Features Introduced in April 2024
Learn what’s new on Prisma® Cloud in April 2024.
New Features
Feature
Description
Integration Support for Cortex XSOAR Version 8.0
Secure the Infrastructure
24.4.2
The Cortex XSOAR integration is enhanced to support both XSOAR versions 6.0 and 8.0. As a result, you will now see the Versions Available option on the Prisma Cloud Console. This option allows you to select between XSOAR versions 6.0 or 8.0 when you create or update the integration on Prisma Cloud.

Share Views with Ease
Secure the Infrastructure
24.4.2
Accelerate team collaboration and communication with Prisma Cloud®'s shareable Dashboards and Saved Views. Enhancements to Prisma Cloud provide a seamless way to share custom dashboards and saved views with other users in your tenant and/or organization. You can now configure the access level of any dashboard or saved view that you have created to make it Public and viewable by any user within your tenant. Review and/or change the access level or visibility status of any Dashboard/Saved View at any time, from the Manage Dashboards/Saved Views page.

Prisma Cloud Service in Indonesia
Secure the Infrastructure
24.4.2
Prisma Cloud tenant (app.id.prismacloud.io) is now available for the Jakarta region.
Identity Access RQL Attributes Added
Secure the Infrastructure
24.4.2
Enhancements to the Permission Query RQL allow you to easily and comprehensively understand the access provided to identities in your cloud environment, without the need for investigating individual actions. Use the action.access.level and action.access.isAdministrative RQL query attributes to track over privileged access in your AWS, Azure, and GCP environments.
Alerts by Status Widget
Secure the Infrastructure
24.4.1
The Dashboards page now includes the Alerts by Status widget. Leverage this widget to enhance your alerts investigations by filtering on alert status (Resolved, Open or Dismissed) and time range.
Update Compliance Trend Widget
Secure the Infrastructure
24.4.1
The Compliance Trend widget now supports filtering data by the following time durations:
24 hours
1 week
1 month
3 months
6 months
1 year
Year to Date
Custom
Note: When you select the Custom option under Time Range, the widget only uses the Start Date and disregards the hourly timestamp. The End Date is always set to the current date, regardless of your selection.
Update IAM Permission Query Results
Secure the Infrastructure
24.4.1
Enhancements to IAM permission queries in Prisma Cloud now allow you to obtain narrowly focused results by refining your search. Choose the fields relevant to your investigation to customize and define your permission query results.

Azure IAM Identity Inventory
Secure the Infrastructure
24.4.1
Gain greater visibility into Azure roles, groups, service principals and managed identities with Azure IAM Identity Inventory. Enforce least privileged access best practices by routinely removing unused privileges and permissions within your Azure roles and entitlements. Select Suggest Least Privilege Access to modify existing permissions and generate a new policy in JSON, and Terraform format, that includes only the permissions required based on actual usage.
API Ingestions
Service
API Details
Update AWS Application Auto Scaling
24.4.2
aws-application-autoscaling-scaling-policy
The AWS Application Auto Scaling API now includes an additional field called ResourceName.
Update Amazon API Gateway
24.4.2
aws-apigateway-method
The aws-apigateway-method API has been updated to exclude to exclude the methodIntegration.cacheNamespace field from the JSON because it changes frequently causing too many resource snapshots.
Amazon Detective
24.4.2
aws-detective-datasource-package
Additional permissions required:
detective:ListGraphsdetective:ListDatasourcePackages
The Security Audit role includes the detective:ListGraphs permission. You must manually add the detective:ListDatasourcePackages permission to the CFT template to enable it.
Amazon Polly
24.4.2
aws-polly-speech-synthesis-task
Additional permission required:
polly:ListSpeechSynthesisTasks
You must manually add the permission to the CFT template to enable it.
Amazon SES
24.4.2
aws-ses-configuration-set
Additional permissions required:
ses:ListConfigurationSetsses:DescribeConfigurationSet
The Security Audit role includes the permissions.
