chore(docs): add STS Endpoint and Allowlist updates (#2964)

This commit is contained in:
Sergio Garcia
2023-10-25 13:58:59 +02:00
committed by GitHub
parent f7312db0c7
commit 41085049e2
3 changed files with 11 additions and 9 deletions

View File

@@ -27,6 +27,10 @@ prowler aws -T/--session-duration <seconds> -I/--external-id <external_id> -R ar
If you are using Prowler in AWS regions that are not enabled by default you need to use the argument `--sts-endpoint-region` to point the AWS STS API calls `assume-role` and `get-caller-identity` to the non-default region, e.g.: `prowler aws --sts-endpoint-region eu-south-2`.
> Since v3.11.0, Prowler uses a regional token in STS sessions so it can scan all AWS regions without needing the `--sts-endpoint-region` argument.
> Make sure that you have enabled the AWS Region you want to scan in BOTH AWS Accounts (assumed role account and account from which you assume the role).
## Role MFA
If your IAM Role has MFA configured you can use `--mfa` along with `-R`/`--role <role_arn>` and Prowler will ask you to input the following values to get a new temporary session for the IAM Role provided: