Initial commit

This commit is contained in:
drewmullen
2022-07-06 09:17:41 -04:00
committed by Rodrigue Koffi
parent eaee1ddedd
commit 0262a8a45d
25 changed files with 559 additions and 10 deletions
@@ -0,0 +1,39 @@
{
"checks": [
{
"code": "CUS002",
"description": "Check to IMDSv2 is required on EC2 instances created by this Launch Template",
"impact": "Instance metadata service can be interacted with freely",
"resolution": "Enable HTTP token requirement for IMDS",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_launch_configuration"
],
"severity": "CRITICAL",
"matchSpec": {
"action": "isPresent",
"name": "metadata_options",
"subMatch": {
"action": "and",
"predicateMatchSpec": [
{
"action": "equals",
"name": "http_tokens",
"value": "required"
}
]
}
},
"errorMessage": "is missing `metadata_options` block - it is required with `http_tokens` set to `required` to make Instance Metadata Service more secure.",
"relatedLinks": [
"https://tfsec.dev/docs/aws/ec2/enforce-http-token-imds#aws/ec2",
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata-options",
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
]
}
]
}
@@ -0,0 +1,39 @@
{
"checks": [
{
"code": "CUS001",
"description": "Check to IMDSv2 is required on EC2 instances created by this Launch Template",
"impact": "Instance metadata service can be interacted with freely",
"resolution": "Enable HTTP token requirement for IMDS",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_launch_template"
],
"severity": "CRITICAL",
"matchSpec": {
"action": "isPresent",
"name": "metadata_options",
"subMatch": {
"action": "and",
"predicateMatchSpec": [
{
"action": "equals",
"name": "http_tokens",
"value": "required"
}
]
}
},
"errorMessage": "is missing `metadata_options` block - it is required with `http_tokens` set to `required` to make Instance Metadata Service more secure.",
"relatedLinks": [
"https://tfsec.dev/docs/aws/ec2/enforce-http-token-imds#aws/ec2",
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_template#metadata-options",
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
]
}
]
}
+27
View File
@@ -0,0 +1,27 @@
{
"checks": [
{
"code": "CUS003",
"description": "Use `aws_launch_template` over `aws_launch_configuration",
"impact": "Launch configurations are not capable of versions",
"resolution": "Convert resource type and attributes to `aws_launch_template`",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_launch_configuration"
],
"severity": "MEDIUM",
"matchSpec": {
"action": "notPresent",
"name": "image_id"
},
"errorMessage": "should be changed to `aws_launch_template` since the functionality is the same but templates can be versioned.",
"relatedLinks": [
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_template",
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
]
}
]
}
@@ -0,0 +1,27 @@
{
"checks": [
{
"code": "CUS005",
"description": "Security group rules should be defined with `aws_security_group_rule` instead of embedded.",
"impact": "Embedded security group rules can cause issues during configuration updates.",
"resolution": "Move `egress` rules to `aws_security_group_rule` and attach to `aws_security_group`.",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_security_group"
],
"severity": "MEDIUM",
"matchSpec": {
"action": "notPresent",
"name": "egress"
},
"errorMessage": "`egress` rules should be moved to `aws_security_group_rule` and attached to `aws_security_group` instead of embedded.",
"relatedLinks": [
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group_rule",
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group"
]
}
]
}
@@ -0,0 +1,27 @@
{
"checks": [
{
"code": "CUS004",
"description": "Security group rules should be defined with `aws_security_group_rule` instead of embedded.",
"impact": "Embedded security group rules can cause issues during configuration updates.",
"resolution": "Move `ingress` rules to `aws_security_group_rule` and attach to `aws_security_group`.",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_security_group"
],
"severity": "MEDIUM",
"matchSpec": {
"action": "notPresent",
"name": "ingress"
},
"errorMessage": "`ingress` rules should be moved to `aws_security_group_rule` and attached to `aws_security_group` instead of embedded.",
"relatedLinks": [
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group_rule",
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/security_group"
]
}
]
}