Hugo P.Brito
6cd2ffbca2
feat(m365): add entra_pim_only_management check sharing PIM alert fetch
...
Add the PIM-only management security check on top of the shared
_get_pim_alerts implementation already introduced for the PIM stale
sign-in alert check (#10798 ). Avoid duplicating the service-layer fetch
that the original branch carried with its own beta endpoint + httpx
client; instead, consume the v1.0 unified roleManagement alerts feed via
the dict already populated on entra_client.
Detection logic: look up an active PIM alert whose definition id contains
'RolesAssignedOutsidePim'. FAIL when the alert is active with affected
items, PASS when it exists with no items (or is inactive), and MANUAL
when the alert is unavailable (no Microsoft Entra ID P2, alert disabled,
or insufficient permissions).
Compliance: extend CIS 4.0/6.0 control 5.3.1 and ISO 27001:2022 A.5.16 /
A.5.18 mappings to include this check alongside the stale sign-in alert
counterpart.
2026-05-11 12:55:32 +01:00
Hugo P.Brito
a646c68308
chore(m365): align PIM stale alert check with project formatters and drop test __init__.py
...
Apply poetry's black to entra_service.py so the file matches the
configuration CI's sdk-code-quality job uses. Also remove the redundant
tests/__init__.py for this check; pytest discovers tests by path and the
project convention is to keep test directories package-free.
2026-05-11 12:24:20 +01:00
Hugo P.Brito
b49e49f543
fix(m365): require active PIM stale alert before flagging accounts
...
The PIM alert object exposes an is_active flag that goes False once the
alert condition stops firing, even though the previous number_of_affected_items
count can stick around in the API response. The check was ignoring that
flag, so a tenant whose alert was already resolved or dismissed could
still receive a FAIL based on stale counters.
Gate the FAIL branch on alert.is_active so only currently-firing alerts
produce findings; everything else (resolved alert, inactive with leftover
counts) is reported as PASS. A regression test covers the inactive-with-
counts case to lock the behavior in.
2026-05-11 11:48:46 +01:00
Hugo P.Brito
4cf2207d58
fix(m365): emit a single MANUAL finding when PIM stale alert is unavailable
...
The previous behavior fanned out a FAIL finding for every Organization the
tenant returned whenever the stale sign-in alert was missing from the API
response. That conflates three distinct conditions — no Microsoft Entra ID
P2 license, alert disabled, or insufficient permission — into the same
verdict, penalizes tenants without PIM, and emits N near-duplicate findings
for what is logically a single tenant-level state.
Emit a single MANUAL finding pinned to the first organization instead, with
a status_extended that lists the actionable causes so the operator can
choose what to remediate. MANUAL is the right verdict because the cause may
be legitimate (no P2) rather than misconfiguration.
2026-05-11 11:43:42 +01:00
Hugo P.Brito
6fac51047c
Merge remote-tracking branch 'origin/master' into feat/prowler-846
2026-05-11 11:34:17 +01:00
Daniel Barranquero
73c0305dc4
feat(aws): add bedrock_prompt_encrypted_with_cmk security check ( #10905 )
2026-05-11 10:32:44 +02:00
lydiavilchez
962ebac8e4
feat(googleworkspace): add Gmail consequence-based checks for attachment safety and spoofing ( #10980 )
2026-05-07 16:50:36 +02:00
Hugo Pereira Brito and Hugo P.Brito
2c5d47a8cd
chore: route vulnerability references to canonical URLs ( #10853 )
...
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home >
2026-05-07 15:28:50 +01:00
bcaa6ac488
fix(sdk): scan every Azure subscription when display names collide ( #10718 )
...
Co-authored-by: Rubén De la Torre Vico <ruben@prowler.com >
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-05-07 13:59:38 +02:00
Pedro Martín and César Arroba
e585ae45bd
feat(aws): rename Essential Eight to ASD Essential Eight ( #11054 )
...
Co-authored-by: César Arroba <cesar@prowler.com >
2026-05-06 13:11:29 +02:00
19b602c381
fix(oci): scan identity in known valid region ( #10529 )
...
Co-authored-by: Ronan Chota <ronan.chota@saic.com >
Co-authored-by: Hugo P.Brito <hugopbrit@gmail.com >
2026-05-06 11:19:19 +01:00
Pepe Fagoaga and Andoni A.
7c6d658154
fix(k8s): match RBAC rules by apiGroup, not just core ( #10969 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2026-05-04 19:54:03 +02:00
Pepe Fagoaga
21d7d08b4b
fix(timeline): Return a compact actor name from CloudTrail events ( #10986 )
2026-05-04 19:39:17 +02:00
Daniel Barranquero
921f49a0de
feat(aws): add bedrock_prompt_management_exists security check ( #10878 )
2026-05-04 12:38:15 +02:00
Daniel Barranquero
86449fb99d
chore(vercel): add disclaimer for checks depending on billing plan ( #10663 )
2026-05-04 08:56:50 +02:00
Andoni Alonso
40dd0e640b
fix(sdk): strip http(s):// scheme from image registry URLs ( #10950 )
2026-05-04 08:37:46 +02:00
Danny Lyubenov and Daniel Barranquero
c802dc8a36
feat(codebuild): use batched API calls to prevent throttling and false positives ( #10639 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-04-30 17:19:21 +02:00
Pepe Fagoaga
36b8aa1b79
fix(boto3): pass config to clients ( #10944 )
2026-04-30 14:11:29 +02:00
228fe6d579
feat: add ASD Essential Eight compliance framework for AWS ( #10808 )
...
Co-authored-by: Boon <boon@security8.work >
Co-authored-by: pedrooot <pedromarting3@gmail.com >
2026-04-30 13:49:08 +02:00
Pedro Martín
578186aa40
feat(sdk): integrate universal compliance into CLI pipeline ( #10301 )
2026-04-30 13:49:00 +02:00
Andoni Alonso
4608e45c8a
fix(image): block parser-mismatch SSRF in registry auth ( #10945 )
2026-04-30 12:56:35 +02:00
Josema Camacho
9297453b8a
fix(sdk): add autouse mock_aws fixture and leak detector to prevent AWS test leaks ( #10605 )
2026-04-29 17:49:40 +02:00
Andoni Alonso and Pepe Fagoaga
7076900fb1
fix(kubernetes): use cluster name as provider_uid in OCSF output ( #10483 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2026-04-29 13:45:49 +02:00
Hugo Pereira Brito
380b89cfb6
fix(sdk): cover CNAME → dangling S3 in route53 takeover check ( #10920 )
2026-04-29 11:14:33 +01:00
Davlet Dzhakishev and Daniel Barranquero
1de01bcb78
fix(azure): tighten flow log workspace checks ( #10645 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-04-28 16:57:04 +02:00
Daniel Barranquero
8b368e1343
feat(aws): add bedrock_guardrails_configured security check ( #10844 )
2026-04-28 14:16:19 +02:00
Hugo Pereira Brito
e252058af4
fix(m365): exclude guest users from entra_users_mfa_capable ( #10785 )
2026-04-28 08:58:16 +01:00
Pepe Fagoaga
7df2703db1
fix(aws): get organization's metadata with assumed role ( #10894 )
2026-04-27 22:15:11 +01:00
Kay Agahd
67234210ba
feat(aws): add check secretsmanager_has_restrictive_resource_policy ( #6985 )
2026-04-27 21:49:34 +01:00
Hugo Pereira Brito
3441ad7f70
fix(sdk): align googleworkspace finding resources ( #10901 )
2026-04-27 15:17:29 +01:00
lydiavilchez
013809919c
feat(googleworkspace): add Gmail service with first batch of checks ( #10683 )
2026-04-27 13:49:07 +02:00
Daniel Barranquero
368d9c1519
fix(admincenter): restrict admincenter group visibility check to Unified groups ( #10899 )
2026-04-27 13:23:03 +02:00
Andoni Alonso
b668770480
feat(github): add zizmor GitHub Actions scanning as a service of the GitHub provider ( #10607 )
2026-04-27 08:55:07 +02:00
Pedro Martín and Alan Buscaglia
d4ece2b43e
feat(sdk): add multi-provider compliance framework JSONs ( #10300 )
...
Co-authored-by: Alan Buscaglia <gentlemanprogramming@gmail.com >
2026-04-24 13:27:31 +02:00
Daniel Barranquero
80d62f355f
fix(alibabacloud): fix CS service SDK compatibility and harden Alibaba provider ( #10871 )
2026-04-24 09:26:09 +02:00
Mathisdjango and Daniel Barranquero
927be17fb7
feat(github): add check for dismissing stale PR approvals on default branch (CIS 1.1.4) ( #10569 )
...
Co-authored-by: Daniel Barranquero <danielbo2001@gmail.com >
2026-04-22 16:14:10 +02:00
Andoni Alonso and Pepe Fagoaga
43bd1083e0
feat(sdk): add SARIF output format for IaC provider ( #10626 )
...
Co-authored-by: Pepe Fagoaga <pepe@prowler.com >
2026-04-22 09:32:20 +02:00
Pedro Martín
a24869fc26
feat(sdk): add universal compliance output modules (CSV, OCSF, table) ( #10299 )
2026-04-22 09:01:45 +02:00
Pepe Fagoaga
f2c5d2ec87
fix(aws): fallback lookup events to resource name ( #10828 )
2026-04-21 18:31:50 +02:00
39911e3ab7
feat(github): add --repo-list-file flag for GitHub scanning ( #10501 )
...
Co-authored-by: Raajhesh Kannaa Chidambaram <495042+raajheshkannaa@users.noreply.github.com >
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2026-04-21 15:31:34 +02:00
Pedro Martín
ac6dd03fb8
feat(sdk): add universal compliance schema models and loaders ( #10298 )
2026-04-21 11:39:04 +02:00
Hugo P.Brito
15a5527910
feat(m365): add entra_pim_stale_sign_in_alert security check
...
Add new security check entra_pim_stale_sign_in_alert for m365 provider.
Includes check implementation, metadata, and unit tests.
2026-04-20 14:37:40 +01:00
Andoni Alonso
19c752c127
fix(cloudflare): guard validate_credentials against paginator infinite loops ( #10771 )
2026-04-17 11:23:31 +02:00
Erich Blume and Andoni A.
a2a1a73749
fix(image): --registry-list crashes with AttributeError on global_provider ( #10691 )
...
Co-authored-by: Andoni A. <14891798+andoniaf@users.noreply.github.com >
2026-04-16 13:02:25 +02:00
lydiavilchez
08fbe17e29
fix(googleworkspace): treat secure Google defaults as PASS for Drive checks ( #10727 )
2026-04-16 13:01:55 +02:00
lydiavilchez
d920f78059
fix(googleworkspace): treat secure Google defaults as PASS for Calendar checks ( #10726 )
2026-04-16 12:51:40 +02:00
Daniel Barranquero
43913b1592
feat(aws): support excluding regions from scans via CLI, env var, and config ( #10688 )
2026-04-15 17:59:46 +02:00
Daniel Barranquero
c3acb818d9
fix(vercel): handle team-scoped firewall config responses ( #10695 )
2026-04-15 11:59:20 +02:00
Hugo Pereira Brito and Hugo P.Brito
a82eaa885d
refactor(m365): normalize CA platforms at model level ( #10635 )
...
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home >
2026-04-14 15:00:23 +02:00
Hugo Pereira Brito and Hugo P.Brito
90a619a8b4
feat(m365): add entra_conditional_access_policy_block_unknown_device_platforms security check ( #10615 )
...
Co-authored-by: Hugo P.Brito <hugopbrito@Mac.home >
2026-04-14 14:32:37 +02:00