Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Feature/cloudsploit gcp new rules p1 #1455

Open
wants to merge 10 commits into
base: master
Choose a base branch
from

Conversation

mcplima
Copy link

@mcplima mcplima commented Nov 7, 2022

New GCP Rules - Cloudsploit - Part 1 (all rules with DOCs on Zanshin)
2 API rules
2 Compute rules
1 kms rule
2 sql rules
10 network rules

Updated collector.js with new collectors
Updated export.js with the new rules
Updated regions.js with the scopes for the new collectors

All these rules where documented previously on Zanshin. They refer to an update done to Cloudsploit 6 months ago.

rfranco and others added 10 commits June 22, 2022 12:53
It is causing alarms to be open and close every day.
auditConfigurationLogging
- supports filter in more than one line
- supports double/single quotes and no quotes at all when there are no special characters in strings
- supports filter when there are multiple spaces between words

customRoleLogging
- supports filter in more than one line
- supports double/single quotes and no quotes at all when there are no special characters in strings
- supports filter when there are multiple spaces between words

projectOwnershipLogging
- supports double/single quotes and no quotes at all when there are no special characters in strings
- supports filter when there are multiple spaces between words

sqlConfigurationLogging
- supports double/single quotes

storagePermissionsLogging
- supports filter in more than one line
- supports double/single quotes and no quotes at all when there are no special characters in strings
- supports filter when there are multiple spaces between words

vpcFirewallRuleLogging
- added a missing payload method to the test
- supports double/single quotes and no quotes at all when there are no special characters in strings
- supports filter when there are multiple spaces between words

vpcNetworkLogging
- supports double/single quotes and no quotes at all when there are no special characters in strings
- supports filter when there are multiple spaces between words

vpcNetworkRouteLogging
- supports double/single quotes and no quotes at all when there are no special characters in strings
- supports filter when there are multiple spaces between words
2 API rules
2 Compute rules
1 kms rule
2 sql rules
10 network rules

Updated collector.js with new collectors
Updated export.js with the new rules
Update regions.js with the scopes for the new collectors
2 API rules
2 Compute rules
1 kms rule
2 sql rules
10 network rules

Updated collector.js with new collectors
Updated export.js with the new rules
Update regions.js with the scopes for the new collectors
@rfranco rfranco deleted the feature/cloudsploit_gcp_new_rules_p1 branch January 3, 2023 17:33
@alphadev4
Copy link
Collaborator

hi @mcplima can you please resolve the conflicts?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants