Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

docs(queries): update queries catalog #6999

Merged
merged 1 commit into from
Apr 12, 2024
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
32 changes: 16 additions & 16 deletions docs/queries/all-queries.md

Large diffs are not rendered by default.

2 changes: 1 addition & 1 deletion docs/queries/ansible-queries.md
Original file line number Diff line number Diff line change
Expand Up @@ -70,6 +70,7 @@ Below are listed queries related to Ansible AWS:
|Auto Scaling Group With No Associated ELB<br/><sup><sub>050f085f-a8db-4072-9010-2cca235cc02f</sub></sup>|<span style="color:#ff7213">Medium</span>|Availability|<a href="../ansible-queries/aws/050f085f-a8db-4072-9010-2cca235cc02f" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/ec2_asg_module.html#parameter-load_balancers">Documentation</a><br/>|
|CMK Is Unusable<br/><sup><sub>133fee21-37ef-45df-a563-4d07edc169f4</sub></sup>|<span style="color:#ff7213">Medium</span>|Availability|<a href="../ansible-queries/aws/133fee21-37ef-45df-a563-4d07edc169f4" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/aws_kms_module.html#parameter-enabled">Documentation</a><br/>|
|RDS With Backup Disabled<br/><sup><sub>e69890e6-fce5-461d-98ad-cb98318dfc96</sub></sup>|<span style="color:#ff7213">Medium</span>|Backup|<a href="../ansible-queries/aws/e69890e6-fce5-461d-98ad-cb98318dfc96" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/rds_instance_module.html#parameter-backup_retention_period">Documentation</a><br/>|
|S3 Bucket Without Versioning<br/><sup><sub>9232306a-f839-40aa-b3ef-b352001da9a5</sub></sup>|<span style="color:#ff7213">Medium</span>|Backup|<a href="../ansible-queries/aws/9232306a-f839-40aa-b3ef-b352001da9a5" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/amazon/aws/s3_bucket_module.html#parameter-versioning">Documentation</a><br/>|
|Stack Retention Disabled<br/><sup><sub>17d5ba1d-7667-4729-b1a6-b11fde3db7f7</sub></sup>|<span style="color:#ff7213">Medium</span>|Backup|<a href="../ansible-queries/aws/17d5ba1d-7667-4729-b1a6-b11fde3db7f7" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/cloudformation_stack_set_module.html#parameter-purge_stacks">Documentation</a><br/>|
|AMI Not Encrypted<br/><sup><sub>97707503-a22c-4cd7-b7c0-f088fa7cf830</sub></sup>|<span style="color:#ff7213">Medium</span>|Encryption|<a href="../ansible-queries/aws/97707503-a22c-4cd7-b7c0-f088fa7cf830" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/amazon/aws/ec2_ami_module.html">Documentation</a><br/>|
|CA Certificate Identifier Is Outdated<br/><sup><sub>5eccd62d-8b4d-46d3-83ea-1879f3cbd3ce</sub></sup>|<span style="color:#ff7213">Medium</span>|Encryption|<a href="../ansible-queries/aws/5eccd62d-8b4d-46d3-83ea-1879f3cbd3ce" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/rds_instance_module.html#parameter-ca_certificate_identifier">Documentation</a><br/>|
Expand Down Expand Up @@ -99,7 +100,6 @@ Below are listed queries related to Ansible AWS:
|CloudFront Logging Disabled<br/><sup><sub>d31cb911-bf5b-4eb6-9fc3-16780c77c7bd</sub></sup>|<span style="color:#ff7213">Medium</span>|Observability|<a href="../ansible-queries/aws/d31cb911-bf5b-4eb6-9fc3-16780c77c7bd" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/cloudfront_distribution_module.html">Documentation</a><br/>|
|CloudTrail Logging Disabled<br/><sup><sub>d4a73c49-cbaa-4c6f-80ee-d6ef5a3a26f5</sub></sup>|<span style="color:#ff7213">Medium</span>|Observability|<a href="../ansible-queries/aws/d4a73c49-cbaa-4c6f-80ee-d6ef5a3a26f5" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/cloudtrail_module.html#parameter-enable_logging">Documentation</a><br/>|
|S3 Bucket Logging Disabled<br/><sup><sub>c3b9f7b0-f5a0-49ec-9cbc-f1e346b7274d</sub></sup>|<span style="color:#ff7213">Medium</span>|Observability|<a href="../ansible-queries/aws/c3b9f7b0-f5a0-49ec-9cbc-f1e346b7274d" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/amazon/aws/s3_bucket_module.html#parameter-debug_botocore_endpoint_logs">Documentation</a><br/>|
|S3 Bucket Without Versioning<br/><sup><sub>9232306a-f839-40aa-b3ef-b352001da9a5</sub></sup>|<span style="color:#ff7213">Medium</span>|Observability|<a href="../ansible-queries/aws/9232306a-f839-40aa-b3ef-b352001da9a5" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/amazon/aws/s3_bucket_module.html#parameter-versioning">Documentation</a><br/>|
|No Stack Policy<br/><sup><sub>ffe0fd52-7a8b-4a5c-8fc7-49844418e6c9</sub></sup>|<span style="color:#ff7213">Medium</span>|Resource Management|<a href="../ansible-queries/aws/ffe0fd52-7a8b-4a5c-8fc7-49844418e6c9" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/amazon/aws/cloudformation_module.html">Documentation</a><br/>|
|Authentication Without MFA<br/><sup><sub>eee107f9-b3d8-45d3-b9c6-43b5a7263ce1</sub></sup>|<span style="color:#edd57e">Low</span>|Access Control|<a href="../ansible-queries/aws/eee107f9-b3d8-45d3-b9c6-43b5a7263ce1" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/iam_mfa_device_info_module.html">Documentation</a><br/>|
|ECS Service Without Running Tasks<br/><sup><sub>f5c45127-1d28-4b49-a692-0b97da1c3a84</sub></sup>|<span style="color:#edd57e">Low</span>|Availability|<a href="../ansible-queries/aws/f5c45127-1d28-4b49-a692-0b97da1c3a84" target="_blank">Query details</a><br><a href="https://docs.ansible.com/ansible/latest/collections/community/aws/ecs_service_module.html#ansible-collections-community-aws-ecs-service-module">Documentation</a><br/>|
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ hide:
- **Query name:** S3 Bucket Without Versioning
- **Platform:** Ansible
- **Severity:** <span style="color:#ff7213">Medium</span>
- **Category:** Observability
- **Category:** Backup
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/ansible/aws/s3_bucket_without_versioning)

### Description
Expand Down
2 changes: 1 addition & 1 deletion docs/queries/azureresourcemanager-queries.md
Original file line number Diff line number Diff line change
Expand Up @@ -35,13 +35,13 @@ This page contains all queries from AzureResourceManager.
|Phone Number Not Set For Security Contacts<br/><sup><sub>3e9fcc67-1f64-405f-b2f9-0a6be17598f0</sub></sup>|<span style="color:#edd57e">Low</span>|Best Practices|<a href="../azureresourcemanager-queries/azure/3e9fcc67-1f64-405f-b2f9-0a6be17598f0" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.security/securitycontacts?tabs=json">Documentation</a><br/>|
|AKS Dashboard Is Enabled<br/><sup><sub>c62d3b92-9a11-4ffd-b7b7-6faaae83faed</sub></sup>|<span style="color:#edd57e">Low</span>|Insecure Configurations|<a href="../azureresourcemanager-queries/azure/c62d3b92-9a11-4ffd-b7b7-6faaae83faed" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.containerservice/managedclusters?tabs=json#managedclusteraddonprofile">Documentation</a><br/>|
|AKS With Authorized IP Ranges Disabled<br/><sup><sub>2583fab1-953b-4fae-bd02-4a136a6c21f9</sub></sup>|<span style="color:#edd57e">Low</span>|Networking and Firewall|<a href="../azureresourcemanager-queries/azure/2583fab1-953b-4fae-bd02-4a136a6c21f9" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.containerservice/managedclusters?tabs=json#managedclusterapiserveraccessprofile-object">Documentation</a><br/>|
|Standard Price Is Not Selected<br/><sup><sub>2081c7d6-2851-4cce-bda5-cb49d462da42</sub></sup>|<span style="color:#edd57e">Low</span>|Networking and Firewall|<a href="../azureresourcemanager-queries/azure/2081c7d6-2851-4cce-bda5-cb49d462da42" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.security/pricings?tabs=json#pricingproperties-object">Documentation</a><br/>|
|Storage Account Allows Default Network Access<br/><sup><sub>9073f073-5d60-4b46-b569-0d6baa80ed95</sub></sup>|<span style="color:#edd57e">Low</span>|Networking and Firewall|<a href="../azureresourcemanager-queries/azure/9073f073-5d60-4b46-b569-0d6baa80ed95" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.storage/storageaccounts?tabs=json#storageaccountpropertiescreateparameters-object">Documentation</a><br/>|
|Website with 'Http20Enabled' Disabled<br/><sup><sub>70111098-7f85-48f0-b1b4-e4261cf5f61b</sub></sup>|<span style="color:#edd57e">Low</span>|Networking and Firewall|<a href="../azureresourcemanager-queries/azure/70111098-7f85-48f0-b1b4-e4261cf5f61b" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.web/sites?tabs=json#siteproperties-object">Documentation</a><br/>|
|Log Profile Incorrect Category<br/><sup><sub>4d522e7b-f938-4d51-a3b1-974ada528bd3</sub></sup>|<span style="color:#edd57e">Low</span>|Observability|<a href="../azureresourcemanager-queries/azure/4d522e7b-f938-4d51-a3b1-974ada528bd3" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.insights/2016-03-01/logprofiles?tabs=json#logprofileproperties-object">Documentation</a><br/>|