AWS Batch
24.4.2
aws-batch-job-queue
Additional permission required:
batch:DescribeJobQueues
You must manually add the permission to the CFT template to enable it.
Azure CDN
24.4.2
azure-frontdoor-standardpremium-routes
Additional permissions required:
Microsoft.Cdn/profiles/readMicrosoft.Cdn/profiles/afdendpoints/readMicrosoft.Cdn/profiles/afdendpoints/routes/read
The Reader role includes the permissions.
Azure CDN
24.4.2
azure-frontdoor-standardpremium-afd-custom-domains
Additional permissions required:
Microsoft.Cdn/profiles/readMicrosoft.Cdn/profiles/customdomains/read
The Reader role includes the permissions.
Azure SQL Database
24.4.2
azure-sql-managed-instance-vulnerability-assessments
Additional permissions required:
Microsoft.Sql/managedInstances/readMicrosoft.Sql/managedInstances/vulnerabilityAssessments/Read
The Reader role includes the permissions.
Azure SQL Database
24.4.2
azure-sql-managed-instance-encryption-protectors
Additional permissions required:
Microsoft.Sql/managedInstances/readMicrosoft.Sql/managedInstances/encryptionProtector/Read
The Reader role includes the permissions.
Azure Synapse Analytics
24.4.2
azure-synapse-workspace-sql-pools
Additional permissions required:
Microsoft.Synapse/workspaces/readMicrosoft.Synapse/workspaces/sqlPools/read
The Reader role includes the permissions.
Google Traffic Director
24.4.2
gcloud-traffic-director-secure-web-proxy-url-list
Additional permission required:
networksecurity.urlLists.list
The Viewer role includes the permission.
Google Vertex AI AIPlatform
24.4.2
gcloud-vertex-ai-aiplatform-notebook-runtime-template
Additional permissions required:
aiplatform.notebookRuntimeTemplates.listaiplatform.notebookRuntimeTemplates.getIamPolicy
The Viewer role includes the permissions.
Google Vertex AI AIPlatform
24.4.2
gcloud-vertex-ai-aiplatform-notebook-runtime
Additional permission required:
aiplatform.notebookRuntimes.list
The Viewer role includes the permission.
Google Traffic Director
24.4.2
gcloud-traffic-director-gateway-security-policy
Additional permission required:
networksecurity.gatewaySecurityPolicies.list
The Viewer role includes the permission.
Google Traffic Director
24.4.2
gcloud-traffic-director-gateway-security-policy-rule
Additional permissions required:
networksecurity.gatewaySecurityPolicies.listnetworksecurity.gatewaySecurityPolicyRules.list
The Viewer role includes the permissions.
Amazon Cognito
24.4.1
aws-cognito-sync-pool-usage
Additional permission required:
cognito-sync:ListIdentityPoolUsage
The Security Audit role includes the permission.
Amazon Comprehend
24.4.1
aws-comprehend-entities-detection-jobs
Additional permission required:
comprehend:ListEntitiesDetectionJobs
The Security Audit role includes the permission.
Amazon Comprehend
24.4.1
aws-comprehend-document-classifier-summary
Additional permission required:
comprehend:ListDocumentClassifierSummaries
The Security Audit role includes the permission.
Amazon Comprehend
24.4.1
aws-comprehend-document-classifier
Additional permission required:
comprehend:ListDocumentClassifiers
The Security Audit role includes the permission.
Amazon Device Farm Projects
24.4.1
aws-device-farm-projects
Additional permission required:
devicefarm:ListProjects
The Security Audit role includes the permission.
Update Amazon DynamoDB
24.4.1
aws-dynamodb-describe-table
Additional permission required:
dynamodb:DescribeContinuousBackups
The Security Audit role includes the permission.
The aws-dynamodb-describe-table API is also updated to include ContinuousBackupsDescription field in the resource JSON.
