Commit 5830cb6
authored
File tree
230 files changed
+253
-251
lines changed- prowler
- providers/aws/services
- accessanalyzer/accessanalyzer_enabled_without_findings
- account
- account_maintain_current_contact_details
- account_maintain_different_contact_details_to_security_billing_and_operations
- account_security_contact_information_is_registered
- account_security_questions_are_registered_in_the_aws_account
- acm/acm_certificates_expiration_check
- apigatewayv2/apigatewayv2_api_access_logging_enabled
- apigateway
- apigateway_restapi_logging_enabled
- apigateway_restapi_tracing_enabled
- athena/athena_workgroup_encryption
- autoscaling
- autoscaling_group_capacity_rebalance_enabled
- autoscaling_group_elb_health_check_enabled
- autoscaling_group_launch_configuration_requires_imdsv2
- autoscaling_group_multiple_az
- autoscaling_group_multiple_instance_types
- autoscaling_group_using_ec2_launch_template
- awslambda
- awslambda_function_inside_vpc
- awslambda_function_not_publicly_accessible
- awslambda_function_url_public
- awslambda_function_using_supported_runtimes
- backup/backup_vaults_encrypted
- bedrock
- bedrock_agent_guardrail_enabled
- bedrock_guardrail_prompt_attack_filter_enabled
- bedrock_guardrail_sensitive_information_filter_enabled
- bedrock_model_invocation_logging_enabled
- cloudformation/cloudformation_stacks_termination_protection_enabled
- cloudfront
- cloudfront_distributions_custom_ssl_certificate
- cloudfront_distributions_default_root_object
- cloudfront_distributions_field_level_encryption_enabled
- cloudfront_distributions_geo_restrictions_enabled
- cloudfront_distributions_https_enabled
- cloudfront_distributions_https_sni_enabled
- cloudfront_distributions_logging_enabled
- cloudfront_distributions_multiple_origin_failover_configured
- cloudfront_distributions_origin_traffic_encrypted
- cloudfront_distributions_s3_origin_access_control
- cloudfront_distributions_s3_origin_non_existent_bucket
- cloudfront_distributions_using_deprecated_ssl_protocols
- cloudfront_distributions_using_waf
- cloudtrail
- cloudtrail_bucket_requires_mfa_delete
- cloudtrail_cloudwatch_logging_enabled
- cloudtrail_kms_encryption_enabled
- cloudtrail_log_file_validation_enabled
- cloudtrail_logs_s3_bucket_is_not_publicly_accessible
- cloudtrail_multi_region_enabled_logging_management_events
- cloudwatch
- cloudwatch_alarm_actions_alarm_state_configured
- cloudwatch_alarm_actions_enabled
- cloudwatch_changes_to_network_acls_alarm_configured
- cloudwatch_log_group_retention_policy_specific_days_enabled
- cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled
- cloudwatch_log_metric_filter_authentication_failures
- cloudwatch_log_metric_filter_aws_organizations_changes
- cloudwatch_log_metric_filter_root_usage
- cloudwatch_log_metric_filter_sign_in_without_mfa
- cloudwatch_log_metric_filter_unauthorized_api_calls
- codepipeline/codepipeline_project_repo_private
- dlm/dlm_ebs_snapshot_lifecycle_policy_exists
- dms
- dms_instance_minor_version_upgrade_enabled
- dms_instance_multi_az_enabled
- dms_instance_no_public_access
- documentdb
- documentdb_cluster_backup_enabled
- documentdb_cluster_cloudwatch_log_export
- documentdb_cluster_deletion_protection
- dynamodb
- dynamodb_accelerator_cluster_encryption_enabled
- dynamodb_tables_kms_cmk_encryption_enabled
- ec2
- ec2_ebs_default_encryption
- ec2_ebs_public_snapshot
- ec2_ebs_snapshots_encrypted
- ec2_ebs_volume_encryption
- ec2_ebs_volume_snapshots_exists
- ec2_instance_account_imdsv2_enabled
- ec2_instance_detailed_monitoring_enabled
- ec2_instance_imdsv2_enabled
- ec2_instance_managed_by_ssm
- ec2_instance_older_than_specific_days
- ec2_instance_port_cifs_exposed_to_internet
- ec2_instance_port_ftp_exposed_to_internet
- ec2_instance_port_mysql_exposed_to_internet
- ec2_instance_port_oracle_exposed_to_internet
- ec2_instance_port_postgresql_exposed_to_internet
- ec2_instance_port_rdp_exposed_to_internet
