Prisma Cloud Remediation - Azure Storage Blob Misconfiguration
This playbook remediates the following Prisma Cloud Azure Storage blob alerts. Prisma Cloud policies remediated: - Azure storage account has a blob container with public access - Azure storage account logging for blobs is disabled
Prisma Cloud by Palo Alto Networks · 9 tasks · 1 input · 0 outputs
Details
| ID | Prisma Cloud Remediation - Azure Storage Blob Misconfiguration |
|---|---|
| From Version | 5.0.0 |
| Tasks | 9 |
README
This playbook remediates the following Prisma Cloud Azure Storage blob alerts.
Prisma Cloud policies remediated:
- Azure storage account has a blob container with public access
- Azure storage account logging for blobs is disabled
Dependencies
This playbook uses the following sub-playbooks, integrations, and scripts.
Sub-playbooks
This playbook does not use any sub-playbooks.
Integrations
- Azure Storage
Scripts
- IsIntegrationAvailable
Commands
- azure-storage-account-create-update
Playbook Inputs
| Name | Description | Default Value | Required |
|---|---|---|---|
| policyId | Prisma Cloud policy Id. | Required |
Playbook Outputs
There are no outputs for this playbook.
Playbook Image
' setting to greater than or equal to 90 days Note: The default value for the retention period is 0 (unlimited retention). 8. Click on 'Ok' 9. Click on 'Save' type: regular iscommand: false brand: "" nexttasks: '#none#': - "3" separatecontext: false view: |- { "position": { "x": 840, "y": 650 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "12": id: "12" taskid: 969cc2cc-e279-44a0-85ba-52679ea457bc type: title task: id: 969cc2cc-e279-44a0-85ba-52679ea457bc version: -1 name: Public access description: "" type: title iscommand: false brand: "" nexttasks: '#none#': - "22" separatecontext: false view: |- { "position": { "x": 290, "y": 500 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "15": id: "15" taskid: 5d417179-2b35-4255-8b78-50adcd0a9bed type: condition task: id: 5d417179-2b35-4255-8b78-50adcd0a9bed version: -1 name: Is Azure Storage integration enabled? description: Returns 'yes' if integration brand is available. Otherwise returns 'no' scriptName: IsIntegrationAvailable type: condition iscommand: false brand: "" nexttasks: '#default#': - "3" "yes": - "5" scriptarguments: brandname: simple: Azure Storage results: - brandInstances separatecontext: false view: |- { "position": { "x": 630, "y": 160 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "21": id: "21" taskid: fc68be83-eeeb-40d4-802f-8fe8afb0cf2d type: title task: id: fc68be83-eeeb-40d4-802f-8fe8afb0cf2d version: -1 name: Secure transfer is disabled description: "" type: title iscommand: false brand: "" nexttasks: '#none#': - "27" separatecontext: false view: |- { "position": { "x": 1350, "y": 500 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "22": id: "22" taskid: 5fa20ec1-d22a-4d2d-839d-3c8d3339fd42 type: regular task: id: 5fa20ec1-d22a-4d2d-839d-3c8d3339fd42 version: -1 name: Disable blob public access description: |- Run this command to create or update a specific account storage. script: Azure Storage|||azure-storage-account-create-update type: regular iscommand: true brand: Azure Storage nexttasks: '#none#': - "3" scriptarguments: access_tier: {} account_name: complex: root: incident.labels accessor: resource transformers: - operator: ParseJSON - operator: getField args: field: value: simple: data - operator: getField args: field: value: simple: name allow_blob_public_access: simple: "false" custom_domain_name: {} enc_key_source: {} enc_keyvault_key_name: {} enc_keyvault_key_version: {} enc_keyvault_uri: {} enc_requireInfrastructureEncryption: {} is_hns_enabled: {} kind: complex: root: incident.labels accessor: resource transformers: - operator: ParseJSON - operator: getField args: field: value: simple: data - operator: getField args: field: value: simple: kind large_file_shares_state: {} location: complex: root: incident.labels accessor: resource transformers: - operator: ParseJSON - operator: getField args: field: value: simple: data - operator: getField args: field: value: simple: location minimum_tls_version: {} network_ruleset_bypass: {} network_ruleset_default_action: {} network_ruleset_ipRules: {} sku: complex: root: incident.labels accessor: resource transformers: - operator: ParseJSON - operator: getField args: field: value: simple: data - operator: getField args: field: value: simple: sku - operator: getField args: field: value: simple: tier supports_https_traffic_only: {} tags: {} use_sub_domain_name: {} virtual_network_rules: {} separatecontext: false view: |- { "position": { "x": 290, "y": 650 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 "27": id: "27" taskid: c5b24d61-3807-4248-86ee-be23e0236c1a type: regular task: id: c5b24d61-3807-4248-86ee-be23e0236c1a version: -1 name: Enable blob secure transfer description: |- Run this command to create or update a specific account storage. script: Azure Storage|||azure-storage-account-create-update type: regular iscommand: true brand: Azure Storage nexttasks: '#none#': - "3" scriptarguments: access_tier: {} account_name: complex: root: incident.labels accessor: resource transformers: - operator: ParseJSON - operator: getField args: field: value: simple: data - operator: getField args: field: value: simple: name allow_blob_public_access: {} custom_domain_name: {} enc_key_source: {} enc_keyvault_key_name: {} enc_keyvault_key_version: {} enc_keyvault_uri: {} enc_requireInfrastructureEncryption: {} is_hns_enabled: {} kind: complex: root: incident.labels accessor: resource transformers: - operator: ParseJSON - operator: getField args: field: value: simple: data - operator: getField args: field: value: simple: kind large_file_shares_state: {} location: complex: root: incident.labels accessor: resource transformers: - operator: ParseJSON - operator: getField args: field: value: simple: data - operator: getField args: field: value: simple: location minimum_tls_version: {} network_ruleset_bypass: {} network_ruleset_default_action: {} network_ruleset_ipRules: {} sku: complex: root: incident.labels accessor: resource transformers: - operator: ParseJSON - operator: getField args: field: value: simple: data - operator: getField args: field: value: simple: sku - operator: getField args: field: value: simple: tier supports_https_traffic_only: simple: "true" tags: {} use_sub_domain_name: {} virtual_network_rules: {} separatecontext: false view: |- { "position": { "x": 1350, "y": 650 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 view: |- { "linkLabelsPosition": { "15_3_#default#": 0.1, "15_5_yes": 0.55, "5_10_#default#": 0.65, "5_21_secureTransfer": 0.7 }, "paper": { "dimensions": { "height": 945, "width": 1440, "x": 290, "y": 0 } } } inputs: - key: policyId value: {} required: true description: Prisma Cloud policy Id. playbookInputQuery: outputs: [] tests: - No Test