Skip to content

Commit

Permalink
Merge pull request #6999 from Checkmarx/feature/kicsbot-update-querie…
Browse files Browse the repository at this point in the history
…s-docs

docs(queries): update queries catalog
  • Loading branch information
gabriel-cx authored Apr 12, 2024
2 parents 87e80fc + 23c2672 commit f4d132d
Show file tree
Hide file tree
Showing 24 changed files with 48 additions and 48 deletions.
32 changes: 16 additions & 16 deletions docs/queries/all-queries.md

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion docs/queries/ansible-queries.md
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,7 @@ Below are listed queries related to Ansible AWS:
|Auto Scaling Group With No Associated ELB<br/><sup><sub>050f085f-a8db-4072-9010-2cca235cc02f</sub></sup>|<span style="color:#ff7213">Medium</span>|Availability|<a href="../ansible-queries/aws/050f085f-a8db-4072-9010-2cca235cc02f" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/ec2_asg_module.html#parameter-load_balancers">Documentation</a><br/>|
|CMK Is Unusable<br/><sup><sub>133fee21-37ef-45df-a563-4d07edc169f4</sub></sup>|<span style="color:#ff7213">Medium</span>|Availability|<a href="../ansible-queries/aws/133fee21-37ef-45df-a563-4d07edc169f4" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/aws_kms_module.html#parameter-enabled">Documentation</a><br/>|
|RDS With Backup Disabled<br/><sup><sub>e69890e6-fce5-461d-98ad-cb98318dfc96</sub></sup>|<span style="color:#ff7213">Medium</span>|Backup|<a href="../ansible-queries/aws/e69890e6-fce5-461d-98ad-cb98318dfc96" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/rds_instance_module.html#parameter-backup_retention_period">Documentation</a><br/>|
|S3 Bucket Without Versioning<br/><sup><sub>9232306a-f839-40aa-b3ef-b352001da9a5</sub></sup>|<span style="color:#ff7213">Medium</span>|Backup|<a href="../ansible-queries/aws/9232306a-f839-40aa-b3ef-b352001da9a5" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/amazon/aws/s3_bucket_module.html#parameter-versioning">Documentation</a><br/>|
|Stack Retention Disabled<br/><sup><sub>17d5ba1d-7667-4729-b1a6-b11fde3db7f7</sub></sup>|<span style="color:#ff7213">Medium</span>|Backup|<a href="../ansible-queries/aws/17d5ba1d-7667-4729-b1a6-b11fde3db7f7" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/cloudformation_stack_set_module.html#parameter-purge_stacks">Documentation</a><br/>|
|AMI Not Encrypted<br/><sup><sub>97707503-a22c-4cd7-b7c0-f088fa7cf830</sub></sup>|<span style="color:#ff7213">Medium</span>|Encryption|<a href="../ansible-queries/aws/97707503-a22c-4cd7-b7c0-f088fa7cf830" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/amazon/aws/ec2_ami_module.html">Documentation</a><br/>|
|CA Certificate Identifier Is Outdated<br/><sup><sub>5eccd62d-8b4d-46d3-83ea-1879f3cbd3ce</sub></sup>|<span style="color:#ff7213">Medium</span>|Encryption|<a href="../ansible-queries/aws/5eccd62d-8b4d-46d3-83ea-1879f3cbd3ce" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/rds_instance_module.html#parameter-ca_certificate_identifier">Documentation</a><br/>|
Expand Down Expand Up @@ -99,7 +100,6 @@ Below are listed queries related to Ansible AWS:
|CloudFront Logging Disabled<br/><sup><sub>d31cb911-bf5b-4eb6-9fc3-16780c77c7bd</sub></sup>|<span style="color:#ff7213">Medium</span>|Observability|<a href="../ansible-queries/aws/d31cb911-bf5b-4eb6-9fc3-16780c77c7bd" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/cloudfront_distribution_module.html">Documentation</a><br/>|
|CloudTrail Logging Disabled<br/><sup><sub>d4a73c49-cbaa-4c6f-80ee-d6ef5a3a26f5</sub></sup>|<span style="color:#ff7213">Medium</span>|Observability|<a href="../ansible-queries/aws/d4a73c49-cbaa-4c6f-80ee-d6ef5a3a26f5" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/cloudtrail_module.html#parameter-enable_logging">Documentation</a><br/>|
|S3 Bucket Logging Disabled<br/><sup><sub>c3b9f7b0-f5a0-49ec-9cbc-f1e346b7274d</sub></sup>|<span style="color:#ff7213">Medium</span>|Observability|<a href="../ansible-queries/aws/c3b9f7b0-f5a0-49ec-9cbc-f1e346b7274d" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/amazon/aws/s3_bucket_module.html#parameter-debug_botocore_endpoint_logs">Documentation</a><br/>|
|S3 Bucket Without Versioning<br/><sup><sub>9232306a-f839-40aa-b3ef-b352001da9a5</sub></sup>|<span style="color:#ff7213">Medium</span>|Observability|<a href="../ansible-queries/aws/9232306a-f839-40aa-b3ef-b352001da9a5" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/amazon/aws/s3_bucket_module.html#parameter-versioning">Documentation</a><br/>|
|No Stack Policy<br/><sup><sub>ffe0fd52-7a8b-4a5c-8fc7-49844418e6c9</sub></sup>|<span style="color:#ff7213">Medium</span>|Resource Management|<a href="../ansible-queries/aws/ffe0fd52-7a8b-4a5c-8fc7-49844418e6c9" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/amazon/aws/cloudformation_module.html">Documentation</a><br/>|
|Authentication Without MFA<br/><sup><sub>eee107f9-b3d8-45d3-b9c6-43b5a7263ce1</sub></sup>|<span style="color:#edd57e">Low</span>|Access Control|<a href="../ansible-queries/aws/eee107f9-b3d8-45d3-b9c6-43b5a7263ce1" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/iam_mfa_device_info_module.html">Documentation</a><br/>|
|ECS Service Without Running Tasks<br/><sup><sub>f5c45127-1d28-4b49-a692-0b97da1c3a84</sub></sup>|<span style="color:#edd57e">Low</span>|Availability|<a href="../ansible-queries/aws/f5c45127-1d28-4b49-a692-0b97da1c3a84" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/ecs_service_module.html#ansible-collections-community-aws-ecs-service-module">Documentation</a><br/>|
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ hide:
- **Query name:** S3 Bucket Without Versioning
- **Platform:** Ansible
- **Severity:** <span style="color:#ff7213">Medium</span>
- **Category:** Observability
- **Category:** Backup
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/ansible/aws/s3_bucket_without_versioning)

