> For the complete documentation index, see [llms.txt](https://docs.prismacloud.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-june-2024.md).

# Features Introduced in June 2024

Learn what’s new on Prisma® Cloud in June 2024.

* [Announcement](#announcement)
* [New Features](#new-features)
* [API Ingestions](#api-ingestions)
* [New Policies](#new-policies)
* [IAM Policies](#iam-policies)
* [Policy Updates](#policy-updates)
* [New Compliance Benchmarks and Updates](#new-compliance-benchmarks-and-updates)
* [Changes in Existing Behavior](#changes-in-existing-behavior)
* [REST API Updates](#rest-api-updates)
* [Deprecation Notices](#deprecation-notices)

## Announcement

| **Feature**                                                                                                                                                                               | **Description**                                                                       |
| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------- |
| <p><strong>Base Image updated to RHEL 9</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">32.06.132</mark></p> | The base image used by Defenders is now updated to Red Hat Enterprise Linux (RHEL) 9. |

## New Features

| **Feature**                                                                                                                                                                                                                                                                                                | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Support for Vulnerability Management in Permission Groups</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                | <p>Prisma Cloud now supports vulnerability management for non-system admins in <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/administration/prisma-cloud-admin-permissions">permission groups</a>. They can use Search and Investigate to perform vulnerability searches, use the Vulnerability Dashboard, and Remediate Vulnerabilities.</p><p><img src="/files/W5iksy97icFQn1zcoxWr" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>New Compliance Support for DSPM</strong></p><p><mark style="background-color:orange;">Secure the Data</mark></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                                                    | <p>Prisma Cloud now supports the following compliance standards for Data Security Posture Management (DSPM):</p><ul><li>GDPR</li><li>ISO27001</li><li>NIST</li><li>PCI DSS v4</li><li>SOC 2 Type 2</li></ul><p>Select <strong>Data Security > Compliance</strong> to see the available compliance standards. You can dive deep into each of the frameworks and see all the different risks related to them as well as the percentage, which is based on how many assets are in violation.</p><p><img src="/files/M2Cl1aQgm5DSMtj1bHlJ" alt="" data-size="original"></p><p><img src="/files/GIgnLFmjabLzLSjxFpgH" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><mark style="background-color:orange;">Update</mark> <strong>Code to Cloud Dashboard</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                             | <p>You can now add up to 20 rows on your <strong>Code to Cloud</strong> dashboard. Previously, you could add only up to 5 rows.</p><p><img src="/files/LshYIHf2ZF2obWyqiTQ9" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| <p><strong>Support for PackageJSON v3</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                                                       | Prisma Cloud now supports PackageJSON v3 for JavaScript projects that significantly enhances the SCA scanning capabilities. With this update, Prisma Cloud can successfully build dependency trees and identify both root and transitive packages, providing comprehensive visibility into your project’s dependencies. In addition, Prisma Cloud SCA scanning now matches CVEs to the vulnerable packages found in v3 files, allowing you to quickly address security risks. You can easily view SCA findings directly from Application Security > Projects in the Prisma Cloud console. Additionally, SCA findings are accessible in all supported IDEs, Checkov CLI, and PR comments for all supported version control systems, ensuring seamless integration into your development workflow.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Support for Ansible Scanning</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                                                     | Prisma Cloud now offers support for [scanning](https://docs.prismacloud.io/en/enterprise-edition/content-collections/application-security/supported-technologies) Ansible, a leading Infrastructure as Code (IaC) framework. Prisma Cloud can now scan Ansible templates for misconfigurations throughout the software development lifecycle (SDLC) using it’s out of-the-box policies.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><mark style="background-color:orange;">Update</mark> <strong>Top Risks From Unmanaged Assets Widget</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                              | <p>The <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/dashboards/dashboards-discovery-exposure-management">Top Risks From Unmanaged Assets</a> widget in the Discovery and Exposure Management Dashboard is enhanced to display the top risks based on various categories that affect your security posture due to public exposure of assets on the internet. The risks are categorized as Critical, Exploited, Patchable, Vulnerable, and Exposed. Links offer additional context and options to convert and inspect affected assets, helping you to quickly assess and address potential threats.</p><p><img src="/files/jErDzzDIbpST6eDtvUJ4" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Vulnerabilities Tab</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                                                      | <p>You can explore the new <strong>Vulnerabilities</strong> tab in the side panel while inspecting internet-exposed assets.</p><ul><li><strong>Support for EPSS Scores</strong> - Prisma Cloud now supports EPSS in the Vulnerability Dashboard, Search and Investigate, and Common Vulnerabilities and Exposures (CVE) side panel.</li><li><strong>Support for Internet Exposure in Vulnerability Prioritization</strong> - The prioritization engine now supports Internet Exposure as a risk factor.</li><li><strong>Complete CVE Details</strong> - The CVE side panel now includes a new <strong>CVE Details</strong> tab that provides all the information about a given CVE, such as complete Common Vulnerability Scoring System (CVSS) Risk Factors, EPSS, Exploit information, CISA KEV, and external links.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Improved IAM Risk Management</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                                             | Enhancements to Prisma Cloud’s [IAM policies](https://docs.prismacloud.io/en/enterprise-edition/content-collections/governance/create-an-iam-policy) enable you to proactively manage IAM-related risks and improve your cloud security posture. Gain granular visibility into violations at the entity level by creating IAM policies based on queries that include **granters** (roles/groups/service accounts) as the violating resource. Next, develop remediation to fix IAM policy violations at the granter level or use the **Suggest Least Privileged Access** feature to remediate over-privileged access by select granters.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>Snooze Assets from Inventory Page</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                                        | <p>You now have the option to <strong>Snooze</strong> known internet-exposed assets, such as test or vendor assets, in the <strong>Inventory > Unmanaged Assets</strong> page. Snoozing assets help you to view Active assets separately from Snoozed assets using the Status filter. You can Snooze one or multiple assets at a time. Use the search bar to find your assets. Filter your search results by <strong>Domain</strong> name or <strong>IP Address</strong>.</p><p><img src="/files/eQaufpJGOCbZCo3n3TJQ" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| <p><strong>Account Mapped Status Filter</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                                             | <p>The <strong>Inventory > Unmanaged Assets</strong> page now includes a new <strong>Account Mapped Status</strong> filter. Use this filter to view a comprehensive list of your Mapped assets separately from Unmapped assets.</p><p><strong>Mapped</strong> — Shows exposed assets that are linked to a parent account or organizational unit (OU) accounts on Prisma Cloud. You can secure these assets by onboarding them to Prisma Cloud. <strong>Unmapped</strong> — Shows exposed assets that cannot be linked to a parent account or organizational unit (OU) accounts on Prisma Cloud. You can an Send Email to receive a summary of the assets for further investigation.</p><p><img src="/files/mE4vOy7RtRo0HhAcujzu" alt="" data-size="original"></p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><mark style="background-color:orange;">Update</mark> <strong>Removal of Select All and Deselect All Capabilities in Some Filters</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p> | For better performance, **Select All** and **Deselect All** are no longer supported for the Account Group, Cloud Account, Cloud Account ID, and Policy Name filters.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>Terraform Enterprise (Run Tasks) support for Transporter</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                         | [Terraform Enterprise (Run Tasks)](https://docs.prismacloud.io/en/enterprise-edition/content-collections/application-security/get-started/connect-code-and-build-providers/ci-cd-runs/add-terraform-enterprise-run-tasks#undefined) now includes support for Transporter. The Transporter serves as a communication proxy or broker, facilitating a secure channel between Prisma Cloud and Terraform Enterprise (Run Tasks). This enables seamless integration and management of Terraform Enterprise within your infrastructure while maintaining stringent security measures.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |
| <p><strong>Support for AWS CodeCommit Integration</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                                           | Integrate prisma Cloud with [AWS Code Commit](https://docs.prismacloud.io/en/enterprise-edition/content-collections/application-security/get-started/connect-code-and-build-providers/code-repositories/add-aws-codecommit) version control system (VCS) to gain visibility into, and monitor the systems, technologies, configurations, and pipelines that make up the AWS CodeCommit platform. This integration enables security scans to identify Infrastructure-as-Code (IaC) misconfigurations, Software Composition Analysis (SCA) vulnerabilities, license non-compliance, exposed secrets and CI/CD pipeline risks in your AWS CodeCommit platform. Enhance the security posture for your organization by contextualizing, prioritizing and mitigating issues as soon as they are detected.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                            |
| <p><strong>Enhanced Security for JavaScript Projects: SCA Now Supports Lockfile v3</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                          | <p>SCA support is now available for <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/application-security/risk-management/monitor-and-manage-code-build/software-composition-analysis/sca-troubleshoot">JavaScript Lockfile v3</a>. This added support offers:</p><ul><li>Vulnerability detection and license compliance: Prisma Cloud can now parse, analyze, and report vulnerabilities, and ensure license compliance for projects using package-lock.json v3</li><li>Full dependency tree analysis: Provides a comprehensive view of all dependencies and sub-dependencies to identify potential risks</li><li>Cross-platform support: Supported across Prisma Cloud platforms such as PR comments, Fix PRs, Enforcement, IDE, and CLI</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| <p><strong>Go Symbol Extraction in Prisma Cloud</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">32.06.132</mark></p>                                                                                                          | <p>When scanning Golang binaries, Prisma Cloud extracts Go symbols, which allows for evaluating vulnerabilities accurately with specific package names and symbols. The feature flag for extracting Go symbols is enabled by default. Prisma Cloud also allows you to selectively disable symbol extraction when they are not needed, to optimize the scan.</p><p>To disable this feature, follow these steps:</p><ul><li>Self-hosted edition: Add the environment variable SYMBOL\_EXTRACTION\_ENABLED=False in the twistlock.cfg file.</li><li>SaaS edition: Add the environment variable core-symbol-extraction-enabled=False in the Launch Darkly mode.</li><li>Using twistcli: Add the --disable-symbol-extraction flag to the image scan command.</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Exporting Software Bill of Materials (SBOM) files in CycloneDX version 1.4</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">32.06.132</mark></p>                                                                    | <p>Prisma Cloud now supports <a href="https://docs.prismacloud.io/en/enterprise-edition/content-collections/runtime-security/vulnerability-management/exporting-sboms">exporting Software Bill of Materials (SBOM) files</a> in CycloneDX version 1.4 for functions, images, and hosts scans. SBOM files can be generated in JSON or XML format.</p><p><strong>SBOM Attributes</strong></p><p>The SBOM files contain the following attributes:</p><ul><li>Name: Name of the package</li><li>BOM-REF: Package URL (PURL) if it exists; otherwise, UUID (for applications)</li><li>Package Version: Version number for the package</li><li>Package Author: Applicable only for specific package types such as rpm, jem, apk, and deb</li><li>PURL Identifier: Package URL (PURL) identifier</li><li>License: Package license details</li><li>Timestamp (metadata): Time of printing</li><li>Type (metadata): Type of asset. In all the stages, images are categorized as containers, serverless functions as services, hosts and VMs as frameworks.</li><li>Name (metadata): Asset ID of images, hosts, and functions</li></ul><p>SBOM files can be downloaded either through API calls or twistcli.</p><p>For information about the SBOM API calls, see the <a href="#rest-api-updates">REST API Updates</a> section.</p><p><strong>twistcli Configuration</strong></p><ul><li>Export SBOMs using the new flag: --SBOM \[file\_format]</li><li>File Format Values: cyclonedx\_json or cyclonedx\_xml</li><li>SBOM output is concatenated to the scan results output. Use the --output flag to print scan results and SBOM output to a specified file.</li></ul> |
| <p><strong>Resolving method for cluster name</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">32.06.132</mark></p>                                                                                                             | <p>When deploying Defender to your Kubernetes cluster, Prisma Cloud now provides you the option to use the API server address from the kube config file to resolve cluster names.</p><p>This option ensures that each cluster has a unique cluster name in Prisma Cloud.</p><p>A new field, Cluster name resolving method, has been added to the Manage → Defenders → “Manual Deploy” → Orchestrator → “Orchestrator type = Kubernetes" → Advanced Settings page.</p><p>The <strong>Cluster name resolving method</strong> field has the following options:</p><ul><li><strong>Default</strong>: Allows Prisma Cloud to automatically generate the name based on available information such as kube config, resource group information, and cloud provider metadata endpoints.</li><li><strong>Manual</strong>: Enables you to set the cluster name manually. When you select this option, the "Specify a cluster name" box appears, allowing you to enter the desired name.</li><li><strong>API Server</strong>: Uses the API server address from the kube config file to generate a unique cluster name in Prisma Cloud.</li></ul><p>This enhancement ensures that vulnerability information is accurately reported for each cluster and makes sure that the clean clusters are not misrepresented as vulnerable due to naming conflicts.</p>                                                                                                                                                                                                                                                                                                                |

## API Ingestions

| **Service**                                                                                                                                                                                  | **API Details**                                                                                                                                                                                                                                                                                                                                                                             |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Amazon Comprehend</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                        | <p><strong>aws-comprehend-pii-entities-detection-jobs</strong></p><p>Additional permissions required:</p><ul><li><code>comprehend:ListPiiEntitiesDetectionJobs</code></li><li><code>comprehend:ListTagsForResource</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                 |
| <p><strong>Amazon Comprehend</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                        | <p><strong>aws-comprehend-sentiment-detection-jobs</strong></p><p>Additional permissions required:</p><ul><li><code>comprehend:ListSentimentDetectionJobs</code></li><li><code>comprehend:ListTagsForResource</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                      |
| <p><strong>Amazon Comprehend</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                        | <p><strong>aws-comprehend-key-phrases-detection-jobs</strong></p><p>Additional permissions required:</p><ul><li><code>comprehend:ListKeyPhrasesDetectionJobs</code></li><li><code>comprehend:ListTagsForResource</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                   |
| <p><strong>AWS Service Catalog</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                      | <p><strong>aws-servicecatalog-principals-for-portfolio</strong></p><p>Additional permissions required:</p><ul><li><code>servicecatalog:ListPortfolios</code></li><li><code>servicecatalog:ListPrincipalsForPortfolio</code></li></ul><p>You must manually add the above permissions to the CFT template to enable them.</p>                                                                 |
| <p><mark style="background-color:orange;">Update</mark> <strong>Amazon Route53</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                      | <p><strong>aws-route53-list-hosted-zones</strong></p><p>The following fields are excluded from the resource JSON for this API:</p><ul><li><code>resourceRecordSet\[*].region</code></li><li><code>resourceRecordSet\[*].trafficPolicyInstanceId</code></li><li><code>resourceRecordSet\[\*].ttl</code></li></ul>                                                                            |
| <p><mark style="background-color:orange;">Update</mark> <strong>AWS Trusted Advisor</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                 | <p><strong>aws-trusted-advisor-check-result</strong></p><p>The <code>flaggedResources</code> field with the status <code>OK</code> is excluded from the resource JSON for this API.</p>                                                                                                                                                                                                     |
| <p><strong>Azure Active Directory</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                   | <p><strong>azure-active-directory-user-registration-details</strong></p><p>Additional permission required:</p><ul><li><code>AuditLog.Read.All</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                               |
| <p><strong>Azure App Service</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                        | <p><strong>azure-app-service-web-apps-functions</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Web/sites/Read</code></li><li><code>Microsoft.web/sites/functions/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                                          |
| <p><mark style="background-color:orange;">Update</mark> <strong>Azure App Service</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                   | <p><strong>azure-app-service-plan</strong></p><p>The <code>zoneRedundant</code> field is now included in the resource JSON for this API. When <code>zoneRedundant</code> is set to <code>true</code>, the <code>azure-app-service-plan</code> API will automatically perform availability zone balancing.</p>                                                                               |
| <p><strong>Azure Compute</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                            | <p><strong>azure-compute-disk-encryption-sets</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Compute/diskEncryptionSets/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                     |
| <p><strong>Azure Databricks</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                         | <p><strong>azure-databricks-diagnostic-settings</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Databricks/workspaces/read</code></li><li><code>Microsoft.Insights/DiagnosticSettings/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                                      |
| <p><strong>Azure NetApp Files</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                       | <p><strong>azure-netappfiles-volumes</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.NetApp/netAppAccounts/capacityPools/volumes/read</code></li><li><code>Microsoft.NetApp/netAppAccounts/read</code></li><li><code>Microsoft.NetApp/netAppAccounts/capacityPools/read</code></li></ul><p>The Reader role includes the permissions.</p>                         |
| <p><strong>Google Vertex AI</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                         | <p><strong>gcloud-vertex-ai-workbench-instance</strong></p><p>Additional permissions required:</p><ul><li><code>notebooks.instances.list</code></li><li><code>notebooks.instances.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                                                                                                             |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                              | <p><strong>gcloud-vertex-ai-aiplatform-monitoring-job</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.modelDeploymentMonitoringJobs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                         |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                              | <p><strong>gcloud-vertex-ai-aiplatform-persistent-resource</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.persistentResources.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                              |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                              | <p><strong>gcloud-vertex-ai-aiplatform-vizier-study</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.studies.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                 |
| <p><strong>Google Vertex AI AIPlatform</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                              | <p><strong>gcloud-vertex-ai-aiplatform-tuning-job</strong></p><p>Additional permission required:</p><ul><li><code>aiplatform.tuningJobs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                |
| <p><strong>Amazon CloudFront</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                        | <p><strong>aws-cloudfront-response-headers-policy</strong></p><p>Additional permissions required:</p><ul><li><code>cloudfront:ListResponseHeadersPolicies</code></li><li><code>cloudfront:GetResponseHeadersPolicy</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                 |
| <p><strong>AWS Database Migration Service</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                           | <p><strong>aws-dms-replication-task</strong></p><p>Additional permissions required:</p><ul><li><code>dms:DescribeReplicationTasks</code></li><li><code>dms:ListTagsForResource</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                                     |
| <p><strong>AWS Network Firewall</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                     | <p><strong>aws-network-firewall-rule-group</strong></p><p>Additional permissions required:</p><ul><li><code>network-firewall:ListRuleGroups</code></li><li><code>network-firewall:DescribeRuleGroup</code></li></ul><p>The Security Audit role includes the permissions.</p>                                                                                                                |
| <p><strong>AWS Glue</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                                 | <p><strong>aws-glue-resource-policy</strong></p><p>Additional permission required:</p><ul><li><code>glue:GetResourcePolicies</code></li></ul><p>You must manually add the above permission to the CFT template to enable it.</p>                                                                                                                                                            |
| <p><strong>AWS Macie</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                                | <p><strong>aws-macie2-classification-job</strong></p><p>Additional permission required:</p><ul><li><code>macie2:ListClassificationJobs</code></li></ul><p>You must manually add the above permission to the CFT template to enable it.</p>                                                                                                                                                  |
| <p><strong>Azure Monitor</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                            | <p><strong>azure-monitor-action-groups</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.Insights/ActionGroups/Read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                 |
| <p><strong>Azure Log Analytics</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                      | <p><strong>azure-log-analytics-clusters</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.OperationalInsights/clusters/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                         |
| <p><strong>Azure App Service</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                        | <p><strong>azure-app-service-private-endpoint-connections</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Web/sites/Read</code></li><li><code>Microsoft.Web/sites/privateEndpointConnections/Read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                               |
| <p><strong>Azure Event Grid</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                         | <p><strong>azure-event-grid-namespaces</strong></p><p>Additional permission required:</p><ul><li><code>Microsoft.EventGrid/namespaces/read</code></li></ul><p>The Reader role includes the permission.</p>                                                                                                                                                                                  |
| <p><strong>Azure Virtual Network</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                    | <p><strong>azure-network-private-dns-zone-groups</strong></p><p>Additional permissions required:</p><ul><li><code>Microsoft.Network/privateEndpoints/read</code></li><li><code>Microsoft.Network/privateEndpoints/privateDnsZoneGroups/read</code></li></ul><p>The Reader role includes the permissions.</p>                                                                                |
| <p><strong>Google Storage Transfer</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                  | <p><strong>gcloud-storage-transfer-agent-pool</strong></p><p>Additional permission required:</p><ul><li><code>storagetransfer.agentpools.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                               |
| <p><strong>Google Storage Transfer</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                  | <p><strong>gcloud-storage-transfer-job</strong></p><p>Additional permission required:</p><ul><li><code>storagetransfer.jobs.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                                            |
| <p><strong>Google Cloud Workstation</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                 | <p><strong>gcloud-cloud-workstation-configuration</strong></p><p>Additional permissions required:</p><ul><li><code>workstations.workstationClusters.list</code></li><li><code>workstations.workstationConfigs.list</code></li><li><code>workstations.workstationConfigs.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p>                                       |
| <p><strong>Google Cloud Workstation</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                 | <p><strong>gcloud-cloud-workstation-cluster</strong></p><p>Additional permission required:</p><ul><li><code>workstations.workstationClusters.list</code></li></ul><p>The Viewer role includes the permission.</p>                                                                                                                                                                           |
| <p><strong>Google Cloud Workstation</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                                 | <p><strong>gcloud-cloud-workstation</strong></p><p>Additional permissions required:</p><ul><li><code>workstations.workstationClusters.list</code></li><li><code>workstations.workstationConfigs.list</code></li><li><code>workstations.workstations.list</code></li><li><code>workstations.workstationConfigs.getIamPolicy</code></li></ul><p>The Viewer role includes the permissions.</p> |
| <p><mark style="background-color:orange;">Update</mark> <strong>GCP Vertex AI Platform Pipeline Job</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p> | <p><strong>gcloud-vertex-ai-aiplatform-pipeline-job</strong></p><p>A new <code>runtimeConfig</code> field and it’s sub-fields are now ingested as part of this update.</p>                                                                                                                                                                                                                  |

## New Policies

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><p><strong>AWS ECR private repository tag mutable</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies AWS ECR private repositories whose tag immutability is not configured.</p><p>AWS Elastic Container Registry (ECR) tag immutability ensures that once an image is pushed to a repository with tag immutability enabled, the tag cannot be overwritten or updated. This feature is useful for ensuring the security, integrity, and reliability of container images in production environments. It prevents tags from being overwritten, which can help prevent unauthorised changes to images.</p><p>It is recommended to enable tag immutability on ECR repositories to maintain the integrity and security of the images pushed.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-ecr-get-repository-policy' AND json.rule = imageTagMutability equal ignore case mutable
</code></pre></td></tr><tr><td><p><strong>AWS IAM group not in use</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies AWS IAM groups that are not actively in use.</p><p>An AWS IAM group is a collection of IAM users managed together, allowing for unified permission assignment. These groups, if not assigned any users, pose a potential security risk if left unmanaged and can inadvertently grant unauthorized access to AWS services and resources.</p><p>It is recommended to review and remove any unused IAM groups to prevent attaching unauthorized IAM users.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-iam-list-users' as X; config from cloud.resource where api.name = 'aws-iam-list-groups' as Y; filter ' not ($.X.groupList[*] intersects  $.Y.groupName)'; show Y;
</code></pre></td></tr><tr><td><p><strong>AWS Opensearch domain audit logging disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies AWS Opensearch domains with audit logging disabled.</p><p>Opensearch audit logs enable you to monitor user activity on your Elasticsearch clusters, such as authentication successes and failures, OpenSearch requests, index updates, and incoming search queries.</p><p>It is recommended to enable audit logging for an Elasticsearch domain to audit activity in the domain.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-es-describe-elasticsearch-domain' AND json.rule = domainProcessingStatus equal ignore case active and (logPublishingOptions does not exist or logPublishingOptions.AUDIT_LOGS.enabled is false)
</code></pre></td></tr><tr><td><p><strong>AWS Opensearch domain Error logging disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies AWS Opensearch domains with no error logging configuration.</p><p>Opensearch application logs contain information about errors and warnings raised during the operation of the service and can be useful for troubleshooting. Error logs from domains can aid in security assessments, access monitoring, and troubleshooting availability problems.</p><p>It is recommended to enable the AWS Opensearch domain with error logs, which will help in security audits and troubleshooting.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-es-describe-elasticsearch-domain' AND json.rule = domainProcessingStatus equal ignore case active and (logPublishingOptions does not exist or logPublishingOptions.ES_APPLICATION_LOGS.enabled is false)
</code></pre></td></tr><tr><td><p><strong>AWS S3 bucket used for storing AWS Sagemaker training job output</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies the AWS S3 bucket used for storing AWS Sagemaker training job output.</p><p>S3 buckets hold the results and artifacts generated from training machine learning models in Sagemaker. Ensuring proper configuration and access control is crucial to maintain the security and integrity of the training output. Improperly secured S3 buckets used for storing AWS Sagemaker training output can lead to unauthorized access, data breaches, and potential exposure of sensitive model information.</p><p>It is recommended to implement strict access controls, enable encryption, and audit permissions to secure AWS S3 buckets for AWS Sagemaker training job output and ensure compliance.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-s3api-get-bucket-acl' as X; config from cloud.resource where api.name = 'aws-sagemaker-training-job' as Y; filter '$.Y.OutputDataConfig.bucketName equals $.X.bucketName'; show X;
</code></pre></td></tr><tr><td><p><strong>AWS S3 bucket is utilized for AWS Sagemaker training job data</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies the AWS S3 bucket used for AWS Sagemaker training job data input.</p><p>S3 buckets store the datasets required for training machine learning models in Sagemaker. Proper configuration and access control are essential to ensure the security and integrity of the training data. Improperly configured S3 buckets used for AWS Sagemaker training data can lead to unauthorized access, data breaches, and potential loss of sensitive information.</p><p>It is recommended to implement strict access controls, enable encryption, and audit permissions to secure AWS S3 buckets for AWS Sagemaker training data and ensure compliance.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-s3api-get-bucket-acl' as X; config from cloud.resource where api.name = 'aws-sagemaker-training-job' as Y; filter '$.Y.InputDataConfig[*].DataSource.S3DataSource.bucketName intersects $.X.bucketName'; show X;
</code></pre></td></tr><tr><td><p><strong>Azure Key vault used for machine learning workspace secrets storage is not enabled with audit logging</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies Azure Key vaults used for machine learning workspace secrets storage that are not enabled with audit logging.</p><p>Azure Key vaults are used to store machine learning workspace secrets and other sensitive information that is needed by the workspace. Enabling key vaults with audit logging will help in monitoring how and when machine learning workspace secrets are accessed, and by whom. This audit log data enhances visibility by providing valuable insights into the trail of interactions involving confidential information.</p><p>As a best practice, it is recommended to enable audit event logging for key vaults used for machine learning workspace secrets storage.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-machine-learning-workspace' AND json.rule = properties.keyVault exists as X; config from cloud.resource where api.name = 'azure-key-vault-list' AND json.rule =  "not (diagnosticSettings.value[*].properties.logs[*].enabled any equal true and diagnosticSettings.value[*].properties.logs[*].enabled size greater than 0)" as Y; filter '$.X.properties.keyVault contains $.Y.name'; show Y;
</code></pre></td></tr><tr><td><p><strong>Azure Storage Account storing Cognitive service diagnostic logs is publicly accessible</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies Azure Storage Accounts storing Cognitive service diagnostic logs are publicly accessible.</p><p>Azure Storage account stores Cognitive service diagnostic logs which might contain detailed information of platform logs, resource logs, trace logs and metrics. Diagnostic log data may contain sensitive data and helps in identifying potentially malicious activity. The attacker could exploit publicly accessible storage account to get cognitive diagnostic data logs and could breach into the system by leveraging exposed data and propagate across your system.</p><p>As a best security practice, it is recommended to restrict storage account access to only the services as per business requirement.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'azure-cognitive-services-account-diagnostic-settings' AND json.rule = (properties.logs[?any(enabled equal ignore case "true")] exists or properties.metrics[?any( enabled equal ignore case "true" )] exists) and properties.storageAccountId exists as X; config from cloud.resource where api.name = 'azure-storage-account-list' AND json.rule = 'totalPublicContainers > 0 and (properties.allowBlobPublicAccess is true or properties.allowBlobPublicAccess does not exist)' as Y; filter '$.X.properties.storageAccountId contains $.Y.id'; show Y;
</code></pre></td></tr><tr><td><p><strong>Azure Application Gateway WAF policy is not enabled in prevention mode</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies the Azure Application Gateway WAF policies that are not enabled in prevention mode.</p><p>Azure Application Gateway WAF policies support Prevention and Detection modes. Detection mode monitors and logs all threat alerts to a log file. Detection mode is useful for testing purposes and configures WAF initially but it does not provide protection. It logs the traffic, but it doesn’t take any actions such as allow or deny. Where as, in Prevention mode, WAF analyzes incoming traffic to the application gateway and blocks any requests that are determined to be malicious based on a set of rules.</p><p>As a best security practice, it is recommended to enable Application Gateway WAF policies with Prevention mode to prevent malicious requests from reaching your application and potentially causing damage.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-application-gateway-waf-policy' AND json.rule = properties.applicationGateways[*].id size greater than 0 and properties.policySettings.state equal ignore case Enabled and properties.policySettings.mode does not equal ignore case Prevention
</code></pre></td></tr><tr><td><p><strong>GCP Storage Bucket storing GCP Vertex AI training pipeline output model</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies publicly exposed GCS buckets that are used to store the GCP Vertex AI training pipeline output model.</p><p>GCP Vertex AI training pipeline output models are stored in the Storage bucket. Vertex AI training pipeline output model is considered sensitive and confidential intellectual property and its storage location should be checked regularly. The storage location should be as per your organization’s security and compliance requirements.</p><p>It is recommended to monitor, identify, and evaluate storage location for the GCP Vertex AI training pipeline output model regularly to prevent unauthorized access and AI model thefts.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-storage-buckets-list' as X; config from cloud.resource where api.name = 'gcloud-vertex-ai-aiplatform-training-pipeline' as Y; filter ' $.Y.trainingTaskOutputDirectory contains $.X.id '; show X;
</code></pre></td></tr><tr><td><p><strong>GCP Storage Bucket storing Vertex AI model</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies publicly exposed GCS buckets that are used to store the GCP Vertex AI model.</p><p>GCP Vertex AI models (except AutoML Models) are stored in the Storage bucket. Vertex AI model is considered sensitive and confidential intellectual property and its storage location should be checked regularly. The storage location should be as per your organization’s security and compliance requirements.</p><p>It is recommended to monitor, identify, and evaluate storage location for GCP Vertex AI model regularly to prevent unauthorized access and AI model thefts.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-storage-buckets-list' as X; config from cloud.resource where api.name = 'gcloud-vertex-ai-aiplatform-model' as Y; filter ' $.Y.artifactUri contains $.X.id '; show X;
</code></pre></td></tr><tr><td><p><strong>GCP Storage Bucket storing GCP Vertex AI pipeline output data</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies publicly exposed GCS buckets that are used to store GCP Vertex AI pipeline output data.</p><p>GCP Vertex AI pipeline output data is stored in the Storage Bucket. This output data is considered sensitive and confidential intellectual property and its storage location should be checked regularly. The storage location should be as per the organization’s security and compliance requirements.</p><p>It is recommended to monitor, identify, and evaluate storage location for GCP Vertex AI pipeline output data regularly to prevent unauthorized access and AI model thefts.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-storage-buckets-list' as X; config from cloud.resource where api.name = 'gcloud-vertex-ai-aiplatform-pipeline-job' as Y; filter ' $.Y.runtimeConfig.gcsOutputDirectory contains $.X.id '; show X;
</code></pre></td></tr><tr><td><p><strong>OCI VCN subnet flow logging is disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies Virtual Cloud Network (VCN) subnets that have flow logs disabled.</p><p>Enabling VCN flow logs enables you to monitor traffic flowing within your virtual network and can be used to detect anomalous traffic. Without the flow logs turned on, it is not possible to get any visibility into network traffic.</p><p>It is recommended to enable a VCN flow log on each of your VCN subnets.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'oci-networking-subnet' as X; config from cloud.resource where api.name = 'oci-logging-logs' AND json.rule = lifecycleState equals ACTIVE and isEnabled is true and configuration.source.service contains flowlogs as Y; filter 'not ($.X.id contains $.Y.configuration.source.resource)'; show X;
</code></pre></td></tr><tr><td><p><strong>OCI Oracle Analytics Cloud (OAC) access is not restricted to allowed sources or deployed within a Virtual Cloud Network</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies Oracle Analytics Cloud (OAC) instances that are not restricted to specific sources or not deployed within a Virtual Cloud Network (VCN).</p><p>OAC is a scalable service for enterprise analytics, and restricting its access to corporate IP addresses or VCNs enhances security by reducing exposure to unauthorized access. Deploying OAC instances within a VCN and implementing access control rules is essential for protecting sensitive data. This ensures that only authorized sources can connect to OAC, mitigating risks and maintaining data integrity.</p><p>As best practice, it is recommended to have new OAC instances deployed within a VCN, and existing instances should have access control rules configured to allow only approved sources.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'oci-analytics-instance' AND json.rule = lifecycleState equal ignore case ACTIVE AND networkEndpointDetails.networkEndpointType equal ignore case PUBLIC AND (networkEndpointDetails.whitelistedServices is empty AND networkEndpointDetails.whitelistedIps is empty AND networkEndpointDetails.whitelistedVcns is empty)
