Commit Graph

85 Commits

Author SHA1 Message Date
Toni de la Fuente
26eeda590a Merge pull request #47 from MrSecure/master
fixes #45 - define TITLE116 variable
2017-06-14 17:46:05 -04:00
Ben Allen
d11a80835f fixes #46 - checks 1.16, 1.17, 1.18 were missing from the default list of checks 2017-06-14 16:43:48 -05:00
Ben Allen
cea02668ad fixes #45 - define TITLE116 variable 2017-06-14 16:35:22 -05:00
Toni de la Fuente
5517d39285 Merge pull request #43 from toniblyx/master
Update README with new options
2017-06-01 15:38:03 -04:00
Toni de la Fuente
9c6d8b8a7c Added new options to README 2017-06-01 15:37:02 -04:00
Toni de la Fuente
6212c50674 Merge pull request #2 from Alfresco/master
updated from base repo
2017-06-01 15:34:24 -04:00
Toni de la Fuente
b208e35cae Merge pull request #42 from AlexCline/master
Improvements and additions to option configurations.
Added filter region option and max-items option for large resource outputs.
2017-06-01 15:27:28 -04:00
AlexClineBB
4439a5f184 Add a configuration option to configure max-items for large resources
This change adds a -m option which configures the --max-items API parameter for large
AWS resources. Currently, SNS topic subscriptions are limited to the default of 100
items. SNS topics can easily surpass 100,000 subscriptions which is too many to show
by default.

Since check 3.15 is confirming that subscribers exist - not what they actually are - it's
a waste to display all 100,000 entries.
2017-05-31 15:05:04 -04:00
AlexClineBB
fc9b8a1d3c Add the option to filter API requests by region
This change adds the ability to perform checks against specific regions only.

The -r option allows you to set the region that API requests are made against,
but checks are always made against all regions.

The -f allows you to filter which regions to run checks against.
2017-05-31 14:59:37 -04:00
AlexClineBB
9727d5a3ed Set defaults for environment variables
This change sets the defaults for PROFILE and REGION before they're set by getopts,
allowing us to add support for more options without needing to update the default
setting code that happened after the options were parsed.
2017-05-31 14:54:39 -04:00
Toni de la Fuente
2c865485d9 Merge pull request #41 from AlexCline/master
Match the entire username when running check12
2017-05-31 13:10:50 -04:00
AlexClineBB
666a1c42cd Match the entire username when running check12
When a password-enabled user with a short name (e.g. "bc") is matched against
another user whose username contains the first (e.g. "abcd"), check12 would
erroneously display the second user "abcd" as having a password and no MFA.

This change ensures that grep matches the whole word.
2017-05-31 11:21:31 -04:00
Toni de la Fuente
e0ef94caa5 Updated github repo name in README 2017-05-05 15:07:31 -04:00
Toni de la Fuente
1abdfff7ac Merge pull request #38 from virtualjj/fix-check28
Fix check28 - Issue #36
2017-01-10 09:13:58 -05:00
Toni de la Fuente
a2371a8c34 Merge pull request #37 from virtualjj/fix-readme-custom-iam-policy
Add logs:DescribeMetricFilters to Custom IAM Policy section.
2017-01-10 09:12:03 -05:00
Virtual JJ
7ba0778162 Fix issue #36. Improve parsing of default KMS keys and customer keys. 2017-01-10 15:59:23 +09:00
Virtual JJ
931da9920e Add logs:DescribeMetricFilters to Custom IAM Policy section. 2017-01-09 20:27:29 +09:00
Toni de la Fuente
aa6cd9c614 Merge pull request #35 from davidpanofsky/fix_2.4
fix for rule 2.4
2016-12-30 11:53:24 +01:00
David Panofsky
71f96f017e fix accidental removal 2016-12-29 17:43:09 -05:00
David Panofsky
2280f1cf9c Merge branch 'master' into fix_2.4 2016-12-29 17:37:56 -05:00
David Panofsky
ae88e34cd5 fix for rule 2.4 2016-12-29 17:31:16 -05:00
David Panofsky
434ad7733d fix for rule 2.4 2016-12-29 17:25:34 -05:00
Toni de la Fuente
3b5e6a0680 Merge pull request #34 from davidpanofsky/master
Fix couple of syntax errors
2016-12-19 08:46:24 +00:00
David Panofsky
ae842f2b1a Merge branch 'master' of github.com:davidpanofsky/aws-cis-security-benchmark 2016-12-16 15:23:08 -05:00
David Panofsky
499042dc6f fix a few lists which were being treated as strings 2016-12-16 15:22:22 -05:00
Toni de la Fuente
61d7d39d0a Merge pull request #33 from toniblyx/master
Added Support for CIS AWS 1.1
2016-11-30 00:49:54 -05:00
Toni de la Fuente
581c7c7ebf Added Support for CIS AWS 1.1 2016-11-30 00:48:35 -05:00
Toni de la Fuente
e7b5b8ce58 Support for CIS AWS 1.1 2016-11-30 00:32:00 -05:00
Toni de la Fuente
ae77663fd7 Merge pull request #32 from toniblyx/master
Added info to README and help
2016-11-14 22:35:19 -05:00
Toni de la Fuente
56656e95ef Added info to README and help 2016-11-14 22:34:48 -05:00
Toni de la Fuente
e294c46722 Merge pull request #31 from toniblyx/master
Fixed section 3 commands and added group checks
2016-11-14 22:32:30 -05:00
Toni de la Fuente
cec364581e Fixed section 3 commands 2016-11-14 22:29:56 -05:00
Toni de la Fuente
2d8f19b61b Merge pull request #28 from toniblyx/master
Improved output for check28 and Fixed issue #27
2016-10-13 13:32:38 -04:00
Toni de la Fuente
7d20141859 Fixed issue #27 2016-10-13 13:31:17 -04:00
Toni de la Fuente
0679fe43e8 Improved output for check28 2016-10-12 16:41:55 -04:00
Toni de la Fuente
ebffbd5166 Merge pull request #25 from toniblyx/master
Added ansi2html for reporting
2016-10-12 15:54:53 -04:00
Toni de la Fuente
f7256d1b97 Improved check25 when configured but not enabled 2016-10-12 15:29:33 -04:00
Toni de la Fuente
e9eda9dfdb fixed report temp deletion after single check and fixed check24 region bug 2016-10-12 12:16:31 -04:00
Toni de la Fuente
3e79b5c5be Added ansi2html for reporting 2016-10-07 13:25:08 -04:00
Toni de la Fuente
259ab994ba Merge pull request #24 from toniblyx/master
Added suggestion as in issue #19
2016-10-07 10:25:59 -04:00
Toni de la Fuente
5c3cee9c0c Added suggestion as in issue #19 2016-10-07 10:25:18 -04:00
Toni de la Fuente
6a5cf701dd Merge pull request #23 from toniblyx/master
Fixes of issue #16
2016-10-06 16:19:53 -04:00
Toni de la Fuente
e70e3c7100 Fixes of issue #16 2016-10-06 16:18:58 -04:00
Toni de la Fuente
a1d6b2b3a4 Merge pull request #22 from toniblyx/master
Fixed issue in check 1.10
2016-10-06 13:57:26 -04:00
Toni de la Fuente
e9839fc2d9 Fixed issue in check 1.10 2016-10-06 13:56:50 -04:00
Toni de la Fuente
9d425c0ea4 Merge pull request #21 from toniblyx/master
Added info about default region us-east-1
2016-10-06 13:26:27 -04:00
Toni de la Fuente
2e2c9b7126 Added info about default region us-east-1 2016-10-06 13:25:22 -04:00
Toni de la Fuente
ba1b9de199 Merge pull request #20 from toniblyx/master
fixed issues 2.1 and 2.2 when more than one trail
2016-10-06 13:22:54 -04:00
Toni de la Fuente
68f8f5b4b8 fixed issues 2.1 and 2.2 when more than one trail 2016-10-06 13:21:28 -04:00
Toni de la Fuente
7ab0ab46be Merge pull request #17 from lyletagawa/use_cloudwatch_group
Ensure ${CLOUDWATCH_GROUP} lookup for single checks
2016-10-06 12:52:16 -04:00