Amazon Elastic Transcoder Pipelines
24.4.1
aws-elastic-transcoder-pipelines
Additional permission required:
elastictranscoder:ListPipelines
The Security Audit role includes the permission.
Amazon ElasticBeanstalk Applications
24.4.1
aws-elasticbeanstalk-applications
Additional permission required:
elasticbeanstalk:DescribeApplications
The Security Audit role includes the permission.
Amazon GuardDuty
24.4.1
aws-guardduty-organization-configuration
Additional permissions required:
guardduty:ListDetectorsguardduty:DescribeOrganizationConfiguration
The Security Audit role includes the guardduty:ListDetectors permission. You must manually add the guardduty:DescribeOrganizationConfiguration permission to the CFT template to enable it.
Amazon IoT Analytics Datastores
24.4.1
aws-iot-analytics-datastores
Additional permission required:
iotanalytics:ListDatastores
The Security Audit role includes the permission.
Amazon IoT Events Inputs
24.4.1
aws-iot-events-inputs
Additional permission required:
iotevents:ListInputs
The Security Audit role includes the permission.
Amazon Lookout for Vision Projects
24.4.1
aws-lookoutvision-projects
Additional permission required:
lookoutvision:ListProjects
The Security Audit role includes the permission.
Amazon LookoutEquipment Datasets
24.4.1
aws-lookoutequipment-datasets
Additional permission required:
lookoutequipment:ListDatasets
The Security Audit role includes the permission.
Amazon Servicecatalog Portfolios
24.4.1
aws-servicecatalog-portfolios
Additional permission required:
servicecatalog:ListPortfolios
The Security Audit role includes the permission.
Amazon SWF Domains
24.4.1
aws-swf-domains
Additional permission required:
swf:ListDomains
The Security Audit role includes the permission.
AWS ComprehendMedical Entities Detection V2 Jobs
24.4.1
aws-comprehendmedical-entities-detection-v2-jobs
Additional permission required:
comprehendmedical:ListEntitiesDetectionV2Jobs
The Security Audit role includes the permission.
AWS Greengrass Core Definitions
24.4.1
aws-greengrass-core-definitions
Additional permission required:
greengrass:ListCoreDefinitions
The Security Audit role includes the permission.
AWS Greengrass Groups
24.4.1
aws-greengrass-groups
Additional permission required:
greengrass:ListGroups
The Security Audit role includes the permission.
AWS IoTFleetWise Signal Catalogs
24.4.1
aws-iotfleetwise-signal-catalogs
Additional permission required:
iotfleetwise:ListSignalCatalogs
The Security Audit role includes the permission.
AWS LookoutMetrics Anomaly Detectors
24.4.1
aws-lookoutmetrics-anomaly-detectors
Additional permission required:
lookoutmetrics:ListAnomalyDetectors
The Security Audit role includes the permission.
AWS Managed Blockchain Networks List
24.4.1
aws-managed-blockchain-networks
Additional permission required:
managedblockchain:ListNetworks
The Security Audit role includes the permission.
AWS OpsWorks Describe User Profiles
24.4.1
aws-opsworks-user-profiles
Additional permission required:
opsworks:DescribeUserProfiles
The Security Audit role includes the permission.
AWS Polly Voices
24.4.1
aws-polly-voices
Additional permission required:
polly:DescribeVoices
The Security Audit role includes the permission.
AWS Resilience Hub
24.4.1
aws-resiliencehub-apps
Additional permission required:
resiliencehub:ListApps
The Security Audit role includes the permission.
AWS SecurityHub Describe Standards
24.4.1
aws-securityhub-standards
Additional permission required:
securityhub:DescribeStandards
The Security Audit role includes the permission.
AWS Service Discovery Namespaces
24.4.1
aws-servicediscovery-namespaces
Additional permission required:
servicediscovery:ListNamespaces
The Security Audit role includes the permission.
Azure Active Directory
24.4.1
azure-active-directory-directoryrole-definition
Additional permissions required:
EntitlementManagement.Read.AllRoleManagement.Read.All
The Global Reader role includes the permissions.
Azure Active Directory
24.4.1
azure-active-directory-directoryrole-assignment
Additional permissions required:
EntitlementManagement.Read.AllRoleManagement.Read.All
The Global Reader role includes the permissions.
Azure App Service
24.4.1
azure-app-service-web-apps-configurations
Additional permissions required:
Microsoft.Web/sites/ReadMicrosoft.Web/sites/config/Read
The Reader role includes the permissions.
Azure Data Factory
24.4.1
azure-data-factory-v2-linked-services
Additional permissions required:
Microsoft.DataFactory/factories/readMicrosoft.DataFactory/factories/linkedservices/read
The Reader role includes the permissions.
Azure Data Factory
24.4.1
azure-data-factory-v2-integration-runtimes
Additional permissions required:
Microsoft.DataFactory/factories/readMicrosoft.DataFactory/factories/integrationruntimes/read
The Reader role includes the permissions.
Update Azure Cosmos DB
24.4.1
The azure-cosmos-db API is updated to include minimalTlsVersion field in the resource JSON.
Google Vertex AI AIPlatform
24.4.1
gcloud-vertex-ai-aiplatform-deployment-resource-pool
Additional permission required:
aiplatform.deploymentResourcePools.list
The Viewer role includes the permission.
Google Vertex AI AIPlatform
24.4.1
gcloud-vertex-ai-aiplatform-nas-job
Additional permission required:
aiplatform.nasJobs.list
The Viewer role includes the permission.
Google Vertex AI AIPlatform
24.4.1
gcloud-vertex-ai-aiplatform-batch-prediction-job
Additional permission required:
aiplatform.batchPredictionJobs.list
The Viewer role includes the permission.
Google Vertex AI AIPlatform
24.4.1
gcloud-vertex-ai-aiplatform-model
Additional permission required:
aiplatform.models.list
The Viewer role includes the permission.
Google Vertex AI AIPlatform
24.4.1
gcloud-vertex-ai-aiplatform-specialist-pool
Additional permission required:
aiplatform.specialistPools.list
The Viewer role includes the permission.
New Policies
Policies
Description
GCP Service account is publicly accessible
24.4.2
This policy identifies GCP Service accounts that are publicly accessible.
GCP Service accounts are intended to be used by an application or compute workload, rather than a person. It can be granted permission to perform actions in the GCP project as any other GCP user. Allowing access to 'allUsers' or 'allAuthenticatedUsers' over a service account would allow unwanted access to the public and could lead to a security breach.
As a security best practice, follow the principle of Least Privilege and grant permissions to entities only on an as needed basis. It is recommended to avoid granting permission to 'allUsers' or 'allAuthenticatedUsers'.
Policy Severity— High
Policy Type— Config
AWS DynamoDB table does not have (PITR) point-in-time recovery enabled
24.4.2
This policy identifies AWS DynamoDB tables that do not have point-in-time recovery (backup) enabled.
AWS DynamoDB enables you to back up your table data continuously by using point-in-time recovery (PITR) with per-second granularity. This helps in protecting your data against accidental write or delete operations.
It is recommended to enable point-in-time recovery functionality on the DynamoDB table to protect data.
Policy Severity— Informational
Policy Type— Config
AWS Cognito identity pool allows unauthenticated guest access
24.4.2
This policy identifies AWS Cognito identity pools that allow unauthenticated guest access.
AWS Cognito identity pools unauthenticated guest access and allows unauthenticated users to assume a role in your AWS account. These unauthenticated users will be granted permissions of the assumed role which may have more privileges than that are intended. This could lead to unauthorized access or data leakage.
It is recommended to disable unauthenticated guest access for the Cognito identity pools.
