文書一覧
| 文書 | パス |
|---|---|
| API Gatewayのデプロイ先ステージと使用量プランの関連付けの確認 | terraform/aws/api_gateway_deployment_without_api_gateway_usage_plan_associated |
| API Gatewayステージと使用量プランの関連付けの確認 | terraform/aws/api_gateway_stage_without_api_gateway_usage_plan_associated |
| API Gateway の X-Ray トレースが無効 | terraform/aws/api_gateway_xray_disabled |
| API Gateway のレスポンス圧縮設定の確認 | terraform/aws/api_gateway_with_invalid_compression |
| API Gateway による Lambda 呼び出し範囲の確認 | terraform/aws/public_lambda_via_api_gateway |
| API GatewayのAPIキーによる利用量管理の確認 | terraform/aws/api_gateway_method_does_not_contains_an_api_key |
| AWS Configの集約対象リージョンの確認 | terraform/aws/config_configuration_aggregator_to_all_regions_disabled |
| AWS Configの変更を通知するCloudWatchアラームが未設定 | terraform/aws/cloudwatch_aws_config_configuration_changes_alarm_missing |
| コンソールサインインの失敗を通知するCloudWatchアラームが未設定 | terraform/aws/cloudwatch_management_console_auth_failed_alarm_missing |
| AWS Organizations の変更を監視するアラームの未設定 | terraform/aws/cloudwatch_aws_organizations_changes_missing_alarm |
| AWS Shield Advancedの適用要否の確認 | terraform/aws/shield_advanced_not_in_use |
| AWS マネージドキーで暗号化された SNS トピック | terraform/aws/sns_topic_encrypted_with_aws_managed_key |
| AWS マネージドキーで暗号化された Secrets Manager シークレット | terraform/aws/secretsmanager_secret_encrypted_with_aws_managed_key |
| API Gateway REST APIの認証構成の確認 | terraform/aws/api_gateway_without_configured_authorizer |
| Auto Scalingグループのタグが未設定 | terraform/aws/autoscaling_groups_supply_tags |
| 起動設定のユーザーデータ内にある Base64 形式の秘密鍵の確認 | terraform/aws/user_data_contains_encoded_private_key |
| CloudFrontのコンテンツ配信設定の確認 | terraform/aws/cdn_configuration_is_missing |
| CloudFormation スタックの通知設定の確認 | terraform/aws/stack_notifications_disabled |
| CloudFormationスタックポリシーが未設定 | terraform/aws/no_stack_policy |
| CloudFormationスタックのテンプレートが未設定 | terraform/aws/stack_without_template |
| CloudFrontのTLSセキュリティポリシーの確認 | terraform/aws/secure_ciphers_disabled |
| CloudTrailのログファイル配信通知が未設定 | terraform/aws/cloudtrail_sns_topic_name_undefined |
| CloudTrail ログの KMS キー設定の確認 | terraform/aws/cloudtrail_log_files_not_encrypted_with_kms |
| CloudTrailログの整合性確認用ダイジェストが無効になっている | terraform/aws/cloudtrail_log_file_validation_disabled |
| CloudTrailのリージョンとグローバルイベントの対象範囲の確認 | terraform/aws/cloudtrail_multi_region_disabled |
| CloudTrailの変更を通知するCloudWatchアラームが未設定 | terraform/aws/cloudwatch_cloudtrail_configuration_changes_alarm_missing |
| CloudTrailとCloudWatch Logsが未連携 | terraform/aws/cloudtrail_not_integrated_with_cloudwatch |
| CloudWatch Logsの送信先ポリシーが過剰なアクセスを許可している | terraform/aws/cloudwatch_logs_destination_with_vulnerable_policy |
| API Gatewayのメソッド詳細メトリクスが無効になっている | terraform/aws/cloudwatch_metrics_disabled |
| Route 53のパブリックDNSクエリログが未設定 | terraform/aws/cloudwatch_logging_disabled |
| CloudWatch ログの保存期間の確認 | terraform/aws/cloudwatch_without_retention_period_specified |
| API GatewayのCloudWatchログ配信設定の確認 | terraform/aws/api_gateway_with_cloudwatch_logging_disabled |
| AWS マネージドキーを使用する CodeBuild プロジェクト | terraform/aws/codebuild_project_encrypted_with_aws_managed_key |
| Cognito User Pool の MFA 適用範囲の確認 | terraform/aws/cognito_userpool_without_mfa |
| DocumentDBの暗号化キー管理の確認 | terraform/aws/docdb_cluster_encrypted_with_aws_managed_key |
| DynamoDBゲートウェイエンドポイントの経路関連付けの確認 | terraform/aws/dynamodb_vpc_endpoint_without_route_table_association |
| DynamoDB のポイントインタイムリカバリが無効 | terraform/aws/dynamodb_table_point_in_time_recovery_disabled |
| EC2 の EBS 最適化設定の確認 | terraform/aws/ec2_not_ebs_optimized |
| EC2 ユーザーデータ内の AWS 認証情報の確認 | terraform/aws/hardcoded_aws_access_key |
| EC2 メタデータの IMDSv1 許可の確認 | terraform/aws/instance_uses_metadata_service_IMDSv1 |
| EC2のサブネットとセキュリティグループ選択の確認 | terraform/aws/instance_with_no_vpc |
| EC2インスタンスのデフォルトVPC利用の確認 | terraform/aws/ec2_instance_using_default_vpc |
| EC2 インスタンスに直接配布する AWS アクセスキー | terraform/aws/ec2_instance_using_api_keys |
