Skip to content
This repository has been archived by the owner on Sep 18, 2023. It is now read-only.

Add MozDef alerting to group role map builder #223

Open
gene1wood opened this issue Jul 9, 2020 · 0 comments
Open

Add MozDef alerting to group role map builder #223

gene1wood opened this issue Jul 9, 2020 · 0 comments

Comments

@gene1wood
Copy link
Contributor

Since we're already looking at all IAM policies that are used for federated login, we might as well make sure there aren't any dangerous conditions present for example

  • a policy which has no amr check thereby allowing every user that can authenticate with Auth0
  • a policy which uses a federated identity provider other than auth0
  • a policy which through amr checks allows all users (e.g. the policy has a StringNotEquals instead of a StringEquals on an amr value)

etc

When we detect these risky situations we should alert to MozDef or something.

Original Jira ticket IAM-140

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant