Skip to content

Commit

Permalink
changing ID to capital C
Browse files Browse the repository at this point in the history
  • Loading branch information
slashben committed Sep 12, 2021
1 parent b888124 commit 1393c37
Show file tree
Hide file tree
Showing 57 changed files with 57 additions and 57 deletions.
2 changes: 1 addition & 1 deletion controls/Applicationscredentialsinconfigurationfiles.json
Original file line number Diff line number Diff line change
Expand Up @@ -13,5 +13,5 @@
"rule-credentials-in-env-var",
"rule-credentials-configmap"
],
"id": "c_0012"
"id": "C-0012"
}
2 changes: 1 addition & 1 deletion controls/ListKubernetessecrets.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-can-list-get-secrets"
],
"id": "c_0015"
"id": "C-0015"
}
2 changes: 1 addition & 1 deletion controls/SSHserverrunninginsidecontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-can-ssh-to-pod"
],
"id": "c_0042"
"id": "C-0042"
}
2 changes: 1 addition & 1 deletion controls/accesscontainerserviceaccount.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"access-container-service-account"
],
"id": "c_0053"
"id": "C-0053"
}
2 changes: 1 addition & 1 deletion controls/accessk8sdashboard.json
Original file line number Diff line number Diff line change
Expand Up @@ -12,5 +12,5 @@
"rulesNames": [
"rule-access-dashboard"
],
"id": "c_0014"
"id": "C-0014"
}
2 changes: 1 addition & 1 deletion controls/accesskubeletAPI.json
Original file line number Diff line number Diff line change
Expand Up @@ -9,5 +9,5 @@
"description": "Kubelet is the Kubernetes agent that is installed on each node. Kubelet is responsible for the proper execution of pods that are assigned to the node. Kubelet exposes a read-only API service that does not require authentication (TCP port 10255). Attackers with network access to the host (for example, via running code on a compromised container) can send API requests to the Kubelet API. Specifically querying https://[NODE IP]:10255/pods/ retrieves the running pods on the node. https://[NODE IP]:10255/spec/ retrieves information about the node itself, such as CPU and memory consumption.",
"remediation": "Define network policy (native kubernetes or using ARMO runtime protection). Use ARMO runtime protection capabilities to monitor network traffic.",
"rulesNames": [],
"id": "c_0003"
"id": "C-0003"
}
2 changes: 1 addition & 1 deletion controls/accesstillerendpoint.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"access-tiller-endpoint"
],
"id": "c_0033"
"id": "C-0033"
}
2 changes: 1 addition & 1 deletion controls/allowedhostpath.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"alert-rw-hostpath"
],
"id": "c_0006"
"id": "C-0006"
}
2 changes: 1 addition & 1 deletion controls/allowprivilegeescalation.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"rule-allow-privilege-escalation"
],
"id": "c_0016"
"id": "C-0016"
}
2 changes: 1 addition & 1 deletion controls/anonymousrequests.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"anonymous-requests"
],
"id": "c_0051"
"id": "C-0051"
}
2 changes: 1 addition & 1 deletion controls/applicationexploitRCE.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"deny-RCE-vuln-image-pods"
],
"id": "c_0025"
"id": "C-0025"
}
2 changes: 1 addition & 1 deletion controls/automaticmappingserviceaccount.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"automount-service-account"
],
"id": "c_0034"
"id": "C-0034"
}
2 changes: 1 addition & 1 deletion controls/backdoorcontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-can-create-modify-pod"
],
"id": "c_0027"
"id": "C-0027"
}
2 changes: 1 addition & 1 deletion controls/bash-cmdinsidecontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-can-bash-cmd-inside-container"
],
"id": "c_0019"
"id": "C-0019"
}
2 changes: 1 addition & 1 deletion controls/clearcontainerlogs.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-can-delete-logs"
],
"id": "c_0029"
"id": "C-0029"
}
2 changes: 1 addition & 1 deletion controls/cluster-adminbinding.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-list-all-cluster-admins"
],
"id": "c_0035"
"id": "C-0035"
}
2 changes: 1 addition & 1 deletion controls/clusterInternalnetworking.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"internal-networking"
],
"id": "c_0054"
"id": "C-0054"
}
2 changes: 1 addition & 1 deletion controls/compromisedimagesinregistry.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-identify-blacklisted-image-registries"
],
"id": "c_0001"
"id": "C-0001"
}
2 changes: 1 addition & 1 deletion controls/configuredlivenessprobe.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"configured-liveness-probe"
],
"id": "c_0056"
"id": "C-0056"
}
2 changes: 1 addition & 1 deletion controls/configuredreadinessprobe.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"configured-readiness-probe"
],
"id": "c_0018"
"id": "C-0018"
}
2 changes: 1 addition & 1 deletion controls/containerhostport.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"container-hostPort"
],
"id": "c_0044"
"id": "C-0044"
}
2 changes: 1 addition & 1 deletion controls/controlplanehardening.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"insecure-port-flag"
