 JuneandDaniel Barranquero
|
1f39b01fb2
|
feat(sagemaker): add sagemaker_domain_sso_configured check (#11094)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-05-14 11:42:30 +02:00 |
|
Hugo Pereira Brito
|
739be07077
|
chore(aws): skip unattached IAM policies unless --scan-unused-services (#11150)
|
2026-05-14 08:10:20 +01:00 |
|
Daniel Barranquero
|
759f7b84d6
|
feat(aws): add cloudtrail_bedrock_logging_enabled security check (#10858)
|
2026-05-11 17:11:49 +02:00 |
|
 Hugo Pereira BritoandHugo P.Brito
|
0b26c1a39c
|
feat(aws): add iam_user_access_not_stale_to_sagemaker security check (#11000)
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home>
|
2026-05-11 16:34:18 +02:00 |
|
Daniel Barranquero
|
73c0305dc4
|
feat(aws): add bedrock_prompt_encrypted_with_cmk security check (#10905)
|
2026-05-11 10:32:44 +02:00 |
|
Pepe Fagoaga
|
21d7d08b4b
|
fix(timeline): Return a compact actor name from CloudTrail events (#10986)
|
2026-05-04 19:39:17 +02:00 |
|
Daniel Barranquero
|
921f49a0de
|
feat(aws): add bedrock_prompt_management_exists security check (#10878)
|
2026-05-04 12:38:15 +02:00 |
|
 Danny LyubenovandDaniel Barranquero
|
c802dc8a36
|
feat(codebuild): use batched API calls to prevent throttling and false positives (#10639)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-04-30 17:19:21 +02:00 |
|
Pepe Fagoaga
|
36b8aa1b79
|
fix(boto3): pass config to clients (#10944)
|
2026-04-30 14:11:29 +02:00 |
|
Josema Camacho
|
9297453b8a
|
fix(sdk): add autouse mock_aws fixture and leak detector to prevent AWS test leaks (#10605)
|
2026-04-29 17:49:40 +02:00 |
|
Hugo Pereira Brito
|
380b89cfb6
|
fix(sdk): cover CNAME → dangling S3 in route53 takeover check (#10920)
|
2026-04-29 11:14:33 +01:00 |
|
Daniel Barranquero
|
8b368e1343
|
feat(aws): add bedrock_guardrails_configured security check (#10844)
|
2026-04-28 14:16:19 +02:00 |
|
Pepe Fagoaga
|
7df2703db1
|
fix(aws): get organization's metadata with assumed role (#10894)
|
2026-04-27 22:15:11 +01:00 |
|
Kay Agahd
|
67234210ba
|
feat(aws): add check secretsmanager_has_restrictive_resource_policy (#6985)
|
2026-04-27 21:49:34 +01:00 |
|
Pepe Fagoaga
|
f2c5d2ec87
|
fix(aws): fallback lookup events to resource name (#10828)
|
2026-04-21 18:31:50 +02:00 |
|
Daniel Barranquero
|
43913b1592
|
feat(aws): support excluding regions from scans via CLI, env var, and config (#10688)
|
2026-04-15 17:59:46 +02:00 |
|
Daniel Barranquero
|
0f4d8ff891
|
feat(aws): add bedrock_vpc_endpoints_configured security check (#10591)
|
2026-04-14 12:22:22 +02:00 |
|
 Daniel BarranqueroandHugo P.Brito
|
d1ab8b8ae5
|
feat(aws): add iam_policy_no_wildcard_marketplace_subscribe and iam_inline_policy_no_wildcard_marketplace_subscribe checks (#10525)
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com>
|
2026-04-14 12:08:40 +02:00 |
|
Daniel Barranquero
|
65e9593b41
|
feat(aws): add bedrock_access_not_stale security check (#10536)
|
2026-04-14 11:20:40 +02:00 |
|
Daniel Barranquero
|
131112398b
|
feat(aws): add bedrock_full_access_policy_attached security check (#10577)
|
2026-04-14 11:00:40 +02:00 |
|
 Avula Jeevan YadavandAndoni A.
|
b898f257f1
|
feat(stepfunctions): add check for secrets in state machine definition (#10570)
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2026-04-09 15:56:29 +02:00 |
|
 Kay AgahdandClaude Opus 4.6
|
89fe867944
|
fix(aws): recognize service-specific condition keys as restrictive in is_policy_public (#10600)
Co-authored-by: Claude Opus 4.6 <noreply@anthropic.com>
|
2026-04-08 10:55:55 +02:00 |
|
 Pepe FagoagaandAndoni Alonso
|
2be2753c55
|
fix(codeartifact): only retrieve the latest version from a package (#10243)
Co-authored-by: Andoni Alonso <14891798+andoniaf@users.noreply.github.com>
|
2026-04-08 09:21:19 +02:00 |
|
Josema Camacho
|
283259f34c
|
fix(sdk): resolve empty-set bug in _enabled_regions causing 36-region client creation and CI timeouts (#10598)
|
2026-04-08 08:40:58 +02:00 |
|
 
|
041f95b3df
|
feat(ec2): add check for SG ingress from public IPs to any port (#10335)
Co-authored-by: Raajhesh Kannaa Chidambaram <495042+raajheshkannaa@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-26 17:21:16 +01:00 |
|
 Sandiyo ChristanandDaniel Barranquero
|
834d1bca49
|
feat(awslambda): enrich Function model with inventory fields and add 3 security checks (#10381)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-26 10:33:39 +01:00 |
|
Pepe Fagoaga
|
571141f57c
|
fix(aws): set partition's region for global services (#10458)
|
2026-03-25 15:47:51 +01:00 |
|
 
|
6100932c60
|
feat(glue): add check for plaintext secrets in ETL job arguments (#10368)
Co-authored-by: Raajhesh Kannaa Chidambaram <495042+raajheshkannaa@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-25 12:25:36 +01:00 |
|
 McRolly NWANGWUandPepe Fagoaga
|
833f3779ef
|
feat(cloudfront): detect Standard Logging v2 via CloudWatch Log Delivery (#10090)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-03-25 10:09:21 +00:00 |
|
 Pawan GambhirandDaniel Barranquero
|
df680ef277
|
fix(route53): resolve false positive in dangling IP check (#9952)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-17 12:02:48 +01:00 |
|
  
|
c9284f8003
|
chore(models): add pydantic validators for CheckMetadata (#8583)
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2026-03-16 10:36:08 +01:00 |
|
 
|
39385567fc
|
feat(organizations): add OU metadata to outputs (#10283)
Co-authored-by: Raajhesh Kannaa Chidambaram <495042+raajheshkannaa@users.noreply.github.com>
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-11 16:41:44 +01:00 |
|
 Michael WentzandDaniel Barranquero
|
c4d692f77b
|
feat(guardduty): add org-wide delegated admin check across all regions (#9867)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-10 12:56:00 +01:00 |
|
 Eran CohenandDaniel Barranquero
|
0b461233c1
|
feat(iam): Add trusted IP configurable option to reduce false positives in 'opensearch' check (#8631)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-03-10 12:12:54 +01:00 |
|
Pepe Fagoaga
|
9c2cb5efa8
|
fix(elbv2): Handle post-quantum (PQ) TLS policies (#10219)
|
2026-03-03 10:18:00 +01:00 |
|
 Harsh MishraandPepe Fagoaga
|
150abce4a8
|
fix(aws): respect AWS_ENDPOINT_URL for STS session creation (#10228)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-03-03 08:25:59 +01:00 |
|
 
|
6962622fd2
|
fix(aws): filter VPC endpoint services by audited account to prevent AccessDenied errors (#10152)
Co-authored-by: Copilot <198982749+Copilot@users.noreply.github.com>
Co-authored-by: jfagoagas <16007882+jfagoagas@users.noreply.github.com>
|
2026-02-24 18:30:31 +01:00 |
|
 
|
90e317d39f
|
fix(kms): detect public access for any KMS action, not just kms:* (#10071)
Co-authored-by: copilot-swe-agent[bot] <198982749+Copilot@users.noreply.github.com>
Co-authored-by: jfagoagas <16007882+jfagoagas@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-02-16 10:12:29 +01:00 |
|
 Hugo Pereira BritoandJosema Camacho
|
cb9ab03778
|
feat(aws): revert Adding check that AWS Auto Scaling group has deletion protection (#9956)
Co-authored-by: Josema Camacho <hello@josema.xyz>
|
2026-02-04 16:53:08 +01:00 |
|
  
|
69818abdd0
|
feat(aws): Adding check that AWS Auto Scaling group has deletion protection (#9928)
Co-authored-by: Serhii Sokolov <serhii.sokolov@automat-it.com>
Co-authored-by: Hugo Pereira Brito <101209179+HugoPBrito@users.noreply.github.com>
Co-authored-by: HugoPBrito <hugopbrit@gmail.com>
|
2026-02-04 13:17:13 +01:00 |
|
 mohd4adilandDaniel Barranquero
|
e97e31c7ca
|
chore(aws): add support for trusted aws accounts in cross account checks for s3, eventbridge bus, eventbridge schema and dynamodb (#9692)
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com>
|
2026-01-29 09:13:34 +01:00 |
|
 Kay AgahdandDaniel Barranquero
|
04e2d15dd2
|
feat(aws): add check rds_instance_extended_support (#9865)
Co-authored-by: Daniel Barranquero <74871504+danibarranqueroo@users.noreply.github.com>
|
2026-01-28 16:49:35 +01:00 |
|
 
|
9e7ecb39fa
|
feat(aws): CloudTrail timeline for findings (#9101)
Co-authored-by: Copilot Autofix powered by AI <62310815+github-advanced-security[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-01-27 13:00:46 +01:00 |
|
 Andoni AlonsoandHugoPBrito
|
6cb0edf3e1
|
feat(aws/codebuild): add check for CodeBreach webhook filter vulnerability (#9840)
Co-authored-by: HugoPBrito <hugopbrit@gmail.com>
|
2026-01-22 15:12:24 +01:00 |
|
 Josema CamachoandAndoni A.
|
847645543a
|
feat(attack-paths): update boto dependencies for catrography compatibility (#9798)
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com>
|
2026-01-15 13:00:54 +01:00 |
|
  
|
429c591819
|
chore(aws): fixup AWS EC2 SG lib (#9216)
Co-authored-by: MrCloudSec <hello@mistercloudsec.com>
Co-authored-by: Sergio Garcia <sergargar1@gmail.com>
Co-authored-by: HugoPBrito <hugopbrit@gmail.com>
|
2026-01-12 13:47:37 +01:00 |
|
 mchennaiandPepe Fagoaga
|
05466cff22
|
test: Add edge case test for s3_bucket_server_access_logging_enabled (#9725)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2026-01-12 10:06:34 +01:00 |
|
 mchennaiandpedrooot
|
4169611a6a
|
test(s3_bucket_server_access_logging_enabled): Add multi-bucket test (#9716)
Co-authored-by: pedrooot <pedromarting3@gmail.com>
|
2026-01-05 11:34:57 +01:00 |
|
 Pedro MartínandPepe Fagoaga
|
8d1d041092
|
chore(aws): support new eusc partition (#9649)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2025-12-23 12:28:10 +01:00 |
|
 Ryan NoletteandPepe Fagoaga
|
81e046ecf6
|
feat(bedrock): API pagination (#9606)
Co-authored-by: Pepe Fagoaga <pepe@prowler.com>
|
2025-12-23 09:06:19 +01:00 |
|