| ECRリポジトリの暗号化キー管理の確認 | terraform/aws/ecr_repository_not_encrypted |
| ECRリポジトリのアクセスポリシーの確認 | terraform/aws/ecr_repository_without_policy |
| ECRイメージの脆弱性スキャン設定の確認 | terraform/aws/unscanned_ecr_image |
| ECS Container Insights 設定の確認 | terraform/aws/ecs_cluster_container_insights_disabled |
| ECS サービスに必要なタスク数の確認 | terraform/aws/ecs_service_without_running_tasks |
| EFS のカスタマー管理 KMS キーの確認 | terraform/aws/efs_without_kms |
| EKSコントロールプレーンのログ種別が不足 | terraform/aws/missing_cluster_log_types |
| EMRクラスターのサブネット選択の確認 | terraform/aws/emr_without_vpc |
| ENCRYPTED_VOLUMES の AWS Config ルールがない構成 | terraform/aws/config_rule_for_encrypted_volumes_is_disabled |
| ElastiCache のエンジン選択の確認 | terraform/aws/redis_disabled |
| ElastiCacheのサブネットグループ選択の確認 | terraform/aws/elasticache_without_vpc |
| ElastiCache の既定ポートとアクセス制御の確認 | terraform/aws/elasticache_using_default_port |
| Elasticsearch のスローログ設定の確認 | terraform/aws/elasticsearch_without_slow_logs |
| クロスアカウント IAM ロールの信頼条件の確認 | terraform/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa |
| GuardDutyの検出器が無効になっている | terraform/aws/guardduty_detector_disabled |
| S3バケットのHTTPS強制ポリシーの確認 | terraform/aws/s3_bucket_policy_accepts_http_requests |
| HTTPポート80がインターネットに公開されている | terraform/aws/http_port_open |
| ElasticsearchドメインでHTTPSが必須になっていない | terraform/aws/elasticsearch_with_https_disabled |
| HTTPを使用するAWS ALBリスナー | terraform/aws/alb_listening_on_http |
| CloudFrontのビューワーポリシーがHTTPを許可している | terraform/aws/cloudfront_viewer_protocol_policy_allows_http |
| IAM Access Analyzer の構成の確認 | terraform/aws/iam_access_analyzer_not_enabled |
| IAM データベース認証が無効な Neptune クラスター | terraform/aws/neptune_cluster_with_iam_database_authentication_disabled |
| IAM パスワード有効期限ポリシーの確認 | terraform/aws/misconfigured_password_policy_expiration |
| IAM パスワード再利用防止の確認 | terraform/aws/password_without_reuse_prevention |
| IAM パスワードの最小文字数の確認 | terraform/aws/iam_password_without_minimum_length |
| IAM ユーザーポリシーの MFA 要件の確認 | terraform/aws/iam_user_policy_without_mfa |
| Elasticsearch ドメインの IAM アクセス制御の確認 | terraform/aws/elasticsearch_without_iam_authentication |
| IAM ポリシー変更を監視するアラームの未設定 | terraform/aws/cloudwatch_iam_policy_changes_alarm_missing |
| KMS カスタマーマネージドキーのローテーション設定の確認 | terraform/aws/cmk_rotation_disabled |
| KMS 暗号化のない AWS Kinesis ストリーム | terraform/aws/kinesis_not_encrypted_with_kms |
| CloudWatch ロググループの暗号化キーの確認 | terraform/aws/cloudwatch_log_group_not_encrypted |
| KMS キー削除待機期間の確認 | terraform/aws/kms_key_with_no_deletion_window |
| DocumentDB の暗号化キー設定の確認 | terraform/aws/docdb_cluster_without_kms |
| Elasticsearch の暗号化キー設定の確認 | terraform/aws/elasticsearch_encryption_with_kms_is_disabled |
| SageMaker ノートブックの暗号化キーを確認 | terraform/aws/sagemaker_notebook_instance_without_kms |
| Secrets Manager シークレットの暗号化キー設定の確認 | terraform/aws/secretsmanager_secret_without_kms |
| Lambda 非同期処理の失敗イベント保管設定の確認 | terraform/aws/lambda_function_without_dead_letter_queue |
| Lambda InvokeFunction の IAM リソース範囲の確認 | terraform/aws/lambda_iam_invokefunction_misconfigured |
| Lambda 権限の action 設定の確認 | terraform/aws/lambda_permission_misconfigured |
| Lambda の X-Ray トレース設定の確認 | terraform/aws/lambda_functions_without_x-ray_tracing |
| Lambda 環境変数内の AWS 認証情報の確認 | terraform/aws/hardcoded_aws_access_key_in_lambda |
| IAM ユーザーアクセスの MFA 要件の確認 | terraform/aws/authentication_without_mfa |
| MFA なしのコンソールログインを監視するアラームの未設定 | terraform/aws/cloudwatch_management_console_sign_in_without_mfa_alarm_missing |
| MQブローカーのログ設定の確認 | terraform/aws/mq_broker_logging_disabled |
| MSKブローカーログ設定の確認 | terraform/aws/msk_cluster_logging_disabled |
| ネットワークACLの変更を通知するCloudWatchアラームが未設定 | terraform/aws/cloudwatch_changes_to_nacl_alarm_missing |
| Neptune監査ログのエクスポート設定の確認 | terraform/aws/neptune_logging_disabled |
| VPCでのNetwork Firewall利用の確認 | terraform/aws/vpc_without_network_firewall |
