* fix(aws_profile_loader): New functions
* fix(shellcheck): Temporary remove Shellcheck
* fix(aws_cli_detector): new function
* fix(jq_detector): New function
* fix(os_detector): New function
* fix(output_bucket): Output bucket input check in main
* fix(python_detector): deleted unused python detector
* fix(credentials): credentials check out of whoami
* [break]refactor(main)
* [BREAK] Get list of checks parsing all input options
* [break]refactor(main): execute checks functions
* [break]refactor(main): move functions to libs
* fix(validations): custom check validation and typos
* refactor(validate_options): Include comments
* fix(custom_checks): Minor fixes
* refactor(closing_files): include libraries
* refactor(loader): Include ignored checks
* refactor(main): Fix shellcheck
* refactor(loader): beautify
* refactor(monochrome): without variables
* refactor(modes): MODES array not needed
* refactor(whoami): get error from AWSCLI
* refactor(secrets-detector)
* refactor(secrets-detector)
* fix(html_scoring): html scoring was fixed.
* fix(load_checks_from_file)
* fix(color-code): Print if not mono
* fix(not extra): Fixed if EXCLUDE_CHECK_ID is empty
* fix(IFS): Restore default IFS once modes are parsed
* fix(bucket): validate before whoami
* fix(bucket): validate before whoami
Co-authored-by: n4ch04 <nachor1992@gmail.com>
Co-authored-by: sergargar <sergio@verica.io>
Co-authored-by: Nacho Rivera <59198746+n4ch04@users.noreply.github.com>
* chore(db providers): db providers first version
* chore(db provider): added db provider setup into Readme
* fix(csv_line): csv_line out of conditional
* fix(README): text instead of varchar in table
* fix(help): help message extended
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com>
* fix(typo): Update README.md
Co-authored-by: Pepe Fagoaga <pepe@verica.io>
* fix(table): add if not exists
Co-authored-by: Pepe Fagoaga <pepe@verica.io>
* fix(typo): Readme postgreSQL
Co-authored-by: Pepe Fagoaga <pepe@verica.io>
* fix(db_connector): details to add a new provider
* fix(typo): Uppercase Prowler
Co-authored-by: Toni de la Fuente <toni@blyx.com>
* fix(prowler): deleted unused variable
* chore(checks): test db connector previous to send data
* chore(input tests): input tests moved to main
* fix(typo): Readme typos
* chore(table): table name from pgpass file
* fix(grep test): Added missing -E flag
* chore(table): check of table name and Readme
* chore(error colors): Added error colors
* chore(inputcheck): checks about mode and output inputs into main
* fix(inputs) custom output file name
* fix(outputs): comment profile
* chore(textXXX): both 3 textfunctions using general
* fix(allowlist): allowlist check included as function
* fix(headers): Add headers to certain output files
* fix(reformulate): change structure and delete comments
* fix(testing): Input test after load includes
* fix(variables): Added named vars
* fix(colors): Deleted unused colors
* fix(outputs): fine tuning
* fix(outputs): allowlist parameters read
* fix(allowlist): allowlist logic reformulated
* fix(REPREGION): REPREGION change by REGION_FROM_CHECK
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@verica.io>
Co-authored-by: Toni de la Fuente <toni@blyx.com>
Rearrange output functions so they support outputting text alongside other formats, if specified
Add a convenience function for checking if JUnit output is enabled
Move monochrome setting into loop so it better supports multiple formats
Update README
- Move Security Hub related code to a dedicated include/securityhub_integration file
- Check that Security Hub is enabled in the target region before beginning checks when -S is specified
- Add error handling to the batch-import-findings call
- Add CHECK_ASFF_TYPE variables to all CIS checks to override the default
- Add support for CHECK_ASFF_RESOURCE_TYPE variables which override the default 'AwsAccount' value for the resource a finding relates to.
- Add CHECK_ASFF_RESOURCE_TYPE variables to all checks where there is a suitable value in the schema
- Remove json-asff output for info messages as they are not appropriate for possible submission to Security Hub
- Update the README to cover Security Hub integration
- Add an IAM policy JSON document that provides the necessary BatchImportFindings permission for Security Hub
- Remove trailing whitespace and periods in pass/fail messages to be consistent with the majority of messages, to prevent future tidy-up from changing the finding IDs
json-asff mode outputs JSON, similar to the standard 'json' mode with one check per line, but in AWS Security Finding Format - used by AWS Security Hub
Currently uses a generic Type, Resources and ProductArn value, but sets the Id to a unique value that includes the details of the message, in order to separate out checks that run against multiple resources and output one result per resource per check. This ensures that findings can be updated, should the resource move in or out of compliance
securityhub mode generates the ASFF JSON and then passes it to an 'aws securityhub batch-import-findings' call, once per resource per check. Output to the screen is similar to the standard mode, but prints whether or not the finding was submitted successfully
Fixes#524