</code></pre></td></tr><tr><td><p><strong>OCI Oracle Autonomous Database (ADB) access is not restricted to allowed sources or deployed within a Virtual Cloud Network</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy identifies Oracle Autonomous Databases (ADBs) that are not restricted to specific sources or not deployed within a Virtual Cloud Network (VCN).</p><p>Autonomous Database automates critical database management tasks, and restricting its access to corporate IP addresses or VCNs is crucial for enhancing security. Deploying Autonomous Databases within a VCN and configuring access control rules ensure that only authorized sources can connect, significantly reducing the risk of unauthorized access. This protection is vital for maintaining the integrity and security of the databases.</p><p>As best practice, it is recommended to have new Autonomous Database instances deployed within a VCN, and existing instances should have access control rules set to restrict connectivity to approved sources.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'oci-database-autonomous-database' AND json.rule = lifecycleState contains AVAILABLE AND whitelistedIps is member of ("null") AND privateEndpoint is member of ("null")
</code></pre></td></tr><tr><td><p><strong>Anthropic API key detected in code</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>An Anthropic API Key is used to access Anthropic’s artificial intelligence services via API. This key enables developers to seamlessly connect to Anthropic’s AI models, facilitating a variety of applications such as natural language processing, predictive analytics, and machine learning tasks. The API key serves as a secure credential, ensuring that only authorized applications and users have access to Anthropic’s AI services, thus safeguarding the data and the integrity of the services provided. Regular review and management of API keys are vital to ensuring robust security in your integrations with Anthropic’s advanced AI platforms.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Subtype—</strong> Build</p></td></tr><tr><td><p><strong>Azure Functions HTTP Trigger Key detected in code</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>An Azure Functions HTTP Trigger Key is crucial for securing HTTP-triggered Azure Functions, restricting access to authorized clients. This key is essential for preventing unauthorized data exposure and manipulation through the function. Securely managing this key is imperative to maintain the integrity and security of applications relying on Azure Functions. Regular checks and updates of your security settings and keys are crucial for maintaining a robust security posture.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Subtype—</strong> Build</p></td></tr><tr><td><p><strong>GCP Cloud Function configured with overly permissive Ingress setting</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy checks whether GCP Cloud Functions are configured with overly permissive Ingress settings. Overly permissive Ingress settings allow all inbound requests to the function, both from the public and from resources within the same project. It is recommended to restrict the traffic to improve network-based access control, allowing traffic only from VPC networks within the same project or through the Cloud Load Balancer.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Subtype—</strong> Run, Build</p></td></tr><tr><td><p><strong>GKE NodePool configuration managed at cluster level</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>This policy checks whether Google Kubernetes Engine (GKE) clusters uses NodePools within their configuration. The reason for this check is that using NodePools in the cluster configuration can unnecessarily complicate cluster management. When NodePools are used at the cluster level, modifying the node configuration creates a new NodePool, increasing operational complexity. Additionally, failing to delete older NodePools after creating new ones can lead to excess resource consumption. It is recommended to manage node configurations separately from the cluster to prevent these issues.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Subtype—</strong> Build</p></td></tr><tr><td><p><strong>Hugging Face token detected in code</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>A Hugging Face Token is used to access Hugging Face’s API for machine learning services, including models, and datasets. This token verifies identity and grants API access, ensuring a secure connection between your application and Hugging Face’s services. Regular management of tokens is crucial for maintaining security, ensuring data privacy and integrity, and preventing unauthorized access.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Subtype—</strong> Build</p></td></tr><tr><td><p><strong>Microsoft Teams webhook detected in code</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>Webhooks and connectors facilitate the connection of web services to channels and teams in Microsoft Teams. Webhooks are user-defined HTTP callbacks that notify users about any action that has occurred in the MS Teams channel. Regularly reviewing and managing webhooks and their usage within your Teams setup is vital for ongoing security.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Subtype—</strong> Build</p></td></tr><tr><td><p><strong>Terraform module sources do not use a git url with a commit hash revision</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>Terraform modules are a collection of multiple resource configuration to offer an easy way of repeatable and reusable code logic. The most common way is to consume them through the public Terraform registry, which are connected to a VCS, like GitHub. This approach is problematic, because the module versions are not immutable and the module can be changed without changing the version, which makes the code vulnerable to a Supply Chain Attack. Therefore it is recommended to leverage Git URLs with a commit hash revision to guarantee immutability and consistency.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Subtype—</strong> Build</p></td></tr><tr><td><p><strong>Terraform module sources do not use a git url with a tag or commit hash revision</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p>Terraform modules are a collection of multiple resource configuration to offer an easy way of repeatable and reusable code logic. The most common way is to consume them through the public Terraform registry, which are connected to a VCS, like GitHub. This approach is problematic, because the module versions are not immutable and the module can be changed without changing the version, which makes the code vulnerable to a Supply Chain Attack. Therefore it is recommended to leverage Git URLs with a commit hash revision to guarantee immutability and consistency. Git tags can be used as well, but are not as immutable as a hash and therefore acceptable, but less preferred. This policy is a less restrictive version of the <a href="https://docs.prismacloud.io/en/enterprise-edition/policy-reference/supply-chain-policies/terraform-policies/ensure-terraform-module-sources-use-git-url-with-commit-hash-revision">Terraform module sources do not use a git url with a commit hash revision</a> policy that only allows for hashes.</p><p><strong>Policy Severity—</strong> High</p><p><strong>Policy Type—</strong> Config</p><p><strong>Policy Subtype—</strong> Build</p></td></tr><tr><td><p><strong>AWS Secret Manager secret not used for more than 90 days</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies the AWS Secret Manager secret not accessed within 90 days.</p><p>AWS Secret Manager securely stores and manages sensitive information like API keys, passwords, and certificates. Leaving unused secrets in AWS Secret Manager increases the risk of security breaches by providing unnecessary access points for attackers, potentially leading to unauthorized data access or leaks.</p><p>It is recommended to routinely review and delete unused secrets to limit the attack surface and risk of unauthorized access.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-secretsmanager-describe-secret' AND json.rule = '(lastAccessedDate does not exist and _DateTime.ageInDays(createdDate) > 90) or (lastAccessedDate exists and _DateTime.ageInDays(lastAccessedDate) > 90)'
</code></pre></td></tr><tr><td><p><strong>AWS Aurora MySQL DB cluster does not publish audit logs to CloudWatch Logs</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies AWS Aurora MySQL DB cluster where audit logging is disabled or audit logs are not published to Amazon CloudWatch Logs.</p><p>Aurora MySQL DB cluster integrates with Amazon CloudWatch for performance metrics gathering and analysis, supporting CloudWatch Alarms. While the Aurora MySQL DB cluster provides customizable audit logs for monitoring database operations, these logs are not automatically sent to CloudWatch Logs, limiting centralized monitoring and analysis of database activities.</p><p>It is recommended to configure the Aurora MySQL DB cluster to enable audit logs and their publishing to CloudWatch.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-rds-db-cluster' AND json.rule = engine equals "aurora-mysql" and status equals "available" as X; config from cloud.resource where api.name = 'aws-rds-db-cluster-parameter-group' AND json.rule = DBParameterGroupFamily contains "aurora-mysql" as Y; filter '$.X.dBclusterParameterGroupArn equals $.Y.DBClusterParameterGroupArn and (($.Y.parameters.server_audit_logging.ParameterValue does not exist or $.Y.parameters.server_audit_logging.ParameterValue equals 0) or ($.X.enabledCloudwatchLogsExports does not contain "audit" and $.Y.parameters.server_audit_logs_upload.ParameterValue equals 0))' ; show X;
</code></pre></td></tr><tr><td><p><strong>AWS AppSync GraphQL API is authenticated with API key</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies the AWS AppSync Graphql API using the API key for primary or additional authentication methods.</p><p>AWS AppSync GraphQL API is a fully managed service by Amazon Web Services for building scalable and secure GraphQL APIs. An API key is a hard-coded value in your application generated by the AWS AppSync service when you create an unauthenticated GraphQL endpoint. Using API keys for authentication can pose security risks such as exposure to unauthorized access and limited control over access privileges, potentially compromising sensitive data and system integrity.</p><p>It is recommended to use authentication methods other than API Keys like IAM, Amazon Cognito User Pools, or OpenID Connect providers for securing AWS AppSync GraphQL APIs, to ensure enhanced security and access control.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-appsync-graphql-api' AND json.rule = authenticationType equals "API_KEY" or additionalAuthenticationProviders[?any( authenticationType equals "API_KEY" )] exists
</code></pre></td></tr><tr><td><p><strong>AWS Network Firewall is not configured with logging configuration</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies an AWS Network Firewall where logging is not configured.</p><p>AWS Network Firewall manages inbound and outbound traffic for the AWS resources within the AWS environment. Logging configuration for the network firewall involves enabling logging of network traffic, including allowed and denied requests, to provide visibility into network activity. Failure to configure logging results in a lack of visibility into potential security threats, making it difficult to detect and respond to malicious activity effectively and hindering threat detection and compliance.</p><p>It is recommended to enable logging to ensure comprehensive monitoring, threat detection, compliance adherence, and effective incident response.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'aws-networkfirewall-firewall' AND json.rule = FirewallStatus.Status equals "READY" as X; config from cloud.resource where api.name = 'aws-network-firewall-logging-configuration' AND json.rule = LoggingConfiguration.LogDestinationConfigs[*].LogType does not exist as Y; filter '$.X.Firewall.FirewallArn equal ignore case $.Y.FirewallArn' ; show X;
</code></pre></td></tr><tr><td><p><strong>AWS Security Hub is not enabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies the AWS Security Hub that is not enabled in specific regions.</p><p>AWS Security Hub is a centralized security management service by Amazon Web Services, providing a comprehensive view of your security posture and automating security checks across AWS accounts. Failure to enable AWS Security Hub in all regions may lead to limited visibility and compromised threat detection across your AWS environment.</p><p>It is recommended to enable AWS Security Hub in all regions for consistent visibility and enhanced threat detection across your AWS environment.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-securityhub-hub' AND json.rule = SubscribedAt exists as X; count(X) less than 1
</code></pre></td></tr><tr><td><p><strong>AWS ECS task definition logging configuration disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies AWS ECS task definitions that have logging configuration disabled.</p><p>AWS ECS logging involves capturing and storing container logs for monitoring, troubleshooting, and analysis purposes within the Amazon ECS environment. Collecting data from task definitions gives visibility, which can aid in debugging processes and determining the source of issues.</p><p>It is recommended to configure logging for an AWS ECS task definition.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-ecs-describe-task-definition' AND json.rule = status equals ACTIVE and containerDefinitions[?any(logConfiguration.logDriver does not exist)] exists
</code></pre></td></tr><tr><td><p><strong>AWS EC2 Client VPN endpoints client connection logging disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies AWS EC2 client VPN endpoints with client connection logging disabled.</p><p>AWS Client VPN endpoints enable remote clients to securely connect to resources in the Virtual Private Cloud (VPC). Connection logs enable you to track user behaviour on the VPN endpoint and gain visibility.</p><p>It is recommended to enable connection logging for AWS EC2 client VPN endpoints.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-ec2-client-vpn-endpoint' AND json.rule = status.code equal ignore case available and connectionLogOptions.Enabled is false
</code></pre></td></tr><tr><td><p><strong>AWS EventBridge event bus with no resource-based policy attached</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies AWS EventBridge event buses with no resource-based policy attached.</p><p>AWS EventBridge is a serverless event bus service that enables businesses to quickly and easily integrate applications, services, and data across multiple cloud environments. By default, an EventBridge custom event bus lacks a resource-based policy associated with it, which allows principals in the account to access the event bus.</p><p>It is recommended to attach a resource based policy to the event bus to limit access scope to fewer entities.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-events-eventbus' AND json.rule = Policy does not exist