Policy Severity— Medium
Policy Type— Config
AWS GuardDuty detector is not enabled
24.4.2
This policy identifies the AWS GuardDuty detector that is not enabled in specific regions. GuardDuty identifies potential security threats in the AWS environment by analyzing data collected from various sources.
The GuardDuty detector is the entity within the GuardDuty service that does this analysis. Failure to enable GuardDuty increases the risk of undetected threats and vulnerabilities which could lead to compromises in the AWS environment.
It is recommended to enable GuardDuty detectors in all regions to reduce the risk of security breaches.
Policy Severity— Informational
Policy Type— Config
AWS Glue Job not encrypted by Customer Managed Key (CMK)
24.4.2
This policy identifies AWS Glue jobs that are encrypted using the default KMS key instead of CMK (Customer Managed Key) or using the CMK that is disabled.
AWS Glue allows you to specify whether the data processed by the job should be encrypted when stored in data storage locations such as Amazon S3. To protect sensitive data from unauthorized access, users can specify CMK to get enhanced security, and control over the encryption key and also comply with any regulatory requirements.
It is recommended to use a CMK to encrypt the AWS Glue job data as it provides complete control over the encrypted data.
Policy Severity— Medium
Policy Type— Config
AWS EC2 Auto Scaling Launch Configuration is not using encrypted EBS volumes
24.4.1
This policy identifies AWS EC2 Auto Scaling Launch Configurations that are not using encrypted EBS volumes.
A launch configuration defines an instance configuration template that an Auto Scaling group uses to launch EC2 instances. Amazon Elastic Block Store (EBS) volumes allow you to create encrypted launch configurations when creating EC2 instances and auto scaling groups. When the entire EBS volume is encrypted, data stored at rest, in-transit, and snapshots are encrypted. This protects the data from unauthorized access.
As a security best practice for data protection, enable encryption for all EBS volumes at auto scaling launch configuration.
Policy Severity— Informational
Policy Type— Config
AWS RDS cluster encryption in transit is not configured
24.4.1
This policy identifies AWS RDS database clusters that are not configured with encryption in transit. This covers MySQL, PostgreSQL, and Aurora clusters.
Enabling encryption is crucial to protect data as it moves through the network and enhances the security between clients and storage servers. Without encryption, sensitive data transmitted between your application and the database is vulnerable to interception by malicious actors. This could lead to unauthorized access, data breaches, and potential compromises of confidential information.
It is recommended that data be encrypted while in transit to ensure its security and reduce the risk of unauthorized access or data breaches.
Policy Severity— Medium
Policy Type— Config
AWS Secrets Manager secret not encrypted by Customer Managed Key (CMK)
24.4.1
This policy identifies AWS Secrets Manager secrets that are encrypted using the default KMS key instead of CMK (Customer Managed Key) or using a CMK that is disabled.
AWS Secrets Manager secrets are a secure storage solution for sensitive information like passwords, API keys, and tokens in the AWS cloud. Secrets Manager secrets are encrypted by default by AWS managed key but users can specify CMK to get enhanced security, control over the encryption key, and also comply with any regulatory requirements.
As a security best practice, using CMK to encrypt your Secrets Manager secrets is advisable as it gives you full control over the encrypted data.
Policy Severity— Low
Policy Type— Config
AWS SageMaker endpoint data encryption at rest not configured
24.4.1
This policy identifies AWS SageMaker Endpoints not configured with data encryption at rest.
AWS SageMaker Endpoint configuration defines the resources and settings for deploying machine learning models to SageMaker endpoints. By default, SageMaker Endpoints are not encrypted at rest. Enabling the encryption helps protect the integrity and confidentiality of the data on the storage volume attached to the ML compute instance that hosts the endpoint.
It is recommended to set encryption at rest to mitigate the risk of unauthorized access and potential data breaches.
Policy Severity— Low
Policy Type— Config
AWS DMS replication instance is publicly accessible
24.4.1
This policy identifies AWS DMS (Database Migration Service) replication instances with public accessibility enabled.
A DMS replication instance is used to connect to your source data store, read the source data, and format the data for consumption by the target data store. When AWS DMS replication instances are publicly accessible and have public IP addresses, any machine outside the VPC can create a connection to these instances, increasing the attack surface and the possibility of malicious activity.
So it is recommended to disable public accessibility of DMS replication instances to decrease the attack surface.
Policy Severity— Low
Policy Type— Config
AWS Athena Workgroup not configured with data encryption at rest
24.4.1
This policy identifies AWS Athena workgroups not configured with data encryption at rest.
AWS Athena workgroup enables you to isolate queries for you or your group of users from other queries in the same account, to set the query results location and the encryption configuration. By default, Athena workgroup query run results are not encrypted at rest and client side settings can override the workgroup settings. Encrypting workgroups and preventing overrides from the client side helps in protecting the integrity and confidentiality of the data stored on Athena.
It is recommended to set encryption at rest and enable 'override client-side settings' to mitigate the risk of unauthorized access and potential data breaches.
Policy Severity— Low
Policy Type— Config
AWS root account activity detected in last 14 days
24.4.1
This policy identifies if AWS root account activity was detected within the last 14 days.
The AWS root account user is the primary administrative identity associated with an AWS account, providing complete access to all AWS services and resources. Since the root user has complete access to the account, adopting the principle of least privilege is important to lower the risk of unintentional disclosure of highly privileged credentials and inadvertent alterations. It’s also advised to remove the root user access keys and restrict the use of the root user, refraining from using them for routine or administrative duties.
It is recommended to restrict the use of the AWS root account.
Policy Severity— Medium
Policy Type— Config
Azure Storage Sync Service configured with overly permissive network access
24.4.1
This policy identifies Storage Sync Services configured with overly permissive network access.
A Storage Sync Service is a management construct that represents registered servers and sync groups. Allowing all traffic to the Sync Service may allow a bad actor to brute force their way into the system and potentially get access to the entire network. With a private endpoint, the network traffic path is secured on both ends and access is restricted to only defined authorized entities.
It is recommended to configure the Storage Sync Service with private endpoints to minimize the access vector.
Policy Severity— Medium
Policy Type— Config
GCP Storage Bucket encryption not configured with Customer-Managed Encryption Key (CMEK)
24.4.1
This policy identifies GCP Storage Buckets that are not configured with a Customer-Managed Encryption key.
GCP Storage Buckets might contain sensitive information. Google Cloud Storage service encrypts all data within the buckets using Google-managed encryption keys by default but users can specify Customer-Managed Keys (CMKs) to get enhanced security, control over the encryption key, and also comply with any regulatory requirements.
As a security best practice, the use of CMK to encrypt your Storage bucket is advisable as it gives you full control over the encrypted data.
Policy Severity— Low
Policy Type— Config
New Configuration Build Policies
24.4.1
Added the following default policies within the Build subtype of Configuration policies under Governance for enhanced continuous integration and deployment pipeline security.
AWS Networking Policies
TLS not enforced in SES configuration set
Azure General Policies
Azure SQL Database server not configured with private endpoint
Azure Database for MySQL server not configured with private endpoint
Azure Database for MariaDB not configured with private endpoint
Azure PostgreSQL servers not configured with private endpoint
Azure Container Registry (ACR) not zone redundant
Azure Container Instance environment variable with regular value type
Azure Synapse Workspace vulnerability assessment is disabled
Azure Microsoft Defender for Cloud set to Off for Resource Manager
Azure IAM Policies
Anonymous blob access configured in Azure storage account
Google Cloud General Policies
Vertex AI instance disks not encrypted with a Customer Managed Key (CMK)
Vertex AI tensorboard does not use a Customer Managed Key (CMK)
Vertex AI workbench instance disks not encrypted with a Customer Managed Key (CMK)
Vertex AI workbench instances are not private
Vertex AI endpoint is not using a Customer Managed Key (CMK)
Vertex AI featurestore is not configured to use a Customer Managed Key (CMK)
Document AI Processors not encrypted with a Customer Managed Key (CMK)
Document AI Warehouse Location is not configured to use a Customer Managed Key (CMK)
Vertex AI runtime is not encrypted with a Customer Managed Key (CMK)
Google Cloud Networking Policies
Vertex AI runtime is public
TPU v2 VM is public
Vertex AI endpoint is public
Vertex AI index endpoint is public
Google Cloud Logging Policies
Logging for Dialogflow CX agents is disabled
Logging for Dialogflow CX webhooks is disabled
Logging is disabled for Dialogflow agents
Impact- You will view policy violations for these policies on Prisma Cloud switcher Application Security > Projects. Enforcement levels for IaC Misconfigurations will now be applied to pipelines with these findings. You are required to enable the additional modules on Application Security > Settings to view violations and alerts for these policies.
IAM Policies
The following OOTB IAM policies are newly added in 24.4.2 release.
Policy Name
Description
RQL
Cloud
Policy Severity
User account with excessive admin privileges
Identifies users in Azure, AWS, and GCP which have administrative permissions that have not been used in the last 90 days.
All
Medium
Cloud service account with excessive admin privileges
Identifies cloud service accounts in Azure, AWS and GCP which have administrative permissions that have not been used in the last 90 days.
All
Medium
Roles with high privileges can be assumed by a service in an external account
Identifies roles which have administrative permissions and can be assumed by an identity in an external account.
AWS
High
AWS Lateral Movement to Data Services Through Redshift Cluster Creation
With access to the iam:PassRole, redshift:CreateCluster permissions, an adversary can create a Redshift cluster with a more privileged existing role, allowing access to more datasources.
AWS
High
Azure Lateral Movement via VM Command Execution Leveraging Managed Identity
Using this role allows running commands on any virtual machine in the subscription. With 'Microsoft.Compute/virtualMachines/runCommand/action', an adversary can steal credentials connected to the VM and perform lateral movements.
Azure
Medium
Azure Lateral Movement Through SSH Key Replacement and Managed Identity Exploitation on VM
Using this role allows creating and changing virtual machines in the subscription. With 'Microsoft.ClassicCompute/virtualMachines/write' and 'Microsoft.ClassicCompute/virtualMachines/extensions/write', an adversary can update SSH keys for a VM.
Azure
Medium
GCP Cloud Run with basic role
Identifies Cloud Run instances granted broad access due to highly permissive basic roles attached ('Viewer', 'Editor', 'Owner').
GCP
Medium
GCP Cloud Run with administrative permissions
Identifies Cloud Run instances granted administrative permissions, increasing the blast radius in case of a potential compromise.
GCP
Medium
GCP Cloud Run Job Public Execution via Default Compute SA Modification
An entity can update Cloud Run job code and public execution permissions, potentially with high permissions.
GCP
High
GCP Lateral Access Expansion by Making Cloud Run Publicly Executable
An entity can update Cloud Run instance code and public execution permissions, potentially with high permissions.
GCP
High
GCP Project-Wide Lateral Movement via SSH Key Modification for VMs
An entity can update VM instance metadata for all project VMs and modify SSH keys for virtual machines inside the project, allowing a lateral movement and hijacking of VMs.
GCP
High
Policy Updates
Policy Updates
Description
Policy Updates—RQL
AWS EBS volume region with encryption is disabled
24.4.1
Changes— The RQL is updated to check for Function app configured with default network configuration
Severity— Low
Policy Type— Config
Updated Recommendation Steps:
Follow the steps outlined here to enable encryption at the region level by default.
