diff --git a/docs/queries/all-queries.md b/docs/queries/all-queries.md
index a64936b5cb4..848034228d9 100644
--- a/docs/queries/all-queries.md
+++ b/docs/queries/all-queries.md
@@ -65,6 +65,7 @@ This page contains all queries.
|Auto Scaling Group With No Associated ELB
050f085f-a8db-4072-9010-2cca235cc02f|Ansible|Medium|Availability|Query details
Documentation
|
|CMK Is Unusable
133fee21-37ef-45df-a563-4d07edc169f4|Ansible|Medium|Availability|Query details
Documentation
|
|RDS With Backup Disabled
e69890e6-fce5-461d-98ad-cb98318dfc96|Ansible|Medium|Backup|Query details
Documentation
|
+|S3 Bucket Without Versioning
9232306a-f839-40aa-b3ef-b352001da9a5|Ansible|Medium|Backup|Query details
Documentation
|
|Stack Retention Disabled
17d5ba1d-7667-4729-b1a6-b11fde3db7f7|Ansible|Medium|Backup|Query details
Documentation
|
|AMI Not Encrypted
97707503-a22c-4cd7-b7c0-f088fa7cf830|Ansible|Medium|Encryption|Query details
Documentation
|
|CA Certificate Identifier Is Outdated
5eccd62d-8b4d-46d3-83ea-1879f3cbd3ce|Ansible|Medium|Encryption|Query details
Documentation
|
@@ -94,7 +95,6 @@ This page contains all queries.
|CloudFront Logging Disabled
d31cb911-bf5b-4eb6-9fc3-16780c77c7bd|Ansible|Medium|Observability|Query details
Documentation
|
|CloudTrail Logging Disabled
d4a73c49-cbaa-4c6f-80ee-d6ef5a3a26f5|Ansible|Medium|Observability|Query details
Documentation
|
|S3 Bucket Logging Disabled
c3b9f7b0-f5a0-49ec-9cbc-f1e346b7274d|Ansible|Medium|Observability|Query details
Documentation
|
-|S3 Bucket Without Versioning
9232306a-f839-40aa-b3ef-b352001da9a5|Ansible|Medium|Observability|Query details
Documentation
|
|No Stack Policy
ffe0fd52-7a8b-4a5c-8fc7-49844418e6c9|Ansible|Medium|Resource Management|Query details
Documentation
|
|Authentication Without MFA
eee107f9-b3d8-45d3-b9c6-43b5a7263ce1|Ansible|Low|Access Control|Query details
Documentation
|
|ECS Service Without Running Tasks
f5c45127-1d28-4b49-a692-0b97da1c3a84|Ansible|Low|Availability|Query details
Documentation
|
@@ -259,13 +259,13 @@ This page contains all queries.
|Phone Number Not Set For Security Contacts
3e9fcc67-1f64-405f-b2f9-0a6be17598f0|AzureResourceManager|Low|Best Practices|Query details
Documentation
|
|AKS Dashboard Is Enabled
c62d3b92-9a11-4ffd-b7b7-6faaae83faed|AzureResourceManager|Low|Insecure Configurations|Query details
Documentation
|
|AKS With Authorized IP Ranges Disabled
2583fab1-953b-4fae-bd02-4a136a6c21f9|AzureResourceManager|Low|Networking and Firewall|Query details
Documentation
|
-|Standard Price Is Not Selected
2081c7d6-2851-4cce-bda5-cb49d462da42|AzureResourceManager|Low|Networking and Firewall|Query details
Documentation
|
|Storage Account Allows Default Network Access
9073f073-5d60-4b46-b569-0d6baa80ed95|AzureResourceManager|Low|Networking and Firewall|Query details
Documentation
|
|Website with 'Http20Enabled' Disabled
70111098-7f85-48f0-b1b4-e4261cf5f61b|AzureResourceManager|Low|Networking and Firewall|Query details
Documentation
|
|Log Profile Incorrect Category
4d522e7b-f938-4d51-a3b1-974ada528bd3|AzureResourceManager|Low|Observability|Query details
Documentation
|
|SQL Server Database With Unrecommended Retention Days
c09cdac2-7670-458a-bf6c-efad6880973a|AzureResourceManager|Low|Observability|Query details
Documentation
|
|Unrecommended Log Profile Retention Policy
25684eac-daaa-4c2c-94b4-8d2dbb627909|AzureResourceManager|Low|Observability|Query details
Documentation
|
|Unrecommended Network Watcher Flow Log Retention Policy
564b70f8-41cd-4690-aff8-bb53add86bc9|AzureResourceManager|Low|Observability|Query details
Documentation
|
+|Standard Price Is Not Selected
2081c7d6-2851-4cce-bda5-cb49d462da42|AzureResourceManager|Low|Resource Management|Query details
Documentation
|
|Account Admins Not Notified By Email
a8852cc0-fd4b-4fc7-9372-1e43fad0732e|AzureResourceManager|Info|Best Practices|Query details
Documentation
|
|SQL Alert Policy Without Emails
89b79fe5-49bd-4d39-84ce-55f5fc6f7764|AzureResourceManager|Info|Best Practices|Query details
Documentation
|
|Email Notifications Disabled
79c2c2c0-eb00-47c0-ac16-f8b0e2c81c92|AzureResourceManager|Info|Networking and Firewall|Query details
Documentation
|
@@ -321,7 +321,6 @@ This page contains all queries.
|User Data Contains Encoded Private Key
568cc372-ca64-420d-9015-ee347d00d288|CloudFormation|High|Encryption|Query details
Documentation
|
|Workspace Without Encryption
89827c57-5a8a-49eb-9731-976a606d70db|CloudFormation|High|Encryption|Query details
Documentation
|
|Batch Job Definition With Privileged Container Properties
76ddf32c-85b1-4808-8935-7eef8030ab36|CloudFormation|High|Insecure Configurations|Query details
Documentation
|
-|IAM User LoginProfile Password Is In Plaintext
06adef8c-c284-4de7-aad2-af43b07a8ca1|CloudFormation|High|Insecure Configurations|Query details
Documentation
|
|KMS Key With Vulnerable Policy
da905474-7454-43c0-b8d2-5756ab951aba|CloudFormation|High|Insecure Configurations|Query details
Documentation
|
|Lambda Functions Without Unique IAM Roles
ae03f542-1423-402f-9cef-c834e7ee9583|CloudFormation|High|Insecure Configurations|Query details
Documentation
|
|MQ Broker Is Publicly Accessible
68b6a789-82f8-4cfd-85de-e95332fe6a61|CloudFormation|High|Insecure Configurations|Query details
Documentation
|
@@ -350,6 +349,7 @@ This page contains all queries.
|DMS Endpoint Password Exposed
5f700072-b7ce-4e84-b3f3-497bf1c24a4d|CloudFormation|High|Secret Management|Query details
Documentation
|
|DocDB Cluster Master Password In Plaintext
39423ce4-9011-46cd-b6b1-009edcd9385d|CloudFormation|High|Secret Management|Query details
Documentation
|
|Hardcoded AWS Access Key In Lambda
2564172f-c92b-4261-9acd-464aed511696|CloudFormation|High|Secret Management|Query details
Documentation
|
+|IAM User LoginProfile Password Is In Plaintext
06adef8c-c284-4de7-aad2-af43b07a8ca1|CloudFormation|High|Secret Management|Query details
Documentation
|
|RefreshToken Is Exposed
5b48c507-0d1f-41b0-a630-76817c6b4189|CloudFormation|High|Secret Management|Query details
Documentation
|
|API Gateway Method Does Not Contains An API Key
3641d5b4-d339-4bc2-bfb9-208fe8d3477f|CloudFormation|Medium|Access Control|Query details
Documentation
|
|API Gateway Without Configured Authorizer
7fd0d461-5b8c-4815-898c-f2b4b117eb28|CloudFormation|Medium|Access Control|Query details
Documentation
|
@@ -358,6 +358,7 @@ This page contains all queries.
|EC2 Network ACL Ineffective Denied Traffic
2623d682-dccb-44cd-99d0-54d9fd62f8f2|CloudFormation|Medium|Access Control|Query details
Documentation
|
|Elasticsearch Without IAM Authentication
5c666ed9-b586-49ab-9873-c495a833b705|CloudFormation|Medium|Access Control|Query details
Documentation
|
|Empty Roles For ECS Cluster Task Definitions
7f384a5f-b5a2-4d84-8ca3-ee0a5247becb|CloudFormation|Medium|Access Control|Query details
Documentation
|
+|IAM Group Inline Policies
a58d1a2d-4078-4b80-855b-84cc3f7f4540|CloudFormation|Medium|Access Control|Query details
Documentation
|
|IAM Group Without Users
8f957abd-9703-413d-87d3-c578950a753c|CloudFormation|Medium|Access Control|Query details
Documentation
|
|IAM Policies Attached To User
edc95c10-7366-4f30-9b4b-f995c84eceb5|CloudFormation|Medium|Access Control|Query details
Documentation
|
|IAM Policies With Full Privileges
953b3cdb-ce13-428a-aa12-318726506661|CloudFormation|Medium|Access Control|Query details
Documentation
|
@@ -375,8 +376,9 @@ This page contains all queries.
|Auto Scaling Group With No Associated ELB
ad21e616-5026-4b9d-990d-5b007bfe679c|CloudFormation|Medium|Availability|Query details
Documentation
|
|CMK Is Unusable
2844c749-bd78-4cd1-90e8-b179df827602|CloudFormation|Medium|Availability|Query details
Documentation
|
|ElastiCache Nodes Not Created Across Multi AZ
cfdef2e5-1fe4-4ef4-bea8-c56e08963150|CloudFormation|Medium|Availability|Query details
Documentation
|
-|RDS Multi-AZ Deployment Disabled
2b1d4935-9acf-48a7-8466-10d18bf51a69|CloudFormation|Medium|Backup|Query details
Documentation
|
+|RDS Multi-AZ Deployment Disabled
2b1d4935-9acf-48a7-8466-10d18bf51a69|CloudFormation|Medium|Availability|Query details
Documentation
|
|RDS With Backup Disabled
8c415f6f-7b90-4a27-a44a-51047e1506f9|CloudFormation|Medium|Backup|Query details
Documentation
|
+|S3 Bucket Without Versioning
a227ec01-f97a-4084-91a4-47b350c1db54|CloudFormation|Medium|Backup|Query details
Documentation
|
|Stack Retention Disabled
fe974ae9-858e-4991-bbd5-e040a834679f|CloudFormation|Medium|Backup|Query details
Documentation
|
|DynamoDB Table Point In Time Recovery Disabled
0f04217d-488f-4e7a-bec8-f16159686cd6|CloudFormation|Medium|Best Practices|Query details
Documentation
|
|ECS No Load Balancer Attached
fb2b0ecf-1492-491a-a70d-ba1df579175d|CloudFormation|Medium|Best Practices|Query details
Documentation
|
@@ -394,7 +396,6 @@ This page contains all queries.
|ELB Without Secure Protocol
80908a75-586b-4c61-ab04-490f4f4525b8|CloudFormation|Medium|Encryption|Query details
Documentation
|
|EMR Security Configuration Encryption Disabled
5b033ec8-f079-4323-b5c8-99d4620433a9|CloudFormation|Medium|Encryption|Query details
Documentation
|
|IAM Database Auth Not Enabled
9fcd0a0a-9b6f-4670-a215-d94e6bf3f184|CloudFormation|Medium|Encryption|Query details
Documentation
|
-|IAM Group Inline Policies
a58d1a2d-4078-4b80-855b-84cc3f7f4540|CloudFormation|Medium|Encryption|Query details
Documentation
|
|KMS Key Rotation Disabled
235ca980-eb71-48f4-9030-df0c371029eb|CloudFormation|Medium|Encryption|Query details
Documentation
|
|Redshift Cluster Without KMS CMK
de76a0d6-66d5-45c9-9022-f05545b85c78|CloudFormation|Medium|Encryption|Query details
Documentation
|
|S3 Bucket Without SSL In Write Actions
38c64e76-c71e-4d92-a337-60174d1de1c9|CloudFormation|Medium|Encryption|Query details
Documentation
|
@@ -458,7 +459,6 @@ This page contains all queries.
|Redshift Cluster Logging Disabled
3de2d4ff-fe53-4fc9-95d3-2f8a69bf90d6|CloudFormation|Medium|Observability|Query details
Documentation
|
|S3 Bucket CloudTrail Logging Disabled
c3ce69fd-e3df-49c6-be78-1db3f802261c|CloudFormation|Medium|Observability|Query details
Documentation
|
|S3 Bucket Logging Disabled
4552b71f-0a2a-4bc4-92dd-ed7ec1b4674c|CloudFormation|Medium|Observability|Query details
Documentation
|
-|S3 Bucket Without Versioning
a227ec01-f97a-4084-91a4-47b350c1db54|CloudFormation|Medium|Observability|Query details
Documentation
|
|VPC FlowLogs Disabled
f6d299d2-21eb-41cc-b1e1-fe12d857500b|CloudFormation|Medium|Observability|Query details
Documentation
|
|High Access Key Rotation Period
800fa019-49dd-421b-9042-7331fdd83fa2|CloudFormation|Medium|Secret Management|Query details
Documentation
|
|IAM User With No Group
06933df4-0ea7-461c-b9b5-104d27390e0e|CloudFormation|Low|Access Control|Query details
Documentation
|
@@ -482,7 +482,6 @@ This page contains all queries.
|API Gateway With Invalid Compression
d6653eee-2d4d-4e6a-976f-6794a497999a|CloudFormation|Low|Encryption|Query details
Documentation
|
|CloudTrail Log Files Not Encrypted With KMS
050a9ba8-d1cb-4c61-a5e8-8805a70d3b85|CloudFormation|Low|Encryption|Query details
Documentation
|
|EFS Without KMS
6d087495-2a42-4735-abf7-02ef5660a7e6|CloudFormation|Low|Encryption|Query details
Documentation
|
-|Unscanned ECR Image
9025b2b3-e554-4842-ba87-db7aeec36d35|CloudFormation|Low|Encryption|Query details
Documentation
|
|API Gateway Cache Cluster Disabled
52790cad-d60d-41d5-8483-146f9f21208d|CloudFormation|Low|Insecure Configurations|Query details
Documentation
|
|Inline Policies Are Attached To ECS Service
9e8c89b3-7997-4d15-93e4-7911b9db99fd|CloudFormation|Low|Insecure Configurations|Query details
Documentation
|
|Instance With No VPC
8a6d36cd-0bc6-42b7-92c4-67acc8576861|CloudFormation|Low|Insecure Configurations|Query details
Documentation
|
@@ -512,6 +511,7 @@ This page contains all queries.
|ElasticSearch Without Slow Logs
086ea2eb-14a6-4fd4-914b-38e0bc8703e8|CloudFormation|Low|Observability|Query details
Documentation
|
|Lambda Functions Without X-Ray Tracing
9488c451-074e-4cd3-aee3-7db6104f542c|CloudFormation|Low|Observability|Query details
Documentation
|
|Stack Notifications Disabled
837e033c-4717-40bd-807e-6abaa30161b7|CloudFormation|Low|Observability|Query details
Documentation
|
+|Unscanned ECR Image
9025b2b3-e554-4842-ba87-db7aeec36d35|CloudFormation|Low|Observability|Query details
Documentation
|
|API Gateway Stage Without API Gateway UsagePlan Associated
7f8f1b60-43df-4c28-aa21-fb836dbd8071|CloudFormation|Low|Resource Management|Query details
Documentation
|
|ECS Task Definition Invalid CPU or Memory
f4c9b5f5-68b8-491f-9e48-4f96644a1d51|CloudFormation|Low|Resource Management|Query details
Documentation
|
|SDB Domain Declared As A Resource
6ea57c8b-f9c0-4ec7-bae3-bd75a9dee27d|CloudFormation|Low|Resource Management|Query details
Documentation
|
@@ -560,7 +560,7 @@ This page contains all queries.
|ECS Cluster with Container Insights Disabled
0c7a76d9-7dc5-499e-81ac-9245839177cb|Crossplane|Low|Observability|Query details
Documentation
|
|CloudWatch Without Retention Period Specified
934613fe-b12c-4e5a-95f5-c1dcdffac1ff|Crossplane|Info|Observability|Query details
Documentation
|
|AKS RBAC Disabled
b2418936-cd47-4ea2-8346-623c0bdb87bd|Crossplane|Medium|Access Control|Query details
Documentation
|
-|Redis Cache Allows Non SSL Connections
6c7cfec3-c686-4ed2-bf58-a1ec054b63fc|Crossplane|Medium|Encryption|Query details
Documentation
|
+|Redis Cache Allows Non SSL Connections
6c7cfec3-c686-4ed2-bf58-a1ec054b63fc|Crossplane|Medium|Insecure Configurations|Query details
Documentation
|
|Google Container Node Pool Auto Repair Disabled
b4f65d13-a609-4dc1-af7c-63d2e08bffe9|Crossplane|Medium|Insecure Configurations|Query details
Documentation
|
|Cloud Storage Bucket Logging Not Enabled
6c2d627c-de0f-45fb-b33d-dad9bffbb421|Crossplane|Medium|Observability|Query details
Documentation
|
|Docker Socket Mounted In Container
d6355c88-1e8d-49e9-b2f2-f8a1ca12c75b|DockerCompose|High|Build Process|Query details
Documentation
|
@@ -627,7 +627,7 @@ This page contains all queries.
|Run Using apt
b84a0b47-2e99-4c9f-8933-98bcabe2b94d|Dockerfile|Low|Supply-Chain|Query details
Documentation
|
|Yum Install Allows Manual Input
6e19193a-8753-436d-8a09-76dcff91bb03|Dockerfile|Low|Supply-Chain|Query details
Documentation
|
|Zypper Install Without Version
562952e4-0348-4dea-9826-44f3a2c6117b|Dockerfile|Low|Supply-Chain|Query details
Documentation
|
-|UNIX Ports Out Of Range
71bf8cf8-f0a1-42fa-b9d2-d10525e0a38e|Dockerfile|Info|Availability|Query details
Documentation
|
+|UNIX Ports Out Of Range
71bf8cf8-f0a1-42fa-b9d2-d10525e0a38e|Dockerfile|Info|Networking and Firewall|Query details
Documentation
|
|Apk Add Using Local Cache Path
ae9c56a6-3ed1-4ac0-9b54-31267f51151d|Dockerfile|Info|Supply-Chain|Query details
Documentation
|
|Apt Get Install Lists Were Not Deleted
df746b39-6564-4fed-bf85-e9c44382303c|Dockerfile|Info|Supply-Chain|Query details
Documentation
|
|APT-GET Not Avoiding Additional Packages
7384dfb2-fcd1-4fbf-91cd-6c44c318c33c|Dockerfile|Info|Supply-Chain|Query details
Documentation
|
@@ -1093,8 +1093,8 @@ This page contains all queries.
|ECS Cluster with Container Insights Disabled
abcefee4-a0c1-4245-9f82-a473f79a9e2f|Pulumi|Low|Observability|Query details
Documentation
|
|DynamoDB Table Point In Time Recovery Disabled
327b0729-4c5c-4c44-8b5c-e476cd9c7290|Pulumi|Info|Best Practices|Query details
Documentation
|
|EC2 Not EBS Optimized
d991e4ae-42ab-429b-ab43-d5e5fa9ca633|Pulumi|Info|Best Practices|Query details
Documentation
|
-|Redis Cache Allows Non SSL Connections
49e30ac8-f58e-4222-b488-3dcb90158ec1|Pulumi|Medium|Encryption|Query details
Documentation
|
|Storage Account Not Forcing HTTPS
cb8e4bf0-903d-45c6-a278-9a947d82a27b|Pulumi|Medium|Encryption|Query details
Documentation
|
+|Redis Cache Allows Non SSL Connections
49e30ac8-f58e-4222-b488-3dcb90158ec1|Pulumi|Medium|Insecure Configurations|Query details
Documentation
|
|Google Compute SSL Policy Weak Cipher In Use
965e8830-2bec-4b9b-a7f0-24dbc200a68f|Pulumi|Medium|Encryption|Query details
Documentation
|
|Cloud Storage Bucket Logging Not Enabled
48f7e44d-d1d1-44c2-b336-9f11b65c4fb0|Pulumi|Medium|Observability|Query details
Documentation
|
|PSP Set To Privileged
ee305555-6b1d-4055-94cf-e22131143c34|Pulumi|High|Insecure Configurations|Query details
Documentation
|
@@ -1342,10 +1342,11 @@ This page contains all queries.
|CMK Is Unusable
7350fa23-dcf7-4938-916d-6a60b0c73b50|Terraform|Medium|Availability|Query details
Documentation
|
|ElastiCache Nodes Not Created Across Multi AZ
6db03a91-f933-4f13-ab38-a8b87a7de54d|Terraform|Medium|Availability|Query details
Documentation
|
|ElastiCache Redis Cluster Without Backup
8fdb08a0-a868-4fdf-9c27-ccab0237f1ab|Terraform|Medium|Backup|Query details
Documentation
|
+|RDS Cluster With Backup Disabled
e542bd46-58c4-4e0f-a52a-1fb4f9548e02|Terraform|Medium|Backup|Query details
Documentation
|
|RDS With Backup Disabled
1dc73fb4-5b51-430c-8c5f-25dcf9090b02|Terraform|Medium|Backup|Query details
Documentation
|
+|S3 Bucket Without Versioning
568a4d22-3517-44a6-a7ad-6a7eed88722c|Terraform|Medium|Backup|Query details
Documentation
|
|Stack Retention Disabled
6e0e2f68-3fd9-4cd8-a5e4-e2213ef0df97|Terraform|Medium|Backup|Query details
Documentation
|
|ALB Not Dropping Invalid Headers
6e3fd2ed-5c83-4c68-9679-7700d224d379|Terraform|Medium|Best Practices|Query details
Documentation
|
-|RDS Cluster With Backup Disabled
e542bd46-58c4-4e0f-a52a-1fb4f9548e02|Terraform|Medium|Best Practices|Query details
Documentation
|
|AMI Not Encrypted
8bbb242f-6e38-4127-86d4-d8f0b2687ae2|Terraform|Medium|Encryption|Query details
Documentation
|
|CA Certificate Identifier Is Outdated
9f40c07e-699e-4410-8856-3ba0f2e3a2dd|Terraform|Medium|Encryption|Query details
Documentation
|
|Cloudfront Viewer Protocol Policy Allows HTTP
55af1353-2f62-4fa0-a8e1-a210ca2708f5|Terraform|Medium|Encryption|Query details
Documentation
|
@@ -1376,6 +1377,7 @@ This page contains all queries.
|S3 Bucket Without Ignore Public ACL
4fa66806-0dd9-4f8d-9480-3174d39c7c91|Terraform|Medium|Insecure Configurations|Query details
Documentation
|
|S3 Bucket Without Restriction Of Public Bucket
1ec253ab-c220-4d63-b2de-5b40e0af9293|Terraform|Medium|Insecure Configurations|Query details
Documentation
|
|Service Control Policies Disabled
5ba6229c-8057-433e-91d0-21cf13569ca9|Terraform|Medium|Insecure Configurations|Query details
Documentation
|
+|Default VPC Exists
96ed3526-0179-4c73-b1b2-372fde2e0d13|Terraform|Medium|Insecure Defaults|Query details
Documentation
|
|Vulnerable Default SSL Certificate
3a1e94df-6847-4c0e-a3b6-6c6af4e128ef|Terraform|Medium|Insecure Defaults|Query details
Documentation
|
|ALB Is Not Integrated With WAF
0afa6ab8-a047-48cf-be07-93a2f8c34cf7|Terraform|Medium|Networking and Firewall|Query details
Documentation
|
|ALB Listening on HTTP
de7f5e83-da88-4046-871f-ea18504b1d43|Terraform|Medium|Networking and Firewall|Query details
Documentation
|
@@ -1410,7 +1412,6 @@ This page contains all queries.
|CloudWatch S3 policy Change Alarm Missing
27c6a499-895a-4dc7-9617-5c485218db13|Terraform|Medium|Observability|Query details
Documentation
|
|Cloudwatch Security Group Changes Alarm Missing
4beaf898-9f8b-4237-89e2-5ffdc7ee6006|Terraform|Medium|Observability|Query details
Documentation
|
|CloudWatch VPC Changes Alarm Missing
9d0d4512-1959-43a2-a17f-72360ff06d1b|Terraform|Medium|Observability|Query details
Documentation
|
-|Default VPC Exists
96ed3526-0179-4c73-b1b2-372fde2e0d13|Terraform|Medium|Observability|Query details
Documentation
|
|DocDB Logging Is Disabled
56f6a008-1b14-4af4-b9b2-ab7cf7e27641|Terraform|Medium|Observability|Query details
Documentation
|
|EC2 Instance Monitoring Disabled
23b70e32-032e-4fa6-ba5c-82f56b9980e6|Terraform|Medium|Observability|Query details
Documentation
|
|EKS cluster logging is not enabled
37304d3f-f852-40b8-ae3f-725e87a7cedf|Terraform|Medium|Observability|Query details
Documentation
|
@@ -1426,7 +1427,6 @@ This page contains all queries.
|Redshift Cluster Logging Disabled
15ffbacc-fa42-4f6f-a57d-2feac7365caa|Terraform|Medium|Observability|Query details
Documentation
|
|S3 Bucket Logging Disabled
f861041c-8c9f-4156-acfc-5e6e524f5884|Terraform|Medium|Observability|Query details
Documentation
|
|S3 Bucket Object Level CloudTrail Logging Disabled
a8fc2180-b3ac-4c93-bd0d-a55b974e4b07|Terraform|Medium|Observability|Query details
Documentation
|
-|S3 Bucket Without Versioning
568a4d22-3517-44a6-a7ad-6a7eed88722c|Terraform|Medium|Observability|Query details
Documentation
|
|Stack Notifications Disabled
b72d0026-f649-4c91-a9ea-15d8f681ac09|Terraform|Medium|Observability|Query details
Documentation
|
|VPC FlowLogs Disabled
f83121ea-03da-434f-9277-9cd247ab3047|Terraform|Medium|Observability|Query details
Documentation
|
|No Stack Policy
2f01fb2d-828a-499d-b98e-b83747305052|Terraform|Medium|Resource Management|Query details
Documentation
|
@@ -1453,11 +1453,10 @@ This page contains all queries.
