Skip to content

Commit

Permalink
Update detected
Browse files Browse the repository at this point in the history
  • Loading branch information
MAMIP Bot committed Nov 15, 2024
1 parent f09bcf3 commit 4f952e0
Show file tree
Hide file tree
Showing 6 changed files with 440 additions and 0 deletions.
39 changes: 39 additions & 0 deletions policies/IAMAuditRootUserCredentials
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
{
"PolicyVersion": {
"CreateDate": "2024-11-06T22:27:58Z",
"VersionId": "v1",
"Document": {
"Version": "2012-10-17",
"Statement": [
{
"NotAction": [
"iam:ListAccessKeys",
"iam:ListSigningCertificates",
"iam:GetLoginProfile",
"iam:ListMFADevices",
"iam:GetAccountSummary",
"iam:GetUser",
"iam:GetAccessKeyLastUsed"
],
"Resource": "*",
"Effect": "Deny",
"Sid": "DenyAllOtherActionsOnAnyResource"
},
{
"Action": [
"iam:ListAccessKeys",
"iam:ListSigningCertificates",
"iam:GetLoginProfile",
"iam:ListMFADevices",
"iam:GetUser",
"iam:GetAccessKeyLastUsed"
],
"NotResource": "arn:aws:iam::*:root",
"Effect": "Deny",
"Sid": "DenyAuditingCredentialsOnNonRootUserResource"
}
]
},
"IsDefaultVersion": true
}
}
30 changes: 30 additions & 0 deletions policies/IAMCreateRootUserPassword
Original file line number Diff line number Diff line change
@@ -0,0 +1,30 @@
{
"PolicyVersion": {
"CreateDate": "2024-11-06T22:32:59Z",
"VersionId": "v1",
"Document": {
"Version": "2012-10-17",
"Statement": [
{
"NotAction": [
"iam:CreateLoginProfile",
"iam:GetLoginProfile"
],
"Resource": "*",
"Effect": "Deny",
"Sid": "DenyAllOtherActionsOnAnyResource"
},
{
"Action": [
"iam:CreateLoginProfile",
"iam:GetLoginProfile"
],
"NotResource": "arn:aws:iam::*:root",
"Effect": "Deny",
"Sid": "DenyCreatingPasswordOnNonRootUserResource"
}
]
},
"IsDefaultVersion": true
}
}
48 changes: 48 additions & 0 deletions policies/IAMDeleteRootUserCredentials
Original file line number Diff line number Diff line change
@@ -0,0 +1,48 @@
{
"PolicyVersion": {
"CreateDate": "2024-11-06T22:47:58Z",
"VersionId": "v1",
"Document": {
"Version": "2012-10-17",
"Statement": [
{
"NotAction": [
"iam:DeleteAccessKey",
"iam:DeleteSigningCertificate",
"iam:DeleteLoginProfile",
"iam:DeactivateMFADevice",
"iam:DeleteVirtualMFADevice",
"iam:ListAccessKeys",
"iam:ListSigningCertificates",
"iam:GetLoginProfile",
"iam:ListMFADevices",
"iam:GetUser",
"iam:GetAccessKeyLastUsed"
],
"Resource": "*",
"Effect": "Deny",
"Sid": "DenyAllOtherActionsOnAnyResource"
},
{
"Action": [
"iam:DeleteAccessKey",
"iam:DeleteSigningCertificate",
"iam:DeleteLoginProfile",
"iam:DeactivateMFADevice",
"iam:DeleteVirtualMFADevice",
"iam:ListAccessKeys",
"iam:ListSigningCertificates",
"iam:GetLoginProfile",
"iam:ListMFADevices",
"iam:GetUser",
"iam:GetAccessKeyLastUsed"
],
"NotResource": "arn:aws:iam::*:root",
"Effect": "Deny",
"Sid": "DenyDeletingRootUserCredentialsOnNonRootUserResource"
}
]
},
"IsDefaultVersion": true
}
}
39 changes: 39 additions & 0 deletions policies/S3UnlockBucketPolicy
Original file line number Diff line number Diff line change
@@ -0,0 +1,39 @@
{
"PolicyVersion": {
"CreateDate": "2024-11-06T21:55:56Z",
"VersionId": "v1",
"Document": {
"Version": "2012-10-17",
"Statement": [
{
"NotAction": [
"s3:DeleteBucketPolicy",
"s3:PutBucketPolicy",
"s3:GetBucketPolicy",
"s3:ListAllMyBuckets"
],
"Resource": "*",
"Effect": "Deny",
"Sid": "DenyAllOtherActionsOnAnyResource"
},
{
"Action": [
"s3:DeleteBucketPolicy",
"s3:PutBucketPolicy",
"s3:GetBucketPolicy",
"s3:ListAllMyBuckets"
],
"Resource": "*",
"Effect": "Deny",
"Condition": {
"StringNotLike": {
"aws:PrincipalArn": "arn:aws:iam::*:root"
}
},
"Sid": "DenyManagingBucketPolicyForNonRootCallers"
}
]
},
"IsDefaultVersion": true
}
}
54 changes: 54 additions & 0 deletions policies/SQSUnlockQueuePolicy
Original file line number Diff line number Diff line change
@@ -0,0 +1,54 @@
{
"PolicyVersion": {
"CreateDate": "2024-11-06T21:51:02Z",
"VersionId": "v1",
"Document": {
"Version": "2012-10-17",
"Statement": [
{
"NotAction": [
"sqs:SetQueueAttributes",
"sqs:GetQueueAttributes",
"sqs:ListQueues",
"sqs:GetQueueUrl"
],
"Resource": "*",
"Effect": "Deny",
"Sid": "DenyAllOtherActionsOnAnyResource"
},
{
"Action": [
"sqs:GetQueueAttributes"
],
"Resource": "arn:aws:sqs:*:*:*",
"Effect": "Deny",
"Condition": {
"StringNotEqualsIfExists": {
"aws:ResourceAccount": [
"${aws:PrincipalAccount}"
]
}
},
"Sid": "DenyGettingQueueAttributesOnNonOwnQueue"
},
{
"Action": [
"sqs:SetQueueAttributes",
"sqs:GetQueueAttributes",
"sqs:ListQueues",
"sqs:GetQueueUrl"
],
"Resource": "*",
"Effect": "Deny",
"Condition": {
"StringNotLike": {
"aws:PrincipalArn": "arn:aws:iam::*:root"
}
},
"Sid": "DenyActionsForNonRootUser"
}
]
},
"IsDefaultVersion": true
}
}
Loading

0 comments on commit 4f952e0

Please sign in to comment.