| API Gatewayエンドポイントの公開範囲の確認 | terraform/aws/api_gateway_endpoint_config_is_not_private |
| RDS for PostgreSQL のクエリログ設定の確認 | terraform/aws/postgres_rds_logging_disabled |
| リソースベースポリシーにPrincipalがない | terraform/aws/policy_without_principal |
| 全アドレスから RDP を許可する AWS Network ACL | terraform/aws/network_acl_with_unrestricted_access_to_rdp |
| すべてのアドレスから RDP を許可する AWS セキュリティグループ | terraform/aws/remote_desktop_port_open_to_internet |
| RDS の既定ポートとアクセス制御の確認 | terraform/aws/rds_using_default_port |
| RDSのCloudWatchログエクスポート設定の確認 | terraform/aws/rds_without_logging |
| RDS インスタンスの自動バックアップが無効 | terraform/aws/rds_with_backup_disabled |
| RDS インスタンスの IAM データベース認証が未使用 | terraform/aws/iam_database_auth_not_enabled |
| RDS の自動マイナーアップグレードが無効 | terraform/aws/automatic_minor_upgrades_disabled |
| RDS クラスターのバックアップ保持期間の確認 | terraform/aws/rds_cluster_with_backup_disabled |
| RDS スナップショットのタグコピー設定の確認 | terraform/aws/tags_not_copied_to_rds_cluster_snapshot |
| RDS クラスターの IAM データベース認証が未使用 | terraform/aws/iam_db_cluster_auth_not_enabled |
| TLS証明書のRSA鍵が短すぎる | terraform/aws/certificate_rsa_key_bytes_lower_than_256 |
| Redshift の既定ポートとアクセス制御の確認 | terraform/aws/redshift_using_default_port |
| Redshiftクラスターのネットワーク選択の確認 | terraform/aws/redshift_cluster_without_vpc |
| Redshift監査ログ設定の確認 | terraform/aws/redshift_cluster_logging_disabled |
| S3オブジェクトのCloudTrailデータイベント収集範囲の確認 | terraform/aws/s3_bucket_object_level_cloudtrail_logging_disabled |
| S3 バケットの MFA Delete 利用の確認 | terraform/aws/s3_bucket_without_enabled_mfa_delete |
| S3サーバーアクセスログ設定の確認 | terraform/aws/s3_bucket_logging_disabled |
| S3 バケットのイベント通知設定の確認 | terraform/aws/s3_bucket_notifications_disabled |
| S3バケットポリシーの変更を通知するCloudWatchアラームが未設定 | terraform/aws/cloudwatch_s3_policy_change_alarm_missing |
| SQL Analysis Servicesのポート2383が接続元を制限していない | terraform/aws/sql_analysis_services_port_2383_is_publicly_accessible |
| SQS VPCエンドポイントのDNS設定の確認 | terraform/aws/sqs_vpc_endpoint_without_dns_resolution |
| SQSキューのサーバー側暗号化設定の確認 | terraform/aws/sqs_with_sse_disabled |
| ネットワークACLが広い範囲からのSSHを許可している | terraform/aws/network_acl_with_unrestricted_access_to_ssh |
| セキュリティグループがインターネット全体からのSSHを許可している | terraform/aws/security_group_with_unrestricted_access_to_ssh |
| API Gateway のバックエンド用クライアント証明書設定の確認 | terraform/aws/api_gateway_without_ssl_certificate |
| SSM セッションの追加 KMS 暗号化設定の確認 | terraform/aws/ssm_session_transit_encryption_disabled |
| IAM Identity Center の許可セットのセッション期間の確認 | terraform/aws/sso_permission_with_inadequate_user_session_duration |
| セキュリティグループルールの説明が未記入 | terraform/aws/security_group_rules_without_description |
| セキュリティグループの説明の確認 | terraform/aws/security_group_without_description |
| Service Control Policy を使用できない AWS Organizations 設定 | terraform/aws/service_control_policies_disabled |
| StackSetのスタック保持設定の確認 | terraform/aws/stack_retention_disabled |
| Terraform で直接作成される AWS Identity Center ユーザー | terraform/aws/sso_policy_with_full_priveleges_copy |
| VPC Flow Logsの収集範囲の確認 | terraform/aws/vpc_flowlogs_disabled |
| VPCの変更を通知するCloudWatchアラームが未設定 | terraform/aws/cloudwatch_vpc_changes_alarm_missing |
| API GatewayのAWS WAF保護設定の確認 | terraform/aws/api_gateway_without_waf |
| CloudFrontのWAF関連付け設定の確認 | terraform/aws/cloudfront_without_waf |
| AWS ALBにWAFが関連付けられていない | terraform/aws/alb_is_not_integrated_with_waf |
| WRITE_ACP 権限を指定した S3 バケット ACL | terraform/aws/s3_bucket_acl_grants_write_acp_permission |
Effect: Allow と NotAction を併用する SNS トピックポリシー |
terraform/aws/sns_topic_publicity_has_allow_and_not_action_simultaneously |
| IAMグループに過剰なCloudFormationとPassRole権限がある | terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack |
| IAMユーザーに過剰なCloudFormation作成とPassRole権限がある | terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack |
cloudformation:CreateStack と iam:PassRole による権限昇格のおそれがある IAM ロール |
terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack |
| IAMグループに過剰なEC2起動とPassRole権限がある | terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances |
| IAMユーザーに過剰なEC2起動とPassRole権限がある | terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances |
ec2:RunInstances と iam:PassRole による権限昇格のおそれがある IAM ロール |
terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances |
| IAMグループに過剰なGlue作成とPassRole権限がある | terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint |
| IAMユーザーに過剰なGlue作成とPassRole権限がある | terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint |
glue:CreateDevEndpoint と iam:PassRole による権限昇格のおそれがある IAM ロール |
terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint |
| IAMグループに過剰なglue:UpdateDevEndpoint権限がある | terraform/aws/group_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint |
| IAMユーザーに過剰なglue:UpdateDevEndpoint権限がある | terraform/aws/user_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint |
glue:UpdateDevEndpoint による権限昇格のおそれがある IAM ロール |
terraform/aws/role_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint |
| IAM グループの iam:AddUserToGroup 権限の確認 | terraform/aws/group_with_privilege_escalation_by_actions_iam_AddUserToGroup |
| IAM ユーザーの iam:AddUserToGroup 権限の確認 | terraform/aws/user_with_privilege_escalation_by_actions_iam_AddUserToGroup |
| IAM ロールの iam:AddUserToGroup 権限の確認 | terraform/aws/role_with_privilege_escalation_by_actions_iam_AddUserToGroup |
| IAM グループの iam:AttachGroupPolicy 権限の確認 | terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachGroupPolicy |
| IAM ユーザーの iam:AttachGroupPolicy 権限の確認 | terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachGroupPolicy |
| IAM ロールの iam:AttachGroupPolicy 権限の確認 | terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachGroupPolicy |
| IAM グループの iam:AttachRolePolicy 権限の確認 | terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachRolePolicy |
| IAM ユーザーの iam:AttachRolePolicy 権限の確認 | terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachRolePolicy |
| IAM ロールの iam:AttachRolePolicy 権限の確認 | terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachRolePolicy |
| IAM グループの iam:AttachUserPolicy 権限の確認 | terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachUserPolicy |
| IAM ユーザーの iam:AttachUserPolicy 権限の確認 | terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachUserPolicy |
| IAM ロールの iam:AttachUserPolicy 権限の確認 | terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachUserPolicy |
| IAMグループに過剰なiam:CreateAccessKey権限がある | terraform/aws/group_with_privilege_escalation_by_actions_iam_CreateAccessKey |
| IAMユーザーに過剰なiam:CreateAccessKey権限がある | terraform/aws/user_with_privilege_escalation_by_actions_iam_CreateAccessKey |
iam:CreateAccessKey による権限昇格のおそれがある IAM ロール |
terraform/aws/role_with_privilege_escalation_by_actions_iam_CreateAccessKey |
| IAMグループに過剰なiam:CreateLoginProfile権限がある | terraform/aws/group_with_privilege_escalation_by_actions_iam_CreateLoginProfile |
| IAMユーザーに過剰なiam:CreateLoginProfile権限がある | terraform/aws/user_with_privilege_escalation_by_actions_iam_CreateLoginProfile |
iam:CreateLoginProfile による権限昇格のおそれがある IAM ロール |
terraform/aws/role_with_privilege_escalation_by_actions_iam_CreateLoginProfile |
| IAM グループの iam:CreatePolicyVersion 権限の確認 | terraform/aws/group_with_privilege_escalation_by_actions_iam_CreatePolicyVersion |
| IAM ユーザーの iam:CreatePolicyVersion 権限の確認 | terraform/aws/user_with_privilege_escalation_by_actions_iam_CreatePolicyVersion |
| IAM ロールの iam:CreatePolicyVersion 権限の確認 | terraform/aws/role_with_privilege_escalation_by_actions_iam_CreatePolicyVersion |
| IAM グループの iam:PutGroupPolicy 権限の確認 | terraform/aws/group_with_privilege_escalation_by_actions_iam_PutGroupPolicy |
| IAM ユーザーの iam:PutGroupPolicy 権限の確認 | terraform/aws/user_with_privilege_escalation_by_actions_iam_PutGroupPolicy |
| IAM ロールの iam:PutGroupPolicy 権限の確認 | terraform/aws/role_with_privilege_escalation_by_actions_iam_PutGroupPolicy |
| IAM グループの iam:PutRolePolicy 権限の確認 | terraform/aws/group_with_privilege_escalation_by_actions_iam_PutRolePolicy |
| IAM ユーザーの iam:PutRolePolicy 権限の確認 | terraform/aws/user_with_privilege_escalation_by_actions_iam_PutRolePolicy |
| IAM ロールの iam:PutRolePolicy 権限の確認 | terraform/aws/role_with_privilege_escalation_by_actions_iam_PutRolePolicy |
| IAM グループの iam:PutUserPolicy 権限の確認 | terraform/aws/group_with_privilege_escalation_by_actions_iam_PutUserPolicy |
| IAM ユーザーの iam:PutUserPolicy 権限の確認 | terraform/aws/user_with_privilege_escalation_by_actions_iam_PutUserPolicy |
| IAM ロールの iam:PutUserPolicy 権限の確認 | terraform/aws/role_with_privilege_escalation_by_actions_iam_PutUserPolicy |
| IAM グループの iam:SetDefaultPolicyVersion 権限の確認 | terraform/aws/group_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion |
| IAM ユーザーの iam:SetDefaultPolicyVersion 権限の確認 | terraform/aws/user_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion |
| IAM ロールの iam:SetDefaultPolicyVersion 権限の確認 | terraform/aws/role_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion |
| IAMグループに過剰な信頼ポリシー変更とロール引き受け権限がある | terraform/aws/group_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole |
| IAMユーザーに過剰な信頼ポリシー変更とロール引き受け権限がある | terraform/aws/user_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole |
iam:UpdateAssumeRolePolicy と sts:AssumeRole による権限昇格のおそれがある IAM ロール |
terraform/aws/role_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole |
| IAMグループに過剰なiam:UpdateLoginProfile権限がある | terraform/aws/group_with_privilege_escalation_by_actions_iam_UpdateLoginProfile |
| IAMユーザーに過剰なiam:UpdateLoginProfile権限がある | terraform/aws/user_with_privilege_escalation_by_actions_iam_UpdateLoginProfile |
iam:UpdateLoginProfile による権限昇格のおそれがある IAM ロール |
terraform/aws/role_with_privilege_escalation_by_actions_iam_UpdateLoginProfile |
| IAMグループに過剰なLambda作成・呼び出しとPassRole権限がある | terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_and_lambda_InvokeFunction |
| IAMユーザーに過剰なLambda作成・呼び出しとPassRole権限がある | terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_and_lambda_InvokeFunction |
lambda:CreateFunction、lambda:InvokeFunction、iam:PassRole による権限昇格のおそれがある IAM ロール |
terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_lambda_InvokeFunction |
| IAMグループに過剰なlambda:UpdateFunctionCode権限がある | terraform/aws/group_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode |
| IAMユーザーに過剰なlambda:UpdateFunctionCode権限がある | terraform/aws/user_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode |
lambda:UpdateFunctionCode による権限昇格のおそれがある IAM ロール |
terraform/aws/role_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode |
| privileged コンテナーを有効にした AWS Batch ジョブ定義 | terraform/aws/batch_job_definition_with_privileged_container_properties |
| EKS の暗号化キー設定の確認 | terraform/aws/eks_cluster_encryption_disabled |
| IAMポリシーがユーザーに直接関連付けられている | terraform/aws/iam_policies_attached_to_user |
| KMSキーの変更を通知するCloudWatchアラームが未設定 | terraform/aws/cloudwatch_disabling_or_scheduled_deletion_of_customer_created_cmk_alarm_missing |
| S3の公開ACLを無視する設定の確認 | terraform/aws/s3_bucket_without_ignore_public_acl |
| 公開 ACL とパブリックアクセスのブロックを併用する S3 バケット | terraform/aws/s3_bucket_public_acl_overridden_by_public_access_block |
| S3の公開ACLブロック設定の確認 | terraform/aws/s3_bucket_allows_public_acl |
| S3の公開バケットポリシーブロック設定の確認 | terraform/aws/s3_bucket_with_public_policy |
| サブネット CIDR に /0 を指定した RDS 構成 | terraform/aws/rds_associated_with_public_subnet |
| すべての接続元アドレスを許可する従来の DB セキュリティグループ | terraform/aws/db_security_group_has_public_interface |
| 公開アクセスが有効な DMS レプリケーションインスタンス | terraform/aws/amazon_dms_replication_instance_is_publicly_accessible |
| SQS キューポリシーの公開主体への許可の確認 | terraform/aws/sqs_policy_with_public_access |
| 公開アクセスが可能な AWS MQ ブローカー | terraform/aws/mq_broker_is_publicly_accessible |
| 公開アクセスが可能な AWS MSK ブローカー | terraform/aws/msk_broker_is_publicly_accessible |
| 公開アクセスが可能な AWS Neptune クラスターインスタンス | terraform/aws/neptune_cluster_instance_is_publicly_accessible |
| ワイルドカードのプリンシパルを使用するECRポリシー | terraform/aws/ecr_repository_is_publicly_accessible |
| アクセス主体にワイルドカードを指定したSNSトピックポリシー | terraform/aws/sns_topic_is_publicly_accessible |
| CloudTrail ログバケットの公開アクセスの確認 | terraform/aws/cloudtrail_log_files_s3_bucket_is_publicly_accessible |
| 公開アクセス設定の確認が必要な RDS 構成 | terraform/aws/rds_db_instance_publicly_accessible |
| EC2インスタンスのパブリックIP割り当ての確認 | terraform/aws/ec2_instance_has_public_ip |
| パブリックIPが割り当てられたECSサービス | terraform/aws/ecs_services_assigned_with_public_ip_address |
| パブリック IP を自動割り当てする VPC サブネット | terraform/aws/vpc_subnet_assigns_public_ip |
| 接続元の範囲を確認する必要がある従来の DB セキュリティグループ | terraform/aws/db_security_group_open_to_large_scope |
| IAM ロールの信頼ポリシーの確認 | terraform/aws/iam_role_with_full_privileges |
| KMS キーのアクセスポリシーの確認 | terraform/aws/kms_key_with_full_permissions |
| Secrets Manager のシークレットアクセスポリシーの確認 | terraform/aws/secrets_manager_with_vulnerable_policy |
| AWS ECS サービスロールの権限確認 | terraform/aws/ecs_service_admin_role_is_present |
| ECSタスクのネットワークモードの確認 | terraform/aws/ecs_task_definition_network_mode_not_recommended |
| 過剰な権限を持つ実行ロールを使用する AWS Lambda 関数 | terraform/aws/lambda_function_with_privileged_role |
| アカウント・リージョンで EBS の既定の暗号化が無効 | terraform/aws/ebs_default_encryption_disabled |
| AWS デフォルト VPC の設定の確認 | terraform/aws/default_vpc_exists |
| EC2インスタンスのデフォルトセキュリティグループ使用の確認 | terraform/aws/ec2_instance_using_default_security_group |
| ネットワークゲートウェイ変更を監視するアラームの未設定 | terraform/aws/cloudwatch_network_gateways_changes_alarm_missing |
| ノード間暗号化がない Elasticsearch ドメイン | terraform/aws/elasticsearch_domain_not_encrypted_node_to_node |
| ElastiCacheノードが複数のアベイラビリティーゾーンに分散されていない | terraform/aws/elasticache_nodes_not_created_across_multi_az |
| データ流出に悪用されるおそれがある IAM ポリシー | terraform/aws/iam_policy_allows_for_data_exfiltration |
| ルートテーブル変更を監視するアラームの未設定 | terraform/aws/cloudwatch_route_table_changes_alarm_missing |
| AWS Route 53レコードの値が空 | terraform/aws/route53_record_undefined |
| CloudFrontリクエストログ設定の確認 | terraform/aws/cloudfront_logging_disabled |
| AWS CloudTrailのログ記録が無効 | terraform/aws/cloudtrail_logging_disabled |
| DocumentDBログエクスポート設定の確認 | terraform/aws/docdb_logging_disabled |
| CloudTrailログバケットのアクセスログ設定の確認 | terraform/aws/cloudtrail_log_files_s3_bucket_with_logging_disabled |
| EKSクラスターのログ記録が無効 | terraform/aws/eks_cluster_log_disabled |
| Elasticsearchログ発行設定の確認 | terraform/aws/elasticsearch_logs_disabled |
| ルートユーザーの使用を通知するCloudWatchアラームが未設定 | terraform/aws/cloudwatch_root_account_use_alarm_missing |
| root という名前の IAM ユーザーのアクセスキーの確認 | terraform/aws/iam_access_key_is_exposed |
| TLS証明書の有効期限が切れている | terraform/aws/certificate_has_expired |
| IAM サービスロールの信頼する主体の確認 | terraform/aws/iam_policy_grants_assumerole_permission_across_all_services |
| 操作とプリンシパルにワイルドカードを使う S3 バケットポリシー | terraform/aws/s3_bucket_with_all_permissions |
| iam:PassRoleの対象がすべてのロールに広がっている | terraform/aws/iam_role_policy_passrole_allows_all |
| 認証されたすべての AWS アカウントに読み取りを許可する S3 バケット ACL | terraform/aws/s3_bucket_acl_allows_read_to_any_authenticated_user |
| SQS キューポリシーの広すぎる操作許可の確認 | terraform/aws/sqs_policy_allows_all_actions |
| IAM ロールのアカウント単位の信頼を確認 | terraform/aws/iam_role_allows_all_principals_to_assume |
| 削除操作のプリンシパルにワイルドカードを指定した S3 バケットポリシー | terraform/aws/s3_bucket_allows_delete_action_from_all_principals |
| Put 操作のプリンシパルにワイルドカードを指定した S3 バケットポリシー | terraform/aws/s3_bucket_allows_put_action_from_all_principals |
| ワイルドカードのプリンシパルを使用する S3 バケットポリシー | terraform/aws/s3_bucket_access_to_any_principal |
| すべての主体に Get 権限を許可する S3 バケットポリシー | terraform/aws/s3_bucket_allows_get_action_from_all_principals |
| すべての主体に一覧取得を許可する S3 バケットポリシー | terraform/aws/s3_bucket_allows_list_action_from_all_principals |
| デフォルトセキュリティグループの通信許可の確認 | terraform/aws/vpc_default_security_group_accepts_all_traffic |
| 全アドレスとの通信を許可する AWS のデフォルトセキュリティグループ | terraform/aws/default_security_groups_with_unrestricted_traffic |
| 未使用のセキュリティグループの確認 | terraform/aws/security_groups_not_used |
| 機密性の高いサービスポートへのプライベートネットワークからのアクセスの確認 | terraform/aws/sensitive_port_is_exposed_to_wide_private_network |
| 全アドレスから管理用・内部サービス用ポートを許可する AWS セキュリティグループ | terraform/aws/sensitive_port_is_exposed_to_entire_network |
| ElastiCache Redisの自動バックアップが無効 | terraform/aws/elasticache_redis_cluster_without_backup |
| S3バージョニング設定の確認 | terraform/aws/s3_bucket_without_versioning |
| セキュリティグループの変更を通知するCloudWatchアラームが未設定 | terraform/aws/cloudwatch_security_group_changes_alarm_missing |
| AWS ElastiCache Redis OSSのエンジンバージョンの確認 | terraform/aws/redis_not_compliant |
| API GatewayカスタムドメインのTLSポリシーの確認 | terraform/aws/api_gateway_without_security_policy |
| ボリューム暗号化のない WorkSpace | terraform/aws/workspaces_workspace_volume_not_encrypted |
| IAMユーザーの初期パスワード設定の確認 | terraform/aws/no_password_policy_enabled |
| 非暗号化 EBS ボリュームから作成された AWS スナップショット | terraform/aws/ebs_volume_snapshot_not_encrypted |
| RDS クラスタースナップショットの暗号化の確認 | terraform/aws/rds_database_cluster_not_encrypted |
| 権限エラーを監視するCloudWatch設定の見直し | terraform/aws/cloudwatch_unauthorized_access_defined_alarm_missing |
| ユーザーが所属していないIAMグループ | terraform/aws/iam_group_without_users |
| IAM ユーザーのパスワード変更権限の確認 | terraform/aws/aws_password_policy_with_unchangeable_passwords |
| 無効な KMS カスタマーマネージドキーの利用確認 | terraform/aws/cmk_is_unusable |
| AWS ALBの削除保護が無効 | terraform/aws/alb_deletion_protection_disabled |
| EC2の詳細モニタリングが無効 | terraform/aws/ec2_instance_monitoring_disabled |
| DynamoDB テーブルの暗号化キー設定の確認 | terraform/aws/dynamodb_table_not_encrypted |
| S3 オブジェクトのサーバー側暗号化設定の確認 | terraform/aws/s3_bucket_object_not_encrypted |
| Amazon Data Firehose のサーバー側暗号化設定の確認 | terraform/aws/kinesis_sse_not_configured |
| S3 CORSの許可範囲の確認 | terraform/aws/s3_bucket_with_unsecured_cors_rule |
| ELBポリシーのSSL/TLSプロトコルの確認 | terraform/aws/elb_using_insecure_protocols |
| ポートの公開範囲を確認すべき AWS セキュリティグループ | terraform/aws/unknown_port_exposed_to_internet |
| MSK クラスターの暗号化設定の確認 | terraform/aws/msk_cluster_encryption_disabled |
| Athena データベース作成クエリの結果暗号化設定の確認 | terraform/aws/athena_database_not_encrypted |
| SageMaker エンドポイントの保存時暗号化キーを確認 | terraform/aws/sagemaker_endpoint_configuration_encryption_disabled |
| Amazon MQ ブローカーの暗号化キー設定の確認 | terraform/aws/amazon_mq_broker_encryption_disabled |
| Glue Data Catalog と接続パスワードの暗号化の確認 | terraform/aws/glue_data_catalog_encryption_disabled |
| Glue Security Configuration の暗号化設定の確認 | terraform/aws/glue_security_configuration_encryption_disabled |
| メッセージ暗号化のない SNS トピック | terraform/aws/sns_topic_not_encrypted |
| 暗号化されていない API Gateway キャッシュ | terraform/aws/api_gateway_method_settings_cache_not_encrypted |
| 暗号化されていない AWS AMI | terraform/aws/ami_not_encrypted |
| 暗号化されていない AWS EBS ボリューム | terraform/aws/ebs_volume_encryption_disabled |
| 暗号化されていない AWS EFS ファイルシステム | terraform/aws/efs_not_encrypted |
| 暗号化されていない AWS ブロックデバイスマッピング | terraform/aws/block_device_is_not_encrypted |
| AWS Classic ELB の暗号スイートポリシーの確認 | terraform/aws/elb_using_weak_ciphers |
| AWS AMI のアカウント間共有の確認 | terraform/aws/ami_shared_with_multiple_accounts |
| Elastic IP の用途と関連付けの確認 | terraform/aws/aws_eip_not_attached_to_any_instance |
| Auto Scalingグループのロードバランサー関連付けの確認 | terraform/aws/auto_scaling_group_with_no_associated_elb |
| RDSインスタンスが古いCA証明書を使用している | terraform/aws/ca_certificate_identifier_is_outdated |
| Lambda 関数ポリシーの広すぎる操作許可の確認 | terraform/aws/lambda_with_vulnerable_policy |
| ワイルドカード principal を使用する Lambda 呼び出し権限 | terraform/aws/lambda_permission_principal_is_wildcard |
| アクセス範囲が過剰な API Gateway REST API ポリシー | terraform/aws/rest_api_with_vulnerable_policy |
| 公開アクセス設定の確認が必要な AWS Redshift クラスター | terraform/aws/redshift_publicly_accessible |
| AWS SQS キューポリシーのアクセス範囲の確認 | terraform/aws/sqs_queue_exposed |
| 運用タグが未設定 | terraform/aws/resource_not_using_tags |
| API Gatewayメソッドの認証設定の確認 | terraform/aws/api_gateway_with_open_access |
| 機密性の高いサービスポートへのアクセス元の確認 | terraform/aws/sensitive_port_is_exposed_to_small_public_network |
| AWS ALBが無効なヘッダーを削除しない | terraform/aws/alb_not_dropping_invalid_headers |
| Redshift の保存時暗号化の確認 | terraform/aws/redshift_not_encrypted |
| Amazon Aurora の保存時の暗号化設定の確認 | terraform/aws/aurora_with_disabled_at_rest_encryption |
| 保存時の暗号化がない AWS DAX クラスター | terraform/aws/dax_cluster_not_encrypted |
| ストレージ暗号化がない Amazon DocumentDB クラスター | terraform/aws/docdb_cluster_not_encrypted |
| 保存時暗号化のない AWS ElastiCache レプリケーショングループ | terraform/aws/elasticache_replication_group_not_encrypted_at_rest |
| 保存時暗号化のない AWS Elasticsearch ドメイン | terraform/aws/elasticsearch_not_encrypted_at_rest |
| 保存時暗号化のない AWS Neptune クラスター | terraform/aws/neptune_database_cluster_encryption_disabled |
| ストレージ暗号化がない AWS DB インスタンス | terraform/aws/db_instance_storage_not_encrypted |
| RDS クラスターの保存時暗号化の確認 | terraform/aws/rds_storage_not_encrypted |
| 転送時暗号化が無効な EFS ボリューム | terraform/aws/efs_volume_with_disabled_transit_encryption |
| 転送時暗号化が無効な ElastiCache レプリケーショングループ | terraform/aws/elasticache_replication_group_not_encrypted_at_transit |
| VPC ピアリング経路の宛先範囲の確認 | terraform/aws/vpc_peering_route_table_with_unrestricted_cidr |
| IAM ポリシーの広すぎる管理権限の確認 | terraform/aws/iam_policies_with_full_privileges |
| Identity Center のアクセス許可セットの過剰な権限を確認 | terraform/aws/sso_policy_with_full_priveleges |
| 過剰な権限を許可する AWS IAM ポリシー | terraform/aws/iam_policy_grants_full_permissions |
| 公開 ACL を指定した S3 バケット設定 | terraform/aws/s3_bucket_acl_allows_read_or_write_to_all_users |
| すべての IPv4 アドレスを許可する EC2-Classic DB セキュリティグループ | terraform/aws/db_security_group_with_public_scope |
| インターネット全体を許可する EKS の公開アクセス CIDR | terraform/aws/eks_cluster_has_public_access_cidrs |
| 全接続元アドレスからの受信を許可する AWS セキュリティグループ | terraform/aws/unrestricted_security_group_ingress |
| SES アイデンティティポリシーのアクセス権限の確認 | terraform/aws/ses_policy_with_allowed_iam_actions |
| API Gatewayデプロイステージのアクセスログ設定の確認 | terraform/aws/api_gateway_deployment_without_access_log_setting |
| API Gatewayステージのログ設定の確認 | terraform/aws/api_gateway_access_logging_disabled |
| Classic ELBのアクセスログが無効 | terraform/aws/elb_access_logging_disabled |
| ELBv2ロードバランサーのアクセスログ設定の確認 | terraform/aws/elb_v2_lb_access_log_disabled |
| 接続元セキュリティグループがない EKS ノードのリモートアクセス | terraform/aws/eks_node_group_remote_access_disabled |
| AWS S3静的ウェブサイトの公開範囲の確認 | terraform/aws/s3_static_website_host_enabled |
| CloudFrontのセキュリティポリシーが古いTLSを許可している | terraform/aws/cloudfront_without_minimum_protocol_tls_1.2 |
| CloudFrontのカスタムドメイン用証明書の確認 | terraform/aws/vulnerable_default_ssl_certificate |
| EFS ファイルシステムポリシーのアクセス権限の確認 | terraform/aws/efs_with_vulnerable_policy |
| AWS Glue Data Catalog ポリシーの権限の確認 | terraform/aws/glue_with_vulnerable_policy |
| Elasticsearch ドメインポリシーのアクセス権限の確認 | terraform/aws/elasticsearch_domain_with_vulnerable_policy |
| IAMユーザーにコンソールアクセスがある | terraform/aws/iam_user_with_access_to_console |
| Athena ワークグループの結果暗号化設定の確認 | terraform/aws/athena_workgroup_not_encrypted |
| イメージタグを変更できる AWS ECR リポジトリ | terraform/aws/ecr_image_tag_not_immutable |
| パブリック EC2 とプライベート EC2 の IAM ロール共有 | terraform/aws/public_and_private_ec2_share_role |
| S3の公開バケットに対するアクセス制限の確認 | terraform/aws/s3_bucket_without_restriction_of_public_bucket |
| パブリックアクセスが有効な EKS クラスター | terraform/aws/eks_cluster_has_public_access |
| IAMユーザーのアクセスキー数の確認 | terraform/aws/iam_user_too_many_access_keys |
| IAM ユーザーの有効なアクセスキーの確認 | terraform/aws/root_account_has_active_access_keys |
| AWS Global Acceleratorのフローログが無効 | terraform/aws/global_accelerator_flow_logs_disabled |