For the complete documentation index, see llms.txt. This page is also available as Markdown.

Features Introduced in April 2024

Learn what’s new on Prisma® Cloud in April 2024.

New Features

Feature

Description

Integration Support for Cortex XSOAR Version 8.0

Secure the Infrastructure

24.4.2

The Cortex XSOAR integration is enhanced to support both XSOAR versions 6.0 and 8.0. As a result, you will now see the Versions Available option on the Prisma Cloud Console. This option allows you to select between XSOAR versions 6.0 or 8.0 when you create or update the integration on Prisma Cloud.

Share Views with Ease

Secure the Infrastructure

24.4.2

Accelerate team collaboration and communication with Prisma Cloud®'s shareable Dashboards and Saved Views. Enhancements to Prisma Cloud provide a seamless way to share custom dashboards and saved views with other users in your tenant and/or organization. You can now configure the access level of any dashboard or saved view that you have created to make it Public and viewable by any user within your tenant. Review and/or change the access level or visibility status of any Dashboard/Saved View at any time, from the Manage Dashboards/Saved Views page.

Prisma Cloud Service in Indonesia

Secure the Infrastructure

24.4.2

Prisma Cloud tenant (app.id.prismacloud.io) is now available for the Jakarta region.

Identity Access RQL Attributes Added

Secure the Infrastructure

24.4.2

Enhancements to the Permission Query RQL allow you to easily and comprehensively understand the access provided to identities in your cloud environment, without the need for investigating individual actions. Use the action.access.level and action.access.isAdministrative RQL query attributes to track over privileged access in your AWS, Azure, and GCP environments.

Alerts by Status Widget

Secure the Infrastructure

24.4.1

The Dashboards page now includes the Alerts by Status widget. Leverage this widget to enhance your alerts investigations by filtering on alert status (Resolved, Open or Dismissed) and time range.

Update Compliance Trend Widget

Secure the Infrastructure

24.4.1

The Compliance Trend widget now supports filtering data by the following time durations:

  • 24 hours

  • 1 week

  • 1 month

  • 3 months

  • 6 months

  • 1 year

  • Year to Date

  • Custom

Note: When you select the Custom option under Time Range, the widget only uses the Start Date and disregards the hourly timestamp. The End Date is always set to the current date, regardless of your selection.

Update IAM Permission Query Results

Secure the Infrastructure

24.4.1

Enhancements to IAM permission queries in Prisma Cloud now allow you to obtain narrowly focused results by refining your search. Choose the fields relevant to your investigation to customize and define your permission query results.

Azure IAM Identity Inventory

Secure the Infrastructure

24.4.1

Gain greater visibility into Azure roles, groups, service principals and managed identities with Azure IAM Identity Inventory. Enforce least privileged access best practices by routinely removing unused privileges and permissions within your Azure roles and entitlements. Select Suggest Least Privilege Access to modify existing permissions and generate a new policy in JSON, and Terraform format, that includes only the permissions required based on actual usage.

API Ingestions

Service

API Details

Update AWS Application Auto Scaling

24.4.2

aws-application-autoscaling-scaling-policy

The AWS Application Auto Scaling API now includes an additional field called ResourceName.

Update Amazon API Gateway

24.4.2

aws-apigateway-method

The aws-apigateway-method API has been updated to exclude to exclude the methodIntegration.cacheNamespace field from the JSON because it changes frequently causing too many resource snapshots.

Amazon Detective

24.4.2

aws-detective-datasource-package

Additional permissions required:

  • detective:ListGraphs

  • detective:ListDatasourcePackages

The Security Audit role includes the detective:ListGraphs permission. You must manually add the detective:ListDatasourcePackages permission to the CFT template to enable it.

Amazon Polly

24.4.2

aws-polly-speech-synthesis-task

Additional permission required:

  • polly:ListSpeechSynthesisTasks

You must manually add the permission to the CFT template to enable it.

Amazon SES

24.4.2

aws-ses-configuration-set

Additional permissions required:

  • ses:ListConfigurationSets

  • ses:DescribeConfigurationSet

The Security Audit role includes the permissions.

AWS Batch

24.4.2

aws-batch-job-queue

Additional permission required:

  • batch:DescribeJobQueues

You must manually add the permission to the CFT template to enable it.

Azure CDN

24.4.2

azure-frontdoor-standardpremium-routes

Additional permissions required:

  • Microsoft.Cdn/profiles/read

  • Microsoft.Cdn/profiles/afdendpoints/read

  • Microsoft.Cdn/profiles/afdendpoints/routes/read

The Reader role includes the permissions.

Azure CDN

24.4.2

azure-frontdoor-standardpremium-afd-custom-domains

Additional permissions required:

  • Microsoft.Cdn/profiles/read

  • Microsoft.Cdn/profiles/customdomains/read

The Reader role includes the permissions.

Azure SQL Database

24.4.2

azure-sql-managed-instance-vulnerability-assessments

Additional permissions required:

  • Microsoft.Sql/managedInstances/read

  • Microsoft.Sql/managedInstances/vulnerabilityAssessments/Read

The Reader role includes the permissions.

Azure SQL Database

24.4.2

azure-sql-managed-instance-encryption-protectors

Additional permissions required:

  • Microsoft.Sql/managedInstances/read

  • Microsoft.Sql/managedInstances/encryptionProtector/Read

The Reader role includes the permissions.

Azure Synapse Analytics

24.4.2

azure-synapse-workspace-sql-pools

Additional permissions required:

  • Microsoft.Synapse/workspaces/read

  • Microsoft.Synapse/workspaces/sqlPools/read

The Reader role includes the permissions.

Google Traffic Director

24.4.2

gcloud-traffic-director-secure-web-proxy-url-list

Additional permission required:

  • networksecurity.urlLists.list

The Viewer role includes the permission.

Google Vertex AI AIPlatform

24.4.2

gcloud-vertex-ai-aiplatform-notebook-runtime-template

Additional permissions required:

  • aiplatform.notebookRuntimeTemplates.list

  • aiplatform.notebookRuntimeTemplates.getIamPolicy

The Viewer role includes the permissions.

Google Vertex AI AIPlatform

24.4.2

gcloud-vertex-ai-aiplatform-notebook-runtime

Additional permission required:

  • aiplatform.notebookRuntimes.list

The Viewer role includes the permission.

Google Traffic Director

24.4.2

gcloud-traffic-director-gateway-security-policy

Additional permission required:

  • networksecurity.gatewaySecurityPolicies.list

The Viewer role includes the permission.

Google Traffic Director

24.4.2

gcloud-traffic-director-gateway-security-policy-rule

Additional permissions required:

  • networksecurity.gatewaySecurityPolicies.list

  • networksecurity.gatewaySecurityPolicyRules.list

The Viewer role includes the permissions.

Amazon Cognito

24.4.1

aws-cognito-sync-pool-usage

Additional permission required:

  • cognito-sync:ListIdentityPoolUsage

The Security Audit role includes the permission.

Amazon Comprehend

24.4.1

aws-comprehend-entities-detection-jobs

Additional permission required:

  • comprehend:ListEntitiesDetectionJobs

The Security Audit role includes the permission.

Amazon Comprehend

24.4.1

aws-comprehend-document-classifier-summary

Additional permission required:

  • comprehend:ListDocumentClassifierSummaries

The Security Audit role includes the permission.

Amazon Comprehend

24.4.1

aws-comprehend-document-classifier

Additional permission required:

  • comprehend:ListDocumentClassifiers

The Security Audit role includes the permission.

Amazon Device Farm Projects

24.4.1

aws-device-farm-projects

Additional permission required:

  • devicefarm:ListProjects

The Security Audit role includes the permission.

Update Amazon DynamoDB

24.4.1

aws-dynamodb-describe-table

Additional permission required:

  • dynamodb:DescribeContinuousBackups

The Security Audit role includes the permission.

The aws-dynamodb-describe-table API is also updated to include ContinuousBackupsDescription field in the resource JSON.

Amazon Elastic Transcoder Pipelines

24.4.1

aws-elastic-transcoder-pipelines

Additional permission required:

  • elastictranscoder:ListPipelines

The Security Audit role includes the permission.

Amazon ElasticBeanstalk Applications

24.4.1

aws-elasticbeanstalk-applications

Additional permission required:

  • elasticbeanstalk:DescribeApplications

The Security Audit role includes the permission.

Amazon GuardDuty

24.4.1

aws-guardduty-organization-configuration

Additional permissions required:

  • guardduty:ListDetectors

  • guardduty:DescribeOrganizationConfiguration

The Security Audit role includes the guardduty:ListDetectors permission. You must manually add the guardduty:DescribeOrganizationConfiguration permission to the CFT template to enable it.

Amazon IoT Analytics Datastores

24.4.1

aws-iot-analytics-datastores

Additional permission required:

  • iotanalytics:ListDatastores

The Security Audit role includes the permission.

Amazon IoT Events Inputs

24.4.1

aws-iot-events-inputs

Additional permission required:

  • iotevents:ListInputs

The Security Audit role includes the permission.

Amazon Lookout for Vision Projects

24.4.1

aws-lookoutvision-projects

Additional permission required:

  • lookoutvision:ListProjects

The Security Audit role includes the permission.

Amazon LookoutEquipment Datasets

24.4.1

aws-lookoutequipment-datasets

Additional permission required:

  • lookoutequipment:ListDatasets

The Security Audit role includes the permission.

Amazon Servicecatalog Portfolios

24.4.1

aws-servicecatalog-portfolios

Additional permission required:

  • servicecatalog:ListPortfolios

The Security Audit role includes the permission.

Amazon SWF Domains

24.4.1

aws-swf-domains

Additional permission required:

  • swf:ListDomains

The Security Audit role includes the permission.

AWS ComprehendMedical Entities Detection V2 Jobs

24.4.1

aws-comprehendmedical-entities-detection-v2-jobs

Additional permission required:

  • comprehendmedical:ListEntitiesDetectionV2Jobs

The Security Audit role includes the permission.

AWS Greengrass Core Definitions

24.4.1

aws-greengrass-core-definitions

Additional permission required:

  • greengrass:ListCoreDefinitions

The Security Audit role includes the permission.

AWS Greengrass Groups

24.4.1

aws-greengrass-groups

Additional permission required:

  • greengrass:ListGroups

The Security Audit role includes the permission.

AWS IoTFleetWise Signal Catalogs

24.4.1

aws-iotfleetwise-signal-catalogs

Additional permission required:

  • iotfleetwise:ListSignalCatalogs

The Security Audit role includes the permission.

AWS LookoutMetrics Anomaly Detectors

24.4.1

aws-lookoutmetrics-anomaly-detectors

Additional permission required:

  • lookoutmetrics:ListAnomalyDetectors

The Security Audit role includes the permission.

AWS Managed Blockchain Networks List

24.4.1

aws-managed-blockchain-networks

Additional permission required:

  • managedblockchain:ListNetworks

The Security Audit role includes the permission.

AWS OpsWorks Describe User Profiles

24.4.1

aws-opsworks-user-profiles

Additional permission required:

  • opsworks:DescribeUserProfiles

The Security Audit role includes the permission.

AWS Polly Voices

24.4.1

aws-polly-voices

Additional permission required:

  • polly:DescribeVoices

The Security Audit role includes the permission.

AWS Resilience Hub

24.4.1

aws-resiliencehub-apps

Additional permission required:

  • resiliencehub:ListApps

The Security Audit role includes the permission.

AWS SecurityHub Describe Standards

24.4.1

aws-securityhub-standards

Additional permission required:

  • securityhub:DescribeStandards

The Security Audit role includes the permission.

AWS Service Discovery Namespaces

24.4.1

aws-servicediscovery-namespaces

Additional permission required:

  • servicediscovery:ListNamespaces

The Security Audit role includes the permission.

Azure Active Directory

24.4.1

azure-active-directory-directoryrole-definition

Additional permissions required:

  • EntitlementManagement.Read.All

  • RoleManagement.Read.All

The Global Reader role includes the permissions.

Azure Active Directory

24.4.1

azure-active-directory-directoryrole-assignment

Additional permissions required:

  • EntitlementManagement.Read.All

  • RoleManagement.Read.All

The Global Reader role includes the permissions.

Azure App Service

24.4.1

azure-app-service-web-apps-configurations

Additional permissions required:

  • Microsoft.Web/sites/Read

  • Microsoft.Web/sites/config/Read

The Reader role includes the permissions.

Azure Data Factory

24.4.1

azure-data-factory-v2-linked-services

Additional permissions required:

  • Microsoft.DataFactory/factories/read

  • Microsoft.DataFactory/factories/linkedservices/read

The Reader role includes the permissions.

Azure Data Factory

24.4.1

azure-data-factory-v2-integration-runtimes

Additional permissions required:

  • Microsoft.DataFactory/factories/read

  • Microsoft.DataFactory/factories/integrationruntimes/read

The Reader role includes the permissions.

Update Azure Cosmos DB

24.4.1

The azure-cosmos-db API is updated to include minimalTlsVersion field in the resource JSON.

Google Vertex AI AIPlatform

24.4.1

gcloud-vertex-ai-aiplatform-deployment-resource-pool

Additional permission required:

  • aiplatform.deploymentResourcePools.list

The Viewer role includes the permission.

Google Vertex AI AIPlatform

24.4.1

gcloud-vertex-ai-aiplatform-nas-job

Additional permission required:

  • aiplatform.nasJobs.list

The Viewer role includes the permission.

Google Vertex AI AIPlatform

24.4.1

gcloud-vertex-ai-aiplatform-batch-prediction-job

Additional permission required:

  • aiplatform.batchPredictionJobs.list

The Viewer role includes the permission.

Google Vertex AI AIPlatform

24.4.1

gcloud-vertex-ai-aiplatform-model

Additional permission required:

  • aiplatform.models.list

The Viewer role includes the permission.

Google Vertex AI AIPlatform

24.4.1

gcloud-vertex-ai-aiplatform-specialist-pool

Additional permission required:

  • aiplatform.specialistPools.list

The Viewer role includes the permission.

New Policies

Policies

Description

GCP Service account is publicly accessible

24.4.2

This policy identifies GCP Service accounts that are publicly accessible.

GCP Service accounts are intended to be used by an application or compute workload, rather than a person. It can be granted permission to perform actions in the GCP project as any other GCP user. Allowing access to 'allUsers' or 'allAuthenticatedUsers' over a service account would allow unwanted access to the public and could lead to a security breach.

As a security best practice, follow the principle of Least Privilege and grant permissions to entities only on an as needed basis. It is recommended to avoid granting permission to 'allUsers' or 'allAuthenticatedUsers'.

Policy Severity— High

Policy Type— Config

AWS DynamoDB table does not have (PITR) point-in-time recovery enabled

24.4.2

This policy identifies AWS DynamoDB tables that do not have point-in-time recovery (backup) enabled.

AWS DynamoDB enables you to back up your table data continuously by using point-in-time recovery (PITR) with per-second granularity. This helps in protecting your data against accidental write or delete operations.

It is recommended to enable point-in-time recovery functionality on the DynamoDB table to protect data.

Policy Severity— Informational

Policy Type— Config

AWS Cognito identity pool allows unauthenticated guest access

24.4.2

This policy identifies AWS Cognito identity pools that allow unauthenticated guest access.

AWS Cognito identity pools unauthenticated guest access and allows unauthenticated users to assume a role in your AWS account. These unauthenticated users will be granted permissions of the assumed role which may have more privileges than that are intended. This could lead to unauthorized access or data leakage.

It is recommended to disable unauthenticated guest access for the Cognito identity pools.

Policy Severity— Medium

Policy Type— Config

AWS GuardDuty detector is not enabled

24.4.2

This policy identifies the AWS GuardDuty detector that is not enabled in specific regions. GuardDuty identifies potential security threats in the AWS environment by analyzing data collected from various sources.

The GuardDuty detector is the entity within the GuardDuty service that does this analysis. Failure to enable GuardDuty increases the risk of undetected threats and vulnerabilities which could lead to compromises in the AWS environment.

It is recommended to enable GuardDuty detectors in all regions to reduce the risk of security breaches.

Policy Severity— Informational

Policy Type— Config

AWS Glue Job not encrypted by Customer Managed Key (CMK)

24.4.2

This policy identifies AWS Glue jobs that are encrypted using the default KMS key instead of CMK (Customer Managed Key) or using the CMK that is disabled.

AWS Glue allows you to specify whether the data processed by the job should be encrypted when stored in data storage locations such as Amazon S3. To protect sensitive data from unauthorized access, users can specify CMK to get enhanced security, and control over the encryption key and also comply with any regulatory requirements.

It is recommended to use a CMK to encrypt the AWS Glue job data as it provides complete control over the encrypted data.

Policy Severity— Medium

Policy Type— Config

AWS EC2 Auto Scaling Launch Configuration is not using encrypted EBS volumes

24.4.1

This policy identifies AWS EC2 Auto Scaling Launch Configurations that are not using encrypted EBS volumes.

A launch configuration defines an instance configuration template that an Auto Scaling group uses to launch EC2 instances. Amazon Elastic Block Store (EBS) volumes allow you to create encrypted launch configurations when creating EC2 instances and auto scaling groups. When the entire EBS volume is encrypted, data stored at rest, in-transit, and snapshots are encrypted. This protects the data from unauthorized access.

As a security best practice for data protection, enable encryption for all EBS volumes at auto scaling launch configuration.

Policy Severity— Informational

Policy Type— Config

AWS RDS cluster encryption in transit is not configured

24.4.1

This policy identifies AWS RDS database clusters that are not configured with encryption in transit. This covers MySQL, PostgreSQL, and Aurora clusters.

Enabling encryption is crucial to protect data as it moves through the network and enhances the security between clients and storage servers. Without encryption, sensitive data transmitted between your application and the database is vulnerable to interception by malicious actors. This could lead to unauthorized access, data breaches, and potential compromises of confidential information.

It is recommended that data be encrypted while in transit to ensure its security and reduce the risk of unauthorized access or data breaches.

Policy Severity— Medium

Policy Type— Config

AWS Secrets Manager secret not encrypted by Customer Managed Key (CMK)

24.4.1

This policy identifies AWS Secrets Manager secrets that are encrypted using the default KMS key instead of CMK (Customer Managed Key) or using a CMK that is disabled.

AWS Secrets Manager secrets are a secure storage solution for sensitive information like passwords, API keys, and tokens in the AWS cloud. Secrets Manager secrets are encrypted by default by AWS managed key but users can specify CMK to get enhanced security, control over the encryption key, and also comply with any regulatory requirements.

As a security best practice, using CMK to encrypt your Secrets Manager secrets is advisable as it gives you full control over the encrypted data.

Policy Severity— Low

Policy Type— Config

AWS SageMaker endpoint data encryption at rest not configured

24.4.1

This policy identifies AWS SageMaker Endpoints not configured with data encryption at rest.

AWS SageMaker Endpoint configuration defines the resources and settings for deploying machine learning models to SageMaker endpoints. By default, SageMaker Endpoints are not encrypted at rest. Enabling the encryption helps protect the integrity and confidentiality of the data on the storage volume attached to the ML compute instance that hosts the endpoint.

It is recommended to set encryption at rest to mitigate the risk of unauthorized access and potential data breaches.

Policy Severity— Low

Policy Type— Config

AWS DMS replication instance is publicly accessible

24.4.1

This policy identifies AWS DMS (Database Migration Service) replication instances with public accessibility enabled.

A DMS replication instance is used to connect to your source data store, read the source data, and format the data for consumption by the target data store. When AWS DMS replication instances are publicly accessible and have public IP addresses, any machine outside the VPC can create a connection to these instances, increasing the attack surface and the possibility of malicious activity.

So it is recommended to disable public accessibility of DMS replication instances to decrease the attack surface.

Policy Severity— Low

Policy Type— Config

AWS Athena Workgroup not configured with data encryption at rest

24.4.1

This policy identifies AWS Athena workgroups not configured with data encryption at rest.

AWS Athena workgroup enables you to isolate queries for you or your group of users from other queries in the same account, to set the query results location and the encryption configuration. By default, Athena workgroup query run results are not encrypted at rest and client side settings can override the workgroup settings. Encrypting workgroups and preventing overrides from the client side helps in protecting the integrity and confidentiality of the data stored on Athena.

It is recommended to set encryption at rest and enable 'override client-side settings' to mitigate the risk of unauthorized access and potential data breaches.

Policy Severity— Low

Policy Type— Config

AWS root account activity detected in last 14 days

24.4.1

This policy identifies if AWS root account activity was detected within the last 14 days.

The AWS root account user is the primary administrative identity associated with an AWS account, providing complete access to all AWS services and resources. Since the root user has complete access to the account, adopting the principle of least privilege is important to lower the risk of unintentional disclosure of highly privileged credentials and inadvertent alterations. It’s also advised to remove the root user access keys and restrict the use of the root user, refraining from using them for routine or administrative duties.

It is recommended to restrict the use of the AWS root account.

Policy Severity— Medium

Policy Type— Config

Azure Storage Sync Service configured with overly permissive network access

24.4.1

This policy identifies Storage Sync Services configured with overly permissive network access.

A Storage Sync Service is a management construct that represents registered servers and sync groups. Allowing all traffic to the Sync Service may allow a bad actor to brute force their way into the system and potentially get access to the entire network. With a private endpoint, the network traffic path is secured on both ends and access is restricted to only defined authorized entities.

It is recommended to configure the Storage Sync Service with private endpoints to minimize the access vector.

Policy Severity— Medium

Policy Type— Config

GCP Storage Bucket encryption not configured with Customer-Managed Encryption Key (CMEK)

24.4.1

This policy identifies GCP Storage Buckets that are not configured with a Customer-Managed Encryption key.

GCP Storage Buckets might contain sensitive information. Google Cloud Storage service encrypts all data within the buckets using Google-managed encryption keys by default but users can specify Customer-Managed Keys (CMKs) to get enhanced security, control over the encryption key, and also comply with any regulatory requirements.

As a security best practice, the use of CMK to encrypt your Storage bucket is advisable as it gives you full control over the encrypted data.

Policy Severity— Low

Policy Type— Config

New Configuration Build Policies

24.4.1

Added the following default policies within the Build subtype of Configuration policies under Governance for enhanced continuous integration and deployment pipeline security.

AWS Networking Policies

  • TLS not enforced in SES configuration set

Azure General Policies

  • Azure SQL Database server not configured with private endpoint

  • Azure Database for MySQL server not configured with private endpoint

  • Azure Database for MariaDB not configured with private endpoint

  • Azure PostgreSQL servers not configured with private endpoint

  • Azure Container Registry (ACR) not zone redundant

  • Azure Container Instance environment variable with regular value type

  • Azure Synapse Workspace vulnerability assessment is disabled

  • Azure Microsoft Defender for Cloud set to Off for Resource Manager

Azure IAM Policies

  • Anonymous blob access configured in Azure storage account

Google Cloud General Policies

  • Vertex AI instance disks not encrypted with a Customer Managed Key (CMK)

