Initial commit

This commit is contained in:
drewmullen
2022-07-06 09:17:41 -04:00
committed by Rodrigue Koffi
parent eaee1ddedd
commit 0262a8a45d
25 changed files with 559 additions and 10 deletions
@@ -0,0 +1,39 @@
{
"checks": [
{
"code": "CUS002",
"description": "Check to IMDSv2 is required on EC2 instances created by this Launch Template",
"impact": "Instance metadata service can be interacted with freely",
"resolution": "Enable HTTP token requirement for IMDS",
"requiredTypes": [
"resource"
],
"requiredLabels": [
"aws_launch_configuration"
],
"severity": "CRITICAL",
"matchSpec": {
"action": "isPresent",
"name": "metadata_options",
"subMatch": {
"action": "and",
"predicateMatchSpec": [
{
"action": "equals",
"name": "http_tokens",
"value": "required"
}
]
}
},
"errorMessage": "is missing `metadata_options` block - it is required with `http_tokens` set to `required` to make Instance Metadata Service more secure.",
"relatedLinks": [
"https://tfsec.dev/docs/aws/ec2/enforce-http-token-imds#aws/ec2",
"https://registry.terraform.io/providers/hashicorp/aws/latest/docs/resources/launch_configuration#metadata-options",
"https://aws.amazon.com/blogs/security/defense-in-depth-open-firewalls-reverse-proxies-ssrf-vulnerabilities-ec2-instance-metadata-service"
]
}
]
}