],
"id": "c_0005"
"id": "C-0005"
}
2 changes: 1 addition & 1 deletion controls/coreDNSpoisoning.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-can-update-configmap"
],
"id": "c_0037"
"id": "C-0037"
}
2 changes: 1 addition & 1 deletion controls/dangerouscapabilities.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"dangerous-capabilities"
],
"id": "c_0028"
"id": "C-0028"
}
2 changes: 1 addition & 1 deletion controls/datadestruction.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-excessive-delete-rights"
],
"id": "c_0007"
"id": "C-0007"
}
2 changes: 1 addition & 1 deletion controls/deleteKubernetesevents.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-can-delete-k8s-events"
],
"id": "c_0031"
"id": "C-0031"
}
2 changes: 1 addition & 1 deletion controls/execintocontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"exec-into-container"
],
"id": "c_0002"
"id": "C-0002"
}
2 changes: 1 addition & 1 deletion controls/exposeddashboard.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-exposed-dashboard"
],
"id": "c_0047"
"id": "C-0047"
}
2 changes: 1 addition & 1 deletion controls/exposedsensitiveinterfaces.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"exposed-sensitive-interfaces"
],
"id": "c_0021"
"id": "C-0021"
}
2 changes: 1 addition & 1 deletion controls/hostPathmount.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"alert-any-hostpath"
],
"id": "c_0048"
"id": "C-0048"
}
2 changes: 1 addition & 1 deletion controls/hostnetworkaccess.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"host-network-access"
],
"id": "c_0041"
"id": "C-0041"
}
2 changes: 1 addition & 1 deletion controls/hostpidipcprivileges.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"host-pid-ipc-privileges"
],
"id": "c_0038"
"id": "C-0038"
}
2 changes: 1 addition & 1 deletion controls/immutablecontainerfilesystem.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"immutable-container-filesystem"
],
"id": "c_0017"
"id": "C-0017"
}
2 changes: 1 addition & 1 deletion controls/ingressandegressblocked.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"ingress-and-egress-blocked"
],
"id": "c_0030"
"id": "C-0030"
}
2 changes: 1 addition & 1 deletion controls/insecurecapabilities.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"insecure-capabilities"
],
"id": "c_0046"
"id": "C-0046"
}
2 changes: 1 addition & 1 deletion controls/instancemetadataAPI..json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"instance-metadata-api-access"
],
"id": "c_0052"
"id": "C-0052"
}
2 changes: 1 addition & 1 deletion controls/kubernetescronJob.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-deny-cronjobs"
],
"id": "c_0026"
"id": "C-0026"
}
2 changes: 1 addition & 1 deletion controls/linuxhardening.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"linux-hardening"
],
"id": "c_0055"
"id": "C-0055"
}
2 changes: 1 addition & 1 deletion controls/maliciousadmissioncontroller-mutating.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"list-all-mutating-webhooks"
],
"id": "c_0039"
"id": "C-0039"
}
2 changes: 1 addition & 1 deletion controls/maliciousadmissioncontroller-validating.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"list-all-validating-webhooks"
],
"id": "c_0036"
"id": "C-0036"
}
2 changes: 1 addition & 1 deletion controls/morethanonereplicas.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"more-than-one-replicas"
],
"id": "c_0032"
"id": "C-0032"
}
2 changes: 1 addition & 1 deletion controls/mountserviceprincipal.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"alert-any-hostpath"
],
"id": "c_0020"
"id": "C-0020"
}
2 changes: 1 addition & 1 deletion controls/namesimilarity.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-name-similarity"
],
"id": "c_0043"
"id": "C-0043"
}
2 changes: 1 addition & 1 deletion controls/networkmapping.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"internal-networking"
],
"id": "c_0049"
"id": "C-0049"
}
2 changes: 1 addition & 1 deletion controls/networkpolicies.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"internal-networking"
],
"id": "c_0011"
"id": "C-0011"
}
2 changes: 1 addition & 1 deletion controls/newcontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-can-create-modify-pod"
],
"id": "c_0010"
"id": "C-0010"
}
2 changes: 1 addition & 1 deletion controls/nonrootcontainers.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"non-root-containers"
],
"id": "c_0013"
"id": "C-0013"
}
2 changes: 1 addition & 1 deletion controls/podspecificversiontag.json
Original file line number Diff line number Diff line change
Expand Up @@ -8,5 +8,5 @@
"rulesNames": [
"pod-specific-version-tag"
],
"id": "c_0040"
"id": "C-0040"
}
2 changes: 1 addition & 1 deletion controls/privilegedcontainer.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-privilege-escalation"
],
"id": "c_0057"
"id": "C-0057"
}
2 changes: 1 addition & 1 deletion controls/resourcehijacking.json
Original file line number Diff line number Diff line change
Expand Up @@ -11,5 +11,5 @@
"rulesNames": [
"rule-can-create-modify-pod"
],
"id": "c_0023"
"id": "C-0023"
}
Loading

0 comments on commit 1393c37

Please sign in to comment.