Raajhesh Kannaa Chidambaram
|
39385567fc
|
feat(organizations): add OU metadata to outputs (#10283)
Co-authored-by: Raajhesh Kannaa Chidambaram <495042+raajheshkannaa@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-11 16:41:44 +01:00 |
|
Michael Wentz
|
c4d692f77b
|
feat(guardduty): add org-wide delegated admin check across all regions (#9867)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-10 12:56:00 +01:00 |
|
Eran Cohen
|
0b461233c1
|
feat(iam): Add trusted IP configurable option to reduce false positives in 'opensearch' check (#8631)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-10 12:12:54 +01:00 |
|
Pepe Fagoaga
|
9c2cb5efa8
|
fix(elbv2): Handle post-quantum (PQ) TLS policies (#10219)
|
2026-03-03 10:18:00 +01:00 |
|
Harsh Mishra
|
150abce4a8
|
fix(aws): respect AWS_ENDPOINT_URL for STS session creation (#10228)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-03-03 08:25:59 +01:00 |
|
Pepe Fagoaga
|
6962622fd2
|
fix(aws): filter VPC endpoint services by audited account to prevent AccessDenied errors (#10152)
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: jfagoagas <16007882+jfagoagas@users.noreply.github.com>
|
2026-02-24 18:30:31 +01:00 |
|
Copilot
|
90e317d39f
|
fix(kms): detect public access for any KMS action, not just kms:* (#10071)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: jfagoagas <16007882+jfagoagas@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-02-16 10:12:29 +01:00 |
|
Hugo Pereira Brito
|
cb9ab03778
|
feat(aws): revert Adding check that AWS Auto Scaling group has deletion protection (#9956)
Co-authored-by: Josema Camacho <hello@josema.xyz>
|
2026-02-04 16:53:08 +01:00 |
|
Serhii Sokolov
|
69818abdd0
|
feat(aws): Adding check that AWS Auto Scaling group has deletion protection (#9928)
Co-authored-by: Serhii Sokolov <serhii.sokolov@automat-it.com>
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com>
Co-authored-by: HugoPBrito <hugopbrit@gmail.com>
|
2026-02-04 13:17:13 +01:00 |
|
mohd4adil
|
e97e31c7ca
|
chore(aws): add support for trusted aws accounts in cross account checks for s3, eventbridge bus, eventbridge schema and dynamodb (#9692)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-01-29 09:13:34 +01:00 |
|
Kay Agahd
|
04e2d15dd2
|
feat(aws): add check rds_instance_extended_support (#9865)
Co-authored-by: Daniel Barranquero <74871504+danibarranqueroo@users.noreply.github.com>
|
2026-01-28 16:49:35 +01:00 |
|
Sergio Garcia
|
9e7ecb39fa
|
feat(aws): CloudTrail timeline for findings (#9101)
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-01-27 13:00:46 +01:00 |
|
Andoni Alonso
|
6cb0edf3e1
|
feat(aws/codebuild): add check for CodeBreach webhook filter vulnerability (#9840)
Co-authored-by: HugoPBrito <hugopbrit@gmail.com>
|
2026-01-22 15:12:24 +01:00 |
|
Josema Camacho
|
847645543a
|
feat(attack-paths): update boto dependencies for catrography compatibility (#9798)
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2026-01-15 13:00:54 +01:00 |
|
Lee Trout
|
429c591819
|
chore(aws): fixup AWS EC2 SG lib (#9216)
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
Co-authored-by: Sergio Garcia <sergargar1@gmail.com>
Co-authored-by: HugoPBrito <hugopbrit@gmail.com>
|
2026-01-12 13:47:37 +01:00 |
|
mchennai
|
05466cff22
|
test: Add edge case test for s3_bucket_server_access_logging_enabled (#9725)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-01-12 10:06:34 +01:00 |
|
mchennai
|
4169611a6a
|
test(s3_bucket_server_access_logging_enabled): Add multi-bucket test (#9716)
Co-authored-by: pedrooot <pedromarting3@gmail.com>
|
2026-01-05 11:34:57 +01:00 |
|
Pedro Martín
|
8d1d041092
|
chore(aws): support new eusc partition (#9649)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2025-12-23 12:28:10 +01:00 |
|
Ryan Nolette
|
81e046ecf6
|
feat(bedrock): API pagination (#9606)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2025-12-23 09:06:19 +01:00 |
|
Ryan Nolette
|
0d363e6100
|
feat(sagemaker): parallelize tag listing for better performance (#9609)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2025-12-23 08:51:16 +01:00 |
|
Prowler Bot
|
57b9a2ea10
|
feat(aws): Update regions for AWS services (#9631)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
Co-authored-by: pedrooot <pedromarting3@gmail.com>
|
2025-12-22 13:31:58 +01:00 |
|
Marc Espin
|
4167de39d2
|
fix(docs): Fix dead links leading to docs.prowler.cloud (#9240)
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2025-11-17 09:56:51 +01:00 |
|
Lee Trout
|
c5c7b84afd
|
chore(ec2): prevent test from calling live AWS endpoint (#9228)
|
2025-11-13 10:12:19 +01:00 |
|
Shaun
|
e246c0cfd7
|
fix(aws): false negative in iam_role_cross_service_confused_deputy_prevention (#9213)
Co-authored-by: shaun <shaun@snotra.cloud>
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
|
2025-11-11 17:39:16 -05:00 |
|
Hugo Pereira Brito
|
61a66f2bbf
|
fix(aws): firehose_stream_encrypted_at_rest description and logic (#9142)
|
2025-11-03 11:31:18 -05:00 |
|
Daniel Barranquero
|
63169289b0
|
fix(ec2): AttributeError in ec2_instance_with_outdated_ami check (#9046)
|
2025-10-28 09:13:44 -04:00 |
|
SeongYong Choi
|
efba5d2a8d
|
feat(codepipeline): add new check codepipeline_project_repo_private (#5915)
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
|
2025-10-27 18:55:36 -04:00 |
|
Daniel Barranquero
|
e279f7fcfd
|
fix: handle eks cluster version and listener certificate arn not in acm (#8802)
|
2025-10-01 13:55:26 -04:00 |
|
Hugo Pereira Brito
|
cdb455b2b1
|
feat(aws): add new check ec2_instance_with_outdated_ami (#6910)
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
|
2025-09-30 13:54:36 -04:00 |
|
MustafaAamir
|
2a4b62527a
|
fix(tests_iam): AWS managed policies are isolated (#8609)
Co-authored-by: MustafaAamir <mustafa@gmail.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2025-09-30 13:44:03 +05:45 |
|
dependabot[bot]
|
52ddaca4c5
|
chore(deps-dev): bump moto from 5.0.28 to 5.1.11 (#7100)
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
|
2025-09-16 14:17:47 +02:00 |
|
Prowler Bot
|
ec27451199
|
chore(regions_update): Changes in regions for AWS services (#8728)
Co-authored-by: prowler-bot <179230569+prowler-bot@users.noreply.github.com>
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
|
2025-09-15 15:02:37 +02:00 |
|
Daniel Barranquero
|
b512f6c421
|
fix(firehose): false positive in firehose_stream_encrypted_at_rest (#8599)
Co-authored-by: Sergio Garcia <hello@mistercloudsec.com>
|
2025-09-11 09:55:16 -04:00 |
|
Daniel Barranquero
|
74bf0e6b47
|
fix(aws): nonetype errors in opensearch, firehose and cognito (#8670)
|
2025-09-09 13:12:57 +05:45 |
|
Daniel Barranquero
|
7916425ed4
|
fix(memorydb): handle clusters with no security groups (#8666)
|
2025-09-08 15:05:13 -04:00 |
|
Samuele Pasini
|
1884874ab6
|
fix: typo ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_* CheckID (#8294)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2025-09-05 13:16:12 +02:00 |
|
Pedro Martín
|
79450d6977
|
fix(securityhub): resolve TypeError from Python3.9 (#8619)
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com>
|
2025-09-03 17:52:09 +02:00 |
|
Daniel Barranquero
|
3b42eb3818
|
fix(s3): resource metadata error in s3_bucket_shadow_resource_vulnerability (#8572)
|
2025-08-26 13:30:49 +02:00 |
|
Sergio Garcia
|
ea6d04ed3a
|
chore(securityhub): add static credentials and role assumption support (#8539)
Co-authored-by: Adrián Jesús Peña Rodríguez <adrianjpr@gmail.com>
|
2025-08-22 11:58:35 +02:00 |
|
Sergio Garcia
|
30518f2e0e
|
feat(aws): new check eks_cluster_deletion_protection_enabled (#8536)
|
2025-08-19 10:25:24 +02:00 |
|
Andoni Alonso
|
2f5fce41dc
|
feat(iam): remove standalone iam:PassRole from privesc detection and add missing patterns (#8530)
|
2025-08-18 11:35:14 +02:00 |
|
Andoni Alonso
|
39e4d20b24
|
feat(iam): add Bedrock AgentCore privilege escalation combo (#8526)
|
2025-08-15 13:25:15 +02:00 |
|
Hugo Pereira Brito
|
f5b1532647
|
fix(kafka): false positives in kafka_cluster_is_public check (#8514)
|
2025-08-13 09:05:09 +02:00 |
|
Pepe Fagoaga
|
260fada3eb
|
fix(s3): Use HeadBucket instead of GetBucketLocation (#8456)
|
2025-08-06 19:20:52 +05:45 |
|
Adrián Jesús Peña Rodríguez
|
581afd38e6
|
fix: add default values for S3 class (#8417)
Co-authored-by: Pedro Martín <pedromarting3@gmail.com>
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
|
2025-08-01 13:50:51 +02:00 |
|
Paul Negedu
|
2170fbb1ab
|
feat(aws): add s3_bucket_shadow_resource_vulnerability check (#8398)
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
|
2025-08-01 18:26:03 +08:00 |
|
Sergio Garcia
|
7ec514d9dd
|
feat(aws): new check bedrock_api_key_no_long_term_credentials (#8396)
|
2025-07-30 17:04:16 +08:00 |
|
Aviad Levy
|
a85b89ffb5
|
fix(ec2): add check that protocol is matched in security group checks (#8374)
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
|
2025-07-28 19:53:08 +08:00 |
|
Kay Agahd
|
d4e66c4a6f
|
chore(sqs): clean up code (#8366)
|
2025-07-25 20:10:34 +08:00 |
|
Andoni Alonso
|
04749c1da1
|
fix(aws): sns_topics_not_publicly_accessible false positive with aws:SourceArn conditions (#8340)
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
|
2025-07-24 18:03:30 +08:00 |
|