diff --git a/checks/check_extra710 b/checks/check_extra710 index 4230686c..bafb10f0 100644 --- a/checks/check_extra710 +++ b/checks/check_extra710 @@ -1,7 +1,6 @@ CHECK_ID_extra710="7.10" CHECK_TITLE_extra710="Check for internet facing EC2 Instances (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra710="NOT_SCORED" -CHECK_ALTERNATE_extra710="extra710" CHECK_ALTERNATE_check710="extra710" extra710(){ diff --git a/checks/check_extra711 b/checks/check_extra711 index 00206c36..9918d716 100644 --- a/checks/check_extra711 +++ b/checks/check_extra711 @@ -1,7 +1,6 @@ CHECK_ID_extra711="7.11" CHECK_TITLE_extra711="Check for Publicly Accessible Redshift Clusters (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra711="NOT_SCORED" -CHECK_ALTERNATE_extra711="extra711" CHECK_ALTERNATE_check711="extra711" extra711(){ diff --git a/checks/check_extra712 b/checks/check_extra712 index b2996e5a..a3b59b84 100644 --- a/checks/check_extra712 +++ b/checks/check_extra712 @@ -1,7 +1,6 @@ CHECK_ID_extra712="7.12" CHECK_TITLE_extra712="Check if Amazon Macie is enabled (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra712="NOT_SCORED" -CHECK_ALTERNATE_extra712="extra712" CHECK_ALTERNATE_check712="extra712" extra712(){ diff --git a/checks/check_extra713 b/checks/check_extra713 index ac1b3bf8..93ed5ab6 100644 --- a/checks/check_extra713 +++ b/checks/check_extra713 @@ -1,7 +1,6 @@ CHECK_ID_extra713="7.13" CHECK_TITLE_extra713="Check if GuardDuty is enabled (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra713="NOT_SCORED" -CHECK_ALTERNATE_extra713="extra713" CHECK_ALTERNATE_check713="extra713" extra713(){ diff --git a/checks/check_extra714 b/checks/check_extra714 index 6e7de69b..92a7118e 100644 --- a/checks/check_extra714 +++ b/checks/check_extra714 @@ -1,7 +1,6 @@ CHECK_ID_extra714="7.14" CHECK_TITLE_extra714="Check if CloudFront distributions have logging enabled (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra714="NOT_SCORED" -CHECK_ALTERNATE_extra714="extra714" CHECK_ALTERNATE_check714="extra714" extra714(){ diff --git a/checks/check_extra715 b/checks/check_extra715 index 883dac35..04e24f84 100644 --- a/checks/check_extra715 +++ b/checks/check_extra715 @@ -1,7 +1,6 @@ CHECK_ID_extra715="7.15" CHECK_TITLE_extra715="Check if Elasticsearch Service domains have logging enabled (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra715="NOT_SCORED" -CHECK_ALTERNATE_extra715="extra715" CHECK_ALTERNATE_check715="extra715" extra715(){ diff --git a/checks/check_extra716 b/checks/check_extra716 index 7289d1b3..00c2d1e8 100644 --- a/checks/check_extra716 +++ b/checks/check_extra716 @@ -1,7 +1,6 @@ CHECK_ID_extra716="7.16" CHECK_TITLE_extra716="Check if Elasticsearch Service domains allow open access (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra716="NOT_SCORED" -CHECK_ALTERNATE_extra716="extra716" CHECK_ALTERNATE_check716="extra716" extra716(){ diff --git a/checks/check_extra717 b/checks/check_extra717 index 997c44c6..d887169c 100644 --- a/checks/check_extra717 +++ b/checks/check_extra717 @@ -1,7 +1,6 @@ CHECK_ID_extra717="7.17" CHECK_TITLE_extra717="Check if Elastic Load Balancers have logging enabled (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra717="NOT_SCORED" -CHECK_ALTERNATE_extra717="extra717" CHECK_ALTERNATE_check717="extra717" extra717(){ diff --git a/checks/check_extra718 b/checks/check_extra718 index 1cbe05e6..8184daeb 100644 --- a/checks/check_extra718 +++ b/checks/check_extra718 @@ -1,7 +1,6 @@ CHECK_ID_extra718="7.18" CHECK_TITLE_extra718="Check if S3 buckets have