Skip to content

Commit

Permalink
Fix up queries that were incorrectly negating traversals, and aliasin…
Browse files Browse the repository at this point in the history
…g the results
  • Loading branch information
jmountifield committed Apr 10, 2024
1 parent c83b531 commit fafafba
Showing 1 changed file with 2 additions and 2 deletions.
4 changes: 2 additions & 2 deletions rule-packs/aws-config.json
Original file line number Diff line number Diff line change
Expand Up @@ -661,7 +661,7 @@
"queries": [
{
"name": "query0",
"query": "FIND aws_iam_group AS group THAT !HAS aws_iam_user AS user RETURN user.accountId, user.name,user.displayName, group.name,group.displayName, group.id",
"query": "FIND aws_iam_user AS user THAT !HAS aws_iam_group RETURN user.displayName, user.name, user.accountId AS \"AWS Account ID\", user.arn",
"version": "v1"
}
],
Expand Down Expand Up @@ -841,7 +841,7 @@
"queries": [
{
"name": "query0",
"query": "FIND aws_security_group AS fw THAT !ALLOWS AS rule (Host|Network) WITH internal != true AS src WHERE (rule.ingress = true AND rule.ipProtocol = 'tcp' AND rule.fromPort <= 20 AND rule.toPort >= 20) OR (rule.ingress = true AND rule.ipProtocol = 'tcp' AND rule.fromPort <= 21 AND rule.toPort >= 21) OR (rule.ingress = true AND rule.ipProtocol = 'tcp' AND rule.fromPort <= 3306 AND rule.toPort >= 3306) OR (rule.ingress = true AND rule.ipProtocol = 'tcp' AND rule.fromPort <= 3389 AND rule.toPort >= 3389) OR (rule.ingress = true AND rule.ipProtocol = 'tcp' AND rule.fromPort <= 4333 AND rule.toPort >= 4333) RETURN fw.displayName, rule.ipProtocol, rule.fromPort, rule.toPort, src.displayName, src.ipAddress, src.CIDR",
"query": "FIND aws_security_group AS fw THAT ALLOWS AS rule (Host|Network) WITH internal != true AS src WHERE (rule.ingress = true AND rule.ipProtocol = 'tcp' AND rule.fromPort <= 20 AND rule.toPort >= 20) OR (rule.ingress = true AND rule.ipProtocol = 'tcp' AND rule.fromPort <= 21 AND rule.toPort >= 21) OR (rule.ingress = true AND rule.ipProtocol = 'tcp' AND rule.fromPort <= 3306 AND rule.toPort >= 3306) OR (rule.ingress = true AND rule.ipProtocol = 'tcp' AND rule.fromPort <= 3389 AND rule.toPort >= 3389) OR (rule.ingress = true AND rule.ipProtocol = 'tcp' AND rule.fromPort <= 4333 AND rule.toPort >= 4333) RETURN fw.displayName, rule.ipProtocol, rule.fromPort, rule.toPort, src.displayName, src.ipAddress, src.CIDR, fw.accountId AS \"AWS Account ID\"",
"version": "v1"
}
],
Expand Down

0 comments on commit fafafba

Please sign in to comment.