mirror of
https://github.com/ghndrx/prowler.git
synced 2026-02-10 23:05:05 +00:00
add "lambda:GetAccountSettings", "lambda:GetFunctionConfiguration", "lambda:GetLayerVersionPolicy", "lambda:GetPolicy", "lambda:List*", to prowler-additions-policy
115 lines
4.1 KiB
JSON
115 lines
4.1 KiB
JSON
{
|
|
"Version": "2012-10-17",
|
|
"Statement": [
|
|
{
|
|
"Action": [
|
|
"access-analyzer:List*",
|
|
"apigateway:get*",
|
|
"apigatewayv2:get*",
|
|
"aws-marketplace:viewsubscriptions",
|
|
"batch:listjobs",
|
|
"clouddirectory:listappliedschemaarns",
|
|
"clouddirectory:listdevelopmentschemaarns",
|
|
"clouddirectory:listpublishedschemaarns",
|
|
"cloudformation:list*",
|
|
"cloudhsm:listavailablezones",
|
|
"cloudsearch:list*",
|
|
"cloudwatch:get*",
|
|
"cloudwatch:list*",
|
|
"codebuild:listbuilds*",
|
|
"codestar:verify*",
|
|
"cognito-identity:listidentities",
|
|
"cognito-idp:list*",
|
|
"cognito-sync:listdatasets",
|
|
"connect:list*",
|
|
"datapipeline:getaccountlimits",
|
|
"dax:describeclusters",
|
|
"dax:describedefaultparameters",
|
|
"dax:describeevents",
|
|
"dax:describeparametergroups",
|
|
"dax:describeparameters",
|
|
"dax:describesubnetgroups",
|
|
"dax:describetable",
|
|
"dax:listtables",
|
|
"devicefarm:list*",
|
|
"discovery:list*",
|
|
"dms:list*",
|
|
"ds:ListAuthorizedApplications",
|
|
"ds:DescribeRoles",
|
|
"dynamodb:describebackup",
|
|
"dynamodb:describeglobaltablesettings",
|
|
"dynamodb:describelimits",
|
|
"dynamodb:describereservedcapacity",
|
|
"dynamodb:describereservedcapacityofferings",
|
|
"dynamodb:describestream",
|
|
"dynamodb:listtagsofresource",
|
|
"ec2:get*",
|
|
"ecr:describe*",
|
|
"ecr:listimages",
|
|
"elasticbeanstalk:listavailablesolutionstacks",
|
|
"elasticmapreduce:list*",
|
|
"elastictranscoder:list*",
|
|
"gamelift:list*",
|
|
"glacier:list*",
|
|
"importexport:listjobs",
|
|
"lambda:GetAccountSettings",
|
|
"lambda:GetFunctionConfiguration",
|
|
"lambda:GetLayerVersionPolicy",
|
|
"lambda:GetPolicy",
|
|
"lambda:List*",
|
|
"lex:getbotaliases",
|
|
"lex:getbotchannelassociations",
|
|
"lex:getbots",
|
|
"lex:getbotversions",
|
|
"lex:getintents",
|
|
"lex:getintentversions",
|
|
"lex:getslottypes",
|
|
"lex:getslottypeversions",
|
|
"lex:getutterancesview",
|
|
"lightsail:getblueprints",
|
|
"lightsail:getbundles",
|
|
"lightsail:getinstancesnapshots",
|
|
"lightsail:getkeypair",
|
|
"lightsail:getregions",
|
|
"lightsail:getstaticips",
|
|
"lightsail:isvpcpeered",
|
|
"machinelearning:describe*",
|
|
"mobilehub:listavailablefeatures",
|
|
"mobilehub:listavailableregions",
|
|
"mobilehub:listprojects",
|
|
"mobiletargeting:getapplicationsettings",
|
|
"mobiletargeting:getcampaigns",
|
|
"mobiletargeting:getimportjobs",
|
|
"mobiletargeting:getsegments",
|
|
"opsworks-cm:describe*",
|
|
"opsworks:describe*",
|
|
"polly:describe*",
|
|
"polly:list*",
|
|
"redshift:viewqueriesinconsole",
|
|
"route53domains:list*",
|
|
"s3:listbucket",
|
|
"sdb:list*",
|
|
"secretsmanager:listsecretversionids",
|
|
"servicecatalog:list*",
|
|
"ses:list*",
|
|
"ses:sendemail",
|
|
"sns:list*",
|
|
"sqs:listqueuetags",
|
|
"ssm:listassociations",
|
|
"states:listactivities",
|
|
"support:describe*",
|
|
"swf:list*",
|
|
"tag:gettagkeys",
|
|
"trustedadvisor:describe*",
|
|
"waf-regional:list*",
|
|
"waf:list*",
|
|
"workdocs:describeavailabledirectories",
|
|
"workdocs:describeinstances",
|
|
"workmail:describe*"
|
|
],
|
|
"Effect": "Allow",
|
|
"Resource": "*"
|
|
}
|
|
]
|
|
}
|