### Description
Expand Down
2 changes: 1 addition & 1 deletion docs/queries/azureresourcemanager-queries.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,13 +35,13 @@ This page contains all queries from AzureResourceManager.
|Phone Number Not Set For Security Contacts<br/><sup><sub>3e9fcc67-1f64-405f-b2f9-0a6be17598f0</sub></sup>|<span style="color:#edd57e">Low</span>|Best Practices|<a href="../azureresourcemanager-queries/azure/3e9fcc67-1f64-405f-b2f9-0a6be17598f0" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.security/securitycontacts?tabs=json">Documentation</a><br/>|
|AKS Dashboard Is Enabled<br/><sup><sub>c62d3b92-9a11-4ffd-b7b7-6faaae83faed</sub></sup>|<span style="color:#edd57e">Low</span>|Insecure Configurations|<a href="../azureresourcemanager-queries/azure/c62d3b92-9a11-4ffd-b7b7-6faaae83faed" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.containerservice/managedclusters?tabs=json#managedclusteraddonprofile">Documentation</a><br/>|
|AKS With Authorized IP Ranges Disabled<br/><sup><sub>2583fab1-953b-4fae-bd02-4a136a6c21f9</sub></sup>|<span style="color:#edd57e">Low</span>|Networking and Firewall|<a href="../azureresourcemanager-queries/azure/2583fab1-953b-4fae-bd02-4a136a6c21f9" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.containerservice/managedclusters?tabs=json#managedclusterapiserveraccessprofile-object">Documentation</a><br/>|
|Standard Price Is Not Selected<br/><sup><sub>2081c7d6-2851-4cce-bda5-cb49d462da42</sub></sup>|<span style="color:#edd57e">Low</span>|Networking and Firewall|<a href="../azureresourcemanager-queries/azure/2081c7d6-2851-4cce-bda5-cb49d462da42" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.security/pricings?tabs=json#pricingproperties-object">Documentation</a><br/>|
|Storage Account Allows Default Network Access<br/><sup><sub>9073f073-5d60-4b46-b569-0d6baa80ed95</sub></sup>|<span style="color:#edd57e">Low</span>|Networking and Firewall|<a href="../azureresourcemanager-queries/azure/9073f073-5d60-4b46-b569-0d6baa80ed95" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.storage/storageaccounts?tabs=json#storageaccountpropertiescreateparameters-object">Documentation</a><br/>|
|Website with 'Http20Enabled' Disabled<br/><sup><sub>70111098-7f85-48f0-b1b4-e4261cf5f61b</sub></sup>|<span style="color:#edd57e">Low</span>|Networking and Firewall|<a href="../azureresourcemanager-queries/azure/70111098-7f85-48f0-b1b4-e4261cf5f61b" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.web/sites?tabs=json#siteproperties-object">Documentation</a><br/>|
|Log Profile Incorrect Category<br/><sup><sub>4d522e7b-f938-4d51-a3b1-974ada528bd3</sub></sup>|<span style="color:#edd57e">Low</span>|Observability|<a href="../azureresourcemanager-queries/azure/4d522e7b-f938-4d51-a3b1-974ada528bd3" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.insights/2016-03-01/logprofiles?tabs=json#logprofileproperties-object">Documentation</a><br/>|
|SQL Server Database With Unrecommended Retention Days<br/><sup><sub>c09cdac2-7670-458a-bf6c-efad6880973a</sub></sup>|<span style="color:#edd57e">Low</span>|Observability|<a href="../azureresourcemanager-queries/azure/c09cdac2-7670-458a-bf6c-efad6880973a" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.sql/servers/databases/auditingsettings?tabs=json">Documentation</a><br/>|
|Unrecommended Log Profile Retention Policy<br/><sup><sub>25684eac-daaa-4c2c-94b4-8d2dbb627909</sub></sup>|<span style="color:#edd57e">Low</span>|Observability|<a href="../azureresourcemanager-queries/azure/25684eac-daaa-4c2c-94b4-8d2dbb627909" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.insights/2016-03-01/logprofiles?tabs=json#retentionpolicy-object">Documentation</a><br/>|
|Unrecommended Network Watcher Flow Log Retention Policy<br/><sup><sub>564b70f8-41cd-4690-aff8-bb53add86bc9</sub></sup>|<span style="color:#edd57e">Low</span>|Observability|<a href="../azureresourcemanager-queries/azure/564b70f8-41cd-4690-aff8-bb53add86bc9" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.network/2019-11-01/networkwatchers/flowlogs?tabs=json#retentionpolicyparameters-object">Documentation</a><br/>|
|Standard Price Is Not Selected<br/><sup><sub>2081c7d6-2851-4cce-bda5-cb49d462da42</sub></sup>|<span style="color:#edd57e">Low</span>|Resource Management|<a href="../azureresourcemanager-queries/azure/2081c7d6-2851-4cce-bda5-cb49d462da42" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.security/pricings?tabs=json#pricingproperties-object">Documentation</a><br/>|
|Account Admins Not Notified By Email<br/><sup><sub>a8852cc0-fd4b-4fc7-9372-1e43fad0732e</sub></sup>|<span style="color:#5bc0de">Info</span>|Best Practices|<a href="../azureresourcemanager-queries/azure/a8852cc0-fd4b-4fc7-9372-1e43fad0732e" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.sql/2017-03-01-preview/servers/securityalertpolicies?tabs=json">Documentation</a><br/>|
|SQL Alert Policy Without Emails<br/><sup><sub>89b79fe5-49bd-4d39-84ce-55f5fc6f7764</sub></sup>|<span style="color:#5bc0de">Info</span>|Best Practices|<a href="../azureresourcemanager-queries/azure/89b79fe5-49bd-4d39-84ce-55f5fc6f7764" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.sql/servers/databases/securityalertpolicies?tabs=json">Documentation</a><br/>|
|Email Notifications Disabled<br/><sup><sub>79c2c2c0-eb00-47c0-ac16-f8b0e2c81c92</sub></sup>|<span style="color:#5bc0de">Info</span>|Networking and Firewall|<a href="../azureresourcemanager-queries/azure/79c2c2c0-eb00-47c0-ac16-f8b0e2c81c92" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.security/securitycontacts">Documentation</a><br/>|
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ hide:
- **Query name:** Standard Price Is Not Selected
- **Platform:** AzureResourceManager
- **Severity:** <span style="color:#edd57e">Low</span>
- **Category:** Networking and Firewall
- **Category:** Resource Management
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/azureResourceManager/standard_price_not_selected)

### Description
Expand Down
Loading

0 comments on commit f4d132d

Please sign in to comment.