server access logging enabled (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra718="NOT_SCORED" -CHECK_ALTERNATE_extra718="extra718" CHECK_ALTERNATE_check718="extra718" extra718(){ diff --git a/checks/check_extra719 b/checks/check_extra719 index ac695483..df90a994 100644 --- a/checks/check_extra719 +++ b/checks/check_extra719 @@ -1,7 +1,6 @@ CHECK_ID_extra719="7.19" CHECK_TITLE_extra719="Check if Route53 hosted zones are logging queries to CloudWatch Logs (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra719="NOT_SCORED" -CHECK_ALTERNATE_extra719="extra719" CHECK_ALTERNATE_check719="extra719" extra719(){ diff --git a/checks/check_extra720 b/checks/check_extra720 index 3790544c..ade6d3ae 100644 --- a/checks/check_extra720 +++ b/checks/check_extra720 @@ -1,7 +1,6 @@ CHECK_ID_extra720="7.20" CHECK_TITLE_extra720="Check if Lambda functions invoke API operations are being recorded by CloudTrail (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra720="NOT_SCORED" -CHECK_ALTERNATE_extra720="extra720" CHECK_ALTERNATE_check720="extra720" extra720(){ diff --git a/checks/check_extra721 b/checks/check_extra721 index 06d2e601..43b0778f 100644 --- a/checks/check_extra721 +++ b/checks/check_extra721 @@ -1,7 +1,6 @@ CHECK_ID_extra721="7.21" CHECK_TITLE_extra721="Check if Redshift cluster has audit logging enabled (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra721="NOT_SCORED" -CHECK_ALTERNATE_extra721="extra721" CHECK_ALTERNATE_check721="extra721" extra721(){ diff --git a/checks/check_extra722 b/checks/check_extra722 index 6ad42e5b..1310d00c 100644 --- a/checks/check_extra722 +++ b/checks/check_extra722 @@ -2,7 +2,6 @@ CHECK_ID_extra722="7.22" CHECK_TITLE_extra722="Check if API Gateway has logging enabled (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra722="NOT_SCORED" CHECK_ALTERNATE_check722="extra722" -CHECK_ALTERNATE_extra722="extra722" extra722(){ # "Check if API Gateway has logging enabled (Not Scored) (Not part of CIS benchmark)" diff --git a/checks/check_extra723 b/checks/check_extra723 index 0c4e91f8..ee32ce47 100644 --- a/checks/check_extra723 +++ b/checks/check_extra723 @@ -2,7 +2,6 @@ CHECK_ID_extra723="7.23" CHECK_TITLE_extra723="Check if RDS Snapshots are public (Not Scored) (Not part of CIS benchmark)" CHECK_SCORED_extra723="NOT_SCORED" CHECK_ALTERNATE_check723="extra723" -CHECK_ALTERNATE_extra723="extra723" extra723(){ # "Check if RDS Snapshots are public (Not Scored) (Not part of CIS benchmark)" diff --git a/checks/check_sample b/checks/check_sample index e69de29b..c57223a1 100644 --- a/checks/check_sample +++ b/checks/check_sample @@ -0,0 +1,21 @@ +# CHECK_ID_checkN="N.N" +# CHECK_TITLE_checkN="Description (Not Scored) (Not part of CIS benchmark)" +# CHECK_SCORED_checkN="NOT_SCORED" +# CHECK_ALTERNATE_checkN="extraN" +# +# extraN(){ +# # "Description (Not Scored) (Not part of CIS benchmark)" +# textNotice "Looking for instances in all regions... " +# for regx in $REGIONS; do +# LIST_OF_PUBLIC_INSTANCES=$($AWSCLI ec2 describe-instances $PROFILE_OPT --region $regx --query 'Reservations[*].Instances[?PublicIpAddress].[InstanceId,PublicIpAddress]' --output text) +# if [[ $LIST_OF_PUBLIC_INSTANCES ]];then +# while read -r instance;do +# INSTANCE_ID=$(echo $instance | awk '{ print $1; }') +# PUBLIC_IP=$(echo $instance | awk '{ print $2; }') +# textWarn "$regx: Instance: $INSTANCE_ID at IP: $PUBLIC_IP is internet-facing!" "$regx" +# done <<< "$LIST_OF_PUBLIC_INSTANCES" +# else +# textOK "$regx: no Internet Facing EC2 Instances found" "$regx" +# fi +# done +# }