Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Invalid test case #466

Closed
nathan-williams-lightspeed opened this issue Aug 1, 2022 · 0 comments · Fixed by #1364
Closed

Invalid test case #466

nathan-williams-lightspeed opened this issue Aug 1, 2022 · 0 comments · Fixed by #1364

Comments

@nathan-williams-lightspeed

For the rule AWS.CloudTrail.SecurityConfigurationChange the final test case "Security Configuration Changed - Allowlisted User" always passes, even if the example user is removed from the ALLOW_LIST as the event is not in the SECURITY_CONFIG_ACTIONS list.

I found this while debugging our internal clone of these rules.

Test case:

SECURITY_CONFIG_ACTIONS:

I'm not sure how best to fix this without inadvertently adding a blindspot for any users named ExampleUser, but thought you should be aware of it.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging a pull request may close this issue.

1 participant