|DOCDB Cluster Encrypted With AWS Managed Key
2134641d-30a4-4b16-8ffc-2cd4c4ffd15d|Terraform|Low|Encryption|Query details
Documentation
|
|ECR Repository Not Encrypted With CMK
0e32d561-4b5a-4664-a6e3-a3fa85649157|Terraform|Low|Encryption|Query details
Documentation
|
|EFS Without KMS
25d251f3-f348-4f95-845c-1090e41a615c|Terraform|Low|Encryption|Query details
Documentation
|
-|Redis Disabled
4bd15dd9-8d5e-4008-8532-27eb0c3706d3|Terraform|Low|Encryption|Query details
Documentation
|
-|Unscanned ECR Image
9630336b-3fed-4096-8173-b9afdfe346a7|Terraform|Low|Encryption|Query details
Documentation
|
|AWS Password Policy With Unchangeable Passwords
9ef7d25d-9764-4224-9968-fa321c56ef76|Terraform|Low|Insecure Configurations|Query details
Documentation
|
|IAM User Policy Without MFA
b5681959-6c09-4f55-b42b-c40fa12d03ec|Terraform|Low|Insecure Configurations|Query details
Documentation
|
|Instance With No VPC
a31a5a29-718a-4ff4-8001-a69e5e4d029e|Terraform|Low|Insecure Configurations|Query details
Documentation
|
+|Redis Disabled
4bd15dd9-8d5e-4008-8532-27eb0c3706d3|Terraform|Low|Insecure Configurations|Query details
Documentation
|
|Redshift Cluster Without VPC
0a494a6a-ebe2-48a0-9d77-cf9d5125e1b3|Terraform|Low|Insecure Configurations|Query details
Documentation
|
|S3 Bucket Without Enabled MFA Delete
c5b31ab9-0f26-4a49-b8aa-4cc064392f4d|Terraform|Low|Insecure Configurations|Query details
Documentation
|
|Dynamodb VPC Endpoint Without Route Table Association
0bc534c5-13d1-4353-a7fe-b8665d5c1d7d|Terraform|Low|Networking and Firewall|Query details
Documentation
|
@@ -1486,6 +1485,7 @@ This page contains all queries.
|ElasticSearch Without Slow Logs
e979fcbc-df6c-422d-9458-c33d65e71c45|Terraform|Low|Observability|Query details
Documentation
|
|KMS Key With No Deletion Window
0b530315-0ea4-497f-b34c-4ff86268f59d|Terraform|Low|Observability|Query details
Documentation
|
|Lambda Functions Without X-Ray Tracing
8152e0cf-d2f0-47ad-96d5-d003a76eabd1|Terraform|Low|Observability|Query details
Documentation
|
+|Unscanned ECR Image
9630336b-3fed-4096-8173-b9afdfe346a7|Terraform|Low|Observability|Query details
Documentation
|
|API Gateway Stage Without API Gateway UsagePlan Associated
c999cf62-0920-40f8-8dda-0caccd66ed7e|Terraform|Low|Resource Management|Query details
Documentation
|
|Security Group Not Used
4849211b-ac39-479e-ae78-5694d506cb24|Terraform|Info|Access Control|Query details
Documentation
|
|DynamoDB Table Point In Time Recovery Disabled
741f1291-47ac-4a85-a07b-3d32a9d6bd3e|Terraform|Info|Best Practices|Query details
Documentation
|
@@ -1655,8 +1655,8 @@ This page contains all queries.
|Service Account with Improper Privileges
cefdad16-0dd5-4ac5-8ed2-a37502c78672|Terraform|Medium|Resource Management|Query details
Documentation
|
|High Google KMS Crypto Key Rotation Period
d8c57c4e-bf6f-4e32-a2bf-8643532de77b|Terraform|Medium|Secret Management|Query details
Documentation
|
|Project-wide SSH Keys Are Enabled In VM Instances
3e4d5ce6-3280-4027-8010-c26eeea1ec01|Terraform|Medium|Secret Management|Query details
Documentation
|
+|User with IAM Role
704fcc44-a58f-4af5-82e2-93f2a58ef918|Terraform|Low|Access Control|Query details
Documentation
|
|Outdated GKE Version
128df7ec-f185-48bc-8913-ce756a3ccb85|Terraform|Low|Best Practices|Query details
Documentation
|
-|User with IAM Role
704fcc44-a58f-4af5-82e2-93f2a58ef918|Terraform|Low|Best Practices|Query details
Documentation
|
|Cluster Labels Disabled
65c1bc7a-4835-4ac4-a2b6-13d310b0648d|Terraform|Low|Insecure Configurations|Query details
Documentation
|
|COS Node Image Not Used
8a893e46-e267-485a-8690-51f39951de58|Terraform|Low|Insecure Configurations|Query details
Documentation
|
|Legacy Client Certificate Auth Enabled
73fb21a1-b19a-45b1-b648-b47b1678681e|Terraform|Low|Insecure Configurations|Query details
Documentation
|
diff --git a/docs/queries/ansible-queries.md b/docs/queries/ansible-queries.md
index 858a2f301b4..bb1a60c7092 100644
--- a/docs/queries/ansible-queries.md
+++ b/docs/queries/ansible-queries.md
@@ -70,6 +70,7 @@ Below are listed queries related to Ansible AWS:
|Auto Scaling Group With No Associated ELB
050f085f-a8db-4072-9010-2cca235cc02f|Medium|Availability|Query details
Documentation
|
|CMK Is Unusable
133fee21-37ef-45df-a563-4d07edc169f4|Medium|Availability|Query details
Documentation
|
|RDS With Backup Disabled
e69890e6-fce5-461d-98ad-cb98318dfc96|Medium|Backup|Query details
Documentation
|
+|S3 Bucket Without Versioning
9232306a-f839-40aa-b3ef-b352001da9a5|Medium|Backup|Query details
Documentation
|
|Stack Retention Disabled
17d5ba1d-7667-4729-b1a6-b11fde3db7f7|Medium|Backup|Query details
Documentation
|
|AMI Not Encrypted
97707503-a22c-4cd7-b7c0-f088fa7cf830|Medium|Encryption|Query details
Documentation
|
|CA Certificate Identifier Is Outdated
5eccd62d-8b4d-46d3-83ea-1879f3cbd3ce|Medium|Encryption|Query details
Documentation
|
@@ -99,7 +100,6 @@ Below are listed queries related to Ansible AWS:
|CloudFront Logging Disabled
d31cb911-bf5b-4eb6-9fc3-16780c77c7bd|Medium|Observability|Query details
Documentation
|
|CloudTrail Logging Disabled
d4a73c49-cbaa-4c6f-80ee-d6ef5a3a26f5|Medium|Observability|Query details
Documentation
|
|S3 Bucket Logging Disabled
c3b9f7b0-f5a0-49ec-9cbc-f1e346b7274d|Medium|Observability|Query details
Documentation
|
-|S3 Bucket Without Versioning
9232306a-f839-40aa-b3ef-b352001da9a5|Medium|Observability|Query details
Documentation
|
|No Stack Policy
ffe0fd52-7a8b-4a5c-8fc7-49844418e6c9|Medium|Resource Management|Query details
Documentation
|
|Authentication Without MFA
eee107f9-b3d8-45d3-b9c6-43b5a7263ce1|Low|Access Control|Query details
Documentation
|
|ECS Service Without Running Tasks
f5c45127-1d28-4b49-a692-0b97da1c3a84|Low|Availability|Query details
Documentation
|
diff --git a/docs/queries/ansible-queries/aws/9232306a-f839-40aa-b3ef-b352001da9a5.md b/docs/queries/ansible-queries/aws/9232306a-f839-40aa-b3ef-b352001da9a5.md
index 9600948d7fe..32476ead786 100644
--- a/docs/queries/ansible-queries/aws/9232306a-f839-40aa-b3ef-b352001da9a5.md
+++ b/docs/queries/ansible-queries/aws/9232306a-f839-40aa-b3ef-b352001da9a5.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** S3 Bucket Without Versioning
- **Platform:** Ansible
- **Severity:** Medium
-- **Category:** Observability
+- **Category:** Backup
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/ansible/aws/s3_bucket_without_versioning)
### Description
diff --git a/docs/queries/azureresourcemanager-queries.md b/docs/queries/azureresourcemanager-queries.md
index 7e45b7efaae..57a8645bdbf 100644
--- a/docs/queries/azureresourcemanager-queries.md
+++ b/docs/queries/azureresourcemanager-queries.md
@@ -35,13 +35,13 @@ This page contains all queries from AzureResourceManager.
|Phone Number Not Set For Security Contacts
3e9fcc67-1f64-405f-b2f9-0a6be17598f0|Low|Best Practices|Query details
Documentation
|
|AKS Dashboard Is Enabled
c62d3b92-9a11-4ffd-b7b7-6faaae83faed|Low|Insecure Configurations|Query details
Documentation
|
|AKS With Authorized IP Ranges Disabled
2583fab1-953b-4fae-bd02-4a136a6c21f9|Low|Networking and Firewall|Query details
Documentation
|
-|Standard Price Is Not Selected
2081c7d6-2851-4cce-bda5-cb49d462da42|Low|Networking and Firewall|Query details
Documentation
|
|Storage Account Allows Default Network Access
9073f073-5d60-4b46-b569-0d6baa80ed95|Low|Networking and Firewall|Query details
Documentation
|
|Website with 'Http20Enabled' Disabled
70111098-7f85-48f0-b1b4-e4261cf5f61b|Low|Networking and Firewall|Query details
Documentation
|
|Log Profile Incorrect Category
4d522e7b-f938-4d51-a3b1-974ada528bd3|Low|Observability|Query details
Documentation
|
|SQL Server Database With Unrecommended Retention Days
c09cdac2-7670-458a-bf6c-efad6880973a|Low|Observability|Query details
Documentation
|
|Unrecommended Log Profile Retention Policy
25684eac-daaa-4c2c-94b4-8d2dbb627909|Low|Observability|Query details
Documentation
|
|Unrecommended Network Watcher Flow Log Retention Policy
564b70f8-41cd-4690-aff8-bb53add86bc9|Low|Observability|Query details
Documentation
|
+|Standard Price Is Not Selected
2081c7d6-2851-4cce-bda5-cb49d462da42|Low|Resource Management|Query details
Documentation
|
|Account Admins Not Notified By Email
a8852cc0-fd4b-4fc7-9372-1e43fad0732e|Info|Best Practices|Query details
Documentation
|
|SQL Alert Policy Without Emails
89b79fe5-49bd-4d39-84ce-55f5fc6f7764|Info|Best Practices|Query details
Documentation
|
|Email Notifications Disabled
79c2c2c0-eb00-47c0-ac16-f8b0e2c81c92|Info|Networking and Firewall|Query details
Documentation
|
diff --git a/docs/queries/azureresourcemanager-queries/azure/2081c7d6-2851-4cce-bda5-cb49d462da42.md b/docs/queries/azureresourcemanager-queries/azure/2081c7d6-2851-4cce-bda5-cb49d462da42.md
index e19d7153c3f..ce960e0475d 100644
--- a/docs/queries/azureresourcemanager-queries/azure/2081c7d6-2851-4cce-bda5-cb49d462da42.md
+++ b/docs/queries/azureresourcemanager-queries/azure/2081c7d6-2851-4cce-bda5-cb49d462da42.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** Standard Price Is Not Selected
- **Platform:** AzureResourceManager
- **Severity:** Low
-- **Category:** Networking and Firewall
+- **Category:** Resource Management
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/azureResourceManager/standard_price_not_selected)
### Description
diff --git a/docs/queries/cloudformation-queries.md b/docs/queries/cloudformation-queries.md
index 4bd438b101d..f37be3d2fc1 100644
--- a/docs/queries/cloudformation-queries.md
+++ b/docs/queries/cloudformation-queries.md
@@ -55,7 +55,6 @@ Below are listed queries related to CloudFormation AWS:
|User Data Contains Encoded Private Key
568cc372-ca64-420d-9015-ee347d00d288|High|Encryption|Query details
Documentation
|
|Workspace Without Encryption
89827c57-5a8a-49eb-9731-976a606d70db|High|Encryption|Query details
Documentation
|
|Batch Job Definition With Privileged Container Properties
76ddf32c-85b1-4808-8935-7eef8030ab36|High|Insecure Configurations|Query details
Documentation
|
-|IAM User LoginProfile Password Is In Plaintext
06adef8c-c284-4de7-aad2-af43b07a8ca1|High|Insecure Configurations|Query details
Documentation
|
|KMS Key With Vulnerable Policy
da905474-7454-43c0-b8d2-5756ab951aba|High|Insecure Configurations|Query details
Documentation
|
|Lambda Functions Without Unique IAM Roles
ae03f542-1423-402f-9cef-c834e7ee9583|High|Insecure Configurations|Query details
Documentation
|
|MQ Broker Is Publicly Accessible
68b6a789-82f8-4cfd-85de-e95332fe6a61|High|Insecure Configurations|Query details
Documentation
|
@@ -84,6 +83,7 @@ Below are listed queries related to CloudFormation AWS:
|DMS Endpoint Password Exposed
5f700072-b7ce-4e84-b3f3-497bf1c24a4d|High|Secret Management|Query details
Documentation
|
|DocDB Cluster Master Password In Plaintext
39423ce4-9011-46cd-b6b1-009edcd9385d|High|Secret Management|Query details
Documentation
|
|Hardcoded AWS Access Key In Lambda
2564172f-c92b-4261-9acd-464aed511696|High|Secret Management|Query details
Documentation
|
+|IAM User LoginProfile Password Is In Plaintext
06adef8c-c284-4de7-aad2-af43b07a8ca1|High|Secret Management|Query details
Documentation
|
|RefreshToken Is Exposed
5b48c507-0d1f-41b0-a630-76817c6b4189|High|Secret Management|Query details
Documentation
|
|API Gateway Method Does Not Contains An API Key
3641d5b4-d339-4bc2-bfb9-208fe8d3477f|Medium|Access Control|Query details
Documentation
|
|API Gateway Without Configured Authorizer
7fd0d461-5b8c-4815-898c-f2b4b117eb28|Medium|Access Control|Query details
Documentation
|
@@ -92,6 +92,7 @@ Below are listed queries related to CloudFormation AWS:
|EC2 Network ACL Ineffective Denied Traffic
2623d682-dccb-44cd-99d0-54d9fd62f8f2|Medium|Access Control|Query details
Documentation
|
|Elasticsearch Without IAM Authentication
5c666ed9-b586-49ab-9873-c495a833b705|Medium|Access Control|Query details
Documentation
|
|Empty Roles For ECS Cluster Task Definitions
7f384a5f-b5a2-4d84-8ca3-ee0a5247becb|Medium|Access Control|Query details
Documentation
|
+|IAM Group Inline Policies
a58d1a2d-4078-4b80-855b-84cc3f7f4540|Medium|Access Control|Query details
Documentation
|
|IAM Group Without Users
8f957abd-9703-413d-87d3-c578950a753c|Medium|Access Control|Query details
Documentation
|
|IAM Policies Attached To User
edc95c10-7366-4f30-9b4b-f995c84eceb5|Medium|Access Control|Query details
Documentation
|
|IAM Policies With Full Privileges
953b3cdb-ce13-428a-aa12-318726506661|Medium|Access Control|Query details
Documentation
|
@@ -109,8 +110,9 @@ Below are listed queries related to CloudFormation AWS:
|Auto Scaling Group With No Associated ELB
ad21e616-5026-4b9d-990d-5b007bfe679c|Medium|Availability|Query details
Documentation
|
|CMK Is Unusable
2844c749-bd78-4cd1-90e8-b179df827602|Medium|Availability|Query details
Documentation
|
|ElastiCache Nodes Not Created Across Multi AZ
cfdef2e5-1fe4-4ef4-bea8-c56e08963150|Medium|Availability|Query details
Documentation
|
-|RDS Multi-AZ Deployment Disabled
2b1d4935-9acf-48a7-8466-10d18bf51a69|Medium|Backup|Query details
Documentation
|
+|RDS Multi-AZ Deployment Disabled
2b1d4935-9acf-48a7-8466-10d18bf51a69|Medium|Availability|Query details
Documentation
|
|RDS With Backup Disabled
8c415f6f-7b90-4a27-a44a-51047e1506f9|Medium|Backup|Query details
Documentation
|
+|S3 Bucket Without Versioning
a227ec01-f97a-4084-91a4-47b350c1db54|Medium|Backup|Query details
Documentation
|
|Stack Retention Disabled
fe974ae9-858e-4991-bbd5-e040a834679f|Medium|Backup|Query details
Documentation
|
|DynamoDB Table Point In Time Recovery Disabled
0f04217d-488f-4e7a-bec8-f16159686cd6|Medium|Best Practices|Query details
Documentation
|
|ECS No Load Balancer Attached
fb2b0ecf-1492-491a-a70d-ba1df579175d|Medium|Best Practices|Query details
Documentation
|
@@ -128,7 +130,6 @@ Below are listed queries related to CloudFormation AWS:
|ELB Without Secure Protocol
80908a75-586b-4c61-ab04-490f4f4525b8|Medium|Encryption|Query details
Documentation
|
|EMR Security Configuration Encryption Disabled
5b033ec8-f079-4323-b5c8-99d4620433a9|Medium|Encryption|Query details
Documentation
|
|IAM Database Auth Not Enabled
9fcd0a0a-9b6f-4670-a215-d94e6bf3f184|Medium|Encryption|Query details
Documentation
|
-|IAM Group Inline Policies
a58d1a2d-4078-4b80-855b-84cc3f7f4540|Medium|Encryption|Query details
Documentation
|
|KMS Key Rotation Disabled
235ca980-eb71-48f4-9030-df0c371029eb|Medium|Encryption|Query details
Documentation
|
|Redshift Cluster Without KMS CMK
de76a0d6-66d5-45c9-9022-f05545b85c78|Medium|Encryption|Query details
Documentation
|
|S3 Bucket Without SSL In Write Actions
38c64e76-c71e-4d92-a337-60174d1de1c9|Medium|Encryption|Query details
Documentation
|
@@ -192,7 +193,6 @@ Below are listed queries related to CloudFormation AWS:
|Redshift Cluster Logging Disabled
3de2d4ff-fe53-4fc9-95d3-2f8a69bf90d6|Medium|Observability|Query details
Documentation
|
|S3 Bucket CloudTrail Logging Disabled
c3ce69fd-e3df-49c6-be78-1db3f802261c|Medium|Observability|Query details
Documentation
|
|S3 Bucket Logging Disabled
4552b71f-0a2a-4bc4-92dd-ed7ec1b4674c|Medium|Observability|Query details
Documentation
|
-|S3 Bucket Without Versioning
a227ec01-f97a-4084-91a4-47b350c1db54|Medium|Observability|Query details
Documentation
|
|VPC FlowLogs Disabled
f6d299d2-21eb-41cc-b1e1-fe12d857500b|Medium|Observability|Query details
Documentation
|
|High Access Key Rotation Period
800fa019-49dd-421b-9042-7331fdd83fa2|Medium|Secret Management|Query details
Documentation
|
|IAM User With No Group
06933df4-0ea7-461c-b9b5-104d27390e0e|Low|Access Control|Query details
Documentation
|
@@ -216,7 +216,6 @@ Below are listed queries related to CloudFormation AWS:
|API Gateway With Invalid Compression
d6653eee-2d4d-4e6a-976f-6794a497999a|Low|Encryption|Query details
Documentation
|
|CloudTrail Log Files Not Encrypted With KMS
050a9ba8-d1cb-4c61-a5e8-8805a70d3b85|Low|Encryption|Query details
Documentation
|
|EFS Without KMS
6d087495-2a42-4735-abf7-02ef5660a7e6|Low|Encryption|Query details
Documentation
|
-|Unscanned ECR Image
9025b2b3-e554-4842-ba87-db7aeec36d35|Low|Encryption|Query details
Documentation
|
|API Gateway Cache Cluster Disabled
52790cad-d60d-41d5-8483-146f9f21208d|Low|Insecure Configurations|Query details
Documentation
|
|Inline Policies Are Attached To ECS Service
9e8c89b3-7997-4d15-93e4-7911b9db99fd|Low|Insecure Configurations|Query details
Documentation
|
|Instance With No VPC
8a6d36cd-0bc6-42b7-92c4-67acc8576861|Low|Insecure Configurations|Query details
Documentation
|
@@ -246,6 +245,7 @@ Below are listed queries related to CloudFormation AWS:
|ElasticSearch Without Slow Logs
086ea2eb-14a6-4fd4-914b-38e0bc8703e8|Low|Observability|Query details
Documentation
|
|Lambda Functions Without X-Ray Tracing
9488c451-074e-4cd3-aee3-7db6104f542c|Low|Observability|Query details
Documentation
|
|Stack Notifications Disabled
837e033c-4717-40bd-807e-6abaa30161b7|Low|Observability|Query details
Documentation
|
+|Unscanned ECR Image
9025b2b3-e554-4842-ba87-db7aeec36d35|Low|Observability|Query details
Documentation
|
|API Gateway Stage Without API Gateway UsagePlan Associated
7f8f1b60-43df-4c28-aa21-fb836dbd8071|Low|Resource Management|Query details
Documentation
|
|ECS Task Definition Invalid CPU or Memory
f4c9b5f5-68b8-491f-9e48-4f96644a1d51|Low|Resource Management|Query details
Documentation
|
|SDB Domain Declared As A Resource
6ea57c8b-f9c0-4ec7-bae3-bd75a9dee27d|Low|Resource Management|Query details
Documentation
|
diff --git a/docs/queries/cloudformation-queries/aws/06adef8c-c284-4de7-aad2-af43b07a8ca1.md b/docs/queries/cloudformation-queries/aws/06adef8c-c284-4de7-aad2-af43b07a8ca1.md
index e4e29fcf714..797d07369e1 100644
--- a/docs/queries/cloudformation-queries/aws/06adef8c-c284-4de7-aad2-af43b07a8ca1.md
+++ b/docs/queries/cloudformation-queries/aws/06adef8c-c284-4de7-aad2-af43b07a8ca1.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** IAM User LoginProfile Password Is In Plaintext
- **Platform:** CloudFormation
- **Severity:** High
-- **Category:** Insecure Configurations
+- **Category:** Secret Management
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/cloudFormation/aws/iam_user_login_profile_password_is_in_plaintext)
### Description
diff --git a/docs/queries/cloudformation-queries/aws/2b1d4935-9acf-48a7-8466-10d18bf51a69.md b/docs/queries/cloudformation-queries/aws/2b1d4935-9acf-48a7-8466-10d18bf51a69.md
index 91c8a7fac97..13336854cfc 100644
--- a/docs/queries/cloudformation-queries/aws/2b1d4935-9acf-48a7-8466-10d18bf51a69.md
+++ b/docs/queries/cloudformation-queries/aws/2b1d4935-9acf-48a7-8466-10d18bf51a69.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** RDS Multi-AZ Deployment Disabled
- **Platform:** CloudFormation
- **Severity:** Medium
-- **Category:** Backup
+- **Category:** Availability
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/cloudFormation/aws/rds_multi_az_deployment_disabled)
### Description
diff --git a/docs/queries/cloudformation-queries/aws/9025b2b3-e554-4842-ba87-db7aeec36d35.md b/docs/queries/cloudformation-queries/aws/9025b2b3-e554-4842-ba87-db7aeec36d35.md
index 37c7460bec3..38c062c84b9 100644
--- a/docs/queries/cloudformation-queries/aws/9025b2b3-e554-4842-ba87-db7aeec36d35.md
+++ b/docs/queries/cloudformation-queries/aws/9025b2b3-e554-4842-ba87-db7aeec36d35.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** Unscanned ECR Image
- **Platform:** CloudFormation
- **Severity:** Low
-- **Category:** Encryption
+- **Category:** Observability
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/cloudFormation/aws/unscanned_ecr_image)
### Description
diff --git a/docs/queries/cloudformation-queries/aws/a227ec01-f97a-4084-91a4-47b350c1db54.md b/docs/queries/cloudformation-queries/aws/a227ec01-f97a-4084-91a4-47b350c1db54.md
index 26acb5ad07d..e79eb7050f8 100644
--- a/docs/queries/cloudformation-queries/aws/a227ec01-f97a-4084-91a4-47b350c1db54.md
+++ b/docs/queries/cloudformation-queries/aws/a227ec01-f97a-4084-91a4-47b350c1db54.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** S3 Bucket Without Versioning
- **Platform:** CloudFormation
- **Severity:** Medium
-- **Category:** Observability
+- **Category:** Backup
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/cloudFormation/aws/s3_bucket_without_versioning)
### Description
diff --git a/docs/queries/cloudformation-queries/aws/a58d1a2d-4078-4b80-855b-84cc3f7f4540.md b/docs/queries/cloudformation-queries/aws/a58d1a2d-4078-4b80-855b-84cc3f7f4540.md
index 9ef78f98eb1..2cbf5857679 100644
--- a/docs/queries/cloudformation-queries/aws/a58d1a2d-4078-4b80-855b-84cc3f7f4540.md
+++ b/docs/queries/cloudformation-queries/aws/a58d1a2d-4078-4b80-855b-84cc3f7f4540.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** IAM Group Inline Policies
- **Platform:** CloudFormation
- **Severity:** Medium
-- **Category:** Encryption
+- **Category:** Access Control
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/cloudFormation/aws/iam_groups_inline_policies)
### Description
diff --git a/docs/queries/crossplane-queries.md b/docs/queries/crossplane-queries.md
index dfc6a3c8dfb..03fc80c3c3d 100644
--- a/docs/queries/crossplane-queries.md
+++ b/docs/queries/crossplane-queries.md
@@ -31,7 +31,7 @@ Below are listed queries related to Crossplane AZURE:
| Query |Severity|Category|More info|
|------------------------------|--------|--------|-----------|
|AKS RBAC Disabled
b2418936-cd47-4ea2-8346-623c0bdb87bd|Medium|Access Control|Query details
Documentation
|
-|Redis Cache Allows Non SSL Connections
6c7cfec3-c686-4ed2-bf58-a1ec054b63fc|Medium|Encryption|Query details
Documentation
|
+|Redis Cache Allows Non SSL Connections
6c7cfec3-c686-4ed2-bf58-a1ec054b63fc|Medium|Insecure Configurations|Query details
Documentation
|
### GCP
Below are listed queries related to Crossplane GCP:
diff --git a/docs/queries/crossplane-queries/azure/6c7cfec3-c686-4ed2-bf58-a1ec054b63fc.md b/docs/queries/crossplane-queries/azure/6c7cfec3-c686-4ed2-bf58-a1ec054b63fc.md
index 17e5cc427b4..659cafe80eb 100644
--- a/docs/queries/crossplane-queries/azure/6c7cfec3-c686-4ed2-bf58-a1ec054b63fc.md
+++ b/docs/queries/crossplane-queries/azure/6c7cfec3-c686-4ed2-bf58-a1ec054b63fc.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** Redis Cache Allows Non SSL Connections
- **Platform:** Crossplane
- **Severity:** Medium
-- **Category:** Encryption
+- **Category:** Insecure Configurations
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/crossplane/azure/redis_cache_allows_non_ssl_connections)
### Description
diff --git a/docs/queries/dockerfile-queries.md b/docs/queries/dockerfile-queries.md
index b8285198c27..4afff5ac246 100644
--- a/docs/queries/dockerfile-queries.md
+++ b/docs/queries/dockerfile-queries.md
@@ -46,7 +46,7 @@ This page contains all queries from Dockerfile.
|Run Using apt
b84a0b47-2e99-4c9f-8933-98bcabe2b94d|Low|Supply-Chain|Query details
Documentation
|
|Yum Install Allows Manual Input
6e19193a-8753-436d-8a09-76dcff91bb03|Low|Supply-Chain|Query details
Documentation
|
|Zypper Install Without Version
562952e4-0348-4dea-9826-44f3a2c6117b|Low|Supply-Chain|Query details
Documentation
|
-|UNIX Ports Out Of Range
71bf8cf8-f0a1-42fa-b9d2-d10525e0a38e|Info|Availability|Query details
Documentation
|
+|UNIX Ports Out Of Range
71bf8cf8-f0a1-42fa-b9d2-d10525e0a38e|Info|Networking and Firewall|Query details
Documentation
|
|Apk Add Using Local Cache Path
ae9c56a6-3ed1-4ac0-9b54-31267f51151d|Info|Supply-Chain|Query details
Documentation
|
|Apt Get Install Lists Were Not Deleted
df746b39-6564-4fed-bf85-e9c44382303c|Info|Supply-Chain|Query details
Documentation
|
|APT-GET Not Avoiding Additional Packages
7384dfb2-fcd1-4fbf-91cd-6c44c318c33c|Info|Supply-Chain|Query details
Documentation
|
diff --git a/docs/queries/dockerfile-queries/71bf8cf8-f0a1-42fa-b9d2-d10525e0a38e.md b/docs/queries/dockerfile-queries/71bf8cf8-f0a1-42fa-b9d2-d10525e0a38e.md
index b4f7a69a225..2b6c0ccb41a 100644
--- a/docs/queries/dockerfile-queries/71bf8cf8-f0a1-42fa-b9d2-d10525e0a38e.md
+++ b/docs/queries/dockerfile-queries/71bf8cf8-f0a1-42fa-b9d2-d10525e0a38e.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** UNIX Ports Out Of Range
- **Platform:** Dockerfile
- **Severity:** Info
-- **Category:** Availability
+- **Category:** Networking and Firewall
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/dockerfile/unix_ports_out_of_range)
### Description
diff --git a/docs/queries/pulumi-queries.md b/docs/queries/pulumi-queries.md
index 93e43216de3..011004deff8 100644
--- a/docs/queries/pulumi-queries.md
+++ b/docs/queries/pulumi-queries.md
@@ -31,8 +31,8 @@ Below are listed queries related to Pulumi AZURE:
| Query |Severity|Category|More info|
|------------------------------|--------|--------|-----------|
-|Redis Cache Allows Non SSL Connections
49e30ac8-f58e-4222-b488-3dcb90158ec1|Medium|Encryption|Query details
Documentation
|
|Storage Account Not Forcing HTTPS
cb8e4bf0-903d-45c6-a278-9a947d82a27b|Medium|Encryption|Query details
Documentation
|
+|Redis Cache Allows Non SSL Connections
49e30ac8-f58e-4222-b488-3dcb90158ec1|Medium|Insecure Configurations|Query details
Documentation
|
### GCP
Below are listed queries related to Pulumi GCP:
diff --git a/docs/queries/pulumi-queries/azure/49e30ac8-f58e-4222-b488-3dcb90158ec1.md b/docs/queries/pulumi-queries/azure/49e30ac8-f58e-4222-b488-3dcb90158ec1.md
index e4e71958e9f..f9d7b2f4b32 100644
--- a/docs/queries/pulumi-queries/azure/49e30ac8-f58e-4222-b488-3dcb90158ec1.md
+++ b/docs/queries/pulumi-queries/azure/49e30ac8-f58e-4222-b488-3dcb90158ec1.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** Redis Cache Allows Non SSL Connections
- **Platform:** Pulumi
- **Severity:** Medium
-- **Category:** Encryption
+- **Category:** Insecure Configurations
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/pulumi/azure/redis_cache_allows_non_ssl_connections)
### Description
diff --git a/docs/queries/terraform-queries.md b/docs/queries/terraform-queries.md
index df3d788134e..034a284cecb 100644
--- a/docs/queries/terraform-queries.md
+++ b/docs/queries/terraform-queries.md
@@ -249,10 +249,11 @@ Below are listed queries related to Terraform AWS:
|CMK Is Unusable
7350fa23-dcf7-4938-916d-6a60b0c73b50|Medium|Availability|Query details
Documentation
|
|ElastiCache Nodes Not Created Across Multi AZ
6db03a91-f933-4f13-ab38-a8b87a7de54d|Medium|Availability|Query details
Documentation
|
|ElastiCache Redis Cluster Without Backup
8fdb08a0-a868-4fdf-9c27-ccab0237f1ab|Medium|Backup|Query details
Documentation
|
+|RDS Cluster With Backup Disabled
e542bd46-58c4-4e0f-a52a-1fb4f9548e02|Medium|Backup|Query details
Documentation
|
|RDS With Backup Disabled
1dc73fb4-5b51-430c-8c5f-25dcf9090b02|Medium|Backup|Query details
Documentation
|
+|S3 Bucket Without Versioning
568a4d22-3517-44a6-a7ad-6a7eed88722c|Medium|Backup|Query details
Documentation
|
|Stack Retention Disabled
6e0e2f68-3fd9-4cd8-a5e4-e2213ef0df97|Medium|Backup|Query details
Documentation
|
|ALB Not Dropping Invalid Headers
6e3fd2ed-5c83-4c68-9679-7700d224d379|Medium|Best Practices|Query details
Documentation
|
-|RDS Cluster With Backup Disabled
e542bd46-58c4-4e0f-a52a-1fb4f9548e02|Medium|Best Practices|Query details
Documentation
|
|AMI Not Encrypted
8bbb242f-6e38-4127-86d4-d8f0b2687ae2|Medium|Encryption|Query details
Documentation
|
|CA Certificate Identifier Is Outdated
9f40c07e-699e-4410-8856-3ba0f2e3a2dd|Medium|Encryption|Query details
Documentation
|
|Cloudfront Viewer Protocol Policy Allows HTTP
55af1353-2f62-4fa0-a8e1-a210ca2708f5|Medium|Encryption|Query details
Documentation
|
@@ -283,6 +284,7 @@ Below are listed queries related to Terraform AWS:
|S3 Bucket Without Ignore Public ACL
4fa66806-0dd9-4f8d-9480-3174d39c7c91|Medium|Insecure Configurations|Query details
Documentation
|
|S3 Bucket Without Restriction Of Public Bucket
1ec253ab-c220-4d63-b2de-5b40e0af9293|Medium|Insecure Configurations|Query details
Documentation
|
|Service Control Policies Disabled
5ba6229c-8057-433e-91d0-21cf13569ca9|Medium|Insecure Configurations|Query details
Documentation
|
+|Default VPC Exists
96ed3526-0179-4c73-b1b2-372fde2e0d13|Medium|Insecure Defaults|Query details
Documentation
|
|Vulnerable Default SSL Certificate
3a1e94df-6847-4c0e-a3b6-6c6af4e128ef|Medium|Insecure Defaults|Query details
Documentation
|
|ALB Is Not Integrated With WAF
0afa6ab8-a047-48cf-be07-93a2f8c34cf7|Medium|Networking and Firewall|Query details
Documentation
|
|ALB Listening on HTTP
de7f5e83-da88-4046-871f-ea18504b1d43|Medium|Networking and Firewall|Query details
Documentation
|
@@ -317,7 +319,6 @@ Below are listed queries related to Terraform AWS:
|CloudWatch S3 policy Change Alarm Missing
27c6a499-895a-4dc7-9617-5c485218db13|Medium|Observability|Query details
Documentation
|
|Cloudwatch Security Group Changes Alarm Missing
4beaf898-9f8b-4237-89e2-5ffdc7ee6006|Medium|Observability|Query details
Documentation
|
|CloudWatch VPC Changes Alarm Missing
9d0d4512-1959-43a2-a17f-72360ff06d1b|Medium|Observability|Query details
Documentation
|
-|Default VPC Exists
96ed3526-0179-4c73-b1b2-372fde2e0d13|Medium|Observability|Query details
Documentation
|
|DocDB Logging Is Disabled
56f6a008-1b14-4af4-b9b2-ab7cf7e27641|Medium|Observability|Query details
Documentation
|
|EC2 Instance Monitoring Disabled
23b70e32-032e-4fa6-ba5c-82f56b9980e6|Medium|Observability|Query details
Documentation
|
|EKS cluster logging is not enabled
37304d3f-f852-40b8-ae3f-725e87a7cedf|Medium|Observability|Query details
Documentation
|
@@ -333,7 +334,6 @@ Below are listed queries related to Terraform AWS:
|Redshift Cluster Logging Disabled
15ffbacc-fa42-4f6f-a57d-2feac7365caa|Medium|Observability|Query details
Documentation
|
|S3 Bucket Logging Disabled
f861041c-8c9f-4156-acfc-5e6e524f5884|Medium|Observability|Query details
Documentation
|
|S3 Bucket Object Level CloudTrail Logging Disabled
a8fc2180-b3ac-4c93-bd0d-a55b974e4b07|Medium|Observability|Query details
Documentation
|
-|S3 Bucket Without Versioning
568a4d22-3517-44a6-a7ad-6a7eed88722c|Medium|Observability|Query details
Documentation
|
|Stack Notifications Disabled
b72d0026-f649-4c91-a9ea-15d8f681ac09|Medium|Observability|Query details
Documentation
|
|VPC FlowLogs Disabled
f83121ea-03da-434f-9277-9cd247ab3047|Medium|Observability|Query details
Documentation
|
|No Stack Policy
2f01fb2d-828a-499d-b98e-b83747305052|Medium|Resource Management|Query details
Documentation
|
@@ -360,11 +360,10 @@ Below are listed queries related to Terraform AWS:
|DOCDB Cluster Encrypted With AWS Managed Key
2134641d-30a4-4b16-8ffc-2cd4c4ffd15d|Low|Encryption|Query details
Documentation
|
|ECR Repository Not Encrypted With CMK
0e32d561-4b5a-4664-a6e3-a3fa85649157|Low|Encryption|Query details
Documentation
|
|EFS Without KMS
25d251f3-f348-4f95-845c-1090e41a615c|Low|Encryption|Query details
Documentation
|
-|Redis Disabled
4bd15dd9-8d5e-4008-8532-27eb0c3706d3|Low|Encryption|Query details
Documentation
|
-|Unscanned ECR Image
9630336b-3fed-4096-8173-b9afdfe346a7|Low|Encryption|Query details
Documentation
|
|AWS Password Policy With Unchangeable Passwords
9ef7d25d-9764-4224-9968-fa321c56ef76|Low|Insecure Configurations|Query details
Documentation
|
|IAM User Policy Without MFA
b5681959-6c09-4f55-b42b-c40fa12d03ec|Low|Insecure Configurations|Query details
Documentation
|
|Instance With No VPC
a31a5a29-718a-4ff4-8001-a69e5e4d029e|Low|Insecure Configurations|Query details
Documentation
|
+|Redis Disabled
4bd15dd9-8d5e-4008-8532-27eb0c3706d3|Low|Insecure Configurations|Query details
Documentation
|
|Redshift Cluster Without VPC
0a494a6a-ebe2-48a0-9d77-cf9d5125e1b3|Low|Insecure Configurations|Query details
Documentation
|
|S3 Bucket Without Enabled MFA Delete
c5b31ab9-0f26-4a49-b8aa-4cc064392f4d|Low|Insecure Configurations|Query details
Documentation
|
|Dynamodb VPC Endpoint Without Route Table Association
0bc534c5-13d1-4353-a7fe-b8665d5c1d7d|Low|Networking and Firewall|Query details
Documentation
|
@@ -393,6 +392,7 @@ Below are listed queries related to Terraform AWS:
|ElasticSearch Without Slow Logs
e979fcbc-df6c-422d-9458-c33d65e71c45|Low|Observability|Query details
Documentation
|
|KMS Key With No Deletion Window
0b530315-0ea4-497f-b34c-4ff86268f59d|Low|Observability|Query details
Documentation
|
|Lambda Functions Without X-Ray Tracing
8152e0cf-d2f0-47ad-96d5-d003a76eabd1|Low|Observability|Query details
Documentation
|
+|Unscanned ECR Image
9630336b-3fed-4096-8173-b9afdfe346a7|Low|Observability|Query details
Documentation
|
|API Gateway Stage Without API Gateway UsagePlan Associated
c999cf62-0920-40f8-8dda-0caccd66ed7e|Low|Resource Management|Query details
Documentation
|
|Security Group Not Used
4849211b-ac39-479e-ae78-5694d506cb24|Info|Access Control|Query details
Documentation
|
|DynamoDB Table Point In Time Recovery Disabled
741f1291-47ac-4a85-a07b-3d32a9d6bd3e|Info|Best Practices|Query details
Documentation
|
@@ -594,8 +594,8 @@ Below are listed queries related to Terraform GCP:
|Service Account with Improper Privileges
cefdad16-0dd5-4ac5-8ed2-a37502c78672|Medium|Resource Management|Query details
Documentation
|
|High Google KMS Crypto Key Rotation Period
d8c57c4e-bf6f-4e32-a2bf-8643532de77b|Medium|Secret Management|Query details
Documentation
|
|Project-wide SSH Keys Are Enabled In VM Instances
3e4d5ce6-3280-4027-8010-c26eeea1ec01|Medium|Secret Management|Query details
Documentation
|
+|User with IAM Role
704fcc44-a58f-4af5-82e2-93f2a58ef918|Low|Access Control|Query details
Documentation
|
|Outdated GKE Version
128df7ec-f185-48bc-8913-ce756a3ccb85|Low|Best Practices|Query details
Documentation
|
-|User with IAM Role
704fcc44-a58f-4af5-82e2-93f2a58ef918|Low|Best Practices|Query details
Documentation
|
|Cluster Labels Disabled
65c1bc7a-4835-4ac4-a2b6-13d310b0648d|Low|Insecure Configurations|Query details
Documentation
|
|COS Node Image Not Used
8a893e46-e267-485a-8690-51f39951de58|Low|Insecure Configurations|Query details
Documentation
|
|Legacy Client Certificate Auth Enabled
73fb21a1-b19a-45b1-b648-b47b1678681e|Low|Insecure Configurations|Query details
Documentation
|
diff --git a/docs/queries/terraform-queries/aws/4bd15dd9-8d5e-4008-8532-27eb0c3706d3.md b/docs/queries/terraform-queries/aws/4bd15dd9-8d5e-4008-8532-27eb0c3706d3.md
index a8ff89f6b95..e1a7da4bb4a 100644
--- a/docs/queries/terraform-queries/aws/4bd15dd9-8d5e-4008-8532-27eb0c3706d3.md
+++ b/docs/queries/terraform-queries/aws/4bd15dd9-8d5e-4008-8532-27eb0c3706d3.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** Redis Disabled
- **Platform:** Terraform
- **Severity:** Low
-- **Category:** Encryption
+- **Category:** Insecure Configurations
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/terraform/aws/redis_disabled)
### Description
diff --git a/docs/queries/terraform-queries/aws/568a4d22-3517-44a6-a7ad-6a7eed88722c.md b/docs/queries/terraform-queries/aws/568a4d22-3517-44a6-a7ad-6a7eed88722c.md
index 4fb0609ca4d..0395fe1d4ce 100644
--- a/docs/queries/terraform-queries/aws/568a4d22-3517-44a6-a7ad-6a7eed88722c.md
+++ b/docs/queries/terraform-queries/aws/568a4d22-3517-44a6-a7ad-6a7eed88722c.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** S3 Bucket Without Versioning
- **Platform:** Terraform
- **Severity:** Medium
-- **Category:** Observability
+- **Category:** Backup
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/terraform/aws/s3_bucket_without_versioning)
### Description
diff --git a/docs/queries/terraform-queries/aws/9630336b-3fed-4096-8173-b9afdfe346a7.md b/docs/queries/terraform-queries/aws/9630336b-3fed-4096-8173-b9afdfe346a7.md
index 820f5618894..7256b4c85ae 100644
--- a/docs/queries/terraform-queries/aws/9630336b-3fed-4096-8173-b9afdfe346a7.md
+++ b/docs/queries/terraform-queries/aws/9630336b-3fed-4096-8173-b9afdfe346a7.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** Unscanned ECR Image
- **Platform:** Terraform
- **Severity:** Low
-- **Category:** Encryption
+- **Category:** Observability
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/terraform/aws/unscanned_ecr_image)
### Description
diff --git a/docs/queries/terraform-queries/aws/96ed3526-0179-4c73-b1b2-372fde2e0d13.md b/docs/queries/terraform-queries/aws/96ed3526-0179-4c73-b1b2-372fde2e0d13.md
index 12880b74dd5..7eddf7014f8 100644
--- a/docs/queries/terraform-queries/aws/96ed3526-0179-4c73-b1b2-372fde2e0d13.md
+++ b/docs/queries/terraform-queries/aws/96ed3526-0179-4c73-b1b2-372fde2e0d13.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** Default VPC Exists
- **Platform:** Terraform
- **Severity:** Medium
-- **Category:** Observability
+- **Category:** Insecure Defaults
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/terraform/aws/default_vpc_exists)
### Description
diff --git a/docs/queries/terraform-queries/aws/e542bd46-58c4-4e0f-a52a-1fb4f9548e02.md b/docs/queries/terraform-queries/aws/e542bd46-58c4-4e0f-a52a-1fb4f9548e02.md
index 21f4fb53847..8b55e857e99 100644
--- a/docs/queries/terraform-queries/aws/e542bd46-58c4-4e0f-a52a-1fb4f9548e02.md
+++ b/docs/queries/terraform-queries/aws/e542bd46-58c4-4e0f-a52a-1fb4f9548e02.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** RDS Cluster With Backup Disabled
- **Platform:** Terraform
- **Severity:** Medium
-- **Category:** Best Practices
+- **Category:** Backup
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/terraform/aws/rds_cluster_with_backup_disabled)
### Description
diff --git a/docs/queries/terraform-queries/gcp/704fcc44-a58f-4af5-82e2-93f2a58ef918.md b/docs/queries/terraform-queries/gcp/704fcc44-a58f-4af5-82e2-93f2a58ef918.md
index 61800770990..c1a99168259 100644
--- a/docs/queries/terraform-queries/gcp/704fcc44-a58f-4af5-82e2-93f2a58ef918.md
+++ b/docs/queries/terraform-queries/gcp/704fcc44-a58f-4af5-82e2-93f2a58ef918.md
@@ -19,7 +19,7 @@ hide:
- **Query name:** User with IAM Role
- **Platform:** Terraform
- **Severity:** Low
-- **Category:** Best Practices
+- **Category:** Access Control
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/terraform/gcp/user_with_iam_role)
### Description