> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-cspm-release-information/features-introduced-in-july-2023.md).

# Features Introduced in July 2023

Learn what’s new on Prisma® Cloud in July 2023.

* [New Features Introduced in 23.7.2](#new-features-jul-2)
* [New Features Introduced in 23.7.1](#new-features-jul-1)

## New Features Introduced in 23.7.2

* [New Features](#new-features2)
* [API Ingestions](#api-ingestions2)
* [New Policies](#new-policies2)
* [Policy Updates](#policy-updates2)
* [IAM Policy Updates](#iam-policy-update)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates2)
* [Changes in Existing Behavior](#changes-in-existing-behavior2)
* [REST API Updates](#rest-api-updates2)

## New Features

| FEATURE                                                 | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| ------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| **Integrated View of Run and Build details for Alerts** | <p>To help you as a Cloud Security Engineer investigate issues from code to cloud, the alert details now include information to trace and attribute which build-time resource has caused a policy violation for a runtime resource deployed in your cloud account. The alert details overview includes the IaC resource details and information on the build time resource. The new Traceability information helps you connect an alert from the production environment back to the origin templates in your upstream development environment.</p><p>To view the build-time details in an alert:</p><ul><li>You must enable a Configuration policy with the subtype Run, Build and attach it to an alert rule on Prisma Cloud.</li><li>Your IaC templates must be onboarded through a VCS integration.</li><li>Terraform resources must include the <strong>yor\_trace</strong> tag so that your IaC resources are tagged with a unique UUID for tracing the relationship between the code resource and the runtime resource that is deployed from it. This is not necessary for CloudFormation.</li></ul><p><img src="/files/vmRkqtWhK9JMnKySeNyg" alt="" data-size="original"></p> |
| **Prisma Cloud Data Security - Asset Level Scan**       | <p>There is usually several TB or PB of data stored in your organization’s S3 buckets. In order to reduce the cost associated with the scanning of a large volume of data and to provide you with more value, Prisma Cloud Data Security now provides you the option of <strong>Asset Level Scan</strong>. When you select this option (default) while configuring a scan, Prisma Cloud randomly scans 10% of objects or maximum of 1TB (whichever is lower) and sends the data for analysis. It stops the scan as soon as it detects an object with sensitive data and triggers a 'Storage Asset with sensitive data found' policy.</p><p>Asset Level Scan only applies when you select the Backward Scan mode and does exposure analysis and data classification and not malware scanning. It is only available when you’re configuring a data security scan for your AWS cloud accounts.</p><p><img src="/files/sN3jQ2dgrQFGlkspAOSB" alt="" data-size="original"></p>                                                                                                                                                                                                            |

## API Ingestions

| SERVICE                           | API DETAILS                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| --------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Amazon Inspector**              | <p><strong>aws-inspector-v2-coverage</strong></p><p>Additional permission required:</p><ul><li><code>inspector2:ListCoverage</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                   |
| **Amazon Inspector**              | <p><strong>aws-inspector-v2-finding</strong></p><p>Additional permission required:</p><ul><li><code>inspector2:ListFindings</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                    |
| **Amazon Inspector**              | <p><strong>aws-inspector-v2-filter</strong></p><p>Additional permission required:</p><ul><li><code>inspector2:ListFilters</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                                      |
| **Amazon Inspector**              | <p><strong>aws-inspector-v2-permission</strong></p><p>Additional permission required:</p><ul><li><code>inspector2:ListAccountPermissions</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                                                                                                                                                                                                       |
| **Azure Virtual Network**         | <p><strong>azure-bastion-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Network/bastionHosts/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                                                                                                     |
| **Google Deployment Manager**     | <p><strong>gcloud-deployment-manager-deployment</strong></p><p>Additional permissions required:</p><ul><li><code>deploymentmanager.deployments.list</code></li><li><code>deploymentmanager.deployments.getIamPolicy</code></li></ul><p>The Viewer role only includes the permission <code>deploymentmanager.deployments.list</code>.</p><p>You must manually add the permission or update the Terraform template to enable <code>deploymentmanager.deployments.getIamPolicy</code></p> |
| **Google Deployment Manager**     | <p><strong>gcloud-deployment-manager-deployment-manifest</strong></p><p>Additional permissions required:</p><ul><li><code>deploymentmanager.deployments.list</code></li><li><code>deploymentmanager.manifests.list</code></li></ul><p>The Viewer role only includes the permissions.</p>                                                                                                                                                                                               |
| **Google Stackdriver Monitoring** | <p><strong>gcloud-monitoring-group</strong></p><p>Additional permission required:</p><ul><li><code>monitoring.groups.list</code></li></ul><p>The Viewer role only includes the permission.</p>                                                                                                                                                                                                                                                                                         |
| **Google Stackdriver Monitoring** | <p><strong>gcloud-monitoring-snooze</strong></p><p>Additional permission required:</p><ul><li><code>monitoring.snoozes.list</code></li></ul><p>The Viewer role only includes the permission.</p>                                                                                                                                                                                                                                                                                       |
| **Google Cloud Translation**      | <p><strong>gcloud-translation-model</strong></p><p>Additional permissions required:</p><ul><li><code>cloudtranslate.locations.list</code></li><li><code>cloudtranslate.customModels.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                                                                                                                              |
| **Google Cloud Translation**      | <p><strong>gcloud-translation-native-dataset</strong></p><p>Additional permissions required:</p><ul><li><code>cloudtranslate.locations.list</code></li><li><code>cloudtranslate.datasets.list</code></li></ul><p>The Viewer role includes the permissions.</p><p>Legacy Datasets are not ingested as part of this API.</p>                                                                                                                                                             |

## New Policies

No new policies for 23.7.2.

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>POLICY UPDATES</td><td>DESCRIPTION</td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>AWS Secret Manager Automatic Key Rotation is not enabled</strong></td><td><p><strong>Changes—</strong> The policy description and RQL are updated. The policy RQL is updated to exclude the secrets managed by owning services.</p><p><strong>Updated Description—</strong> Identifies AWS Secret Manager that are not enabled with key rotation. As a security best practice, it is important to rotate the keys periodically so that if the keys are compromised, the data in the underlying service is still secure with the new keys.</p><p>This policy does not include secret manager which are managed by some of the AWS services that store AWS Secrets Manager secrets on your behalf.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-secretsmanager-describe-secret' AND json.rule = rotationEnabled is false
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-secretsmanager-describe-secret' AND json.rule = rotationEnabled is false and owningService is not member of (appflow, databrew, datasync, directconnect, events, opsworks-cm, rds, sqlworkbench)
</code></pre><p><strong>Impact—</strong> Low. Existing alerts are resolved as <strong>Policy_Updated</strong> for secrets managed by owning services such as appflow, databrew, datasync, directconnect, events, opsworks-cm, rds, and sqlworkbench.</p></td></tr><tr><td><strong>AWS Elastic Load Balancer v2 (ELBv2) with listener TLS/SSL is not configured</strong></td><td><p><strong>Changes—</strong> The policy RQL is updated to exclude the NLBs which are forwarding to ALB using TCP as a listener as per the AWS limitation.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = 'state.code contains active and ((listeners[*].protocol equals HTTPS or listeners[*].protocol equals TLS) and listeners[*].certificates[*].certificateArn does not exist) or listeners[*].protocol equals HTTP or listeners[*].protocol equals TCP or listeners[*].protocol equals UDP or listeners[*].protocol equals TCP_UDP'
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = state.code contains active and listeners[?any( protocol equals HTTP or protocol equals TCP or protocol equals UDP or protocol equals TCP_UDP )] exists as X; config from cloud.resource where api.name = 'aws-elbv2-target-group' AND json.rule = targetType does not equal alb and protocol exists and protocol is not member of ('TLS', 'HTTPS') as Y; filter '$.X.listeners[?any( protocol equals HTTP or protocol equals UDP or protocol equals TCP_UDP )] exists or ( $.X.listeners[*].protocol equals TCP and $.X.listeners[*].defaultActions[*].targetGroupArn contains $.Y.targetGroupArn)'; show X;
</code></pre><p><strong>Impact—</strong> Low. Alerts that are generated for NLBs which are using ALB as listener via TCP will be resolved as <strong>Policy_Updated</strong>.</p></td></tr><tr><td><strong>OCI Block Storage Block Volume does not have backup enabled</strong></td><td><p><strong>Changes—</strong> The policy description and RQL are updated. The RQL is updated to exclude the Block volumes which are attached to volume groups.</p><p><strong>Updated Description—</strong> Identifies the OCI Block Storage Volumes that do not have backup enabled. It is recommended to have block volume backup policies on each block volume so that the block volume can be restored during data loss events.</p><p>Note: This Policy is not applicable for block volumes that are added to volume groups.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'oci' AND api.name = 'oci-block-storage-volume' AND json.rule = volumeBackupPolicyAssignment[*] size equals 0
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'oci' AND api.name = 'oci-block-storage-volume' AND json.rule = volumeBackupPolicyAssignment[*] size equals 0 and volumeGroupId equal ignore case "null"
</code></pre><p><strong>Impact—</strong> Low. Alerts that are generated for block volumes added to volume groups will be resolved as <strong>Policy_Updated</strong>.</p></td></tr><tr><td><strong>Policy Updates—Metadata</strong></td><td></td></tr><tr><td><strong>AWS Route53 Hosted Zone having dangling DNS record with subdomain takeover risk</strong></td><td><p><strong>Changes—</strong> The policy name and description are updated to reflect the association of this risk with S3 Buckets, providing a more accurate representation of the associated service.</p><p><strong>Current Policy Name—</strong> AWS Route53 Hosted Zone having dangling DNS record with subdomain takeover risk</p><p><strong>Updated Policy Name—</strong> AWS Route53 Hosted Zone having dangling DNS record with subdomain takeover risk associated with AWS S3 Bucket</p><p><strong>Updated Description—</strong> Identifies AWS Route53 Hosted Zones which have dangling DNS records with subdomain takeover risk associated with AWS S3 Bucket. A Route53 Hosted Zone having a CNAME entry pointing to a non-existing S3 bucket will have a risk of these dangling domain entries being taken over by an attacker by creating a similar S3 bucket in any AWS account which the attacker owns / controls. Attackers can use this domain to do phishing attacks, spread malware and other illegal activities. As a best practice, it is recommended to delete dangling DNS records entry from your AWS Route 53 hosted zones.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><p><strong>Impact—</strong> None.</p></td></tr></tbody></table>

## IAM Policy Updates

Prisma Cloud has updated the following AWS IAM out-of-the-box (OOTB) policies as follows:

<table data-header-hidden><thead><tr><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td>POLICY NAME</td><td>CURRENT RQL</td><td>UPDATED RQL</td><td>CURRENT SEVERITY</td><td>UPDATED SEVERITY</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; CloudFormation stack permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( ‘iam:PassRole', 'cloudformation:CreateStack', 'cloudformation:DescribeStacks') AND dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'cloudformation:CreateStack', 'cloudformation:DescribeStacks') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Lambda create Function &#x26; Event source mapping permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:CreateEventSourceMapping', 'lambda:CreateFunction') AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:CreateEventSourceMapping', 'lambda:CreateFunction') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>Medium AWS IAM policy allows Privilege escalation via PassRole &#x26; SageMaker create training job permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'sagemaker:CreateTrainingJob' ) AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'sagemaker:CreateTrainingJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; CodeStar project permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'codestar:CreateProject' ) AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'codestar:CreateProject' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Lambda create Function &#x26; add permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:AddPermission', 'lambda:CreateFunction') AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:AddPermission', 'lambda:CreateFunction') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; CodeBuild permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'codebuild:CreateProject', 'codebuild:StartBuild', 'codebuild:StartBuildBatch') AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'codebuild:CreateProject', 'codebuild:StartBuild', 'codebuild:StartBuildBatch') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; SageMaker create notebook permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'sagemaker:CreateNotebookInstance', 'sagemaker:CreatePresignedNotebookInstanceUrl' ) AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'sagemaker:CreateNotebookInstance', 'sagemaker:CreatePresignedNotebookInstanceUrl' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; SageMaker create processing job permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'sagemaker:CreateProcessingJob' ) AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'sagemaker:CreateProcessingJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via EC2 Instance Connect permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'ec2:DescribeInstances', 'ec2-instance-connect:SendSSHPublicKey', 'ec2-instance-connect:SendSerialConsoleSSHPublicKey' ) AND  dest.cloud.resource.name ENDS WITH '*’
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'ec2:DescribeInstances', 'ec2-instance-connect:SendSSHPublicKey', 'ec2-instance-connect:SendSerialConsoleSSHPublicKey' ) AND dest.cloud.wildcardscope = true
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; EC2 permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'ec2:RunInstances' ) AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'ec2:RunInstances' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Data Pipeline permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'datapipeline:ActivatePipeline', 'datapipeline:CreatePipeline', 'datapipeline:PutPipelineDefinition') AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'datapipeline:ActivatePipeline', 'datapipeline:CreatePipeline', 'datapipeline:PutPipelineDefinition') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Glue development endpoint permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:CreateDevEndpoint', 'glue:GetDevEndpoint') AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:CreateDevEndpoint', 'glue:GetDevEndpoint') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Glue create job permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:CreateJob' ) AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:CreateJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Glue update job permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:UpdateJob' ) AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'glue:UpdateJob' ) AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via Glue Dev Endpoint permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'glue:UpdateDevEndpoint', 'glue:GetDevEndpoint' ) AND  dest.cloud.resource.name ENDS WITH '*’
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'glue:UpdateDevEndpoint', 'glue:GetDevEndpoint' ) AND dest.cloud.wildcardscope = true
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via Codestar create project and associate team member permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'codestar:CreateProject', 'codestar:AssociateTeamMember' ) AND  dest.cloud.resource.name ENDS WITH '*’
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'codestar:CreateProject', 'codestar:AssociateTeamMember' ) AND dest.cloud.wildcardscope = true
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via EC2 describe and SSM list and send command permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'ec2:DescribeInstances', 'ssm:listCommands', 'ssm:listCommandInvocations', 'ssm:sendCommand') AND  dest.cloud.resource.name ENDS WITH '*’
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'ec2:DescribeInstances', 'ssm:listCommands', 'ssm:listCommandInvocations', 'ssm:sendCommand') AND dest.cloud.wildcardscope = true
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via EC2 describe and SSM session permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'ec2:DescribeInstances', 'ssm:StartSession', 'ssm:DescribeSessions', 'ssm:GetConnectionStatus', 'ssm:DescribeInstanceProperties', 'ssm:TerminateSession', 'ssm:ResumeSession' ) AND  dest.cloud.resource.name ENDS WITH '*’
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'ec2:DescribeInstances', 'ssm:StartSession', 'ssm:DescribeSessions', 'ssm:GetConnectionStatus', 'ssm:DescribeInstanceProperties', 'ssm:TerminateSession', 'ssm:ResumeSession' ) AND dest.cloud.wildcardscope = true
</code></pre></td><td>High</td><td>Medium</td></tr><tr><td><strong>AWS IAM policy allows Privilege escalation via PassRole &#x26; Lambda create &#x26; invoke Function permissions</strong></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:InvokeFunction', 'lambda:CreateFunction') AND  dest.cloud.resource.name ENDS WITH '*’ and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td><pre><code>config from iam where action.name CONTAINS ALL ( 'iam:PassRole', 'lambda:InvokeFunction', 'lambda:CreateFunction') AND dest.cloud.wildcardscope = true and grantedby.cloud.policy.condition ('iam:PassedToService') does not exist
</code></pre></td><td>High</td><td>Medium</td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| COMPLIANCE BENCHMARK      | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| ------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **MLPS Level 3 Controls** | <p>Prisma Cloud now supports Multi-Level Protection Scheme (MLPS) Level 3 controls. Access control, data encryption, network segmentation, intrusion detection, and incident response are among the security measures outlined in the MLPS framework. Based on the MLPS classifications, you can assess the security risks associated with your information systems and implement the appropriate controls.</p><p>You can review this compliance standard and its associated policies on the <strong>Compliance > Standard</strong> page.</p> |

## Changes in Existing Behavior

No changes in existing behavior for 23.7.2.

## REST API Updates

| CHANGE                               | DESCRIPTION                                                                                                                                                                                                                                                             |
| ------------------------------------ | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **New API to Get Resource Snapshot** | <p>The following new endpoint is added to get the latest resource snapshot by using the Restricted Resource Name(rrn).</p><ul><li>Get Resource Snapshot - <a href="https://pan.dev/prisma-cloud/api/cspm/get-resource-snapshot/">GET /das/api/v1/resource</a></li></ul> |

## New Features Introduced in 23.7.1

* [New Features](#new-features1)
* [API Ingestions](#api-ingestions1)
* [New Policies](#new-policies1)
* [Policy Updates](#policy-updates1)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates1)
* [Changes in Existing Behavior](#changes-in-existing-behavior1)
* [REST API Updates](#rest-api-updates1)

## New Features

| FEATURE                                                                                            | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                     |
| -------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Support for New Regions on AWS**                                                                 | <p>Prisma Cloud now ingests data for resources deployed in the Zurich and Melbourne regions on AWS.</p><p>To review a list of supported regions, select "Inventory > Assets", and choose <a href="https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/connect-your-cloud-platform-to-prisma-cloud/cloud-service-provider-regions-on-prisma-cloud#id091e5e1f-e6d4-42a8-b2ff-85840eb23396_id9c4f8473-140d-4e4a-94a1-523e00ebfbe4">Cloud Region</a> from the filter drop-down.</p><p><img src="/files/t2uGO13EzB0gMV3kWA1n" alt="" data-size="original"></p>                                                                                                                                                                                  |
| <mark style="background-color:orange;">Prisma Cloud Data Security</mark> **Support for Singapore** | Prisma Cloud Data Security is now available on the **app.sg** stack for all Prisma Cloud customers in Singapore. The data scans and data will remain within Singapore.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| **Least Privilege Access Enforcement**                                                             | Streamline access management and promote secure and efficient permissions configuration with the [least privilege access](https://docs.paloaltonetworks.com/prisma/prisma-cloud/prisma-cloud-admin/prisma-cloud-iam-security/cloud-identity-inventory) suggestions. Solve for over-privileged access issues that arise when you manage Identity Access through Groups or/and Roles rather than individual identities. You can now remediate over-permissive permissions effectively at the Group/Role level by creating new policies containing only the permissions applicable to all members. Alternatively, you can leverage existing policies by retaining only the permissions applicable to the entire Group/Role and removing any excessive permissions. |

## API Ingestions

| SERVICE                                                                       | API DETAILS                                                                                                                                                                                                                                                                                                           |
| ----------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **AWS CloudHSM**                                                              | <p><strong>aws-cloudhsm-cluster</strong></p><p>Additional permission required:</p><ul><li><code>cloudhsm:DescribeClusters</code></li></ul><p>You must manually add the permission or update the CFT template to enable it.</p>                                                                                        |
| **Amazon VPC**                                                                | <p><strong>aws-ec2-vpc-endpoint-service-permission</strong></p><p>Additional permission required:</p><ul><li><code>ec2:DescribeVpcEndpointServicePermissions</code></li></ul><p>The Security Audit role includes the permission.</p>                                                                                  |
| **Google Cloud Translation**                                                  | <p><strong>gcloud-translation-glossary</strong></p><p>Additional permissions required:</p><ul><li><code>cloudtranslate.locations.list</code></li><li><code>cloudtranslate.glossaries.list</code></li></ul><p>The Viewer role includes the permissions.</p>                                                            |
| **OCI Compute**                                                               | <p><strong>oci-compute-image</strong></p><p>Additional permissions required:</p><ul><li><code>INSTANCE\_IMAGE\_INSPECT</code></li><li><code>INSTANCE\_IMAGE\_READ</code></li></ul><p>You must update the Terraform template to enable the permissions.</p>                                                            |
| <mark style="background-color:orange;">Update</mark> **OCI Compute Instance** | <p><strong>oci-compute-instance</strong></p><p>The resource JSON for this API has been updated to include a new field <strong>vnicIds</strong>.</p><p>Additional permission required:</p><ul><li><code>VNIC\_ATTACHMENT\_READ</code></li></ul><p>You must update the Terraform template to enable the permission.</p> |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>NEW POLICIES</td><td>DESCRIPTION</td></tr><tr><td><strong>Azure SQL on Virtual Machine (Linux) with basic authentication</strong></td><td><p>Identifies Azure Virtual Machines that are hosted with SQL on them and have basic authentication.</p><p>Azure Virtual Machines with basic authentication could allow attackers to brute force and gain access to SQL database hosted on it, which might lead to sensitive information leakage. It is recommended to use SSH keys for authentication to avoid brute force attacks on SQL database hosted virtual machines.</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-vm-list' AND json.rule = powerState equal ignore case "PowerState/running" and ['properties.storageProfile'].['imageReference'].['publisher'] equal ignore case microsoftsqlserver and (['properties.osProfile'].['linuxConfiguration'] exists and ['properties.osProfile'].['linuxConfiguration'].['disablePasswordAuthentication'] is false)
</code></pre><p><strong>Policy Type—</strong> Config</p><p><strong>Severity—</strong> Low</p></td></tr><tr><td><strong>AWS Route53 Hosted Zone having dangling DNS record with subdomain takeover risk</strong></td><td><p>Identifies AWS Route53 Hosted Zones which have dangling DNS records with subdomain takeover risk. A Route53 Hosted Zone having a CNAME entry pointing to a non-existing S3 bucket will have a risk of these dangling domain entries being taken over by an attacker by creating a similar S3 bucket in any AWS account which the attacker owns / controls. Attackers can use this domain to do phishing attacks, spread malware and other illegal activities. As a best practice, it is recommended to delete dangling DNS records entry from your AWS Route 53 hosted zones.</p><pre><code>config from cloud.resource where api.name = 'aws-route53-list-hosted-zones' AND json.rule = hostedZone.config.privateZone is false and resourceRecordSet[?any( type equals CNAME and resourceRecords[*].value contains s3-website )] exists as X; config from cloud.resource where api.name = 'aws-s3api-get-bucket-acl' as Y; filter 'not ($.X.resourceRecordSet[*].name intersects $.Y.bucketName)'; show X;
</code></pre><p><strong>Policy Type—</strong> Config</p><p><strong>Severity—</strong> High</p></td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td>POLICY UPDATES</td><td>DESCRIPTION</td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><strong>AWS Application Load Balancer (ALB) is not using the latest predefined security policy</strong></td><td><p><strong>Changes—</strong> The policy description and recommendation steps have been updated. The policy RQL has been updated to check for the latest security policy <code>ELBSecurityPolicy-TLS13-1-2-2021-06</code></p><p><strong>Updated Description—</strong> Identifies Application Load Balancers (ALBs) are not using the latest predefined security policy. A security policy is a combination of protocols and ciphers. The protocol establishes a secure connection between a client and a server and ensures that all data passed between the client and your load balancer is private. A cipher is an encryption algorithm that uses encryption keys to create a coded message. So it is recommended to use the latest predefined security policy which uses only secured protocol and ciphers.</p><p>We recommend using ELBSecurityPolicy-TLS13-1-2-2021-06 policy to meet compliance and security standards that require disabling certain TLS protocol versions or to support legacy clients that require deprecated ciphers.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and listeners[?any(protocol equals HTTPS and sslPolicy exists and (sslPolicy does not contain ELBSecurityPolicy-FS-1-2-Res-2020-10 and sslPolicy does not contain ELBSecurityPolicy-TLS-1-2-Ext-2018-06))] exists
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-elbv2-describe-load-balancers' AND json.rule = type equals application and listeners[?any(protocol equals HTTPS and sslPolicy exists and (sslPolicy does not contain ELBSecurityPolicy-TLS13-1-2-2021-06))] exists
</code></pre><p><strong>Impact—</strong> Medium. New alerts will be generated in case ALB is not configured to use the latest security policy. Existing alerts for resources that are already using the latest security policy are resolved as <strong>Policy_updated</strong>.</p></td></tr><tr><td><strong>AWS EC2 instance that is reachable from untrust internet source to ports with high risk</strong></td><td><p><strong>Changes—</strong> Policy RQL is updated to check and report EC2 instance which are in active state.</p><p><strong>Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from network where source.network = UNTRUST_INTERNET and dest.resource.type = 'Instance' and dest.cloud.type = 'AWS' and protocol.ports in ( 'tcp/20:21', 'tcp/23', 'tcp/25', 'tcp/110', 'tcp/135', 'tcp/143', 'tcp/445', 'tcp/1433:1434', 'tcp/3000', 'tcp/3306', 'tcp/4333', 'tcp/5000', 'tcp/5432', 'tcp/5500', 'tcp/5601', 'tcp/8080', 'tcp/8088', 'tcp/8888', 'tcp/9200', 'tcp/9300' )
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from network where source.network = UNTRUST_INTERNET and dest.resource.type = 'Instance' and dest.cloud.type = 'AWS' and dest.resource.state = 'Active' and protocol.ports in ( 'tcp/20:21', 'tcp/23', 'tcp/25', 'tcp/110', 'tcp/135', 'tcp/143', 'tcp/445', 'tcp/1433:1434', 'tcp/3000', 'tcp/3306', 'tcp/4333', 'tcp/5000', 'tcp/5432', 'tcp/5500', 'tcp/5601', 'tcp/8080', 'tcp/8088', 'tcp/8888', 'tcp/9200', 'tcp/9300' )
</code></pre><p><strong>Impact—</strong> Low. Alerts will be resolved for EC2 instances which are in inactive state.</p></td></tr><tr><td><strong>Azure SQL Server ADS Vulnerability Assessment is disabled</strong></td><td><p><strong>Changes—</strong> The policy description and recommendation steps have been updated. The policy RQL has been updated according to new express configuration to check if ADS vulnerability assessment is disabled.</p><p><strong>Updated Decsription—</strong> Identifies Azure SQL Server which has ADS Vulnerability Assessment setting disabled. Advanced Data Security - Vulnerability Assessment service scans SQL databases for known security vulnerabilities and highlight deviations from best practices, such as misconfigurations, excessive permissions, and unprotected sensitive data. It is recommended to enable ADS - VA service.</p><p><strong>Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-sql-server-list' AND json.rule = vulnerabilityAssessments[*].properties.storageContainerPath does not exist
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-sql-server-list' AND json.rule = vulnerabilityAssessments[*].type does not exist
</code></pre><p><strong>Impact—</strong> Medium. New alerts will be generated if vulnerability assessment is disabled. Existing alerts will be resolved are resolved as <strong>Policy_updated</strong> when <code>vulnerabilityAssessments[*\].properties.storageContainerPath</code> does not exist.</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| COMPLIANCE BENCHMARK                             | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Otoritas Jasa Keuangan (OJK) 38/POJK.03/2016** | <p>Prisma Cloud now supports Otoritas Jasa Keuangan (OJK) 38/POJK.03/20 regulations. The regulation provides specific guidance on the contents of the outsourcing agreement, due diligence, monitoring performance, contingency planning, audit, and information access rights.</p><p>You can review this compliance standard and its associated policies on Prisma Cloud’s <strong>Compliance > Standard</strong> page.</p> |

## Changes in Existing Behavior

| FEATURE                                                                                                                                                                                                      | DESCRIPTION                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Access to Alerts for Deleted Assets</strong></p><p><mark style="background-color:orange;">This change was first announced in the Look Ahead that was published with the 23.5.2 release</mark></p> | <p>The ability to view resolved alerts for assets that have been deleted in cloud accounts onboarded to Prisma Cloud will be available for up to 90 days after asset deletion. After 90 days, these alerts will be permanently deleted from Prisma Cloud.</p><p>This change will be in effect starting July 1, 2023. Before July 1, if you want to export all resolved alerts older than 90 days for assets that have been deleted on the cloud account, use this API endpoint <a href="https://pan.dev/prisma-cloud/api/cspm/get-alerts-v-2/"><https://pan.dev/prisma-cloud/api/cspm/get-alerts-v-2/></a> .</p> |

## REST API Updates

No REST API updates for 23.7.1.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/classic-releases/prisma-cloud-cspm-release-information/features-introduced-in-july-2023.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