</code></pre></td></tr><tr><td><p><strong>AWS WAF Rule Group CloudWatch metrics disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies the AWS WAF Rule Group having CloudWatch metrics disabled.</p><p>AWS WAF rule groups have CloudWatch metrics that provide information about the number of allowed and blocked web requests, counted requests, and requests that pass through without matching any rule in the rule group. These metrics can be used to monitor and analyse the performance of the web access control list (web ACL) and its associated rules.</p><p>It is recommended to enable CloudWatch metrics for a WAF rule group to help in monitoring and analysis of web requests.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-waf-v2-rule-group' AND json.rule = VisibilityConfig.CloudWatchMetricsEnabled is false or Rules[?any( VisibilityConfig.CloudWatchMetricsEnabled is false)] exists
</code></pre></td></tr><tr><td><p><strong>AWS Step Function state machines logging disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies AWS Step Function state machines with logging disabled.</p><p>AWS Step Functions uses state machines to define and execute workflows that coordinate the components of distributed applications and microservices. Step Functions logs state machine executions to Amazon CloudWatch Logs for debugging and monitoring purposes.</p><p>It is recommended to enable logging on the Step Function state machine to maintain reliability, availability, and performance.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-step-functions-statemachine' AND json.rule = loggingConfiguration.level equal ignore case off
</code></pre></td></tr><tr><td><p><strong>Azure Application Insights configured with overly permissive network access</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies Application Insights configured with overly permissive network access.</p><p>Virtual network access configuration in Application Insights allows you to restrict data ingestion and queries coming from the public networks.</p><p>It is recommended to configure the Application Insight with virtual networks access configuration set to restrict; so that the Application Insight is accessible only to restricted Azure Monitor private link scopes.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-application-insights-component' AND json.rule = properties.provisioningState equals Succeeded and (properties.publicNetworkAccessForQuery equals Enabled or properties.publicNetworkAccessForIngestion equals Enabled)
</code></pre></td></tr><tr><td><p><strong>Azure Application Insights not configured with Azure Active Directory (Azure AD) authentication</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies Application Insights that are not configured with Azure Active Directory (AAD) authentication and are enabled with local authentication.</p><p>Disabling local authentication and using AAD-based authentication enhances the security and reliability of the telemetry used to make both critical operational and business decisions.</p><p>It is recommended to configure the Application Insights with Azure Active Directory (AAD) authentication so that all actions are strongly authenticated.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-application-insights-component' AND json.rule = properties.provisioningState equals Succeeded and (properties.DisableLocalAuth does not exist or properties.DisableLocalAuth is false)
</code></pre></td></tr><tr><td><p><strong>Azure Log Analytics configured with overly permissive network access</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies Log Analytics configured with overly permissive network access.</p><p>Virtual network access configuration in Log Analytics allows you to restrict data ingestion and queries coming from the public networks.</p><p>It is recommended to configure the Log Analytics with virtual networks access configuration set to restrict; so that the Log Analytics is accessible only to restricted Azure Monitor private link scopes.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-log-analytics-workspace' AND json.rule = properties.provisioningState equals Succeeded and (properties.publicNetworkAccessForQuery equals Enabled or properties.publicNetworkAccessForIngestion equals Enabled)
</code></pre></td></tr><tr><td><p><strong>Azure storage account infrastructure encryption is disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>The policy identifies Azure storage accounts for which infrastructure encryption is disabled.</p><p>Infrastructure double encryption adds a second layer of encryption using service-managed keys. When infrastructure encryption is enabled for a storage account or an encryption scope, data is encrypted twice. Once at the service level and once at the infrastructure level - with two different encryption algorithms and two different keys. Infrastructure encryption is recommended for scenarios where double encrypted data is necessary for compliance requirements.</p><p>It is recommended to enable infrastructure encryption on Azure storage accounts so that encryption can be implemented at the layer closest to the storage device or network wires.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-storage-account-list' AND json.rule = properties.provisioningState equal ignore case Succeeded and (properties.encryption.requireInfrastructureEncryption does not exist or properties.encryption.requireInfrastructureEncryption is false)
</code></pre></td></tr><tr><td><p><strong>Azure Activity log alert for Create or update public IP address rule does not exist</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>The policy identifies Azure storage accounts for which infrastructure encryption is disabled.</p><p>Infrastructure double encryption adds a second layer of encryption using service-managed keys. When infrastructure encryption is enabled for a storage account or an encryption scope, data is encrypted twice. Once at the service level and once at the infrastructure level - with two different encryption algorithms and two different keys. Infrastructure encryption is recommended for scenarios where double encrypted data is necessary for compliance requirements.</p><p>It is recommended to enable infrastructure encryption on Azure storage accounts so that encryption can be implemented at the layer closest to the storage device or network wires.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-activity-log-alerts' AND json.rule = "location equal ignore case Global and properties.enabled equals true and properties.scopes[*] does not contain resourceGroups and properties.condition.allOf[?(@.field=='operationName')].equals equals Microsoft.Network/publicIPAddresses/write" as X; count(X) less than 1
</code></pre></td></tr><tr><td><p><strong>Azure Activity log alert for Delete public IP address rule does not exist</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies the Azure accounts in which activity log alert for Delete public IP address rule does not exist.</p><p>Creating an activity log alert for Delete public IP address rule gives insight into network rule access changes and may reduce the time it takes to detect suspicious activity. By enabling this monitoring, you get alerts whenever any deletions are made to public IP addresses rules.</p><p>As a best practice, it is recommended to have an activity log alert for Delete public IP address rule to enhance network security monitoring and detect suspicious activities.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-activity-log-alerts' AND json.rule = "location equal ignore case Global and properties.enabled equals true and properties.scopes[*] does not contain resourceGroups and properties.condition.allOf[?(@.field=='operationName')].equals equals Microsoft.Network/publicIPAddresses/delete" as X; count(X) less than 1
</code></pre></td></tr><tr><td><p><strong>GCP Vertex AI Workbench user-managed notebook auto-upgrade is disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies GCP Vertex AI Workbench user-managed notebooks that have auto-upgrade disabled.</p><p>Auto-upgrading Google Cloud Vertex environments ensures timely security updates, bug fixes, and compatibility with APIs and libraries. It reduces security risks associated with outdated software, enhances stability, and enables access to new features and optimizations.</p><p>It is recommended to enable auto-upgrade to minimize maintenance overhead and mitigate security risks.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-notebook-instance' AND json.rule = state equals "ACTIVE" and metadata.notebook-upgrade-schedule does not exist
</code></pre></td></tr><tr><td><p><strong>GCP Vertex AI Workbench user-managed notebook has vTPM disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies GCP Vertex AI Workbench user-managed notebooks that have Virtual Trusted Platform Module (vTPM) feature disabled.</p><p>Virtual Trusted Platform Module (vTPM) validates guest VM pre-boot and boot integrity and offers key generation and protection. The vTPM’s root keys and the keys it generates can’t leave the vTPM, thus gaining enhanced protection from compromised operating systems or highly privileged project admins.</p><p>It is recommended to enable virtual TPM device on supported virtual machines to facilitate measured Boot and other OS security features that require a TPM.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-notebook-instance' AND json.rule = state equals "ACTIVE" and shieldedInstanceConfig.enableVtpm is false
</code></pre></td></tr><tr><td><p><strong>GCP Vertex AI Workbench user-managed notebook’s JupyterLab interface access mode is set to single user</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies GCP Vertex AI Workbench user-managed notebooks with JupyterLab interface access mode set to single user.</p><p>Vertex AI Workbench user-managed notebook can be accessed using the web-based JupyterLab interface. Access mode controls the control access to this interface. Allowing access to only a single user could limit collaboration, increase chances of credential sharing, and hinder security audits and reviews of the resource.</p><p>It is recommended to avoid single user access and make use of the service account access mode for user-managed notebooks.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-step-functions-statemachine' AND json.rule = loggingConfiguration.level equal ignore case off
</code></pre></td></tr><tr><td><p><strong>GCP Vertex AI Workbench user-managed notebook has Integrity monitoring disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies GCP Vertex AI Workbench user-managed notebooks that have Integrity monitoring disabled.</p><p>Integrity Monitoring continuously monitors the boot integrity, kernel integrity, and persistent data integrity of the underlying VM of the shielded user-managed notebooks. It detects unauthorized modifications or tampering, enhancing security by verifying the trusted state of VM components throughout their lifecycle. It provides active alerting allowing administrators to respond to integrity failures and prevent compromised nodes from being deployed into the cluster.</p><p>It is recommended to enable integrity monitoring for user-managed notebooks to detect and mitigate advanced threats like rootkits and bootkit malware.</p><p><strong>Policy Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where cloud.type = 'gcp' AND api.name = 'gcloud-vertex-ai-notebook-instance' AND json.rule = state equals "ACTIVE" and shieldedInstanceConfig.enableIntegrityMonitoring is false
</code></pre></td></tr><tr><td><p><strong>GCP Cloud Run service revision is using default service account with editor role</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies GCP Cloud Run service revisions that are utilizing the default service account with the editor role.</p><p>GCP Compute Engine Default service account is automatically created upon enabling the Compute Engine API. This service account is granted the IAM basic Editor role by default, unless explicitly disabled. Assigning default service account with the editor role to cloud run revisions could lead to privilege escalation. Granting minimal access rights helps in promoting a better security posture.</p><p>Following the principle of least privileges, it is recommended to avoid assigning default service account with the editor role to cloud run revision.</p><p><strong>Policy Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'gcloud-projects-get-iam-user' AND json.rule = user contains "compute@developer.gserviceaccount.com" and roles[*] contains "roles/editor" as X; config from cloud.resource where api.name = 'gcloud-cloud-run-revisions-list' AND json.rule = spec.serviceAccountName contains "compute@developer.gserviceaccount.com" as Y; filter ' $.X.user equals $.Y.spec.serviceAccountName '; show Y;
</code></pre></td></tr><tr><td><p><strong>OCI Cloud Guard is not enabled in the root compartment of the tenancy</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies the absence of OCI Cloud Guard enablement in the root compartment of the tenancy.</p><p>OCI Cloud Guard is a vital service that detects misconfigured resources and insecure activities within an OCI tenancy. It offers security administrators visibility to identify and resolve these issues promptly. Cloud Guard not only detects but also suggests, assists, or takes corrective actions to mitigate security risks. By enabling Cloud Guard in the root compartment of the tenancy with default configuration, activity detectors, and responders, administrators can proactively monitor and secure their OCI resources against potential security threats.</p><p>As best practice, it is recommended to have Cloud Guard enabled in the root compartment of your tenancy.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'oci-cloudguard-configuration' AND json.rule = status does not equal ignore case ENABLED
</code></pre></td></tr><tr><td><p><strong>OCI boot volume is not encrypted with Customer Managed Key (CMK)</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p></td><td><p>This policy identifies OCI boot volumes that are not encrypted with a Customer Managed Key (CMK).</p><p>Encrypting boot volumes with a CMK enhances data security by providing an additional layer of protection. Effective management of encryption keys is crucial for safeguarding and accessing sensitive data. Customers should review boot volumes encrypted with Oracle service managed keys to determine if they prefer managing keys for specific volumes and implement their own key lifecycle management accordingly.</p><p>As best practice, it is recommended to encrypt OCI boot volumes using a Customer Managed Key (CMK) to strengthen data security measures.</p><p><strong>Policy Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><pre><code>config from cloud.resource where api.name = 'oci-block-storage-boot-volume' AND json.rule = lifecycleState equal ignore case "AVAILABLE" AND kmsKeyId is member of ("null")
</code></pre></td></tr></tbody></table>

