diff --git a/checks/check_extra7113 b/checks/check_extra7113 new file mode 100644 index 00000000..aede9db7 --- /dev/null +++ b/checks/check_extra7113 @@ -0,0 +1,50 @@ +#!/usr/bin/env bash + +# Prowler - the handy cloud security tool (copyright 2018) by Toni de la Fuente +# +# Licensed under the Apache License, Version 2.0 (the "License"); you may not +# use this file except in compliance with the License. You may obtain a copy +# of the License at http://www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, software distributed +# under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR +# CONDITIONS OF ANY KIND, either express or implied. See the License for the +# specific language governing permissions and limitations under the License. + +# Remediation: +# +# https://www.cloudconformity.com/knowledge-base/aws/RDS/instance-deletion-protection.html +# https://docs.aws.amazon.com/AmazonRDS/latest/UserGuide/Overview.DBInstance.Modifying.html +# +# aws rds modify-db-instance \ +# --region us-east-1 \ +# --db-instance-identifier test-db \ +# --deletion-protection \ +# [--apply-immediately | --no-apply-immediately] + +CHECK_ID_extra7113="7.113" +CHECK_TITLE_extra7113="[extra7113] Check if RDS instances have deletion protection enabled (Not Scored) (Not part of CIS benchmark)" +CHECK_SCORED_extra7113="NOT_SCORED" +CHECK_TYPE_extra7113="EXTRA" +CHECK_SEVERITY_extra7113="Medium" +CHECK_ASFF_RESOURCE_TYPE_extra7113="AwsRdsDbInstance" +CHECK_ALTERNATE_check7113="extra7113" + +extra7113(){ + textInfo "Looking for RDS Volumes in all regions... " + for regx in $REGIONS; do + LIST_OF_RDS_INSTANCES=$($AWSCLI rds describe-db-instances $PROFILE_OPT --region $regx --query 'DBInstances[*].DBInstanceIdentifier' --output text) + if [[ $LIST_OF_RDS_INSTANCES ]];then + for rdsinstance in $LIST_OF_RDS_INSTANCES; do + IS_DELETIONPROTECTION=$($AWSCLI rds describe-db-instances $PROFILE_OPT --region $regx --db-instance-identifier $rdsinstance --query 'DBInstances[*].DeletionProtection' --output text) + if [[ $IS_DELETIONPROTECTION == "False" ]]; then + textFail "$regx: RDS instance $rdsinstance deletion protection is not enabled!" "$regx" + else + textPass "$regx: RDS instance $rdsinstance deletion protection is enabled" "$regx" + fi + done + else + textInfo "$regx: No RDS instances found" "$regx" + fi + done +}