Features Introduced in November 2023
Learn what’s new on Prisma® Cloud in November 2023.
New Features Introduced in November 2023
Announcement
FEATURE
DESCRIPTION
Prisma Cloud Darwin Release
The Prisma Cloud Darwin Release is here for Prisma Cloud environments on app.ind, app.ca, app.uk, and app.fr except app.gov. With the Code to Cloud™ intelligence capabilities in this release, your security and development teams can work together to reduce application risks and prevent breaches.
With this change, your tenant will be updated with the new intuitive user interface and rich set of security capabilities.
Connect with your Customer Success team for more details.
When you are upgraded to the Darwin release, refer to the Enterprise Edition documentation.
New Features
New Attack Path policies are available. Log in to the Prisma Cloud console and filter for the list of available policies.
API Ingestions
SERVICE
API DETAILS
Amazon EC2
23.11.1
aws-ec2-launch-template-data
Additional permissions required:
ec2:GetLaunchTemplateDataec2:DescribeInstances
The Security Audit role only includes the ec2:DescribeInstances permission. You must manually add the ec2:GetLaunchTemplateData permission to the CFT template to enable the permission.
AWS Audit Manager
23.11.1
aws-audit-manager-assessment
Additional permissions required:
auditmanager:ListAssessmentsauditmanager:GetAssessment
The Security Audit role only includes the auditmanager:ListAssessments permission. You must manually add the auditmanager:GetAssessment permission to the CFT template to enable the permission.
AWS Audit Manager
23.11.1
aws-audit-manager-control
Additional permissions required:
auditmanager:ListControlsauditmanager:GetControl
The Security Audit role only includes the auditmanager:ListControls permission. You must manually add the auditmanager:GetControl permission to the CFT template to enable the permission.
AWS Application Migration Service
23.11.1
aws-mgn-launch-configuration-template
Additional permission required:
mgn:DescribeLaunchConfigurationTemplates
You must manually add the mgn:DescribeLaunchConfigurationTemplates permission to the CFT template to enable the permission.
Update Azure Key Vault
23.11.1
azure-key-vault-list
This API has been updated to support Key rotation data. The resource JSON for this API has been updated to include the keys[*].keyRotationPolicy field.
Azure Synapse Analytics
23.11.1
azure-synapse-workspace-managed-sql-server-blob-auditing-policies
Additional permissions required:
Microsoft.Synapse/workspaces/readMicrosoft.Synapse/workspaces/auditingSettings/read
The Reader role includes the permissions.
Azure Synapse Analytics
23.11.1
azure-synapse-workspace-ip-firewall-rules
Additional permissions required:
Microsoft.Synapse/workspaces/readMicrosoft.Synapse/workspaces/firewallRules/read
The Reader role includes the permissions.
Google AlloyDB for PostgreSQL
23.11.1
gcloud-alloydb-cluster
Additional permissions required:
alloydb.locations.listalloydb.clusters.list
The Viewer role includes the permissions.
Google AlloyDB for PostgreSQL
23.11.1
gcloud-alloydb-cluster-user
Additional permissions required:
alloydb.locations.listalloydb.clusters.listalloydb.users.list
The Viewer role includes the permissions.
Google AlloyDB for PostgreSQL
23.11.1
gcloud-alloydb-cluster-instance
Additional permissions required:
alloydb.locations.listalloydb.clusters.listalloydb.instances.list
The Viewer role includes the permissions.
Google AlloyDB for PostgreSQL
23.11.1
gcloud-alloydb-backup
Additional permissions required:
alloydb.locations.listalloydb.backups.list
The Viewer role includes the permissions.
OCI Cloud Guard
23.11.1
oci-cloudguard-configuration
Additional permissions required:
CG_CONFIG_INSPECTCG_CONFIG_READ
You must update the Terraform template to enable the permissions.
New Policies
NEW POLICIES
DESCRIPTION
AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443
23.11.1
Identifies AWS EC2 instances that are internet reachable with unrestricted access (0.0.0.0/0) to HTTP/HTTPS ports (80 / 443). EC2 instances with unrestricted access to the internet for HTTP/HTTPS ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.
Policy Type— Network Configuration
Policy Severity— Informational
Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443
23.11.1
Identifies Azure Virtual Machines that are internet reachable with unrestricted access (0.0.0.0/0) to HTTP/HTTPS ports (80 / 443). Azure Virtual Machines with unrestricted access to the internet for HTTP/HTTPS ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.
Policy Type— Network Configuration
Policy Severity— Informational
Azure Virtual Machine (Linux) does not authenticate using SSH keys
23.11.1
Identifies Azure Virtual Machines that have basic authentication, not authenticating using SSH keys. Azure Virtual Machines with basic authentication could allow attackers to brute force and gain unauthorized access, which might lead to potential data leaks. It is recommended to use SSH keys for authentication to avoid brute force attacks on virtual machines.
Policy Type— Config
Policy Severity— Low
GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) on ports 80/443
23.11.1
Identifies GCP VM instances that are internet reachable with unrestricted access (0.0.0.0/0) to HTTP/HTTPS ports (80 / 443). GCP VM instances with unrestricted access to the internet for HTTP/HTTPS ports may enable bad actors to use brute force on a system to gain unauthorized access to the entire network. As a best practice, restrict traffic from unknown IP addresses and limit access to known hosts, services, or specific entities.
Policy Type— Network Configuration
Policy Severity— Informational
Policy Updates
POLICY UPDATES
DESCRIPTION
Policy Updates—RQL
Azure Application Gateway is configured with SSL policy having TLS version 1.1 or lower
23.11.1
Changes— The RQL willl be updated to not report Application gateways with default policy created using API versions 2023-02-01 or higher as the minimum protocol version is set to 1.2.
Current RQL—
Updated RQL—
Severity— Low
Policy Type— Config
Impact— Low. Existing alerts where the application gateways were created with default policy using API versions 2023-02-01 or higher will be resolved as Policy_Updated.
New Compliance Benchmarks and Updates
COMPLIANCE BENCHMARK
DESCRIPTION
Support for CMMC v2 Level 2 standard
23.11.1
Prisma Cloud now supports the Cybersecurity Maturity Model Certification (CMMC) v2 Level 2 compliance standard. This framework includes cybersecurity practices, standards, and processes published by the Department of Defense (DoD) as part of the CMMC program, which aims to protect national security by standardizing how Defense contractors and subcontractors handle Federal Contract Information (FCI) and Controlled Unclassified Information (CUI).
You can now view this built-in standard and the associated policies on the Compliance > Standards page with this support. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.
Changes in Existing Behavior
FEATURE
DESCRIPTION
Checkov CLI upgrade
Secure the Source
23.11.1
The Checkov CLI has been upgraded to Checkov 3.0. The upgrade impacts a few known changes:
Level Up: This capability has been removed. This change is non-disruptive and affects only Bridgecrew standalone sign ups.
Multi-Signatures: Multi-signatures in Python checks are being removed. This will only impact custom Python policies using this method.
Deprecating flags for Suppression and Fix: CLI command of
--skip-fixesand--skip-suppressionsare being deprecated. Instead--skip-downloadis a recommended command.API Key Restriction and Repo-ID Parameter: Scans with API keys will now require the --repo-id parameter for repository scans allowing for easier platform mapping.
Enhanced Argument Handling: The way to specify frameworks and skip frameworks will align to other flags where multiple values can be listed (like --check). For example:
--framework terraform,arm..Pyston Docker Build Deprecation: The Pyston Docker build has been depreciated due to increasing complexities in support. The regular Checkov image will still be available for use.
REST API Updates
CHANGE
DESCRIPTION
New SSO APIs
23.11.1
The following new endpoints are available for configuring SAML:
Get SAML Configuration - GET /authn/v1/saml/config
Update SAML Configuration - PUT /authn/v1/saml/config
Create SAML Configuration - POST /authn/v1/saml/config
New Cloud Account API
23.11.1
The following new endpoint is available to enable or disable a feature for a set of members of an organization:
Enable a Feature for Members - PUT /cas/api/v1/org/{id}/features
New Alerts APIs
23.11.1
The following new endpoints are available for the Alerts API:
Get Alert Count of Policies - POST /alert/v1/policy
Get Alert Count by Policy Groups - POST /alert/v1/aggregate
Get Alert Evidence Graph - GET /alert/v1/{id}/graph
Updates to Alerts API
23.11.1
The List Alert Remediation Commands API and Remediate Alert API will have an additional optional parameter, findingId. This parameter is used to remediate the findings of an attack path alert.
Last updated
Was this helpful?

