github-actions
9b6ed45e0f
chore(release): 3.8.1
2023-08-10 11:51:13 +00:00
Pepe Fagoaga
9340ae43f3
fix(ds): Restore enums without optional ( #2704 )
2023-08-10 13:43:31 +02:00
Sergio Garcia
552024c53e
fix(Enum): handle Enum classes correctly ( #2702 )
2023-08-10 13:21:24 +02:00
Pepe Fagoaga
3aba71ad2f
docs(aws-orgs): Update syntax ( #2703 )
2023-08-10 12:40:17 +02:00
christiandavilakoobin
ade511df28
fix(sns): allow default SNS policy with SourceOwner ( #2698 )
...
Co-authored-by: Azure Pipeplines CI <monitor@koobin.com >
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-08-10 12:13:57 +02:00
Sergio Garcia
fc650214d4
fix(security hub): include custom output filename in resolve_security_hub_previous_findings ( #2687 )
2023-08-10 12:11:10 +02:00
Sergio Garcia
8266fd0c6f
chore(print): prettify prints of listings and logs ( #2699 )
2023-08-10 12:08:07 +02:00
Pepe Fagoaga
f4308032c3
fix(cloudfront): fix ViewerProtocolPolicy and GeoRestrictionType ( #2701 )
2023-08-10 12:02:49 +02:00
Sergio Garcia
1e1f445ade
chore(regions_update): Changes in regions for AWS services. ( #2700 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-08-10 11:29:05 +02:00
Pepe Fagoaga
d41b0332ac
feat(athena): New AWS Athena service + 2 workgroup checks ( #2696 )
2023-08-10 10:23:17 +02:00
Pepe Fagoaga
7258466572
fix(iam): password policy expiration ( #2694 )
2023-08-10 10:10:20 +02:00
Pepe Fagoaga
76db92ea14
chore(service): service class type hints ( #2695 )
2023-08-10 10:01:54 +02:00
Sergio Garcia
ad3cd66e08
docs(organizations): fix script and improve titles ( #2693 )
2023-08-10 09:56:47 +02:00
Sergio Garcia
22f8855ad7
chore(regions_update): Changes in regions for AWS services. ( #2692 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-08-09 11:23:28 +02:00
Sergio Garcia
36e095c830
fix(iam_role_cross_service_confused_deputy_prevention): add ResourceAccount and PrincipalAccount conditions ( #2689 )
2023-08-09 10:41:48 +02:00
Sergio Garcia
887cac1264
fix(typo): spelling typo in organizations_scp_check_deny_regions ( #2691 )
2023-08-09 10:24:29 +02:00
Pepe Fagoaga
13059e0568
fix(ec2-securitygroups): Handle IPv6 public ( #2690 )
2023-08-09 10:08:30 +02:00
Pepe Fagoaga
9e8023d716
fix(config): Pass a configuration file using --config-file config.yaml ( #2679 )
2023-08-09 09:52:45 +02:00
Sergio Garcia
c54ba5fd8c
chore(regions_update): Changes in regions for AWS services. ( #2688 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-08-09 09:34:52 +02:00
dependabot[bot]
db80e063d4
build(deps-dev): bump pylint from 2.17.4 to 2.17.5 ( #2685 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-08 10:48:42 +02:00
dependabot[bot]
b6aa12706a
build(deps): bump mkdocs from 1.4.3 to 1.5.2 ( #2684 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-08 10:22:20 +02:00
Chris Farris
c1caf6717d
fix(organizations): request Organization Info after assume_role occurs ( #2682 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-08-07 15:17:05 +02:00
Pepe Fagoaga
513fd9f532
fix(iam-dynamodb): Handle errors ( #2680 )
2023-08-07 10:04:19 +02:00
Pepe Fagoaga
bf77f817cb
chore(azure): Improve AzureService class with __set_clients__ ( #2676 )
2023-08-04 13:04:05 +02:00
Sergio Garcia
e0bfef2ece
chore(regions_update): Changes in regions for AWS services. ( #2677 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-08-04 12:10:19 +02:00
Sergio Garcia
4a87f908a8
chore(release): update Prowler Version to 3.8.0 ( #2674 )
...
Co-authored-by: github-actions <noreply@github.com >
2023-08-03 18:34:23 +02:00
Sergio Garcia
16d95e5155
chore(readme): update providers summary table ( #2673 )
2023-08-03 16:45:09 +02:00
Pepe Fagoaga
1797b54259
test(azure): Storage Service ( #2672 )
2023-08-03 15:07:17 +02:00
Pepe Fagoaga
f289c8fb2e
test(azure): SQL Server Service ( #2671 )
2023-08-03 14:43:18 +02:00
Pepe Fagoaga
e4ad881a69
test(azure): IAM service ( #2670 )
2023-08-03 14:15:34 +02:00
Pepe Fagoaga
138bca38e7
test(azure): Defender service ( #2669 )
2023-08-03 13:52:55 +02:00
edurra
44f7af3580
feat(azure): add Azure SQL Server service and 3 checks ( #2665 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-08-03 11:29:17 +02:00
Sergio Garcia
2d832bca15
feat(gcp): Improve gcp performance ( #2662 )
2023-08-03 10:52:52 +02:00
Pepe Fagoaga
efa75a62e3
fix(iam_policy_allows_privilege_escalation): Handle permissions in groups ( #2655 )
2023-08-03 10:40:51 +02:00
Pepe Fagoaga
5763bca317
refactor(vpc_endpoint_connections_trust_boundaries) ( #2667 )
2023-08-03 09:56:09 +02:00
Pepe Fagoaga
c335334402
fix(test_only_aws_service_linked_roles): Flaky test ( #2666 )
2023-08-03 09:18:06 +02:00
Pepe Fagoaga
5bf3f70717
fix(vpc_endpoint_connections_trust_boundaries): Handle AWS Account ID as Principal ( #2611 )
2023-08-03 09:16:58 +02:00
Pepe Fagoaga
92c8a440ea
feat(gcp): Add internet-exposed and encryption categories ( #2663 )
2023-08-02 15:53:12 +02:00
Pepe Fagoaga
b92d8a014c
fix(cryptography): Update to 41.0.3 ( #2661 )
2023-08-02 11:47:51 +02:00
Sergio Garcia
aced44f051
fix(sns): handle topic policy conditions ( #2660 )
2023-08-02 11:45:27 +02:00
Sergio Garcia
49c9d2b077
chore(regions_update): Changes in regions for AWS services. ( #2658 )
2023-08-02 11:32:11 +02:00
Pepe Fagoaga
61beacf085
fix(docs): Azure auth and Slack integration ( #2659 )
2023-08-02 11:18:45 +02:00
Pepe Fagoaga
02f432238e
fix(outputs): Not use reserved keyword list as variable ( #2657 )
2023-08-02 09:00:04 +02:00
Sergio Garcia
864d178e01
chore(regions_update): Changes in regions for AWS services. ( #2654 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-08-01 11:52:02 +02:00
Sergio Garcia
78f0b823a9
fix(s3_bucket_level_public_access_block): check s3 public access block at account level ( #2653 )
2023-08-01 11:24:58 +02:00
dependabot[bot]
26cdc7a0ee
build(deps-dev): bump flake8 from 6.0.0 to 6.1.0 ( #2651 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-08-01 10:59:58 +02:00
dependabot[bot]
5e773f1eee
build(deps): bump azure-mgmt-authorization from 3.0.0 to 4.0.0 ( #2652 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-01 10:18:56 +02:00
dependabot[bot]
4a7ac7df22
build(deps-dev): bump moto from 4.1.13 to 4.1.14 ( #2650 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-01 10:03:03 +02:00
dependabot[bot]
5250670d5d
build(deps): bump google-api-python-client from 2.94.0 to 2.95.0 ( #2649 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-01 09:49:51 +02:00
Gabriel Pragin
de4a825db8
fix(metadata): Typos ( #2646 )
2023-08-01 09:07:23 +02:00
dependabot[bot]
c256419144
build(deps): bump mkdocs-material from 9.1.19 to 9.1.20 ( #2648 )
2023-08-01 08:58:32 +02:00
Pepe Fagoaga
7bdca0420e
fix(cloudtrail): Set status to INFO when trail is outside the audited account ( #2643 )
2023-07-31 17:50:21 +02:00
Pepe Fagoaga
3aa1fbced9
feat(azure_service): New parent class ( #2642 )
2023-07-31 16:03:49 +02:00
Pepe Fagoaga
dbbb70027a
feat(gcp_service): Parent class ( #2641 )
2023-07-31 15:01:25 +02:00
Pepe Fagoaga
b4e78d28f8
fix(test): mock VPC client ( #2640 )
2023-07-31 11:19:15 +02:00
Pepe Fagoaga
e3d4e38a59
feat(aws): New AWSService class as parent ( #2638 )
2023-07-31 11:18:54 +02:00
Pepe Fagoaga
386f558eae
fix(ec2_instance_secrets_user_data): Include line numbers in status ( #2639 )
2023-07-31 10:33:34 +02:00
Sergio Garcia
e08424d3a3
chore(regions_update): Changes in regions for AWS services. ( #2637 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-31 09:54:44 +02:00
Chris Farris
03ad403e7a
feat(s3): Add checks for publicly listable Buckets or writable buckets by ACL ( #2628 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-07-31 08:35:18 +02:00
Sergio Garcia
4a674aae99
chore(regions_update): Changes in regions for AWS services. ( #2634 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-28 11:34:30 +02:00
Pepe Fagoaga
8ee3744027
chore(security-hub): Explain Unique ID ( #2631 )
2023-07-27 13:39:12 +02:00
Gabriel Pragin
965327e801
chore(typos): Update check's status ( #2629 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-07-27 11:44:09 +02:00
Sergio Garcia
f82ea43324
chore(regions_update): Changes in regions for AWS services. ( #2630 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-27 11:31:45 +02:00
Pepe Fagoaga
a5c63845b4
test: security groups ( #2627 )
2023-07-26 16:29:27 +02:00
Sergio Garcia
034faa72cf
chore(release): update Prowler Version to 3.7.2 ( #2625 )
...
Co-authored-by: github-actions <noreply@github.com >
2023-07-26 13:37:31 +02:00
Sergio Garcia
9bcd617964
chore(ec2): add SG name to resource_details ( #2495 )
2023-07-26 13:12:36 +02:00
Sergio Garcia
0db975dc7b
fix(pypi-release): solve GH action for release ( #2624 )
2023-07-26 13:03:34 +02:00
Pepe Fagoaga
a51fa7703b
fix(security): certifi issue ( #2623 )
2023-07-26 12:45:07 +02:00
Sergio Garcia
69fad0009d
fix(ec2_ami_public): correct check metadata and logic ( #2618 )
2023-07-26 10:34:04 +02:00
Sergio Garcia
e721251936
fix(compute): solve key errors in compute service ( #2610 )
2023-07-26 08:49:09 +02:00
Pepe Fagoaga
2fe767e3e5
fix(ecs_task_def_secrets): Improve description to explain findings ( #2621 )
2023-07-25 18:26:22 +02:00
Sergio Garcia
6328ef4444
fix(guardduty): handle disabled detectors in guardduty_is_enabled ( #2616 )
2023-07-25 12:26:37 +02:00
dependabot[bot]
50b8e084e7
build(deps): bump google-api-python-client from 2.93.0 to 2.94.0 ( #2614 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-25 09:37:10 +02:00
dependabot[bot]
3d88544feb
build(deps): bump mkdocs-material from 9.1.18 to 9.1.19 ( #2615 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-25 09:10:01 +02:00
dependabot[bot]
62e602c32e
build(deps): bump pydantic from 1.10.11 to 1.10.12 ( #2613 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-25 08:55:43 +02:00
Pepe Fagoaga
47a82560ea
fix(s3): __get_object_lock_configuration__ warning logs ( #2608 )
2023-07-24 10:49:50 +02:00
Pepe Fagoaga
f7bbcc98b3
docs(boto3-configuration): format list ( #2609 )
2023-07-24 10:47:55 +02:00
Sergio Garcia
98a587aa15
chore(regions_update): Changes in regions for AWS services. ( #2606 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-23 18:30:30 +02:00
Sergio Garcia
d2e34c42fd
chore(regions_update): Changes in regions for AWS services. ( #2599 )
2023-07-18 17:38:43 +02:00
dependabot[bot]
605b07901e
build(deps): bump google-api-python-client from 2.92.0 to 2.93.0 ( #2597 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-18 10:52:26 +02:00
dependabot[bot]
18f02fac68
build(deps-dev): bump moto from 4.1.12 to 4.1.13 ( #2598 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-07-18 10:37:34 +02:00
Pepe Fagoaga
28ea37f367
test(aws_provider): Role and User MFA ( #2486 )
2023-07-18 09:36:37 +02:00
Gabriel Pragin
65a737bb58
chore(metadata): Typos ( #2595 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-07-18 09:27:58 +02:00
dependabot[bot]
7423cd2f93
build(deps): bump azure-storage-blob from 12.16.0 to 12.17.0 ( #2596 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-18 09:25:51 +02:00
Gabriel Pragin
babd026351
chore(metadata): Typos ( #2594 )
2023-07-17 22:28:24 +02:00
Sergio Garcia
dd6e5a9029
fix(security): solve dependabot security alert ( #2592 )
2023-07-17 12:03:35 +02:00
Pepe Fagoaga
02519a4429
fix(assume_role): Set the AWS STS endpoint region ( #2587 )
2023-07-17 10:09:48 +02:00
Pepe Fagoaga
6575121b7a
fix(ssm_incidents): Handle empty name ( #2591 )
2023-07-17 09:20:44 +02:00
Pepe Fagoaga
5b66368f0d
fix(opensearch): log exception as WARNING ( #2581 )
2023-07-17 09:18:42 +02:00
Sergio Garcia
971c6720e4
chore(regions_update): Changes in regions for AWS services. ( #2590 )
2023-07-16 21:56:21 +02:00
Sergio Garcia
3afccc279f
chore(regions_update): Changes in regions for AWS services. ( #2588 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-14 11:34:21 +02:00
Nacho Rivera
8f015d0672
fix(allowlist): single account checks handling ( #2585 )
...
Co-authored-by: thomscode <thomscode@gmail.com >
2023-07-14 09:55:27 +02:00
Pepe Fagoaga
f33b96861c
release: v3.7.1 ( #2578 )
2023-07-13 16:48:18 +02:00
Sergio Garcia
9832ce2ff9
chore(regions_update): Changes in regions for AWS services. ( #2580 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-13 12:34:16 +02:00
Kay Agahd
490cbbaa48
docs: typos in README.md ( #2579 )
2023-07-13 07:34:27 +02:00
Nacho Rivera
d1c91093e2
feat(cond parser): add policy cond parser & apply in sqs public check ( #2575 )
2023-07-12 15:39:01 +02:00
Nacho Rivera
66fe101ccd
fix(allowlist): handle wildcard in account field ( #2577 )
2023-07-12 14:22:42 +02:00
Pepe Fagoaga
7ab8c6b154
fix(iam): Handle NoSuchEntityException when calling list_attached_role_policies ( #2571 )
2023-07-12 12:48:57 +02:00
Sergio Garcia
73017b14c3
chore(regions_update): Changes in regions for AWS services. ( #2574 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-12 11:17:00 +02:00
Sergio Garcia
f55495cd6a
chore(regions_update): Changes in regions for AWS services. ( #2572 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-11 11:45:43 +02:00
dependabot[bot]
e97146b5a3
build(deps): bump google-api-python-client from 2.91.0 to 2.92.0 ( #2570 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-11 11:45:21 +02:00
dependabot[bot]
58f056c76d
build(deps-dev): bump openapi-spec-validator from 0.5.7 to 0.6.0 ( #2569 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-11 11:16:23 +02:00
dependabot[bot]
338bbc7a1f
build(deps): bump pydantic from 1.10.9 to 1.10.11 ( #2568 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-11 09:59:01 +02:00
dependabot[bot]
4ba54738a9
build(deps): bump boto3 from 1.26.161 to 1.26.165 ( #2566 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-07-11 09:37:29 +02:00
Toni de la Fuente
235fd2adc4
docs: Update Compliance in README ( #2563 )
2023-07-11 09:12:11 +02:00
Toni de la Fuente
b15d518c94
feat(compliance): CIS Benchmark 2.0 for AWS ( #2562 )
2023-07-11 09:12:03 +02:00
dependabot[bot]
021e1c122c
build(deps-dev): bump pytest-randomly from 3.12.0 to 3.13.0 ( #2567 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-11 09:07:05 +02:00
Sergio Garcia
014b0dd6f6
chore(regions_update): Changes in regions for AWS services. ( #2561 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-10 08:28:09 +02:00
Sergio Garcia
f9f68f9b86
chore(regions_update): Changes in regions for AWS services. ( #2560 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-07 11:34:53 +02:00
Pepe Fagoaga
11a8ba131a
test(outputs): Remove debug ( #2559 )
2023-07-07 10:14:47 +02:00
Sergio Garcia
858de64f8e
chore(release): version 3.7.0 ( #2558 )
2023-07-06 21:17:21 +02:00
Sergio Garcia
676e60afb7
feat(gcp): add CIS checks ( #2544 )
2023-07-06 17:01:56 +02:00
Nacho Rivera
b1968f3f8b
fix(allowlist): reformat allowlist logic ( #2555 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-07-06 15:33:32 +02:00
Sergio Garcia
d2d077afaa
chore(regions_update): Changes in regions for AWS services. ( #2557 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-06 11:29:50 +02:00
Nacho Rivera
7097ca401d
feat(lambda allowlist): mapping lambda/awslambda in allowlist ( #2554 )
2023-07-05 11:49:42 +02:00
Antoine Cichowicz
73e9a1eb9e
docs: Update Amazon Linux 2 installation ( #2553 )
2023-07-05 07:54:18 +02:00
Nacho Rivera
0439d455fb
fix(reporting docs): fix S3 reporting desc ( #2551 )
2023-07-04 12:43:39 +02:00
Sergio Garcia
d57f665a78
docs(allowlist): update DynamoDB allowlist example ( #2552 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-07-04 11:55:33 +02:00
dependabot[bot]
859c731a13
build(deps): bump google-api-python-client from 2.90.0 to 2.91.0 ( #2548 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-04 11:08:13 +02:00
Sergio Garcia
2e7613ddec
docs(OCSF): add docs for OCSF output ( #2550 )
2023-07-04 10:37:42 +02:00
dependabot[bot]
57e9436783
build(deps): bump botocore from 1.29.161 to 1.29.165 ( #2547 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-04 10:23:03 +02:00
dependabot[bot]
2f153fda2e
build(deps): bump mkdocs-material from 9.1.17 to 9.1.18 ( #2546 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-04 09:02:25 +02:00
dependabot[bot]
cbcb5905a3
build(deps): bump boto3 from 1.26.156 to 1.26.161 ( #2545 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-04 08:46:49 +02:00
Sergio Garcia
6a2fb37615
fix(bigquery_dataset_public_access): handle status correctly ( #2542 )
2023-07-03 13:01:51 +02:00
Nacho Rivera
6403feaff9
fix(cloudwatch secrets): fix nonetype error handling ( #2543 )
2023-07-03 12:52:46 +02:00
Sergio Garcia
47736910ca
fix(list-checks): handle listing checks when -s ( #2540 )
2023-07-03 11:48:40 +02:00
Sergio Garcia
ead592a0bf
chore(regions_update): Changes in regions for AWS services. ( #2539 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-07-03 11:22:43 +02:00
Nacho Rivera
d5bdba9244
feat(lambda service): mapping lambda service to awslambda ( #2538 )
2023-07-03 11:19:02 +02:00
Sergio Garcia
4f033cec8d
feat(MITRE): add MITRE ATT&CK framework for AWS ( #2537 )
2023-06-30 12:24:05 +02:00
sssalim-aws
a58f4b2498
feat(compliance): AWS Well-Architected Framework Reliability Pillar v0.1 ( #2536 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-06-29 11:13:38 +02:00
Sergio Garcia
01522ed8c7
feat(ENS): complete ENS Compliance Framework mapping ( #2534 )
2023-06-27 15:22:25 +02:00
Sergio Garcia
fa99ee9d5b
feat(allowlist): add exceptions to allowlist ( #2527 )
2023-06-27 12:57:18 +02:00
Sergio Garcia
6efe634850
fix(iam): add StringLike condition in iam_role_cross_service_confused_deputy_prevention ( #2533 )
2023-06-27 10:06:46 +02:00
dependabot[bot]
60a1497eaf
build(deps-dev): bump moto from 4.1.11 to 4.1.12 ( #2530 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-27 09:07:44 +02:00
dependabot[bot]
1d0cbc08df
build(deps): bump google-api-python-client from 2.89.0 to 2.90.0 ( #2531 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-27 08:36:41 +02:00
dependabot[bot]
4d4280033b
build(deps-dev): bump pytest from 7.3.2 to 7.4.0 ( #2532 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-27 07:55:26 +02:00
dependabot[bot]
fd58775cae
build(deps): bump mkdocs-material from 9.1.16 to 9.1.17 ( #2529 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-27 07:39:58 +02:00
dependabot[bot]
ccb0e93da2
build(deps): bump botocore from 1.29.156 to 1.29.161 ( #2528 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-27 07:19:22 +02:00
Sergio Garcia
c2a05da908
chore(ec2): reduce noise in Security Groups checks ( #2525 )
2023-06-23 15:06:09 +02:00
Sergio Garcia
e1da9e60fc
chore(region): add get_default_region function in AWS Services ( #2524 )
2023-06-23 14:10:49 +02:00
Sergio Garcia
d044e535e0
fix(compliance): add version to ISO27001 ( #2523 )
2023-06-21 17:04:08 +02:00
Sergio Garcia
293560dcd4
fix(contrib): migrate multi-account-securityhub/run-prowler-securityhub.sh to v3 ( #2503 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-06-21 15:18:02 +02:00
Sergio Garcia
90ebb815d5
fix(security hub): solve Security Hub format requirements ( #2520 )
2023-06-21 13:04:14 +02:00
Sergio Garcia
3d3d418ee6
chore(regions_update): Changes in regions for AWS services. ( #2522 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-06-21 11:32:35 +02:00
Pedro Martín
f875cd05be
feat(compliance): add ISO27001 compliance framework ( #2517 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-06-20 16:57:28 +02:00
Sergio Garcia
435911489f
fix(gcp): update Prowler SDK info of GCP ( #2515 )
2023-06-20 14:32:24 +02:00
Sergio Garcia
5fcfcd53aa
fix(compliance): remove unnecessary Optional attributes ( #2514 )
2023-06-20 14:22:13 +02:00
dependabot[bot]
bc09215aad
build(deps): bump boto3 from 1.26.147 to 1.26.156 ( #2511 )
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-06-20 10:36:53 +02:00
dependabot[bot]
5f7e109e3d
build(deps-dev): bump openapi-spec-validator from 0.5.6 to 0.5.7 ( #2507 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-20 09:44:30 +02:00
Nacho Rivera
b75a5050d7
fix(apigw): Update metadata for API GW checks ( #2512 )
2023-06-20 09:22:00 +02:00
dependabot[bot]
be497f7083
build(deps): bump google-api-python-client from 2.88.0 to 2.89.0 ( #2510 )
2023-06-20 08:40:41 +02:00
dependabot[bot]
0ccae3e15b
build(deps): bump mkdocs-material from 9.1.15 to 9.1.16 ( #2508 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-20 08:08:17 +02:00
dependabot[bot]
d736c32aec
build(deps): bump botocore from 1.29.152 to 1.29.156 ( #2506 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-20 07:41:30 +02:00
Sergio Garcia
8ea5ba5d3f
chore(OCSF): improve OCSF logic ( #2502 )
2023-06-19 12:37:04 +02:00
Nacho Rivera
60c341befd
fix(vpc): handle ephemeral VPC endpoint services ( #2501 )
2023-06-19 12:23:52 +02:00
Sergio Garcia
be4f58ed8f
chore(regions_update): Changes in regions for AWS services. ( #2500 )
2023-06-19 07:59:42 +02:00
Sergio Garcia
d82d1abab6
chore(3.6.1): release version ( #2498 )
2023-06-16 12:34:17 +02:00
Sergio Garcia
0d81bd457c
fix(asff): handle empty Recommendation Url ( #2496 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-06-16 12:17:09 +02:00
Sergio Garcia
af2b19436f
fix(route53): correct Hosted Zone ARN ( #2494 )
2023-06-15 16:32:54 +02:00
Sergio Garcia
51beb3c7e4
chore(regions_update): Changes in regions for AWS services. ( #2497 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-06-15 15:56:23 +02:00
Chris Kelly
5061456735
fix(security hub): Adds logic to map to valid ASFF statuses ( #2491 )
2023-06-15 15:52:19 +02:00
Nacho Rivera
b01eb3af95
fix(rds checks): test if key exists prior checking it ( #2489 )
2023-06-14 12:15:33 +02:00
Sergio Garcia
328bebc168
chore(regions_update): Changes in regions for AWS services. ( #2487 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-06-14 11:52:11 +02:00
Sergio Garcia
fc63fffa15
chore(release): 3.6.0 ( #2485 )
2023-06-13 17:38:51 +02:00
Sebastian Nyberg
707584b2ef
feat(aws): Add MFA flag if try to assume role in AWS ( #2478 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-06-13 17:18:10 +02:00
Nacho Rivera
561459d93b
fix(dataevents checks): add trails home region ( #2484 )
2023-06-13 11:48:55 +02:00
Sergio Garcia
25e48ae546
chore(arn): include ARN of AWS accounts ( #2477 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-06-13 10:18:23 +02:00
dependabot[bot]
513bb3e8d0
build(deps): bump botocore from 1.29.147 to 1.29.152 ( #2482 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-13 10:07:57 +02:00
dependabot[bot]
04710ca908
build(deps): bump google-api-python-client from 2.86.0 to 2.88.0 ( #2483 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-13 09:50:10 +02:00
dependabot[bot]
fcf0fcf20c
build(deps): bump pydantic from 1.10.8 to 1.10.9 ( #2481 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-13 09:06:59 +02:00
dependabot[bot]
2ff40d8e37
build(deps): bump boto3 from 1.26.142 to 1.26.147 ( #2480 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-13 08:11:54 +02:00
dependabot[bot]
1bab5b06a4
build(deps-dev): bump pytest from 7.3.1 to 7.3.2 ( #2479 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-13 07:50:41 +02:00
Sergio Garcia
01cd4bcb47
chore(arn): add missing ARNs to AWS Services ( #2476 )
2023-06-12 13:33:12 +02:00
Sebastian Nyberg
49b2a559ae
feat(vpc): add check vpc_subnet_no_public_ip_by_default ( #2472 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-06-12 09:44:10 +02:00
Sergio Garcia
9212d24685
chore(regions_update): Changes in regions for AWS services. ( #2474 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-06-12 08:48:44 +02:00
Nacho Rivera
eb43b11202
fix(arn validator): include : in regex ( #2471 )
2023-06-09 13:24:29 +02:00
Sergio Garcia
5c4cae8c9d
feat(wellarchitected): add WellArchitected service and check ( #2461 )
2023-06-09 13:19:01 +02:00
Sergio Garcia
cfd7099743
chore(regions_update): Changes in regions for AWS services. ( #2469 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-06-09 13:09:30 +02:00
Sergio Garcia
19ae237d29
chore(regions_update): Changes in regions for AWS services. ( #2462 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-06-09 13:09:01 +02:00
Sergio Garcia
9cda78e561
chore(docs): improve allowlist suggestion ( #2466 )
2023-06-09 13:07:28 +02:00
Sergio Garcia
cc31872a7f
fix(kms): check only KMS CMK tags ( #2468 )
2023-06-09 13:06:06 +02:00
Sebastian Nyberg
3c2c896708
chore(vpc): add mapPublicIpOnLaunch attribute to VPC subnets ( #2470 )
2023-06-09 12:45:28 +02:00
Jit
b73da9c54c
feat(gcp): add 12 new checks for CIS Framework ( #2426 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-06-08 11:25:51 +02:00
Sergio Garcia
414a45bfb0
chore(quick inventory): add warning message ( #2460 )
2023-06-07 15:16:52 +02:00
Sergio Garcia
2a6f808bca
chore(boto3): update boto3 config ( #2459 )
2023-06-07 14:32:40 +02:00
Sergio Garcia
cdf2a13bbd
feat(oscf): add OCSF format as JSON output for AWS, Azure and GCP. Hello Amazon Security Lake! ( #2429 )
2023-06-07 14:28:43 +02:00
Sergio Garcia
3e3e8a14ee
fix(inventory): handle exception for every call ( #2457 )
2023-06-07 09:33:10 +02:00
Nacho Rivera
37e180827a
fix(azure): fix empty subscriptions case ( #2455 )
2023-06-06 17:31:43 +02:00
Pepe Fagoaga
b047b54545
fix(backup): Handle last_execution_date when None ( #2454 )
2023-06-06 16:57:17 +02:00
Pepe Fagoaga
b7bb4bbd57
fix(aws): Add missing resources ARN ( #2453 )
2023-06-06 16:56:59 +02:00
Pepe Fagoaga
86cf2cd233
fix(efs): Include resource ARN and handle from input ( #2452 )
2023-06-06 14:29:58 +02:00
Sergio Garcia
ab12c201b4
chore(docs): improve custom checks docs ( #2428 )
2023-06-06 11:58:20 +02:00
Sergio Garcia
a8f03d859c
feat(gcp): add --project-ids flag and scan all projects by default ( #2393 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-06-06 11:56:39 +02:00
Sergio Garcia
3c7580f024
fix(ec2): handle false positive in ec2_securitygroup_allow_ingress_from_internet_to_any_port ( #2449 )
2023-06-06 11:55:27 +02:00
Sergio Garcia
277833e388
fix(services): verify Route53 records and handle TrustedAdvisor error ( #2448 )
2023-06-06 11:50:44 +02:00
Sergio Garcia
eb16d7e6f9
chore(regions_update): Changes in regions for AWS services. ( #2450 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-06-06 11:20:03 +02:00
Pepe Fagoaga
1418068d2b
fix(services): Handle AWS service errors ( #2440 )
2023-06-06 09:23:03 +02:00
dependabot[bot]
774346f5f8
build(deps): bump botocore from 1.29.142 to 1.29.147 ( #2447 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-06 08:38:49 +02:00
dependabot[bot]
1aab88e6ca
build(deps): bump alive-progress from 3.1.1 to 3.1.4 ( #2446 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-06 08:25:06 +02:00
dependabot[bot]
613f49b8bb
build(deps-dev): bump docker from 6.1.2 to 6.1.3 ( #2445 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-06 08:03:03 +02:00
dependabot[bot]
5c95dc6e20
build(deps): bump boto3 from 1.26.138 to 1.26.142 ( #2444 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-06 07:45:14 +02:00
dependabot[bot]
cbc2713bee
build(deps-dev): bump moto from 4.1.10 to 4.1.11 ( #2443 )
2023-06-06 07:29:25 +02:00
christiandavilakoobin
2955975793
fix(cloudfront): fix DefaultCacheConfigBehaviour enum type( #2430 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-06-05 15:48:34 +02:00
Sergio Garcia
f8299d7f40
chore(regions_update): Changes in regions for AWS services. ( #2441 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-06-05 14:44:30 +02:00
Toni de la Fuente
e855d44523
docs: Create CONTRIBUTING.md ( #2416 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-06-05 08:52:57 +02:00
dependabot[bot]
64e7715480
build(deps): bump cryptography from 40.0.2 to 41.0.0 ( #2436 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-05 08:52:11 +02:00
Nacho Rivera
2e9a74f609
fix(README): add references to tenant-id when browser auth ( #2439 )
2023-06-05 08:39:59 +02:00
Sergio Garcia
11a1230738
chore(regions_update): Changes in regions for AWS services. ( #2437 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-06-05 08:09:21 +02:00
Sergio Garcia
298373742e
chore(regions_update): Changes in regions for AWS services. ( #2427 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-06-02 13:32:04 +02:00
Sergio Garcia
dc7aeecd85
chore(regions_update): Changes in regions for AWS services. ( #2434 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-06-02 13:24:47 +02:00
Nacho Rivera
15a7de7b24
fix(browser auth): fix browser auth in Azure to include tenant id ( #2415 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-06-02 13:22:43 +02:00
sssalim-aws
714d0d4092
Update aws_well_architected_framework_security_pillar_aws.json ( #2432 )
2023-06-02 11:58:31 +02:00
Jenny Kim
225d7f39d1
chore(logo): Add Prowler logo in SVG format & Propose to Prowler icon design ( #2423 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-06-01 12:03:49 +02:00
Sergio Garcia
0005798c83
chore(regions_update): Changes in regions for AWS services. ( #2424 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-31 18:22:44 +02:00
dependabot[bot]
1d9078f9be
build(deps): bump mkdocs-material from 9.1.12 to 9.1.15 ( #2420 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-30 12:51:50 +02:00
dependabot[bot]
510ac7005a
build(deps-dev): bump pytest-xdist from 3.3.0 to 3.3.1 ( #2421 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-30 11:00:11 +02:00
dependabot[bot]
c049b968a5
build(deps): bump pydantic from 1.10.7 to 1.10.8 ( #2418 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-30 10:45:13 +02:00
dependabot[bot]
858698f7cd
build(deps): bump botocore from 1.29.138 to 1.29.142 ( #2419 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-30 09:42:19 +02:00
dependabot[bot]
d104f6f8fc
build(deps-dev): bump coverage from 7.2.5 to 7.2.7 ( #2422 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-30 07:52:01 +02:00
Sergio Garcia
3ecf0d3230
chore(regions_update): Changes in regions for AWS services. ( #2414 )
2023-05-29 07:20:44 +02:00
Sergio Garcia
6e4131fee4
fix(ecr): handle LifecyclePolicyNotFoundException ( #2411 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-05-26 17:15:49 +02:00
Sergio Garcia
41fa6bc8ed
chore(regions_update): Changes in regions for AWS services. ( #2413 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-26 13:02:37 +02:00
Sergio Garcia
58a29bf058
fix(codebuild): handle FAIL in codebuild_project_user_controlled_buildspec ( #2410 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-05-25 13:30:01 +02:00
Sergio Garcia
7dac17de18
chore(regions_update): Changes in regions for AWS services. ( #2409 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-25 11:51:32 +02:00
Toni de la Fuente
799d7de182
fix: typo in README.md ( #2407 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-05-24 16:55:49 +02:00
Pedro Martín
735af02f59
feat(new_security_framework): AWS Well Architected Framework security pillar ( #2382 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-05-24 16:38:32 +02:00
Sergio Garcia
ad3f3799fa
fix(typo): typo in README.md ( #2406 )
2023-05-24 14:22:58 +02:00
Sergio Garcia
5f97df015e
chore(release): change release version to 3.5.3 ( #2405 )
2023-05-24 13:56:53 +02:00
Toni de la Fuente
ff18fd2c38
chore(docs): add summary table to README.md ( #2402 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-05-24 13:56:17 +02:00
Jit
3ab0cd02df
feat(checks-gcp): Include 4 new checks covering GCP CIS ( #2376 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-05-24 12:10:43 +02:00
Sergio Garcia
c31072f42f
chore(regions_update): Changes in regions for AWS services. ( #2403 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-24 11:59:15 +02:00
Sergio Garcia
c01c59023a
fix(ClientError): handle ClientErrors in DynamoDB and Directory Service ( #2400 )
2023-05-24 11:50:08 +02:00
Sergio Garcia
4329aac377
chore(quick-inventory): send quick inventory to output bucket ( #2399 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-05-24 11:48:49 +02:00
Sergio Garcia
c10b31e9d0
fix(categories): remove empty categories from metadata ( #2401 )
2023-05-24 10:44:51 +02:00
kij
71a789c0b4
fix(OSError): handle different OSErrors ( #2398 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-05-23 17:16:17 +02:00
Sergio Garcia
deb9847e2b
fix(route53_dangling_ip_subdomain_takeover): notify only IPs with AWS IP Ranges ( #2396 )
2023-05-23 16:35:13 +02:00
Pepe Fagoaga
9e9e7e1e96
fix(aws): Handle unique map keys ( #2390 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-05-23 15:54:22 +02:00
Sergio Garcia
d34e0341e2
chore(regions_update): Changes in regions for AWS services. ( #2392 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-23 12:28:38 +02:00
Sergio Garcia
aec254b05a
fix(inspector2): fix active findings count ( #2395 )
2023-05-23 12:26:09 +02:00
dependabot[bot]
f8b420047a
build(deps): bump boto3 from 1.26.125 to 1.26.138 ( #2389 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 11:15:42 +02:00
dependabot[bot]
7e6e4c0bc6
build(deps): bump shodan from 1.29.0 to 1.29.1 ( #2385 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 10:56:50 +02:00
dependabot[bot]
71fb59943c
build(deps): bump requests from 2.30.0 to 2.31.0 ( #2388 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 10:25:28 +02:00
dependabot[bot]
34419d0ca1
build(deps): bump azure-identity from 1.12.0 to 1.13.0 ( #2386 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 10:22:05 +02:00
dependabot[bot]
475a36f0d7
build(deps-dev): bump moto from 4.1.9 to 4.1.10 ( #2384 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 09:52:18 +02:00
Kevin Pullin
1234c1e7e2
fix(allowlist) - tags parameter is a string, not a list ( #2375 )
2023-05-23 09:51:50 +02:00
dependabot[bot]
a4a400facf
build(deps): bump botocore from 1.29.134 to 1.29.138 ( #2383 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-23 07:52:47 +02:00
Sergio Garcia
ed2ca4d896
chore(regions_update): Changes in regions for AWS services. ( #2378 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-19 11:36:08 +02:00
Pepe Fagoaga
ce42e4d1cd
fix(pypi-release): Push version change to the branch ( #2374 )
2023-05-18 18:46:11 +02:00
Sergio Garcia
b048128e77
chore(release): release version 3.5.2 ( #2373 )
2023-05-18 17:04:18 +02:00
Sergio Garcia
635c257502
fix(ssm incidents): check if service available in aws partition ( #2372 )
2023-05-18 16:44:52 +02:00
Pepe Fagoaga
58a38c08d7
docs: format regions-and-partitions ( #2371 )
2023-05-18 16:35:54 +02:00
Pepe Fagoaga
8fbee7737b
fix(resource_not_found): Handle error ( #2370 )
2023-05-18 16:26:08 +02:00
Pepe Fagoaga
e84f5f184e
fix(sts): Use the right region to validate credentials ( #2349 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-05-18 15:51:57 +02:00
Sergio Garcia
0bd26b19d7
chore(regions_update): Changes in regions for AWS services. ( #2368 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-18 11:17:28 +02:00
Sergio Garcia
64f82d5d51
chore(regions_update): Changes in regions for AWS services. ( #2366 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-17 11:52:16 +02:00
Sergio Garcia
f63ff994ce
fix(action): solve pypi-release action creating the release branch ( #2364 )
2023-05-16 13:32:46 +02:00
Sergio Garcia
a10ee43271
release: 3.5.1 ( #2363 )
2023-05-16 11:42:08 +02:00
Sergio Garcia
54ed29e08d
fix(route53): handle empty Records in Zones ( #2351 )
2023-05-16 10:51:43 +02:00
dependabot[bot]
cc097e7a3f
build(deps-dev): bump docker from 6.1.1 to 6.1.2 ( #2360 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-16 09:39:24 +02:00
dependabot[bot]
5de92ada43
build(deps): bump mkdocs-material from 9.1.8 to 9.1.12 ( #2359 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-16 09:24:39 +02:00
dependabot[bot]
0c546211cf
build(deps-dev): bump pytest-xdist from 3.2.1 to 3.3.0 ( #2358 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-16 08:09:55 +02:00
dependabot[bot]
4dc5a3a67c
build(deps): bump botocore from 1.29.125 to 1.29.134 ( #2357 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-16 07:51:19 +02:00
dependabot[bot]
c51b226ceb
build(deps): bump shodan from 1.28.0 to 1.29.0 ( #2356 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-16 07:34:51 +02:00
dependabot[bot]
0a5ca6cf74
build(deps): bump pymdown-extensions from 9.11 to 10.0 ( #2355 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-16 07:33:56 +02:00
Sergio Garcia
96957219e4
chore(regions_update): Changes in regions for AWS services. ( #2353 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-16 07:32:41 +02:00
Sergio Garcia
32b7620db3
chore(regions_update): Changes in regions for AWS services. ( #2350 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-12 11:37:53 +02:00
Sergio Garcia
347f65e089
chore(release): 3.5.0 ( #2346 )
2023-05-11 17:42:46 +02:00
Sergio Garcia
16628a427e
fix(README): update Architecture image and PyPi links ( #2345 )
2023-05-11 17:29:17 +02:00
Sergio Garcia
ed16034a25
fix(README): order providers alphbetically ( #2344 )
2023-05-11 16:30:04 +02:00
Pepe Fagoaga
0c5f144e41
fix(poetry): Skip updates during pre-commit ( #2342 )
2023-05-11 12:17:21 +02:00
Sergio Garcia
acc7d6e7dc
chore(regions_update): Changes in regions for AWS services. ( #2341 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-11 11:41:39 +02:00
Sergio Garcia
84b4139052
chore(iam): add new permissions ( #2339 )
2023-05-11 11:35:32 +02:00
Sergio Garcia
9943643958
fix(s3): improve error handling ( #2337 )
2023-05-10 16:43:06 +02:00
Pepe Fagoaga
9ceaefb663
fix(access-analyzer): Handle ResourceNotFoundException ( #2336 )
2023-05-10 15:44:14 +02:00
Gabriel Soltz
ec03ea5bc1
feat(workspaces): New check workspaces_vpc_2private_1public_subnets_nat ( #2286 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: n4ch04 <nachor1992@gmail.com >
2023-05-10 15:40:42 +02:00
Sergio Garcia
5855633c1f
fix(resourceexplorer2): add resource id ( #2335 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-05-10 14:48:34 +02:00
Pedro Martín
a53bc2bc2e
feat(rds): new check rds_instance_deprecated_engine_version ( #2298 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-05-10 14:48:12 +02:00
Sergio Garcia
88445820ed
feat(slack): add Slack App integration ( #2305 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-05-10 13:38:28 +02:00
Sergio Garcia
044ed3ae98
chore(regions_update): Changes in regions for AWS services. ( #2334 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-10 13:30:24 +02:00
Pepe Fagoaga
6f48012234
fix(ecr): Refactor service ( #2302 )
...
Co-authored-by: Gabriel Soltz <thegaby@gmail.com >
Co-authored-by: Kay Agahd <kagahd@users.noreply.github.com >
Co-authored-by: Nacho Rivera <nachor1992@gmail.com >
Co-authored-by: Kevin Pullin <kevin.pullin@gmail.com >
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-05-09 17:04:21 +02:00
Sergio Garcia
d344318dd4
feat(allowlist): allowlist a specific service ( #2331 )
2023-05-09 15:43:04 +02:00
Sergio Garcia
6273dd3d83
chore(regions_update): Changes in regions for AWS services. ( #2330 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-09 12:21:07 +02:00
dependabot[bot]
0f3f3cbffd
build(deps-dev): bump moto from 4.1.8 to 4.1.9 ( #2328 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-05-09 11:38:41 +02:00
Pepe Fagoaga
3244123b21
fix(cloudfront_distributions_https_enabled): Add default case ( #2329 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-05-09 11:09:18 +02:00
dependabot[bot]
cba2ee3622
build(deps): bump boto3 from 1.26.115 to 1.26.125 ( #2327 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-09 08:48:15 +02:00
dependabot[bot]
25ed925df5
build(deps-dev): bump docker from 6.0.1 to 6.1.1 ( #2326 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-09 08:22:03 +02:00
dependabot[bot]
8c5bd60bab
build(deps-dev): bump pylint from 2.17.3 to 2.17.4 ( #2325 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-09 07:59:21 +02:00
dependabot[bot]
c5510556a7
build(deps): bump mkdocs from 1.4.2 to 1.4.3 ( #2324 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-09 07:38:43 +02:00
Sergio Garcia
bbcfca84ef
fix(trustedadvisor): avoid not_available checks ( #2323 )
2023-05-08 17:55:31 +02:00
Sergio Garcia
1260e94c2a
fix(cloudtrail): handle InsightNotEnabledException error ( #2322 )
2023-05-08 16:06:13 +02:00
Pepe Fagoaga
8a02574303
fix(sagemaker): Handle ValidationException ( #2321 )
2023-05-08 14:52:28 +02:00
Pepe Fagoaga
c930f08348
fix(emr): Handle InvalidRequestException ( #2320 )
2023-05-08 14:52:12 +02:00
Pepe Fagoaga
5204acb5d0
fix(iam): Handle ListRoleTags and policy errors ( #2319 )
2023-05-08 14:42:23 +02:00
Sergio Garcia
784aaa98c9
feat(iam): add iam_role_cross_account_readonlyaccess_policy check ( #2312 )
2023-05-08 13:27:51 +02:00
Sergio Garcia
745e2494bc
chore(docs): improve GCP docs ( #2318 )
2023-05-08 13:26:23 +02:00
Sergio Garcia
c00792519d
chore(docs): improve GCP docs ( #2318 )
2023-05-08 13:26:02 +02:00
Sergio Garcia
142fe5a12c
chore(regions_update): Changes in regions for AWS services. ( #2315 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-08 12:40:31 +02:00
Sergio Garcia
5b127f232e
fix(typo): typo in backup_vaults_exist check title ( #2317 )
2023-05-08 12:29:08 +02:00
Kevin Pullin
c22bf01003
feat(allowlist): Support regexes in Tags to allow "or"-like conditional matching ( #2300 )
...
Co-authored-by: Kevin Pullin <kevinp@nexttrucking.com >
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-05-05 14:56:27 +02:00
Nacho Rivera
05e4911d6f
fix(vpc services): list to dicts in vpc and subnets ( #2310 )
2023-05-04 15:35:02 +02:00
Nacho Rivera
9b551ef0ba
feat(pre-commit): added trufflehog to pre-commit ( #2311 )
2023-05-04 15:33:11 +02:00
Sergio Garcia
56a8bb2349
chore(regions_update): Changes in regions for AWS services. ( #2309 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-04 12:30:10 +02:00
Pepe Fagoaga
8503c6a64d
fix(client_error): Handle errors ( #2308 )
2023-05-04 11:06:24 +02:00
Pepe Fagoaga
820f18da4d
release: 3.4.1 ( #2303 )
2023-05-03 19:24:17 +02:00
Kay Agahd
51a2432ebf
fix(typo): remove redundant lines ( #2307 )
2023-05-03 19:23:48 +02:00
Gabriel Soltz
6639534e97
feat(ssmincidents): Use regional_client region instead of audit_profile region ( #2306 )
2023-05-03 19:22:30 +02:00
Gabriel Soltz
0621577c7d
fix(backup): Return [] when None AdvancedBackupSettings ( #2304 )
2023-05-03 17:10:53 +02:00
Sergio Garcia
26a507e3db
feat(route53): add route53_dangling_ip_subdomain_takeover check ( #2288 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-05-03 11:47:36 +02:00
Sergio Garcia
244b540fe0
fix(s3): handle NoSuchBucket error ( #2289 )
2023-05-03 09:55:19 +02:00
Gabriel Soltz
030ca4c173
fix(backups): change severity and only check report_plans if plans exists ( #2291 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-05-03 09:00:15 +02:00
dependabot[bot]
88a2810f29
build(deps): bump botocore from 1.29.115 to 1.29.125 ( #2301 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-03 08:55:14 +02:00
dependabot[bot]
9164ee363a
build(deps-dev): bump coverage from 7.2.3 to 7.2.5 ( #2297 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-03 08:38:03 +02:00
dependabot[bot]
4cd47fdcc5
build(deps): bump google-api-python-client from 2.84.0 to 2.86.0 ( #2296 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-03 08:11:36 +02:00
dependabot[bot]
708852a3cb
build(deps): bump mkdocs-material from 9.1.6 to 9.1.8 ( #2294 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-05-03 07:49:52 +02:00
Sergio Garcia
4a93bdf3ea
chore(regions_update): Changes in regions for AWS services. ( #2293 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-05-03 07:49:27 +02:00
Gabriel Soltz
22e7d2a811
feat(Organizations): New check organizations_tags_policies_enabled_and_attached ( #2287 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-28 16:14:08 +02:00
Sergio Garcia
93eca1dff2
chore(regions_update): Changes in regions for AWS services. ( #2290 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-28 13:19:46 +02:00
Gabriel Soltz
9afe7408cd
feat(FMS): New Service FMS and Check fms_accounts_compliant ( #2259 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: Nacho Rivera <nacho@verica.io >
2023-04-28 11:47:55 +02:00
Sergio Garcia
5dc2347a25
docs(security hub): improve security hub docs ( #2285 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-27 16:22:49 +02:00
Pepe Fagoaga
e3a0124b10
fix(opensearch): Handle invalid JSON policy ( #2262 )
2023-04-27 12:05:43 +02:00
Gabriel Soltz
16af89c281
feat(autoscaling): new check autoscaling_group_multiple_az ( #2273 )
2023-04-26 15:10:04 +02:00
Sergio Garcia
621e4258c8
feat(s3): add s3_bucket_object_lock check ( #2274 )
2023-04-26 15:04:45 +02:00
Sergio Garcia
ac6272e739
fix(rds): check configurations for DB instances at cluster level ( #2277 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-26 13:51:07 +02:00
Sergio Garcia
6e84f517a9
fix(apigateway2): correct paginator name ( #2283 )
2023-04-26 13:43:15 +02:00
Pepe Fagoaga
fdbdb3ad86
fix(sns_topics_not_publicly_accessible): Change PASS behaviour ( #2282 )
2023-04-26 12:51:51 +02:00
Sergio Garcia
7adcf5ca46
chore(regions_update): Changes in regions for AWS services. ( #2280 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-26 11:59:34 +02:00
Gabriel Soltz
fe6716cf76
feat(NetworkFirewall): New Service and Check ( #2261 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-04-26 11:58:11 +02:00
dependabot[bot]
3c2096db68
build(deps): bump azure-mgmt-security from 4.0.0 to 5.0.0 ( #2270 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-25 11:59:30 +02:00
Pepe Fagoaga
58cad1a6b3
fix(log_group_retention): handle log groups that never expire ( #2272 )
2023-04-25 10:45:43 +02:00
dependabot[bot]
662e67ff16
build(deps): bump boto3 from 1.26.105 to 1.26.115 ( #2269 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-25 10:35:15 +02:00
dependabot[bot]
8d577b872f
build(deps-dev): bump moto from 4.1.7 to 4.1.8 ( #2268 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-25 10:12:25 +02:00
dependabot[bot]
b55290f3cb
build(deps-dev): bump pylint from 2.17.2 to 2.17.3 ( #2267 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-25 09:20:15 +02:00
dependabot[bot]
e8d3eb7393
build(deps-dev): bump pytest from 7.3.0 to 7.3.1 ( #2266 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-25 08:03:45 +02:00
Sergio Garcia
47fa16e35f
chore(test): add CloudWatch and Logs tests ( #2264 )
2023-04-24 17:05:05 +02:00
Gabriel Soltz
a87f769b85
feat(DRS): New DRS Service and Checks ( #2257 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-24 14:22:22 +02:00
Sergio Garcia
8e63fa4594
fix(version): execute check current version function only when -v ( #2263 )
2023-04-24 12:45:59 +02:00
Gabriel Soltz
63501a0d59
feat(inspector2): New Service and Check ( #2250 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-04-24 12:15:16 +02:00
Sergio Garcia
828fb37ca8
chore(regions_update): Changes in regions for AWS services. ( #2258 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-24 08:32:40 +02:00
Sergio Garcia
40f513d3b6
chore(regions_update): Changes in regions for AWS services. ( #2251 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-21 12:10:15 +02:00
Sergio Garcia
f0b8b66a75
chore(test): add rds_instance_transport_encrypted test ( #2252 )
2023-04-21 12:09:47 +02:00
Sergio Garcia
d51cdc068b
fix(iam_role_cross_service_confused_deputy_prevention): avoid service linked roles ( #2249 )
2023-04-21 10:42:05 +02:00
Sergio Garcia
f8b382e480
fix(version): update version to 3.4.0 ( #2247 )
2023-04-20 17:05:18 +02:00
Ronen Atias
1995f43b67
fix(redshift): correct description in redshift_cluster_automatic_upgrades ( #2246 )
2023-04-20 15:19:49 +02:00
Sergio Garcia
69e0392a8b
fix(rds): exclude Aurora in rds_instance_transport_encrypted check ( #2245 )
2023-04-20 14:28:12 +02:00
Sergio Garcia
1f6319442e
chore(docs): improve GCP docs ( #2242 )
2023-04-20 14:15:28 +02:00
Sergio Garcia
559c4c0c2c
chore(regions_update): Changes in regions for AWS services. ( #2243 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-20 11:43:02 +02:00
Sergio Garcia
feeb5b58d9
fix(checks): improve --list-checks function ( #2240 )
2023-04-19 17:00:20 +02:00
Sergio Garcia
7a00f79a56
fix(iam_policy_no_administrative_privileges): check attached policies and AWS-Managed ( #2200 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-19 14:34:53 +02:00
Sergio Garcia
10d744704a
fix(errors): solve ECR and CodeArtifact errors ( #2239 )
2023-04-19 13:27:19 +02:00
Gabriel Soltz
eee35f9cc3
feat(ssmincidents): New Service and Checks ( #2219 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-19 12:26:20 +02:00
Gabriel Soltz
b3656761eb
feat(check): New VPC checks ( #2218 )
2023-04-19 12:01:12 +02:00
Sergio Garcia
7b5fe34316
feat(html): add html to Azure and GCP ( #2181 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-18 16:13:57 +02:00
Sergio Garcia
4536780a19
feat(check): new check ecr_registry_scan_images_on_push_enabled ( #2237 )
2023-04-18 15:45:21 +02:00
Sergio Garcia
05d866e6b3
chore(regions_update): Changes in regions for AWS services. ( #2236 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-18 13:43:15 +02:00
dependabot[bot]
0d138cf473
build(deps): bump botocore from 1.29.105 to 1.29.115 ( #2233 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-18 13:42:50 +02:00
dependabot[bot]
dbe539ac80
build(deps): bump boto3 from 1.26.90 to 1.26.105 ( #2232 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-18 12:35:33 +02:00
dependabot[bot]
665a39d179
build(deps): bump azure-storage-blob from 12.15.0 to 12.16.0 ( #2230 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-18 11:02:39 +02:00
dependabot[bot]
5fd5d8c8c5
build(deps-dev): bump coverage from 7.2.2 to 7.2.3 ( #2234 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-18 08:03:44 +02:00
dependabot[bot]
2832b4564c
build(deps-dev): bump moto from 4.1.6 to 4.1.7 ( #2231 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-18 07:40:50 +02:00
dependabot[bot]
d4369a64ee
build(deps): bump azure-mgmt-security from 3.0.0 to 4.0.0 ( #2141 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-17 13:22:09 +02:00
Sergio Garcia
81fa1630b7
chore(regions_update): Changes in regions for AWS services. ( #2227 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-17 11:18:41 +02:00
Sergio Garcia
a1c4b35205
chore(regions_update): Changes in regions for AWS services. ( #2217 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-17 11:16:22 +02:00
Sergio Garcia
5e567f3e37
fix(iam tests): mock audit_info object ( #2226 )
...
Co-authored-by: n4ch04 <nachor1992@gmail.com >
2023-04-17 11:14:48 +02:00
Pepe Fagoaga
c4757684c1
fix(test): Mock audit into in SecurityHub CodeBuild ( #2225 )
2023-04-17 11:14:36 +02:00
Sergio Garcia
a55a6bf94b
fix(test): Mock audit info in EC2 ( #2224 )
2023-04-17 10:54:56 +02:00
Pepe Fagoaga
fa1792eb77
fix(test): Mock audit into in CloudWatch ( #2223 )
2023-04-17 10:54:01 +02:00
Nacho Rivera
93a8f6e759
fix(rds tests): mocked audit_info object ( #2222 )
2023-04-17 10:06:25 +02:00
Nacho Rivera
4a614855d4
fix(s3 tests): audit_info object mocked ( #2221 )
2023-04-17 10:04:28 +02:00
Pepe Fagoaga
8bdd47f912
fix(test): Mock audit info in KMS ( #2215 )
2023-04-14 14:34:55 +02:00
Nacho Rivera
f9e82abadc
fix(vpc tests): mock current_audit_info ( #2214 )
2023-04-14 14:31:34 +02:00
Gabriel Soltz
428fda81e2
feat(check): New GuardDuty check guardduty_centrally_managed ( #2195 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-14 14:30:51 +02:00
Pepe Fagoaga
29c9ad602d
fix(test): Mock audit into in Macie ( #2213 )
2023-04-14 14:29:19 +02:00
Pepe Fagoaga
44458e2a97
fix(test): Mock audit info codeartifact-config-ds ( #2210 )
2023-04-14 14:25:45 +02:00
Pepe Fagoaga
861fb1f54b
fix(test): Mock audit into in Glacier ( #2212 )
2023-04-14 14:20:03 +02:00
Pepe Fagoaga
02534f4d55
fix(test): Mock audit info DynamoDB ( #2211 )
2023-04-14 14:19:08 +02:00
Pepe Fagoaga
5532cb95a2
fix(test): Mock audit info in appstream and autoscaling ( #2209 )
2023-04-14 14:06:07 +02:00
Pepe Fagoaga
9176e43fc9
fix(test): Mock audit info API Gateway ( #2208 )
2023-04-14 13:49:38 +02:00
Pepe Fagoaga
cb190f54fc
fix(elb-test): Use a mocked current audit info ( #2207 )
2023-04-14 12:43:08 +02:00
Sergio Garcia
4be2539bc2
fix(resourceexplorer2): solve test and region ( #2206 )
2023-04-14 12:33:52 +02:00
Sergio Garcia
291e2adffa
chore(regions_update): Changes in regions for AWS services. ( #2205 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-14 12:32:58 +02:00
Gabriel Soltz
fa2ec63f45
feat(check): New Check and Service: resourceexplorer2_indexes_found ( #2196 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-04-14 10:18:36 +02:00
Nacho Rivera
946c943457
fix(global services): fixed global services region ( #2203 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-14 09:57:33 +02:00
Pepe Fagoaga
0e50766d6e
fix(test): call cloudtrail_s3_dataevents_write_enabled check ( #2204 )
2023-04-14 09:35:29 +02:00
Sergio Garcia
58a1610ae0
chore(regions_update): Changes in regions for AWS services. ( #2201 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-13 15:53:56 +02:00
Nacho Rivera
06dc21168a
feat(orgs checks region): added region to all orgs checks ( #2202 )
2023-04-13 14:41:18 +02:00
Gabriel Soltz
305b67fbed
feat(check): New check cloudtrail_bucket_requires_mfa_delete ( #2194 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-13 14:18:31 +02:00
Sergio Garcia
4da6d152c3
feat(custom checks): add -x/--checks-folder for custom checks ( #2191 )
2023-04-13 13:44:25 +02:00
Sergio Garcia
25630f1ef5
chore(regions): sort AWS regions ( #2198 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-12 13:24:14 +02:00
Sergio Garcia
9b01e3f1c9
chore(regions_update): Changes in regions for AWS services. ( #2197 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-12 12:53:03 +02:00
Sergio Garcia
99450400eb
chore(regions_update): Changes in regions for AWS services. ( #2189 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-12 10:47:21 +02:00
Gabriel Soltz
2f8a8988d7
feat(checks): New IAM Checks no full access to critical services ( #2183 )
2023-04-12 07:47:21 +02:00
Sergio Garcia
9104d2e89e
fix(kms): handle empty principal error ( #2192 )
2023-04-11 16:59:29 +02:00
Gabriel Soltz
e75022763c
feat(checks): New iam_securityaudit_role_created ( #2182 )
2023-04-11 14:15:39 +02:00
Gabriel Soltz
f0f3fb337d
feat(check): New CloudTrail check cloudtrail_insights_exist ( #2184 )
2023-04-11 13:49:54 +02:00
dependabot[bot]
f7f01a34c2
build(deps): bump google-api-python-client from 2.81.0 to 2.84.0 ( #2188 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-11 12:13:41 +02:00
dependabot[bot]
f9f9ff0cb8
build(deps): bump alive-progress from 3.1.0 to 3.1.1 ( #2187 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-11 08:13:17 +02:00
dependabot[bot]
522ba05ba8
build(deps): bump mkdocs-material from 9.1.5 to 9.1.6 ( #2186 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-11 07:54:41 +02:00
Gabriel Soltz
f4f4093466
feat(backup): New backup service and checks ( #2172 )
...
Co-authored-by: Nacho Rivera <nacho@verica.io >
2023-04-11 07:43:40 +02:00
dependabot[bot]
2e16ab0c2c
build(deps-dev): bump pytest from 7.2.2 to 7.3.0 ( #2185 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-11 07:39:09 +02:00
Sergio Garcia
6f02606fb7
fix(iam): handle no display name error in service account ( #2176 )
2023-04-10 12:06:08 +02:00
Sergio Garcia
df40142b51
chore(regions_update): Changes in regions for AWS services. ( #2180 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-10 12:05:48 +02:00
Sergio Garcia
cc290d488b
chore(regions_update): Changes in regions for AWS services. ( #2178 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-10 12:05:30 +02:00
Nacho Rivera
64328218fc
feat(banner): azure credential banner ( #2179 )
2023-04-10 09:58:28 +02:00
Sergio Garcia
8d1356a085
fix(logging): add default resource id when no resources ( #2177 )
2023-04-10 08:02:40 +02:00
Sergio Garcia
4f39dd0f73
fix(version): handle request response property ( #2175 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-05 15:17:30 +02:00
Pepe Fagoaga
54ffc8ae45
chore(release): 3.3.4 ( #2174 )
2023-04-05 14:18:07 +02:00
Sergio Garcia
78ab1944bd
chore(regions_update): Changes in regions for AWS services. ( #2173 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-05 12:32:25 +02:00
dependabot[bot]
434cf94657
build(deps-dev): bump moto from 4.1.5 to 4.1.6 ( #2164 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-04-05 12:31:58 +02:00
Nacho Rivera
dcb893e230
fix(elbv2 desync check): Mixed elbv2 desync and smuggling ( #2171 )
2023-04-05 11:36:06 +02:00
Sergio Garcia
ce4fadc378
chore(regions_update): Changes in regions for AWS services. ( #2170 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-05 08:47:19 +02:00
dependabot[bot]
5683d1b1bd
build(deps): bump botocore from 1.29.100 to 1.29.105 ( #2163 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-04 13:24:03 +02:00
dependabot[bot]
0eb88d0c10
build(deps): bump mkdocs-material from 9.1.4 to 9.1.5 ( #2162 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-04 11:07:41 +02:00
Nacho Rivera
eb1367e54d
fix(pipeline build): fixed wording when build and push ( #2169 )
2023-04-04 10:21:28 +02:00
dependabot[bot]
33a4786206
build(deps-dev): bump pylint from 2.17.0 to 2.17.2 ( #2161 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-04-04 09:35:10 +02:00
Pepe Fagoaga
8c6606ad95
fix(dax): Call list_tags using the cluster ARN ( #2167 )
2023-04-04 09:30:36 +02:00
Pepe Fagoaga
cde9519a76
fix(iam): Handle LimitExceededException when calling generate_credential_report ( #2168 )
2023-04-04 09:29:27 +02:00
Pepe Fagoaga
7b2e0d79cb
fix(cloudformation): Handle ValidationError ( #2166 )
2023-04-04 09:28:11 +02:00
Pepe Fagoaga
5b0da8e92a
fix(rds): Handle DBSnapshotNotFound ( #2165 )
2023-04-04 09:27:36 +02:00
Michael Göhler
0126d2f77c
fix(secretsmanager_automatic_rotation_enabled): Improve description for Secrets Manager secret rotation ( #2156 )
2023-04-03 11:01:29 +02:00
Sergio Garcia
0b436014c9
chore(regions_update): Changes in regions for AWS services. ( #2159 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-04-03 11:01:15 +02:00
Igor Ceron
2cb7f223ed
fix(docs): check extra_742 name adjusted in the V2 to V3 mapping ( #2154 )
2023-03-31 12:54:13 +02:00
Sergio Garcia
eca551ed98
chore(regions_update): Changes in regions for AWS services. ( #2155 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-31 12:53:49 +02:00
Gabriel Soltz
608fd92861
feat(new_checks): New AWS Organizations related checks ( #2133 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-03-30 17:36:23 +02:00
Sergio Garcia
e37d8fe45f
chore(release): update Prowler Version to 3.3.2 ( #2150 )
...
Co-authored-by: github-actions <noreply@github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-03-30 11:33:33 +02:00
Sergio Garcia
4cce91ec97
chore(regions_update): Changes in regions for AWS services. ( #2153 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-30 11:29:00 +02:00
Pepe Fagoaga
72fdde35dc
fix(pypi): Set base branch when updating release version ( #2152 )
2023-03-30 10:59:58 +02:00
Pepe Fagoaga
d425187778
fix(pypi): Build from release branch ( #2151 )
2023-03-30 10:14:49 +02:00
Sergio Garcia
e419aa1f1a
chore(regions_update): Changes in regions for AWS services. ( #2149 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-29 11:45:35 +02:00
Pepe Fagoaga
5506547f7f
fix(ssm): Handle ValidationException when retrieving documents ( #2146 )
2023-03-29 09:16:52 +02:00
Nacho Rivera
568ed72b3e
fix(audit_info): azure subscriptions parsing error ( #2147 )
2023-03-29 09:15:53 +02:00
Nacho Rivera
e8cc0e6684
fix(delete check): delete check ec2_securitygroup_in_use_without_ingress_filtering ( #2148 )
2023-03-29 09:13:43 +02:00
Sergio Garcia
4331f69395
chore(regions_update): Changes in regions for AWS services. ( #2145 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-28 13:08:02 +02:00
dependabot[bot]
7cc67ae7cb
build(deps): bump botocore from 1.29.90 to 1.29.100 ( #2142 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-28 13:07:23 +02:00
dependabot[bot]
244b3438fc
build(deps): bump mkdocs-material from 9.1.3 to 9.1.4 ( #2140 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-28 12:39:00 +02:00
Nacho Rivera
1a741f7ca0
fix(azure output): change default values of audit identity metadata ( #2144 )
2023-03-28 10:42:47 +02:00
dependabot[bot]
1447800e2b
build(deps): bump pydantic from 1.10.6 to 1.10.7 ( #2139 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-28 10:41:09 +02:00
Sergio Garcia
f968fe7512
fix(readme): add GCP provider to README introduction ( #2143 )
2023-03-28 10:40:56 +02:00
dependabot[bot]
0a2349fad7
build(deps): bump alive-progress from 3.0.1 to 3.1.0 ( #2138 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-28 09:55:18 +02:00
Sergio Garcia
941b8cbc1e
chore(docs): Developer Guide - how to create a new check ( #2137 )
2023-03-27 20:20:13 +02:00
Pepe Fagoaga
3b7b16acfd
fix(resource_not_found): Handle error ( #2136 )
2023-03-27 17:27:50 +02:00
Nacho Rivera
fbc7bb68fc
feat(defender service): retrieving key dicts with get ( #2129 )
2023-03-27 17:13:11 +02:00
Pepe Fagoaga
0d16880596
fix(s3): handle if ignore_public_acls is None ( #2128 )
2023-03-27 17:00:20 +02:00
Sergio Garcia
3b5218128f
fix(brew): move brew formula action to the bottom ( #2135 )
2023-03-27 11:24:28 +02:00
Pepe Fagoaga
cb731bf1db
fix(aws_provider): Fix assessment session name ( #2132 )
2023-03-25 00:11:16 +01:00
Sergio Garcia
7c4d6eb02d
fix(gcp): handle error when Project ID is None ( #2130 )
2023-03-24 18:30:33 +01:00
Sergio Garcia
c14e7fb17a
feat(gcp): add Google Cloud provider with 43 checks ( #2125 )
2023-03-24 13:38:41 +01:00
Sergio Garcia
fe57811bc5
chore(regions_update): Changes in regions for AWS services. ( #2126 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-24 10:18:33 +01:00
Sergio Garcia
e073b48f7d
chore(regions_update): Changes in regions for AWS services. ( #2123 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-23 15:58:47 +01:00
Ben Nugent
a9df609593
fix(quickinventory): AttributError when creating inventory table ( #2122 )
2023-03-23 10:22:14 +01:00
Sergio Garcia
6c3db9646e
fix(output bucket): solve IsADirectoryError using compliance flag ( #2121 )
2023-03-22 13:38:41 +01:00
Sergio Garcia
ff9c4c717e
chore(regions_update): Changes in regions for AWS services. ( #2120 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-22 12:18:44 +01:00
Sergio Garcia
182374b46f
docs: improve reporting documentation ( #2119 )
2023-03-22 10:02:52 +01:00
Sergio Garcia
0871cda526
docs: improve quick inventory section ( #2117 )
2023-03-21 18:09:40 +01:00
Toni de la Fuente
1b47cba37a
docs(developer-guide): added phase 1 of the developer guide ( #1904 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-03-21 15:35:26 +01:00
Pepe Fagoaga
e5bef36905
docs: Remove list severities ( #2116 )
2023-03-21 14:18:07 +01:00
Sergio Garcia
706d723703
chore(version): check latest version ( #2106 )
2023-03-21 11:16:13 +01:00
Sergio Garcia
51eacbfac5
feat(allowlist): add tags filter to allowlist ( #2105 )
2023-03-21 11:14:59 +01:00
dependabot[bot]
5c2a411982
build(deps): bump boto3 from 1.26.86 to 1.26.90 ( #2114 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-21 11:04:26 +01:00
Sergio Garcia
08d65cbc41
chore(regions_update): Changes in regions for AWS services. ( #2115 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-21 11:03:54 +01:00
dependabot[bot]
9d2bf429c1
build(deps): bump mkdocs-material from 9.1.2 to 9.1.3 ( #2113 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-21 10:18:36 +01:00
dependabot[bot]
d34f863bd4
build(deps-dev): bump moto from 4.1.4 to 4.1.5 ( #2111 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-03-21 09:27:44 +01:00
Sergio Garcia
b4abf1c2c7
chore(regions_update): Changes in regions for AWS services. ( #2104 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-21 08:32:26 +01:00
dependabot[bot]
68baaf589e
build(deps-dev): bump coverage from 7.2.1 to 7.2.2 ( #2112 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-21 08:18:47 +01:00
dependabot[bot]
be74e41d84
build(deps-dev): bump openapi-spec-validator from 0.5.5 to 0.5.6 ( #2110 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-21 07:52:50 +01:00
Sergio Garcia
848122b0ec
chore(release): update Prowler Version to 3.3.0 ( #2102 )
...
Co-authored-by: github-actions <noreply@github.com >
2023-03-16 22:30:02 +01:00
Nacho Rivera
0edcb7c0d9
fix(ulimit check): try except when checking ulimit ( #2096 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-03-16 17:39:46 +01:00
Pepe Fagoaga
cc58e06b5e
fix(providers): Move provider's logic outside main ( #2043 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-03-16 17:32:53 +01:00
Sergio Garcia
0d6ca606ea
fix(ec2_securitygroup_allow_wide_open_public_ipv4): correct check title ( #2101 )
2023-03-16 17:25:32 +01:00
Sergio Garcia
75ee93789f
chore(regions_update): Changes in regions for AWS services. ( #2095 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-16 17:14:40 +01:00
Sergio Garcia
05daddafbf
feat(SecurityHub): add compliance details to Security Hub findings ( #2100 )
2023-03-16 17:11:55 +01:00
Nacho Rivera
7bbce6725d
fix(ulimit check): test only when platform is not windows ( #2094 )
2023-03-16 08:38:37 +01:00
Nacho Rivera
789b211586
feat(lambda_cloudtrail check): improved logic and status extended ( #2092 )
2023-03-15 12:32:58 +01:00
Sergio Garcia
826a043748
chore(regions_update): Changes in regions for AWS services. ( #2091 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-15 12:28:03 +01:00
Sergio Garcia
6761048298
fix(cloudwatch): solve inexistent filterPattern error ( #2087 )
2023-03-14 14:46:34 +01:00
Sergio Garcia
738fc9acad
feat(compliance): add compliance field to HTML, CSV and JSON outputs including frameworks and reqs ( #2060 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-03-14 14:20:46 +01:00
Sergio Garcia
43c0540de7
chore(regions_update): Changes in regions for AWS services. ( #2085 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-14 13:11:02 +01:00
Sergio Garcia
2d1c3d8121
fix(emr): solve emr_cluster_publicly_accesible error ( #2086 )
2023-03-14 13:10:21 +01:00
dependabot[bot]
f48a5c650d
build(deps-dev): bump pytest-xdist from 3.2.0 to 3.2.1 ( #2084 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-14 10:21:17 +01:00
dependabot[bot]
66c18eddb8
build(deps): bump botocore from 1.29.86 to 1.29.90 ( #2083 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-14 10:01:23 +01:00
dependabot[bot]
fdd2ee6365
build(deps-dev): bump bandit from 1.7.4 to 1.7.5 ( #2082 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-14 09:03:46 +01:00
dependabot[bot]
c207f60ad8
build(deps): bump pydantic from 1.10.5 to 1.10.6 ( #2081 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-14 08:02:28 +01:00
dependabot[bot]
0eaa95c8c0
build(deps): bump mkdocs-material from 9.1.1 to 9.1.2 ( #2080 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-14 07:48:02 +01:00
Pepe Fagoaga
df2fca5935
fix(bug_report): typo in bug reporting template ( #2078 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-03-13 18:42:34 +01:00
Toni de la Fuente
dcaf5d9c7d
update(docs): update readme with new ECR alias ( #2079 )
2023-03-13 18:07:51 +01:00
Sergio Garcia
0112969a97
fix(compliance): add check to 2.1.5 CIS ( #2077 )
2023-03-13 09:25:51 +01:00
Sergio Garcia
3ec0f3d69c
chore(regions_update): Changes in regions for AWS services. ( #2075 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-13 07:51:13 +01:00
Pepe Fagoaga
5555d300a1
fix(bug_report): Update wording ( #2074 )
2023-03-10 12:21:51 +01:00
Nacho Rivera
8155ef4b60
feat(templates): New versions of issues and fr templates ( #2072 )
2023-03-10 10:32:17 +01:00
Sergio Garcia
a12402f6c8
chore(regions_update): Changes in regions for AWS services. ( #2073 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-10 10:27:29 +01:00
Sergio Garcia
cf28b814cb
fix(ec2): avoid terminated instances ( #2063 )
2023-03-10 08:11:35 +01:00
Pepe Fagoaga
b05f67db19
chore(actions): Missing cache in the PR ( #2067 )
2023-03-09 11:50:49 +01:00
Pepe Fagoaga
260f4659d5
chore(actions): Use GHA cache ( #2066 )
2023-03-09 10:29:16 +01:00
dependabot[bot]
9e700f298c
build(deps-dev): bump pylint from 2.16.4 to 2.17.0 ( #2062 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-08 15:41:22 +01:00
dependabot[bot]
56510734c4
build(deps): bump boto3 from 1.26.85 to 1.26.86 ( #2061 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-08 15:14:18 +01:00
Pepe Fagoaga
3938a4d14e
chore(dependabot): Change to weekly ( #2057 )
2023-03-08 14:41:34 +01:00
Sergio Garcia
fa3b9eeeaf
chore(regions_update): Changes in regions for AWS services. ( #2058 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-08 14:38:56 +01:00
dependabot[bot]
eb9d6fa25c
build(deps): bump botocore from 1.29.85 to 1.29.86 ( #2054 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-08 09:57:44 +01:00
Alex Nelson
b53307c1c2
docs: Corrected spelling mistake in multiacount ( #2056 )
2023-03-08 09:57:08 +01:00
dependabot[bot]
c3fc708a66
build(deps): bump boto3 from 1.26.82 to 1.26.85 ( #2053 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-08 09:03:00 +01:00
Sergio Garcia
b34ffbe6d0
feat(inventory): add tags to quick inventory ( #2051 )
2023-03-07 14:20:50 +01:00
Sergio Garcia
f364315e48
chore(iam): update Prowler permissions ( #2050 )
2023-03-07 14:14:31 +01:00
Sergio Garcia
3ddb5a13a5
fix(ulimit): handle low ulimit OSError ( #2042 )
...
Co-authored-by: Toni de la Fuente <toni@blyx.com >
2023-03-07 13:19:24 +01:00
dependabot[bot]
a24cc399a4
build(deps-dev): bump moto from 4.1.3 to 4.1.4 ( #2045 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-03-07 12:45:50 +01:00
Sergio Garcia
305f4b2688
chore(regions_update): Changes in regions for AWS services. ( #2049 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-07 11:27:28 +01:00
dependabot[bot]
9823171d65
build(deps-dev): bump pylint from 2.16.3 to 2.16.4 ( #2048 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-07 10:11:19 +01:00
dependabot[bot]
4761bd8fda
build(deps): bump mkdocs-material from 9.1.0 to 9.1.1 ( #2047 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-07 09:33:19 +01:00
dependabot[bot]
9c22698723
build(deps-dev): bump pytest from 7.2.1 to 7.2.2 ( #2046 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-07 08:32:19 +01:00
dependabot[bot]
e3892bbcc6
build(deps): bump botocore from 1.29.84 to 1.29.85 ( #2044 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-07 08:18:53 +01:00
Sergio Garcia
629b156f52
fix(quick inventory): add non-tagged s3 buckets to inventory ( #2041 )
2023-03-06 16:55:03 +01:00
Gary Mclean
c45dd47d34
fix(windows-path): --list-services bad split ( #2028 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-03-06 14:00:07 +01:00
Sergio Garcia
ef8831f784
feat(quick_inventory): add regions to inventory table ( #2026 )
2023-03-06 13:41:30 +01:00
Sergio Garcia
c5a42cf5de
feat(rds_instance_transport_encrypted): add new check ( #1963 )
...
Co-authored-by: Toni de la Fuente <toni@blyx.com >
2023-03-06 13:18:41 +01:00
dependabot[bot]
90ebbfc20f
build(deps-dev): bump pylint from 2.16.2 to 2.16.3 ( #2038 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-06 13:18:26 +01:00
Fennerr
17cd0dc91d
feat(new_check): cloudwatch_log_group_no_secrets_in_logs ( #1980 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: Jeffrey Souza <JeffreySouza@users.noreply.github.com >
2023-03-06 12:16:46 +01:00
dependabot[bot]
fa1f42af59
build(deps): bump botocore from 1.29.82 to 1.29.84 ( #2037 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-06 12:14:48 +01:00
Sergio Garcia
f45ea1ab53
fix(check): change cloudformation_outputs_find_secrets name ( #2027 )
2023-03-06 12:11:58 +01:00
Sergio Garcia
0dde3fe483
chore(poetry): add poetry checks to pre-commit ( #2040 )
2023-03-06 11:44:04 +01:00
dependabot[bot]
277dc7dd09
build(deps-dev): bump freezegun from 1.2.1 to 1.2.2 ( #2033 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-06 11:06:23 +01:00
dependabot[bot]
3215d0b856
build(deps-dev): bump coverage from 7.1.0 to 7.2.1 ( #2032 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-06 09:55:19 +01:00
dependabot[bot]
0167d5efcd
build(deps): bump mkdocs-material from 9.0.15 to 9.1.0 ( #2031 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-06 09:15:44 +01:00
Sergio Garcia
b48ac808a6
chore(regions_update): Changes in regions for AWS services. ( #2035 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-03 10:14:20 +01:00
dependabot[bot]
616524775c
build(deps-dev): bump docker from 6.0.0 to 6.0.1 ( #2030 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-03 10:02:11 +01:00
dependabot[bot]
5832849b11
build(deps): bump boto3 from 1.26.81 to 1.26.82 ( #2029 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-03 09:43:43 +01:00
Sergio Garcia
467c5d01e9
fix(cloudtrail): list tags only in owned trails ( #2025 )
2023-03-02 16:16:19 +01:00
Sergio Garcia
24711a2f39
feat(tags): add resource tags to S-W services ( #2020 )
2023-03-02 14:21:05 +01:00
Nacho Rivera
24e8286f35
feat(): 7 chars in dispatch commit message ( #2024 )
2023-03-02 14:20:31 +01:00
Sergio Garcia
e8a1378ad0
feat(tags): add resource tags to G-R services ( #2009 )
2023-03-02 13:56:22 +01:00
Sergio Garcia
76bb418ea9
feat(tags): add resource tags to E services ( #2007 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-03-02 13:55:26 +01:00
Nacho Rivera
cd8770a3e3
fix(actions): fixed dispatch commit message ( #2023 )
2023-03-02 13:55:03 +01:00
Sergio Garcia
da834c0935
feat(tags): add resource tags to C-D services ( #2003 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-03-02 13:14:53 +01:00
Nacho Rivera
024ffb1117
fix(head): Pass head commit to dispatch action ( #2022 )
2023-03-02 12:06:41 +01:00
Nacho Rivera
eed7ab9793
fix(iam): refactor IAM service ( #2010 )
2023-03-02 11:16:05 +01:00
Sergio Garcia
032feb343f
feat(tags): add resource tags in A services ( #1997 )
2023-03-02 10:59:49 +01:00
Pepe Fagoaga
eabccba3fa
fix(actions): push should be true ( #2019 )
2023-03-02 10:37:29 +01:00
Nacho Rivera
d86d656316
feat(dispatch): add tag info to dispatch ( #2002 )
2023-03-02 10:31:30 +01:00
Sergio Garcia
fa73c91b0b
chore(regions_update): Changes in regions for AWS services. ( #2018 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-02 10:23:59 +01:00
Pepe Fagoaga
2eee50832d
fix(actions): Stop using github storage ( #2016 )
2023-03-02 10:23:04 +01:00
Toni de la Fuente
b40736918b
docs(install): Add brew and github installation to quick start ( #1991 )
2023-03-02 10:21:57 +01:00
Sergio Garcia
ffb1a2e30f
chore(regions_update): Changes in regions for AWS services. ( #1995 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-02 10:21:41 +01:00
Sergio Garcia
d6c3c0c6c1
feat(s3_bucket_level_public_access_block): new check ( #1953 )
2023-03-02 10:18:27 +01:00
dependabot[bot]
ee251721ac
build(deps): bump botocore from 1.29.81 to 1.29.82 ( #2015 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-02 09:53:24 +01:00
dependabot[bot]
fdbb9195d5
build(deps-dev): bump moto from 4.1.2 to 4.1.3 ( #2014 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-02 09:23:48 +01:00
dependabot[bot]
c68b08d9af
build(deps-dev): bump black from 22.10.0 to 22.12.0 ( #2013 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-02 08:59:18 +01:00
dependabot[bot]
3653bbfca0
build(deps-dev): bump flake8 from 5.0.4 to 6.0.0 ( #2012 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-02 08:32:41 +01:00
dependabot[bot]
05c7cc7277
build(deps): bump boto3 from 1.26.80 to 1.26.81 ( #2011 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-02 07:54:33 +01:00
Sergio Garcia
5670bf099b
chore(regions_update): Changes in regions for AWS services. ( #2006 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-03-01 10:16:58 +01:00
Nacho Rivera
0c324b0f09
fix(awslambdacloudtrail): include advanced event and all lambdas in check ( #1994 )
2023-03-01 10:04:06 +01:00
dependabot[bot]
968557e38e
build(deps): bump botocore from 1.29.80 to 1.29.81 ( #2005 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-03-01 08:59:54 +01:00
dependabot[bot]
882cdebacb
build(deps): bump boto3 from 1.26.79 to 1.26.80 ( #2004 )
2023-03-01 08:40:41 +01:00
Sergio Garcia
07753e1774
feat(encryption): add new encryption category ( #1999 )
2023-02-28 13:42:11 +01:00
Pepe Fagoaga
5b984507fc
fix(emr): KeyError EmrManagedSlaveSecurityGroup ( #2000 )
2023-02-28 13:41:58 +01:00
Sergio Garcia
27df481967
chore(metadata): remove tags from metadata ( #1998 )
2023-02-28 12:27:59 +01:00
dependabot[bot]
0943031f23
build(deps): bump mkdocs-material from 9.0.14 to 9.0.15 ( #1993 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-28 11:02:59 +01:00
dependabot[bot]
2d95168de0
build(deps): bump botocore from 1.29.79 to 1.29.80 ( #1992 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-28 10:46:25 +01:00
Sergio Garcia
97cae8f92c
chore(brew): bump new version to brew ( #1990 )
2023-02-27 18:07:05 +01:00
github-actions
eb213bac92
chore(release): 3.2.4
2023-02-27 14:25:52 +01:00
Sergio Garcia
8187788b2c
fix(pypi-release.yml): create PR before replicating ( #1986 )
2023-02-27 14:16:53 +01:00
Sergio Garcia
c80e08abce
fix(compliance): solve AWS compliance dir path ( #1987 )
2023-02-27 14:16:17 +01:00
github-actions[bot]
42fd851e5c
chore(release): update Prowler Version to 3.2.3 ( #1985 )
...
Co-authored-by: github-actions <noreply@github.com >
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-02-27 13:59:28 +01:00
Pepe Fagoaga
70e4ebccab
chore(codeowners): Update team to OSS ( #1984 )
2023-02-27 13:31:16 +01:00
Sergio Garcia
140f87c741
chore(readme): add brew stats ( #1982 )
2023-02-27 13:17:48 +01:00
Pepe Fagoaga
b0d756123e
fix(action): Use PathContext to get version changes ( #1983 )
2023-02-27 13:17:09 +01:00
Pedro Martín González
6188c92916
chore(compliance): implements dynamic handling of available compliance frameworks ( #1977 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-02-27 10:47:47 +01:00
dependabot[bot]
34c6f96728
build(deps): bump boto3 from 1.26.74 to 1.26.79 ( #1981 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-27 09:45:45 +01:00
dependabot[bot]
50fd047c0b
build(deps): bump botocore from 1.29.78 to 1.29.79 ( #1978 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-27 09:14:29 +01:00
Sergio Garcia
5bcc05b536
chore(regions_update): Changes in regions for AWS services. ( #1972 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-24 12:10:27 +01:00
Sergio Garcia
ce7d6c8dd5
fix(service errors): solve EMR, VPC and ELBv2 service errors ( #1974 )
2023-02-24 10:49:54 +01:00
dependabot[bot]
d87a1e28b4
build(deps): bump alive-progress from 2.4.1 to 3.0.1 ( #1965 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-24 10:12:52 +01:00
Pepe Fagoaga
227306c572
fix(acm): Fix issues with list-certificates ( #1970 )
2023-02-24 10:12:38 +01:00
dependabot[bot]
45c2691f89
build(deps): bump mkdocs-material from 8.2.1 to 9.0.14 ( #1964 )
...
Signed-off-by: dependabot[bot] <support@github.com >
2023-02-24 10:03:52 +01:00
Pepe Fagoaga
d0c81245b8
fix(directoryservice): tzinfo without _ ( #1971 )
2023-02-24 10:03:34 +01:00
dependabot[bot]
e494afb1aa
build(deps): bump botocore from 1.29.74 to 1.29.78 ( #1968 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-24 09:43:14 +01:00
dependabot[bot]
ecc3c1cf3b
build(deps): bump azure-storage-blob from 12.14.1 to 12.15.0 ( #1966 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-24 08:42:44 +01:00
dependabot[bot]
228b16416a
build(deps): bump colorama from 0.4.5 to 0.4.6 ( #1967 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-24 07:56:47 +01:00
Nacho Rivera
17eb74842a
fix(cloudfront): handle empty objects in checks ( #1962 )
2023-02-23 16:57:44 +01:00
Nacho Rivera
c01ff74c73
fix(kms): handle if describe_keys returns no value
2023-02-23 15:54:23 +01:00
Sergio Garcia
f88613b26d
fix(toml): add toml dependency to pypi release action ( #1960 )
2023-02-23 15:24:46 +01:00
Sergio Garcia
3464f4241f
chore(release): 3.2.2 ( #1959 )
...
Co-authored-by: github-actions <noreply@github.com >
2023-02-23 15:10:03 +01:00
Sergio Garcia
849b703828
chore(resource-based scan): execute only applicable checks ( #1934 )
2023-02-23 13:30:21 +01:00
Sergio Garcia
4b935a40b6
fix(metadata): remove us-east-1 in remediation ( #1958 )
2023-02-23 13:19:10 +01:00
Sergio Garcia
5873a23ccb
fix(key errors): solver EMR and IAM errrors ( #1957 )
2023-02-23 13:15:00 +01:00
Nacho Rivera
eae2786825
fix(cloudtrail): Handle when the CloudTrail bucket is in another account ( #1956 )
2023-02-23 13:04:32 +01:00
github-actions[bot]
6407386de5
chore(regions_update): Changes in regions for AWS services. ( #1952 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-23 12:24:36 +01:00
Sergio Garcia
3fe950723f
fix(actions): add README to docker action and filter steps for releases ( #1955 )
2023-02-23 12:22:41 +01:00
Sergio Garcia
52bf6acd46
chore(regions): add secret token to avoid stuck checks ( #1954 )
2023-02-23 12:11:54 +01:00
Sergio Garcia
9590e7d7e0
chore(poetry): make python-poetry as packaging and dependency manager ( #1935 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-02-23 11:50:29 +01:00
github-actions[bot]
7a08140a2d
chore(regions_update): Changes in regions for AWS services. ( #1950 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-23 08:42:36 +01:00
dependabot[bot]
d1491cfbd1
build(deps): bump boto3 from 1.26.74 to 1.26.76 ( #1948 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-22 08:01:13 +01:00
dependabot[bot]
695b80549d
build(deps): bump botocore from 1.29.75 to 1.29.76 ( #1946 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-22 07:50:39 +01:00
Sergio Garcia
11c60a637f
release: 3.2.1 ( #1945 )
2023-02-21 17:22:02 +01:00
Sergio Garcia
844ad70bb9
fix(cloudwatch): allow " in regex patterns ( #1943 )
2023-02-21 16:46:23 +01:00
Sergio Garcia
5ac7cde577
chore(iam_disable_N_days_credentials): improve checks logic ( #1923 )
2023-02-21 15:20:33 +01:00
Sergio Garcia
ce3ef0550f
chore(Security Hub): add status extended to Security Hub ( #1921 )
2023-02-21 15:11:43 +01:00
Sergio Garcia
813f3e7d42
fix(errors): handle errors when S3 buckets or EC2 instances are deleted ( #1942 )
2023-02-21 12:31:23 +01:00
Sergio Garcia
d03f97af6b
fix(regions): add unique branch name ( #1941 )
2023-02-21 11:53:36 +01:00
github-actions[bot]
019ab0286d
chore(regions_update): Changes in regions for AWS services. ( #1940 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-21 11:47:03 +01:00
Fennerr
c6647b4706
chore(secrets): Improve the status_extended with more information ( #1937 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-02-21 11:37:20 +01:00
Sergio Garcia
f913536d88
fix(services): solve errors in EMR, RDS, S3 and VPC services ( #1913 )
2023-02-21 11:11:39 +01:00
dependabot[bot]
640d1bd176
build(deps-dev): bump moto from 4.1.2 to 4.1.3 ( #1939 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-21 07:48:08 +01:00
dependabot[bot]
66baccf528
build(deps): bump botocore from 1.29.74 to 1.29.75 ( #1938 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-21 07:32:44 +01:00
Sergio Garcia
6e6dacbace
chore(security hub): add --skip-sh-update ( #1911 )
2023-02-20 09:58:00 +01:00
dependabot[bot]
cdbb10fb26
build(deps): bump boto3 from 1.26.72 to 1.26.74 ( #1933 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-20 07:56:40 +01:00
dependabot[bot]
c34ba3918c
build(deps): bump botocore from 1.29.73 to 1.29.74 ( #1932 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-20 07:34:20 +01:00
Fennerr
fa228c876c
fix(iam_rotate_access_key_90_days): check only active access keys ( #1929 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-02-17 12:53:28 +01:00
dependabot[bot]
2f4d0af7d7
build(deps): bump botocore from 1.29.72 to 1.29.73 ( #1926 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-17 12:14:23 +01:00
github-actions[bot]
2d3e5235a9
chore(regions_update): Changes in regions for AWS services. ( #1927 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-17 11:13:13 +01:00
dependabot[bot]
8e91ccaa54
build(deps): bump boto3 from 1.26.71 to 1.26.72 ( #1925 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-17 10:56:19 +01:00
Fennerr
6955658b36
fix(quick_inventory): handle ApiGateway resources ( #1924 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-02-16 18:29:23 +01:00
Fennerr
dbb44401fd
fix(ecs_task_definitions_no_environment_secrets): dump_env_vars is reintialised ( #1922 )
2023-02-16 15:59:53 +01:00
dependabot[bot]
b42ed70c84
build(deps): bump botocore from 1.29.71 to 1.29.72 ( #1919 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-16 14:21:46 +01:00
dependabot[bot]
a28276d823
build(deps): bump pydantic from 1.10.4 to 1.10.5 ( #1918 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-16 13:51:37 +01:00
Pepe Fagoaga
fa4b27dd0e
fix(compliance): Set Version as optional and fix list ( #1899 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-02-16 12:47:39 +01:00
dependabot[bot]
0be44d5c49
build(deps): bump boto3 from 1.26.70 to 1.26.71 ( #1920 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-16 12:38:10 +01:00
github-actions[bot]
2514596276
chore(regions_update): Changes in regions for AWS services. ( #1910 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-16 11:56:10 +01:00
dependabot[bot]
7008d2a953
build(deps): bump botocore from 1.29.70 to 1.29.71 ( #1909 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-15 07:39:16 +01:00
dependabot[bot]
2539fedfc4
build(deps): bump boto3 from 1.26.69 to 1.26.70 ( #1908 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-15 07:12:18 +01:00
Ignacio Dominguez
b453df7591
fix(iam-credentials-expiration): IAM password policy expires passwords fix ( #1903 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-02-14 13:54:58 +01:00
Pepe Fagoaga
9e5d5edcba
fix(codebuild): Handle endTime in builds ( #1900 )
2023-02-14 11:27:53 +01:00
Nacho Rivera
2d5de6ff99
fix(cross account): cloudtrail s3 bucket logging ( #1902 )
2023-02-14 11:23:31 +01:00
github-actions[bot]
259e9f1c17
chore(regions_update): Changes in regions for AWS services. ( #1901 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-14 10:28:04 +01:00
dependabot[bot]
daeb53009e
build(deps): bump botocore from 1.29.69 to 1.29.70 ( #1898 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-14 08:27:14 +01:00
dependabot[bot]
f12d271ca5
build(deps): bump boto3 from 1.26.51 to 1.26.69 ( #1897 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-14 07:55:26 +01:00
dependabot[bot]
965185ca3b
build(deps-dev): bump pylint from 2.16.1 to 2.16.2 ( #1896 )
2023-02-14 07:35:29 +01:00
Pepe Fagoaga
9c484f6a78
Release: 3.2.0 ( #1894 )
2023-02-13 15:42:57 +01:00
Fennerr
de18c3c722
docs: Minor changes to logging ( #1893 )
2023-02-13 15:31:23 +01:00
Fennerr
9be753b281
docs: Minor changes to the intro paragraph ( #1892 )
2023-02-13 15:20:48 +01:00
Pepe Fagoaga
d6ae122de1
docs: Boto3 configuration ( #1885 )
...
Co-authored-by: Toni de la Fuente <toni@blyx.com >
2023-02-13 15:20:33 +01:00
Pepe Fagoaga
c6b90044f2
chore(Dockerfile): Remove build files ( #1886 )
2023-02-13 15:19:05 +01:00
Nacho Rivera
14898b6422
fix(Azure_Audit_Info): Added audited_resources field ( #1891 )
2023-02-13 15:17:11 +01:00
Fennerr
26294b0759
docs: Update AWS Role Assumption ( #1890 )
2023-02-13 15:13:22 +01:00
Nacho Rivera
6da45b5c2b
fix(list_checks): arn filtering checks after audit_info set ( #1887 )
2023-02-13 14:57:42 +01:00
Acknosyn
674332fddd
update(logging): fix plural grammar for checks execution message ( #1680 )
...
Co-authored-by: Francesco Badraun <francesco.badraun@zxsecurity.co.nz >
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-02-13 14:33:34 +01:00
Sergio Garcia
ab8942d05a
fix(service errors): solve errors in IAM, S3, Lambda, DS, Cloudfront services ( #1882 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-02-13 10:35:04 +01:00
github-actions[bot]
29790b8a5c
chore(regions_update): Changes in regions for AWS services. ( #1884 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-13 10:01:43 +01:00
dependabot[bot]
4a4c26ffeb
build(deps): bump botocore from 1.29.51 to 1.29.69 ( #1883 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-13 09:19:01 +01:00
Sergio Garcia
25c9bc07b2
chore(compliance): add manual checks to compliance CSV ( #1872 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-02-10 12:38:13 +01:00
Nacho Rivera
d22d4c4c83
fix(cloudtrail_multi_region_enabled): reformat check ( #1880 )
2023-02-10 12:34:53 +01:00
Sergio Garcia
d88640fd20
fix(errors): solve several services errors (AccessAnalyzer, AppStream, KMS, S3, SQS, R53, IAM, CodeArtifact and EC2) ( #1879 )
2023-02-10 12:26:00 +01:00
github-actions[bot]
57a2fca3a4
chore(regions_update): Changes in regions for AWS services. ( #1878 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-10 11:25:00 +01:00
Sergio Garcia
f796688c84
fix(metadata): typo in appstream_fleet_session_disconnect_timeout.metadata.json ( #1875 )
2023-02-09 16:22:19 +01:00
alexr3y
d6bbf8b7cc
update(compliance): ENS RD2022 Spanish security framework updates ( #1809 )
...
Co-authored-by: Sergio Garcia <sergargar1@gmail.com >
2023-02-09 14:14:38 +01:00
Nacho Rivera
37ec460f64
fix(hardware mfa): changed hardware mfa description ( #1873 )
2023-02-09 14:06:54 +01:00
Sergio Garcia
004b9c95e4
fix(key_errors): handle Key Errors in Lambda and EMR ( #1871 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-09 10:32:00 +01:00
github-actions[bot]
86e27b465a
chore(regions_update): Changes in regions for AWS services. ( #1870 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-09 10:17:18 +01:00
Nacho Rivera
5e9afddc3a
fix(permissive role assumption): actions list handling ( #1869 )
2023-02-09 10:06:53 +01:00
Pepe Fagoaga
de281535b1
feat(boto3-config): Use standard retrier ( #1868 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-02-09 09:58:47 +01:00
Pedro Martín González
9df7def14e
feat(compliance): Add 17 new security compliance frameworks for AWS ( #1824 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-09 07:39:57 +01:00
Sergio Garcia
5b9db9795d
feat(new check): add accessanalyzer_enabled check ( #1864 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-08 17:39:25 +01:00
Sergio Garcia
7d2ce7e6ab
fix(action): do not trigger action when editing release ( #1865 )
2023-02-08 17:34:02 +01:00
Oleksandr Mykytenko
3e807af2b2
fix(checks): added validation for non-existing VPC endpoint policy ( #1859 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-08 12:13:22 +01:00
Oleksandr Mykytenko
4c64dc7885
Fixed elbv2 service for GWLB resources ( #1860 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-08 10:38:34 +01:00
github-actions[bot]
e7a7874b34
chore(regions_update): Changes in regions for AWS services. ( #1863 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-08 10:36:03 +01:00
dependabot[bot]
c78a47788b
build(deps): bump cryptography from 39.0.0 to 39.0.1 ( #1862 )
2023-02-08 08:02:47 +01:00
dependabot[bot]
922698c5d9
build(deps-dev): bump pytest-xdist from 3.1.0 to 3.2.0 ( #1858 )
2023-02-07 18:04:30 +01:00
Sergio Garcia
8e8a490936
chore(release): 3.1.4 ( #1857 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-07 17:49:27 +01:00
Sergio Garcia
231bc0605f
fix(output_bucket): Use full path for -o option with output to S3 bucket ( #1854 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-02-07 17:28:25 +01:00
Carlos
0298ff9478
Change prowler additional policy json due errors in creation ( #1852 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2023-02-07 13:09:12 +01:00
Sergio Garcia
33a25dcf0e
fix(exit_code): change sys exit code to 1 in Critical Errors ( #1853 )
2023-02-07 11:43:14 +01:00
Sergio Garcia
54c16e3cdb
chore(security hub): improve securityhub_enabled check logic ( #1851 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-07 11:29:39 +01:00
github-actions[bot]
28a978acc2
chore(regions_update): Changes in regions for AWS services. ( #1849 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-07 10:58:10 +01:00
dependabot[bot]
bea26a461f
build(deps-dev): bump openapi-spec-validator from 0.5.4 to 0.5.5 ( #1846 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-07 09:58:56 +01:00
Sergio Garcia
ed54c5b8b9
feat(exit_code 3): add -z option ( #1848 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-07 09:51:46 +01:00
Sergio Garcia
13316b68aa
fix(checks): solve different errors in EFS, S3 and VPC ( #1841 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-07 09:42:10 +01:00
dependabot[bot]
043986f35b
build(deps-dev): bump sure from 2.0.0 to 2.0.1 ( #1847 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-07 09:28:26 +01:00
dependabot[bot]
2dc4421dd6
build(deps-dev): bump moto from 4.1.1 to 4.1.2 ( #1845 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-07 08:22:55 +01:00
Sergio Garcia
6c16e2bca2
fix(kms): call GetKeyRotationStatus only for Customer Keys ( #1842 )
2023-02-06 17:07:03 +01:00
Sergio Garcia
c2b4a8e115
fix(errors): solve CloudWatch, KMS, EMR and OpenSearch service errors ( #1843 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-06 16:59:46 +01:00
Toni de la Fuente
63b7bc8794
chore(issues): update bug_report.md ( #1844 )
2023-02-06 16:45:52 +01:00
github-actions[bot]
f41ae74ae2
chore(regions_update): Changes in regions for AWS services. ( #1840 )
2023-02-06 09:59:50 +01:00
Pepe Fagoaga
98689d223e
fix(lambda-runtime): Init value must be empty string ( #1837 )
2023-02-06 09:38:35 +01:00
Sergio Garcia
f19cf21146
fix(readme): correct PyPi download link ( #1836 )
2023-02-03 16:43:43 +01:00
Sergio Garcia
24e19e6b18
fix(errors): solve different errors in KMS, EFS and Lambda ( #1835 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-03 15:05:07 +01:00
Sergio Garcia
08376cb15e
chore(release): 3.1.3 ( #1832 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-03 14:32:15 +01:00
Pepe Fagoaga
5f6e4663c0
fix(action): Build from release branch ( #1834 )
2023-02-03 14:31:43 +01:00
Pepe Fagoaga
9b91c00fcc
fix(awslambda_function_no_secrets_in_code): Retrieve Code if set ( #1833 )
2023-02-03 14:28:31 +01:00
Sergio Garcia
229ab88c2f
fix(shub): update link to Security Hub documentation ( #1830 )
2023-02-03 14:10:27 +01:00
dependabot[bot]
8863d13578
build(deps-dev): bump pylint from 2.16.0 to 2.16.1 ( #1823 )
2023-02-03 14:03:20 +01:00
Nacho Rivera
e07fc9fbb9
fix(cloudtrail): included advanced data events selectors ( #1814 )
2023-02-03 14:02:16 +01:00
Sergio Garcia
0164574fdd
fix(KeyError): handle service key errors ( #1831 )
2023-02-03 12:28:23 +01:00
github-actions[bot]
98eec332d8
chore(regions_update): Changes in regions for AWS services. ( #1829 )
2023-02-03 11:30:01 +01:00
Oleksandr Mykytenko
3d2986fc64
fix(metadata) fixed typo in title for awslambda_function_not_publicly… ( #1826 )
2023-02-03 10:34:24 +01:00
dependabot[bot]
29e7f8581e
build(deps-dev): bump openapi-spec-validator from 0.5.2 to 0.5.4 ( #1821 )
2023-02-02 18:04:24 +01:00
dependabot[bot]
4ee3f6c87a
build(deps-dev): bump pylint from 2.15.10 to 2.16.0 ( #1815 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-02-02 11:39:32 +01:00
Sergio Garcia
b8c7440e1f
fix(KeyError): Handle service key errors ( #1819 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-02 11:34:19 +01:00
Sergio Garcia
d49ff8d9a4
chore(logs): improve check error logs ( #1818 )
2023-02-02 11:13:40 +01:00
github-actions[bot]
07198042bd
chore(regions_update): Changes in regions for AWS services. ( #1817 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-02 10:58:47 +01:00
Sergio Garcia
c7a9492e96
feat(scan-type): AWS Resource ARNs based scan ( #1807 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-02-01 14:09:22 +01:00
Sergio Garcia
360c6f3c1c
fix(cloudtrail): improve cloudtrail_cloudwatch_logging_enabled status extended ( #1813 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-02-01 14:08:11 +01:00
github-actions[bot]
89aab4acd5
chore(regions_update): Changes in regions for AWS services. ( #1812 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-02-01 10:15:10 +01:00
Nacho Rivera
d9b3e842d9
fix(accessanalyzer): no analyzers using pydantic ( #1806 )
2023-01-31 13:01:54 +01:00
Sergio Garcia
3ac4dc8392
feat(scanner): Tag-based scan ( #1751 )
...
Co-authored-by: Toni de la Fuente <toni@blyx.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-01-31 12:19:29 +01:00
Nacho Rivera
0d1a5318ec
feat(audit-metadata): retrieve audit metadata from execution ( #1803 )
2023-01-31 11:24:01 +01:00
Pepe Fagoaga
94b7a219fd
chore(regions): Change feat to chore ( #1805 )
2023-01-31 10:32:32 +01:00
github-actions[bot]
ba3eb71abd
feat(regions_update): Changes in regions for AWS services. ( #1804 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-01-31 10:22:05 +01:00
Sergio Garcia
bbc9e11205
fix(ec2_securitygroup_not_used): ignore default security groups ( #1800 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-30 16:51:07 +01:00
Sergio Garcia
75571e4266
fix(iam_avoid_root_usage): correct date logic ( #1801 )
2023-01-30 16:47:24 +01:00
Sergio Garcia
4e879271a0
fix(iam_policy_no_administrative_privileges): check only *:* permissions ( #1802 )
2023-01-30 16:47:09 +01:00
Nacho Rivera
552e0fefc3
fix(accessanalyzer_enabled_without_findings): fixed status findings ( #1799 )
2023-01-30 13:22:05 +01:00
Jose Luis Martinez
cb7439a831
feat(allowlist): AWS Lambda function support ( #1793 )
2023-01-30 11:30:29 +01:00
Sergio Garcia
35d6b8bbc6
chore(readme): add prowler PyPi stats ( #1798 )
2023-01-30 11:26:09 +01:00
Jose Luis Martinez
48b9220ffc
fix(allowlist): validate allowlist for any database format (file, dynamo, s3, etc) ( #1792 )
2023-01-30 10:30:46 +01:00
ifduyue
5537981877
Use docs.aws.amazon.com like other aws checks, not docs.amazonaws.cn ( #1790 )
2023-01-30 10:29:18 +01:00
Sergio Garcia
711f24a5b2
fix(partition): add dynamic partition in CloudTrail S3 DataEvents checks ( #1787 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-27 10:50:31 +01:00
Sergio Garcia
5d2b8bc8aa
fix(kms): add symmetric condition to kms_cmk_rotation_enabled check ( #1788 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-27 10:49:40 +01:00
github-actions[bot]
f6ea10db2d
feat(regions_update): Changes in regions for AWS services. ( #1786 )
2023-01-27 10:17:22 +01:00
Sergio Garcia
fc38ba3acb
docs(readme): correct compliance link ( #1780 )
2023-01-26 12:48:58 +01:00
Sergio Garcia
0830ad268f
chore(release): new version 3.1.2 ( #1779 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-26 12:44:43 +01:00
github-actions[bot]
e633664c2a
feat(regions_update): Changes in regions for AWS services. ( #1778 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-01-26 10:28:13 +01:00
Ozan-Ekinci
d4c7d9a60a
docs(grammar): Improved grammar in the Documentation paragraph #HSFDPMUW ( #1776 )
2023-01-26 10:18:42 +01:00
dependabot[bot]
5ee0d964f3
build(deps-dev): bump coverage from 7.0.5 to 7.1.0 ( #1777 )
2023-01-26 10:18:00 +01:00
Sergio Garcia
ba5e0f145f
fix(severity): update severities for Security Hub, GuardDuty and NACL related checks ( #1775 )
2023-01-25 15:03:43 +01:00
Nacho Rivera
34eb9cc063
fix(cloudtrail_multi_region_enabled.py): fixed region when no trails ( #1774 )
2023-01-25 14:33:24 +01:00
Sergio Garcia
a795fdc40d
fix(IAM): remove duplicate list_policies function ( #1763 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-25 13:58:58 +01:00
Sergio Garcia
24cba4c4ca
chore(contrib): CloudFormation of CodeBuild for v3 ( #1764 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Toni de la Fuente <toni@blyx.com >
2023-01-25 13:57:47 +01:00
Sergio Garcia
3d13f4bb9b
fix(apigatewayv2): correct apigatewayv2_access_logging_enabled check title ( #1769 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-25 13:56:28 +01:00
Sergio Garcia
e713d0d321
chore(readme): update pip package name ( #1768 )
2023-01-25 13:55:35 +01:00
Sergio Garcia
4e34be87a1
fix(json): close Json correctly when no findings ( #1773 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-25 13:54:48 +01:00
Sergio Garcia
07307d37a1
fix(iam): handle credential report errors ( #1765 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: n4ch04 <nacho@verica.io >
2023-01-25 10:31:58 +01:00
github-actions[bot]
81463181bc
feat(regions_update): Changes in regions for AWS services. ( #1772 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-01-25 10:31:04 +01:00
Acknosyn
02e57927fc
fix(): IAM status messages switched fail and pass text and some grammar ( #1756 )
...
Co-authored-by: Francesco Badraun <francesco.badraun@zxsecurity.co.nz >
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: n4ch04 <nachor1992@gmail.com >
2023-01-25 10:29:04 +01:00
Sergio Garcia
36925f0dbd
fix(): solve metadata replace ( #1755 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-24 13:45:46 +01:00
github-actions[bot]
f9b985e03d
feat(regions_update): Changes in regions for AWS services. ( #1761 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-24 10:39:49 +01:00
dependabot[bot]
598ad62b92
build(deps-dev): bump moto from 4.1.0 to 4.1.1 ( #1758 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-01-24 09:27:05 +01:00
github-actions[bot]
ea929ab713
feat(regions_update): Changes in regions for AWS services. ( #1748 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-01-23 12:43:51 +01:00
Ozan-Ekinci
04e56ced58
docs: Improved grammar in the AZ CLI / Browser / Managed Identity authentication paragraph #HSFDPMUW ( #1745 )
2023-01-23 10:24:23 +01:00
Vaibhav Bagaria
2278565b86
Update resource type for SQS and SNS ( #1747 )
2023-01-23 10:22:26 +01:00
Leon
afd0c56b44
fix(docs): Changed the azure subscription file text #HSFDPMUW ( #1749 )
2023-01-23 09:31:34 +01:00
Sergio Garcia
5ebdf66d22
release: 3.1.1 ( #1744 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-20 15:36:27 +01:00
Toni de la Fuente
177d8a72a7
docs: add mapping of v2 to v3 checks and update pip package name in docs ( #1742 )
2023-01-20 12:50:57 +01:00
Pepe Fagoaga
03ef80dd8e
fix(actions): Exclude docs folder in action ( #1743 )
2023-01-20 12:50:28 +01:00
Pepe Fagoaga
6f9825362a
chore(code-ql): test tool ( #1703 )
2023-01-20 12:31:53 +01:00
github-actions[bot]
2167154064
feat(regions_update): Changes in regions for AWS services. ( #1741 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-01-20 10:24:37 +01:00
Sergio Garcia
f88b35bd80
fix(rds): remove DocumentDB from RDS ( #1737 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-20 09:31:19 +01:00
Nacho Rivera
6b9520338e
fix(pipeline): fixed typo in main pipeline ( #1740 )
2023-01-20 09:30:53 +01:00
Sergio Garcia
438c087856
fix(arguments): improve quiet option ( #1723 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-20 09:14:38 +01:00
Nacho Rivera
2a43274b06
feat(dispatch): dispatch triggered actions ( #1739 )
2023-01-20 09:13:57 +01:00
github-actions[bot]
20a9336867
feat(regions_update): Changes in regions for AWS services. ( #1736 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-01-19 12:45:35 +01:00
Sergio Garcia
c921782714
feat(allowlist): add yaml structure validator ( #1735 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-18 17:49:13 +01:00
Sergio Garcia
776ac9e3d4
fix(lambda): solve lambda errors ( #1732 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-18 17:47:45 +01:00
Sergio Garcia
d02bd9b717
fix(allowlist): remove re.escape ( #1734 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-18 17:45:51 +01:00
Sergio Garcia
50070e8fe7
fix(IAM): add missing permissions for Prowler ( #1731 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-18 11:45:37 +01:00
github-actions[bot]
e3e3b3e279
feat(regions_update): Changes in regions for AWS services. ( #1730 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-01-18 11:01:46 +01:00
Pepe Fagoaga
38fba297e8
fix: remove old example ( #1728 )
2023-01-17 18:04:12 +01:00
Sergio Garcia
52d65ee4e8
feat(pypi): replicate PyPi package ( #1727 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-17 17:53:08 +01:00
Sergio Garcia
9ad2f33dd8
fix: remove check_sample.metadata.json ( #1725 )
2023-01-17 14:36:00 +01:00
Sergio Garcia
02ae23b11d
feat(release): add PyPi GitHub Action ( #1724 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-01-17 14:33:15 +01:00
Sergio Garcia
70c6d6e7ae
release: 3.1.0 ( #1722 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-17 13:15:07 +01:00
Sergio Garcia
8efebf992f
fix(metadata): fix recommendation in iam_role_cross_service_confused_deputy_prevention check ( #1721 )
2023-01-17 13:11:46 +01:00
Sergio Garcia
b9be94bcc5
feat(README): add pypi downloads ( #1720 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-17 13:05:44 +01:00
Sergio Garcia
e6310c32ac
feat(check): add iam_role_cross_service_confused_deputy_prevention check ( #1710 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-17 12:17:37 +01:00
Sergio Garcia
654b4702d0
fix(error): ecr_repositories_scan_vulnerabilities_in_latest_image report not found ( #1719 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-17 12:17:15 +01:00
dependabot[bot]
262b5a7ee5
build(deps-dev): bump openapi-spec-validator from 0.5.1 to 0.5.2 ( #1716 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-01-17 12:13:44 +01:00
Pepe Fagoaga
ef0d4fe34b
fix(fill_html_overview_statistics): Handle if file exists ( #1718 )
2023-01-17 11:40:05 +01:00
github-actions[bot]
c08342f40c
feat(regions_update): Changes in regions for AWS services. ( #1717 )
...
Co-authored-by: sergargar <sergargar@users.noreply.github.com >
2023-01-17 10:18:40 +01:00
Pepe Fagoaga
e7796268b5
feat(only_logs): New logging flag to only show execution logs ( #1708 )
2023-01-17 10:13:09 +01:00
Nacho Rivera
0cbe80d2ab
feat(report): conditional import ( #1702 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-01-17 10:00:31 +01:00
Ozan-Ekinci
11d3ba70a0
docs: missing comma in the Service Principal authentication paragraph ( #1713 )
...
Co-authored-by: Ozan-Can Ekinci <ozan-can.ekinci1@informatik.hs-fulda >
2023-01-17 08:50:52 +01:00
dependabot[bot]
c30e4c4867
build(deps-dev): bump pytest from 7.2.0 to 7.2.1 ( #1715 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-01-17 08:42:48 +01:00
Sergio Garcia
d1e5087c18
fix(): add permissions to Github action ( #1712 )
2023-01-16 16:04:57 +01:00
Gabriel Soltz
618dd442e3
Incorrect ResourceType for check ec2_elastic_ip_unassgined ( #1711 )
2023-01-16 14:16:35 +01:00
Sergio Garcia
7f26fdf2d0
feat(iam): add IAM Role Class ( #1709 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-16 11:47:23 +01:00
Gabriel Soltz
64090474e1
fix(apigateway): Add ApiGateway ResourceArn and check fixes ( #1707 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-16 10:23:14 +01:00
Leon
a69c28713a
fix(docs): Include multiple commas in the troubleshooting file #HSFDPMUW ( #1706 )
2023-01-16 09:05:24 +01:00
Leon
1d4b3095af
fix(docs): Include a new comma in the Basic Usage paragraph #HSFDPMUW ( #1705 )
2023-01-16 09:04:48 +01:00
Sergio Garcia
ff75125af8
fix(docs): correct permissions links ( #1701 )
2023-01-13 10:28:54 +01:00
Toni de la Fuente
aa0025abbe
fix(quick_inventory): Prowler quick inventory for US GovCloud and China ( #1698 )
2023-01-12 17:40:10 +01:00
Sergio Garcia
c9436da235
fix: Solve IAM policy Errors ( #1692 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-12 17:39:09 +01:00
Sergio Garcia
12f1eaace7
fix: VPC Key Error ( #1695 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-12 17:35:57 +01:00
Sergio Garcia
09ef8aba0f
fix(): set default region CloudWatch ( #1693 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-12 17:17:40 +01:00
Toni de la Fuente
08c094b8a5
docs(SECURITY.md): Include Security Policy ( #1697 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-01-12 17:16:46 +01:00
Sergio Garcia
e9fb4410cd
fix(docs): Add security section and solve images location ( #1696 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: Toni de la Fuente <toni@blyx.com >
2023-01-12 17:16:34 +01:00
Nacho Rivera
cbdda22a33
fix: deleted test exclusion in name loading checks ( #1694 )
2023-01-12 15:43:54 +01:00
Sergio Garcia
fe906477da
fix(aws_regions_by_service.json): FileNotFoundError[13] ( #1689 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-12 13:24:03 +01:00
dependabot[bot]
b03df619df
build(deps-dev): bump coverage from 7.0.4 to 7.0.5 ( #1688 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-01-12 11:32:41 +01:00
Sergio Garcia
53d89d8d17
fix: solve multiple errors ( #1690 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-12 11:29:33 +01:00
Sergio Garcia
1e5a1f3e1f
fix: remove unnecessary print ( #1686 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-12 08:58:15 +01:00
Nacho Rivera
6efe2979c6
fix(): Edit troubleshooting page ( #1685 )
2023-01-11 11:18:37 +01:00
Sergio Garcia
92cc2c8e69
fix(config): path error in Windows environment ( #1684 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-10 17:06:14 +01:00
dependabot[bot]
50dd2e4179
build(deps-dev): bump vulture from 2.6 to 2.7 ( #1677 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-01-10 08:26:44 +01:00
dependabot[bot]
7a8fd9c3d3
build(deps-dev): bump coverage from 7.0.3 to 7.0.4 ( #1678 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-01-10 08:15:55 +01:00
dependabot[bot]
d5a3fc490b
build(deps-dev): bump moto from 4.0.13 to 4.1.0 ( #1675 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-01-10 07:56:16 +01:00
dependabot[bot]
13f948062b
build(deps-dev): bump pylint from 2.15.9 to 2.15.10 ( #1676 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-01-10 07:43:54 +01:00
Fennerr
b965fda226
feat(ecs_task_definitions_no_environment_secrets): Update resource_id ( #1665 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-09 16:05:45 +01:00
Sergio Garcia
f9d67f0e9d
fix(compliance): Security Hub working with compliance ( #1673 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-09 14:18:12 +01:00
Sergio Garcia
4dfa20e40b
fix(Security Hub): associate resource_arn as resourceId ( #1672 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-09 14:16:57 +01:00
Gabriel Soltz
d5edbaa3a9
fix(s3): Add S3 ResourceArn ( #1666 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-09 11:04:09 +01:00
Leon
0cd5ce8c29
fix(docs): Include a comma in the permissions paragraph ( #1668 )
2023-01-09 09:52:36 +01:00
Sergio Garcia
1c50a87ca2
fix(trustedadvisor_errors_and_warnings): add region ( #1662 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-05 17:57:21 +01:00
Sergio Garcia
efa83e05e4
release: 3.0.2 ( #1660 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-05 14:01:24 +01:00
Fennerr
76a694d043
feat(): add ECS task revision number ( #1657 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-05 13:36:32 +01:00
Fennerr
571280f0cd
feat(): update recommendation of ecs_task_definitions_no_environment_secrets ( #1658 )
2023-01-05 13:11:05 +01:00
dependabot[bot]
c2fc01608e
build(deps-dev): bump moto from 4.0.12 to 4.0.13 ( #1656 )
2023-01-05 08:52:19 +01:00
dependabot[bot]
2ba144843a
build(deps-dev): bump coverage from 7.0.2 to 7.0.3 ( #1655 )
2023-01-05 07:57:49 +01:00
Sergio Garcia
458dadc9b6
fix(contrib): Update contrib folder ( #1635 )
2023-01-04 13:11:51 +01:00
Gabriel Soltz
6ed0c59762
feat(ec2): Add ResourceArn ( #1649 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-04 11:55:58 +01:00
Sergio Garcia
54fbaa808e
fix(glacier): handle no vault policy error ( #1650 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-04 11:41:56 +01:00
Nacho Rivera
f0db63da35
fix(): Refresh credentials when assuming role ( #1636 )
2023-01-04 08:48:00 +01:00
Sergio Garcia
9b8c80b74d
fix(codeartifact): set Namespace attribute as optional ( #1648 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-03 16:04:40 +01:00
github-actions[bot]
0c23b6af84
feat(regions_update): Changes in regions for AWS services. ( #1646 )
2023-01-03 14:00:09 +01:00
Sergio Garcia
1189177079
fix: GH Action permissions ( #1644 )
2023-01-03 13:58:49 +01:00
Sergio Garcia
794402e92d
fix: add Github Action permission ( #1643 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-01-03 13:32:09 +01:00
Sergio Garcia
0de6d87af5
feat(aws-regions): update refresh regions action ( #1641 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2023-01-03 12:59:08 +01:00
dependabot[bot]
567c150eaa
build(deps-dev): bump coverage from 7.0.1 to 7.0.2 ( #1640 )
2023-01-03 08:03:29 +01:00
Peter Dave Hello
7ea9225277
Remove additional apk update in Dockerfile ( #1617 )
2023-01-02 18:41:46 +01:00
Sergio Garcia
df25ead15a
fix(): update pipfile.lock ( #1639 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-02 17:25:07 +01:00
Nacho Rivera
5227d57a55
fix(): Delete old reqs from issue template ( #1638 )
2023-01-02 17:17:24 +01:00
Sergio Garcia
8db86992aa
fix(outputs): apply -q to security hub ( #1637 )
...
Co-authored-by: sergargar <sergio@verica.io >
2023-01-02 15:56:49 +01:00
Nacho Rivera
79c09e613b
fix(): password enabled issues in iam_user_mfa_enabled_console_access ( #1634 )
2023-01-02 14:08:45 +01:00
Pepe Fagoaga
99d1cea537
fix(output_filename): Use custom output filename when set ( #1632 )
2023-01-02 10:37:01 +01:00
Christian Clauss
98bc3f18fe
docs: Fix typo in Azure documentation ( #1619 )
2023-01-02 08:27:44 +01:00
github-actions[bot]
b007d01057
feat(regions_update): Changes in regions for AWS services. ( #1629 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2023-01-02 08:26:18 +01:00
dependabot[bot]
ea85e0824b
build(deps-dev): bump coverage from 7.0.0 to 7.0.1 ( #1618 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-01-02 08:22:49 +01:00
Toni de la Fuente
d75b48877d
docs(install): Add multiple ways to install Prowler ( #1627 )
2023-01-02 08:09:22 +01:00
Ikko Ashimine
94bda8c17d
docs(AWS-Role): fixed typo ( #1610 )
2022-12-26 12:06:29 +01:00
Pepe Fagoaga
f05cb2859e
fix(output-filename): Handle argument ( #1604 )
2022-12-23 14:11:32 +01:00
Sergio Garcia
3c6254f086
feat(3.0.1): 3.0.1 release ( #1601 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-23 12:51:35 +01:00
Sergio Garcia
d9dc6c0a49
fix(global_services): handle global regions correctly ( #1594 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-12-23 12:32:31 +01:00
Nacho Rivera
3cfe1b8376
docs: Include Azure requirements in README ( #1600 )
2022-12-23 12:31:16 +01:00
Nacho Rivera
83275c5fd0
fix(send to s3): fixed send to s3 feature ( #1599 )
2022-12-23 11:38:42 +01:00
Pepe Fagoaga
e4698b5843
fix(check_report): Init status field and fix stats output ( #1580 )
2022-12-23 11:16:39 +01:00
Pepe Fagoaga
c4b134c0b5
fix(refresh-aws-regions): Change branch ( #1598 )
2022-12-23 10:30:44 +01:00
Sergio Garcia
5065cdb9e6
fix(sqs): Get SQS encryption ( #1596 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-23 10:24:10 +01:00
Sergio Garcia
f72be9a1e4
feat(errors): prettify unknown service errors ( #1592 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-22 17:02:28 +01:00
Sergio Garcia
a53f9eb294
fix(aws-cn partition): solve aws-cn partition errors ( #1576 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-12-22 15:39:50 +01:00
Sergio Garcia
44e0eedac2
fix(efs): handle PolicyNotFound error ( #1591 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-22 15:38:16 +01:00
Sergio Garcia
d894556191
fix(shub): Handle Security Hub InvalidAccessException error ( #1590 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-22 15:13:20 +01:00
Nacho Rivera
00cac892a7
fix(list services): Solve list services issue ( #1587 )
2022-12-22 15:00:08 +01:00
Sergio Garcia
167d332257
fix(vpc): endpoint policy error ( #1588 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-22 14:50:55 +01:00
Sergio Garcia
258abf6fe3
fix(iam): handle NoSuchEntity error ( #1589 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-22 14:49:41 +01:00
Sergio Garcia
451b362c52
fix(ECR): handle ECR errors that are not AccessDenied ( #1586 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-22 13:29:59 +01:00
Sergio Garcia
ff6b433661
fix(errors): Handle S3 errors that are not Access Denied ( #1585 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-22 13:26:22 +01:00
dependabot[bot]
3af2a44c70
build(deps-dev): bump pylint from 2.15.8 to 2.15.9 ( #1569 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-12-22 13:10:21 +01:00
dependabot[bot]
7f712e4d72
build(deps-dev): bump moto from 4.0.11 to 4.0.12 ( #1570 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-12-22 13:02:17 +01:00
Jonty Behr
28dee33e4f
docs(links): Update broken links to permissions folder ( #1584 )
2022-12-22 12:59:04 +01:00
dependabot[bot]
2d0b503f9f
build(deps-dev): bump coverage from 6.5.0 to 7.0.0 ( #1568 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-12-22 12:51:52 +01:00
Pepe Fagoaga
b0b706e2f4
feat(dependabot): Daily check ( #1582 )
2022-12-22 12:34:23 +01:00
Pepe Fagoaga
0391fad32b
feat(issues): Disable blank issues ( #1583 )
2022-12-22 12:32:19 +01:00
Pepe Fagoaga
167902616c
test(credential_report): Improve credential report tests ( #1579 )
2022-12-22 12:20:54 +01:00
Sergio Garcia
ea42a6274b
fix(logs): add check_name to logs ( #1574 )
2022-12-22 11:48:44 +01:00
Pepe Fagoaga
65e72d6937
fix(issue_template): Update for Prowler v3 ( #1581 )
2022-12-22 11:02:25 +01:00
Sergio Garcia
bb5ba8c37c
fix(description): pyproject.toml description ( #1567 )
2022-12-21 12:08:46 +01:00
Pepe Fagoaga
f5e5921abc
feat(dependabot): Automatic updates ( #1564 )
2022-12-21 12:02:29 +01:00
Pepe Fagoaga
80a8cfb6a6
fix(build-push): Update for 3.0 ( #1563 )
2022-12-21 11:47:32 +01:00
Pepe Fagoaga
4e34040e62
docs(usage): Format epilog ( #1562 )
2022-12-21 10:42:19 +01:00
github-actions[bot]
ba2620d91d
feat(regions_update): Changes in regions for AWS services. ( #1561 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-12-21 10:15:51 +01:00
Pepe Fagoaga
c2ae4a5efd
docs(README): Chame img relative paths to permalinks ( #1560 )
2022-12-21 09:25:20 +01:00
Toni de la Fuente
62c1ce73bb
feat(docs): added AWS CloudShell and rename FAQ to Troubleshooting ( #1559 )
2022-12-21 08:39:07 +01:00
Sergio Garcia
bab6380d68
fix: Refactor Outputs ( #1548 )
2022-12-20 18:23:30 +01:00
github-actions[bot]
9502355d22
feat(regions_update): Changes in regions for AWS services. ( #1557 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-12-20 13:09:12 +01:00
Pepe Fagoaga
a82d9591ab
fix(Dockerfile): Build from source ( #1555 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-20 13:08:53 +01:00
Pepe Fagoaga
d8fe11f393
docs(AWS-Role): Include section and remove CLI ( #1556 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-12-20 13:01:26 +01:00
Toni de la Fuente
df5963082c
docs: Add multiaccount scan in docs ( #1554 )
2022-12-20 11:47:52 +01:00
Toni de la Fuente
c3980e4f27
docs: General changes ( #1552 )
...
Co-authored-by: Sergio Garcia <sergio@verica.io >
2022-12-19 18:29:26 +01:00
Toni de la Fuente
a7155300d3
update(docs): update compliance and links ( #1551 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-12-19 17:00:33 +01:00
Pepe Fagoaga
b622fe7229
feat(HTML): Fix layout and include stats ( #1549 )
2022-12-19 14:34:41 +01:00
Sergio Garcia
2ddf3c8881
feat(docs): add Powler config.yaml information to docs ( #1546 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-19 14:27:25 +01:00
Pepe Fagoaga
38ba009794
delete: Old Dockerfile ( #1550 )
2022-12-19 14:23:16 +01:00
Pepe Fagoaga
a55649b3e1
feat(outputs): Unify classes to generate outputs dynamically based on the provider ( #1545 )
...
Co-authored-by: n4ch04 <nachor1992@gmail.com >
Co-authored-by: sergargar <sergio@verica.io >
2022-12-19 13:03:04 +01:00
github-actions[bot]
fdf80ed89d
feat(regions_update): Changes in regions for AWS services. ( #1544 )
2022-12-16 12:20:44 +01:00
Pepe Fagoaga
2da27d59b6
fix: Release fixes ( #1543 )
2022-12-15 15:16:29 +01:00
Sergio Garcia
b67e718412
feat(config): add comments to config ( #1542 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-15 10:41:21 +01:00
github-actions[bot]
b05286f455
feat(regions_update): Changes in regions for AWS services. ( #1541 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-12-15 10:22:37 +01:00
Pepe Fagoaga
2a5f032a52
feat(args): Global and provider-specific arguments ( #1540 )
2022-12-14 17:39:05 +01:00
github-actions[bot]
27a79d9c8c
feat(regions_update): Changes in regions for AWS services. ( #1524 )
2022-12-14 15:06:02 +01:00
Nacho Rivera
7ff72c048a
feat(Audit_Info): Unifying import set audit info for different providers ( #1538 )
2022-12-14 11:34:14 +01:00
Sergio Garcia
388c0b2b9f
feat(parse_regions): Add AWS regions parser && Dockerfile ( #1537 )
2022-12-13 19:00:43 +01:00
Sergio Garcia
bb09267f2a
feat(pip): Prepare for PyPI ( #1531 )
2022-12-13 09:07:55 +01:00
Sergio Garcia
0cd13b90f4
feat(docs): Add compliance and inventory docs ( #1534 )
2022-12-12 17:20:45 +01:00
Sergio Garcia
fbb39a364e
feat(quick_inventory): add quick inventory ( #1533 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-07 19:02:05 +01:00
Sergio Garcia
7bffe6b2d5
fix(html): fix error html generator ( #1530 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Toni de la Fuente <toni@blyx.com >
2022-12-07 13:04:38 +01:00
Sergio Garcia
df4b89366c
feat(docs): add new docs and readme ( #1529 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: n4ch04 <nachor1992@gmail.com >
2022-12-07 12:08:30 +01:00
Sergio Garcia
05075d6508
feat(cis_ouput): add csv output and table ( #1532 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-12-07 12:06:28 +01:00
Nacho Rivera
5e40d93d63
feat(Azure): Include multiple authentication ( #1528 )
2022-12-02 09:20:56 +01:00
Pepe Fagoaga
c2f5177afa
fix(list-groups): Delete option ( #1527 )
2022-11-29 16:51:06 +01:00
Nacho Rivera
e5e01e51a9
feat(azure): subscription as parameter ( #1526 )
2022-11-29 13:46:38 +01:00
Sergio Garcia
8f802f1241
feat(html): add html output ( #1525 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-11-29 13:44:52 +01:00
Pepe Fagoaga
a54372e05e
feat(categories): Remove old groups and use categories from metadata ( #1523 )
2022-11-29 11:09:50 +01:00
Nacho Rivera
f964439a15
fix(Pipfile): pipfile azure packages from dev to general ( #1522 )
2022-11-28 13:25:00 +01:00
github-actions[bot]
309c1e004b
feat(regions_update): Changes in regions for AWS services. ( #1516 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-11-28 12:19:02 +01:00
Pepe Fagoaga
9d91250f05
fix(globalaccelerator): Region must be us-west-2 ( #1518 )
2022-11-28 12:12:49 +01:00
Pepe Fagoaga
1f7262aaaa
fix(route53domains): Set us-east-1 as region ( #1521 )
2022-11-28 12:12:20 +01:00
Nacho Rivera
9a5e433489
fix(outputs): Table and Azure metadata ( #1520 )
2022-11-28 11:16:13 +01:00
Pepe Fagoaga
d1f5d58eeb
fix(directoryservice): Use ID instead of Name ( #1519 )
2022-11-28 11:08:52 +01:00
Nacho Rivera
e3d118f5bc
feat(): Azure provider and checks ( #1517 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-11-28 10:07:25 +01:00
Pepe Fagoaga
1a11f5777a
fix(compliance): List Compliance Requirements ( #1514 )
2022-11-23 17:53:49 +01:00
Pepe Fagoaga
b3e57ca3e5
feat(compliance): Loader and Execute ( #1465 )
2022-11-23 15:53:53 +01:00
github-actions[bot]
1a70a45805
feat(regions_update): Changes in regions for AWS services. ( #1508 )
2022-11-23 15:11:22 +01:00
Sergio Garcia
989638a42d
feat(RDS): Service and missing checks ( #1513 )
2022-11-23 14:34:51 +01:00
Sergio Garcia
9204142eaf
feat(display): add progress bar and summary table ( #1512 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-11-22 11:18:43 +01:00
alexr3y
af1d85ae75
feat(compliance): ENS RD2022 first draft and json converter ( #1502 )
2022-11-21 12:13:24 +01:00
Toni de la Fuente
25d92ca4b0
feat(CIS): Compliance for CIS AWS 1.4 and 1.5 ( #1509 )
2022-11-21 11:30:21 +01:00
Sergio Garcia
52a3e990c6
feat(shield): Service and checks ( #1504 )
2022-11-21 10:18:54 +01:00
Pepe Fagoaga
1370e0dec4
fix(directoryservice): Errors related to the DS Type ( #1506 )
2022-11-21 09:59:37 +01:00
github-actions[bot]
f99a89eae2
feat(regions_update): Changes in regions for AWS services. ( #1484 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-11-21 07:54:13 +01:00
Pepe Fagoaga
9954763356
feat(Lambda): Service and checks ( #1491 )
2022-11-17 22:59:28 +01:00
Nacho Rivera
538496ed6b
feat(): workspace service and checks ( #1503 )
2022-11-17 22:59:14 +01:00
Nacho Rivera
7d80a9d048
feat(): ECS service and checks ( #1476 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: sergargar <sergio@verica.io >
2022-11-17 22:54:38 +01:00
Nacho Rivera
a0ef56f245
feat(): sqs service and checks ( #1501 )
2022-11-17 22:51:36 +01:00
Sergio Garcia
e016fb2d6b
feat(TrustedAvisor): add TrustedAvisor tests and checks ( #1498 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-11-17 22:36:06 +01:00
Sergio Garcia
62081cb399
feat(ec2): add extra7124 ( #1500 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-11-17 22:34:56 +01:00
Sergio Garcia
bfc8c90abb
feat(Glue): add Glue tests and checks ( #1495 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-11-17 21:06:15 +01:00
Sergio Garcia
967990b76d
feat(EC2): add EC2 tests and checks ( #1482 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-11-17 21:01:47 +01:00
Pepe Fagoaga
6ff9f30473
feat(ssm): Service and checks ( #1496 )
2022-11-17 20:59:55 +01:00
Nacho Rivera
025b0547cd
feat(): redshift service and checks ( #1497 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-11-17 20:50:30 +01:00
Sergio Garcia
3370475fe9
feat(ELB): add ELB and ELBv2 tests and checks ( #1489 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-11-17 20:30:27 +01:00
Pepe Fagoaga
12896cceaa
feat(Route53): Service and checks ( #1493 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-11-17 19:57:20 +01:00
Nacho Rivera
62ffe26b42
feat(): sns checks and services ( #1494 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-11-17 19:45:41 +01:00
Nacho Rivera
c83c4d0892
feat(): ECR service and checks ( #1475 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
Co-authored-by: sergargar <sergio@verica.io >
2022-11-17 19:41:03 +01:00
Nacho Rivera
9ff9b68d91
feat(): guardduty checks and service ( #1492 )
2022-11-17 19:29:36 +01:00
Nacho Rivera
daa299c7a6
feat(): Sagemaker service and checks ( #1490 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-11-17 12:56:36 +01:00
Nacho Rivera
67b5de205b
feat(): EKS service and checks ( #1479 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
Co-authored-by: sergargar <sergio@verica.io >
2022-11-17 11:50:13 +01:00
Nacho Rivera
5a9c064943
feat(): opensearch service and checks ( #1487 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-11-17 11:48:18 +01:00
Pepe Fagoaga
24ca19d502
feat(EMR): Service and checks ( #1486 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-11-17 11:31:20 +01:00
Pepe Fagoaga
d2d2c75967
feat(directoryservice): Service and checks ( #1477 )
2022-11-17 11:16:36 +01:00
Pepe Fagoaga
684b7fe0b8
feat(secretsmanager): Service and check ( #1483 )
2022-11-16 10:23:05 +01:00
Pepe Fagoaga
2c5320a0b0
feat(CloudFront): Service and Checks ( #1470 )
2022-11-16 10:21:43 +01:00
Pepe Fagoaga
30738d7810
feat(Glacier): Service and check ( #1480 )
2022-11-15 17:41:58 +01:00
Sergio Garcia
5281d521f4
feat(DynamoDB): add DynamoDB service and checks ( #1468 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-11-15 14:21:09 +01:00
github-actions[bot]
58bdbadb11
feat(regions_update): Changes in regions for AWS services. ( #1478 )
2022-11-15 11:16:28 +01:00
github-actions[bot]
e9b2f1d2fb
feat(regions_update): Changes in regions for AWS services. ( #1466 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-11-14 17:54:46 +01:00
Sergio Garcia
8c8763a620
feat(CIS checks): Complete CIS checks ( #1461 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Nacho Rivera <59198746+n4ch04@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-11-14 17:50:26 +01:00
Pepe Fagoaga
6497f7bfe8
fix(codebuild_project_user_controlled_buildspec): regex ( #1474 )
2022-11-14 17:35:23 +01:00
Pepe Fagoaga
9b035230ac
feat(CodeArtifact): Service and checks ( #1473 )
2022-11-14 16:28:00 +01:00
Pepe Fagoaga
9d3bff9e54
fix: Linter issues ( #1471 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-11-14 16:21:51 +01:00
Nacho Rivera
3b86b3ac77
feat(codebuild): codebuild service and checks ( #1467 )
2022-11-14 15:09:56 +01:00
Nacho Rivera
c87327bb77
feat(EFS): Service and checks ( #1469 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
Co-authored-by: sergargar <sergio@verica.io >
2022-11-14 15:05:41 +01:00
github-actions[bot]
c9880b953f
feat(regions_update): Changes in regions for AWS services. ( #1457 )
2022-11-10 18:13:20 +01:00
Sergio Garcia
b187bf12c2
feat(CloudWatch): add CloudWatch service and checks ( #1456 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Nacho Rivera <59198746+n4ch04@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-11-10 13:29:46 +01:00
Sergio Garcia
19ab29628f
feat(S3): add S3 service and checks ( #1450 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-11-08 18:06:06 +01:00
github-actions[bot]
bbecd505eb
feat(regions_update): Changes in regions for AWS services. ( #1453 )
2022-11-08 12:26:57 +01:00
Pepe Fagoaga
69d3a9e363
feat(cloudformation): Service and Checks ( #1454 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-11-07 16:17:38 +01:00
Pepe Fagoaga
f5873fe0d7
feat(appstream): Service and Checks ( #1452 )
2022-11-07 16:16:58 +01:00
Nacho Rivera
4762e1cc4c
feat(test): Remaining IAM tests ( #1451 )
2022-11-04 13:38:22 +01:00
Nacho Rivera
8ae989cce8
feat(cloudtrail): cloudtrail service and checks ( #1449 )
...
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-11-03 15:39:41 +01:00
Sergio Garcia
c6adf3a6d8
feat(account): Aaccount service and manual checks ( #1446 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-11-02 11:36:57 +01:00
Pepe Fagoaga
976e07c125
feat(services): Sort services alphabetically ( #1443 )
2022-10-31 15:06:01 +01:00
Sergio Garcia
7c1dc1c977
feat(count): add number of services and checks ( #1442 )
2022-10-31 14:49:54 +01:00
Sergio Garcia
3e749dd652
feat(config): add config service and checks and check43 ( #1441 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-10-31 14:37:59 +01:00
Sergio Garcia
adf04ba632
feat(apigateway): Service and checks for APIGW v1 and v2 ( #1415 )
2022-10-31 14:13:11 +01:00
Sergio Garcia
f7842fdcdd
feat(kms): add service, checks and tests ( #1439 )
2022-10-28 12:30:34 +02:00
Sergio Garcia
b2976984d3
feat(vpc): add service, checks and tests ( #1432 )
2022-10-28 12:15:15 +02:00
Sergio Garcia
7e1b0d13c7
feat(autoscaling): Add AutoScaling service, check and test ( #1426 )
2022-10-28 09:33:29 +02:00
Pepe Fagoaga
8487777f96
fix(typo): FPT -> FTP ( #1431 )
2022-10-26 08:57:45 +02:00
Nacho Rivera
2d86254549
fix(allowlist): allowlist file default value ( #1425 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-10-24 09:29:24 +02:00
github-actions[bot]
e77486f771
feat(regions_update): Changes in regions for AWS services. ( #1424 )
2022-10-24 09:14:28 +02:00
Sergio Garcia
53f8a9698f
feat(allowlist): Add Allowlist feature ( #1395 )
2022-10-21 11:33:23 +02:00
Sergio Garcia
bd6eb723dd
feat(ACM): Add check and service for ACM ( #1365 )
2022-10-20 17:17:12 +02:00
Sergio Garcia
5c78e6b171
feat(line_no): Add line number to errors ( #1422 )
2022-10-20 14:32:35 +02:00
github-actions[bot]
44ce95979b
feat(regions_update): Changes in regions for AWS services. ( #1421 )
2022-10-20 11:54:22 +02:00
Nacho Rivera
44ce00d6e9
fix(iam_user_two_active_access_key_test): fix tests ( #1418 )
2022-10-20 08:34:28 +02:00
Nacho Rivera
df0925394b
feat(extra7100): Migrate check extra7100 -> iam_no_custom_policy_permissive_role_assumption ( #1417 )
2022-10-20 08:10:54 +02:00
Sergio Garcia
5b5b0b0405
feat(securityhub_check): Add check and service for SecurityHub ( #1360 )
...
Co-authored-by: Toni de la Fuente <toni@blyx.com >
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-10-19 15:21:07 +02:00
github-actions[bot]
6e73321a95
feat(regions_update): Changes in regions for AWS services. ( #1416 )
2022-10-19 12:11:28 +02:00
Nacho Rivera
d09020d144
feat(iam): Add IAM checks ( #1407 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-10-19 09:51:25 +02:00
Nacho Rivera
e2a8fa8738
feat(iam_check_saml_providers_sts): Check and test ( #1413 )
2022-10-18 13:23:50 +02:00
Toni de la Fuente
1119ee54af
feat(accessanalyzer): Check accessanalyzer_enabled_without_findings ( #1359 )
...
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-10-18 12:26:42 +02:00
github-actions[bot]
e6cd7c838f
feat(regions_update): Changes in regions for AWS services. ( #1414 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-10-18 12:21:39 +02:00
Nacho Rivera
2b59068e50
feat(password_policy_checks): Include password policy checks ( #1364 )
2022-10-18 10:15:15 +02:00
github-actions[bot]
5cc3888022
feat(regions_update): Changes in regions for AWS services. ( #1406 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-10-17 08:09:53 +02:00
github-actions[bot]
78975c286a
feat(regions_update): Changes in regions for AWS services. ( #1404 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-10-14 11:20:08 +02:00
github-actions[bot]
7a40d9c44b
feat(regions_update): Changes in regions for AWS services. ( #1392 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-10-07 11:57:42 +02:00
github-actions[bot]
460b71e3d9
feat(regions_update): Changes in regions for AWS services. ( #1387 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-10-06 11:08:26 +02:00
Sergio Garcia
107070e6e2
feat(shodan_integration): add ec2_elastic_ip_shodan check and config yaml ( #1356 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-10-05 13:48:34 +02:00
github-actions[bot]
fb176f56d0
feat(regions_update): Changes in regions for AWS services. ( #1378 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-09-30 11:11:07 +02:00
github-actions[bot]
f67dc57384
feat(regions_update): Changes in regions for AWS services. ( #1373 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-09-22 11:08:50 +02:00
github-actions[bot]
dc7c0cd981
feat(regions_update): Changes in regions for AWS services. ( #1371 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-09-16 11:07:52 +02:00
github-actions[bot]
5cda2ad19f
feat(regions_update): Changes in regions for AWS services. ( #1367 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-09-15 12:10:27 +02:00
github-actions[bot]
470b2ae369
feat(regions_update): Changes in regions for AWS services. ( #1366 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-09-13 11:07:28 +02:00
github-actions[bot]
14ee08ce6d
feat(regions_update): Changes in regions for AWS services. ( #1363 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-09-09 13:55:50 +02:00
github-actions[bot]
c85b2567f7
feat(regions_update): Changes in regions for AWS services. ( #1361 )
2022-09-08 14:22:34 +02:00
github-actions[bot]
ef110128f2
feat(regions_update): Changes in regions for AWS services. ( #1358 )
2022-09-05 10:42:50 +02:00
github-actions[bot]
1fc249e772
feat(regions_update): Changes in regions for AWS services. ( #1355 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-09-01 16:59:34 +02:00
Pepe Fagoaga
7388cb33d4
test(iam_user_two_active_access_key_test): Create unit tests ( #1354 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-09-01 13:35:00 +02:00
Sergio Garcia
f40c8f2dc5
feat(output-bucket-no-assume): add -D flag ( #1353 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-08-31 16:40:59 +02:00
Sergio Garcia
eb914d03ce
feat(services_testing): Add tests for EC2, IAM and S3 services ( #1352 )
...
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: sergargar <sergio@verica.io >
2022-08-31 13:40:28 +02:00
StylusFrost
e087f2e1b6
fix(check_network_acl): check with all rules together ( #1350 )
2022-08-30 13:58:50 +01:00
github-actions[bot]
f0c24d5152
feat(regions_update): Changes in regions for AWS services. ( #1351 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-08-30 11:12:01 +02:00
Sergio Garcia
44f514f02c
feat(s3_output): send outputs to S3 bucket ( #1343 )
2022-08-29 08:43:34 +02:00
Sergio Garcia
a63c42f59c
feat(custom_filename): custom output filename ( #1345 )
...
* feat(s3_output): send outputs to S3 bucket
* feat(custom_filename): custom output filename
Co-authored-by: sergargar <sergio@verica.io >
2022-08-26 13:08:34 +02:00
Sergio Garcia
65185943ca
feat(shub_compatibility): send finding to filter regions and change checkType to list ( #1341 )
2022-08-26 11:24:12 +01:00
github-actions[bot]
de1f707434
feat(regions_update): Update regions for AWS services. ( #1349 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-08-26 12:01:53 +02:00
github-actions[bot]
0d0e00a8bd
feat(regions_update): Update regions for AWS services. ( #1344 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-08-25 11:48:40 +02:00
Sergio Garcia
5054b82030
feat(api_banner): remove API region from banner ( #1342 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-08-25 08:06:03 +02:00
Nacho Rivera
182d0381c3
chore(tests): Add tests to output generation ( #1340 )
...
* chore(tests): added tests to outputs
* fix(timestamp): change timestamp coming from config
2022-08-23 11:51:40 +02:00
Sergio Garcia
fb0429b2a5
fix(mkdir_security-hub): mkdir when using security-hub ( #1339 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-08-22 12:26:40 +02:00
Pepe Fagoaga
c7a43b09ce
chore: Move shared to lib/ for AWS ( #1321 )
...
* chore: Move shared to lib/
* chore: Move shared to lib/ for AWS
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-08-22 10:41:09 +01:00
Sergio Garcia
d18b430c16
feat(new_checks): add check for ec2 and iam ( #1337 )
...
* fix(key_error): remove KeyError.
* feat(ftp_check): add ec2_securitygroup_allow_ingress_from_internet_to_tcp_ftp_port_20_21 check.
* feat(password_check): iam_password_policy_expires_passwords_within_15_days_or_less added.
* change days to 90
Co-authored-by: sergargar <sergio@verica.io >
2022-08-22 10:33:43 +02:00
Sergio Garcia
9b4415f7b3
fix(s3_regions): verify if there are filter regions ( #1338 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-08-22 10:30:26 +02:00
github-actions[bot]
6c36c599a5
feat(regions_update): Update regions for AWS services. ( #1336 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-08-22 08:11:05 +01:00
github-actions[bot]
a6fb000266
feat(regions_update): Update regions for AWS services. ( #1325 )
2022-08-18 12:47:45 +01:00
Sergio Garcia
92024e2b0e
feat(iam_password_policy): add password policy class. ( #1330 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-08-09 09:08:00 -07:00
Sergio Garcia
b229c01450
fix(key_error): remove KeyError. ( #1326 )
2022-08-08 22:26:50 +02:00
Sergio Garcia
15867d3ef6
fix(version): Update version to beta ( #1327 )
2022-08-08 22:24:03 +02:00
github-actions[bot]
5abd7817af
feat(regions_update): Update regions for AWS services. ( #1324 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-08-05 11:19:45 +02:00
Pepe Fagoaga
fa0fdbf0d1
fix(output): No resources ( #1320 )
2022-08-04 18:46:03 +02:00
Pepe Fagoaga
f30245bb15
fix(nacls): Handle IPv6 source ingress ( #1319 )
2022-08-04 16:33:16 +02:00
Pepe Fagoaga
bc5df671dd
feat(check): handle errors ( #1318 )
2022-08-04 16:09:30 +02:00
Sergio Garcia
a796545da5
feat(regions): add regions to resources ( #1285 )
2022-08-04 13:35:13 +02:00
Pepe Fagoaga
6e58991986
fix(time_comparison): Correct time formats ( #1317 )
2022-08-04 11:41:54 +02:00
Pepe Fagoaga
85a6634a56
feat(check): iam-policy-allows-privilege-escalation ( #1315 )
...
* feat(check): iam-policy-allows-privilege-escalation
* feat(metadata): Enrich check metadata
Co-authored-by: Toni de la Fuente <toni@blyx.com >
Co-authored-by: Toni de la Fuente <toni@blyx.com >
2022-08-04 11:26:42 +02:00
Pepe Fagoaga
5541ec0763
fix(ec2_instance_public_ip): format resource_id ( #1316 )
2022-08-04 11:22:50 +02:00
github-actions[bot]
a9aabd0082
feat(regions_update): Update regions for AWS services. ( #1314 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-08-04 11:04:42 +02:00
Pepe Fagoaga
cbd375f5d0
fix(iam): Set user's region in findings ( #1312 )
2022-08-04 10:04:00 +02:00
Pepe Fagoaga
de96894a4d
feat(metadata): Include EC2 subservices ( #1311 )
2022-08-03 17:29:43 +02:00
Pepe Fagoaga
5e40fc28c9
feat(output): Report generation data, color legend and assumed role information ( #1300 )
...
* feat(color-code): include legend
* chore(version): alfa -> alpha
* chore: remove comments
* feat(credentials): Include report generation data
2022-08-03 17:09:38 +02:00
Pepe Fagoaga
0b34940e20
feat(output): Include tab for better reading ( #1310 )
2022-08-03 16:55:11 +02:00
Pepe Fagoaga
f93dfe5e78
feat(version): Include -V ( #1309 )
2022-08-03 16:45:57 +02:00
Pepe Fagoaga
b59042d9e9
fix(check_name): Remove check_name ( #1307 )
2022-08-03 16:38:53 +02:00
Pepe Fagoaga
0c2ed53c54
refactor(security_groups): general function ( #1306 )
2022-08-03 16:38:29 +02:00
Pepe Fagoaga
fe474ae9df
chore: change default log level ( #1303 )
2022-08-03 12:21:10 +02:00
Pepe Fagoaga
6f0d42a881
fix: Sort checks ( #1302 )
...
* fix: sort checks
* fix(metadata): Include missing provider
2022-08-03 12:14:23 +02:00
Pepe Fagoaga
5e479a5050
Prwlr 750 exclude metadata json order ( #1301 )
...
* chore: exclude metadata
* chore: exclude metadata
* chore: no prettify
* chore: no prettify
2022-08-03 12:07:36 +02:00
Pepe Fagoaga
dfbc618d44
chore(metadata): Remove CheckName and CheckAlias field ( #1299 )
2022-08-03 10:12:34 +02:00
Pepe Fagoaga
9f82a8a6d6
feat(provider): Set AWS as the default provider ( #1298 )
2022-08-02 13:43:42 +02:00
github-actions[bot]
476d93b33e
feat(regions_update): Update regions for AWS services. ( #1295 )
2022-08-02 11:46:12 +02:00
github-actions[bot]
9895f9f595
feat(regions_update): Update regions for AWS services. ( #1292 )
2022-08-02 09:05:47 +02:00
github-actions[bot]
510cca6b29
feat(regions_update): Update regions for AWS services. ( #1288 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-07-28 13:30:51 -04:00
Sergio Garcia
66d2b7b4d9
feat(ec2_checks): add several checks for ec2 ( #1268 )
...
* feat(checks): add extra718
* feat(checks): add extra763
* feat(checks): add extra748, extra749, extra72
* feat(checks): add extra750
* feat(checks): add check45
* feat(checks): add check46, check45, check42, check41
* feat(metadata_sample): add sample of check metadata
* feat(pci-group): add pci group.
* feat(cloud9): environment setup.
* fix(protocol): add protocol conditions
Co-authored-by: sergargar <sergio@verica.io >
2022-07-27 00:21:40 +02:00
Sergio Garcia
da76f69e51
feat(s3_checks): add several checks for s3 ( #1266 )
...
* feat(checks): add extra718
* feat(checks): add extra763
Co-authored-by: sergargar <sergio@verica.io >
2022-07-25 19:45:31 +02:00
Sergio Garcia
ed1572d2d9
feat(iam_checks): add several checks for iam ( #1264 )
...
* feat(extra71): add iam_administrator_access_with_mfa check.
* feat(checks): add extra7125 and extra7123
* feat(checks): add check14
* feat(checks): add check112
* feat(checks): add check11
* feat(checks): add check114 and check113
* feat(checks): add check12
* feat(classes): add IAM classess.
* Update iam_root_hardware_mfa_enabled.py
* fix(comments): Resolve comments.
Co-authored-by: sergargar <sergio@verica.io >
2022-07-22 12:14:49 +02:00
Sergio Garcia
7d0a95e98f
feat(shub): add Security Hub integration ( #1255 )
2022-07-21 12:22:56 +02:00
github-actions[bot]
67834c3f8b
feat(regions_update): Update regions for AWS services. ( #1273 )
2022-07-21 11:27:54 +02:00
github-actions[bot]
a5e58ad9ce
feat(regions_update): Update regions for AWS services. ( #1267 )
2022-07-15 11:15:17 +02:00
github-actions[bot]
5cb363c389
feat(regions_update): Update regions for AWS services. ( #1263 )
2022-07-13 16:21:26 +02:00
github-actions[bot]
b80c7222ea
feat(regions_update): Update regions for AWS services. ( #1256 )
2022-07-08 11:04:50 +02:00
Sergio Garcia
611bd909ef
feat(json-asff): add json-asff ouput ( #1252 )
...
* feat(json): add json output
* feat(pydantic): add pydantic model to json output
* feat(json-asff): add json-asff ouput
* Update config/config.py
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
* Update models.py
* fix(comments): Resolve comments.
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-07-08 09:37:32 +02:00
Sergio Garcia
db3de2d69e
feat(sort_exec): Sort checks execution ( #1253 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-07-07 09:12:15 +02:00
Sergio Garcia
7b9fae5605
feat(json): add json output ( #1251 )
...
* feat(json): add json output
* feat(pydantic): add pydantic model to json output
Co-authored-by: sergargar <sergio@verica.io >
2022-07-06 14:35:15 +02:00
Sergio Garcia
d47bb09b2a
feat(organizations): Extract Metadata from Management Account ID (-O) ( #1248 )
...
* feat(organizations): add organizations funtion to provider
* feat(organizations): add organizations -O option
* fix(comments): Resolve comments.
* feat(test): add test
* fix(pipfile): update pipfile
Co-authored-by: sergargar <sergio@verica.io >
2022-07-05 12:00:14 +02:00
Pepe Fagoaga
b2899bda69
test(aws-provider): First tests ( #1231 )
...
* test(pre-commit): Include security checks
* test(pre-commit): Include dependencies
* test(aws-provider): First unit tests
* test(arn-parsing): Include first tests
* chore(providers): Remove old comments
2022-07-04 12:51:31 +02:00
Nacho Rivera
11652838e2
feat(outputS): Output generation format CSV ( #1230 )
...
* chore(csv): first version csv output
* chore(pytest): added pytest dependency
* chore(outputs): organizations demo
* chore(compliance): Added new dataclass for each compliance framework
* fix(test org values): deleted test values in orgs instantiation
* fix(csv): formatted to match output format
* fix(csv output): Reformulation of check report and minor changes
* fix(minor issues): Fix various issues coming from PR comments
* fix(csv): Renamed csv output data model
* fix(output dir): create default if not present
* fix(typo): remove s
* fix(oldcode)
* fix(typo)
* fix(output): Only send to csv when -M is passed
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-07-04 10:30:47 +02:00
github-actions[bot]
a1dcc1310a
feat(regions_update): Update regions for AWS services. ( #1246 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-07-01 11:11:58 +02:00
github-actions[bot]
7e2303a732
feat(regions_update): Update regions for AWS services. ( #1243 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-06-30 11:12:07 +02:00
github-actions[bot]
0d7214a4a6
feat(regions_update): Update regions for AWS services. ( #1241 )
...
Co-authored-by: jfagoagas <jfagoagas@users.noreply.github.com >
2022-06-29 12:54:23 +02:00
github-actions[bot]
cbd23c7fb1
feat(regions_update): Update regions for AWS services. ( #1234 )
2022-06-28 09:07:57 +02:00
Sergio Garcia
a2b40caeda
feat(default_regions): Set profile region as default for global regions. ( #1228 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-06-23 17:28:01 +02:00
Pepe Fagoaga
66d57a3d36
feat(severity): Run checks by severity ( #1223 )
2022-06-23 16:56:06 +02:00
Pepe Fagoaga
2288702d26
feat(list-services): List Prowler available services by provider ( #1222 )
2022-06-23 16:53:44 +02:00
github-actions[bot]
cdbf62a9e5
feat(regions_update): Update regions for AWS services. ( #1226 )
2022-06-23 11:20:11 +02:00
Sergio Garcia
25dc6c4a20
feat(refresh_aws_regions): Auto refresh of AWS regions for services. ( #1221 )
...
* feat(refresh_aws_regions): Auto refresh of AWS regions for services.
* Update refresh_aws_services_regions.yml
* Delete aws_regions_by_service.json
* Update refresh_aws_services_regions.yml
Co-authored-by: sergargar <sergio@verica.io >
2022-06-23 10:47:43 +02:00
Pepe Fagoaga
af2bdc37ea
fix(quit): Replace with sys.exit() ( #1220 )
2022-06-22 16:48:10 +02:00
Pepe Fagoaga
438ef9f348
feat(logger): Logs to file with custom log level ( #1217 )
2022-06-22 13:26:29 +02:00
Pepe Fagoaga
6ac6ef359f
feat(validate-metadata): Validate Check's metadata and list checks ( #1215 )
2022-06-22 10:12:55 +02:00
Pepe Fagoaga
b07b7f3f26
feat(list-groups): List available groups ( #1213 )
2022-06-22 09:59:48 +02:00
Sergio Garcia
ecefda11c7
feat(quiet): Add -q option. ( #1211 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-06-22 09:45:03 +02:00
Pepe Fagoaga
21f8f56c18
feat(exclude-groups-and-services) ( #1205 )
2022-06-21 08:05:32 +02:00
Nacho Rivera
e52ab12696
feat(global_aws_session): Global data structure for the current AWS audit ( #1212 )
...
* fix(audit info): Common data structure for current audit
* fix(iam): iam session audit fixed
* feat(aws_session): Include else block
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-06-21 07:53:49 +02:00
Sergio Garcia
b89b883741
feat(regions): Filter Audited Regions (-f) ( #1202 )
...
* feat(filter-regions): Added -f and ebs encryption check.
* feat(filter-regions): Added -f and ebs encryption check.
* feat(regional_clients): add regional_clients.
* fix(global variables): created global variables
* chore(role option): Mixed -A/-R option including error handling
* fix(arn): import errors from error.py file
* fix(review_comments): Review PR comments.
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: n4ch04 <nachor1992@gmail.com >
2022-06-20 11:25:26 +02:00
Pepe Fagoaga
f694a6d12a
feat(groups): Launch specific checks from groups and services ( #1204 )
2022-06-16 13:27:25 +02:00
Pepe Fagoaga
8abcc5988d
feat(checks): Exclude checks with -e/--exclude-checks
...
* feat(checks): Select checks to run
* feat(checks): Include tests
* feat(checks): Exclude checks with -e
* fix(checks): Include missing path
* fix(checks): Include comments
2022-06-16 12:57:36 +02:00
Pepe Fagoaga
9d5e43e6a2
feat(checks): Select checks to run from provider using -C/--checks-file ( #1200 )
2022-06-16 12:49:55 +02:00
Pepe Fagoaga
162852634e
feat(checks): Select checks to run from provider using -c/--checks ( #1197 )
...
* feat(checks): Select checks to run
* Update providers/aws/services/iam/iam_disable_30_days_credentials/iam_disable_30_days_credentials.py
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-06-16 12:20:03 +02:00
Nacho Rivera
33c6801501
feat(core): AWS Role Assumption support ( #1199 )
...
* chore(assuming role): assume role logic and exceptions demo
* chore(exceptions): Exception handling
* fix(get_caller_identity): Deleted duplicate get_caller_identity and add info entries
* chore(creds renewal): Added support to credential renewal
* chore(assume options): Added condition for -I/-T options
* fix(typo/comments): Deleted f in logger config and comments
* chore(session_duration): limits for -T option
* fix(log messages): Changed -A/-R log messages
* fix(critical error): Errors in input options are critical
* fix(ClientError): IAM service ClientError exception support
2022-06-16 12:00:46 +02:00
Sergio Garcia
eb679f50f1
feat(reorganize_folders): Merge checks. ( #1196 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-06-14 13:10:26 +02:00
Pepe Fagoaga
36fcab17f3
feat(prowler3): pipenv usage
2022-06-14 12:51:53 +02:00
Pepe Fagoaga
b22faa01ea
feat(prowler3): first commit
2022-06-14 12:22:54 +02:00
Pepe Fagoaga
9b05a9c334
delete(prowler): Main file
2022-06-14 12:19:31 +02:00
Pepe Fagoaga
0f39ee9b34
rename(provider): keep old version
2022-06-14 12:19:10 +02:00
Pepe Fagoaga
9a0088c84e
delete(include): Old bash libraries
2022-06-14 12:15:39 +02:00
Toni de la Fuente
c533d48cf5
New folder structure phase 3
2022-05-25 16:45:23 +02:00
Toni de la Fuente
6a3ceb6bc0
New folder structure phase 2
2022-05-25 16:43:54 +02:00
Toni de la Fuente
5ad517ce83
New folder structure phase 1
2022-05-25 12:54:15 +02:00
Pepe Fagoaga
432416d09e
fix(checks): Severity for Lambda URL checks ( #1162 )
2022-05-25 12:22:42 +02:00
Pepe Fagoaga
dd7d25dc10
release: Prowler 2.10 ( #1161 )
2022-05-25 12:03:05 +02:00
Pepe Fagoaga
24c60a0ef6
fix(checks): Handle AWS Gov Cloud regions ( #1160 )
2022-05-25 12:01:58 +02:00
Andrea Di Fabio
f616c17bd2
feat(new): New custom check extra9999 to build a custom check on the fly ( #1103 )
2022-05-25 09:16:36 +02:00
Pepe Fagoaga
5628200bd4
fix(remediation): Fix remediation fields for checks ( #1157 )
2022-05-23 15:48:26 +02:00
Pepe Fagoaga
ae93527a6f
fix(BucketLocation): Recover bucket policy using the right region endpoint ( #1156 )
2022-05-23 15:45:30 +02:00
Pepe Fagoaga
2939d5cadd
feat(lambda-function): Checks for misconfigured function's URLs ( #1148 )
2022-05-23 10:46:19 +02:00
Pepe Fagoaga
e2c7bc2d6d
fix(IllegalLocationConstraintException): Recover bucket policy using the right region endpoint ( #1155 )
2022-05-23 09:37:46 +02:00
Nacho Rivera
f4bae78730
Timestamp to date casting issues solved ( #1154 )
...
* fix(date): Deleted @ char before date argument
* fix(date): Use @ only when input is epoch
2022-05-23 09:28:56 +02:00
1vicente
d307898289
Update README.md ( #1153 )
...
pretty README.md
2022-05-19 12:14:11 +02:00
Pepe Fagoaga
879ac3ccb1
fix(actions): Ignore changes on Readme ( #1149 )
2022-05-17 16:09:55 +02:00
Sergio Garcia
cd41e73cbe
fix(readme): Correct permissions for DynamoDB allowlist ( #1147 )
2022-05-17 12:33:49 +02:00
Pepe Fagoaga
47f1ca646e
fix(typo): ArtifactBucket tags ( #1145 )
2022-05-17 09:08:11 +02:00
Charles Josiah Rusch Alandt
a18b18e530
K8s cronjob sample files ( #1140 )
2022-05-16 10:58:50 +02:00
Pepe Fagoaga
4d1ffbb652
fix(actions): tag and push ( #1142 )
2022-05-13 11:20:30 +02:00
Pepe Fagoaga
13423b137e
fix(actions): Include AWS region ( #1141 )
...
* fix(actions): Include AWS regions
* fix(zip): Quiet output
2022-05-13 10:13:03 +02:00
Sergio Garcia
d60eea5e2f
fix(copyToS3): Upload to S3 only when indicated ( #1134 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-05-12 17:30:49 +02:00
Pepe Fagoaga
39c7d3b69f
fix(typo) ( #1139 )
2022-05-12 17:28:30 +02:00
Pepe Fagoaga
2de04f1374
fix(actions): Job permissions ( #1138 )
2022-05-12 17:24:15 +02:00
Pepe Fagoaga
5fb39ea316
fix(actions): Trigger on PR ( #1136 )
...
* fix(actions): Include checkout
* fix(actions): version name
* fix(actions): fix branch
* fix(actions): version name
* fix(actions): PR trigger
2022-05-12 17:20:11 +02:00
Pepe Fagoaga
55640ecad2
fix(actions): Github token permissions ( #1135 )
2022-05-12 16:46:06 +02:00
Pepe Fagoaga
69d3867895
feat(actions): Upload Prowler containers to registries ( #1132 )
...
* feat(actions): Upload Prowler latest to dockerhub
* feat(upload-container): Action to Public Registries
* feat(upload-container): Include env secrets
* feat(actions): Include Docker linters
* feat(linters): include pre-commit
* fix(names)
2022-05-12 16:37:46 +02:00
Sergio Garcia
210f44f66f
fix(custom-file-in-bucket): Custom file names are also support for S3 output. ( #1129 )
2022-05-11 10:16:29 +02:00
Sergio Garcia
b78e4ad6a1
fix(allowlist_db): Improve DynamoDB regex for allowlisting. ( #1127 )
2022-05-06 13:46:53 +02:00
stof
4146566f92
feat(assume-role): Properly handle External ID variable
2022-05-05 16:10:52 +02:00
Sergio Garcia
4e46dfb068
feat(add_prowler_pro_banner): include Prowler Pro banner in README ( #1119 )
...
* feat(add_prowler_pro_banner): include Prowler Pro banner in README
Context
Include Prowler Pro banner in README.md
Description
Add Prowler Pro banner in README.md for giving visibility to the Enterprise version of Prowler.
License
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
* Update README.md
2022-05-03 16:24:23 +02:00
Milton Torasso
13c96a80db
feat(deployment): Serverless multi account Prowler with SecurityHub Integration ( #1113 )
2022-05-03 13:41:56 +02:00
Sergio Garcia
de77a33341
fix(allowlist_db): Improve DynamoDB regex for allowlisting. ( #1126 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-05-03 11:57:23 +02:00
ChrisGoKim
295bb74acf
fix(additions-policy): Updated multi-org ProwlerRole.yaml ( #1123 )
2022-05-03 11:34:12 +02:00
Jens Brey
59abd2bd5b
check_extra7113: Fix wrong listing of RDS instances in regions without databases ( #1124 )
...
Co-authored-by: Jens Brey <jens.brey@allcloud.io >
2022-05-03 11:31:23 +02:00
Sergio Garcia
ecbfbfb960
fix(allowlist_db): Improve DynamoDB regex for allowlisting. ( #1125 )
...
Co-authored-by: sergargar <sergio@verica.io >
2022-05-03 11:31:12 +02:00
Justin Plock
04e5804665
Update CloudFormation template for CodeBuild ( #1114 )
2022-05-03 09:14:38 +02:00
Pepe Fagoaga
681d0d9538
feat(group7): Include extra7178 ( #1121 )
2022-04-29 14:26:19 +02:00
Pepe Fagoaga
8bfd9c0e62
feat(emr): Check BlockPublicAccessConfiguration for EMR ( #1120 )
2022-04-29 14:23:54 +02:00
Divyanshu
95df9bc316
feat(checks): New group and checks for Codebuild and EMR ( #1112 )
2022-04-29 14:19:04 +02:00
Sergio Garcia
d08576f672
feat(add_prowler_pro_banner): include Prowler Pro banner in README.md ( #1117 )
2022-04-28 17:28:52 +02:00
Sergio Garcia
aa16bf4084
feat(dynamodb_allowlist): Support DynamoDB tables ARN for allowlist input ( #1118 )
...
* feat(dynamodb_allowlist): Support dynamodb tables arn for allowlist input.
* feat(allowlist): Include logging messages for input file
* fix(allowlist): Modify DynamoDB key name
Co-authored-by: sergargar <sergio@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-04-28 17:04:44 +02:00
Pepe Fagoaga
432632d981
chore(release): 2.9.0 ( #1109 )
2022-04-13 13:54:53 +02:00
Pepe Fagoaga
d6ade7694e
chore(allowlist): Rename references ( #1108 )
...
* chore(allowlist): rename file
* chore(allowlist): remove old references
2022-04-13 11:31:50 +02:00
n4ch04
c9e282f236
IAM check116 and check122 modified to log also PASS results ( #1107 )
...
* fix(check116): Fixed logic to include resource_id of passed users
* fix(check122): Changed logic check to include explicit pass records
2022-04-12 19:54:51 +02:00
carterjones
5b902a1329
fix typo: publiccly -> publicly ( #1106 )
2022-04-12 18:12:26 +02:00
Pepe Fagoaga
fc7c932169
fix(extra7147): Handle unsupported AWS regions for Glacier ( #1101 )
2022-04-11 16:10:23 +02:00
n4ch04
819b52687c
Replace comma from csv input info ( #1102 )
...
* fix(output): replace comma from csv input info
* fix(outputs): parameter expansion done in echo to csv
2022-04-11 16:04:47 +02:00
Sergio Garcia
28fff104a1
feat(S3_in_w_x_flags): Support S3 URIs for custom checks paths and whitelist files. ( #1090 )
...
* feat(S3_in_w_x_flags): Support S3 URIs for custom checks paths and whitelist files.
* feat(S3_in_w_x_flags): README document was updated.
* Update README.md
* Update README.md
* Update README.md
* Update README.md
Co-authored-by: Toni de la Fuente <toni@blyx.com >
Co-authored-by: Sergio Garcia Garcia
2022-04-07 14:37:02 -04:00
n4ch04
07b2b0de5a
fix(extra764): Deleted temp file refs ( #1089 )
2022-04-07 17:03:32 +02:00
nealalan
4287b7ac61
check empty array in SECURITYGROUPS object ( #1099 )
...
* check empty array in SECURITYGROUPS object
Logic is only checking an object to see if it is null. This should be checking for the array in the object to see if it is empty.
* Replace new conditional with the old one
* Update check_extra75
Co-authored-by: Sergio Garcia <38561120+sergargar@users.noreply.github.com >
2022-04-07 10:57:29 -04:00
Sergio Garcia
734331d5bc
fix(extra764): NoSuchBucket error properly handled. ( #1094 )
2022-03-31 15:35:17 +02:00
Sergio Garcia
5de2bf7a83
fix(extra7172): IllegalLocationConstraintException properly handled. ( #1093 )
2022-03-31 14:40:32 +02:00
Sergio Garcia
1744921a0a
fix(extra792): TLS1.3 policies added as secure ( #1091 )
2022-03-30 17:50:00 +02:00
Andrew Grangaard
d4da64582c
docs(tf-quickstart): Update example code for terraform-quickstart ( #1086 )
...
+ use primary repository rather than fork.
+ use default branch.
+ fixed a missing character typos.
+ remove blank end-of-line spaces.
@singergs: thanks for adding this code and the video.
2022-03-30 09:15:38 +02:00
Andrea Di Fabio
d94acfeb17
New Extra Check - Detect SGs created by the EC2 Launch Wizard ( #1081 )
...
* new check
* added check to group
* fixed name
* added testpass logic
* Fixed a few issues
* Fixed more issues
* Updated to add extended information
* Added new line at end of file
* Fixed Spelling
* fix(title): Update title name
* refactor(style): Minor changes
Co-authored-by: Andrea Di Fabio <adifabio@amazon.com >
2022-03-29 10:06:44 +02:00
soffensive
fcc14012da
Update check_extra736, is missing $PROFILE_OPT ( #1084 )
...
$PROFILE_OPT was missing in one aws command
2022-03-29 09:11:41 +02:00
Lucas Moura
cc8cbc89fd
Fix typo extra729 and extra740 ( #1083 )
...
* Fix typo on remediation
* Fix typo on remediation description
2022-03-29 08:58:06 +02:00
Sergio Garcia
8582e40edf
fix(secrets_library): Verify if detect-secrets library is missing ( #1080 )
2022-03-25 13:19:05 +01:00
Toni de la Fuente
1e87ef12ee
feat(new_version): Prowler 2.8.1 ( #1082 )
2022-03-25 12:58:06 +01:00
Pepe Fagoaga
565200529f
fix(detect-secrets): Include missing colon to link values ( #1078 )
2022-03-22 13:53:36 +01:00
Sergio Garcia
198c7f48ca
fix(bucket_region): check extra764 doesn't handle bucket region properly ( #1077 )
...
* fix(bucket_region): check extra764 doesn't handle bucket region properly
2022-03-18 11:51:42 +01:00
Toni de la Fuente
8105e63b79
fix(extras-group): Add extra7172 to group extras ( #1074 )
2022-03-16 18:39:16 +01:00
Sergio Garcia
3932296fcf
feat(new_version): Prowler 2.8.0 ( #1073 )
2022-03-16 18:15:57 +01:00
David Childs
cb0d9d3392
fix(filter-region): Support comma separated regions ( #1071 )
...
* regions separated by a comma deliminator
* Update README.md
Co-authored-by: Toni de la Fuente <toni@blyx.com >
* Update README.md
Co-authored-by: David Childs <d.childs@elsevier.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: Toni de la Fuente <toni@blyx.com >
2022-03-16 17:49:04 +01:00
Pepe Fagoaga
4b90eca21e
docs(readme): Fix typo ( #1072 )
2022-03-16 16:54:27 +01:00
Toni de la Fuente
365b396f9a
feat(metadata): Include account metadata in Prowler assessments ( #1049 )
...
* Add support for organizations accounts metadata part 1
* Add support for organizations accounts metadata part 2
* Add gathering account metadata from org
* chore(prowler): get accounts metadata
Use assume_role backing up normal assumed credentials to assume management account and then restore it to old ones
* fix(orgs metadata): deleted assume_role_orgs
* refactor(organization_metadata)
Reformulate to extract AWS Organizations metadata
* doc(org_metadata): include required -R in usage
* docs(org-metadata): Update README
Co-authored-by: n4ch04 <nachor1992@gmail.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-03-16 16:27:19 +01:00
plarso
c526c61d5e
Fix(check122): Error when policy name contains commas ( #1067 )
...
* check122 - Support policy names with commas
* Requested changes
2022-03-16 15:06:12 +01:00
Leonardo Azize Martins
c4aff56f23
fix(extra760): Improve error handling ( #1055 )
...
* Fix AccessDenied issue
* fix(extra760): Error handling
* Fix merge conflict
* Improve code style
* Fix grep filter
* Fix bash variable expansion
* Fix grep logic to handle zip file
2022-03-16 14:57:37 +01:00
n4ch04
d9e0ed1cc9
fix(check_extra7161): fixed check title ( #1068 )
2022-03-15 12:30:57 +01:00
Leonardo Azize Martins
e77cd6b2b2
fix: Change lower case from bash variable expansion to tr ( #1064 )
...
* fix(extra715): Change lower case from bash variable expansion to tr command
* fix: Change from bash variable expansion to tr command
* Change the way to handle lower case
2022-03-15 08:22:22 +01:00
n4ch04
f04b174e67
fix(whitelist): Whitelist logic reformulated ( #1061 )
...
* fix(whitelist): Whitelist logic reformulated again
* chore(whitelist): reformulate style
2022-03-11 10:15:58 +01:00
Pepe Fagoaga
0c1c641765
fix(extra776): Handle image tag commas and json output ( #1063 )
2022-03-08 19:08:40 +01:00
xxxMinoo
d44f6bf20f
fix: extra7167 Advanced Shield and CloudFront bug parsing None output without distributions ( #1062 )
...
* fix: not to flag as finding for account without cloudfront distributions
* fix: output empty for None from cloudfront list-distributions
* fix: extra7167 Advanced Shield and CloudFront bug parsing None output without distributions
Co-authored-by: moo.xin.foo <moo.xin.foo@accenture.com >
2022-03-08 14:09:20 +01:00
Leonardo Azize Martins
1fa62cf417
fix(extra758): Reduce API calls. Print correct instance state. ( #1057 )
...
* fix(extra758): Reduce API calls. Print correct instance state.
* feat(oldage-format): Include comment
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-03-08 10:45:02 +01:00
Toni de la Fuente
d8d2ddd9e7
Revert "fix: extra7167 Advanced Shield and CloudFront bug parsing None output without distributions ( #1053 )" ( #1054 )
...
This reverts commit f3ff8369c3 .
2022-03-04 13:12:03 +01:00
xxxMinoo
f3ff8369c3
fix: extra7167 Advanced Shield and CloudFront bug parsing None output without distributions ( #1053 )
...
* fix: not to flag as finding for account without cloudfront distributions
* fix: output empty for None from cloudfront list-distributions
Co-authored-by: moo.xin.foo <moo.xin.foo@accenture.com >
2022-03-04 10:25:47 +01:00
Roman Mueller
99d1868827
Add right region to CSV if access is denied ( #1045 )
2022-03-02 16:32:35 +01:00
Andrea Di Fabio
31cefa5b3c
Make python3 default in Dockerfile ( #1043 )
2022-03-02 16:21:28 +01:00
Andrea Di Fabio
2d5ac8238b
Added Timestamp to secrets related 5 checks ( #1041 )
2022-03-02 15:56:02 +01:00
Leonardo Azize Martins
248cc9d68b
Fix(extra771): jq fail when policy action is an array ( #1031 )
...
* Fix error handling and policy output
* Fix jq filter when Action is an array
Fix jq select condition to handle Action as string or as array.
Add error handling.
When fail, print policies as just one line.
* Double quote variables to prevent globbing and word splitting
* Replace comma character from json by word comma
2022-03-02 15:04:18 +01:00
Leonardo Azize Martins
5f0a5b57f9
Fix(ES): Improve AWS CLI query and add error handling for ElasticSearch/OpenSearch checks ( #1032 )
...
* Fix CLI query and add error handling
Check extra781, extra782, extra783, extra784 and extra785
* Fix CLI query, add error handling, combine AWS CLI calls when possible
Checks related to Opensearch/ElasticSearch.
* Fix CLI query, add error handling, combine AWS CLI calls when possible
Checks related to Opensearch/ElasticSearch.
2022-03-02 12:44:24 +01:00
Pepe Fagoaga
86367fca3f
fix: remove PR automatic labels ( #1044 )
2022-02-15 08:19:40 +01:00
Pepe Fagoaga
07be3c21bf
docs(templates): Include triage label ( #1042 )
2022-02-14 17:47:53 +01:00
n4ch04
3097ba6c66
fix(include/outputs):Rolling back whitelist checking to RE check ( #1037 )
...
* fix(include/outputs):Rolling back whitelist checking to RE check
* fix(include/ouputs): Clarified variable assignation coming from argument
2022-02-14 13:04:47 +01:00
n4ch04
b4669a2a72
fix(check41/42): Added tcp protocol filter to query ( #1035 )
...
* fix(check41/42): Added tcp protocol filter to query
* Include {} in vars
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
* Include {} in vars
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
2022-02-11 10:54:32 +01:00
Leonardo Azize Martins
e8848ca261
docs: Improve check_sample examples, add general comments ( #1039 )
2022-02-10 17:58:50 +01:00
Pepe Fagoaga
5c6902b459
fix(extra730): Handle invalid date formats checking ACM certificates ( #1033 )
2022-02-09 17:56:55 +01:00
Leonardo Azize Martins
9b772a70a1
Fix(extra7141): Error handling and include missing policy ( #1024 )
...
* Fix AccessDenied issue when get document
Add check to validate access denied when get document from SSM.
Add missing action permission to allow ssm:GetDocument.
* Double quote variables to prevent globbing and word splitting
2022-02-09 16:01:01 +01:00
Pepe Fagoaga
6c12a3e1e0
fix(extra736): Recover Customer Managed KMS keys ( #1036 )
2022-02-09 10:05:57 +01:00
jeffmaley
c6f0351e9c
feat(check): New check7172 for S3 Bucket ACLs ( #1023 )
...
* added check7172 for s3 bucket acls
* Added more errors to error handling and an access check for s3
* Removed extra api call
Co-authored-by: Jeff Maley <jeff.maley@symmetry-systems.com >
2022-02-07 16:58:18 -05:00
Martin Muller
7e90389dab
fix: CFN codebuild example ( #1030 )
...
Since 2.7.0 this template failed:
```
An error occurred (AccessDeniedException) when calling the GetSubscriptionState operation: User: arn:aws:sts::863046042023:assumed-role/prowler-codebuild-role/AWSCodeBuild-2c3151c9-7c5d-4618-94e5-0234bddce775 is not authorized to perform: shield:GetSubscriptionState on resource: arn:aws:shield::863046042023:subscription/* because no identity-based policy allows the shield:GetSubscriptionState action
INFO! No AWS Shield Advanced subscription found. Skipping check.
7.167 [extra7167] Check if Cloudfront distributions are protected by AWS Shield Advanced - shield [Medium]
```
I aligned it with https://github.com/prowler-cloud/prowler/blob/master/iam/prowler-additions-policy.json#L19 .
2022-02-04 12:09:53 -05:00
n4ch04
30ce25300f
fix(include/outputs): Whitelist logic reformulated to exactly match input ( #1029 )
...
* fix(inlcude/outputs) Whitelist logic reformulated to exactly match input
* fix(include/outputs): Changed name of iterative variable that browses whitelisted values
* fix(include/outputs): Deleted missing echo and include and put variables in brackets
2022-02-04 12:07:48 -05:00
Pepe Fagoaga
26caf51619
fix(CODEOWNERS): Rename team ( #1027 )
2022-02-04 12:05:43 -05:00
Leonardo Azize Martins
3ecb5dbce6
Fix AccessDenied issue ( #1025 )
2022-02-04 12:05:10 -05:00
Toni de la Fuente
1d409d04f2
Fix (extra7148 and add action #1017 ( #1021 )
2022-02-04 11:58:22 -05:00
Daniel Lorch
679414418e
Fix: when prowler exits with a non-zero status, the remainder of the block is not executed ( #1015 )
...
* Fix: when prowler exits with a non-zero status, the remainder of the block is not executed
* Fix: do not trigger exit code 3 on failed checks, so that the remainder of the block is executed
2022-02-02 17:45:56 +01:00
Daniel Lorch
b26370d508
Typo (breaking change) ( #1010 )
...
Co-authored-by: Daniel Lorch <lorchda@amazon.ch >
2022-02-02 11:13:31 -05:00
Daniel Lorch
72b30aa45f
Skip packages with broken dependencies when upgrading system ( #1009 )
...
Co-authored-by: Daniel Lorch <lorchda@amazon.ch >
2022-02-02 11:12:58 -05:00
n4ch04
d9561d5d22
fix(check32): filterName base64encoded to avoid space problems in filter names ( #1020 )
...
* fix(check32): filterName base64encoded to avoid space problems in filter names
* fix(check32): base64 decoding atomic expression
* fix(check32): Variable enclosing
Co-authored-by: Nacho Rivera <nachor1992@gmail>
2022-02-02 11:09:38 -05:00
Mike Stewart
3d0ab4684f
docs(docker): Docker hub references ( #1018 )
2022-02-02 16:45:07 +01:00
Daniel Lorch
29a071c98e
docs(whitelist): Add examples for Control Tower resources ( #1013 )
2022-02-02 13:36:02 +01:00
Daniel Lorch
0ac7064d80
fix(ftr-group): Visual formatting ( #1012 )
2022-02-02 13:17:46 +01:00
Toni de la Fuente
dcd55dbb8f
Add badges
2022-01-28 12:12:59 +01:00
Jan Sepke
441dc11963
Fix issue #1002 ( #1007 )
...
regression in extra793
Co-authored-by: Jan Sepke <jan.sepke@jungheinrich.de >
2022-01-28 11:01:32 +01:00
Jan Sepke
21a8193510
Fix issue #1001 ( #1006 )
...
regression in extra75
Co-authored-by: Jan Sepke <jan.sepke@jungheinrich.de >
2022-01-27 15:13:07 +01:00
Pepe Fagoaga
3b9a3ff6be
Include codeowners template ( #1005 )
...
* docs(templates): include Codeowners
* docs(templates): update PR template
2022-01-27 12:58:14 +01:00
Toni de la Fuente
c5f12f0a6c
Fix issue #1002 ( #1004 )
2022-01-27 12:27:41 +01:00
Pepe Fagoaga
90565099bd
Change references from toniblyx to prowler-cloud ( #1003 )
...
Co-authored-by: Toni de la Fuente <toni@blyx.com >
2022-01-27 12:17:38 +01:00
Toni de la Fuente
2b2814723f
Prowler 2.7.0 - Brave ( #998 )
...
* Extra7161 EFS encryption at rest check
* Added check_extra7162 which checks if Log groups have 365 days retention
* fixed code to handle all regions and formatted output
* changed check title, resource type and service name as well as making the code more dynamic
* Extra7161 EFS encryption at rest check
* New check_extra7163 Secrets Manager key rotation enabled
* New check7160 Enabled AutomaticVersionUpgrade on RedShift Cluster
* Update ProwlerRole.yaml to have same permissions as util/org-multi-account/ProwlerRole.yaml
* Fix link to quicksight dashboard
* Install detect-secrets (e.g. for check_extra742)
* Updating check_extra7163 with requested changes
* fix(assumed-role): Check if -T and -A options are set
* docs(Readme): `-T` option is not mandatory
* fix(assume-role): Handle AWS STS CLI errors
* fix(assume-role): Handle AWS STS CLI errors
* Update group25_FTR
When trying to run the group 25 (Amazon FTR related security checks) nothing happens, after looking at the code there is a misconfiguration in 2 params: GROUP_RUN_BY_DEFAULT[9] and GROUP_CHECKS[9]. Updating values to 25 fixed the issue.
* Update README.md
broken link for capital letters in group file (group25_FTR)
* #938 issue assume_role multiple times should be fixed
* Label 2.7.0-1December2021 for tests
* Fixed error that appeared if the number of findings was very high.
* Adjusted the batch to only do 50 at a time. 100 caused capacity issues. Also added a check for an edge case where if the updated findings was a multiple of the batch size, it would throw an error for attempting to import 0 findings.
* Added line to delete the temp folder after everything is done.
* New check 7164 Check if Cloudwatch log groups are protected by AWS KMS@maisenhe
* updated CHECK_RISK
* Added checks extra7160,extra7161,extra7162,extra7163 to group Extras
* Added checks extra7160,extra7161,extra7162,extra7163 to group Extras
* Added issue templates
* New check 7165 DynamoDB: DAX encrypted at rest @Daniel-Peladeau
* New check 7165 DynamoDB: DAX encrypted at rest @Daniel-Peladeau
* Fix #963 check 792 to force json in ELB queries
* Fix #957 check 763 had us-east-1 region hardcoded
* Fix #962 check 7147 ALTERNATE NAME
* Fix #940 handling error when can not list functions
* Added new checks 7164 and 7165 to group extras
* Added invalid check or group id to the error message #962
* Fix Broken Link
* Add docker volume example to README.md
* Updated Dockerfile to use amazonlinux container
* Updated Dockerfile with AWS cli v2
* Added upgrade to the RUN
* Added cache purge to Dockerfile
* Backup AWS Credentials before AssumeRole and Restore them before CopyToS3
* exporting the ENV variables
* fixed bracket
* Improved documentation for install process
* fix checks with comma issues
* Added -D option to copy to S3 with the initial AWS credentials
* Cosmetic variable name change
* Added $PROFILE_OPT to CopyToS3 commands
* remove commas
* removed file as it is not needed
* Improved help usage options -h
* Fixed CIS LEVEL on 7163 through 7165
* When performing a restoreInitialAWSCredentials, unset the credentials ENV variables if they were never set
* New check 7166 Elastic IP addresses with associations are protected by AWS Shield Advanced
* New check 7167 Cloudfront distributions are protected by AWS Shield Advanced
* New check 7168 Route53 hosted zones are protected by AWS Shield Advanced
* New check 7169 Global accelerators are protected by AWS Shield Advanced
* New check 7170 Application load balancers are protected by AWS Shield Advanced
* New check 7171 Classic load balancers are protected by AWS Shield Advanced
* Include example for global resources
* Add AWS Advance Shield protection checks corrections
* Added Shield actions GetSubscriptionState and DescribeProtection
* Added Shield actions GetSubscriptionState and DescribeProtection
* docs(templates): Improve bug template with more info (#982 )
* Removed echoes after role chaining fix
* Changed Route53 checks7152 and 7153 to INFO when no domains found
* Changed Route53 checks 7152 and 7153 title to clarify
* Added passed security groups in output to check 778
* Added passed security groups and updated title to check 777
* Added FAIL as error handling when SCP prevents queries to regions
* Label version 2.7.0-6January2022
* Updated .dockerignore with .github/
* Fix: issue #758 and #984
* Fix: issue #741 CloudFront and real-time logs
* Fix issues #971 set all as INFO instead of FAIL when no access to resource
* Fix: issue #986
* Add additional action permissions for Glue and Shield Advanced checks @lazize
* Add extra shield action permission
Allows the shield:GetSubscriptionState action
* Add permission actions
Make sure all files where permission actions are necessary will have the same actions
* Fix: Credential chaining from environment variables @lazize #996f
If profile is not defined, restore original credentials from environment variables,
if they exists, before assume-role
* Lable version 2.7.0-24January2022
Co-authored-by: Lee Myers <ichilegend@gmail.com >
Co-authored-by: Chinedu Obiakara <obiakac@amazon.com >
Co-authored-by: Daniel Peladeau <dcpeladeau@gmail.com >
Co-authored-by: Jonathan Lozano <jonloza@amazon.com >
Co-authored-by: Daniel Lorch <dlorch@gmail.com >
Co-authored-by: Pepe Fagoaga <jose.fagoaga@smartprotection.com >
Co-authored-by: Israel <6672089+lopmoris@users.noreply.github.com >
Co-authored-by: root <halfluke@gmail.com >
Co-authored-by: nikirby <nikirby@amazon.com >
Co-authored-by: Joel Maisenhelder <maisenhe@gmail.com >
Co-authored-by: RT <35173068+rtcms@users.noreply.github.com >
Co-authored-by: Andrea Di Fabio <39841198+sectoramen@users.noreply.github.com >
Co-authored-by: Joseph de CLERCK <clerckj@amazon.fr >
Co-authored-by: Michael Dickinson <45626543+michael-dickinson-sainsburys@users.noreply.github.com >
Co-authored-by: Pepe Fagoaga <pepe@verica.io >
Co-authored-by: Leonardo Azize Martins <lazize@users.noreply.github.com >
2022-01-24 13:49:47 +01:00
Toni de la Fuente
42e54c42cf
Label new version 2.6.1-15November2021
2021-11-15 19:12:06 +01:00
Toni de la Fuente
f0c12bbf93
Merge pull request #928 from toniblyx/2.6.1
...
2.6.1
2021-11-15 18:56:16 +01:00
Toni de la Fuente
d272fad4c2
Enhancement IAM assumed role session duration error handling by @jfagoagas
...
Enhancement IAM assumed role session duration error handling by @jfagoagas
2021-11-15 18:17:09 +01:00
Toni de la Fuente
3e78f017e2
Fix Terraform Kickstarter path in README by @z0ph
...
Fix Terraform Kickstarter path in README
2021-11-15 17:05:37 +01:00
Toni de la Fuente
cee6437ae1
Fix issue #926 resource id and remediation typo
2021-11-15 16:49:40 +01:00
Toni de la Fuente
b251f31da9
Fix issue #925 replace sensible by sensitive
2021-11-15 15:59:13 +01:00
Toni de la Fuente
50de9f2ab4
Fix output for checks check3x when no CW group is in place
2021-11-15 15:49:33 +01:00
Toni de la Fuente
a6ba580344
Fix severity case variable
2021-11-15 15:45:33 +01:00
Pepe Fagoaga
563cd71060
fix(iam-role): Delete temporary prowler.sts_assumed* if error
2021-11-13 16:25:43 +01:00
Victor GRENU
32e5738c46
fix readme for terraform kickstarter
2021-11-13 14:48:16 +01:00
Pepe Fagoaga
e4edb5e39e
fix(iam-role): IAM assumed role session duration
2021-11-12 18:32:02 +01:00
Toni de la Fuente
cbd1c31424
Merge pull request #922 from toniblyx/2.6
...
2.6
2021-11-12 13:23:42 +01:00
Toni de la Fuente
df6e3f9462
Merge branch 'master' into 2.6
2021-11-12 13:21:18 +01:00
Toni de la Fuente
79c32a3c0b
Label new version 2.6.0-12November2021
2021-11-12 10:34:32 +01:00
Toni de la Fuente
9cf076899e
Updated screenshots and minor changes
2021-11-12 10:33:45 +01:00
Toni de la Fuente
dd398a994b
Fix issue #904
2021-11-11 14:05:14 +01:00
Toni de la Fuente
82b7eca80a
Fix CIS LEVEL variable in check21
2021-11-11 14:00:33 +01:00
Toni de la Fuente
140e96e5e1
Fix issue #848 CIS LEVEL added to CSV and other formats
2021-11-11 13:40:40 +01:00
Toni de la Fuente
34aba53649
Consolidate Apache License file in LICENSE
2021-11-11 12:52:57 +01:00
Toni de la Fuente
6921eaa6e9
Fix issue #868
2021-11-11 11:25:12 +01:00
Toni de la Fuente
4b205e2cdd
Add badges for Docker Hub and AWS ECR public registry
2021-11-10 18:49:06 +01:00
Toni de la Fuente
5d79bd6b0f
Add extra7158,extra7159 to extras
2021-11-10 16:55:17 +01:00
Toni de la Fuente
a5dfa788a6
New check 7159 ELB Classic Load balancer has listeners underneath @kbgoll05
...
New check 7159 ELB Classic Load balancer has listeners underneath @kbgoll05
2021-11-10 16:49:10 +01:00
Toni de la Fuente
afed5eb4b2
New check 7158 ELBV2 has listeners underneath @kbgoll05
...
New check 7158 ELBV2 has listeners underneath @kbgoll05
2021-11-10 16:48:45 +01:00
Toni de la Fuente
aecb784eca
Merge pull request #918 from toniblyx/revert-911-check7158
...
Revert "New check 7158 ELBV2 has listeners underneath @kbgoll05"
2021-11-10 14:27:36 +01:00
Toni de la Fuente
1ee7f4f276
Revert "New check 7158 ELBV2 has listeners underneath @kbgoll05"
2021-11-10 14:27:27 +01:00
Toni de la Fuente
98d465b84b
Merge pull request #917 from toniblyx/revert-912-check7159
...
Revert "New check 7159 ELB Classic Load balancer has listeners underneath @kbgoll05"
2021-11-10 14:27:12 +01:00
Toni de la Fuente
24c3da2a60
Revert "New check 7159 ELB Classic Load balancer has listeners underneath @kbgoll05"
2021-11-10 14:27:01 +01:00
Toni de la Fuente
69164c5176
New check 7159 ELB Classic Load balancer has listeners underneath @kbgoll05
...
New check 7159 ELB Classic Load balancer has listeners underneath @kbgoll05
2021-11-10 14:26:23 +01:00
Toni de la Fuente
fa5c5773f7
New check 7158 ELBV2 has listeners underneath @kbgoll05
...
New check 7158 ELBV2 has listeners underneath @kbgoll05
2021-11-10 14:25:58 +01:00
Toni de la Fuente
950f14c845
Fix issue #886
2021-11-09 15:47:09 +01:00
Toni de la Fuente
48d7381822
Fix issue #871
2021-11-09 14:21:32 +01:00
Toni de la Fuente
2c81b383e8
Fix scoring check counter
2021-11-09 12:59:36 +01:00
Toni de la Fuente
60d89fa98d
Enhanced scoring when only INFO is detected
2021-11-08 22:44:41 +01:00
Toni de la Fuente
7b6e4ccd13
Added Discord link to README.md
2021-11-08 21:21:39 +01:00
Toni de la Fuente
9ec4db456c
Added Discord link to README.md
2021-11-08 21:19:48 +01:00
Toni de la Fuente
918dd9eb07
Added Discord link to README.md
2021-11-08 20:34:16 +01:00
Toni de la Fuente
83dc0a0987
Fixes issue #906
2021-11-08 20:05:50 +01:00
kbgoll05
226b016557
Add files via upload
2021-11-05 16:02:25 -05:00
kbgoll05
41c6131d10
Add files via upload
2021-11-05 15:50:54 -05:00
Toni de la Fuente
623e62ad3f
Fix service name string with bash colors in html report
2021-11-05 18:33:24 +01:00
Toni de la Fuente
98e7e543fd
Fix issue #827
2021-11-05 17:36:34 +01:00
Toni de la Fuente
5d5250076b
Updated documentation about detect-secrets version to use issue #806
2021-11-04 19:50:33 +01:00
Toni de la Fuente
12f49a2795
Fixed typo in README.md @bevel-zgates
...
Fixed typo in README.md @bevel-zgates
2021-11-04 19:15:33 +01:00
Zach
2e0695112d
Update README.md
...
fixed typo in `readme.md`
2021-11-04 12:29:36 -05:00
Toni de la Fuente
89e87c713b
Added extra7157 to group extras
2021-10-26 14:34:44 +02:00
Toni de la Fuente
2c1fd8aeb4
New Check 7157 API Gateway V2 has Configured Authorizers @qumei
...
New Check 7157 API Gateway V2 has Configured Authorizers @qumei
2021-10-26 14:31:10 +02:00
Toni de la Fuente
7fe2946241
New checks group FTR (AWS Foundational Technical Review) @jfagoagas
...
New checks group FTR (AWS Foundational Technical Review) @jfagoagas
2021-10-26 14:19:52 +02:00
Pepe Fagoaga
bb068f1c7a
feat(group): include new AWS FTR checks group
2021-10-26 14:06:34 +02:00
Toni de la Fuente
1c7d3c452f
Fix Shodan typo in -h usage text @jfagoagas
...
Fix Shodan typo in -h usage text @jfagoagas
2021-10-26 12:42:44 +02:00
Pepe Fagoaga
12c6f726e9
fix(lambda-secrets): change aws cli output format to extract keys and values ( #4 )
2021-10-26 12:31:25 +02:00
Pepe Fagoaga
7a3e353d54
docs(usage): Fix Shodan typo ( #3 )
2021-10-25 14:49:51 +02:00
Zaid Qumei
dfdcd107fc
Fixed servicename and fail text
2021-10-22 10:48:01 -04:00
Toni de la Fuente
a3a5d7cc4d
Delete main.yml
2021-10-21 12:35:42 +02:00
Toni de la Fuente
c7c76a0581
Create main.yml
2021-10-21 12:15:09 +02:00
Toni de la Fuente
f06168f490
Fix check extra734 about S3 buckets default encryption with StringNotEquals @rustic
...
Fix check extra734 about S3 buckets default encryption with StringNotEquals @rustic
2021-10-19 16:54:53 +02:00
Lee Myers
fc07fa44ee
check_extra734 update to StringNotEquals
2021-10-15 15:09:56 -04:00
Toni de la Fuente
8f265dca68
Updated parts from check7152 @jarrettandrulis
...
Updated parts from check7152 @jarrettandrulis
2021-10-15 14:30:17 +02:00
Jarrett Andrulis
7ff9dcd65e
Updated link
2021-10-14 16:39:49 -05:00
Jarrett Andrulis
64a162fca1
Updated parts from check7152 accidentally left in
2021-10-14 16:37:47 -05:00
Zaid Qumei
e284a56f0d
Added extracheck 7157
2021-10-14 09:46:03 -04:00
Toni de la Fuente
9d9a3ef761
Removed dot in title for consistency in new checks
2021-10-07 16:49:10 +02:00
Toni de la Fuente
571a714a82
Updated with right service name for consistency
2021-10-07 16:42:30 +02:00
Toni de la Fuente
b6fdbaba01
New feature: adding the ability to provide a file for checks to be ran @Kirizan
...
New feature: adding the ability to provide a file for checks to be ran @Kirizan
2021-10-07 14:31:34 +02:00
nikirby
6874fa4793
Fixed sample file to be what it's looking for.
2021-10-06 10:48:13 -04:00
nikirby
e23b24099d
Added -C option to provide a file with the checklist to be checked against. Also added checklist.txt to provide a sample file
2021-10-06 10:41:40 -04:00
Toni de la Fuente
d3b04d3ed9
Update group extras with new checks
2021-10-05 17:39:52 +02:00
Toni de la Fuente
ea1d0c4dfa
New check 7148 EFS File systems have backup enabled @georgie969
2021-10-05 17:39:22 +02:00
Toni de la Fuente
a9b2bc1167
New check 7155 Application Load Balancer is configured with defensive or strictest desync mitigation mode @ShubhamShah11
2021-10-05 17:31:59 +02:00
Toni de la Fuente
6fb49a46bf
New check 7153 Route53 transfer lock for domains enabled @jarrettandrulis
2021-10-05 17:31:30 +02:00
Toni de la Fuente
221f6038d7
Restore group extras
2021-10-05 17:22:53 +02:00
Toni de la Fuente
f4045c6d97
New Check 7156 API Gateway V2 has Access Logging enabled @dsensibaugh
...
New Check 7156 API Gateway V2 has Access Logging enabled @dsensibaugh
2021-10-05 16:55:08 +02:00
Toni de la Fuente
53e5681f35
New check 7154 CloudFormation stack termination protection enabled @ShubhamShah11
...
New check 7154 CloudFormation stack termination protection enabled @ShubhamShah11
2021-10-05 16:52:38 +02:00
Toni de la Fuente
ca96addd92
New check 7152 Route53 domain privacy protection enabled @jarrettandrulis
...
New check 7152 Route53 domain privacy protection enabled @jarrettandrulis
2021-10-05 16:49:15 +02:00
Jarrett Andrulis
27ab868e49
Update check_extra7152
2021-10-04 15:26:05 -05:00
Toni de la Fuente
bffc9799c1
Updated documentation regarding a confusion with the -q option (issue #884 ) @w0rmr1d3r
...
Updated documentation regarding a confusion with the `-q` option (issue #884 ) @w0rmr1d3r
2021-10-04 13:28:37 +02:00
Toni de la Fuente
d704f1003c
New check 7151 DynamoDB tables point-in-time recovery (PITR) enabled @ManuelUgarte
...
New check 7151 DynamoDB tables point-in-time recovery (PITR) enabled @ManuelUgarte
2021-10-04 13:24:01 +02:00
Toni de la Fuente
af7c4393d2
New check 7149 Redshift automated snapshots enabled @georgie969
...
New check 7149 Redshift automated snapshots enabled @georgie969
2021-10-04 13:22:14 +02:00
Toni de la Fuente
13d8c94053
New check 7150 ELB deletion protection enabled @ManuelUgarte
...
New check 7150 ELB deletion protection enabled @ManuelUgarte
2021-10-04 13:21:32 +02:00
Ramon
2f4a5c7c51
updated documentation regarding a confusion with the -q option
2021-10-04 13:13:24 +02:00
David Sensibaugh
fec9c9c976
Update check_extra7156
2021-10-03 18:59:52 -04:00
EC2 Default User
4f7d75598d
Changed ',' with ';' in check variables
2021-10-01 15:24:14 +00:00
EC2 Default User
babbf065de
Changed ',' with ';' in variables
2021-10-01 15:21:02 +00:00
Shubham Shah
f74414532d
Update check_extra7154
2021-10-01 11:14:26 -04:00
Shubham Shah
44d40e4f0d
Update check_extra7154
2021-09-28 16:34:44 -04:00
EC2 Default User
cff8f4a8d2
variable ends with just the value of key 'PointInTimeRecoveryStatus' if it is ENABLED.
2021-09-28 18:54:33 +00:00
Toni de la Fuente
34dd6842c4
New check 7148 EFS File systems have backup enabled @georgie969
...
New check 7148 EFS File systems have backup enabled @georgie969
2021-09-28 17:29:46 +02:00
Toni de la Fuente
70c6e5c7af
Fix duplicated region in textFail message for extra741 @pablopagani
...
Fix duplicated region in textFail message for extra741 @pablopagani
2021-09-28 17:27:51 +02:00
Pablo Pagani
11deceb9e6
Bugfix: duplicated region in textFail message.
2021-09-23 14:05:20 -03:00
Toni de la Fuente
7c0d53a0e6
Delete group7_extras
2021-09-23 10:16:26 +02:00
Toni de la Fuente
e4ecbcbd54
Delete group7_extras
2021-09-23 10:08:26 +02:00
Toni de la Fuente
db6363e89f
Delete randomFile.txt
2021-09-23 10:08:03 +02:00
Toni de la Fuente
fad06ef5c0
New feature added flags Z to control if Prowler returns exit code 3 on a failed check @Kirizan
...
New feature added flags `Z` to control if Prowler returns exit code 3 on a failed check @Kirizan
2021-09-23 09:30:56 +02:00
Toni de la Fuente
473e0fbc3a
Fix doc reference link in check23 @FallenAtticus
...
Fix doc reference link in check23 @FallenAtticus
2021-09-23 09:27:14 +02:00
Toni de la Fuente
254cb0cf63
Fix Security Hub conflict with duplicated findings in the management account #711 @xeroxnir
...
Fix Security Hub conflict with duplicated findings in the management account #711 @xeroxnir
2021-09-21 17:03:04 +02:00
Shubham Shah
73c65cf323
Update group7_extras
2021-09-20 20:07:43 -04:00
Shubham Shah
052a36207c
Update check_extra7154
2021-09-20 20:06:48 -04:00
Shubham Shah
ff3ef0b8c0
Update check_extra7154
2021-09-20 19:11:23 -04:00
Shubham Shah
e42a2f8249
Merge pull request #1 from ShubhamShah11/ShubhamShah11-patch-1
...
Shubham shah11 patch 1
2021-09-20 19:02:53 -04:00
Shubham Shah
6201a2a3fb
Update check_extra7154
2021-09-20 19:02:28 -04:00
Shubham Shah
c6c730a81e
Update check_extra7154
2021-09-20 17:21:19 -04:00
Shubham Shah
7d79532c1f
Adding check_extra7154
2021-09-20 17:20:13 -04:00
Shubham Shah
af38286a15
Create check_extra7154
2021-09-20 17:06:33 -04:00
Jarrett Andrulis
6566e80a3c
renamed as extra7152
2021-09-20 10:59:30 -05:00
Jarrett Andrulis
397a44e3f9
Adding check_extra7151
2021-09-20 10:16:52 -05:00
EC2 Default User
9d76ba0c7b
Removed xargs from line 30, not needed. Tested code against resources.
2021-09-16 13:29:06 +00:00
Joaquin Rinaudo
504b27b47a
#711 fix Security Hub management account
...
* Filter by AWS account Id to avoid importing findings from other accounts.
2021-09-16 15:15:15 +02:00
EC2 Default User
ee5ae4fc5e
Check if DynamoDB tables point-in-time recovery (PITR) is enabled.
2021-09-15 20:38:24 +00:00
EC2 Default User
df7a2c6ef3
Added EOL and updated some variables to make it easier to read.
2021-09-15 18:12:11 +00:00
Toni de la Fuente
48b45bbf95
Terraform Kickstarter @singergs
...
Terraform Kickstarter @singergs
2021-09-15 14:52:21 +02:00
George
9776c412c9
New Prowler check 7149 added
2021-09-14 16:50:07 -04:00
George
7b645a4a34
New Prowler check 7149 added
2021-09-14 16:36:17 -04:00
EC2 Default User
5c6b81dd8b
elb deletion protection enabled checkextra 7150
2021-09-14 19:57:40 +00:00
Geoff Singer
0437c10dfd
Update: Documentation reference
...
Removed gifs in git repo and moved to S3 for storage. Effort to reduce the size of the git repo.
Moved artifacts to the util dir
2021-09-13 16:14:35 -05:00
Toni de la Fuente
9fc9e43172
Fix typo and HTTP capitalisation in extra7142 @acknosyn
...
Fix typo and HTTP capitalisation in extra7142 @acknosyn
2021-09-13 19:23:41 +02:00
Toni de la Fuente
c1403dc140
Fix support policy arn in check120 @hersh86
...
Fix support policy arn in check120 @hersh86
2021-09-13 19:20:15 +02:00
Toni de la Fuente
a827504d58
Added feature to allow role ARN while using -R parameter @mmuller88
...
Added feature to allow role ARN while using -R parameter @mmuller88 #859
2021-09-13 19:01:15 +02:00
Toni de la Fuente
f3dcfe9f8e
Added a new way to deploy Prowler at Organizational level with serverless @bella-kwon
...
Added a new way to deploy Prowler at Organizational level with serverless @bella-kwon
2021-09-13 18:57:36 +02:00
Geoff Singer
8617c77889
Remove: Link
...
Removed the hardlink to repo video file
2021-09-13 11:53:50 -05:00
Toni de la Fuente
28b97058ad
Fix bug in extra784 @tayivan-sg
...
Fix bug in extra784 @tayivan-sg
2021-09-13 18:52:28 +02:00
Geoff Singer
8769783b75
Remove: Video File
...
Uploaded video file to youtube and removed it from the repo
2021-09-13 11:38:08 -05:00
Geoff Singer
1f1d7b2954
Update: Video Reference
2021-09-13 11:37:02 -05:00
georgie969
8586b1073d
Delete extra_check7149
...
This file (7149) was committed in error
2021-09-10 10:52:15 -04:00
George
e17d6e580f
New Prowler Check 7149 by George O. submitted for review
2021-09-10 09:22:21 -04:00
George
b3aa82a3b0
New Prowler Check 7148 by George O. submitted for review
2021-09-08 16:01:18 -04:00
Jarrett Andrulis
c23ba56313
commit
2021-09-08 14:43:54 -05:00
sascha.duwe
aadc7640b1
Removed the trailing space
2021-09-07 15:30:17 +02:00
nikirby
c901233199
Added CLI flags Z for selecting which checks should generate exit code 3, and z to stop exit code 3 being generated at all.
2021-09-07 08:54:47 -04:00
Sascha Duwe
ecec784113
Update check23
...
Fixed reference link
2021-09-07 11:13:42 +02:00
Acknosyn
d2c75d8d71
Fix typo and HTTP capitalisation
2021-09-06 11:24:34 +12:00
Alex Hershey
56fd096620
Quick fix for check120
2021-09-03 17:01:08 -04:00
Geoff Singer
1a2fd87777
Update: Create tf files for variables, output, etc.
...
Separated the variables, outputs, and data into separate tf files
2021-09-02 12:01:39 -05:00
Geoff Singer
859d78a204
Merge remote-tracking branch 'origin/terraform-kickstarter' into terraform-kickstarter
2021-09-02 09:29:30 -05:00
Geoff Singer
ea337993c3
Update: buildspec.yml
...
- removed the branch checkout
- moved all the commands to the install phase
per comments by w0rmr1d3r
2021-09-02 09:29:24 -05:00
Geoff Singer
21694f866e
Update:
...
- removed the branch checkout
- moved all the commands to the install phase
per comments by w0rmr1d3r
2021-09-02 09:28:22 -05:00
Martin Mueller
36c4040a7f
improve doc for -R
2021-09-02 07:32:42 +02:00
Toni de la Fuente
5757767b25
Fixed typo in risk description for check29 @kamiryo
...
Fixed typo in risk description for check29 @kamiryo
2021-09-01 19:14:03 +02:00
Geoff Singer
74a2f5ba03
Documentation: Updates
2021-09-01 11:33:31 -05:00
Martin Mueller
8d8ec38c60
feat: allow role arn for R parameter
2021-09-01 08:06:59 +02:00
Geoff Singer
8280ff619a
Update: Documentation
2021-08-31 10:21:26 -05:00
Geoff Singer
77a732b8b3
Buildspec: parameter change
2021-08-31 09:43:57 -05:00
Geoff Singer
dc8e3b0028
Update: IAM role
2021-08-31 09:16:36 -05:00
Geoff Singer
066c90028f
Update: IAM role
2021-08-31 09:05:16 -05:00
Geoff Singer
e621ae465a
Updated: install commands
2021-08-31 08:25:28 -05:00
Geoff Singer
66cb830b66
Added: terraform artifacts
2021-08-31 08:21:37 -05:00
kamiryo
9f9d82adef
Update check29
...
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.
Fixed typo
2021-08-30 16:43:42 +09:00
bella-kwon
12c52625c5
Readme and doc resources added
2021-08-30 11:00:31 +09:00
bella-kwon
f33342aef9
Prowler execution script added
2021-08-30 10:59:33 +09:00
bella-kwon
9f435b45fa
Organizational prowler template added
2021-08-30 10:59:08 +09:00
Ivan Tay
13b93c81ea
Changes to fix bug in extra 784
2021-08-26 09:55:27 +08:00
Toni de la Fuente
06f790858b
Fix title, remediation and doc link for check extra768 @w0rmr1d3r
...
Fix title, remediation and doc link for check extra768 @w0rmr1d3r
2021-08-25 11:28:40 +02:00
Toni de la Fuente
a72a2e9b48
Ignore archived findings in GuardDuty for check extra7139 @chbiel
...
Ignore archived findings in GuardDuty for check extra7139 @chbiel
2021-08-25 11:26:31 +02:00
Ramon
c14593a40e
fix check_extra768 texts
2021-08-20 16:22:52 +02:00
Christopher Biel
321c79a374
Ignore archvived findings, as the check should only look at active findings, not those that were moved to the archive of guardduty
2021-08-19 11:50:16 +02:00
Toni de la Fuente
49261840d0
Fix extra737 remove false positives due to policies with condition @rinaudjaws
...
Fix extra737 remove false positives due to policies with condition @rinaudjaws
2021-08-18 20:31:26 +02:00
Toni de la Fuente
06157bcb87
Updated prowler-codebuild-role name for CFN StackSets name length limit @varunirv
...
Updated prowler-codebuild-role name for CFN StackSets name length limit @varunirv
2021-08-18 20:29:17 +02:00
rinaudjaws
38df162976
Remove KMS with conditions false positives
...
CDK for example implements callerAccount as a condition for the KMS policy resulting in too many false positives.
2021-08-18 08:52:46 +02:00
Rajat
3df5ee330d
Updated prowler-codebuild-role name
...
This change is to fix the issue as reported at
https://github.com/toniblyx/prowler/issues/845
2021-08-13 14:55:12 -04:00
Ramon
fbf7bb0bfe
Merge pull request #1 from toniblyx/master
...
Updating with Upstream
2021-08-13 11:33:04 +02:00
Toni de la Fuente
3b6bc7fa64
2.5 - See release notes https://github.com/toniblyx/prowler/releases/tag/2.5.0
...
2.5 - See release notes https://github.com/toniblyx/prowler/releases/tag/2.5.0
2021-08-13 11:03:49 +02:00
Toni de la Fuente
e0f60114f4
Consolidated license file
2021-08-13 10:05:56 +02:00
Toni de la Fuente
e39ff9683c
Set new version 2.5.0-12August2021
2021-08-12 10:38:59 +02:00
Toni de la Fuente
63233c9333
Changed check textTitle format for default output
2021-08-12 10:37:36 +02:00
Toni de la Fuente
3297fba209
Added new checks to extras
2021-08-10 23:11:50 +02:00
Toni de la Fuente
9c3ab79510
Removed Scored from title
2021-08-10 18:45:39 +02:00
Toni de la Fuente
24dec21aa4
Merge branch '2.5-new-checks' into 2.5
2021-08-10 17:28:48 +02:00
Toni de la Fuente
c8e9cf2e77
Tested new checks 7143 to 7147
2021-08-10 17:00:18 +02:00
Toni de la Fuente
5d4a96c35b
Adding custom security checks @nayabpatel
...
Adding custom security checks @nayabpatel
2021-08-10 15:29:29 +02:00
Toni de la Fuente
4607e519a9
Merge branch '2.5-new-checks' into custom-checks
2021-08-10 15:25:31 +02:00
Toni de la Fuente
eba79e265e
Merge branch '2.5' of https://github.com/toniblyx/prowler into 2.5
2021-08-10 15:13:26 +02:00
Toni de la Fuente
f418c706b5
Removed extra756 from extras as duplicated
2021-08-10 15:13:14 +02:00
Toni de la Fuente
7b9a7ccb8a
Merge pull request #841 from toniblyx/2.5
...
2.5
2021-08-10 15:09:11 +02:00
Toni de la Fuente
ad23bddabe
Ignore secrets folder in git @w0rmr1d3r
...
Ignore secrets folder in git @w0rmr1d3r
2021-08-10 15:04:50 +02:00
Toni de la Fuente
d869c748fb
Now shows default output regardless custom outputs called with -M
2021-08-10 14:07:31 +02:00
Toni de la Fuente
cdf99c9600
Removed scored info from title
2021-08-10 14:03:13 +02:00
Toni de la Fuente
c6203bf9e3
Clean up redentials report output
2021-08-10 14:02:21 +02:00
Toni de la Fuente
62050e2e34
Added PROWLER_START_TIME to CSV for reports
2021-08-10 14:01:40 +02:00
Ramon
558a9b5f2e
ignore secrets folder when scanning for secrets
2021-08-06 11:46:45 +02:00
Toni de la Fuente
d71e4a0214
Updated html report colour contrast for WCAG 2.1 accessibility standards @danielperez660
...
Updated html report colour contrast for WCAG 2.1 accessibility standards @danielperez660
2021-08-02 15:15:57 +02:00
danielperez660
9c24ae59cf
Merge branch '2.5' into master
2021-08-02 14:10:14 +01:00
Toni de la Fuente
98f0755a0f
Fix grammar issue in scoring @w0rmr1d3r
...
Fix grammar issue in scoring @w0rmr1d3r
2021-08-02 15:01:50 +02:00
Toni de la Fuente
38ebad4f00
Delete duplicated check extra737 and its references @w0rmr1d3r
...
Delete duplicated check extra737 and its references @w0rmr1d3r
2021-08-02 14:15:45 +02:00
Toni de la Fuente
5685cb8959
Merge branch '2.5' into delete_check_extra737_is_duplicated
2021-08-02 14:14:45 +02:00
Toni de la Fuente
ad28cf4671
Delete duplicated check extra756 and its references @w0rmr1d3r
...
Delete duplicated check extra756 and its references @w0rmr1d3r
2021-08-02 14:12:38 +02:00
daniel
3a66ca336a
changes made so there is enough colour contrast for WCAG 2.1 accessibility standards
2021-08-02 13:23:16 +02:00
Toni de la Fuente
26d310e35b
Updated Prowler additions policy
2021-07-29 18:37:57 +02:00
Toni de la Fuente
52e04406dc
Added servicename to the title for ASFF
2021-07-29 17:03:04 +02:00
Toni de la Fuente
3f63b83179
Added section with info about regions
2021-07-27 15:12:14 +02:00
Toni de la Fuente
4d6285f167
Added s3 and glue required permissions and removed obsoletes
2021-07-27 14:52:23 +02:00
Toni de la Fuente
ffe147b5b5
Added s3 and glue required permissions and removed obsoletes
2021-07-27 14:49:58 +02:00
Toni de la Fuente
c32fa9aa1f
Added s3 and glue required permissions
2021-07-27 14:43:20 +02:00
Ramon
9ddb31f9c3
fix grammar issue
2021-07-16 12:26:46 +02:00
Ramon
0d9ec6320e
delete check extra737 and its references
2021-07-16 12:09:54 +02:00
Ramon
8c70efde5f
delete check extra756 and its references
2021-07-16 12:03:39 +02:00
Toni de la Fuente
065483a8b6
Update check12 - Missing MFA at the beginning of remediation @thorkill
...
Update check12 - Missing MFA at the beginning of remediation @thorkill
2021-07-16 10:17:28 +02:00
Rafał Leśniak
0a4ca0d2ed
Update check12
...
Added missing MFA in remediation description.
2021-07-16 01:35:46 +02:00
Toni de la Fuente
ab1407217d
Enhanced Dockerfile with py3-pip
2021-07-09 13:57:35 +02:00
Toni de la Fuente
265f494b0d
Fixed check21 to fail if trail is off
2021-07-08 17:09:22 +02:00
Toni de la Fuente
85cb2085b9
Output consolidation
2021-07-07 16:15:53 +02:00
Toni de la Fuente
5670e4a972
Removed CSV header stdout and add bucket-owner-full-control
2021-07-07 16:00:09 +02:00
Toni de la Fuente
c09385976a
Consolidated titles and outputs including resource ID in ASFF
2021-07-05 20:17:27 +02:00
Toni de la Fuente
a9f277e131
Delete util/dashboard directory
2021-07-05 20:16:22 +02:00
Toni de la Fuente
f540758e36
Delete util/ec2-automation directory
2021-07-05 20:15:48 +02:00
Toni de la Fuente
90ae53a976
Delete util/quicksight directory
2021-07-05 20:15:33 +02:00
Toni de la Fuente
24a02c1f71
Merge branch '2.5' of https://github.com/toniblyx/prowler into 2.5
2021-07-05 20:14:03 +02:00
Toni de la Fuente
3936a7b17a
Changed how color codes are shown in text mode
2021-07-05 20:11:35 +02:00
Toni de la Fuente
bc959a23f1
License file and banner cosolidation
2021-07-04 12:32:50 +02:00
Toni de la Fuente
d53e6eb3a9
Fixed aws organizations multi-account deployment s3 upload issue @owlvat
...
Fixed aws organizations multi-account deployment s3 upload issue @owlvat
2021-06-30 10:30:04 +02:00
IB (AWS)
8c74ef102f
fixed aws organizations multi-account s3 upload issue
2021-06-28 14:49:54 -07:00
Toni de la Fuente
706d20b5f6
Updated document title
2021-06-24 17:55:46 +02:00
Toni de la Fuente
4e9e421c84
Updated README to include reference to CloudShelld
2021-06-24 17:49:33 +02:00
Patel
800bcb0016
renaming extra checkId, change in text message format, adding more metadata variables, lowercase servicename, adding checks in extras group
2021-06-24 15:47:29 +05:30
Toni de la Fuente
3441b34f01
Add ResourceID to all checks output for ASFF and other output formats @singergs
...
Add ResourceID to all checks output for ASFF and other output formats @singergs
2021-06-23 23:25:05 +02:00
Toni de la Fuente
dc47d32a36
Update: Add data to the ASFF @singergs
...
Update: Add data to the ASFF @singergs
2021-06-23 23:18:41 +02:00
Toni de la Fuente
a8ae0bc845
Adding code for running in AWS CloudShell @hackersifu
...
Adding code for running in AWS CloudShell @hackersifu
2021-06-23 10:34:55 +02:00
Joshua McKiddy
74ddaf8087
Adding code for running in cloudshell
2021-06-22 11:07:14 -07:00
Patel
8a2d2924b4
Fixed typo issues, removed commented line, change in severity
2021-06-17 11:43:19 +05:30
Geoff
4961498562
Added parameter to report resource name
...
Added a third parameter to checks textFail and textPass to identify resource name in finding.
2021-06-16 22:25:44 -05:00
Geoff
b14ac340bb
Update: Add data to the ASFF
...
Added in the ASFF ProductFields ProwlerResourceName. The resource name is passed into the fining from the third parameter in the Prowler checks
2021-06-16 09:12:17 -05:00
Toni de la Fuente
86aa9c317f
HTML Report: Filtering and other nice things @nickmalcolm
...
HTML Report: Filtering and other nice things @nickmalcolm
2021-06-14 14:31:48 +02:00
Toni de la Fuente
7dec9f3d52
Merge branch '2.5' into nicer-html
2021-06-14 14:30:04 +02:00
Nick Malcolm
da45af78bc
Disable ordering so that it sticks with the order the HTML was generated
2021-06-14 21:13:19 +12:00
Nick Malcolm
01663e4e0d
Page width improvements. Use the 'link' icon for the link to docs, to cut down on page width. Remove the status column to save width, and also remove redundancy (colour coding and Result column serve the same purpose). Remove the column widths that added to over 100%.
2021-06-14 21:00:40 +12:00
Nick Malcolm
34e27131fd
Refactor the HTML outputs so that they reuse code and are easier to change
2021-06-14 20:46:14 +12:00
Nick Malcolm
89af81ed22
Use DataTable's SearchPanes extension to allow easy filtering by result, severity, region, service, or check.
2021-06-14 20:33:38 +12:00
Nick Malcolm
f5a4e357b9
Consolidate javascript at the bottom of the template. Remove duplicate bootstrap includes - you only need bundle to get Popper (see https://getbootstrap.com/docs/4.0/getting-started/contents/#js-files ) and you don't need both plain bootstrap and bundled bootstrap. Remove dupe jQuery too.
2021-06-14 20:27:16 +12:00
Patel
8e9ef841e5
Adding custom security checks
2021-06-14 12:43:21 +05:30
Toni de la Fuente
1229815c04
Add WAF CLASSIC check for extra7129 @kamiryo
...
Add WAF CLASSIC check for extra7129 @kamiryo
2021-06-11 17:17:28 +02:00
kamiryo
79a0eb622d
Add WAF CLASSIC check for extra7129
2021-06-10 23:13:17 +09:00
Toni de la Fuente
f38f99e786
Corrected bug on groups when listing checks @pablopagani
...
Corrected bug on groups when listing checks @pablopagani
2021-06-10 10:29:37 +02:00
Pablo Pagani
aa3edbc636
corrected bug on groups when listing checks
...
corrected bug on groups when listing checks (option -l)
Previous regular expression will include groups when it matched half of the check_id
2021-06-09 14:01:27 -03:00
Toni de la Fuente
3f07afd7d4
Added custom file option @yangsec888
...
Added custom file option @yangsec888
2021-06-08 15:46:47 +02:00
Toni de la Fuente
701d5687be
Fixed issue #811 @h1008
...
Fixed issue #811 @h1008
2021-06-08 14:50:59 +02:00
Toni de la Fuente
382e9c8e00
Align group21 title with the rest @w0rmr1d3r
...
Align group21 title with the rest @w0rmr1d3r
2021-06-08 14:49:52 +02:00
Ramon
c74faa6d07
add missing * to align with the rest of the titles
2021-06-08 14:18:46 +02:00
h1008
5aeb670a84
Fixed issue #811
2021-06-05 11:57:04 +02:00
Toni de la Fuente
124ae0fd2e
Fixed kms keys compatibility in cli v2 and v1
2021-06-02 17:53:12 +02:00
Toni de la Fuente
4ddf0aff86
Added extra7142 to group extras
2021-06-01 12:28:30 +02:00
Toni de la Fuente
96b9accea8
New check extra7142 ALB Header Check request smuggling @Outrun207
...
New check extra7142 ALB Header Check request smuggling @Outrun207
2021-06-01 12:27:07 +02:00
Toni de la Fuente
324a1002a5
Fix finding customer kms keys in cli v2 for checks extra737 extra736 @dbellizzi
...
Fix finding customer kms keys in cli v2 for checks extra737 extra736 @dbellizzi
2021-06-01 12:24:19 +02:00
Toni de la Fuente
311d21546d
Enhanced -f <filterregion> usage info
2021-06-01 09:10:51 +02:00
Toni de la Fuente
5f1fa558c9
Changes in text output with severity and service name
2021-06-01 09:09:25 +02:00
Toni de la Fuente
9b6198d5b0
Merge branch '2.5' of https://github.com/toniblyx/prowler into 2.5
2021-05-31 18:48:10 +02:00
Toni de la Fuente
55e703540e
Fixed typo in check extra7141 ID
2021-05-31 18:47:56 +02:00
Dom Bellizzi
baf5232cbc
Fix finding customer kms keys in cli v2 for checks extra737 extra736
...
Key id is in position 6 in aws cli version 2.2.5, but in position 4 in aws cli 1.x
Use --query to select only the data necessary and output in a consistent format
2021-05-29 22:27:15 +00:00
Josh Moss
e3893c7d5b
Update check_extra7142
2021-05-25 13:49:27 -04:00
Sam (Yang) Li
a711b482df
Fix #795 custom file option
2021-05-20 14:49:53 -04:00
Josh Moss
229d9ba00c
ALB Header Check
2021-05-20 12:36:30 -04:00
Toni de la Fuente
51617df6c9
Bump Alpine to 3.13 in Dockerfile @gliptak
...
Bump Alpine to 3.13 in Dockerfile @gliptak
2021-05-20 17:10:28 +02:00
Toni de la Fuente
78e5dc5dba
Added new check extra7141 to detect secrets in SSM Documents
2021-05-18 18:28:15 +02:00
Toni de la Fuente
1655bdb902
Added resource id to RDS checks and in json,csv,html outputs
2021-05-18 16:57:37 +02:00
Toni de la Fuente
30442b2da7
Added new check extra7140 for public SSM Documents
2021-05-18 16:10:55 +02:00
Toni de la Fuente
501082876c
Fixed alias of extra7139
2021-05-18 16:08:10 +02:00
Toni de la Fuente
8d9ca987b5
Added link to doc for check45 check46 extra7138 and extras
2021-05-18 15:41:45 +02:00
Toni de la Fuente
f4cd84afd2
Merge pull request #785 from jfagoagas/new-acls-checks
...
Added new checks to test Network ACLs open to 22, 3389 and any port
2021-05-18 15:35:33 +02:00
Toni de la Fuente
46c6f44055
Merge branch '2.5' into new-acls-checks
2021-05-18 15:34:27 +02:00
Gábor Lipták
b72f66469e
Bump Alpine to 3.13 in Dockerfile
2021-05-17 11:23:51 -04:00
Toni de la Fuente
cf4034c3b4
Improved error handling sts get-caller-identity @pablopagani
...
Improved error handling sts get-caller-identity @pablopagani
2021-05-04 15:43:29 +02:00
Toni de la Fuente
7c65430508
Improved error handling when listing regions @pablopagani
...
Improved error handling when listing regions @pablopagani
2021-05-04 15:39:25 +02:00
Toni de la Fuente
497b473431
Added check extra7139 shows number of GuardDuty critical findings @pablopagani
...
Added check extra7139 shows number of GuardDuty critical findings @pablopagani
2021-05-04 15:35:36 +02:00
Pablo Pagani
5385c4e546
Improved error handling sts get-caller-identity
...
Instead of looking for a fixed error string, it uses error codes from aws cli
Previos condition was not catching this error message:
An error occurred (ExpiredToken) when calling the GetCallerIdentity operation: The security token included in the request is expired
Also forced the output of the command to json. In some tests I was doing was failing becuase it was sending output as text
2021-05-01 17:54:11 -03:00
Pablo Pagani
9ac8c78fdb
improved error handling when listing regions
2021-05-01 17:47:08 -03:00
Pablo Pagani
ce00f3a019
improved error handling. Added check 7139 .
2021-05-01 17:33:54 -03:00
Pepe Fagoaga
2727b7e8e2
fix(network-acls): update resource type to match AWS documentation
2021-04-28 18:50:20 +02:00
Pepe Fagoaga
2dc1ce61ec
fix(network-acls): fix line typo
2021-04-26 12:30:44 +02:00
Pepe Fagoaga
625384ad6d
feat(network-acls): include checks in networking and internetexposed checks
2021-04-24 13:38:36 +02:00
Pepe Fagoaga
056190cfc9
feat(network-acls): change textFail to textInfo because NACLs are stateless
2021-04-24 13:24:33 +02:00
Pepe Fagoaga
8f784a4548
feat(network-acls): include checks to test NetworkACLs open to 22, 3389 and any port
2021-04-24 13:13:41 +02:00
Pepe Fagoaga
f1185213e8
Merge branch 'master' of github.com:toniblyx/prowler
2021-04-22 18:30:48 +02:00
Pepe Fagoaga
cb60085779
New Networking checks for FTP, Telnet, SQL Server and Kafka ( #2 )
...
* feat(aws-securitygroups): include new control to test ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21
* feat(aws-securitygroups): include extra control 7134 in extra group
* feat(aws-securitygroups): include new control to test ingress from 0.0.0.0/0 or ::/0 to Kafka port 9092
* feat(aws-securitygroups): include new control to test ingress from 0.0.0.0/0 or ::/0 to Telnet port 23
* feat(aws-securitygroups): include new control to test ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 or 1434
* feat(aws-securitygroups): include extra controls 7135, 7136 and 7137 in extra and internet-exposed groups
2021-04-22 18:29:12 +02:00
Toni de la Fuente
0e33e066cd
Added 4 new checks to look for FTP, Telnet, SQL Server and Kafka open ports @jfagoagas
...
Added 4 new checks to look for FTP, Telnet, SQL Server and Kafka open ports @jfagoagas
2021-04-20 17:23:48 +02:00
Pepe Fagoaga
672f3833fc
feat(aws-securitygroups): include extra controls 7135, 7136 and 7137 in extra and internet-exposed groups
2021-04-19 19:31:06 +02:00
Pepe Fagoaga
4327333d00
feat(aws-securitygroups): include new control to test ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 or 1434
2021-04-19 19:28:10 +02:00
Pepe Fagoaga
ab43a8b717
feat(aws-securitygroups): include new control to test ingress from 0.0.0.0/0 or ::/0 to Telnet port 23
2021-04-19 19:26:10 +02:00
Pepe Fagoaga
595bcba1d9
feat(aws-securitygroups): include new control to test ingress from 0.0.0.0/0 or ::/0 to Kafka port 9092
2021-04-19 19:24:31 +02:00
Pepe Fagoaga
68b3e1fa06
feat(aws-securitygroups): include extra control 7134 in extra group
2021-04-19 19:19:24 +02:00
Pepe Fagoaga
2ac96cf29a
feat(aws-securitygroups): include new control to test ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21
2021-04-19 19:18:23 +02:00
Toni de la Fuente
49533de21b
Added support for custom output folder and S3 bucket
2021-04-15 23:51:21 +02:00
Toni de la Fuente
583cffaefb
2.4.1 @toniblyx
...
2.4.1 @toniblyx
2021-04-15 10:22:00 +02:00
Toni de la Fuente
721b15d105
Fixed issue #776
2021-04-15 09:30:31 +02:00
Toni de la Fuente
53117819fc
Fixed credentials renew issue #775
2021-04-14 11:47:38 +02:00
Toni de la Fuente
2552f2977d
Fixed issue #775
2021-04-12 21:23:28 +02:00
Toni de la Fuente
8a04f40a80
Fixed issue #774
2021-04-12 20:20:04 +02:00
Toni de la Fuente
b0fd6ce60f
Merge pull request #773 from toniblyx/2.4
...
v2.4
2021-04-09 15:51:44 +02:00
Toni de la Fuente
e4edc2fa2c
Improved feature to refresh assume role credentials before it expires
2021-04-09 15:13:13 +02:00
Toni de la Fuente
10d062960e
Updated screenshots
2021-04-08 00:35:12 +02:00
Toni de la Fuente
7f24aab715
Updated README
2021-04-08 00:22:07 +02:00
Toni de la Fuente
3dfca9c9dd
Improved html output with scoring information
2021-04-08 00:14:24 +02:00
Toni de la Fuente
dacfea6b32
Included Risk, Remediation and Link support for CSV and HTML outputs
2021-04-07 18:42:44 +02:00
Toni de la Fuente
574a9c94b0
Added Risk, Remediation and Link to html report
2021-04-07 18:40:50 +02:00
Toni de la Fuente
7bace94e08
Fixed servicename variable in extra72
2021-04-07 18:39:14 +02:00
Toni de la Fuente
778910eff3
Added new logo to README.md header
2021-04-06 17:32:55 +02:00
Toni de la Fuente
755f7d952f
Added new logo
2021-04-06 17:15:33 +02:00
Toni de la Fuente
d02e1967dc
Improved PublicIP discovery used in Shodan check_extra7102 @as-km
...
Improved PublicIP discovery used in Shodan check_extra7102 @as-km
2021-04-06 13:05:27 +02:00
Mateusz
d77001356a
use describe-network-interfaces instead of describe-addresses in order to get public IPs #768
2021-04-06 12:57:11 +02:00
Toni de la Fuente
e85d8b2a9d
Add check23 to group17_internetexposed group @RyanJarv
...
Add check23 to group17_internetexposed group @RyanJarv
2021-04-06 12:01:52 +02:00
Toni de la Fuente
4f16c8dec5
Merge pull request #766 from toniblyx/revert-765-patch-2
...
Revert "Add check23 to group17_internetexposed group"
2021-04-05 21:17:35 +02:00
Toni de la Fuente
236ce1fb21
Revert "Add check23 to group17_internetexposed group"
2021-04-05 21:16:58 +02:00
Toni de la Fuente
15230ae6f3
Add check23 to group17_internetexposed @RyanJarv
...
Add check23 to group17_internetexposed @RyanJarv
2021-04-05 21:16:54 +02:00
Ryan Gerstenkorn
6c5776106f
Add check23 to group17_internetexposed group
...
This add's the following check to group17.
* 2.3 [check23] Ensure the S3 bucket CloudTrail logs to is not publicly accessible (Scored)
2021-04-05 12:07:08 -07:00
Toni de la Fuente
4100d1dbfd
Replace empty space with '\s' in check43 regex @frannovo
...
Replace empty space with '\s' in check43 regex @frannovo
2021-04-05 15:49:04 +02:00
Toni de la Fuente
abcd299559
Add get_regions function in order to call after assume_role @HG00
...
Add get_regions function in order to call after assume_role @HG00
2021-04-05 15:35:54 +02:00
Toni de la Fuente
f6049a0597
Merge branch '2.4' into master
2021-04-05 15:27:31 +02:00
HG00
bb397baa8a
Add get_regions function in order to call after assume_role
2021-03-30 11:53:24 +00:00
Toni de la Fuente
c0f3265754
Better handle permissions and errors
2021-03-24 15:41:51 +01:00
Toni de la Fuente
9614b6fc82
Merge branch '2.4' of https://github.com/toniblyx/prowler into 2.4
2021-03-24 15:12:48 +01:00
Toni de la Fuente
a9d56be81a
Added risk, remediation, doc link and caf epic to checks 742 to 7133
2021-03-24 15:12:32 +01:00
Toni de la Fuente
0c4111efda
Moved assume role before listing regions fixes issue #744
2021-03-24 15:11:00 +01:00
Toni de la Fuente
5fb2e496a9
Added risk, remediation, doc link and caf epics to controls 1 to 741 @pablopagani
...
Added risk, remediation, doc link and caf epics to controls 1 to 741 @pablopagani
2021-03-24 14:36:54 +01:00
Pablo Pagani
7b4dae634e
Merge branch '2.4' of https://github.com/pablopagani/prowler into 2.4
2021-03-24 10:23:04 -03:00
Pablo Pagani
35a22a71cd
added risk remediation doc and epics to controls 1 to 741
2021-03-24 10:22:29 -03:00
Toni de la Fuente
21f817b087
Removed textInfo extra information on extra712
2021-03-24 12:30:59 +01:00
Toni de la Fuente
923dc3403b
Added risk, remediation, doc link and epics to first 3 checks @pablopagani
...
Added risk, remediation, doc link and epics to first 3 checks
2021-03-24 09:08:19 +01:00
Pablo Pagani
68d240939c
added risk, remediation doc and epics to firts 3 checks
2021-03-23 15:23:55 -03:00
Pablo Pagani
a9d0649122
added risk, remediation doc and epics to firts 3 checks
2021-03-23 15:19:23 -03:00
Fran Novo
3eeba2ef4e
Replace empty space with '\s' in check43 regex
2021-03-15 17:45:49 +01:00
Toni de la Fuente
806eaa0b98
Updated ProwlerExecRoleAdditionalViewPrivileges Policy with lambda:GetFunction
...
Updated ProwlerExecRoleAdditionalViewPrivileges Policy with lambda:GetFunction
2021-03-11 14:27:52 +01:00
Pepe Fagoaga
2cd8d15410
Merge pull request #1 from toniblyx/master
...
Include missing AWS function policy to check AWS Lambda
2021-03-11 13:33:11 +01:00
Toni de la Fuente
d8473cfe87
Include missing AWS function lambda:GetFunction policy in prowler-additions-policy.json to check AWS Lambda @jfagoagas
...
Include missing AWS function lambda:GetFunction policy in prowler-additions-policy.json to check AWS Lambda @jfagoagas
2021-03-11 13:13:06 +01:00
Pepe Fagoaga
34625ff4e7
fix: include lambda:GetFunction in prowler policy to check AWS Lambda related controls: extra720,extra759,extra760,extra762,extra798
2021-03-11 12:48:32 +01:00
Toni de la Fuente
097ddbb957
Added extra7133 RDS multi-AZ
2021-03-04 20:29:40 +01:00
Toni de la Fuente
db1380422f
Added high level architecture
2021-02-25 11:56:45 +01:00
Toni de la Fuente
669cb6f1a9
Added IAM to extra7100 title
2021-02-25 11:56:22 +01:00
Toni de la Fuente
fa2a40f5c0
Fix output on extra731
2021-02-23 18:27:38 +01:00
Toni de la Fuente
80b94eb667
Fix output on extra731
2021-02-23 18:24:26 +01:00
Toni de la Fuente
b633ec8bef
Added more checks mappings to ISO27001 group and reordered the list @mario-platt
...
Added more checks mappings to ISO27001 group and reordered the list @mario-platt
2021-02-22 23:21:32 +01:00
Toni de la Fuente
a6ee7922c6
Cloudtrail metrics (check3x) pass if found on any, not every, cloudtrail log @zfLQ2qx2
...
Cloudtrail metrics (check3x) pass if found on any, not every, cloudtrail log @zfLQ2qx2
2021-02-22 23:18:31 +01:00
Toni de la Fuente
2883de016e
Ensure check28 only looks at symmetric keys
2021-02-22 23:15:06 +01:00
Toni de la Fuente
f94bf38bdc
Merge pull request #752 from toniblyx/revert-742-check28-asymmetric-keys
...
Revert "check28 only look at symmetric keys"
2021-02-22 23:05:52 +01:00
Toni de la Fuente
5d7d9efa69
Revert "check28 only look at symmetric keys"
2021-02-22 23:05:05 +01:00
Toni de la Fuente
1d0887ac89
Make check28 only look at symmetric keys @mdop-wh
...
Make check28 only look at symmetric keys @mdop-wh. Asymmetric keys don't support automatic rotation.
2021-02-22 22:36:53 +01:00
Toni de la Fuente
e0dbfaaa37
Merge branch 'master' into check28-asymmetric-keys
2021-02-22 22:35:32 +01:00
Toni de la Fuente
b68cf876bc
Merge pull request #751 from toniblyx/revert-736-universal_epoch_time
...
Revert "Implement OS neutral method of converting rfc3339 dates to epoch"
2021-02-22 21:54:08 +01:00
Toni de la Fuente
97a7471f24
Revert "Implement OS neutral method of converting rfc3339 dates to epoch"
2021-02-22 21:52:19 +01:00
Toni de la Fuente
5d3c526ba7
Implement OS neutral method of converting rfc3339 dates to epoch @zfLQ2qx2
...
Implement OS neutral method of converting rfc3339 dates to epoch
2021-02-22 21:47:06 +01:00
Toni de la Fuente
3d834fae42
Fix typos and add to extras extra7132
2021-02-22 21:44:48 +01:00
Toni de la Fuente
aa3f8a6b5c
Add check for RDS enhanced monitoring @mpratsch
...
Add check for RDS enhanced monitoring @mpratsch
2021-02-22 21:41:24 +01:00
Toni de la Fuente
bddf71d5e6
Add access checks for several checks @zfLQ2qx2
...
Add access checks for several checks @zfLQ2qx2 (21,22,23,24,25,26,27,28,29,720,725)
2021-02-22 21:38:39 +01:00
Toni de la Fuente
8a32d8ae5f
Force default AWS CLI output issue #696 @Kirizan
...
Force default AWS CLI output issue #696 @Kirizan
2021-02-22 21:31:32 +01:00
Mario Platt
78c2cacfd9
added more checks mappings to ISO27001 group, and reordered the list of comment mappings to go from lower to highest requirements in ISO
2021-02-19 14:23:26 +00:00
C.J
7e6291c51d
Cloudtrail metrics pass if found on any, not every, cloudtrail log
2021-02-09 12:29:43 -05:00
Toni de la Fuente
138ece153e
Adjusted severity to secrets and Shodan checks
2021-02-05 08:39:02 +01:00
Toni de la Fuente
5d04febf81
Adjusted severity like in Security Hub
2021-02-05 08:34:34 +01:00
Martina Rath
696a776e2e
Move extra7132 to rd group and add CHECK_SERVICENAME to check
2021-02-05 08:32:06 +01:00
Martina Rath
073d2ab727
Add check if Enhanced monitoring is enabled on RDS instances
2021-02-05 08:12:11 +01:00
Michael Dop
7e8de8adb8
check28 only look at symmetric keys
...
AWS doesn't support the automatic rotation of asymmetric keys
2021-02-04 10:07:27 -05:00
C.J
de87de3b39
Add access checks for several checks
2021-02-03 17:07:02 -05:00
Toni de la Fuente
e91e2cfee6
Updated extra73 with service name
...
Updated extra73 with service name
2021-02-03 14:55:15 +01:00
Toni de la Fuente
d33c82cd00
Merge branch 'master' into patch-1
2021-02-03 14:54:22 +01:00
Toni de la Fuente
0e3e4a9227
Updated
...
added CHECK_SERVICENAME_extra73="s3"
2021-02-03 14:51:11 +01:00
Toni de la Fuente
bea84ad6d3
Fix title grammar in check_extra73 @CenturionGamer
...
Fix title grammar in check_extra73 @CenturionGamer
2021-02-03 14:49:35 +01:00
Toni de la Fuente
79c4a65ba8
Improved to consider services and severity
2021-02-02 17:36:35 +01:00
Toni de la Fuente
e6d175d62e
Check for errors generating credential report, limit loop iterations @zfLQ2qx2
...
Check for errors generating credential report, limit loop iterations @zfLQ2qx2
2021-02-02 15:28:32 +01:00
CenturionGamer
880523880d
Update check_extra73
...
Fixed the grammar by removing "the" in the description.
2021-01-28 13:06:44 -05:00
C.J
cbcc8c61a5
Implement OS neutral method of converting rfc3339 dates to epoch
2021-01-26 14:54:27 -05:00
Toni de la Fuente
f9c2e0cf26
Revert PR #718
2021-01-22 16:17:26 +01:00
Toni de la Fuente
6f371744dc
Added AWS service name to json, csv and html outputs
2021-01-22 10:56:59 +01:00
Toni de la Fuente
dfdff6e863
Added service name to all checks
2021-01-22 00:23:53 +01:00
Toni de la Fuente
8ed40791ad
Added service name to sample check
2021-01-22 00:21:26 +01:00
Toni de la Fuente
f85845c26b
Added service name to all checks
2021-01-22 00:19:45 +01:00
Toni de la Fuente
73cac580f3
Added severity field to CSV and HTML output reports
2021-01-21 22:42:40 +01:00
Toni de la Fuente
6bb49fd162
Merge branch 'master' of https://github.com/toniblyx/prowler
2021-01-21 22:40:50 +01:00
Toni de la Fuente
478cb4aa54
Adjusted severity variable
2021-01-21 22:40:25 +01:00
Toni de la Fuente
47aa6998f4
Update check_extra7130 profile parameter was not set @soffensive
...
Update check_extra7130 profile parameter was not set @soffensive
2021-01-18 17:07:00 +01:00
soffensive
f7e4a1f6a4
Update check_extra7130
...
Profile was not set
2021-01-18 16:41:18 +01:00
Toni de la Fuente
b1332f1154
Fix regex in check43 @ilyas28
...
Fix regex in check43 @ilyas28
2021-01-15 13:05:29 +01:00
İlyas Apaydın
8e35e63359
fix regex in check43
2021-01-14 13:38:33 +03:00
C.J
be3e771454
Check for errors generating credential report, limit loop iterations
2021-01-14 04:41:16 -05:00
Toni de la Fuente
f5b26387f0
Clear AWS_DEFAULT_OUTPUT on start @zfLQ2qx2
...
Clear AWS_DEFAULT_OUTPUT on start @zfLQ2qx2
2021-01-14 10:19:07 +01:00
C.J
ed0f01b617
Clear AWS_DEFAULT_OUTPUT on start
2021-01-14 04:01:40 -05:00
Toni de la Fuente
d047cd807a
Fix check extra73 fail message omits bucket name @zfLQ2qx2
...
Fix check extra73 fail message omits bucket name @zfLQ2qx2
2021-01-14 09:28:44 +01:00
C.J
6a9a47e549
Fix for issue 713
2021-01-13 19:16:48 -05:00
Toni de la Fuente
6cbee3b16c
Fix log metric filter check3x with multiple trails @bridgecrewio
...
Fix log metric filter check3x with multiple trails @bridgecrewio
2021-01-13 23:08:17 +01:00
Toni de la Fuente
a53aeff0e8
Catch errors assuming role and describing regions @zfLQ2qx2
...
Catch errors assuming role and describing regions @zfLQ2qx2
2021-01-13 22:50:11 +01:00
Toni de la Fuente
81787d1946
Add check for AccessDenied when calling GetBucketLocation in extra73,extra734,extra764 @zfLQ2qx2
...
Add check for AccessDenied when calling GetBucketLocation in extra73,extra734,extra764 @zfLQ2qx2
2021-01-13 22:35:20 +01:00
Toni de la Fuente
b23f9b3b5d
Fix changes made in check27
2021-01-13 22:21:45 +01:00
Toni de la Fuente
51d6fc99ed
Handle shadow CloudTrails more gracefully in checks check21,check22,check24,check27 @zfLQ2qx2
...
Handle shadow CloudTrails more gracefully in checks check21,check22,check24,check27 @zfLQ2qx2
2021-01-13 21:35:07 +01:00
Toni de la Fuente
0d4988b874
Additional check for location of awscli @zfLQ2qx2
...
Additional check for location of awscli @zfLQ2qx2
2021-01-13 21:25:04 +01:00
Toni de la Fuente
17c0409d35
Fix date command for busybox @zfLQ2qx2
...
Fix date command for busybox @zfLQ2qx2
2021-01-13 21:19:07 +01:00
C.J
1d9c1eaece
Catch errors assuming role and describing regions
2021-01-13 09:44:15 -05:00
Toni de la Fuente
d77f1ea651
Add new check extra7131 RDS minor version upgrade
2021-01-13 12:58:23 +01:00
Toni de la Fuente
2bc3fcf7ee
Add new check extra7131 RDS minor version upgrade
2021-01-13 12:57:08 +01:00
Toni de la Fuente
bcdd12bf84
Add new check extra7131 RDS minor version upgrade
2021-01-13 12:51:49 +01:00
C.J
733c99c1e0
Add check for AccessDenied when calling GetBucetLocation
2021-01-12 15:38:47 -05:00
C.J
ecc08722e1
Handle shadow cloudtrails more gracefully
2021-01-12 13:37:30 -05:00
C.J
f53a32ae26
Additional check for location of awscli
2021-01-12 11:03:30 -05:00
C.J
bf1bd505c5
Fix for busybox date command
2021-01-12 09:11:52 -05:00
Toni de la Fuente
eac59cade8
Add new check extra_7130 to check encryption of a SNS topic @mpratsch
...
Add new check extra_7130 to check encryption of a SNS topic @mpratsch
2021-01-08 13:54:55 +01:00
Martina Rath
994abe8fa3
Add check7130 to group7_extras and fix some issues
2021-01-08 13:43:46 +01:00
Toni de la Fuente
6ad1816e37
Fix EKS related checks regarding us-west-1 @njgibbon
...
Fix EKS related checks regarding us-west-1 @njgibbon
2021-01-07 19:29:22 +01:00
Toni de la Fuente
20b8b1eb1f
Enhance check extra792 to accept current most restrictive TLSv1.2 @bazbremner
...
Enhance check extra792 to accept current most restrictive TLSv1.2 @bazbremner
2021-01-07 19:22:20 +01:00
Martina Rath
9a060a3c43
Add new extras check (7130) to check encryption of a SNS topic
2020-12-30 08:46:13 +01:00
Barrie Bremner
75e5de9c37
Accept current most restrictive TLSv1.2-only ALB security policy as secure
...
The `ELBSecurityPolicy-FS-1-2-Res-2020-10` policy is the most
restrictive TLS v1.2 only SSL/TLS security policy available, and is a
subset of the already accepted `ELBSecurityPolicy-FS-1-2-Res-2019-08`
policy - this commit adds `ELBSecurityPolicy-FS-1-2-Res-2020-10` to
the list of acceptable "secure" security policies.
`ELBSecurityPolicy-FS-1-2-Res-2020-10` has a very limited set of
ciphers, is TLS v1.2 only and supports Forward Secrecy.
Current SSL Labs tests gives it an "A" rating for another source of
confirmation.
2020-12-24 16:52:01 +00:00
njgibbon
4adc7f5864
feat - fix - taking out eks check condition because california region
2020-12-24 00:00:06 +00:00
Toni de la Fuente
0ddb045ca2
Update README.md
2020-12-18 15:27:59 +01:00
Toni de la Fuente
297eeea783
Label version 2.3.0-18122020
2020-12-18 13:09:47 +01:00
Toni de la Fuente
d540cefc23
Fix FreeBSD $OSTYPE check @ring-pete
...
Fix FreeBSD $OSTYPE check @ring-pete
2020-12-18 10:24:48 +01:00
Toni de la Fuente
953bdf3034
Merge branch 'master' into master
2020-12-18 10:24:25 +01:00
Toni de la Fuente
823c7d4b61
Enhanced check extra740: reworked to consider all snapshots, use JMESPath query @pacohope
...
Enhanced check extra740: reworked to consider all snapshots, use JMESPath query
2020-12-18 10:17:52 +01:00
Toni de la Fuente
e298158bcd
Enhanced error handling without credentials
2020-12-17 17:15:17 +01:00
Toni de la Fuente
810801fb3d
Fix error handling for SubscriptionRequiredException in extra77
2020-12-17 16:52:18 +01:00
Toni de la Fuente
91ce905a5a
Fix issue assuming role in regions with STS disabled
2020-12-17 16:34:10 +01:00
Toni de la Fuente
6ed6a47f8f
Add sleep to extra7102 to avoid Shodan API limits
2020-12-17 15:27:00 +01:00
Toni de la Fuente
347872a6de
Refresh assumed role credentials to avoid role chaining limitations @michael-dickinson-sainsburys
...
Refresh assumed role credentials to avoid role chaining limitations @michael-dickinson-sainsburys
2020-12-17 15:24:06 +01:00
Toni de la Fuente
8c19583ac7
Update prowler
...
Adapted execute_check to renew creds
2020-12-17 15:21:50 +01:00
Toni de la Fuente
5c620949f0
Update os_detector
...
Change above is because epoch time generator in BSD is 1h less than in Linux
2020-12-17 15:20:20 +01:00
Toni de la Fuente
5be38a15d9
Update os_detector bsd_convert_date_to_timestamp
2020-12-17 10:24:25 +01:00
Toni de la Fuente
5e38c61286
Refresh assumed role credentials to avoid role chaining limitations @michael-dickinson-sainsburys
...
Refresh assumed role credentials to avoid role chaining limitations @michael-dickinson-sainsburys
2020-12-16 20:04:21 +00:00
Toni de la Fuente
de3e2c3a2b
Added support to run inside AWS CloudShell
2020-12-16 13:41:54 +01:00
Toni de la Fuente
687cfd0a34
Merge pull request #709 from toniblyx/revert-694-master
...
Revert "Refresh assumed role credentials to avoid role chaining limitations"
2020-12-15 17:38:00 +01:00
Toni de la Fuente
aa0440e426
Revert "Refresh assumed role credentials to avoid role chaining limitations"
2020-12-15 17:37:42 +01:00
Toni de la Fuente
31182059e4
Refresh assumed role credentials to avoid role chaining limitations @michael-dickinson-sainsburys
...
Refresh assumed role credentials to avoid role chaining limitations @michael-dickinson-sainsburys
2020-12-15 17:29:11 +01:00
Toni de la Fuente
e047dc8764
Added latest checks to extras group
2020-12-15 15:10:33 +01:00
Toni de la Fuente
7f1df739c4
Added -N <shodan_api_key> support for extra7102
2020-12-15 12:25:47 +01:00
Toni de la Fuente
9ed576b09d
Fix issue in extra776 when ECR Scanning imageDigest @adamcanzuk
...
Fix issue in extra776 when ECR Scanning imageDigest @adamcanzuk
2020-12-14 12:59:19 +01:00
Paco Hope
f3dbecbe89
reworked check740 to consider all snapshots, use JMESPath query, and to limit its output according to max-items
2020-12-10 09:27:43 -05:00
Toni de la Fuente
3d62aedf29
New RC6 including ENS as a new compliance type all formats
2020-12-01 10:03:59 +01:00
Toni de la Fuente
30937c3275
Updated ENS group with new checks
2020-12-01 09:56:08 +01:00
Toni de la Fuente
63040e1c07
New 7 checks required for ENS
2020-12-01 09:55:20 +01:00
Michael Dickinson
30eb447919
docs: Update Organizations command to only incude active accounts
2020-11-23 21:05:27 +00:00
Michael Dickinson
5da54467b5
fix: Refresh assumed role credentials if session is nearing expiration
2020-11-23 21:05:20 +00:00
Michael Dickinson
8ab91e9f8e
fix: Store assumed role expiry time for later checking
2020-11-23 21:05:11 +00:00
mikeurbanski1
4fddb7fa63
Fix log metric filter checks ( #33 )
...
* debug statements for issue demonstration
* use separate array elements
* add debug and comments
* clean up debug statements
2020-11-23 09:26:44 -06:00
Pete Wright
65bbdfdd83
Fix FreeBSD $OSTYPE check
...
As per this bug report:
https://github.com/toniblyx/prowler/issues/693
Add detection for freebsd releases which should be similar to darwin
in that it will use GNU coreutils for date and base64.
2020-11-20 13:29:21 -08:00
nikirby
013b106564
Merge branch 'master' of github.com:Kirizan/prowler
2020-11-20 15:22:31 -05:00
nikirby
fa72e7c21f
Ensures JSON is the default AWS command output.
2020-11-20 15:16:22 -05:00
Toni de la Fuente
25a04cd59e
Merge branch 'master' of https://github.com/toniblyx/prowler into master
2020-11-20 15:07:48 +01:00
Toni de la Fuente
72303ea126
Fixed syntax typo
2020-11-20 15:04:47 +01:00
Toni de la Fuente
600a7c9f2f
Adapt check119 to exclude instances shutting down @stku1985
...
Adapt check119 to exclude instances shutting down @stku1985
2020-11-18 15:30:57 +01:00
Toni de la Fuente
53e95ac9f3
Improved CodeBuild CFN template with scheduler and documentation
2020-11-18 15:12:44 +01:00
Toni de la Fuente
1f6931a591
Merge branch 'master' of https://github.com/toniblyx/prowler into master
2020-11-18 14:48:47 +01:00
Toni de la Fuente
fdc8c1ce36
Added session durantion option to 12h
2020-11-18 14:48:34 +01:00
Toni de la Fuente
a8fed14cea
Fixed extra7116 extra7117 outputs and added to extras @ramondiez
...
Fixed extra7116 extra7117 outputs and added to extras @ramondiez
2020-11-18 13:41:12 +01:00
Toni de la Fuente
f3d4cc8514
Fixed extra7116 extra7117 outputs and added to extras
2020-11-18 13:31:20 +01:00
Stefan Kunkel
7397126794
adapt check119 to exclude instances shutting down
...
brain fart: used logical 'or' instead of correct '&&'
2020-11-18 13:25:28 +01:00
Toni de la Fuente
11bf35d993
Enhancement check119 to exclude instances shutting-down @stku1985
...
Enhancement check119 to exclude instances shutting-down in addition to terminated ones
2020-11-18 13:21:52 +01:00
Stefan Kunkel
147fac0777
adapt check119 to exclude instances shutting down
2020-11-18 13:20:55 +01:00
Ramon Diez
49423dee4a
fixing check_extra7116 and check_extra7117
2020-11-18 12:42:01 +01:00
Toni de la Fuente
345a8d48c4
Added group for ENS - Spanish Esquema Nacional de Seguridad
2020-11-18 11:45:07 +01:00
Toni de la Fuente
1576f2ba39
Added start build automatically
2020-11-16 20:15:41 +01:00
Toni de la Fuente
0bd1fefd7d
Glue checks additional @dlpzx
...
Glue checks additional @dlpzx
2020-11-16 18:32:09 +01:00
Toni de la Fuente
c2a2e393cb
Merge branch 'master' into dlpzx-master
2020-11-16 18:31:18 +01:00
Toni de la Fuente
7cd1413c93
Glue grup 2 corrections
2020-11-16 18:29:16 +01:00
Toni de la Fuente
9c39f69210
Glue checks part 1 @ramondiez
...
Glue checks part 1 @ramondiez
2020-11-16 17:55:50 +01:00
Toni de la Fuente
6e604e1834
Some corrections for glue related checks
2020-11-16 17:51:53 +01:00
Toni de la Fuente
b702990ea6
Fix: Security Hub eventual consistency + PREFIX query bug + Archive PASSED @xeroxnir
...
Fix: Security Hub eventual consistency + PREFIX query bug + Archive PASSED
2020-11-13 19:16:58 +01:00
Toni de la Fuente
594215661d
Fix for check_extra764 @grzegorznittner
...
Fix for check_extra764 fix #680
2020-11-13 19:10:41 +01:00
Toni de la Fuente
b32538b7e5
Glue review 2
2020-11-13 19:05:19 +01:00
Toni de la Fuente
8c9d843813
Glue review 1
2020-11-13 19:02:26 +01:00
Toni de la Fuente
c934e788b7
Center logo in html report
2020-11-13 18:22:09 +01:00
Grzegorz Nittner
c9ca8d48b1
#680 - fix for check_extra764
2020-11-13 14:56:22 +00:00
Joaquin Rinaudo
f6d17ba6e0
fix(securityhub): consistency + prefix bug + PASSED
...
fix(securityhub): consistency + prefix bug + PASSED
2020-11-12 21:48:21 +01:00
Ramon Diez
0bfa263ad9
Fixing some descriptions
2020-11-12 12:30:22 +01:00
dlpzx
943b096f35
checks for glue - 7119, 7121, 7123
2020-11-12 12:06:43 +01:00
dlpzx
888133e986
checks for glue - 7119, 7121, 7123,7124,7125
2020-11-10 13:06:03 +01:00
dlpzx
39a7c3b18e
checks for glue - 7119, 7121, 7123,7124,7125
2020-11-10 13:05:22 +01:00
dlpzx
ebe2594456
checks for glue - 7119, 7121, 7123,7124,7125
2020-11-09 19:17:00 +01:00
dlpzx
e0a8e0f318
checks for glue - 7119, 7121, 7123,7124,7125
2020-11-09 18:48:11 +01:00
Toni de la Fuente
7dbed63143
Added CodeBuild deployment section
2020-11-05 21:49:05 +01:00
Toni de la Fuente
2304d14f28
Added CodeBuild template - original from @stevecjones
2020-11-05 00:35:05 +01:00
Ramon Diez
954848c6e8
Glue checks part 1
2020-11-04 10:44:43 +01:00
Toni de la Fuente
97055e84b4
Fix quotes in check extra78 for public RDS instances @goldfiglabs
...
Fix quotes in check extra78 for public RDS instances @goldfiglabs
2020-11-03 23:31:44 +01:00
Toni de la Fuente
6188021e63
Adding fix to generate test summary so reports display graphs correctly @stevecjones
...
Adding fix to generate test summary so reports display graphs correctly @stevecjones
2020-11-03 21:14:05 +01:00
dlpzx
65c63d5bdd
checks for glue - 7119,7121,7123,7124. 7125 not done yet
2020-11-03 19:18:40 +01:00
Toni de la Fuente
180f12d625
Fix extra7111 parser error
2020-11-03 13:48:39 +01:00
Toni de la Fuente
62fcbf2f05
Fix extra7103 parser error
2020-11-03 13:44:24 +01:00
Toni de la Fuente
3844c2151b
Merge branch 'master' of https://github.com/toniblyx/prowler into master
2020-11-03 13:34:05 +01:00
Toni de la Fuente
5d4648c812
Fix extra7108 parser error
2020-11-03 13:33:51 +01:00
Stephen Jones
e7f837eb7b
Correct typo and simplify count
2020-11-03 22:45:27 +11:00
Toni de la Fuente
f0949f6ec6
Enable Security Hub official integration and version 2.3.0RC5 @toniblyx
...
Enable Security Hub official integration and version 2.3.0RC5 @toniblyx
2020-10-30 19:36:45 +01:00
Stephen Jones
87f91cf467
Removing gnarly code and add refined counters for summary metrics in output
2020-10-30 22:51:11 +11:00
Toni de la Fuente
ae1d7be7f2
Enable Security Hub official integration
2020-10-29 22:40:38 +01:00
Greg Soltis
7585ad7d57
Fix check for public rds instances
2020-10-26 11:39:37 -07:00
Stephen Jones
2756f16c87
Adding fix to generate test summary so reports display graphs correctly
2020-10-22 02:15:15 +11:00
Toni de la Fuente
d6760f15b7
fix extra7110 title
2020-10-20 13:30:26 +02:00
Toni de la Fuente
b8e1ef6b33
Fix check_extra7107 condition
2020-10-20 13:20:15 +02:00
Toni de la Fuente
79808fbe30
Fix syntax in extra7110
2020-10-20 09:29:30 +02:00
Toni de la Fuente
c34535f585
Fix report metadata in html output
2020-10-15 22:01:28 +02:00
Toni de la Fuente
fa925bdef2
Fix account id in output file name
2020-10-15 21:56:44 +02:00
Toni de la Fuente
a05aba84e1
Added GovCloud usage information
2020-10-14 22:29:51 +02:00
Toni de la Fuente
19b894c14b
Added extra7113: Check RDS instances deletion protection @gchib297
...
Added extra7113: Check RDS instances deletion protection @gchib297
2020-10-08 22:46:31 +02:00
gchib
23df3dd8d0
Add extra7113: Check RDS deletion protection
2020-10-08 17:21:26 +05:30
gchib
5994700c09
Add check extra7113
2020-10-08 17:19:58 +05:30
gchib
ba7c3a3124
Add extra7113: Check RDS deletion protection
2020-10-08 17:18:56 +05:30
Toni de la Fuente
b512585d80
Added all new Sagemaker checks to extras
2020-10-06 16:43:21 +02:00
Toni de la Fuente
645ea25ddc
New group for Sagemaker with 10 new controls
2020-10-06 16:40:19 +02:00
Toni de la Fuente
923267c3e5
extra7102 increased severity to medium
2020-10-06 16:39:39 +02:00
Toni de la Fuente
2fb9588883
Add extra7102 to groups extras and internetexposed
2020-10-02 19:14:37 +02:00
Toni de la Fuente
ffcb6a0b69
Added extra7102 ElasticIP Shodan integration
2020-10-02 19:10:00 +02:00
Toni de la Fuente
ad45035ad3
Updated README.md
2020-09-30 23:43:48 +02:00
Toni de la Fuente
62a87d961c
Add SOC2 compliance group @gchib297
...
Add SOC2 compliance group @gchib297
2020-09-30 22:59:51 +02:00
Toni de la Fuente
6aa8dd643d
Add check extra798 to gdpr and pci groups @gchib297
...
Add check extra798 to gdpr and pci groups @gchib297
2020-09-30 22:58:28 +02:00
Toni de la Fuente
f674868dd9
Add check extra798 to iso27001 @gchib297
...
Add check extra798 to iso27001 @gchib297
2020-09-30 22:57:35 +02:00
Toni de la Fuente
859951a63c
Add FFIEC cybersecurity assessment group @gchib297
...
Add FFIEC cybersecurity assessment group @gchib297
2020-09-30 22:56:37 +02:00
gchib
a3a71f499c
Add SOC2 compliance group
2020-09-30 17:44:19 +05:30
gchib
cf62f2bb05
Add check extra798 to PCI
2020-09-30 17:36:20 +05:30
gchib
dd05575508
Add check extra798 to GDPR
2020-09-30 17:33:41 +05:30
gchib
ff19182cf1
Add check extra798 to iso27001
2020-09-30 17:19:06 +05:30
gchib
58c4af98d1
Add FFIEC group
...
Add FFIEC Cybersecurity assessment checks
2020-09-30 17:10:56 +05:30
Toni de la Fuente
8e1fac1b7c
Added checks about EKS to groups internet-exposed and forensics
2020-09-28 09:41:40 +02:00
Toni de la Fuente
d620754bae
Added extra796 EKS control plane access to internet-exposed group
2020-09-28 09:36:04 +02:00
Toni de la Fuente
cf926e6f5a
Added coreutils to Dockerfile
2020-09-24 14:58:10 +02:00
Toni de la Fuente
60c741a202
Merge branch 'master' of https://github.com/toniblyx/prowler into master
2020-09-24 14:55:20 +02:00
Toni de la Fuente
c14799915c
Fix issue #659
2020-09-24 14:55:10 +02:00
Toni de la Fuente
9165d3a8ba
Fix SecurityHub: other os/check fixes + batch in 100 findings @xeroxnir
...
fix(securityhub): other os/check fixes + batch in 100 findings
2020-09-24 10:29:04 +02:00
Joaquin Rinaudo
321401f755
fix(securityhub): other os/check fixes + batch in 100 findings
2020-09-24 09:34:09 +02:00
Toni de la Fuente
5182403041
Improved documentation about SecurityHub integration and region filter
2020-09-23 15:30:08 +02:00
Toni de la Fuente
4d9473881f
Fixed title id for eks-cis
2020-09-18 18:47:14 +02:00
Toni de la Fuente
88e67cc42d
Merge branch 'master' of https://github.com/toniblyx/prowler into master
2020-09-18 18:44:11 +02:00
Toni de la Fuente
0f84181d89
Added new check [extra7101] Check if Amazon Elasticsearch Service (ES) domains have audit logging enabled
2020-09-18 18:44:01 +02:00
Toni de la Fuente
4c0dd42214
Fix security-hub integration: Race condition timestamp xeroxnir
...
Fix(security-hub): Race condition timestamp
2020-09-18 18:19:50 +02:00
Joaquin Rinaudo
660bbf5676
fix(security-hub): race condition timestamp
2020-09-18 18:14:05 +02:00
Toni de la Fuente
a9b946b4e6
Merge branch 'master' of https://github.com/toniblyx/prowler into master
2020-09-18 15:29:12 +02:00
Toni de la Fuente
903840970b
Merge pull request #657 from xeroxnir/master
...
Security Hub: Bugfix missing ","
2020-09-18 15:28:18 +02:00
Joaquin Rinaudo
65638af6a1
bugfix(securityhub): missing ,
2020-09-18 15:25:51 +02:00
Toni de la Fuente
a6bd8a59bf
Security Hub: Mark as ARCHIVED + fix race condition @xeroxnir
...
Security Hub: Mark as ARCHIVED + fix race condition @xeroxnir
2020-09-18 15:19:12 +02:00
Joaquin Rinaudo
09212add77
fix(debug): resolveSecurityHubPreviousFails
2020-09-18 15:09:38 +02:00
Joaquin Rinaudo
b7c1823ec9
fix(securityhub): add RecordState outputs
2020-09-18 14:59:28 +02:00
Joaquin Rinaudo
c1b09b6b9d
bugfix(securityhub): race condition fix
2020-09-18 14:52:32 +02:00
Joaquin Rinaudo
0f3e6ee90b
feature(security-hub): archive finding instead of mark as PASSED
2020-09-18 14:07:00 +02:00
Toni de la Fuente
70aed72aff
Added parameters and made the template parameterised @pacohope
...
Added parameters and made the template parameterised @pacohope
2020-09-18 11:57:35 +02:00
Paco Hope
d012342422
added parameters and made the template parameterised.
2020-09-17 12:06:33 -04:00
Toni de la Fuente
7bfeebe2a2
Title adjustments for internetexposed iso27001 and eks-cis groups
2020-09-17 16:51:48 +02:00
Toni de la Fuente
448f506882
Merge pull request #654 from marcjay/patch-1
...
Add GetFindings action to example IAM policy for Security Hub
2020-09-17 09:39:45 +02:00
Marc Jay
7e2110dc4e
Add GetFindings action to example IAM policy for Security Hub
...
Following the merge of #651 , prowler now calls the GetFindings API when using Security Hub integration - this action needs to be added to the required policy
2020-09-17 01:37:45 +01:00
Toni de la Fuente
0dc4c316a2
Merge branch 'master' of https://github.com/toniblyx/prowler into master
2020-09-16 23:32:28 +02:00
Toni de la Fuente
392da158e7
Labeled 2.3.0RC4, time for a final GA version...
2020-09-16 23:32:13 +02:00
Toni de la Fuente
ac0d90cee7
Whitelist feature improvements @QuinnStevens
...
Whitelist feature improvements @QuinnStevens
2020-09-16 23:28:40 +02:00
Toni de la Fuente
d66a8d0ac6
Fix execute_group_by_id @xeroxnir
...
Fix execute_group_by_id @xeroxnir
2020-09-16 23:26:33 +02:00
Toni de la Fuente
7eff48715c
Security Hub integration improvement and adding severity for checks @xeroxnir
...
Security Hub integration improvement and adding severity for checks @xeroxnir
2020-09-16 23:19:06 +02:00
Toni de la Fuente
66a9525d23
Support custom folder checks when running all checks @xeroxnir
...
Support custom folder checks when running all checks @xeroxnir
2020-09-16 23:13:24 +02:00
Toni de la Fuente
7e9a5dc8f5
Allow list checks and groups without credentials
2020-09-16 23:11:33 +02:00
Joaquin Rinaudo
24c80c8548
Fix: If is never called (also under execute_check)
2020-09-07 16:33:45 +02:00
Joaquin Rinaudo
e1fb89838a
Fix execute_group_by_id
...
* All other group checks for IAM have no credential report.
* ${GROUP_ID[$1]} is invalid as first parameter is group_id
2020-09-07 16:09:10 +02:00
Joaquin Rinaudo
69609b08c2
Fix: Json output
2020-09-07 14:26:02 +02:00
Quinn Stevens
801be49523
Return default behaviour to previous, remove distinction between strict & non-strict matching
2020-09-04 13:20:21 +01:00
Quinn Stevens
28b3604b1c
Improve whitelisting to allow regexes and fuzzy/strict matching
2020-09-04 13:19:00 +01:00
Joaquin Rinaudo
7b634de36b
Update securityhub_integration
2020-09-03 16:57:59 +02:00
Joaquin Rinaudo
981497e0e2
Update securityhub_integration
2020-09-03 16:55:07 +02:00
Joaquin Rinaudo
ebf5d5f449
Update securityhub_integration
2020-09-03 16:53:26 +02:00
Joaquin Rinaudo
054e296501
Update outputs
2020-09-03 15:32:46 +02:00
Joaquin Rinaudo
f642926f50
fix(severity): missing check
2020-09-03 08:23:17 +02:00
Joaquin Rinaudo
e93bb654f8
cleanup outputs
2020-09-03 08:09:52 +02:00
Joaquin Rinaudo
dce3cb0ead
cleanup: working
2020-09-03 08:08:11 +02:00
Joaquin Rinaudo
0f3994a135
fix(error-handling): security-hub
2020-09-03 08:05:49 +02:00
Joaquin Rinaudo
ecbe997084
severity+security_hub
2020-09-03 08:04:13 +02:00
Joaquin Rinaudo
20decaafd5
fix(security_hub): remove echo
2020-09-02 12:05:39 +02:00
Joaquin Rinaudo
c53804a3eb
fixes(security_hub): missing region and rename variables
2020-09-02 12:04:24 +02:00
Joaquin Rinaudo
bed61c9ee7
remove comment
2020-09-01 17:08:47 +02:00
Joaquin Rinaudo
ea914e47d7
remove debug statements
2020-09-01 17:07:53 +02:00
Joaquin Rinaudo
ae4940a7d8
revert-custom-branch
2020-09-01 17:05:37 +02:00
Joaquin Rinaudo
ebc3c4d4e4
WIP remove comments
2020-09-01 17:04:30 +02:00
Joaquin Rinaudo
2a4cebaa1e
WIP: security hub integration
2020-09-01 17:03:25 +02:00
Joaquin Rinaudo
6c0e1a13e3
feature: Only when custom checks are set
2020-09-01 16:36:07 +02:00
Joaquin Rinaudo
0eab753620
feature: Execute custom checks in execute_all
2020-09-01 16:34:19 +02:00
Joaquin Rinaudo
118ff0819e
Merge branch 'master' of github.com:xeroxnir/prowler
2020-09-01 16:32:34 +02:00
Joaquin Rinaudo
9baa6d6ae9
revert: master
2020-09-01 16:26:16 +02:00
Joaquin Rinaudo
43f3365bb4
revert: master
2020-09-01 16:22:32 +02:00
Joaquin Rinaudo
580523fde4
fix(all_checks): also run custom folder
2020-09-01 16:17:19 +02:00
Toni de la Fuente
2186f648c8
Ensure that checks are sorted numerically when listing checks @marcjay
...
Ensure that checks are sorted numerically when listing checks @marcjay
2020-09-01 09:13:04 +02:00
Marc Jay
e3ecee83af
Ensure that checks are sorted numerically when listing checks
...
Sort first by section, then by check within each section
Fix group IDs in documentation
Relates to #545 and #561
2020-09-01 00:21:48 +01:00
Joaquin Rinaudo
17e74a355f
Merge branch 'master' of https://github.com/toniblyx/prowler
2020-08-28 07:13:16 +02:00
Joaquin Rinaudo
9283fb59b4
Merge branch 'master' of github.com:xeroxnir/prowler
2020-08-27 17:09:16 +02:00
Joaquin Rinaudo
c65fc3b989
fix(security-hub): unique finding id, if status not changed, comment otherwise resolve older findings
2020-08-27 17:08:37 +02:00
Toni de la Fuente
7f03ef0e7e
Adding back extra798
2020-08-27 16:50:48 +02:00
Toni de la Fuente
1496e3ab60
New check 7.98 [extra798] Ensure that no custom policies exist which allow permissive role assumption (e.g. sts:AssumeRole on *) @nickmalcolm
...
New check 7.98 [extra798] Ensure that no custom policies exist which allow permissive role assumption (e.g. sts:AssumeRole on *) @nickmalcolm
2020-08-27 16:31:18 +02:00
Toni de la Fuente
36a291c4a9
Rename check_extra798 to check_extra7100
2020-08-27 16:30:20 +02:00
Toni de la Fuente
0b9d3e39d4
Merge branch 'master' into master
2020-08-27 16:28:35 +02:00
Toni de la Fuente
1d4563f60d
Added extra799 and extra7100 to group extras
...
Added extra799 and extra7100 to group extras
2020-08-27 16:23:08 +02:00
Toni de la Fuente
565edf7b4b
Change check ID to extra7100
...
Change check ID to extra7100
2020-08-27 16:21:56 +02:00
Toni de la Fuente
5552ea1eb6
Fix getops OPTARG for custom checks @xeroxnir
...
Fix getops OPTARG for custom checks @xeroxnir
2020-08-27 16:12:59 +02:00
Joaquin Rinaudo
7868904c3b
Fix getops OPTARG for custom checks
...
Custom checks in folder are not being sourced. `./prowler -c extra800 -x custom` results in empty EXTERNAL_CHECKS_PATH variables due to missing colon.
The fix was tested in both OSX and toniblyx/prowler:latest Docker.
Regards,
2020-08-26 23:59:02 +02:00
Toni de la Fuente
9647d80fc1
Fix check12 when MFA is enabled and user contains true in the name @xeroxnir
...
Fix check12 when MFA is enabled and user contains true in the name @xeroxnir
2020-08-26 18:41:51 +02:00
Toni de la Fuente
89db9d4b70
Update check12
2020-08-26 18:40:11 +02:00
Toni de la Fuente
553faf72ec
Added [extra736] Check exposed KMS keys to group internet-exposed
2020-08-26 16:57:20 +02:00
Toni de la Fuente
33a53663db
Added [extra799] Check if Security Hub is enabled and its standard subscriptions
2020-08-25 19:54:57 +02:00
Toni de la Fuente
ca471700c2
Added [extra798] Check if Lambda functions have resource-based policy set as Public
2020-08-25 19:06:06 +02:00
Toni de la Fuente
03b1d898a6
Added AWS partition variable to the ASFF output format
2020-08-25 16:54:22 +02:00
Toni de la Fuente
97e6a80bdc
Added AWS partition variable to the ASFF output format
2020-08-25 16:49:20 +02:00
Joaquin Rinaudo
024190dd8a
[Check12] Bugfix: Remove $ from grep
...
Check is failing to detect users without MFA, solved by removing `$` sign addresses the issue.
2020-08-21 10:35:50 +02:00
Nick Malcolm
ba87f437d5
This check will identify IAM Policies which allow an IAM Principal (a Role or User) to escalate their privileges due to insecure STS permissions. It is AWS best practice to only use explicitly defined Resources (Role ARNs) for an sts:AssumeRole action.
...
See more: https://docs.aws.amazon.com/IAM/latest/UserGuide/id_roles_use_permissions-to-switch.html#roles-usingrole-createpolicy
2020-08-20 21:08:00 +12:00
Toni de la Fuente
cd0b5d29dd
Added html to -M in usage
2020-08-18 11:59:53 +02:00
Toni de la Fuente
c1992ef2a7
Added html to -M in usage
2020-08-18 11:52:49 +02:00
Toni de la Fuente
7aa0864bd2
Adding EKS checks to eks-cis and extras group @jonjozwiak
...
Adding EKS checks to eks-cis and extras group @jonjozwiak
2020-08-05 19:03:55 +02:00
Jon Jozwiak
022df45ae1
Adding EKS checks to eks-cis and extras group
2020-08-03 08:02:21 -05:00
Toni de la Fuente
f5ec2bceda
Adding 4 new EKS checks @jonjozwiak
...
Adding 4 new EKS checks @jonjozwiak
2020-07-31 21:40:38 +02:00
Toni de la Fuente
85efe3e342
Fixed extra737 now doesn't fail for keys scheduled for deletion @QuinnStevens
...
Fixed extra737 now doesn't fail for keys scheduled for deletion @QuinnStevens
2020-07-31 21:33:06 +02:00
Quinn Stevens
93c89530ff
Explicitly set output --json for aws call
2020-07-31 20:30:20 +01:00
Toni de la Fuente
4a02d54ec1
Add additional GDPR checks to GDPR group @gchib297
...
Add additional GDPR checks to GDPR group @gchib297
2020-07-31 21:15:30 +02:00
jonjozwiak
a2c92c2e7b
Adding 4 EKS checks
2020-07-31 10:42:16 -05:00
gchib
04fae53da5
Add additional GDPR checks
...
Added checks:
check11,check110,check111,check112,check116,check120,check122,check13,check14,check15,check16,check17,check18,check19,check28,check29,check31,check310,check311,check312,check313,check314,check32,check33,check34,check36,check37,check38,check41,check42,extra711,extra72,extra723,extra730,extra739,extra76,extra763,extra778,extra78,extra792
2020-07-24 22:26:09 +05:30
Toni de la Fuente
43d95ac18c
Set version label PROWLER_VERSION=2.3.0RC3
2020-07-24 15:22:28 +02:00
Toni de la Fuente
19c68980fe
fix typo on title group18
2020-07-24 15:18:46 +02:00
Toni de la Fuente
19bd281c78
Added group18 for ISO27001 thanks to @gchib297 issue #637
2020-07-24 15:16:35 +02:00
Toni de la Fuente
9eb6a6d1fe
Add additional checks to HIPAA group @gchib297
...
Add additional checks to HIPAA group @gchib297
2020-07-24 14:58:29 +02:00
Quinn Stevens
e58d8cbc8d
Don't fail check extra737 for keys scheduled for deletion
2020-07-24 12:44:57 +01:00
gchib
a8026ba3c3
Add additional HIPAA checks
...
Added checks:
check112,check13,check15,check16,check17,check18,check19,check21,check24,check28,check31,check310,check311,check312,check313,check314,check32,check33,check34,check35,check36,check37,check39,extra792.
2020-07-23 19:10:17 +05:30
Toni de la Fuente
9b1c152607
New check extra793 for SSL listeners on load balancers @jonjozwiak
...
New check extra793 for SSL listeners on load balancers
2020-07-21 16:57:20 +02:00
jonjozwiak
6ba9be46fb
Adding check for SSL load balancers
2020-07-17 09:59:53 -05:00
Toni de la Fuente
b3a2f850cf
extra792 - skip check if no HTTPS/SSL Listener plus add NLB Support @jonjozwiak
...
extra792 - skip check if no HTTPS/SSL Listener plus add NLB Support
2020-07-17 11:48:28 +02:00
jonjozwiak
1c970b0387
extra792 skip check if no HTTPS/SSL Listener and add NLB support
2020-07-16 16:08:33 -05:00
Toni de la Fuente
206b675179
Added group for pci-dss as reference
2020-07-13 17:33:07 +02:00
Toni de la Fuente
c3c5971ff2
Fix listing configurations if default output format is not JSON check119,extra742,extra75 and extra772 @anthirian
...
Fix listing configurations if default output format is not JSON
2020-07-08 15:48:05 +02:00
Toni de la Fuente
1fefc11d8e
CFN template helper for role
2020-06-29 15:06:54 +02:00
Toni de la Fuente
9732e5be70
Reduce needed actions in additions policy @
2020-06-29 13:59:19 +02:00
Geert Smelt
d3553b642e
Fix listing Elastic IPs if default output format is not JSON
2020-06-26 12:50:09 +02:00
Geert Smelt
63d06212db
Fix listing CloudFormation stacks if default output format is not JSON
2020-06-26 11:55:12 +02:00
Geert Smelt
a0c58e1cb2
Fix listing EC2 Security Groups if default output format is not JSON
2020-06-26 11:25:16 +02:00
Geert Smelt
0878511abf
Fix listing EC2 instances if default output format is not JSON
2020-06-26 11:16:59 +02:00
Toni de la Fuente
01be8520b9
Merge branch 'master' of https://github.com/toniblyx/prowler
2020-06-25 15:16:14 +02:00
Toni de la Fuente
9e9535def8
Delete _config.yml
2020-06-25 15:15:59 +02:00
Toni de la Fuente
64a617d26d
delete _config.yml
2020-06-25 15:15:14 +02:00
Toni de la Fuente
4a593df142
Merge branch 'master' of https://github.com/toniblyx/prowler
2020-06-25 15:13:47 +02:00
Toni de la Fuente
8686547ebb
Allow list All findings in single view in html report
2020-06-25 15:03:45 +02:00
Toni de la Fuente
6acde2c843
Set theme jekyll-theme-hacker
2020-06-23 20:18:33 +02:00
Toni de la Fuente
facc2a7b30
Added script to generate html report from multiple csv outputs
2020-06-23 20:08:12 +02:00
Toni de la Fuente
dac24b3aa8
Fix issue #624 ID of check_extra792
2020-06-23 19:34:41 +02:00
Toni de la Fuente
84060db013
Added group internet-exposed
2020-06-16 18:01:14 +02:00
Toni de la Fuente
2d927f333a
Fixed profile and region settings for extra792 - ELB SSL ciphers @jonjozwiak
...
Fixing profile and region settings for extra792 - ELB SSL ciphers
2020-06-11 09:05:50 +02:00
jonjozwiak
4db109bb26
Fixing profile and region settings for check_extra792 - ELB SSL ciphers
2020-06-10 15:46:34 -05:00
Toni de la Fuente
f1690e8ddc
Added old multiaccount sample info to util/other-contrib folder
2020-06-08 13:27:19 +02:00
Toni de la Fuente
acab5d11ed
Update README.md with link to new org-multi-account
2020-06-08 13:23:15 +02:00
Toni de la Fuente
f42358f361
AWS Organizational Prowler Deployment @tekdj7
...
AWS Organizational Prowler Deployment
2020-06-08 13:16:42 +02:00
Julio Delgado Jr
9e2580cc34
removed ansi2html, added -M html
2020-06-05 12:06:33 -04:00
Toni de la Fuente
7a46d23820
Import Security Hub finding into the same region as the related resource @marcjay
...
Import Security Hub finding into the same region as the related resource
2020-06-05 15:07:11 +02:00
Marc Jay
4dac3aab55
Import Security Hub finding into the same region as the related resource
...
Force the batch-import-findings AWS CLI call to be directed at the region the currently reporting resource is located in, as Security Hub enforces this requirement
When checking that Security Hub is enabled, check for all regions that are in scope, e.g. all regions, unless '-f <region>' is used
Fixes #618
2020-06-05 12:55:53 +01:00
Toni de la Fuente
26665a4645
Fix extra734 - handle us-east-1 @nimrodkor
...
Fix extra734 - handle us-east-1
2020-06-05 11:09:44 +02:00
Toni de la Fuente
94378726bc
Fix extra764 - handle us-east-1 & check validity of policy @nimrodkor
...
Fix extra764 - handle us-east-1 & check validity of policy
2020-06-05 10:48:28 +02:00
Nimrod Kor
4dae0718c1
Fix extra764 - handle us-east-1 & check validity of policy
...
(cherry picked from commit 89bd8a90d5 )
2020-06-04 23:18:08 +03:00
Nimrod Kor
ef4d2d33be
Fix extra734 - handle us-east-1
...
(cherry picked from commit 5f2eb7f82e )
2020-06-04 23:15:21 +03:00
Toni de la Fuente
99d1de8c15
Improved whitelisting by splitting ignores by newline instead of spaces only @urjitbhatia
...
Split ignores by newline instead of spaces only
2020-05-29 11:40:44 +02:00
Julio Delgado Jr
a58ee251b5
adhoc & switch user in session manager
2020-05-28 13:43:55 -04:00
Urjit Singh Bhatia
2fca2a49fd
Split ignores by newline instead of spaces only
2020-05-27 13:58:55 -07:00
Toni de la Fuente
e69b079220
Fix typo on PR #601
2020-05-27 10:02:32 +02:00
Toni de la Fuente
75cd911b0f
Removed ansi2html from Pipfile, Dockerfile and README
2020-05-27 09:55:17 +02:00
Toni de la Fuente
2dda3f1ec1
Removed ansi2html from Pipfile
2020-05-27 09:52:34 +02:00
Toni de la Fuente
46a8a3ca82
Adding support for IRSA @GabrielCastro
...
Adding support for IRSA
2020-05-27 09:44:52 +02:00
Toni de la Fuente
69e2e19e7d
Added extra791 and extra792 to group extras
2020-05-27 09:37:10 +02:00
Toni de la Fuente
b7c8f7a7ef
New checks for insecure SSL in CloudFront and ELB @jonjozwiak
...
Adding insecure SSL checks for CloudFront and ELB, extra791 and extra792
2020-05-27 09:32:13 +02:00
Adam
ad1d4874c4
add fixes for none digest and multi-value digest return
2020-05-26 17:16:14 -04:00
Jon Jozwiak
06e81a7f33
Update check_extra792 ASFF resource tye
2020-05-26 09:35:48 -05:00
Jon Jozwiak
70337ecd84
Add ASFF resource type
2020-05-26 09:34:37 -05:00
jonjozwiak
df15388577
Adding insecure SSL checks for CloudFront and CLB/ALB
...
(cherry picked from commit c9a60c07a2 )
2020-05-26 16:33:18 +03:00
Toni de la Fuente
485b7d90bc
Added native html report - upgrade to 21st century ;)
2020-05-25 21:29:29 +02:00
Toni de la Fuente
78b26a022a
Added native html report - upgrade to 21st century ;)
2020-05-25 21:24:33 +02:00
Gabriel Castro
3e19ed44e5
Feature: add support for IRSA
...
IAM roles for service accounts (IRSA) allows prowler to be used from
inside a kubernetes cluster.
2020-05-25 13:14:15 -04:00
Toni de la Fuente
3e6f29c3fd
Support Ctrl-C/SIG INT stopping Prowler when running in Docker @marcjay
...
Support Ctrl-C/SIG INT stopping Prowler when running in Docker
2020-05-21 18:08:00 +02:00
Toni de la Fuente
e5ce06e761
Write output files to a directory relative to Prowler @marcjay
...
Write output files to a directory relative to Prowler
2020-05-21 18:06:46 +02:00
Toni de la Fuente
e3d5b89531
Delete prowler-logo.png
2020-05-21 14:40:06 +02:00
Toni de la Fuente
7987ee3011
Added Prowler logo to util/html/
2020-05-21 14:38:33 +02:00
Toni de la Fuente
2b336d08de
Added ENV to output when credentials are env variables
2020-05-19 15:06:57 +02:00
Toni de la Fuente
c7ed6a6693
Improved region handing for extra734 and extra764
2020-05-19 15:03:42 +02:00
Toni de la Fuente
48b6c290b1
Enhance handing region on assume role when default is not us-east-1
2020-05-11 16:32:43 +02:00
Toni de la Fuente
e0c2ca2436
Fixed issue #596 for extra71
2020-05-11 13:21:06 +02:00
Toni de la Fuente
38fb596e94
Merge branch 'master' of https://github.com/toniblyx/prowler
2020-05-11 13:16:53 +02:00
Toni de la Fuente
c79d346961
Fixed issue #596 on check114
2020-05-11 13:16:38 +02:00
Marc Jay
0f9783791b
Support Ctrl-C/SIG INT stopping Prowler when running in Docker
...
Trap Ctrl-C/SIG INT, call cleanup function and then exit, using the appropriate exit code
Fixes #594
2020-05-08 12:34:03 +01:00
Marc Jay
802d1151c2
Write output files to a directory relative to Prowler
...
Write output files (CSV, JSON, etc.) to an `output` directory that is relative to prowler itself, no matter where prowler is invoked from.
Simplify Dockerfile by specifying a WORKDIR
Replace ADD command with the more recommended COPY command
Update README to cover how to run in Docker and access saved reports
Add a .dockerignore file to ignore .git and output directories
This partially addresses #570 - previously, within Docker, Prowler was attempting to write
reports to the root `/` directory in the container, which it did not have permission to do.
Instead, reports are now written to a path relative to Prowler
2020-05-08 11:46:53 +01:00
Toni de la Fuente
2a9f6c67a8
Change value of FAIL to FAILED for jsonAsff output type @wildtangent
...
Change value of FAIL to FAILED for jsonAsff output type
2020-05-07 17:55:01 +02:00
Stephen Connor
2a54a180da
Change value of FAIL to FAILED for jsonAsff output type (incompatible with AWS Security Hub)
2020-05-07 14:47:09 +01:00
Toni de la Fuente
7ab9962e08
Show failures that are ignored due to whitelisting as skipped checks in JUnit output @marcjay
...
Show failures that are ignored due to whitelisting as skipped checks in JUnit output
2020-05-07 09:22:48 +02:00
Marc Jay
6279dc1517
Show failures that are ignored due to whitelisting as skipped checks in JUnit output
...
Continue to show (unwhitelisted) failed checks as failures in JUnit output, but rather than exclude failing whitelisted checks from JUnit, mark them as skipped
Fixes #590
2020-05-07 01:00:42 +01:00
Toni de la Fuente
376cc0ff08
Usage update
2020-05-07 00:48:14 +02:00
Toni de la Fuente
a37160bf41
Usage update
2020-05-07 00:46:43 +02:00
Toni de la Fuente
b72501f691
Usage update
2020-05-07 00:45:45 +02:00
Toni de la Fuente
733aa439ec
Usage update
2020-05-07 00:44:27 +02:00
Toni de la Fuente
24fcfb1066
v2.3.0RC
2020-05-06 23:27:30 +02:00
Toni de la Fuente
977fe7408e
Added whitelist option to README and recuce output for -w
2020-05-06 23:24:42 +02:00
Toni de la Fuente
f618a16075
Fixed AWS partition variable on generateJsonAsffOutput
2020-05-06 22:57:26 +02:00
Toni de la Fuente
68ad3a7461
Support whitelists per check @urjitbhatia
...
Support whitelists per check using option -w whitelistfile.txt
2020-05-06 22:46:57 +02:00
Toni de la Fuente
412c9c1e5a
added back LIST_OF_CHECKS_AND_GROUPS.md
2020-05-06 22:09:32 +02:00
Julio Delgado Jr
d6033e287d
encryption of ebs volume
2020-05-06 10:55:42 -04:00
Toni de la Fuente
3df27862ac
Support setting entropy limit for detect-secrets from env BASE64_LIMIT and HEX_LIMIT @yumminhuang
...
Support setting entropy limit for detect-secrets from env:
export BASE64_LIMIT=4.5
export HEX_LIMIT=3.0
2020-05-06 14:37:23 +02:00
Huang Yaming
bc07c95bda
Support setting entropy limit for detect-secrets from env
2020-05-06 17:53:23 +08:00
Urjit Singh Bhatia
8cdf3838a0
Print warnings with the right color code
2020-05-04 16:33:50 -07:00
Urjit Singh Bhatia
5ac9be3292
correct color info line for warning
2020-05-04 14:48:04 -07:00
Urjit Singh Bhatia
103782f72b
Fix warning handling with changes to official master
2020-05-04 14:37:30 -07:00
Urjit Singh Bhatia
5886f8524a
Merge remote-tracking branch 'official/master' into whitelistSupport
2020-05-04 13:56:14 -07:00
Julio Delgado Jr
49456424fa
example
2020-05-03 13:02:46 -04:00
Julio Delgado Jr
d095ea75d8
intro
2020-05-03 12:14:36 -04:00
Julio Delgado Jr
23dc8ce883
.
2020-05-03 12:12:57 -04:00
Julio Delgado Jr
378dd88808
.
2020-05-03 12:09:29 -04:00
Julio Delgado Jr
8fd2c17b5d
.
2020-05-03 12:08:56 -04:00
Julio Delgado Jr
d2503ad1d3
more links, formatting
2020-05-03 12:07:31 -04:00
Julio Delgado Jr
159ae3ac32
removed ingress rule
2020-05-03 12:07:15 -04:00
Julio Delgado Jr
bb46702d37
updates
2020-05-03 11:50:05 -04:00
Julio Delgado Jr
95135305d7
updated links
2020-05-03 11:48:44 -04:00
Julio Delgado Jr
8728815704
.
2020-05-03 11:46:37 -04:00
Julio Delgado Jr
f4af505270
better markdown for code, more documentation
2020-05-03 11:45:20 -04:00
Julio Delgado Jr
25cb42e3c4
added parallel_accounts variable
2020-05-03 11:44:50 -04:00
Julio Delgado Jr
29378a1339
Updated Patterns,Defaults,Tags,BucketPolicy
2020-05-03 11:43:50 -04:00
Julio Delgado Jr
ac5212990a
Updated Patterns,Descriptions,Defaults,Tags
2020-05-03 11:42:56 -04:00
Julio Delgado Jr
1be68b1e00
Updated Patterns,Descriptions,Defaults,Tags
2020-05-03 11:42:30 -04:00
Julio Delgado Jr
4230e9dc13
added elapsed times, support run prower parallel
2020-04-30 20:12:19 -04:00
Julio Delgado Jr
36e9f5174d
reduced sts calls, updated comments
2020-04-30 17:24:00 -04:00
Julio Delgado Jr
d716cf2664
more documentation and links
2020-04-30 17:23:28 -04:00
Julio Delgado Jr
299cb7e541
Renamed Parameters, Updated Descriptions
2020-04-30 17:22:29 -04:00
Julio Delgado Jr
7816fd0648
Renamed Parameters, Updated Descriptions
2020-04-30 17:21:52 -04:00
Julio Delgado Jr
0cf97a99b3
Renamed Parameters, Updated Descriptions
2020-04-30 17:21:42 -04:00
Toni de la Fuente
996f785af6
Improve check21 If no account cloudtrail trail is found, check org trail @nimrodkor @bridgecrewio
...
check21 - If no account CloudTrail trail is found, check org trail
2020-04-29 22:24:24 +02:00
Nimrod Kor
dd0ef8c0b4
If no local cloudtrail trail is found - check org trail
2020-04-29 21:39:27 +03:00
Toni de la Fuente
a2cbcc00eb
Fix issue with aws-cli v2 and timestamp on check24 #585
2020-04-29 18:10:41 +02:00
Toni de la Fuente
5450bf949e
Fix check12's grep to find users with true in their name who really have password access @nimrodkor @bridgecrewio
...
Fix check12's grep to find users with true in their name who really have password access @nimrodkor @bridgecrewio
2020-04-29 13:02:26 +02:00
Toni de la Fuente
e4ae0a403a
Ensure that hyphen is at end of tr string to prevent 'reverse collating sequence order' error in GNU tr @marcjay
...
Ensure that hyphen is at end of tr string to prevent 'reverse collating sequence order' error in GNU tr
2020-04-29 12:09:53 +02:00
Toni de la Fuente
1f949b4175
Improved AWS partition handle
2020-04-29 12:06:47 +02:00
Julio Delgado Jr
129a22e9c3
updated cron job settings
2020-04-28 18:53:04 -04:00
Julio Delgado Jr
e0b6d4a21d
Added Adhoc: Run Prowler Interactively
2020-04-28 18:33:29 -04:00
Julio Delgado Jr
94b978a934
renamed
2020-04-28 12:36:10 -04:00
Julio Delgado Jr
09e4feb095
stopped embedding script into CF, download script
2020-04-28 12:35:57 -04:00
Nimrod Kor
dbca70ef2e
Add $ to end of regex
2020-04-28 14:28:59 +03:00
Nimrod Kor
54f2b72cb6
Fix check12's grep to find users who really have password access
...
(cherry picked from commit 4006c581a0 )
2020-04-28 14:13:32 +03:00
Julio Delgado Jr
200bbf9a7d
org-multi-account initial commit
2020-04-28 00:47:42 -04:00
Marc Jay
af3afa8c8f
Merge branch 'master' into fix-tr-error-on-centos-573
2020-04-27 17:24:03 +01:00
Toni de la Fuente
684473327a
Fix output modes strings to ensure correct outputs are selected @marcjay
...
Wrap all mode checks with whitespace, along with comparison strings to ensure correct outputs are selected
2020-04-27 16:20:56 +02:00
Marc Jay
f84b843388
Wrap all mode checks with whitespace, along with comparison strings, so only exact string matches are allowed, preventing clashes when output modes are named similarly, e.g. 'json' and 'json-asff'
...
Fixes #571
2020-04-26 01:02:39 +01:00
Marc Jay
e25125fbfc
Ensure that hyphen is at end of tr string to prevent 'reverse collating sequence order' error in GNU tr
...
Stop echo from adding newlines using `-n`, removing the need to stop replacing new-line characters with underscores
Fixes #573
2020-04-26 00:40:27 +01:00
Toni de la Fuente
33523885f1
Delete LIST_OF_CHECKS_AND_GROUPS.md
2020-04-23 16:27:59 +02:00
Toni de la Fuente
13ca147d02
Updated checks with hardcoded arn to support GovCloud partition
2020-04-22 23:23:17 +02:00
Toni de la Fuente
dbb3ed9663
Improved extra734 for GovCloud
2020-04-22 22:19:21 +02:00
Toni de la Fuente
1beb483be3
Fixed issue with govcloud on extra764 #536
2020-04-22 20:40:18 +02:00
Toni de la Fuente
7dc790a3f5
Fixed issue with govcloud on extra764 #536
2020-04-22 20:05:39 +02:00
Toni de la Fuente
8c9aea1231
Improved GetCallerIdentity handling / credentials
2020-04-22 13:54:17 +02:00
Toni de la Fuente
9f03bd7545
Added txt output as mono for -M
2020-04-22 12:58:54 +02:00
Toni de la Fuente
2eb41ff910
Added account id to the output filename
2020-04-22 12:32:05 +02:00
Toni de la Fuente
2d64a1182e
Added account id to the output filename
2020-04-22 12:31:27 +02:00
Toni de la Fuente
43fb877109
Added account id to the output filename
2020-04-22 12:28:31 +02:00
Toni de la Fuente
ef952ce9cc
Simplified caller id info on outputs
2020-04-22 12:07:20 +02:00
Toni de la Fuente
0cca77a141
Check if gbase64 (GNU) is available on Mac and use it in preference to BSD base64 @marcjay
...
Check if gbase64 (GNU) is available on Mac and use it in preference to BSD base64
2020-04-22 12:01:40 +02:00
Toni de la Fuente
5b9cf7fa99
Fix -E flag no longer excluding checks @marcjay
...
Fix -E flag no longer excluding checks
2020-04-22 11:55:01 +02:00
Marc Jay
5805576dce
Check if gbase64 (GNU) is available on Mac and use it in preference to BSD base64
...
Previously it was switching to GNU versions of base64 even if base64 was the BSD version
Fixes #568
2020-04-22 10:35:33 +01:00
Toni de la Fuente
9cbdefc2de
Adds CSV header to the output file too #565
2020-04-22 11:27:08 +02:00
Marc Jay
c2669622cf
Fix -E flag no longer excluding checks
...
Remove re-declaration of TOTAL_CHECKS variable
Bug introduced by #561
Fixes #566
2020-04-22 09:58:33 +01:00
Toni de la Fuente
b9051e6fc9
Merge pull request #563 from marcjay/correct-check13-496
...
Extend check13 to meet all CIS rules and consolidate with extra774
2020-04-22 10:46:37 +02:00
Toni de la Fuente
92091d9ecd
Rollback #562 fix issue #564
2020-04-22 10:31:30 +02:00
Marc Jay
ad66254b45
Extend check13 to meet all CIS rules and consolidate with extra774
...
Create `include/check_creds_last_used` and move all logic for checking last usages of passwords and access keys there
Modify check13 and extra774 to call new function, specifying time-range of last 90 days and last 30 days respectively
Modify messages in check14 and check121 so that all mentions of 'access key's are consistent
Fixes #496
2020-04-21 01:21:55 +01:00
Toni de la Fuente
d6374f8bc8
Updated textInfo message on extra712
2020-04-20 19:27:39 +02:00
Toni de la Fuente
0c7805356e
Enhancement: extra712 improved with Macie API call instead of IAM @eko0126
...
using api commands to check if macie is enabled instead of looking ia…
2020-04-20 19:20:13 +02:00
Toni de la Fuente
86ea46d77c
Update check_extra712
2020-04-20 19:19:05 +02:00
Toni de la Fuente
3feac6f75b
Improve listing of Checks and Groups @marcjay
...
Improve listing of Checks and Groups
2020-04-20 19:14:50 +02:00
Marc Jay
71bf414faf
Merge branch 'master' into improve-listing-of-checks-and-groups-545
2020-04-20 18:11:06 +01:00
Toni de la Fuente
38a970f4fc
Enhancement: extra768 only check latest version of ECS task definition
...
Only check latest version of task definition
2020-04-20 19:00:26 +02:00
Toni de la Fuente
3dae201a80
Merge branch 'marcjay-add-junit-xml-output-mode-log-duration-537'
2020-04-20 18:57:27 +02:00
Toni de la Fuente
d45b739b1e
Merge branch 'add-junit-xml-output-mode-log-duration-537' of https://github.com/marcjay/prowler into marcjay-add-junit-xml-output-mode-log-duration-537
2020-04-20 18:51:26 +02:00
Toni de la Fuente
ce56f0cb24
git push origin masterMerge branch 'nalansitan-extra725'
2020-04-20 18:49:37 +02:00
Toni de la Fuente
d02d9e1c95
Merge branch 'extra725' of https://github.com/nalansitan/prowler into nalansitan-extra725
2020-04-20 18:46:39 +02:00
Alex Gray
5b8370179a
Get the list of families and then get latest task definition
2020-04-20 09:15:15 -04:00
He.Longfei
b42cc33a6c
using api commands to check if macie is enabled instead of looking iam role
2020-04-20 15:01:38 +08:00
Marc Jay
8f179338d8
Fix invalid references to $i when it should reference a local $group_index variable
2020-04-20 01:30:37 +01:00
Marc Jay
47a05c203a
Improve listing of Checks and Groups
...
Change `-l` flag to print a unique list of every single check (assuming none are orphaned outside of all groups)
Allow `-g <group_id>` to be specified in combination with `-l`, to only print checks that are referenced by the specified group
When listing all checks with `-l` only, print out all groups that reference each check
Fixes : #545
2020-04-20 01:12:53 +01:00
Toni de la Fuente
6747b208ce
Improved extra716 and extra788
2020-04-17 15:16:55 +02:00
Marc Jay
78f649bd65
Replace -J flag with junit-xml output format
...
Rearrange output functions so they support outputting text alongside other formats, if specified
Add a convenience function for checking if JUnit output is enabled
Move monochrome setting into loop so it better supports multiple formats
Update README
2020-04-15 23:36:40 +01:00
Alex Gray
172f4b2681
Only check latest version of task definition
2020-04-15 15:19:44 -04:00
Marc Jay
dc31adcc18
Rename JUnit XML files to match the Java convention - with a 'TEST-' prefix
2020-04-15 13:42:33 +01:00
Marc Jay
fa17829832
Fix arithmetic expression for calculating test duration
2020-04-15 12:52:48 +01:00
Marc Jay
994390351e
Add the ability to generate JUnit XML reports with a -J flag
...
If the -J flag is passed, generate JUnit XML reports for each check, in-line with how Java tools generate JUnit reports.
Check section numbers equate to 'root packages', checks are second-level packages, each check equates to a testsuite (mirroring Java where each test class is a testsuite) and each pass/fail of a check equates to a testcase
Time the execution of each check and include this in the report
Include properties (Prowler version, check level etc.) in-line with standard JUnit files
XML escape all strings for safety
Detect if a user has GNU coreutils installed on Mac OS X, but not as their default, switching to using gdate for date commands if so, as it has more features, including getting dates in milliseconds
Add prowler-output, junit-reports and VSCode files to .gitignore
Update README to include JUnit info, address markdownlint warnings
Remove unused arguments to jq in generateJsonAsffOutput
Fixes #537
2020-04-15 02:36:16 +01:00
Urjit Singh Bhatia
bf72025b9b
Ignore inline whitelist comments, pass checkid to filter ignores specifically for checks
2020-04-14 17:29:36 -07:00
Toni de la Fuente
462527015c
Merge branch 'marcjay-simplify-check-id-variables'
2020-04-15 00:24:17 +02:00
Toni de la Fuente
3311acf82c
Merge branch 'simplify-check-id-variables' of https://github.com/marcjay/prowler into marcjay-simplify-check-id-variables
2020-04-15 00:23:54 +02:00
Toni de la Fuente
f065beb93b
Fixed title in group16_trustboundaries
2020-04-14 23:57:55 +02:00
Toni de la Fuente
2de49c3940
Added more sample commands and updates
2020-04-14 23:55:02 +02:00
Toni de la Fuente
f3664b56ec
Open
2020-04-14 22:46:44 +02:00
Toni de la Fuente
4ea1864365
Allow multiple report types at once #345
2020-04-14 22:28:58 +02:00
Toni de la Fuente
e6fe5addbc
Added section for Security Hub integration
2020-04-14 18:52:48 +02:00
Toni de la Fuente
58d793ec2a
Added section for Security Hub integration
2020-04-14 18:51:13 +02:00
Toni de la Fuente
973f6b39a0
Merge branch 'master' of https://github.com/toniblyx/prowler
2020-04-14 16:45:54 +02:00
Toni de la Fuente
11c182c5fe
Fixed issue with regions on check21
2020-04-14 16:45:37 +02:00
nalansitan
036ae640e5
support arn:aws:s3::: on extra725
2020-04-14 10:38:01 +08:00
Marc Jay
7e5a4a1de4
Adjust execute_check() now that check71's ID has changed
...
Fix minor typo in a comment
2020-04-14 02:17:28 +01:00
Marc Jay
0f49468601
Limit CHECK_ID to a single value, handing the left-pad formatting in one place
...
Remove the second entry in any comma-separated check IDs from each check, formatting
the check ID with leading zeros in `include/outputs` if the `-n` flag is active
2020-04-14 02:02:48 +01:00
Toni de la Fuente
df52057287
Fix: extra741 - Check if User Data is a valid GZIP file before attempting to gunzip @marcjay
...
Extra741 - Check if User Data is a valid GZIP file before attempting to gunzip
2020-04-13 23:53:39 +02:00
Marc Jay
460f65618b
Add clarifying text to pass/fail messages
2020-04-13 22:43:22 +01:00
Marc Jay
c4374a2818
Extra741 - Check if User Data is a valid GZIP file before attempting to gunzip
...
Test if the user data is a valid GZIP file using `gunzip -t` and only then attempt to gunzip it
Remove some code duplication
Fixes #535
2020-04-13 22:27:22 +01:00
Toni de la Fuente
9be0b3f749
Prowler IAM Policy Enhancements and README Updates @tekdj7
...
Prowler IAM Policy Enhancements and README Updates @tekdj7
2020-04-13 18:52:28 +02:00
Julio Delgado Jr
05247a2ccb
Prowler IAM Policy Enhancements and ReadMe Updates
2020-04-13 12:39:20 -04:00
Toni de la Fuente
a4264628cb
Extra725 - Improved support cross account and region cloudtrail @patdowney
...
Extra725 - Support cross account and region cloudtrail
2020-04-13 18:34:31 +02:00
Toni de la Fuente
8a7344ef86
Extra720 - Support cross account and cross-region cloudtrail @patdowney
2020-04-13 18:33:38 +02:00
Toni de la Fuente
4cf66a2f32
Merge pull request #527 from yumminhuang/master
...
Remove --output text in CLOUDTRAILBUCKET_LOGENABLED
2020-04-13 18:18:55 +02:00
Toni de la Fuente
7f2e097205
Merge pull request #518 from bridgecrewio/bugfix/check_23_error_fails
...
check23 - on failure, output info and not failure
2020-04-13 16:50:30 +02:00
Toni de la Fuente
67504e8591
Merge pull request #519 from bridgecrewio/bugfix/check_26_error_fails
...
check26 - on failure, output info and not failure
2020-04-13 16:50:05 +02:00
Toni de la Fuente
958a54e337
Merge pull request #530 from marcjay/aws-security-hub-output-524
...
Add 'json-asff' output mode and ability to send output to AWS Security Hub
2020-04-13 14:03:50 +02:00
Toni de la Fuente
d39bad2ee2
Merge pull request #541 from marcjay/sort-checks-correctly-when-excludes-in-place-492
...
Avoid changing the execution order of checks when some checks are excluded
2020-04-13 13:40:20 +02:00
Toni de la Fuente
3c77130f65
Merge pull request #540 from marcjay/check121-filter-out-password-access-513
...
check121 - Filter out users who do not have a console password
2020-04-13 13:31:33 +02:00
Toni de la Fuente
d855432f28
Merge pull request #538 from marcjay/fix-no-information-extra774-501
...
Extra 774 - Handle IAM credential report containing 'no_information' for a user's last console login date
2020-04-13 13:30:24 +02:00
Toni de la Fuente
3e1d9ea0d3
Merge pull request #539 from marcjay/handle-gnu-date-as-default-on-mac-osx-534
...
Detect when GNU coreutils is installed on Mac OS X and use the correct date functions
2020-04-13 13:27:42 +02:00
Marc Jay
24e691901e
Convert tabs to spaces within modified function
2020-04-12 17:17:46 +01:00
Marc Jay
57c15c2cc9
Avoid changing the execution order of checks when some checks are excluded
...
Replace the use of `sort -u` to remove duplicate checks, which has the side-effect of reordering checks alphabetically when one or more are excluded with awk, which preserves the check order
Adjust indentation and formatting to be more consistent with the rest of the file
Fixes #492
2020-04-12 17:12:54 +01:00
Marc Jay
4f623b4e31
check121 - Filter out users who do not have a console password
...
According to the benchmark, only users with a console password should be considered for this check,
therefore filter out any users who do not have a console password
Fixes #513
2020-04-12 02:18:42 +01:00
Marc Jay
d9588f4de0
Detect when GNU coreutils is installed on Mac OS X and use the correct date functions
...
As some users may have installed GNU coreutils on Mac OS X, e.g. `brew install coreutils`, it's possible that
the `date` command uses the GNU version, instead of the standard BSD version.
- Detect if GNU coreutils is installed on Mac and if it is, use the GNU variants of date functions
- Reduce some of the duplication in the file, which resolves a bug where the cygwin version of `how_many_days_from_today()`
had the operands switched around, leading to a positive result instead of negative
- Add test_tcp_connectivity function for cygwin (uses the GNU variant)
Fixes #534
2020-04-12 01:28:11 +01:00
Marc Jay
ce1058dfed
Remove the varying number of days in the message so that message stays consistent over time
2020-04-12 01:22:34 +01:00
Marc Jay
8d9c7e8ab0
Handle IAM credential report containing 'no_information' for a user's last console login date
...
A user who has never logged into the console, or not logged in since Oct 2014 will present as 'no_information' in the
'password_last_used' column of the credential report. Handle this scenario and output a failed message if it has been
more than MAX_DAYS days since the user was created, or an info message if it is less than MAX_DAYS
Fixes #501
2020-04-11 20:07:03 +01:00
Marc Jay
c02811f411
Add CHECK_ASFF_RESOURCE_TYPE variables for recently added checks
2020-04-11 03:34:32 +01:00
Marc Jay
4bae0ca5f5
Merge branch 'master' into aws-security-hub-output-524
2020-04-11 03:16:23 +01:00
Marc Jay
5bab65c56d
- Remove securityhub output mode and replace with '-S' flag to send findings to Security Hub
...
- Move Security Hub related code to a dedicated include/securityhub_integration file
- Check that Security Hub is enabled in the target region before beginning checks when -S is specified
- Add error handling to the batch-import-findings call
- Add CHECK_ASFF_TYPE variables to all CIS checks to override the default
- Add support for CHECK_ASFF_RESOURCE_TYPE variables which override the default 'AwsAccount' value for the resource a finding relates to.
- Add CHECK_ASFF_RESOURCE_TYPE variables to all checks where there is a suitable value in the schema
- Remove json-asff output for info messages as they are not appropriate for possible submission to Security Hub
- Update the README to cover Security Hub integration
- Add an IAM policy JSON document that provides the necessary BatchImportFindings permission for Security Hub
- Remove trailing whitespace and periods in pass/fail messages to be consistent with the majority of messages, to prevent future tidy-up from changing the finding IDs
2020-04-11 03:04:03 +01:00
Huang Yaming
7982cc462a
Remove --output text in CLOUDTRAILBUCKET_LOGENABLED
...
When adding `--output text`, aws cli will return `None` instead of
`null`. It makes the following if check misjudge LoggingEnabled
status.
2020-04-10 10:18:20 +08:00
Toni de la Fuente
8f83da985a
PR #511
2020-04-08 18:00:54 +02:00
Patrick Downey
b6adfd58ec
Support cross-region and cross-account object-level cloudtrail logs for S3
...
Buckets that log to one or more trails are logged as `PASS!` for each trail they are associated with.
Buckets that aren't associated with any trails are logged as `FAIL!` once.
```
...
PASS! : S3 bucket bucket-one has Object-level logging enabled in trails: arn:aws:cloudtrail:eu-west-2:123456789012:trail/central-trail
PASS! : S3 bucket bucket-two has Object-level logging enabled in trails: arn:aws:cloudtrail:eu-west-2:9876543210989:trail/trail-two
PASS! : S3 bucket bucket-two has Object-level logging enabled in trails: arn:aws:cloudtrail:eu-west-2:123456789012:trail/central-trail
PASS! : S3 bucket bucket-three has Object-level logging enabled in trails: arn:aws:cloudtrail:eu-west-2:123456789012:trail/central-trail
...
```
This change should also address #387
2020-04-08 15:50:52 +01:00
Patrick Downey
78ccc7d953
Remove HomeRegion predicate from describe-trails in extras725
...
So we can look at cross-region trails too
2020-04-08 13:28:18 +01:00
Patrick Downey
fc83a9896c
Use TrailARN property to query get-event-selectors in checks_extra725
...
This will work to query cloudtrail's that are in different accounts.
e.g. in the case of organisation managed cloudtrails.
2020-04-08 13:27:09 +01:00
Toni de la Fuente
effc3eb14d
Added new checks to group extras
2020-04-08 14:06:11 +02:00
Toni de la Fuente
6ea37b05ca
Improvements and new checks for elasticsearch
2020-04-08 14:00:12 +02:00
Patrick Downey
84711d1ef5
Remove HomeRegion predicate from describe-trails to look for cross-region trails too
...
This will hopefully address #455
2020-04-08 12:52:13 +01:00
Patrick Downey
4ff685635e
Use TrailARN property to query get-event-selectors
...
This will work to query cloudtrail's that are in different accounts.
e.g. in the case of organisation managed cloudtrails.
2020-04-08 12:52:13 +01:00
Toni de la Fuente
9c4e629647
Fixed typo in extra786
2020-04-07 20:28:38 +02:00
Marc Jay
92e1f17a80
Adds 'json-asff' and 'securityhub' output modes
...
json-asff mode outputs JSON, similar to the standard 'json' mode with one check per line, but in AWS Security Finding Format - used by AWS Security Hub
Currently uses a generic Type, Resources and ProductArn value, but sets the Id to a unique value that includes the details of the message, in order to separate out checks that run against multiple resources and output one result per resource per check. This ensures that findings can be updated, should the resource move in or out of compliance
securityhub mode generates the ASFF JSON and then passes it to an 'aws securityhub batch-import-findings' call, once per resource per check. Output to the screen is similar to the standard mode, but prints whether or not the finding was submitted successfully
Fixes #524
2020-04-07 16:08:07 +01:00
Toni de la Fuente
bd432fed92
New check for Metadata Service Version 2 #413
2020-04-07 16:46:46 +02:00
Toni de la Fuente
b5e1c9002a
Improved policy handling on extra716
2020-04-03 17:54:55 +02:00
Toni de la Fuente
afb908f190
Improved policy handling on extra716
2020-04-03 17:54:25 +02:00
Toni de la Fuente
e567ccb828
v2.2.1 with new function and Improved extra779 and extra716
2020-04-02 15:31:43 +02:00
Toni de la Fuente
2c580dd750
Fix issue #488 only works if CloudWatchLog configuration
2020-04-02 00:19:43 +02:00
Toni de la Fuente
9dec4e6eb3
Fix issue #488 only works if IsMultiRegionTrail
2020-04-02 00:02:42 +02:00
Toni de la Fuente
2e2fe96ff5
Improved extra716 filters and auth check
2020-04-01 21:57:20 +02:00
Toni de la Fuente
2e2e9b85af
Merge branch 'master' of https://github.com/toniblyx/prowler
2020-04-01 16:53:04 +02:00
Toni de la Fuente
1ae5d5d725
Added custom ports variable to extra779
2020-04-01 16:52:52 +02:00
Toni de la Fuente
71c9d12184
Merge pull request #526 from dhirajdatar/change-in-usage
...
Updated extra in usage of extra for multiple checks
2020-03-31 13:24:23 +02:00
dhirajdatar
059c701923
Update README.md
2020-03-31 16:46:38 +05:30
Toni de la Fuente
d24e824735
Merge pull request #522 from yumminhuang/master
...
Ignore imported ACM Certificate in check_extra724
2020-03-27 15:03:45 +01:00
Huang Yaming
1419d4887a
Ignore imported ACM Certificate in check_extra724
2020-03-27 14:49:52 +08:00
Toni de la Fuente
ba75d89911
Added connection test for port 9300 in both linux and macosx on extra779
2020-03-25 18:20:20 +01:00
Toni de la Fuente
8faf1f45c4
Added connection test for port 9300 in both linux and macosx on extra779
2020-03-25 18:19:41 +01:00
Toni de la Fuente
eae4722499
Updated ES check titles and results
2020-03-25 17:25:38 +01:00
Toni de la Fuente
8c18533752
Updated check titles
2020-03-25 17:18:43 +01:00
Toni de la Fuente
ee82424869
Enhanced extra779 with better authentication test and TEST_ES_AUTHENTICATION disabled
2020-03-25 12:44:10 +01:00
Toni de la Fuente
b4aaf0b81e
Added initial PCI group without checks yet, issue #296
2020-03-25 10:53:55 +01:00
Toni de la Fuente
f809f2fa1d
Modify group names header to clarify what is CIS only
2020-03-25 10:53:05 +01:00
Toni de la Fuente
1615478444
Fixed query on extra779
2020-03-25 09:40:03 +01:00
Toni de la Fuente
568bba4c38
Add Elasticsearch checks issue #521
2020-03-24 23:46:11 +01:00
Toni de la Fuente
705d75606d
Merge pull request #520 from bridgecrewio/bugfix/extra774_fixes
...
extra774 requires credential report to run successfully
2020-03-23 15:50:08 +01:00
Toni de la Fuente
3ff4acf648
Merge branch 'lanhhuyet510-patch-2'
2020-03-23 15:09:45 +01:00
Toni de la Fuente
e082ef05f0
Merge branch 'patch-2' of https://github.com/lanhhuyet510/prowler into lanhhuyet510-patch-2
2020-03-23 15:09:15 +01:00
Toni de la Fuente
2db9151939
Merge pull request #508 from renuez/checks/find_security_groups_with_wide_open_non_RFC1918_IPv4
...
Checks/find security groups with wide open non rfc1918 IPv4 addresses
2020-03-23 14:50:05 +01:00
Toni de la Fuente
db3ac2361c
Merge branch 'master' into checks/find_security_groups_with_wide_open_non_RFC1918_IPv4
2020-03-23 14:48:05 +01:00
Toni de la Fuente
30941c355c
Added extra777 - Security Groups with too many rules @renuez
2020-03-23 14:39:23 +01:00
Nimrod Kor
25bc8699b3
check_extra774 - revert changes
...
(cherry picked from commit 87fd299cdb )
2020-03-22 11:24:07 +02:00
Nimrod Kor
d62027440d
extra774 - check correct date, consolidate files and fix report generation
...
(cherry picked from commit 75d66df940 )
2020-03-22 11:24:07 +02:00
Nimrod Kor
b704568b23
check26 - on failure, output info and not failure
...
(cherry picked from commit f80c2e28b7 )
2020-03-22 11:23:41 +02:00
Nimrod Kor
259f24ee06
check23 - on failure, output info and not failure
...
(cherry picked from commit 168c71cd5f )
2020-03-22 11:23:18 +02:00
Urjit Singh Bhatia
56a4fd813c
Support whitelists per check
2020-03-10 18:55:28 -07:00
Ngọ Anh Đức
0979f421c3
Update check21
2020-03-09 13:00:43 +07:00
Ngọ Anh Đức
89514a1fa8
Update check21
2020-03-09 12:59:47 +07:00
Ngọ Anh Đức
ba13f25c9e
Update check21
2020-03-09 12:57:49 +07:00
Ngọ Anh Đức
53ee538e0f
add $PROFILE_OPT to the CLI
2020-03-09 12:57:00 +07:00
Ngọ Anh Đức
3116adf86e
Update check21
2020-03-09 12:46:16 +07:00
Ngọ Anh Đức
263926a53b
Improve check21
...
- Add ISLOGGING_STATUS, INCLUDEMANAGEMENTEVENTS_STATUS, READWRITETYPE_STATUS to check
- Remove ` --no-include-shadow-trails ` from CLI
2.1 Ensure CloudTrail is enabled in all regions (Scored):
Via CLI
1. ` aws cloudtrail describe-trails `
Ensure `IsMultiRegionTrail` is set to true
2. `aws cloudtrail get-trail-status --name <trailname shown in describe-trails>`
Ensure `IsLogging` is set to true
3. `aws cloudtrail get-event-selectors --trail-name <trailname shown in describetrails>`
Ensure there is at least one Event Selector for a Trail with `IncludeManagementEvents` set to
`true` and `ReadWriteType` set to `All`
2020-03-09 12:44:23 +07:00
Philipp Zeuner
cb5858d08a
Updated check_extra778 to use PROFILE_OPT and AWSCLI
2020-03-08 09:56:52 +01:00
Philipp Zeuner
1b2b52e6a7
Fixed check_extra778 reference CHECK_ID
2020-03-08 09:22:11 +01:00
Philipp Zeuner
f5d083f781
Updated check_extra778 to exclude 0.0.0.0/0 edge case
2020-03-08 09:21:17 +01:00
Philipp Zeuner
f585ca54d1
Fixed check_extra788 logic bug related to SECURITY_GROUP and improved check_cidr() isolation
2020-03-08 09:20:05 +01:00
Philipp Zeuner
f149fb7535
Refactored check name to check_extra778
2020-03-08 08:15:20 +01:00
Toni de la Fuente
530bacac5b
Merge pull request #510 from jonjozwiak/master
...
Improve performance of check_extra742 by limiting to one AWS CLI call per region
2020-03-05 21:33:26 +01:00
Toni de la Fuente
0b2c3c9f4f
Merge pull request #509 from nexeck/new_check_ecr_findings
...
fix: Enable check extra776 in extra group
2020-03-05 21:26:34 +01:00
jonjozwiak
8173c20941
Improve performance of check_extra742 by limiting to one AWS CLI call
2020-03-04 16:46:28 +02:00
Marcel Beck
95cb26fb2b
fix: Enable check extra776 in extra group
2020-03-04 07:27:40 +01:00
Toni de la Fuente
c0d8258283
[new check] Check if ECR image scan found vulnerabilities in the newest image version
...
[new check] Check if ECR image scan found vulnerabilities in the newest image version
2020-03-03 23:06:44 +01:00
Toni de la Fuente
4646dbcd0b
Updated check_extra776 title
2020-03-03 23:04:09 +01:00
Marcel Beck
db260da8b0
feat: New check for ecr image scan findings
...
This will check if there is any ecr image with findings.
2020-03-03 22:53:26 +01:00
Philipp Zeuner
162ff05e42
Updated check_extra777 to fix CHECK_ALTERNATE variable
2020-03-02 22:53:32 +01:00
Philipp Zeuner
6ea863ac3b
Initial commit
2020-03-01 20:26:51 +01:00
Toni de la Fuente
655aae7014
Merge pull request #499 from nexeck/check119_ignore_terminated
...
fix: check119 needs to ignore terminated instances
2020-02-28 18:51:52 +01:00
Marcel Beck
5257ce6c0b
docs: Fix typo
2020-02-28 17:58:10 +01:00
Marcel Beck
c9508c28b3
fix: check119 needs to ignore terminated instances
...
Terminated does not seem to have an instance profile. And its not
possible to start a terminated instance again.
2020-02-25 09:23:55 +01:00
Toni de la Fuente
50b10c4018
Minor fixes for checks 774 and 775
...
Faraz minor fixes
2020-02-24 18:53:20 +01:00
Faraz Angabini
2321655503
fixed check numbers for 774,775
2020-02-22 22:16:59 -08:00
Faraz Angabini
7358e9cd75
added .gitignore for .DS_Store
2020-02-22 22:12:44 -08:00
Faraz Angabini
020374b6f9
deleted .DS_Store
2020-02-22 22:10:52 -08:00
Toni de la Fuente
24cccf64d6
Merge branch 'fredski-github-master'
2020-02-21 15:32:47 +01:00
Toni de la Fuente
77f07cccf8
Merge branch 'master' of https://github.com/fredski-github/prowler into fredski-github-master
2020-02-21 15:31:23 +01:00
Kasprzykowski
40985212ab
check_extra775 added | group7_extras and group11_secrets updated
2020-02-21 09:24:13 -05:00
Toni de la Fuente
e461714226
Merge branch 'master' of https://github.com/toniblyx/prowler
2020-02-21 15:06:24 +01:00
Toni de la Fuente
11e5d44d9b
version 2.2.0
2020-02-21 15:06:13 +01:00
Kasprzykowski
a1d26b44c3
check_extra999 added and group7_extras updated
2020-02-21 09:05:33 -05:00
Toni de la Fuente
42af217524
Merge pull request #489 from TopherIsSwell/master
...
Extra 774 - Fixed bug - Erroneously checking account creation date
2020-02-21 14:44:21 +01:00
Christopher Morrow
4a1d4060ec
Check Extra 774 - Fixed bug - was checking account creation time instead of last logon date.
2020-02-20 15:11:13 -08:00
Toni de la Fuente
0210c43b60
Merge branch 'bridgecrewio-bugfix/check_11_check_access_keys_usage'
...
t push origin master:wq
2020-02-19 18:19:37 +01:00
Toni de la Fuente
ca34590da0
Merge branch 'bugfix/check_11_check_access_keys_usage' of https://github.com/bridgecrewio/prowler into bridgecrewio-bugfix/check_11_check_access_keys_usage
2020-02-19 18:14:37 +01:00
Toni de la Fuente
44716cfab2
Merge pull request #486 from bridgecrewio/bugfix/mark_only_available_rds_instances_as_violating
...
Filter for only available rds instances
2020-02-19 18:11:43 +01:00
Toni de la Fuente
1f3aaa8c7b
Merge pull request #485 from bridgecrewio/bugfix/es_public_domains_filter_condition
...
Add conditions check for extra716
2020-02-19 18:09:37 +01:00
Toni de la Fuente
6213a7418c
Merge pull request #484 from bridgecrewio/bugfix/public_bucket_policy_check_for_conditions
...
Add conditions check for extra771
2020-02-19 18:08:02 +01:00
Toni de la Fuente
bf9ffc0485
Merge pull request #483 from bridgecrewio/bugfix/extra748_check_for_all_ports
...
Check extra748 should fail in case of all ports (0-65535) open
2020-02-19 17:58:17 +01:00
Toni de la Fuente
fff605b356
Merge pull request #482 from bridgecrewio/bugfix/fix_extra_764_handle_all_aws
...
Check extra764 should also check for principal being AWS = "*"
2020-02-19 17:50:54 +01:00
Nimrod Kor
e41e77ed78
Remove unnecessary print
...
(cherry picked from commit 72bb29f13c )
2020-02-18 11:58:05 +02:00
Nimrod Kor
a6516e4af8
Check 1.1 - check password access and access key usage
...
(cherry picked from commit f62cde1bf1 )
2020-02-18 11:36:57 +02:00
Nimrod Kor
4fe575030b
Filter for only available rds instances
...
(cherry picked from commit 5a7356be3c )
2020-02-18 10:48:58 +02:00
Nimrod Kor
178a34e40d
Add conditions check for extra716
...
(cherry picked from commit 2ec6696897 )
2020-02-18 10:48:25 +02:00
Nimrod Kor
5f3293af1e
Add conditions check for extra771
...
(cherry picked from commit 805b276578 )
2020-02-18 10:28:36 +02:00
Nimrod Kor
28a8ae7572
Check extra748 should fail in case of all ports (0-65535) open
2020-02-18 10:26:44 +02:00
Nimrod Kor
daa26ed14c
extra764 should also check for principal being AWS = "*"
2020-02-18 10:20:13 +02:00
Toni de la Fuente
9bd54ca30e
Fixed issue #378
2020-02-12 23:46:42 +01:00
Toni de la Fuente
d832b11047
Merge branch 'alphad05-patch-1'
2020-02-12 23:22:44 +01:00
Toni de la Fuente
f99d35888a
Merge branch 'patch-1' of https://github.com/alphad05/prowler into alphad05-patch-1
2020-02-12 23:20:32 +01:00
Toni de la Fuente
4d683a7566
Merge branch 'bridgecrewio-fix-check11'
2020-02-12 23:15:30 +01:00
Toni de la Fuente
35fc8cd0bf
Merge branch 'fix-check11' of https://github.com/bridgecrewio/prowler into bridgecrewio-fix-check11
2020-02-12 23:13:49 +01:00
jonnyCodev
447657140d
check if last_login_date is a valid date
2020-02-12 10:16:18 +02:00
alphad05
5069fd29f9
Associate VPCFlowLog with VPC
...
Associate VPCFlowLow with the VPC it is for to ensure accurate check. If there are multiple VPCs in a region and only some have VPC flow logs, current check will pass all VPCs even those without VPC flow logs.
2020-02-11 20:55:30 -08:00
Toni de la Fuente
b9a4f2c4e8
Merge pull request #479 from nickmalcolm/patch-1
...
Remove `ses:sendemails`
2020-02-11 23:46:46 +01:00
Nick Malcolm
0d1807bd33
Remove ses:sendemails
...
Prowler doesn't need to send emails via SES. https://github.com/toniblyx/prowler/issues/124
2020-02-12 11:38:23 +13:00
Toni de la Fuente
a77d3b0361
Merge pull request #477 from toniblyx/revert-474-feature/handle_get_bucket_policy_error
...
Revert "Feature/handle get bucket policy error"
2020-02-10 23:31:23 +01:00
Toni de la Fuente
274d02576f
Revert "Feature/handle get bucket policy error"
2020-02-10 23:31:02 +01:00
Toni de la Fuente
5cebebba97
Merge pull request #474 from bridgecrewio/feature/handle_get_bucket_policy_error
...
Feature/handle get bucket policy error
2020-02-10 23:29:04 +01:00
Toni de la Fuente
092dc84186
Merge pull request #454 from zfLQ2qx2/prowler_check119
...
Add command for check119
2020-02-10 22:56:34 +01:00
Toni de la Fuente
528e14d4cf
Update check119
...
updated to not scored
2020-02-10 22:55:57 +01:00
Toni de la Fuente
9519539de3
Merge branch 'master' of https://github.com/toniblyx/prowler
2020-02-07 17:01:52 +01:00
Toni de la Fuente
1e1de4fa46
Added Security Hub integration link
2020-02-07 17:00:23 +01:00
jonnyCodev
fe2d2b45bb
check root account access login and fail if used in the last day
2020-02-06 11:10:10 +02:00
Or Evron
74cbbddc5c
add text info in case of error occurred
...
(cherry picked from commit b28917beb7 )
2020-02-06 09:37:16 +02:00
Or Evron
e575fcd6b2
typo
...
(cherry picked from commit eb4f336428 )
2020-02-06 09:37:16 +02:00
Or Evron
aca93b7526
typo
...
(cherry picked from commit b89f67bba1 )
2020-02-06 09:37:16 +02:00
Or Evron
029c330ed1
fix check extra 764
...
(cherry picked from commit 0db690ad5f )
2020-02-06 09:37:16 +02:00
Toni de la Fuente
4ecc9c929c
Merge pull request #473 from bridgecrewio/check-if-user-have-unused-login-more-then-30-days
...
Check if user have unused console login
2020-02-05 09:30:25 -05:00
jonnyCodev
2abe36083f
Update group7_extras
2020-02-05 15:55:09 +02:00
jonnyCodev
d473ebe3f2
moving MAX_DAYS to the inner scope of the function
2020-02-05 11:15:14 +02:00
jonnyCodev
a824e064b3
Check if user have unused console login
2020-02-04 14:39:42 +02:00
Toni de la Fuente
24780b4caa
Improve documentation with prowler-additions-policy.json, issue #468
2020-01-30 22:23:53 +00:00
Toni de la Fuente
b35350291f
Merge pull request #442 from dbellizzi/patch-1
...
add "lambda:GetAccountSettings",
"lambda:GetFunctionConfiguration",
"lambda:GetLayerVersionPolicy",
"lambda:GetPolicy",
"lambda:List*", to prowler-additions-policy
2020-01-27 18:07:05 -05:00
Toni de la Fuente
f038074e0c
Update prowler-additions-policy.json
2020-01-27 18:06:43 -05:00
Toni de la Fuente
f797805970
Merge pull request #463 from zfLQ2qx2/issue458
...
Rewrite of check extra73
2020-01-27 18:03:28 -05:00
Toni de la Fuente
ef001af1ec
Merge pull request #461 from zfLQ2qx2/issue459
...
Add additional error checking to address issue 459
2020-01-27 18:01:00 -05:00
Toni de la Fuente
2d712f6ab0
Merge pull request #457 from fayezgb/issue-163-CloudFront-WAF
...
Issue 163 cloud front waf
2020-01-27 17:59:30 -05:00
Toni de la Fuente
8b5733b5fe
Merge branch 'master' into issue-163-CloudFront-WAF
2020-01-27 17:59:13 -05:00
Toni de la Fuente
278e382f9a
Update group7_extras
2020-01-27 17:58:04 -05:00
Toni de la Fuente
425fe16752
Update and rename check_extra772 to check_extra773
2020-01-27 17:57:06 -05:00
Toni de la Fuente
3452ecdf03
Merge pull request #453 from zfLQ2qx2/prowler_eip_check
...
Add Prowler check for unused elastic IP addresses
2020-01-27 17:45:35 -05:00
Toni de la Fuente
e65a11bc27
Merge branch 'master' into prowler_eip_check
2020-01-27 17:44:59 -05:00
Toni de la Fuente
f2f82165ab
Merge pull request #462 from zfLQ2qx2/issue460
...
Remove check 766, dupe of check 765
2020-01-27 17:42:30 -05:00
C.J
f735de8836
Rewrite of check extra73
2020-01-26 03:00:45 -05:00
C.J
9fc0f6c61c
Remove check 766, dupe of check 765
2020-01-25 15:29:05 -05:00
C.J
41ccd4517b
Add additional error checking to address issue 459
2020-01-25 15:22:39 -05:00
Fayez Barbari
2f17cfbc30
Check if CloudFront is using a WAF
2020-01-20 17:14:52 -06:00
Toni de la Fuente
ab5968cbee
Merge pull request #452 from bgeesaman/remove-colors-json
...