  • Vertex AI tensorboard does not use a Customer Managed Key (CMK)

  • Vertex AI workbench instance disks not encrypted with a Customer Managed Key (CMK)

  • Vertex AI workbench instances are not private

  • Vertex AI endpoint is not using a Customer Managed Key (CMK)

  • Vertex AI featurestore is not configured to use a Customer Managed Key (CMK)

  • Document AI Processors not encrypted with a Customer Managed Key (CMK)

  • Document AI Warehouse Location is not configured to use a Customer Managed Key (CMK)

  • Vertex AI runtime is not encrypted with a Customer Managed Key (CMK)

Google Cloud Networking Policies

  • Vertex AI runtime is public

  • TPU v2 VM is public

  • Vertex AI endpoint is public

  • Vertex AI index endpoint is public

Google Cloud Logging Policies

  • Logging for Dialogflow CX agents is disabled

  • Logging for Dialogflow CX webhooks is disabled

  • Logging is disabled for Dialogflow agents

Impact- You will view policy violations for these policies on Prisma Cloud switcher Application Security > Projects. Enforcement levels for IaC Misconfigurations will now be applied to pipelines with these findings. You are required to enable the additional modules on Application Security > Settings to view violations and alerts for these policies.

IAM Policies

The following OOTB IAM policies are newly added in 24.4.2 release.

Policy Name

Description

RQL

Cloud

Policy Severity

User account with excessive admin privileges

Identifies users in Azure, AWS, and GCP which have administrative permissions that have not been used in the last 90 days.

All

Medium

Cloud service account with excessive admin privileges

Identifies cloud service accounts in Azure, AWS and GCP which have administrative permissions that have not been used in the last 90 days.

All

Medium

Roles with high privileges can be assumed by a service in an external account

Identifies roles which have administrative permissions and can be assumed by an identity in an external account.

AWS

High

AWS Lateral Movement to Data Services Through Redshift Cluster Creation

With access to the iam:PassRole, redshift:CreateCluster permissions, an adversary can create a Redshift cluster with a more privileged existing role, allowing access to more datasources.

AWS

High

Azure Lateral Movement via VM Command Execution Leveraging Managed Identity

Using this role allows running commands on any virtual machine in the subscription. With 'Microsoft.Compute/virtualMachines/runCommand/action', an adversary can steal credentials connected to the VM and perform lateral movements.

Azure

Medium

Azure Lateral Movement Through SSH Key Replacement and Managed Identity Exploitation on VM

Using this role allows creating and changing virtual machines in the subscription. With 'Microsoft.ClassicCompute/virtualMachines/write' and 'Microsoft.ClassicCompute/virtualMachines/extensions/write', an adversary can update SSH keys for a VM.

Azure

Medium

GCP Cloud Run with basic role

Identifies Cloud Run instances granted broad access due to highly permissive basic roles attached ('Viewer', 'Editor', 'Owner').

GCP

Medium

GCP Cloud Run with administrative permissions

Identifies Cloud Run instances granted administrative permissions, increasing the blast radius in case of a potential compromise.

GCP

Medium

GCP Cloud Run Job Public Execution via Default Compute SA Modification

An entity can update Cloud Run job code and public execution permissions, potentially with high permissions.

GCP

High

GCP Lateral Access Expansion by Making Cloud Run Publicly Executable

An entity can update Cloud Run instance code and public execution permissions, potentially with high permissions.

GCP

High

GCP Project-Wide Lateral Movement via SSH Key Modification for VMs

An entity can update VM instance metadata for all project VMs and modify SSH keys for virtual machines inside the project, allowing a lateral movement and hijacking of VMs.

