forked from vmware-samples/secureclouds-remediation-jobs
-
Notifications
You must be signed in to change notification settings - Fork 0
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Add remediation jobs for storage and RDP violations (#12) #6
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
* add remediation job for closing RDP access * Add remediation job for remove public access for blob * Add remediation job to allow only https traffic to storage account * update READMEs to fix broken links Co-authored-by: Mohammad Zuber Khan <[email protected]>
mzkhan
added a commit
that referenced
this pull request
Nov 4, 2020
* PLA-17940 updating constraints and fixing s3_enable_access_logging to… (#3) * PLA-17940 updating constraints and fixing s3_enable_access_logging to not remediate the logging target bucket * PLA-17940 fixing copyright info * Updated readme to have link for reporting issues (#4) Co-authored-by: svikramjeet <[email protected]> * S3 access logs permissions (#6) * Update minimum permissions for the job * Add more logs when permission is missing Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Paul Allen <[email protected]> Co-authored-by: svikramjeet <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]>
mzkhan
added a commit
that referenced
this pull request
Nov 4, 2020
* PLA-17940 updating constraints and fixing s3_enable_access_logging to… (#3) * PLA-17940 updating constraints and fixing s3_enable_access_logging to not remediate the logging target bucket * PLA-17940 fixing copyright info * Updated readme to have link for reporting issues (#4) Co-authored-by: svikramjeet <[email protected]> * S3 access logs permissions (#6) * Update minimum permissions for the job * Add more logs when permission is missing Co-authored-by: Mohammad Zuber Khan <[email protected]> * change the way cloudAccountId is parsed from Job Paramaters (#9) Co-authored-by: Mohammad Zuber Khan <[email protected]> * PLA-16779: Add remediation job for azure security group port 22 (#10) * PLA-16779: Add remediation job for azure security group port 22 * add test dependencies * update README.md * add deployment info to the README * add rule information Co-authored-by: Mohammad Zuber Khan <[email protected]> * Add remediation job for closing port 22 for VM (#11) * PLA-18743: Add remediation job for closing port 22 for VM * add tests for azure_vm_close_port_22 to tox * add deployment details Co-authored-by: Mohammad Zuber Khan <[email protected]> * Add remediation jobs for storage and RDP violations (#12) * add remediation job for closing RDP access * Add remediation job for remove public access for blob * Add remediation job to allow only https traffic to storage account * update READMEs to fix broken links Co-authored-by: Mohammad Zuber Khan <[email protected]> * fix the parameters passed for remediation (#13) Co-authored-by: Mohammad Zuber Khan <[email protected]> * add check for existing permissions before adding new (vmware-samples#15) Co-authored-by: Mohammad Zuber Khan <[email protected]> * Fix ports range for network security groups (vmware-samples#19) (vmware-samples#20) * handle the case when the security rule port is a range * Add minimum permissions for each remediation jobs * add link to built in roles Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Paul Allen <[email protected]> Co-authored-by: svikramjeet <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]>
mzkhan
added a commit
that referenced
this pull request
Nov 4, 2020
* Release/v1.0.0 (#7) * PLA-17940 updating constraints and fixing s3_enable_access_logging to… (#3) * PLA-17940 updating constraints and fixing s3_enable_access_logging to not remediate the logging target bucket * PLA-17940 fixing copyright info * Updated readme to have link for reporting issues (#4) Co-authored-by: svikramjeet <[email protected]> * S3 access logs permissions (#6) * Update minimum permissions for the job * Add more logs when permission is missing Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Paul Allen <[email protected]> Co-authored-by: svikramjeet <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]> * Release/v1.1.0 (vmware-samples#17) * PLA-17940 updating constraints and fixing s3_enable_access_logging to… (#3) * PLA-17940 updating constraints and fixing s3_enable_access_logging to not remediate the logging target bucket * PLA-17940 fixing copyright info * Updated readme to have link for reporting issues (#4) Co-authored-by: svikramjeet <[email protected]> * S3 access logs permissions (#6) * Update minimum permissions for the job * Add more logs when permission is missing Co-authored-by: Mohammad Zuber Khan <[email protected]> * change the way cloudAccountId is parsed from Job Paramaters (#9) Co-authored-by: Mohammad Zuber Khan <[email protected]> * PLA-16779: Add remediation job for azure security group port 22 (#10) * PLA-16779: Add remediation job for azure security group port 22 * add test dependencies * update README.md * add deployment info to the README * add rule information Co-authored-by: Mohammad Zuber Khan <[email protected]> * Add remediation job for closing port 22 for VM (#11) * PLA-18743: Add remediation job for closing port 22 for VM * add tests for azure_vm_close_port_22 to tox * add deployment details Co-authored-by: Mohammad Zuber Khan <[email protected]> * Add remediation jobs for storage and RDP violations (#12) * add remediation job for closing RDP access * Add remediation job for remove public access for blob * Add remediation job to allow only https traffic to storage account * update READMEs to fix broken links Co-authored-by: Mohammad Zuber Khan <[email protected]> * fix the parameters passed for remediation (#13) Co-authored-by: Mohammad Zuber Khan <[email protected]> * add check for existing permissions before adding new (vmware-samples#15) Co-authored-by: Mohammad Zuber Khan <[email protected]> * Fix ports range for network security groups (vmware-samples#19) (vmware-samples#20) * handle the case when the security rule port is a range * Add minimum permissions for each remediation jobs * add link to built in roles Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Paul Allen <[email protected]> Co-authored-by: svikramjeet <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Paul Allen <[email protected]> Co-authored-by: svikramjeet <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]>
mzkhan
added a commit
that referenced
this pull request
Nov 4, 2020
* PLA-17940 updating constraints and fixing s3_enable_access_logging to… (#3) * PLA-17940 updating constraints and fixing s3_enable_access_logging to not remediate the logging target bucket * PLA-17940 fixing copyright info * Updated readme to have link for reporting issues (#4) Co-authored-by: svikramjeet <[email protected]> * S3 access logs permissions (#6) * Update minimum permissions for the job * Add more logs when permission is missing Co-authored-by: Mohammad Zuber Khan <[email protected]> * change the way cloudAccountId is parsed from Job Paramaters (#9) Co-authored-by: Mohammad Zuber Khan <[email protected]> * PLA-16779: Add remediation job for azure security group port 22 (#10) * PLA-16779: Add remediation job for azure security group port 22 * add test dependencies * update README.md * add deployment info to the README * add rule information Co-authored-by: Mohammad Zuber Khan <[email protected]> * Add remediation job for closing port 22 for VM (#11) * PLA-18743: Add remediation job for closing port 22 for VM * add tests for azure_vm_close_port_22 to tox * add deployment details Co-authored-by: Mohammad Zuber Khan <[email protected]> * Add remediation jobs for storage and RDP violations (#12) * add remediation job for closing RDP access * Add remediation job for remove public access for blob * Add remediation job to allow only https traffic to storage account * update READMEs to fix broken links Co-authored-by: Mohammad Zuber Khan <[email protected]> * fix the parameters passed for remediation (#13) Co-authored-by: Mohammad Zuber Khan <[email protected]> * add check for existing permissions before adding new (vmware-samples#15) Co-authored-by: Mohammad Zuber Khan <[email protected]> * Fix ports range for network security groups (vmware-samples#19) * handle the case when the security rule port is a range * Add minimum permissions for each remediation jobs * add link to built in roles Co-authored-by: Mohammad Zuber Khan <[email protected]> * update the remediation job payload (vmware-samples#21) Co-authored-by: Mohammad Zuber Khan <[email protected]> * PLA-20459: Add rule information for the remediation job (vmware-samples#22) * update the remediation job payload (vmware-samples#21) Co-authored-by: Mohammad Zuber Khan <[email protected]> * PLA-20459: Add rule information for the remediation job * add another rule remediated by the job Co-authored-by: Mohammad Zuber Khan <[email protected]> * Master -> Dev Merge (vmware-samples#23) * Release/v1.0.0 (#7) * PLA-17940 updating constraints and fixing s3_enable_access_logging to… (#3) * PLA-17940 updating constraints and fixing s3_enable_access_logging to not remediate the logging target bucket * PLA-17940 fixing copyright info * Updated readme to have link for reporting issues (#4) Co-authored-by: svikramjeet <[email protected]> * S3 access logs permissions (#6) * Update minimum permissions for the job * Add more logs when permission is missing Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Paul Allen <[email protected]> Co-authored-by: svikramjeet <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]> * Release/v1.1.0 (vmware-samples#17) * PLA-17940 updating constraints and fixing s3_enable_access_logging to… (#3) * PLA-17940 updating constraints and fixing s3_enable_access_logging to not remediate the logging target bucket * PLA-17940 fixing copyright info * Updated readme to have link for reporting issues (#4) Co-authored-by: svikramjeet <[email protected]> * S3 access logs permissions (#6) * Update minimum permissions for the job * Add more logs when permission is missing Co-authored-by: Mohammad Zuber Khan <[email protected]> * change the way cloudAccountId is parsed from Job Paramaters (#9) Co-authored-by: Mohammad Zuber Khan <[email protected]> * PLA-16779: Add remediation job for azure security group port 22 (#10) * PLA-16779: Add remediation job for azure security group port 22 * add test dependencies * update README.md * add deployment info to the README * add rule information Co-authored-by: Mohammad Zuber Khan <[email protected]> * Add remediation job for closing port 22 for VM (#11) * PLA-18743: Add remediation job for closing port 22 for VM * add tests for azure_vm_close_port_22 to tox * add deployment details Co-authored-by: Mohammad Zuber Khan <[email protected]> * Add remediation jobs for storage and RDP violations (#12) * add remediation job for closing RDP access * Add remediation job for remove public access for blob * Add remediation job to allow only https traffic to storage account * update READMEs to fix broken links Co-authored-by: Mohammad Zuber Khan <[email protected]> * fix the parameters passed for remediation (#13) Co-authored-by: Mohammad Zuber Khan <[email protected]> * add check for existing permissions before adding new (vmware-samples#15) Co-authored-by: Mohammad Zuber Khan <[email protected]> * Fix ports range for network security groups (vmware-samples#19) (vmware-samples#20) * handle the case when the security rule port is a range * Add minimum permissions for each remediation jobs * add link to built in roles Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Paul Allen <[email protected]> Co-authored-by: svikramjeet <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]> Co-authored-by: Paul Allen <[email protected]> Co-authored-by: svikramjeet <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]> * Revert "Master -> Dev Merge (vmware-samples#23)" (vmware-samples#24) This reverts commit a875459. Co-authored-by: Paul Allen <[email protected]> Co-authored-by: svikramjeet <[email protected]> Co-authored-by: Zuber <[email protected]> Co-authored-by: Mohammad Zuber Khan <[email protected]>
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
add remediation job for closing RDP access
Add remediation job for remove public access for blob
Add remediation job to allow only https traffic to storage account
update READMEs to fix broken links
Co-authored-by: Mohammad Zuber Khan [email protected]