Additional Information:
To detect existing EBS volumes that are not encrypted ; refer Saved Search: AWS EBS volumes are not encrypted_RL
To detect existing EBS volumes that are not encrypted with CMK, refer Saved Search: AWS EBS volume not encrypted using Customer Managed Key_RL.
Impact— No impact
Azure Function app configured with public network access
24.4.1
Changes— The RQL will be updated to check for Function app configured with default network configuration
Severity— Medium
Policy Type— Config
Current RQL—
Updated RQL—
Impact— Medium. New Alerts will be generated when the publicNetworkAccess for function app is set with default networking configuration.
AWS MFA is not enabled on Root account
24.4.1
Changes— The policy RQL is updated to be inline with standard conventions followed by Prisma Cloud.
Current RQL—
Updated RQL—
Impact— None.
Policy Updates—Metadata
AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports
24.4.1
Changes— The policy name is updated to show admin ports information in the policy names for better readability.
Current Policy Name— AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports
Updated Policy Name— AWS EC2 instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389
Severity— High
Policy Type— Network
Impact— None.
Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports
24.4.1
Changes— The policy name is updated to show admin ports information in the policy names for better readability.
Current Policy Name— Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports
Updated Policy Name— Azure Virtual Machine that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389
Severity— High
Policy Type— Network
Impact— None.
GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports
24.4.1
Changes— The policy name is updated to show admin ports information in the policy names for better readability.
Current Policy Name— GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) to Admin ports
Updated Policy Name— GCP VM instance that is internet reachable with unrestricted access (0.0.0.0/0) on Admin ports 22/3389
Severity— High
Policy Type— Network
Impact— None.
New Compliance Benchmarks and Updates
Compliance Benchmark
Description
Support for CRI Profile v2.0
24.4.2
Prisma Cloud supports the CRI Profile v2.0 compliance standard. This framework is designed to offer an effective method for managing technology and cybersecurity risks, addressing dynamic threats while providing sufficient assurance to government regulators. The compliance standard encompasses all requirements and controls outlined by the Cyber Risk Institute (CRI), and is meticulously aligned with Prisma Cloud policies.
You can now view this built-in standard and the associated policies on the Compliance > Standards page. You can also generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.
REST API Updates
Change
Description
Update Integration APIs
24.4.2
The Integration APIs now support Cortex XSOAR 8.0. All Integration APIs have an additional demistoVersion parameter to recognize the Cortex XSOAR version.
Update Alerts API Responses
24.4.1
The following Alert API responses include a new investigateOptions field:
List Alerts
List Alerts V2
Alert Info
Update GET CVE Overview API
24.4.1
The response of the GET CVE Overview endpoint includes the following changes:
The following new parameters are added to impactedDistrosList:
highestCVSS
highestSeverity
firstPublishedDate
lastModifiedDate
The following new parameters are added to impactedDistrosList.distroDetailsList:
publishedDate
modifiedDate
The data type of impactedDistrosList.distroDetailsList.severity is changed from integer to string.
Update Compliance Posture APIs
24.4.1
The Get Compliance Trend V2 - POST API now supports the timeRange parameter. For more information on Time Ranges , see CSPM Time Range Model.
Update Search APIs
24.4.1
New version of Config Search APIs include a new Time Range model and various enhancements to response values.
Changes in Existing Behavior
Feature
Description
S3 Flow Logs with Hourly Partition
This change was first announced in the look ahead that was published with the 23.1.1 release.
If you currently ingest AWS flow logs using S3 with the 24-hour partition, you need to change it to the hourly partition.
To make this change, Configure Flow Logs to use the hourly partition and enable the required additional fields.
Impact— VPC Flow logs with partitions set to Every 24 hours (default) was disabled on February 29th, 2024. As a result, you will no longer be able to monitor or receive alerts for these logs. If you have any questions, contact your Prisma Cloud Customer Success Representative immediately.
Last updated
Was this helpful?