GCP

High

Policy Updates

Policy Updates

Description

Policy Updates—RQL

AWS EBS volume region with encryption is disabled

24.4.1

Changes— The RQL is updated to check for Function app configured with default network configuration

Severity— Low

Policy Type— Config

Updated Recommendation Steps:

Follow the steps outlined here to enable encryption at the region level by default.

Additional Information:

  • To detect existing EBS volumes that are not encrypted ; refer Saved Search: AWS EBS volumes are not encrypted_RL

  • To detect existing EBS volumes that are not encrypted with CMK, refer Saved Search: AWS EBS volume not encrypted using Customer Managed Key_RL.

Impact— No impact

Azure Function app configured with public network access

24.4.1

Changes— The RQL will be updated to check for Function app configured with default network configuration

Severity— Medium

Policy Type— Config

Current RQL—

Updated RQL—

Impact— Medium. New Alerts will be generated when the publicNetworkAccess for function app is set with default networking configuration.

AWS MFA is not enabled on Root account

24.4.1

Changes— The policy RQL is updated to be inline with standard conventions followed by Prisma Cloud.

Current RQL—

Updated RQL—

Impact— None.

Policy Updates—Metadata

AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports

24.4.1

Changes— The policy name is updated to show admin ports information in the policy names for better readability.

Current Policy Name— AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports

Updated Policy Name— AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389

Severity— High

Policy Type— Network

Impact— None.

Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports

24.4.1

Changes— The policy name is updated to show admin ports information in the policy names for better readability.

Current Policy Name— Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports

Updated Policy Name— Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389

Severity— High

Policy Type— Network

Impact— None.

GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports

24.4.1

Changes— The policy name is updated to show admin ports information in the policy names for better readability.

Current Policy Name— GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports

Updated Policy Name— GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389

Severity— High

Policy Type— Network

Impact— None.

New Compliance Benchmarks and Updates

Compliance Benchmark

Description

Support for CRI Profile v2.0

24.4.2

Prisma Cloud supports the CRI Profile v2.0 compliance standard. This framework is designed to offer an effective method for managing technology and cybersecurity risks, addressing dynamic threats while providing sufficient assurance to government regulators. The compliance standard encompasses all requirements and controls outlined by the Cyber Risk Institute (CRI), and is meticulously aligned with Prisma Cloud policies.

You can now view this built-in standard and the associated policies on the Compliance > Standards page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.

REST API Updates

Change

Description

Update Integration APIs

24.4.2

The Integration APIs now support Cortex XSOAR 8.0. All Integration APIs have an additional demistoVersion parameter to recognize the Cortex XSOAR version.

Update Alerts API Responses

24.4.1

The following Alert API responses include a new investigateOptions field:

Update GET CVE Overview API

24.4.1

The response of the GET CVE Overview endpoint includes the following changes:

  • The following new parameters are added to impactedDistrosList:

    • highestCVSS

    • highestSeverity

    • firstPublishedDate

    • lastModifiedDate

  • The following new parameters are added to impactedDistrosList.distroDetailsList:

    • publishedDate

    • modifiedDate

  • The data type of impactedDistrosList.distroDetailsList.severity is changed from integer to string.

Update Compliance Posture APIs

24.4.1

The Get Compliance Trend V2 - POST API now supports the timeRange parameter. For more information on Time Ranges , see CSPM Time Range Model.

Update Search APIs

24.4.1

New version of Config Search APIs include a new Time Range model and various enhancements to response values.

Changes in Existing Behavior

Feature

Description

S3 Flow Logs with Hourly Partition

This change was first announced in the look ahead that was published with the 23.1.1 release.

If you currently ingest AWS flow logs using S3 with the 24-hour partition, you need to change it to the hourly partition.

To make this change, Configure Flow Logs to use the hourly partition and enable the required additional fields.

Impact— VPC Flow logs with partitions set to Every 24 hours (default) was disabled on February 29th, 2024. As a result, you will no longer be able to monitor or receive alerts for these logs. If you have any questions, contact your Prisma Cloud Customer Success Representative immediately.

Last updated

Was this helpful?