## IAM Policies

The 24.6.1 release includes the following OOTB IAM policies:

<table data-header-hidden><thead><tr><th></th><th></th><th></th><th></th><th></th></tr></thead><tbody><tr><td><strong>Policy Name</strong></td><td><strong>Description</strong></td><td><strong>RQL</strong></td><td><strong>Cloud</strong></td><td><strong>Policy Severity</strong></td></tr><tr><td><strong>AWS Compute Instance (EC2/Lambda) Assigned CloudFormation Creation Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to create CloudFormation stacks with any role would be able to escalate their permissions by attaching a privileged role to the stack while influencing the actions taken by the created resources. As such, they would obtain the ability to perform actions using the permissions of the attached role, allowing further enumeration and exploitation of the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name CONTAINS ALL ('iam:PassRole', 'cloudformation:CreateStack') AND source.cloud.resource.type IN ('instance', 'function')
</code></pre></td><td>AWS</td><td>High</td></tr><tr><td><strong>AWS Compute Instance (EC2/Lambda) Assigned Permissions to Run EC2 Instances Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to run EC2 instances with any role would be able to escalate their permissions by attaching a privileged role to the instance. As such, they would obtain the permissions of the role attached to the EC2, allowing further enumeration and exploitation of the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name CONTAINS ALL ('iam:PassRole', 'ec2:RunInstances') AND source.cloud.resource.type IN ('instance', 'function')
</code></pre></td><td>AWS</td><td>High</td></tr><tr><td><strong>AWS Compute Instance (EC2/Lambda) Assigned Lambda Creation Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to create a Lambda Function with any role and give themselves the permissions to invoke it would be able to escalate their permissions by attaching a privileged role to the function while defining the Lambda’s actions. As such, they would obtain the ability to perform actions using the permissions of the attached role, allowing further enumeration and exploitation of the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name CONTAINS ALL ('iam:PassRole', 'lambda:CreateFunction', 'lambda:AddPermission') AND source.cloud.resource.type IN ('instance', 'function')
</code></pre></td><td>AWS</td><td>High</td></tr><tr><td><strong>AWS Compute Instance (EC2/Lambda) Assigned IAM Policy Management Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to influence or change IAM policies could grant themselves extensive permissions using the policies. As such, they would obtain the ability to perform actions allowed by the policies, allowing further enumeration and exploitation of the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name in ('iam:PutGroupPolicy', 'iam:PutRolePolicy', 'iam:AttachGroupPolicy', 'iam:AttachUserPolicy', 'iam:CreatePolicyVersion') AND source.cloud.resource.type IN ('instance', 'function')
</code></pre></td><td>AWS</td><td>High</td></tr><tr><td><strong>AWS Compute Instance (EC2/Lambda) Assigned Glue DevEndpoint Creation Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to create a Glue DevEndpoint with any role would be able to escalate their permissions by attaching a privileged role to the endpoint and configuring authentication to the endpoint using a key which they control. As such, they would obtain the ability to perform actions using the permissions of the attached role, allowing further enumeration and exploitation of the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name CONTAINS ALL ('iam:PassRole', 'glue:CreateDevEndpoint') AND source.cloud.resource.type IN ('instance', 'function')
</code></pre></td><td>AWS</td><td>High</td></tr><tr><td><strong>AWS Compute Instance (EC2/Lambda) Assigned Glue DevEndpoint Creation Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to create a Glue DevEndpoint with any role would be able to escalate their permissions by attaching a privileged role to the endpoint and configuring authentication to the endpoint using a key which they control. As such, they would obtain the ability to perform actions using the permissions of the attached role, allowing further enumeration and exploitation of the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AWS' AND action.name CONTAINS ALL ('iam:PassRole', 'glue:CreateDevEndpoint') AND source.cloud.resource.type IN ('instance', 'function')
</code></pre></td><td>AWS</td><td>High</td></tr><tr><td><strong>Azure Compute Resource Assigned Role &#x26; Role Assignment Related Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit role assignments or role definitions could grant themselves additional roles, or grant additional permissions to roles they already have access to, escalating their privileges within the environment. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AZURE' AND source.cloud.type = 'AZURE' AND source.cloud.service.name = 'Microsoft.Compute' AND source.cloud.resource.type = 'VirtualMachines' and action.name IN ('Microsoft.Authorization/roleAssignments/write', 'Microsoft.Authorization/roleDefinitions/write')
</code></pre></td><td>Azure</td><td>High</td></tr><tr><td><strong>Azure Compute Resource Assigned Managed Identity Assignment Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to assign managed identities could assign them to themselves, obtaining the additional permissions granted to the managed identity, escalating their privileges within the environment. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'AZURE' AND source.cloud.type = 'AZURE' AND source.cloud.service.name = 'Microsoft.Compute' AND source.cloud.resource.type = 'VirtualMachines' and action.name = 'Microsoft.ManagedIdentity/userAssignedIdentities/assign/action'
</code></pre></td><td>Azure</td><td>High</td></tr><tr><td><strong>AWS Role With Administrative Permissions Can Be Assumed By All Users</strong></td><td>A globally assumable role with administartive permissions could allow an adversary to assume it (regardless of their original role as the target role is globally assumable) and utilize its administrative permissions to further compromise the environment.</td><td><pre><code>config from iam where source.public = true AND grantedby.cloud.entity.type='role' and action.access.isAdministrative = true
</code></pre></td><td>AWS</td><td>High</td></tr><tr><td><strong>GCP Compute Instance (VM/Cloud Function) Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to create Cloud Function instances with Service Account impersonation privileges would be able to escalate their permissions creating an instance which performs attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.resource.type IN ('Instances', 'functions') AND action.name CONTAINS ALL ( 'cloudfunctions.functions.create', 'cloudfunctions.functions.sourceCodeSet', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run Creation Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to create Cloud Run instances with Service Account impersonation privileges would be able to escalate their permissions creating an instance which performs attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.resource.type IN ('Instances', 'functions') AND action.name CONTAINS ALL ( 'run.services.create', 'run.routes.invoke', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Compute Instance (VM/Cloud Function) Assigned Cloud Function IAM Policy Edit Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit the IAM policy for Cloud Function instances, in conjunction with Service Account impersonation privileges would be able to escalate their permissions by adding edit permissions to an instance, causing it to perform attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.resource.type IN ('Instances', 'functions') AND action.name CONTAINS ALL ( 'cloudfunctions.functions.setIamPolicy', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run IAM Policy Edit Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit the IAM policy for Cloud Run instances, in conjunction with Service Account impersonation privileges would be able to escalate their permissions by adding edit permissions to an instance, causing it to perform attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.resource.type IN ('Instances', 'functions') AND action.name CONTAINS ALL ( 'run.services.setIamPolicy', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Compute Instance (VM/Cloud Function) Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit the IAM policy for Cloud Run Jobs, in conjunction with Service Account impersonation privileges would be able to escalate their permissions by adding edit permissions to an instance, causing it to perform attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.resource.type IN ('Instances', 'functions') AND action.name CONTAINS ALL ( 'run.jobs.setIamPolicy', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Compute Instance (VM/Cloud Function) Assigned IAM Role Update Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to retrieve and edit IAM roles could grant themselves additional permissions within the environment, escalating their privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.resource.type IN ('Instances', 'functions') AND action.name CONTAINS ALL ( 'iam.roles.update', 'iam.roles.get' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Compute Instance (VM/Cloud Function) Assigned Permissions to Retrieve Service Account Tokens Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to retrieve Service Account tokens could authenticate as high-privileged Service Accounts, escalating their original privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.resource.type IN ('Instances', 'functions') AND action.name CONTAINS ALL ( 'iam.serviceAccounts.getAccessToken', 'iam.serviceAccounts.get' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Compute Instance (VM/Cloud Function) Assigned Permissions to Edit IAM Policy for Service Accounts Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit Service Accounts' IAM Policies could grant themselves additional permissions within the environment, escalating their privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.resource.type IN ('Instances', 'functions') AND action.name = 'iam.serviceAccounts.setIamPolicy'
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Compute Instance (VM/Cloud Function) Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit IAM Policies at the organization, folder or project levels could grant themselves additional permissions within the environment, escalating their privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.resource.type IN ('Instances', 'functions') AND action.name IN ('resourcemanager.organizations.setIamPolicy', 'resourcemanager.folders.setIamPolicy', 'resourcemanager.projects.setIamPolicy')
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Cloud Run Instance Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to create Cloud Function instances with Service Account impersonation privileges would be able to escalate their permissions creating an instance which performs attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND action.name CONTAINS ALL ( 'cloudfunctions.functions.create', 'cloudfunctions.functions.sourceCodeSet', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Cloud Run Instance Assigned Cloud Run Creation Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to create Cloud Run instances with Service Account impersonation privileges would be able to escalate their permissions creating an instance which performs attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND action.name CONTAINS ALL ( 'run.services.create', 'run.routes.invoke', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Cloud Run Instance Assigned Cloud Function IAM Policy Edit Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit the IAM policy for Cloud Function instances, in conjunction with Service Account impersonation privileges would be able to escalate their permissions by adding edit permissions to an instance, causing it to perform attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND action.name CONTAINS ALL ( 'cloudfunctions.functions.setIamPolicy', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Cloud Run Instance Assigned Cloud Run IAM Policy Edit Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit the IAM policy for Cloud Run instances, in conjunction with Service Account impersonation privileges would be able to escalate their permissions by adding edit permissions to an instance, causing it to perform attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND action.name CONTAINS ALL ( 'run.services.setIamPolicy', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Cloud Run Instance Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit the IAM policy for Cloud Run Jobs, in conjunction with Service Account impersonation privileges would be able to escalate their permissions by adding edit permissions to an instance, causing it to perform attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND action.name CONTAINS ALL ( 'run.jobs.setIamPolicy', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Cloud Run Instance Assigned IAM Role Update Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to retrieve and edit IAM roles could grant themselves additional permissions within the environment, escalating their privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND action.name CONTAINS ALL ( 'iam.roles.update', 'iam.roles.get' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Cloud Run Instance Assigned Permissions to Retrieve Service Account Tokens Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to retrieve Service Account tokens could authenticate as high-privileged Service Accounts, escalating their original privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND action.name CONTAINS ALL ( 'iam.serviceAccounts.getAccessToken', 'iam.serviceAccounts.get' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Cloud Run Instance Assigned Permissions to Edit IAM Policy for Service Accounts Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit Service Accounts' IAM Policies could grant themselves additional permissions within the environment, escalating their privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND action.name = 'iam.serviceAccounts.setIamPolicy'
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP Cloud Run Instance Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation</strong></td><td>An adversary able to edit IAM Policies at the organization, folder or project levels could grant themselves additional permissions within the environment, escalating their privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'run' AND action.name IN ('resourcemanager.organizations.setIamPolicy', 'resourcemanager.folders.setIamPolicy', 'resourcemanager.projects.setIamPolicy')
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP App Engine Web Service Assigned Cloud Function Creation Permissions Which Could Lead to Privilege Escalation</strong></td><td>An attacker who successfully exploits a vulnerability or misconfiguration in the web service can leverage the permissions associated with the App Engine service. By creating Cloud Function instances with service account impersonation privileges, the attacker can escalate their permissions. This enables the creation of instances that perform actions under the guise of the impersonated service account, further allowing the attacker to enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'appengine' AND action.name CONTAINS ALL ( 'cloudfunctions.functions.create', 'cloudfunctions.functions.sourceCodeSet', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP App Engine Web Service Assigned Cloud Run Creation Which Could Lead to Privilege Escalation</strong></td><td>An attacker who successfully exploits a vulnerability or misconfiguration in the web service can leverage the permissions associated with the App Engine service. By creating Cloud Run instances with Service Account impersonation privileges they would be able to escalate their permissions creating an instance which performs attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'appengine' AND action.name CONTAINS ALL ( 'run.services.create', 'run.routes.invoke', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP App Engine Web Service Assigned Cloud Function IAM Policy Edit Permissions Which Could Lead to Privilege Escalation</strong></td><td>An attacker who successfully exploits a vulnerability or misconfiguration in the web service can leverage the permissions associated with the App Engine service. By editing the IAM policy for Cloud Function instances, in conjunction with Service Account impersonation privileges they would be able to escalate their permissions by adding edit permissions to an instance, causing it to perform attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'appengine' AND action.name CONTAINS ALL ( 'cloudfunctions.functions.setIamPolicy', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP App Engine Web Service Assigned Cloud Run IAM Policy Edit Permissions Which Could Lead to Privilege Escalation</strong></td><td>An attacker who successfully exploits a vulnerability or misconfiguration in the web service can leverage the permissions associated with the App Engine service. By editing the IAM policy for Cloud Run instances, in conjunction with Service Account impersonation privileges they would be able to escalate their permissions by adding edit permissions to an instance, causing it to perform attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'appengine' AND action.name CONTAINS ALL ( 'run.services.setIamPolicy', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP App Engine Web Service Assigned Cloud Run Jobs IAM Policy Edit Permissions Which Could Lead to Privilege Escalation</strong></td><td>An attacker who successfully exploits a vulnerability or misconfiguration in the web service can leverage the permissions associated with the App Engine service. By editing the IAM policy for Cloud Run Jobs, in conjunction with Service Account impersonation privileges they will be able to escalate their permissions by adding edit permissions to an instance, causing it to perform attacker controlled actions using the permissions of an impersonated Service Account. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'appengine' AND action.name CONTAINS ALL ( 'run.jobs.setIamPolicy', 'iam.serviceAccounts.actAs' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP App Engine Web Service Assigned IAM Role Update Permissions Which Could Lead to Privilege Escalation</strong></td><td>An attacker who successfully exploits a vulnerability or misconfiguration in the web service can leverage the permissions associated with the App Engine service. With the ability to retrieve and edit IAM roles could grant themselves additional permissions within the environment, escalating their privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'appengine' AND action.name CONTAINS ALL ( 'iam.roles.update', 'iam.roles.get' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP App Engine Web Service Assigned Permissions to Retrieve Service Account Tokens Which Could Lead to Privilege Escalation</strong></td><td>An attacker who successfully exploits a vulnerability or misconfiguration in the web service can leverage the permissions associated with the App Engine service. With the ability to retrieve Service Account tokens could authenticate as high-privileged Service Accounts, escalating their original privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'appengine' AND action.name CONTAINS ALL ( 'iam.serviceAccounts.getAccessToken', 'iam.serviceAccounts.get' )
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP App Engine Web Service Assigned Permissions to Edit IAM Policy for Service Accounts Which Could Lead to Privilege Escalation</strong></td><td>An attacker who successfully exploits a vulnerability or misconfiguration in the web service can leverage the permissions associated with the App Engine service. With the ability to edit Service Accounts' IAM Policies they could grant themselves additional permissions within the environment, escalating their privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'appengine' AND action.name = 'iam.serviceAccounts.setIamPolicy'
</code></pre></td><td>GCP</td><td>High</td></tr><tr><td><strong>GCP App Engine Web Service Assigned Resource Manager Permissions Which Could Lead to Privilege Escalation</strong></td><td>An attacker who successfully exploits a vulnerability or misconfiguration in the web service can leverage the permissions associated with the App Engine service. With the ability to edit IAM Policies at the organization, folder or project levels they can grant themselves additional permissions within the environment, escalating their privileges. This would allow them to further enumerate and exploit the environment.</td><td><pre><code>config from iam where dest.cloud.type = 'GCP' AND source.cloud.service.name = 'appengine' AND action.name IN ('resourcemanager.organizations.setIamPolicy', 'resourcemanager.folders.setIamPolicy', 'resourcemanager.projects.setIamPolicy')
</code></pre></td><td>GCP</td><td>High</td></tr></tbody></table>

## Policy Updates

<table data-header-hidden><thead><tr><th></th><th></th></tr></thead><tbody><tr><td><strong>Policies</strong></td><td><strong>Description</strong></td></tr><tr><td><strong>Policy Updates—RQL</strong></td><td></td></tr><tr><td><p><strong>Azure Function App doesn’t have a Managed Service Identity</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL will be updated to exclude logic apps and web apps from reporting, focusing solely on Azure function apps within its scope.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case Running and kind contains functionapp and (identity.type does not exist or identity.principalId is empty)
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case "Running" AND kind contains "functionapp" AND kind does not contain "workflowapp" AND kind does not equal "app" AND (identity.type does not exist or identity.principalId is empty)----
</code></pre><p><strong>Impact—</strong> Medium. Existing alerts generated for logicapp and webapps will be resolved as <strong>Policy_Updated</strong>.</p></td></tr><tr><td><p><strong>Azure Function app configured with public network access</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL will be updated to exclude logic apps and web apps from reporting, focusing solely on Azure function apps within its scope.</p><p><strong>Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = 'kind starts with functionapp and properties.state equal ignore case running and ((properties.publicNetworkAccess exists and properties.publicNetworkAccess equal ignore case Enabled) or (properties.publicNetworkAccess does not exist)) and config.ipSecurityRestrictions[?any((action equals Allow and ipAddress equals Any) or (action equals Allow and ipAddress equals 0.0.0.0/0))] exists'
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = 'kind contains functionapp and kind does not contain workflowapp and kind does not equal app and properties.state equal ignore case running and ((properties.publicNetworkAccess exists and properties.publicNetworkAccess equal ignore case Enabled) or (properties.publicNetworkAccess does not exist)) and config.ipSecurityRestrictions[?any((action equals Allow and ipAddress equals Any) or (action equals Allow and ipAddress equals 0.0.0.0/0))] exists'
</code></pre><p><strong>Impact—</strong> Medium. Existing alerts generated for logicapp and webapps will be resolved as <strong>Policy_Updated</strong>.</p></td></tr><tr><td><p><strong>Azure Function App doesn’t use latest TLS version</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL will be updated to exclude logic apps and web apps from reporting, focusing solely on Azure function apps within its scope.</p><p><strong>Severity—</strong> Low</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case "Running" AND kind contains "functionapp" AND config.minTlsVersion does not equal "1.2"
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case "Running" AND kind contains "functionapp" AND kind does not contain "workflowapp" AND kind does not equal "app" AND config.minTlsVersion does not equal "1.2"
</code></pre><p><strong>Impact—</strong> Medium. Existing alerts generated for logicapp and webapps will be resolved as <strong>Policy_Updated</strong>.</p></td></tr><tr><td><p><strong>Azure Function App doesn’t use HTTP 2.0</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL will be updated to exclude logic apps and web apps from reporting, focusing solely on Azure function apps within its scope.</p><p><strong>Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case "Running" AND kind contains "functionapp" AND config.http20Enabled is false
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case "Running" AND kind contains "functionapp" AND kind does not contain "workflowapp" AND kind does not equal "app" AND config.http20Enabled is false
</code></pre><p><strong>Impact—</strong> Medium. Existing alerts generated for logicapp and webapps will be resolved as <strong>Policy_Updated</strong>.</p></td></tr><tr><td><p><strong>Azure Function App doesn’t redirect HTTP to HTTPS</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL will be updated to exclude logic apps and web apps from reporting, focusing solely on Azure function apps within its scope.</p><p><strong>Severity—</strong> Medium</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case "Running" AND kind contains "functionapp" AND properties.httpsOnly is false
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case "Running" AND kind contains "functionapp" AND kind does not contain "workflowapp" AND kind does not equal "app" AND properties.httpsOnly is false
</code></pre><p><strong>Impact—</strong> Medium. Existing alerts generated for logicapp and webapps will be resolved as <strong>Policy_Updated</strong>.</p></td></tr><tr><td><p><strong>Azure Function App client certificate is disabled</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p><strong>Changes—</strong> The policy RQL will be updated to exclude logic apps and web apps from reporting, focusing solely on Azure function apps within its scope.</p><p><strong>Severity—</strong> Informational</p><p><strong>Policy Type—</strong> Config</p><p><strong>Current RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case Running and kind contains functionapp and properties.clientCertEnabled is false
</code></pre><p><strong>Updated RQL—</strong></p><pre><code>config from cloud.resource where cloud.type = 'azure' AND api.name = 'azure-app-service' AND json.rule = properties.state equal ignore case "Running" AND kind contains "functionapp" AND kind does not contain "workflowapp" AND kind does not equal "app" AND properties.clientCertEnabled is false
</code></pre><p><strong>Impact—</strong> Medium. Existing alerts generated for logicapp and webapps will be resolved as <strong>Policy_Updated</strong>.</p></td></tr><tr><td><strong>Policy Deletions</strong></td><td></td></tr><tr><td><p><strong>AWS role having iam:PassRole and lambda:InvokeFunction permissions attached to EC2 instance [Beta]</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p><strong>Changes—</strong> This policy is deleted because it is replaced by the following policy:</p><p>AWS role having iam:PassRole and lambda:InvokeFunction permissions attached to EC2 instance</p></td></tr><tr><td><p><strong>EC2 with IAM role attached has iam:PassRole and ec2:RunInstances permissions [Beta]</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p></td><td><p><strong>Changes—</strong> This policy is deleted because it is replaced by the following policy:</p><p>EC2 with IAM role attached has iam:PassRole and ec2:Run Instances permissions</p></td></tr></tbody></table>

## New Compliance Benchmarks and Updates

| **Compliance Benchmark**                                                                                                                            | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| --------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Policy Mapping Update for CIS AWS v2.0</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>          | <p>New Policy mappings are added to CIS v2.0.0 (AWS) - Level 1 compliance standard.</p><p><strong>Impact—</strong> No impact on existing alerts. The compliance score may vary because a new mapping has been added.</p>                                                                                                                                                                                                                                                |
| <p><strong>Policy Mapping Update for CIS GCP v2.0</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>          | <p>New Policy mappings are added to CIS v2.0.0 (GCP) Level 1 and CIS v2.0.0 (GCP) Level 2 compliance standards.</p><p><strong>Impact—</strong> No impact on existing alerts. The compliance score may vary because a new mapping has been added.</p>                                                                                                                                                                                                                    |
| <p><strong>Policy Mapping Update for ISO/IEC 27001:2022</strong></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>    | <p>New Policy mappings are added to ISO/IEC 27001:2022 compliance standard.</p><p><strong>Impact—</strong> No impact on existing alerts. The compliance score may vary because a new mapping has been added.</p>                                                                                                                                                                                                                                                        |
| <p><strong>Support for CIS GKE v1.5</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                        | <p>Prisma Cloud now supports CIS GKE version 1.5. The latest version has new controls and new Prisma cloud policies are mapped to the controls increasing the overall coverage.</p><p>You can view this built-in standard and the associated policies on <strong>Compliance > Standards</strong>. Generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p>                                    |
| <p><strong>Support for CIS OCI v2.0</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                        | <p>Prisma Cloud now supports CIS OCI version 2.0. The latest version has new controls and new Prisma cloud policies are mapped to the controls increasing the overall coverage.</p><p>You can view this built-in standard and the associated policies on <strong>Compliance > Standards</strong>. Generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p>                                    |
| <p><strong>Support for CIS Azure Foundation benchmark v2.1</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p> | <p>Prisma Cloud now supports CIS Azure Foundation benchmark version 2.1. The latest version has new controls and new Prisma cloud policies are mapped to the controls increasing the overall coverage.</p><p>You can view this built-in standard and the associated policies on <strong>Compliance > Standards</strong>. Generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p>             |
| <p><strong>Support for CIS AWS Foundation benchmark 3.0</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>    | <p>Prisma Cloud now supports CIS AWS Foundation Benchmark version 3.0. This latest version has new controls and new Prisma cloud policies are mapped to the controls increasing the overall coverage.</p><p>You can now view this built-in standard and the associated policies on the <strong>Compliance > Standards</strong> page. Generate reports for immediate viewing or download, or schedule recurring reports to track this compliance standard over time.</p> |

## Changes in Existing Behavior

| **Feature**                                                                                                         | **Description**                                                                                                                                                                                                                             |
| ------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>API Rate Limits</strong></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p> | Prisma Cloud uses API [rate limits](https://pan.dev/prisma-cloud/api/cspm/rate-limits/) at the endpoint level to protect the performance and availability of its services. Rate limits will be applied to the additional APIs listed below. |

| **Endpoint**                                                                                                                                              | **Rate Limit (tps)** | **Burst Rate (tps)** |
| --------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------- | -------------------- |
| **Resource Lists**                                                                                                                                        |                      |                      |
| Get Resource Lists - [GET /v1/resource\_list](https://pan.dev/prisma-cloud/api/cspm/get-all-resource-list-for-customer/)                                  | 80                   | 80                   |
| Get Resource List by ID - [GET /v1/resource\_list/#id](https://pan.dev/prisma-cloud/api/cspm/get-resource-list-by-id/)                                    | 4                    | 4                    |
| Get Resource List Types - [GET /v1/resource\_list/types](https://pan.dev/prisma-cloud/api/cspm/get-resource-list-types/)                                  | 4                    | 4                    |
| Get Resource List Names - GET /v1/resource\_list/names                                                                                                    | 80                   | 80                   |
| **Account Groups**                                                                                                                                        |                      |                      |
| List Account Groups - [GET /cloud/group](https://pan.dev/prisma-cloud/api/cspm/get-account-groups/)                                                       | 32                   | 32                   |
| Account Group Info - [GET /cloud/group/#id](https://pan.dev/prisma-cloud/api/cspm/get-account-group/)                                                     | 80                   | 80                   |
| List Account Group Names - [GET /cloud/group/name](https://pan.dev/prisma-cloud/api/cspm/get-account-group-name/)                                         | 32                   | 32                   |
| List Account Group Names by Cloud Type - [GET cloud/group/name/#cloud\_type](https://pan.dev/prisma-cloud/api/cspm/get-account-group-name-by-cloud-type/) | 4                    | 4                    |
| **Collections**                                                                                                                                           |                      |                      |
| Get All Collections - [GET /entitlement/api/v1/collection](https://pan.dev/prisma-cloud/api/cspm/get-all-collections/)                                    | 4                    | 4                    |
| Get Collection by ID - [GET /entitlement/api/v1/collection/#id](https://pan.dev/prisma-cloud/api/cspm/get-collection-by-id/)                              | 8                    | 8                    |

## REST API Updates

| **Change**                                                                                                                                                                                                                                         | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>Vulnerabilities Dashboard APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                   | <p>The <a href="https://pan.dev/prisma-cloud/api/cspm/vulnerabilities-dashboard/">Vulnerabilities Dashboard</a> endpoints now require specific access permissions to get the dashboard data and create remediation requests. For details on the required permissions, see the respective endpoint description.</p><p>Also, the <a href="https://pan.dev/prisma-cloud/api/cspm/vulnerabilities-search-api/">Get Vulnerabilities by RQL</a> endpoint will now contain the following new parameters in the response:</p><ul><li><code>vulnerabilities</code> - Total number of vulnerabilities</li><li><code>assetCount</code> - Total number of unique assets</li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><strong>CI/CD Risks API</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                          | <p>The following new endpoints have been added to the API:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/code/pipeline-risks-get-all/">Get All CI/CD Risks Summary</a></li><li><a href="https://pan.dev/prisma-cloud/api/code/pipeline-risks-get-alerts-by-policy/">Get CI/CD Risk Events</a></li><li><a href="https://pan.dev/prisma-cloud/api/code/pipeline-risks-get-details-by-policy-get/">Get CI/CD Risk Details</a></li><li><a href="https://pan.dev/prisma-cloud/api/code/pipeline-risks-suppress-events/">Suppress CI/CD Risk Events</a></li><li><a href="https://pan.dev/prisma-cloud/api/code/pipeline-risks-unsuppress-events/">Unsuppress CI/CD Risk Events</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                   |
| <p><strong>Technologies API</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                         | <p>The following new endpoints have been added to the API:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/code/get-apps/">Get VCS 3rd Party Apps</a></li><li><a href="https://pan.dev/prisma-cloud/api/code/get-webhooks/">Get VCS 3rd Party Webhooks</a></li><li><a href="https://pan.dev/prisma-cloud/api/code/assets-inventory-get-all/">List Technologies</a></li><li><a href="https://pan.dev/prisma-cloud/api/code/get-ci-inventory/">Get Pipeline Tools</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| <p><strong>Repositories API</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                         | <p>The following new endpoint has been added to the API:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/code/get-vcs-repository-page/">Get Repositories Page</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>SBOM API</strong></p><p><mark style="background-color:orange;">Secure the Source</mark></p><p><mark style="background-color:orange;"><strong>24.6.2</strong></mark></p>                                                                 | <p>The following new endpoint has been added to the API:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/code/sbom-dependencies/">Get Dependencies</a></li></ul><p>Also, the existing <a href="https://pan.dev/prisma-cloud/api/code/get-bom-report/">Get BOM Report</a> endpoint is listed under the new SBOM category now.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| <p><mark style="background-color:orange;">Update</mark> <strong>Alerts APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p> | The [POST /alert/v1/policy](https://pan.dev/prisma-cloud/api/cspm/alert-policy-list/) and [POST /alert/v1/aggregate](https://pan.dev/prisma-cloud/api/cspm/alert-aggregation/) APIs have an additional `countDetails` parameter in the response that includes `totalAlerts` and `totalPolicies`. The `countDetails` parameter allows you to view the total number of alerts across the total number of policies on the **Alerts Overview** page.                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| <p><strong>IAM APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                                                         | <p>Get least privilege access suggestions and resource metadata with the following new APIs:</p><ul><li>Get least Privilege Access Metadata of a Resource - <a href="https://pan.dev/prisma-cloud/api/cspm/least-privilege-access-metadata-by-resource-v-1/">GET iam/api/v1/resources/:resourceId/over-permissive-metadata</a></li><li>Get existing Least Privilege Access Suggestions for a Resource - <a href="https://pan.dev/prisma-cloud/api/cspm/existing-least-privilege-access-by-resource-v-1/">GET iam/api/v1/resources/:resourceId/existing-least-privileged-access</a></li><li>Get new Least Privilege Access Suggestions for a Resource - <a href="https://pan.dev/prisma-cloud/api/cspm/custom-least-privilege-access-by-resource-v-1/">GET iam/api/v1/resources/:resourceId/custom-least-privileged-access</a></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| <p><strong>Cloud Discovery and Exposure Management (CDEM) APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>              | <p><strong>New Endpoints</strong>: The following endpoints are now available to fetch vulnerability details, distributions impacted by a vulnerability, and snooze patterns:</p><ul><li>Get Vulnerabilities of Unmanaged Asset - <a href="https://pan.dev/prisma-cloud/api/cspm/asset-vulnerability/">GET /asm/api/v1/asset/{asset\_id}/vulnerability</a></li><li>Get Impacted Distros of a Vulnerability - <a href="https://pan.dev/prisma-cloud/api/cspm/vulnerability/">GET /asm/api/v1/asset/vulnerability</a></li><li>Get Snooze Regex Pattern - <a href="https://pan.dev/prisma-cloud/api/cspm/list-snoozed-pattern/">GET asm/api/v1/asset/snoozed-regex</a></li></ul><p><strong>Updates to the existing Endpoints</strong>:</p><p>Introducing support to snooze or unsnooze a set of assets that match a regular expression by adding the <strong>regex</strong> parameter in the following endpoints:</p><ul><li>Snooze Unmanaged Assets - <a href="https://pan.dev/prisma-cloud/api/cspm/asset-snooze/">POST asm/api/v1/asset/snooze</a></li><li>Unsnooze Unmanaged Assets - <a href="https://pan.dev/prisma-cloud/api/cspm/asset-unsnooze/">POST asm/api/v1/asset/reopen</a></li></ul><p>You can now filter assets by the account mapping status, which indicates if the asset is associated with a parent account on Prisma Cloud. The <strong>accountMappingStatus</strong> parameter is now added to the request or response of the following endpoints:</p><ul><li>Get Assets List - <a href="https://pan.dev/prisma-cloud/api/cspm/asset-inventory-for-l-3/">GET asm/api/v1/asset</a></li><li>Get Asset Filters - <a href="https://pan.dev/prisma-cloud/api/cspm/get-asset-filters/">GET asm/api/v1/asset/filters</a></li><li>Get Aggregated Asset Count by Asset Type - <a href="https://pan.dev/prisma-cloud/api/cspm/get-asset-count-by-asset-type-for-l-2/">GET asm/api/v1/asset/aggregation-by-resource-type</a></li><li>Get Aggregated Asset Count by Cloud Type - <a href="https://pan.dev/prisma-cloud/api/cspm/get-assets-aggregated-by-provider-for-l-1/">GET asm/api/v1/asset/aggregation-by-cloud-type</a></li></ul> |
| <p><strong>Vulnerabilities Dashboard (UVE) APIs</strong></p><p><mark style="background-color:orange;">Secure the Infrastructure</mark></p><p><mark style="background-color:orange;"><strong>24.6.1</strong></mark></p>                             | <p><strong>New Endpoints</strong>: The following new versions of the existing endpoints are introduced to fetch additional details about the vulnerabilities:</p><ul><li>Get Prioritized Vulnerabilities V3 - <a href="https://pan.dev/prisma-cloud/api/cspm/prioritised-vulnerability-v-3/">GET uve/api/v3/dashboard/vulnerabilities/prioritised</a></li><li>Get Top Impacting Vulnerabilities V2 - <a href="https://pan.dev/prisma-cloud/api/cspm/top-prioritised-vulnerability-v-2/">GET uve/api/v2/dashboard/vulnerabilities/prioritised-vuln</a></li><li>Get CVE Overview V2 - <a href="https://pan.dev/prisma-cloud/api/cspm/cve-overview-v-2/">GET uve/api/v1/cve-overview</a></li></ul><p><strong>Updates to the existing Endpoints</strong>:</p><ul><li><p>The EPSS score and its details are added to the response to the following endpoints:</p><ul><li>Get Vulnerabilities by RQL - <a href="https://pan.dev/prisma-cloud/api/cspm/vulnerabilities-search-api/">GET uve/api/v1/vulnerabilities/search</a></li><li>Get CVE Overview - <a href="https://pan.dev/prisma-cloud/api/cspm/cve-overview/">GET uve/api/v1/dashboard/vulnerabilities/cve-overview</a></li></ul></li><li><p>The <strong>atRisk</strong> and <strong>internetExposed</strong> parameters are added to the response of Get Vulnerable Assets by RQL.</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cspm/list-vulnerable-assets/">GET uve/api/v1/vulnerabilities/search/asset</a> endpoint.</li></ul></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Download the Software Bill of Materials (SBOM)</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">32.06.132</mark></p>                                        | <p>The following new API endpoints enable you to download the Software Bill of Materials (SBOM) details:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cwpp/get-sbom-download-images/">Download SBOM Images</a></li><li><a href="https://pan.dev/prisma-cloud/api/cwpp/get-sbom-download-hosts/">Download SBOM Hosts</a></li><li><a href="https://pan.dev/prisma-cloud/api/cwpp/get-sbom-download-vms/">Download SBOM VMs</a></li><li><a href="https://pan.dev/prisma-cloud/api/cwpp/get-sbom-download-serverless/">Download SBOM Serverless</a></li><li><a href="https://pan.dev/prisma-cloud/api/cwpp/get-sbom-download-registry/">Download SBOM Registry</a></li><li><a href="https://pan.dev/prisma-cloud/api/cwpp/get-sbom-download-cli-serverless/">Download SBOM CLI Serverless</a></li><li><a href="https://pan.dev/prisma-cloud/api/cwpp/get-sbom-download-cli-images/">Download SBOM CLI Images</a></li></ul><p>For more details on the SBOM feature, refer to the <a href="#new-features">New Features</a> section.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| <p><strong>Remove hostname from registry progress response</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">32.06.132</mark></p>                                       | <p>The response of the <a href="https://pan.dev/prisma-cloud/api/cwpp/get-registry-progress/">View Registry Scan Progress</a> API has the following changes:</p><ul><li>A new “specScanStartTime” field is added</li><li><p>The existing “discovery” and “imageScan” properties have been modified to:</p><ul><li>Include a new “type” field</li><li>Remove the “hostname” and “scanTime” fields\`</li></ul></li></ul>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| <p><strong>Documentation update for Add Registry Settings</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">32.06.132</mark></p>                                        | <p>A new registry type - “Harbor” is added to the “version” field for the <a href="https://pan.dev/prisma-cloud/api/cwpp/post-settings-registry/">Add Registry Settings</a> API.</p><p>This option enables you to configure a Harbor registry for scanning.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| <p><strong>Component documentation for API address resolving method for cluster name</strong></p><p><mark style="background-color:orange;">Secure the Runtime</mark></p><p><mark style="background-color:orange;">32.06.132</mark></p>             | <p>A new optional field clusterNameResolvingMethod is added to the following APIs:</p><ul><li><a href="https://pan.dev/prisma-cloud/api/cwpp/post-defenders-daemonset-yaml/">Generate Daemonset Deployment YAML File</a></li><li><a href="https://pan.dev/prisma-cloud/api/cwpp/post-defenders-helm-twistlock-defender-helm-tar-gz/">Generate a Helm Deployment Chart for Defender</a></li></ul><p>The permissible values for this field are default, manual, and api-server.</p>                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                               |

## Deprecation Notices

| **Change**                                                                                                                                                                | **Description**                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| <p><strong>End of support for Azure Data Lake Analytics and Azure Data Lake Storage Gen1 Services</strong></p><p><mark style="background-color:orange;">24.6.1</mark></p> | <p>The following APIs are planned for deprecation because Azure has announced the retirement of Azure Data Lake Analytics and Azure Data Lake Storage Gen1 Services. Due to this, Prisma Cloud will no longer ingest metadata for the following APIs:</p><ul><li>azure-data-lake-analytics-account</li><li>azure-data-lake-analytics-diagnostic-settings</li><li>azure-data-lake-store-gen1-account</li><li>azure-data-lake-store-gen1-diagnostic-settings</li></ul><p>In RQL, the key will not be available in the <code>api.name</code> attribute auto-completion.</p><p><strong>Impact—</strong> If you have a saved search or custom policies based on this API, you must delete those manually. The policy alerts will be resolved as Policy\_Deleted.</p> |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.prismacloud.io/release-notes/prisma-cloud-release-information/features-introduced-in-2024/features-introduced-in-june-2024.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
