Cloud Security Posture Management Playbooks v2.1.1
This pack provides the remediation playbooks for Cortex Cloud Issues and Cases.
- Author:
- Cortex XSOAR
- Support:
- xsoar
Cloud Runtime SecurityAgentixCloud Posture SecurityXSIAMCortex Cloud
Cloud Services
Automation Rules (47)
- Allow Access by Trusted Services
- Assign Managed Identity to Function App
- Assign Managed Identity to Web App
- Disable Network Access to Storage Account
- Disable Public & Private Access to VM Disk
- Disable Public Access on RDS
- Disable Remote Debugging on Azure App
- Disable Storage Account Cross Tenant Replication
- Enable Automatic Backup for RDS dB
- Enable Azure App Service Auth
- Enable CloudTrail Log Validation
- Enable CloudTrail Logging
- Enable Copy Tags on RDS Snapshot
- Enable Deletion Protection on RDS
- Enable GCP Bucket Versioning
- Enable GKE Cluster Intra-node Visibility
- Enable IAM Authentication on RDS
- Enable IAM Authentication on RDS Cluster
- Enable Master Authorized Networks on GKE
- Enable RDS Auto Upgrade
- Enable RDS Cluster Deletion Protection
- Enable S3 Versioning
- Enable Soft Delete on Blob
- Make GCP Bucket Private
- Remediation playbook for AWS EC2 misconfigurations
- Remediation playbook for AWS IAM Password Policy Misconfiguration
- Remediation playbook for AWS S3 Bucket Publicly accessible
- Remove GCP Bucket AllAuthenticatedUser Access
- Remove GCP Bucket AllUsers Access
- Set AMI to Private
- Set Function App HTTP Version to 2.0
- Set Function App Min TLS Version
- Set GCP Bucket Access to Uniform
- Set RDS Cluster Snapshot to Private
- Set RDS Snapshot to Private
- Set Secure Transport for MySQL
- Set Snapshot to Private
- Set Storage Account to HTTPS only
- Set Web App Min TLS Version
- Set Webapp HTTP Version to 2.0
- Trigger - AWS Network Exposure
- Trigger - AWS Public Access Misconfiguration
- Trigger - Azure Network Exposure
- Trigger - Azure Public Access Misconfiguration
- Trigger - GCP Network Exposure
- Trigger - GCP Public Access Misconfiguration
- Update Azure Monitor Log Retention Period
README
Overview
This content pack helps fix common cloud misconfigurations automatically with analyst approval or performs auto-remediation without approval, optionally notifying stakeholders. It also includes two versatile, cloud-agnostic playbooks for creating tickets and sending notifications via ServiceNow, Jira, Email, Slack, or Microsoft Teams.
Key Use Cases
- Automatically remediate AWS misconfigurations with optional analyst approval.
- Automatically remediate AWS, Azure, and GCP public access misconfigurations with minimal or no manual intervention.
- Create or update issue tickets in Jira or ServiceNow.
- Notify teams through Slack, Microsoft Teams, or email.
Included Playbooks
AWS Remediation Playbooks
AWS EC2 Instance Misconfiguration Remediation
- Ensures EC2 instances are configured with Instance Metadata Service v2 (IMDSv2).
- Offers analyst-in-the-loop or fully automated remediation.
- Integrates with AWS and Cortex Core IR.
AWS IAM Password Policy Remediation
-
Remediates 9 different insecure IAM password policy configurations, such as:
- Password reuse
- Minimum password length
- Lack of complexity requirements (uppercase, symbols, etc.)
- No expiration policy
-
Supports both automated and analyst approval flows.
AWS S3 Bucket Public Access Remediation
- Detects and remediates publicly accessible S3 buckets (read or write access).
- Ensures S3 compliance with cloud security policies.
AWS Public Access Misconfiguration - Auto-remediate
- Automatically disables public access settings for RDS Database instances, EBS Snapshots and S3 buckets.
- Option to notify stakeholders about the remediation via Email, Slack or MS Teams.
- Set enableNotifications to ‘yes’ and configure inputs for the Notify Stakeholders playbook to send issue, asset and remediation details.
Azure Remediation Playbooks
Azure Public Access Misconfiguration - Auto-remediate
- Automatically remediates the misconfiguration issues for publicly accessible Azure blob containers, overly permissive Azure VM Disks or default Allow network access to Azure Storage Accounts.
- Option to notify stakeholders about the remediation via Email, Slack or MS Teams.
- Set enableNotifications to ‘yes’ and configure inputs for the Notify Stakeholders playbook to send issue, asset and remediation details.
GCP Remediation Playbooks
GCP Public Access Misconfiguration - Auto-remediate
- Automatically secure the publicly exposed GCP bucket by updating policies to block public access immediately.
- Option to notify stakeholders about the remediation via Email, Slack or MS Teams.
- Set enableNotifications to ‘yes’ and configure inputs for the Notify Stakeholders playbook to send issue, asset and remediation details.
All remediation playbooks leverage:
- AWS integrations
- Sub-playbooks for ticket creation and/or notification
- Context-aware command execution
Generic Utility Playbook
Create Ticket and Notify
- Creates or updates incident tickets using Jira V3 or ServiceNow v2.
- Notifies stakeholders via Slack, Microsoft Teams, or email.
- Customizable behavior: ticket-only, notification-only, or both.
- Detects available integrations and adapts accordingly.
Notify Stakeholders
- This is a sub-playbook that is used in the Public Access Misconfiguration remediation playbooks for AWS, Azure, and GCP.
- It is used to send issue and asset details along with the remediation action taken, in a well formatted notification message via Email, Slack or MS Teams, depending on the configured and enabled integrations.
- Configure recipients for email, slack or MS Teams notification in the Playbook Triggered header of this playbook
- If no inputs are pre-configured and enableNotifications is set to ‘yes’ in the remediation playbook, execution will pause to request at least one recipient.
Dependencies
This pack uses the following integrations:
- AWS
- Azure
- GCP
- Cortex Core - IR
- Jira V3
- ServiceNow v2
- Microsoft Teams
- SlackV3
- mail-sender
Future Roadmap
- Additional coverage for High/Critical severity AWS, Azure, and GCP misconfiguration issues
Requirements
- Active integrations for AWS, Azure, GCP, Jira, ServiceNow, Slack, Microsoft Teams (depending on use)
- Access to cloud account APIs with sufficient permissions for remediation
Pack Contributors
- Shashi Testman
- Ann Testman
- Marc Cyr
- Anmol Baansal
Contributions are welcome and appreciated. For more info, visit our Contribution Guide.