|SQL Server Database With Unrecommended Retention Days<br/><sup><sub>c09cdac2-7670-458a-bf6c-efad6880973a</sub></sup>|<span style="color:#edd57e">Low</span>|Observability|<a href="../azureresourcemanager-queries/azure/c09cdac2-7670-458a-bf6c-efad6880973a" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.sql/servers/databases/auditingsettings?tabs=json">Documentation</a><br/>|
|Unrecommended Log Profile Retention Policy<br/><sup><sub>25684eac-daaa-4c2c-94b4-8d2dbb627909</sub></sup>|<span style="color:#edd57e">Low</span>|Observability|<a href="../azureresourcemanager-queries/azure/25684eac-daaa-4c2c-94b4-8d2dbb627909" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.insights/2016-03-01/logprofiles?tabs=json#retentionpolicy-object">Documentation</a><br/>|
|Unrecommended Network Watcher Flow Log Retention Policy<br/><sup><sub>564b70f8-41cd-4690-aff8-bb53add86bc9</sub></sup>|<span style="color:#edd57e">Low</span>|Observability|<a href="../azureresourcemanager-queries/azure/564b70f8-41cd-4690-aff8-bb53add86bc9" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.network/2019-11-01/networkwatchers/flowlogs?tabs=json#retentionpolicyparameters-object">Documentation</a><br/>|
|Standard Price Is Not Selected<br/><sup><sub>2081c7d6-2851-4cce-bda5-cb49d462da42</sub></sup>|<span style="color:#edd57e">Low</span>|Resource Management|<a href="../azureresourcemanager-queries/azure/2081c7d6-2851-4cce-bda5-cb49d462da42" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.security/pricings?tabs=json#pricingproperties-object">Documentation</a><br/>|
|Account Admins Not Notified By Email<br/><sup><sub>a8852cc0-fd4b-4fc7-9372-1e43fad0732e</sub></sup>|<span style="color:#5bc0de">Info</span>|Best Practices|<a href="../azureresourcemanager-queries/azure/a8852cc0-fd4b-4fc7-9372-1e43fad0732e" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.sql/2017-03-01-preview/servers/securityalertpolicies?tabs=json">Documentation</a><br/>|
|SQL Alert Policy Without Emails<br/><sup><sub>89b79fe5-49bd-4d39-84ce-55f5fc6f7764</sub></sup>|<span style="color:#5bc0de">Info</span>|Best Practices|<a href="../azureresourcemanager-queries/azure/89b79fe5-49bd-4d39-84ce-55f5fc6f7764" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.sql/servers/databases/securityalertpolicies?tabs=json">Documentation</a><br/>|
|Email Notifications Disabled<br/><sup><sub>79c2c2c0-eb00-47c0-ac16-f8b0e2c81c92</sub></sup>|<span style="color:#5bc0de">Info</span>|Networking and Firewall|<a href="../azureresourcemanager-queries/azure/79c2c2c0-eb00-47c0-ac16-f8b0e2c81c92" target="_blank">Query details</a><br><a href="https://docs.microsoft.com/en-us/azure/templates/microsoft.security/securitycontacts">Documentation</a><br/>|
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ hide:
- **Query name:** Standard Price Is Not Selected
- **Platform:** AzureResourceManager
- **Severity:** <span style="color:#edd57e">Low</span>
- **Category:** Networking and Firewall
- **Category:** Resource Management
- **URL:** [Github](https://github.com/Checkmarx/kics/tree/master/assets/queries/azureResourceManager/standard_price_not_selected)

### Description
Expand Down
Loading
Loading