cartography icon indicating copy to clipboard operation
cartography copied to clipboard

AWS: Public RDS/EBS snapshot

Open opt9 opened this issue 6 years ago • 6 comments

Feature request

Title: AWS: Public RDS/EBS snapshot

Description:

It would be good to add AWS public RDS/EBS snapshot check.

[optional Relevant Links:]

https://www.cloudconformity.com/knowledge-base/aws/RDS/public-snapshots.html https://asecure.cloud/a/rds-snapshots-public-prohibited/

opt9 avatar Jan 06 '20 10:01 opt9

Just to make sure I understand, is this feature request asking to add RDS DB snapshots as nodes to the graph?

achantavy avatar Jan 06 '20 19:01 achantavy

  1. Add RDS DB snapshots as nodes.
  2. Check the value of DBSnapshotAttributes/AttributeValues

It would be good to add an analysis job.

opt9 avatar Jan 07 '20 01:01 opt9

Ah interesting:

From: https://docs.aws.amazon.com/AmazonRDS/latest/APIReference/API_DBSnapshotAttribute.html The attribute named restore refers to the list of AWS accounts that have permission to copy or restore the manual DB cluster snapshot. For more information, see the ModifyDBSnapshotAttribute API action.

I'm assuming you're thinking of an analysis job that would connect snapshots to the AWS accounts that are allowed to restore them?

achantavy avatar Jan 07 '20 01:01 achantavy

I'm just considering to check whether AttributeValues are all. It means any AWS user account can restore snapshots.

opt9 avatar Jan 07 '20 04:01 opt9

Ah I see, yeah that's super interesting.

We can't make any commitments on adding this feature at the moment but I like the idea a lot. If others have cycles to add/modify an intel module we'll be happy to give guidance.

achantavy avatar Jan 08 '20 20:01 achantavy

This issue has been automatically marked as stale because it has not had recent activity. It will be closed if no further activity occurs.

stale[bot] avatar Jan 22 '20 21:01 stale[bot]