- ec2_instance_port_redis_exposed_to_internet
- ec2_instance_port_sqlserver_exposed_to_internet
- ec2_instance_port_ssh_exposed_to_internet
- ec2_instance_port_telnet_exposed_to_internet
- ec2_instance_profile_attached
- ec2_instance_public_ip
- ec2_securitygroup_allow_ingress_from_internet_to_all_ports
- ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22
- ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389
- ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21
- ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306
- ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432
- ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23
- ec2_securitygroup_from_launch_wizard
- ec2_securitygroup_not_used
- ec2_securitygroup_with_many_ingress_egress_rules
- ecr
- ecr_repositories_lifecycle_policy_enabled
- ecr_repositories_scan_images_on_push_enabled
- ecs/ecs_service_fargate_latest_platform_version
- eks
- eks_cluster_kms_cmk_encryption_in_secrets_enabled
- eks_cluster_network_policy_enabled
- eks_cluster_not_publicly_accessible
- eks_cluster_uses_a_supported_version
- elasticache
- elasticache_redis_cluster_backup_enabled
- elasticache_redis_cluster_in_transit_encryption_enabled
- elasticache_redis_cluster_multi_az_enabled
- elasticache_redis_cluster_rest_encryption_enabled
- elasticbeanstalk/elasticbeanstalk_environment_managed_updates_enabled
- elbv2
- elbv2_cross_zone_load_balancing_enabled
- elbv2_deletion_protection
- elbv2_desync_mitigation_mode
- elbv2_insecure_ssl_ciphers
- elbv2_internet_facing
- elbv2_is_in_multiple_az
- elbv2_logging_enabled
- elbv2_nlb_tls_termination_enabled
- elb
- elb_connection_draining_enabled
- elb_cross_zone_load_balancing_enabled
- elb_desync_mitigation_mode
- elb_insecure_ssl_ciphers
- elb_internet_facing
- elb_is_in_multiple_az
- elb_logging_enabled
- elb_ssl_listeners
- emr/emr_cluster_account_public_block_enabled
- eventbridge
- eventbridge_bus_cross_account_access
- eventbridge_bus_exposed
- firehose/firehose_stream_encrypted_at_rest
- glacier/glacier_vaults_policy_public_access
- glue
- glue_data_catalogs_metadata_encryption_enabled
- glue_development_endpoints_cloudwatch_logs_encryption_enabled
- glue_development_endpoints_job_bookmark_encryption_enabled
- glue_development_endpoints_s3_encryption_enabled
- glue_etl_jobs_amazon_s3_encryption_enabled
- glue_etl_jobs_cloudwatch_logs_encryption_enabled
- glue_etl_jobs_job_bookmark_encryption_enabled
- guardduty
- guardduty_ec2_malware_protection_enabled
- guardduty_is_enabled
- guardduty_no_high_severity_findings
- guardduty_s3_protection_enabled
- iam
- iam_avoid_root_usage
- iam_customer_attached_policy_no_administrative_privileges
- iam_customer_unattached_policy_no_administrative_privileges
- iam_group_administrator_access_policy
- iam_no_expired_server_certificates_stored
- iam_no_root_access_key
- iam_policy_cloudshell_admin_not_attached
- iam_root_hardware_mfa_enabled
- iam_rotate_access_key_90_days
- iam_support_role_created
- iam_user_accesskey_unused
- iam_user_administrator_access_policy
- iam_user_mfa_enabled_console_access
- iam_user_two_active_access_key
- inspector2
- inspector2_active_findings_exist
- inspector2_is_enabled
- kafka
- kafka_cluster_encryption_at_rest_uses_cmk
- kafka_cluster_enhanced_monitoring_enabled
- kafka_cluster_in_transit_encryption_enabled
- kafka_cluster_is_public
- kafka_cluster_mutual_tls_authentication_enabled
- kafka_cluster_unrestricted_access_disabled
- kafka_cluster_uses_latest_version
- kinesis/kinesis_stream_encrypted_at_rest
- kms/kms_key_not_publicly_accessible
- mq
- mq_broker_active_deployment_mode
- mq_broker_auto_minor_version_upgrades
- mq_broker_logging_enabled
- mq_broker_not_publicly_accessible
- neptune
- neptune_cluster_backup_enabled
- neptune_cluster_iam_authentication_enabled
- neptune_cluster_multi_az
- networkfirewall/networkfirewall_in_all_vpc
- opensearch
- opensearch_service_domains_cloudwatch_logging_enabled