Prevent colorization on Failed and Info
2020-01-20 22:03:47 +01:00
Toni de la Fuente
5f8c2328f1
Merge pull request #456 from fayezgb/cross-account
...
Use custom aws profile with Role to assume
2020-01-20 21:52:24 +01:00
Fayez Barbari
cc0b1bcf11
Merge pull request #1 from fayezgb/cross-account
...
Use custom aws profile with Role to assume
2020-01-20 14:47:08 -06:00
Fayez Barbari
f006c81e6a
Use custom aws profile with Role to assume
2020-01-20 14:36:01 -06:00
root
9ed7d75c44
Add command for check119
2020-01-12 17:40:41 -05:00
root
4c1d1887e4
Add Prowler check for unused elastic IP addresses
2020-01-10 15:47:15 -05:00
bgeesaman
cea0cfb47d
Prevent colorization on Failed and Info
2020-01-08 20:21:18 -05:00
Toni de la Fuente
754ff31ea3
Merge pull request #450 from lanhhuyet510/patch-1
...
Update README.md with jq install instructions
2020-01-08 09:15:25 +01:00
Toni de la Fuente
49ec898b9e
Update README.md
2020-01-08 09:14:21 +01:00
Ngọ Anh Đức
c2f541134b
Update README.md
...
Add jq package in requirements
2020-01-08 11:13:25 +07:00
Toni de la Fuente
b3b903959b
Merge pull request #446 from zfLQ2qx2/cleanup_temp_files
...
Try to make sure prowler cleans up its temporary files
2019-12-31 15:21:33 +01:00
Toni de la Fuente
4806d5fc78
Merge pull request #447 from zfLQ2qx2/update_check_extra764
...
Misc fixes to check extra764
2019-12-31 11:39:21 +01:00
Toni de la Fuente
a755ec806a
Merge pull request #444 from zfLQ2qx2/update_extra769
...
Add additional error checking to check extra769
2019-12-31 11:05:44 +01:00
Toni de la Fuente
3c703de4f4
Merge pull request #448 from zfLQ2qx2/update_check_extra726
...
Resolve issue with not_available state in results
2019-12-31 11:03:34 +01:00
root
7d324bed65
Resolve issue with not_available state in results
2019-12-30 14:43:51 -05:00
root
b22b0af2ce
Misc fixes to check extra764
2019-12-30 14:20:50 -05:00
root
4cc5cd1ab1
Try to make sure prowler cleans up its temporary files
2019-12-30 13:43:53 -05:00
Toni de la Fuente
f3bfe90587
Add native support for AssumeRole clean up issue #445
2019-12-30 18:32:00 +01:00
Toni de la Fuente
53ea126065
Add native support for AssumeRole issue #445
2019-12-30 18:30:25 +01:00
root
688f028698
Add additional error checkings to check extra769
2019-12-30 11:33:12 -05:00
Toni de la Fuente
74380a62d9
Merge pull request #443 from zfLQ2qx2/update_ecr_checks
...
Add error checking to checks extra77 and extra765
2019-12-30 16:31:27 +01:00
root
c84190c3d9
Add error checking to checks extra77 and extra765
2019-12-30 10:07:14 -05:00
Toni de la Fuente
42f15ce164
Merge pull request #441 from dbellizzi/master
...
Add quiet mode that only logs failures
2019-12-27 12:33:13 +01:00
Toni de la Fuente
23be47a9b6
Enhanced title for check extra723
2019-12-27 12:09:35 +01:00
Toni de la Fuente
ab75f19a62
Merge pull request #440 from bridgecrewio/feature/small_fixes_to_extra731_extra716
...
Small check fixes to extra716 & extra731
2019-12-27 12:02:55 +01:00
Toni de la Fuente
20b127f516
Added DS IAM actions
2019-12-26 16:34:24 +01:00
Dominick Bellizzi
cc5da42797
add lambda:get* to prowler-additions-policy
...
The check: 7.60 [extra760] Find secrets in Lambda functions code (Not Scored) (Not part of CIS benchmark)
errors by default, with the following:
An error occurred (AccessDeniedException) when calling the GetFunction operation: User: user/prowler is not authorized to perform: lambda:GetFunction on resource: arn:aws:lambda:eu-west-2:347708466071:function:ApiSimpleDelayDDMonitor
Adding this policy to be successfully run that check.
2019-12-18 14:53:09 -08:00
Dom Bellizzi
f979c7334f
Add quiet mode that only logs failures
2019-12-18 22:06:44 +00:00
Nimrod Kor
1087d60457
Small check fixes
...
(cherry picked from commit 70879ba1e0 )
2019-12-18 13:24:31 +02:00
Toni de la Fuente
d2b3e5ecdc
Added new checks to extras group
2019-12-17 10:44:38 +01:00
Toni de la Fuente
3db94a5a98
Merge pull request #429 from dbellizzi/patch-1
...
Add "access-analyzer:ListTagsForResource" to prowler-additions-policy…
2019-12-17 10:42:04 +01:00
Toni de la Fuente
0d120a4536
Merge pull request #437 from bridgecrewio/feature/check_bucket_policies_public_write
...
Check bucket policies public write
2019-12-17 10:41:35 +01:00
Toni de la Fuente
0ab5d87b8f
Merge pull request #433 from kmcquade/check/public-instance-with-instance-profile-attached
...
Added check_extra770, which checks for internet facing instances with an instance profile attached
2019-12-17 10:40:01 +01:00
Toni de la Fuente
39c7ea52c6
Add feature custom checks folder issue #439
2019-12-17 10:37:14 +01:00
Toni de la Fuente
933e4152cc
Merge pull request #435 from bridgecrewio/feature/fix_check26
...
Fix check26 - get the account ID from sts
2019-12-17 10:14:11 +01:00
Nimrod Kor
fc3f4e830e
Reuse ACCOUNT_NUM
2019-12-17 09:29:06 +02:00
Nimrod Kor
7e803bb6a9
Change to check 771
2019-12-15 18:18:02 +02:00
Nimrod Kor
2d5d551696
Initial commit
2019-12-15 18:18:02 +02:00
Nimrod Kor
8e1aa17a80
Fix check26 - get the account ID from sts
...
(cherry picked from commit ae20d9c5b7 )
2019-12-15 15:55:54 +02:00
Toni de la Fuente
dd5bf6c7f8
Merge pull request #432 from bridgecrewio/feature/fix_check21
...
Add trail count to check21 and fail if no trail exist
2019-12-13 14:22:14 +01:00
Dominick Bellizzi
7cb869ad33
use more generic access-analyzer:List*
2019-12-12 09:36:19 -08:00
Kinnaird McQuade
3b264d556b
Added check_extra770, which checks for internet facing instances with an Instance Profile attached.
2019-12-12 11:07:14 -05:00
Toni de la Fuente
e4a063f9d1
Merge pull request #430 from JohnVonNeumann/patch-1
...
UPDATE README.md - fix incorrect group flag
2019-12-12 10:19:28 +01:00
Nimrod Kor
559b0585dc
Add trail count to check21 and fail if no trail exist
...
(cherry picked from commit fcf28dfa70 )
2019-12-12 09:45:06 +02:00
JohnVonNeumann
2da125ff8b
UPDATE README.md - fix incorrect group flag
...
To run prowler with the cislevelx group you use '-g', not '-c'
2019-12-12 11:28:52 +11:00
Dominick Bellizzi
53f097c2af
Add "access-analyzer:ListTagsForResource" to prowler-additions-policy.json
...
check extra769 (Check if IAM Access Analyzer is enabled and its findings) requires this IAM permission
2019-12-06 14:49:36 -08:00
Toni de la Fuente
b6e34adc24
Fix issue #409
2019-12-05 12:52:19 +01:00
Toni de la Fuente
7b5ece8007
New check IAM Access Analyzer issue #428
2019-12-03 15:58:19 +01:00
Toni de la Fuente
fe65eaf373
New check ECS scan on push issue #427
2019-12-03 15:27:09 +01:00
Toni de la Fuente
4af3dc1254
Fix issue #426 updated base64 function
2019-12-02 15:26:48 +01:00
Toni de la Fuente
923fadbfa9
Merge pull request #425 from zfLQ2qx2/check-3xx-whitespace-tolerance
...
Make check3x more tolerant
2019-11-26 10:18:49 +01:00
Toni de la Fuente
3f68accf6f
Added missing file iam/prowler-additions-policy.json
2019-11-26 09:57:29 +01:00
zfLQ2qx2
25d1aa9126
Make check3x more tolerant
2019-11-26 00:56:52 -05:00
Toni de la Fuente
dce9d5c96d
Merge pull request #423 from barnhartguy/master
...
Update check_extra768
2019-11-25 10:03:27 +01:00
Toni de la Fuente
80c6900193
Merge pull request #424 from willthames/extra764_fix
...
Fix extra764 check
2019-11-25 10:01:51 +01:00
Will Thames
2e11e0a3f2
Fix extra764 check
...
Add missing bracket to prevent:
```
jq: error: syntax error, unexpected INVALID_CHARACTER, expecting $end (Unix shell quoting issues?) at <top-level>, line 1:
.Statement[]|select(((.Principal|type == "object") and .Principal.AWS == "*") or ((.Principal|type == "string") and
.Principal == "*")) and .Action=="s3:*" and (.Resource|type == "array") and (.Resource|map({(.):0})[]|has($arn)) and
(.Resource|map({(.):0})[]|has($arn+"/*")) and .Condition.Bool."aws:SecureTransport" == "false")
```
(line breaks added to reduce commit width)
2019-11-25 16:01:26 +10:00
barnhartguy
c630c02a26
Update check_extra768
...
fixed typo
2019-11-24 14:37:09 +02:00
Toni de la Fuente
e18cea213b
consolidated ProwlerReadOnlyPolicy and available json
2019-11-22 12:42:57 +01:00
Toni de la Fuente
8f91bfee24
clean up documentation and added info to check_sample
2019-11-22 11:59:03 +01:00
Toni de la Fuente
a191a4eae6
consolidated ProwlerReadOnlyPolicy and available json
2019-11-22 11:41:13 +01:00
Toni de la Fuente
ce7e07d66d
consolidated ProwlerReadOnlyPolicy and available json
2019-11-22 11:29:16 +01:00
Toni de la Fuente
ab5ed2c527
Merge pull request #421 from jonrau-at-aws/master
...
Update HIPAA language
2019-11-22 09:49:57 +01:00
Toni de la Fuente
c513e7af6c
Merge pull request #420 from bridgecrewio/feature/ecs_task_definition_secrets_check_contribute
...
Add ECS task definition environment variables check
2019-11-22 00:18:00 +01:00
Toni de la Fuente
2e1cead3a2
Merge pull request #419 from zfLQ2qx2/prowler-extra719
...
Filter out private zones in check extra719
2019-11-22 00:12:36 +01:00
Toni de la Fuente
5c8b0aa942
Merge pull request #418 from zfLQ2qx2/prowler-check726
...
Handle Trusted Advisor entitlement issue gracefully
2019-11-22 00:10:39 +01:00
Toni de la Fuente
15dda01842
Merge pull request #417 from zfLQ2qx2/prowler-misc-updates
...
Update extra764 and extra734, add .gitignore rules for vim
2019-11-22 00:09:35 +01:00
Nimrod Kor
d19ae27f7c
Fix merge issue
2019-11-21 12:48:17 -08:00
Nimrod Kor
b61af3a9eb
Add ECS task definition environment variables check
...
(cherry picked from commit 662f287dd6 )
2019-11-21 12:44:09 -08:00
zfLQ2qx2
687686c929
Filter out private zones in check extra719
2019-11-21 15:36:38 -05:00
zfLQ2qx2
94a90599bd
Handle Trusted Advisor entitlement issue gracefully
2019-11-21 15:17:03 -05:00
zfLQ2qx2
669469e618
Update extra764 and extra734, add .gitignore rules for vim
2019-11-21 14:56:13 -05:00
Jonathan Rau
73a5ee1bac
Update README.md
2019-11-21 12:38:31 -05:00
Jonathan Rau
0ff9806d70
Update README.md
2019-11-21 12:33:38 -05:00
Toni de la Fuente
961b79a4aa
Added extra767 for CloudFront field level encryption issue #425
2019-11-21 17:48:34 +01:00
Toni de la Fuente
264b84ae2a
Added check_extra765 ECR scanning issue #406
2019-11-21 00:52:18 +01:00
Toni de la Fuente
031b68adde
fixed typo in iam policy
2019-11-20 23:20:17 +01:00
Toni de la Fuente
d737193b98
Merge pull request #407 from zfLQ2qx2/prowler_misc_fixes
...
Misc prowler fixes
Add GetEbsEncryptionByDefault wherever Prowler policies are mentioned
Update Extra718 check to be aware of access denied responses
Update Extra726 check to be more verbose for non-failure items
Update Extra73 check to be aware of access denied responses
Update Extra734 check to be aware of access denied responses and parse policies with jq for better accuracy
Update Extra742 check for verbiage
Update Extra756 check for verbiage and parameter order
Update Extra761 check for failure scenarios (requires most recent awscli and addition to Prowler IAM policy)
Added Extra763 check to verify that object versioning is enabled on S3 buckets
Added Extra764 check to verify that S3 buckets enforce a secure transport policy
2019-11-20 22:03:02 +00:00
Toni de la Fuente
649192eb41
Merge pull request #411 from zfLQ2qx2/prowler-extra75-enhancement
...
Update extra75 to be aware of default security groups
2019-11-20 21:46:21 +00:00
Toni de la Fuente
f83ce78e8f
Merge pull request #410 from zfLQ2qx2/prowler-3x-checks
...
Update log metric filter checks to latest AWS CIS Foundations Benchmarks
2019-11-20 21:44:23 +00:00
zfLQ2qx2
054043d78e
Update extra75 to aware of default security groups
2019-11-20 00:09:35 -05:00
zfLQ2qx2
603ed0b16f
Update log metric filter checks to latest AWS CIS Foundations Benchmark and provide hints on how to remediate
2019-11-19 01:37:42 -05:00
zfLQ2qx2
3a893889b6
Misc prowler fixes
2019-11-13 22:49:32 -05:00
Toni de la Fuente
2e181920ab
Added pull request template
2019-11-05 11:07:09 +01:00
Toni de la Fuente
4f4591dc42
Added more install details and docker run
2019-10-29 23:36:39 +01:00
Toni de la Fuente
18e5c0b8ae
Merge pull request #404 from gabrielsoltz/check_extra731_jq
...
Extra 731 with JQ
2019-10-28 15:36:43 +01:00
Toni de la Fuente
e748275fc5
Merge pull request #403 from gabrielsoltz/check_extra727_smarter
...
Check extra727 smarter (SQS)
2019-10-28 15:35:45 +01:00
Toni de la Fuente
4ca5b53948
Merge pull request #401 from gabrielsoltz/extra73_smarter
...
Smarter extra73 (S3 Public Buckets)
2019-10-28 15:29:48 +01:00
gabrielsoltz
8bb1529c2a
jq_improvements
2019-10-25 16:46:36 +02:00
gabrielsoltz
61ef02ec50
reduce_api_calls
2019-10-25 16:42:59 +02:00
gabrielsoltz
fb45fa0c03
reduce_api_calls
2019-10-24 23:56:02 +02:00
gabrielsoltz
6a52ebe492
reduce_api_calls
2019-10-24 23:54:04 +02:00
gabrielsoltz
9b81fc0ac7
fix jq array
2019-10-24 23:30:34 +02:00
gabrielsoltz
508a9354b7
fix jq array
2019-10-24 23:28:58 +02:00
gabrielsoltz
63898690c8
remove_old_check
2019-10-24 13:25:18 +02:00
gabrielsoltz
d026ed5cac
improve_extra727
2019-10-24 13:22:26 +02:00
gabrielsoltz
529fc6421d
better_output
2019-10-23 15:04:22 +02:00
gabrielsoltz
7aa1573275
comments
2019-10-23 14:06:29 +02:00
gabrielsoltz
bb69f51456
comment
2019-10-23 14:03:49 +02:00
gabrielsoltz
5cadd0c2f2
remove_unused_variable
2019-10-23 14:03:08 +02:00
gabrielsoltz
df5def48d9
comments_and_fix
2019-10-23 13:45:20 +02:00
gabrielsoltz
5252518d97
extra73
2019-10-23 13:38:36 +02:00
Toni de la Fuente
231f0e6fb3
Merge pull request #400 from MrSecure/check762_cleanup
...
extra 7.62 - output cleanup
2019-10-22 17:48:04 +02:00
Mr. Secure
be0bc7aa65
extra 7.62 - output cleanup
...
- remove warnings about long execution
- update pass/fail text to help split on ':' for CSV post-processing
2019-10-22 10:35:48 -05:00
Toni de la Fuente
c460e351a4
Merge pull request #399 from MrSecure/obsolete_runtimes
...
Add check for unsupported lambda runtimes
2019-10-22 15:29:26 +02:00
Mr. Secure
827b1fdb3b
add region info to textFail,textPass output
2019-10-22 08:12:00 -05:00
Mr. Secure
23a7c7f393
fix spelling error in message
2019-10-21 18:07:56 -05:00
Mr. Secure
e683ea5384
fix over-quoting bug
2019-10-21 09:38:16 -05:00
Mr. Secure
2c531a2ffc
add check for unsupported lambda runtimes
2019-10-21 09:28:00 -05:00
Toni de la Fuente
e25ea9621b
Merge pull request #396 from ricoli/dockerfile-git-clone-cache-fix
...
replacing git clone with ADD as to not cache layer indefinetely
2019-10-17 22:11:27 +02:00
Ricardo Oliveira
826cc00a7c
replacing git clone with ADD as to not cache layer indefinetely
2019-10-16 09:56:44 +01:00
Toni de la Fuente
65f787bfe0
Merge pull request #397 from ricoli/fix-exclude-checks-from-group
...
fixing multiple exclusions overriding each other because of iteration
2019-10-15 18:17:19 +02:00
Ricardo Oliveira
77b3a9b4d9
unsetting excluded_checks
2019-10-15 11:12:59 +01:00
Toni de la Fuente
f8db025fdf
Merge pull request #395 from MrSecure/mega
...
Fix paths in multi-account code-build job
2019-10-14 23:17:33 +02:00
Mr. Secure
d4fad17416
update pipeline commands to use multi-account path
2019-10-14 15:42:09 -05:00
Mr. Secure
ddb498320a
bring in quoting nits
2019-10-14 15:39:33 -05:00
Toni de la Fuente
31a4024dfc
Merge pull request #392 from MrSecure/mega
...
WIP: MegaProwler Add-on
2019-10-14 18:13:23 +02:00
Toni de la Fuente
38c0b60141
Rename util/megaprowler.sh to util/multi-account/megaprowler.sh
2019-10-14 18:11:46 +02:00
Toni de la Fuente
81cc85a8fc
Rename util/config to util/multi-account/config
2019-10-14 18:11:24 +02:00
Toni de la Fuente
ffcfef02a6
Rename util/Audit_Pipeline.yaml to util/multi-account/Audit_Pipeline.yaml
2019-10-14 18:10:57 +02:00
Toni de la Fuente
27305365ef
Rename util/Audit_Exec_Role.yaml to util/multi-account/Audit_Exec_Role.yaml
2019-10-14 18:10:34 +02:00
Toni de la Fuente
08cd94fe5b
Merge pull request #391 from jcaffet/add/check_extra761
...
add extra761 check if EBS default encryption is enabled per region
2019-10-13 20:55:19 +02:00
Toni de la Fuente
40a2ea6c90
fixed region for extra757 and extra758
2019-10-13 19:05:57 +02:00
Jerome Caffet
7e28f85247
add cli options
2019-10-13 08:02:18 +02:00
Mr. Secure
64667ea9d0
grant codebuild the ability to assume audit role
2019-10-11 21:46:20 -05:00
Mr. Secure
70304dc2a2
suppress remaining shell check warnings
2019-10-11 21:16:17 -05:00
Mr. Secure
e0a77b3e46
cleanup using shellcheck
2019-10-11 21:12:24 -05:00
Mr. Secure
70de023114
more output structure cleanup
2019-10-11 20:30:59 -05:00
Mr. Secure
b5ccdad3dc
change bucket resource name
...
cleans up auto-generated bucket name
2019-10-11 20:21:07 -05:00
Mr. Secure
d0af7f439f
remove 'out' from artifact storage path
2019-10-11 20:10:30 -05:00
Mr. Secure
64e38dd843
bring in megaprowler code
2019-10-11 19:58:49 -05:00
Jerome Caffet
66c59ea1f7
add extra761 EBS default encryption
2019-10-09 14:33:46 +02:00
Toni de la Fuente
fc77b4a55e
Merge pull request #390 from Quiq/master
...
Add missing permission
2019-10-02 14:37:16 -04:00
Roman Vynar
4540fd77e6
Add missing permission
2019-10-02 21:17:52 +03:00
Toni de la Fuente
d415ea6f20
restore docs
2019-09-19 15:25:00 -04:00
Toni de la Fuente
ec8f51ba8a
readthedocs initial commit
2019-09-19 14:40:31 -04:00
Toni de la Fuente
ad49d2accb
readthedocs initial commit
2019-09-19 14:33:42 -04:00
Toni de la Fuente
67311e84d2
Delete index.rst
2019-09-19 14:30:21 -04:00
Toni de la Fuente
8f566ec690
Create index.rst
2019-09-19 14:25:38 -04:00
Toni de la Fuente
75f6cbbdd6
Merge pull request #384 from venky999/master
...
fixing #383 and #380
2019-09-17 14:54:31 -04:00
Toni de la Fuente
4401d4209c
CURRENT_ACCOUNT_ID is not needed
...
since ACCOUNT_ID is available
2019-09-17 14:52:30 -04:00
Venki
44cfa71358
updated logging
2019-09-16 09:24:34 +01:00
Venki
ecde62451c
remove unnecessary variables and removed echo
2019-09-16 09:16:59 +01:00
Venkatadri Duggina
d5f22ab100
fixing check26 cross access bug
2019-09-15 23:33:37 +01:00
Venkatadri Duggina
72b1421294
fixing cross account cloudtrail issue
2019-09-14 22:10:45 +01:00
Toni de la Fuente
04acb7412b
Enhanced requirements and installation
2019-09-12 19:13:52 -04:00
Toni de la Fuente
0327880258
Merge pull request #376 from mastertinner/372
...
List CloudFront distributions only once
2019-09-13 00:09:37 +02:00
Toni de la Fuente
6a9f32a284
Merge pull request #375 from mastertinner/373
...
List successful cases as PASS! for 7.27
2019-09-13 00:08:17 +02:00
Toni de la Fuente
3079bd51f3
Merge pull request #382 from venky999/master
...
fixing check3x bug 381 related to cloudwatch groups
2019-09-13 00:08:00 +02:00
Venki
dffb09b001
updating tr
2019-09-12 12:24:49 +01:00
Venkatadri Duggina
5e4eba54cc
fixing check3x bug 381 related to cloudwatch groups
2019-09-11 15:53:20 +01:00
Toni de la Fuente
84d69ef5d8
Merge pull request #377 from bfallik/patch-1
...
fix typo
2019-09-06 14:20:09 -04:00
Brian Fallik
cd52bf8b7d
fix typo
2019-08-23 15:04:02 -04:00
Tobi Fuhrimann
aba697aa99
List CloudFront distributions only once
...
Fixes #372
2019-08-23 09:13:33 +02:00
Toni de la Fuente
18be522b87
Merge pull request #370 from shaunography/master
...
Fix Pipfile for equal or newer versions
2019-08-23 15:01:08 +08:00
Tobi Fuhrimann
49994d1c51
List successful cases as PASS! for 7.27
...
Fixes #373
2019-08-23 08:57:21 +02:00
shaunography
f3d617a1c8
Fix Pipfile
2019-08-21 19:34:14 +01:00
Toni de la Fuente
de5b87c6ad
Merge pull request #366 from mastertinner/master
...
Make 3.x tests simpler and more useful
2019-08-18 14:03:48 +08:00
Tobi Fuhrimann
f32b76987e
Make 3.x tests simpler and more useful
2019-08-17 20:07:03 +02:00
Toni de la Fuente
1be58e02b2
Fix issue #323
2019-08-17 20:13:34 +08:00
Toni de la Fuente
8333c575ae
Fixed issue #348 -e option back to work
2019-08-17 15:18:44 +08:00
Toni de la Fuente
02d2561d6b
Fix issue #354
2019-08-17 12:57:48 +08:00
Toni de la Fuente
30b2f55ba1
Merge pull request #365 from rjnienaber/support_role_added_to_groups
...
Allow check 1.20 to evaluate users, groups or roles
2019-08-17 12:19:58 +08:00
Toni de la Fuente
253fa5ef54
Merge pull request #352 from FoxAndDuckSoftware/351
...
Ability to exclude check(s) from group run
2019-08-17 12:10:11 +08:00
Toni de la Fuente
188a681cb5
Merge pull request #350 from ralphrodkey/check314_case_sensitivity
...
Made check314 less case sensitive
2019-08-17 12:06:40 +08:00
Toni de la Fuente
1fb8b47a9c
Merge pull request #342 from mapete94/master
...
adding regex for wildcard option in cloudtrail extra 720
2019-08-17 11:49:59 +08:00
Toni de la Fuente
2afdabf9bc
Merge pull request #367 from toniblyx/revert-340-fix_check_extra741
...
Revert "ignore None when user data is empty (gunzip: invalid magic)"
2019-08-17 11:33:20 +08:00
Toni de la Fuente
3a989516d1
Revert "ignore None when user data is empty (gunzip: invalid magic)"
2019-08-17 11:32:12 +08:00
Toni de la Fuente
9e06297d5f
Merge pull request #340 from gabrielsoltz/fix_check_extra741
...
ignore None when user data is empty (gunzip: invalid magic)
2019-08-17 11:23:50 +08:00
Toni de la Fuente
1789dab4df
Merge branch 'master' into fix_check_extra741
2019-08-17 11:12:11 +08:00
Toni de la Fuente
eecb272f93
Fixed output for PR #339
2019-08-17 11:01:30 +08:00
Toni de la Fuente
2ed3378556
Merge pull request #339 from gabrielsoltz/refactor_check_extra734
...
refactor check_extra734
2019-08-17 10:48:24 +08:00
Toni de la Fuente
bd9ae4bce7
Merge pull request #336 from gabrielsoltz/improve_check_extra73
...
Fix check extra73
2019-08-17 10:42:46 +08:00
Toni de la Fuente
459a688b7a
Merge pull request #362 from koflTW/master
...
[FIX] allow 1.22 checks on policies with only one statement block
2019-08-17 10:21:40 +08:00
Richard Nienaber
30e2360acc
remove filter by roles so that groups are included as well
2019-08-15 13:09:36 +01:00
Toni de la Fuente
d8c29cc263
Merge pull request #363 from james-portman-contino/patch-1
...
Stop colorizing the JSON output
2019-08-08 20:25:55 +08:00
james-portman-contino
7313628cc6
Stop colorizing the JSON output
...
If using a terminal then jq prints out JSON with color.
I suggest color should either be disabled always or with some other flag (more complicated)
jq flag: -M monochrome (don't colorize JSON);
2019-08-08 08:50:28 +01:00
Kim Oliver Fehrs
033e2623d3
[FIX] remove duplicated filter condition | kf/aa/if
2019-08-07 16:13:36 +02:00
Kim Oliver Fehrs
2b95f69fa6
[FIX] allow 1.22 checks on policies with only one statement block | kf/aa/if
2019-08-07 16:06:51 +02:00
Toni de la Fuente
0ebdb1698f
Merge pull request #357 from bridgecrewio/master
...
create Pipfile
2019-07-13 21:59:56 -04:00
Barak Schoster Goihman
50d8359022
Merge pull request #1 from bridgecrewio/create-pipfile
...
Create Pipfile
2019-07-14 01:07:41 +03:00
Barak Schoster Goihman
4bc64e938e
Create Pipfile
...
add python dependencies
2019-07-14 01:07:21 +03:00
Toni de la Fuente
8f852457ff
Merge pull request #353 from kpawloski/patch-1
...
Fix typo
2019-07-11 22:58:43 -03:00
Kevin Pawloski
5bd3f0b995
Fix typo
...
Fix a small typo in the messaging.
2019-07-11 18:04:45 -07:00
Martin Kemp
e5e5e84112
Add documentation for excluding group checks
2019-07-10 13:15:10 +01:00
Martin Kemp
a430ad421b
Tabs to 4 spaces
2019-07-10 12:57:32 +01:00
Martin Kemp
58fdd45424
Ability to exclude check from group run
...
Fixes #351
2019-07-10 12:46:51 +01:00
Ralph Rodkey
85dc0408c2
Made check314 less case sensitive
2019-07-09 10:58:07 -04:00
Toni de la Fuente
c037067be2
Merge pull request #346 from nomex/add_detect_secrets_to_docker
...
Fixing missing &&
2019-07-04 05:36:15 -03:00
David Lladro
4fa48671e0
Merge branch 'master' into add_detect_secrets_to_docker
2019-07-04 08:45:35 +02:00
David Lladro
a259571cb0
Fixing missing &&
2019-07-04 08:38:25 +02:00
Toni de la Fuente
8b2c113614
Merge pull request #344 from nomex/add_detect_secrets_to_docker
...
Adding detect_secrets support to Docker
2019-06-28 17:23:29 -03:00
David Lladro
e273ae3123
Adding detect_secrets support to Docker
2019-06-27 15:27:19 -05:00
Michael Peterson
e04c34986e
adding regex for wildcard option in cloudtrail
2019-06-25 13:45:52 -04:00
Toni de la Fuente
ea6d9c93fc
Integration with Yelp detect-secrets
2019-06-25 08:28:50 -04:00
gabrielsoltz
cea45f43c8
remove REGION from Bucket Listing
2019-06-20 17:36:15 +02:00
gabrielsoltz
d7d2246498
improved for other file types like empty and very short
2019-06-19 14:58:18 +02:00
gabrielsoltz
e6992e87ee
ignore None when user data is empty
2019-06-18 12:59:58 +02:00
gabrielsoltz
c8622bc347
better check denied
2019-06-13 14:32:19 +02:00
gabrielsoltz
76e6657e42
refactor check_extra734
2019-06-13 14:12:43 +02:00
gabrielsoltz
de8336092b
fix locations
2019-06-13 12:05:39 +02:00
gabrielsoltz
d50c3afebd
add check for explicit deny
2019-06-13 12:04:52 +02:00
Toni de la Fuente
f54bc4238e
Merge branch 'master' of https://github.com/toniblyx/prowler
2019-06-12 10:14:22 +02:00
Toni de la Fuente
c7320ec7e2
Added comment to clarify change
2019-06-12 10:13:58 +02:00
Toni de la Fuente
a5ea0f59b2
Merge pull request #335 from gabrielsoltz/age_checks
...
improve AWS CLI parameters order, same as other checks (extra757 and extra758)
2019-06-12 03:35:39 -04:00
Toni de la Fuente
3947ee2aae
Improved -l option to list uniq checks
2019-06-11 20:37:18 +02:00
gabrielsoltz
0db97d5a24
improve AWS CLI parameters order, same as other checks
2019-06-11 20:36:40 +02:00
Toni de la Fuente
588976ac45
Fixed lack of in PR #331
2019-06-11 19:31:07 +02:00
Toni de la Fuente
6eb68a1218
Merge pull request #331 from gabrielsoltz/age_checks
...
New ec2 age checks
2019-06-11 13:21:18 -04:00
gabrielsoltz
b1e7dc8519
get_date_previous_than_months compatible busybox
2019-06-11 17:09:28 +02:00
gabrielsoltz
c5f170307d
add linux and cygwin get_date_previous_than_months function
2019-06-11 12:08:48 +02:00
Toni de la Fuente
e8b59b6722
Merge pull request #332 from gabrielsoltz/fix_extra731
...
fix extra731 output
2019-06-07 12:55:01 -04:00
Toni de la Fuente
ea886b84f2
Merge pull request #334 from gabrielsoltz/guardduty_regions
...
add guardduty regions
2019-06-07 12:54:32 -04:00
gabrielsoltz
89268e4875
textInfo
2019-06-07 05:51:26 +01:00
gabrielsoltz
8ee06449b7
fix code
2019-06-07 05:49:47 +01:00
gabrielsoltz
a09055ff31
fix
2019-06-06 21:35:52 +01:00
gabrielsoltz
d640086112
add guardduty regions
2019-06-06 21:26:10 +01:00
gabrielsoltz
5037cb03f2
improve code
2019-06-06 21:07:57 +01:00
gabrielsoltz
085dd338f4
function os
2019-06-06 21:04:40 +01:00
Toni de la Fuente
5a0366382b
Merge pull request #333 from gabrielsoltz/fix_check121
...
Review outputs, credentials never used are a FAIL now
2019-06-06 15:58:20 -04:00
gabrielsoltz
c4ddb8f14a
review outputs
2019-06-06 19:42:55 +01:00
gabrielsoltz
df6c323a64
fix extra731 output
2019-06-06 19:37:10 +01:00
gabrielsoltz
40117ed5dd
new ec2 age checks
2019-06-06 19:22:26 +01:00
Toni de la Fuente
2012bbb119
Merge pull request #328 from gabrielsoltz/master
...
check43: iterate across all default sg
2019-06-05 21:58:56 -04:00
gabrielsoltz
004f882a1d
iterate across all default sg, so fail more for each one and also add output sg
2019-05-23 17:19:56 +02:00
Toni de la Fuente
7bf636bfc7
Add new checks to group extras
2019-05-16 16:15:13 -04:00
Toni de la Fuente
b8c79154cb
Added check extra756 Redshift cluster public
2019-05-16 15:41:29 -04:00
Toni de la Fuente
5cd7214f21
Added check extra755 open Memcached port
2019-05-16 15:40:48 -04:00
Toni de la Fuente
4f00760e88
Added check extra754 open Cassandra port
2019-05-16 15:40:23 -04:00
Toni de la Fuente
660b573d05
Added check extra753 open MongoDB port
2019-05-16 15:40:00 -04:00
Toni de la Fuente
1d45c45afa
Added check extra752 open Redis prt
2019-05-16 15:39:30 -04:00
Toni de la Fuente
3693ee3692
Added check extra751 SG open Postgres port
2019-05-16 15:38:41 -04:00
Toni de la Fuente
c36a6067fa
Added check extra750 SG open MySQL ports
2019-05-16 15:38:00 -04:00
Toni de la Fuente
5325bab0ab
Added check extra750 SG open MySQL ports
2019-05-16 15:02:06 -04:00
Toni de la Fuente
e283d3587b
Added check extra749 SG open Oracle ports
2019-05-16 14:57:48 -04:00
Toni de la Fuente
b95cf5bc7b
Added check extra748 SG open to any port
2019-05-16 14:48:00 -04:00
Toni de la Fuente
c6dfbfd0ec
Added IPv6 support to networking checks
2019-05-16 14:38:11 -04:00
Toni de la Fuente
62991cfb48
Added exttra747 RDS CloudWatch Log integration
2019-05-15 23:31:25 -04:00
Toni de la Fuente
8b4b59e9d5
Added extra739 RDS backup and RDS group of checks
2019-05-15 23:12:06 -04:00
Toni de la Fuente
303cdc7acd
Merge branch 'master' of https://github.com/toniblyx/prowler
2019-05-14 20:46:17 -04:00
Toni de la Fuente
3275713aa8
Added new apigateway checks to extras
2019-05-14 20:45:56 -04:00
Toni de la Fuente
08cdf3511f
Added CODE_OF_CONDUCT.md
2019-05-14 15:05:21 -04:00
Toni de la Fuente
f28c4330b4
Merge branch 'master' of https://github.com/toniblyx/prowler
2019-05-13 17:02:16 -04:00
Toni de la Fuente
a6569a0a70
Added group12 apigateway checks
2019-05-13 17:01:45 -04:00
Toni de la Fuente
959bd8dfd4
Changed version to 2.0.2
2019-05-13 17:01:17 -04:00
Toni de la Fuente
a59aedc43b
Fixed accuracy for check_extra722
2019-05-13 17:00:56 -04:00
Toni de la Fuente
50b6e630d8
Added extra746 API Gateway has authorizers
2019-05-13 16:39:37 -04:00
Toni de la Fuente
da25a02e80
removed extra746 duplicated with extra722
2019-05-13 16:33:38 -04:00
Toni de la Fuente
967fe029c2
Fixed new API Gateway checks alias
2019-05-13 16:30:03 -04:00
Toni de la Fuente
3582b424b0
Added extra747 API Gateway has CloudWatch Logs
2019-05-13 16:29:28 -04:00
Toni de la Fuente
65e2ff7951
Added extra746 API Gateway has authorizers
2019-05-13 15:52:48 -04:00
Toni de la Fuente
ab66211f9b
Merge pull request #326 from RyPeck/patch-1
...
Update README.md to clone from right repo
2019-05-13 15:08:07 -04:00
Ryan John Peck
8e71c6e5c5
Update README.md to clone from right repo
...
Looks like the project was moved out of an org to your personal account.
2019-05-13 13:56:12 -04:00
Toni de la Fuente
504a11bb2e
Added extra745 API Gateway public or private
2019-05-07 00:03:23 -04:00
Toni de la Fuente
f03eccf6c8
Added extra744 API Gateway has a WAF ACL attached
2019-05-06 23:25:14 -04:00
Toni de la Fuente
d0789859a3
Added extra743 API Gateway has client certificate enabled
2019-05-06 23:21:27 -04:00
Toni de la Fuente
1b4045d57c
Added extra743 API Gateway has client certificate enabled
2019-05-06 23:10:27 -04:00
Toni de la Fuente
f406b4bbcf
Merge pull request #322 from toniblyx/devel
...
Devel
2019-04-29 22:34:22 -04:00
Toni de la Fuente
d9ced05d25
Merge pull request #321 from soffensive/devel
...
Separate handling of S3 default encryption and bucket policy encryption
2019-04-29 22:08:04 -04:00
soffensive
f5708d7db6
Separate default encryption and bucket policy encryption
...
Default encryption (2017): https://aws.amazon.com/blogs/aws/new-amazon-s3-encryption-security-features/
Bucket policy (2016): https://aws.amazon.com/blogs/security/how-to-prevent-uploads-of-unencrypted-objects-to-amazon-s3/
2019-04-29 16:31:42 +02:00
Toni de la Fuente
6dd0ab06d2
Merge pull request #319 from toniblyx/devel
...
Devel
2019-04-23 23:21:47 -04:00
Toni de la Fuente
42220828ce
Fixed issue #317
2019-04-23 23:20:11 -04:00
Toni de la Fuente
4527522acb
Merge pull request #314 from soffensive/devel
...
Iterate over all regions for Cloudtrail Checks check21 and check22
2019-04-23 23:01:43 -04:00
Toni de la Fuente
b4c4a46cc6
Fixed issue #315
2019-04-23 11:32:56 -04:00
soffensive
e0d86c134a
Iterate over all regions
...
Iterate over all regions
2019-04-17 13:38:12 +02:00
soffensive
7a44b8bcca
Iterate over all regions
...
Iterate over all regions
2019-04-17 13:36:00 +02:00
Toni de la Fuente
a707b382b0
Revert adding freebsd detector
2019-04-08 22:15:22 -04:00
Toni de la Fuente
fff424dbfa
Label v2.0.1
2019-04-08 21:58:01 -04:00
Toni de la Fuente
2870f38bdc
Merge pull request #312 from toniblyx/devel
...
Devel for 2.0.1
2019-04-09 02:51:04 +01:00
Toni de la Fuente
1956be4dc3
Delete duplicate check extra739
2019-04-09 02:49:55 +01:00
Toni de la Fuente
e4cf874c5c
Merge pull request #311 from artashus/master
...
Fixed check122 to match CIS 1.22 checks requirements, instead of '=~ …
2019-04-09 02:32:25 +01:00
Toni de la Fuente
a2ccac97d9
Make it work in FreeBSD issue #310
2019-04-08 21:18:39 -04:00
Artashes Arabajyan
917a323c15
Fixed check122 to match CIS 1.22 checks requirements, instead of '=~ *' use '== *'
2019-04-05 12:06:27 +02:00
Toni de la Fuente
ddad72fc5f
Fix issue #309
2019-03-27 22:42:13 +00:00
Toni de la Fuente
b03aca80a1
Fixed issue #308
2019-03-27 22:35:50 +00:00
Toni de la Fuente
9d526ff098
Added group11 keys and improved 741 and 742
2019-03-12 23:14:50 -04:00
Toni de la Fuente
bde9482928
Added check extra742 to find keys in CloudFormation Outputs
2019-03-12 22:40:40 -04:00
Toni de la Fuente
07f426aec0
Merge pull request #306 from nicdoye/devel
...
Merge RUNs. Run as non-root. Added jq
2019-03-12 10:05:38 -04:00
Toni de la Fuente
3b2f5522fd
Merge branch 'devel' into devel
2019-03-12 10:00:52 -04:00
Nic Doye
ea89242644
Merge RUNs. Run as non-root
2019-03-12 13:52:42 +00:00
Toni de la Fuente
da9cb41b3b
Added jq to Dockerfile and fixes
2019-03-12 09:44:34 -04:00
Toni de la Fuente
bc9d4fe762
Created a new Dockerfile based on Alpine
2019-03-11 23:59:02 -04:00
Toni de la Fuente
ec05e2f0f4
Merge pull request #305 from toniblyx/devel
...
Fix issue #301
2019-03-11 22:45:15 -04:00
Toni de la Fuente
fa1a3b8406
Fix issue #301
2019-03-11 22:44:00 -04:00
Toni de la Fuente
a3d1ed5129
Merge pull request #304 from toniblyx/devel
...
Devel
2019-03-11 22:27:07 -04:00
Toni de la Fuente
e284dd3afc
Merge pull request #302 from mindfulmonk/patch-1
...
Update cislevel names README.md
2019-03-11 22:20:36 -04:00
Toni de la Fuente
c8cc343784
Fix issue #303
2019-03-11 22:12:54 -04:00
Toni de la Fuente
6d15bb67fe
Fix issue #300
2019-03-11 22:10:37 -04:00
Toni de la Fuente
b60d320622
Improved tittle to describe what extra71 does
2019-03-11 22:09:12 -04:00
Marcus Maxwell
3290563716
Update README.md
2019-03-07 09:21:15 +00:00
Marcus Maxwell
4c0c6b181b
Update README.md
2019-03-07 09:18:57 +00:00
Marcus Maxwell
10a99aa5ae
Update README.md
...
-c is only for individual checks, need to use -g for level1 checks.
2019-03-07 09:11:12 +00:00
Toni de la Fuente
7117399e14
Added find creds in URL on extra741
2019-03-05 11:40:29 -05:00
Toni de la Fuente
6f678a1093
Merge pull request #298 from toniblyx/devel
...
Devel
2019-03-04 22:45:58 -05:00
Toni de la Fuente
bc1271788c
Added MFA help to README issue #294
2019-03-04 22:45:15 -05:00
Toni de la Fuente
9d88a27e0a
Merge branch 'devel' of https://github.com/toniblyx/prowler into devel
2019-03-04 22:25:22 -05:00
Toni de la Fuente
2bc3575de8
Improved extra714 to find secrets
2019-03-04 22:25:04 -05:00
Toni de la Fuente
18e9e7f0e1
Merge pull request #297 from toniblyx/devel
...
Devel
2019-03-04 21:26:29 -05:00
Toni de la Fuente
327323e32f
Merge pull request #295 from clintmoyer/spellcheck
...
Spelling fix "reshift" means "redshift"
2019-02-20 18:11:31 -05:00
Clint Moyer
3c2ad65246
Spelling fix "reshift" means "redshift"
2019-02-20 12:30:04 -07:00
Toni de la Fuente
069b54057b
Fixed typo in hipaa
2019-02-11 09:08:05 -05:00
Toni de la Fuente
edf7826121
Fixed typo on hipaa
2019-02-11 09:07:27 -05:00
Toni de la Fuente
be4bbe4430
New POC scoring and extra741 key finder userdata
2019-02-08 16:47:51 +00:00
Toni de la Fuente
9bf3fd87ac
New POC scoring and extra741 key finder userdata
2019-02-08 16:47:12 +00:00
Toni de la Fuente
11c7d55203
New POC scoring and extra741 key finder userdata
2019-02-08 16:39:57 +00:00
Toni de la Fuente
170557a422
New POC scoring and extra741 key finder userdata
2019-02-08 16:39:05 +00:00
Toni de la Fuente
5b0c6f8689
Merge pull request #290 from tomcrawf90/master
...
Added check for integer in response from AWS
2019-02-04 22:55:24 +00:00
tomcrawf90
17f00f167f
Merge pull request #1 from tomcrawf90/check111fix
...
Added check for integer in response from AWS
2019-02-04 17:08:49 +00:00
Tom Crawford
34b6c4446d
Added check for integer in response from AWS
2019-02-04 17:01:37 +00:00
Toni de la Fuente
6600df9be9
extra741 finding keys in UserData
2019-01-29 06:09:37 +00:00
Toni de la Fuente
8f89a01541
Merge pull request #284 from toniblyx/devel
...
Devel
2019-01-07 22:15:28 -05:00
Toni de la Fuente
b59d5db16b
Added new opton exclude to README
2019-01-07 22:12:01 -05:00
Toni de la Fuente
2e754a5370
Fixed check120
2019-01-07 22:06:34 -05:00
Toni de la Fuente
2f9886efe2
Merge pull request #283 from SDugo/master
...
New option "-E" supports exclusion of one or multiple checks
2018-12-21 09:06:58 -05:00
Samuel Dugo
71355b0c4c
New option "-E" supports exclusion of one or multiple checks
...
Added new option "-E" which will execute all tests except a list of specified checks separated by comma (i.e. check21,check31). Any invalid check name will be discarded. And if just one argument is passed and this is invalid, then Prowler will execute all checks.
To save space, the option will return a list of total checks excluding the list provided. Then, the functionality will overwrite CHECK_ID with the final list and the program will continue as if the user entered "-c" option and the final list of checks.
2018-12-21 12:14:10 +01:00
Toni de la Fuente
1203700d34
Merge pull request #282 from toniblyx/devel
...
Devel
2018-12-19 23:57:26 -05:00
Toni de la Fuente
97a59cf5e4
Merge pull request #276 from affanhmalik/check29
...
Check for flowlogs only in active VPCs, avoid false flag if a region …
2018-12-19 23:53:42 -05:00
Toni de la Fuente
8a3893cd33
Merge pull request #281 from SDugo/master
...
Option "-c" supports one or multiple checks
2018-12-19 23:50:57 -05:00
Toni de la Fuente
1fc2b77bfb
Merge pull request #278 from SatanicMechanic/patch-1
...
Update check_extra739
2018-12-19 23:49:53 -05:00
Samuel Dugo
00e5e65176
Option "-c" supports one or multiple checks
...
Added support for option "-c" to specify one or multiple specific checks to be performed. To specify multiple tests include them using a comma delimiter (i.e. check21,check22).
2018-12-19 17:05:13 +01:00
Morey Straus
8935233a05
Update check_extra739
...
typo correction
2018-12-14 14:32:38 -08:00
Toni de la Fuente
c9c4620988
format fix
2018-12-13 18:14:31 +01:00
Toni de la Fuente
2700365101
Improved README and change rules ID
2018-12-13 18:13:18 +01:00
Affan Malik
bacdf6ed22
Check for flowlogs only in active VPCs, avoid false flag if a region has no VPCs
2018-12-12 15:09:31 -05:00
Toni de la Fuente
30cac002fa
Wazuh integration guide DRAFT
2018-12-05 14:41:07 +00:00
Toni de la Fuente
d818381bcf
Wazuh integration guide DRAFT
2018-12-05 14:38:39 +00:00
Toni de la Fuente
d78424b346
gdpr fix
2018-12-05 12:00:38 +00:00
Toni de la Fuente
1727758479
enhanced gdpr and first wazuh integration bits
2018-12-05 11:58:43 +00:00
Toni de la Fuente
9e0923407e
Merge branch 'devel' of https://github.com/toniblyx/prowler into devel
2018-12-05 11:55:51 +00:00
Toni de la Fuente
79e02ce074
Merge pull request #271 from toniblyx/devel
...
Fixed bug in check extra730: certs expiration
2018-12-05 11:52:19 +00:00
Toni de la Fuente
b4cb323de4
Merge pull request #270 from SDugo/master
...
Fixed AccessDeniedException on extra730
2018-12-05 11:49:41 +00:00
Samuel Dugo
573fa46aac
Fixed AccessDeniedException on extra730
...
When executing Prowler using a specific profile (in my case to assume a role) , check_extra730 returns:
"An error occurred (AccessDeniedException) when calling the DescribeCertificate operation: User: [ASSUMED_ROLE_ARN] is not authorized to perform: acm:DescribeCertificate on resource: [RESOURCE_ARN]"
This is because line 28 did not contain the following parameters: "$PROFILE_OPT --region $regx" .
2018-12-05 11:35:44 +01:00
Toni de la Fuente
be29f2f0d9
version and extras last addition
2018-11-26 23:22:05 -05:00