSerializer): def validate_email(self, value): normalized_email = value.strip().lower() if User.objects.filter(email__iexact=normalized_email).exists(): - raise ValidationError("User with this email already exists.") + raise ValidationError("User with this email already exists.", code="unique") return value def create(self, validated_data): diff --git a/src/backend/conftest.py b/src/backend/conftest.py index eb9d62901e..976b75ede4 100644 --- a/src/backend/conftest.py +++ b/src/backend/conftest.py @@ -5,7 +5,8 @@ from django.conf import settings from django.db import connections as django_connections, connection as django_connection from django.urls import reverse from django_celery_results.models import TaskResult -from prowler.lib.outputs.finding import Severity, Status +from prowler.lib.check.models import Severity +from prowler.lib.outputs.finding import Status from rest_framework import status from rest_framework.test import APIClient diff --git a/src/backend/tasks/jobs/scan.py b/src/backend/tasks/jobs/scan.py index e583f45ac4..1380171d2a 100644 --- a/src/backend/tasks/jobs/scan.py +++ b/src/backend/tasks/jobs/scan.py @@ -1,4 +1,3 @@ -import json import time from datetime import datetime, timezone @@ -62,8 +61,8 @@ def _store_finding( Finding: The newly created or updated Finding instance. """ - finding_uid = finding.finding_uid - status = FindingStatus[finding.status.value] if finding.status is not None else None + finding_uid = finding.uid + status = FindingStatus[finding.status] with tenant_transaction(tenant_id): most_recent_finding = ( Finding.objects.filter(uid=finding_uid) @@ -78,11 +77,12 @@ def _store_finding( tenant_id=tenant_id, uid=finding_uid, delta=delta, + check_metadata=finding.get_metadata(), status=status, status_extended=finding.status_extended, - severity=finding.severity.value, - impact=finding.severity.value, - raw_result=json.loads(finding.json()), + severity=finding.severity, + impact=finding.severity, + raw_result=finding.raw, check_id=finding.check_id, scan=scan_instance, ) @@ -172,9 +172,7 @@ def perform_prowler_scan( ) provider_instance.save() - prowler_scan = ProwlerScan( - provider=prowler_provider, checks_to_execute=checks_to_execute - ) + prowler_scan = ProwlerScan(provider=prowler_provider, checks=checks_to_execute) for progress, findings in prowler_scan.scan(): for finding in findings: resource_instance, resource_uid_tuple = _store_resources( diff --git a/src/backend/tasks/tests/test_scan.py b/src/backend/tasks/tests/test_scan.py index 225862c586..d98c037375 100644 --- a/src/backend/tasks/tests/test_scan.py +++ b/src/backend/tasks/tests/test_scan.py @@ -1,4 +1,3 @@ -import json from unittest.mock import patch, MagicMock import pytest @@ -34,16 +33,17 @@ class TestPerformScan: checks_to_execute = ["check1", "check2"] finding = MagicMock() - finding.finding_uid = "this_is_a_test_finding_id" - finding.status = StatusChoices.PASS + finding.uid = "this_is_a_test_finding_id" + finding.status = "PASS" finding.status_extended = "test status extended" finding.severity = Severity.medium finding.check_id = "check1" - finding.json.return_value = '{"key": "value"}' + finding.get_metadata.return_value = '{"key": "value"}' finding.resource_uid = "resource_uid" finding.region = "region" finding.service_name = "service_name" finding.resource_type = "resource_type" + finding.raw = {} mock_prowler_scan.return_value.scan.return_value = [(100, [finding])] perform_prowler_scan(tenant_id, scan_id, provider_id, checks_to_execute) @@ -60,12 +60,12 @@ class TestPerformScan: assert scan.started_at is not None assert scan.unique_resource_count == 1 assert scan.progress == 100 - assert scan_finding.uid == finding.finding_uid + assert scan_finding.uid == finding.uid assert scan_finding.status == finding.status assert scan_finding.status_extended == finding.status_extended assert scan_finding.severity == finding.severity assert scan_finding.check_id == finding.check_id - assert scan_finding.raw_result == json.loads(finding.json()) + assert scan_finding.raw_result == finding.raw assert scan_resource.tenant == tenant assert scan_resource.uid == finding.resource_uid