- opensearch_service_domains_encryption_at_rest_enabled
- opensearch_service_domains_node_to_node_encryption_enabled
- opensearch_service_domains_not_publicly_accessible
- opensearch_service_domains_updated_to_the_latest_service_software_version
- rds
- rds_cluster_backtrack_enabled
- rds_cluster_default_admin
- rds_cluster_iam_authentication_enabled
- rds_instance_backup_enabled
- rds_instance_certificate_expiration
- rds_instance_copy_tags_to_snapshots
- rds_instance_critical_event_subscription
- rds_instance_default_admin
- rds_instance_deletion_protection
- rds_instance_event_subscription_security_groups
- rds_instance_iam_authentication_enabled
- rds_instance_integration_cloudwatch_logs
- rds_instance_minor_version_upgrade_enabled
- rds_instance_multi_az
- rds_instance_no_public_access
- rds_instance_non_default_port
- rds_instance_storage_encrypted
- rds_instance_transport_encrypted
- rds_snapshots_encrypted
- rds_snapshots_public_access
- redshift
- redshift_cluster_enhanced_vpc_routing
- redshift_cluster_in_transit_encryption_enabled
- redshift_cluster_non_default_username
- redshift_cluster_public_access
- route53
- route53_dangling_ip_subdomain_takeover
- route53_domains_privacy_protection_enabled
- route53_public_hosted_zones_cloudwatch_logging_enabled
- s3
- s3_bucket_kms_encryption
- s3_bucket_level_public_access_block
- s3_bucket_lifecycle_enabled
- s3_bucket_object_lock
- s3_bucket_public_list_acl
- s3_bucket_public_write_acl
- s3_bucket_secure_transport_policy
- sagemaker
- sagemaker_notebook_instance_encryption_enabled
- sagemaker_notebook_instance_vpc_settings_configured
- sagemaker_notebook_instance_without_direct_internet_access_configured
- sagemaker_training_jobs_intercontainer_encryption_enabled
- sns
- sns_topics_kms_encryption_at_rest_enabled
- sns_topics_not_publicly_accessible
- sqs
- sqs_queues_not_publicly_accessible
- sqs_queues_server_side_encryption_enabled
- trustedadvisor
- trustedadvisor_errors_and_warnings
- vpc
- vpc_flow_logs_enabled
- vpc_peering_routing_tables_with_least_privilege
- wafv2/wafv2_webacl_logging_enabled
- wellarchitected/wellarchitected_workload_no_high_or_medium_risks
- workspaces/workspaces_volume_encryption_enabled
Some content is hidden
Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.
230 files changed
+253
-251
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
51 | 51 | | |
52 | 52 | | |
53 | 53 | | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
| 57 | + | |
54 | 58 | | |
55 | 59 | | |
56 | 60 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
27 | 27 | | |
28 | 28 | | |
29 | 29 | | |
30 | | - | |
| 30 | + | |
31 | 31 | | |
32 | 32 | | |
33 | 33 | | |
| |||
Lines changed: 0 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
19 | 18 | | |
20 | 19 | | |
21 | 20 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
21 | 20 | | |
22 | 21 | | |
23 | 22 | | |
24 | | - | |
| 23 | + | |
25 | 24 | | |
26 | 25 | | |
27 | 26 | | |
| |||
Lines changed: 0 additions & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
21 | 20 | | |
22 | 21 | | |
23 | 22 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
15 | 15 | | |
16 | 16 | | |
17 | 17 | | |
18 | | - | |
19 | | - | |
| 18 | + | |
20 | 19 | | |
21 | 20 | | |
22 | 21 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
17 | 17 | | |
18 | 18 | | |
19 | 19 | | |
20 | | - | |
| 20 | + | |
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
19 | 19 | | |
20 | 20 | | |
21 | 21 | | |
22 | | - | |
| 22 | + | |
23 | 23 | | |
24 | 24 | | |
25 | 25 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
18 | 18 | | |
19 | 19 | | |
20 | 20 | | |
21 | | - | |
| 21 | + | |
22 | 22 | | |
23 | 23 | | |
24 | 24 | | |
| |||
Lines changed: 1 addition & 1 deletion
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
21 | 21 | | |
22 | 22 | | |
23 | 23 | | |
24 | | - | |
| 24 | + | |
25 | 25 | | |
26 | 26 | | |
27 | 27 | | |
| |||
0 commit comments