id: Cloud Credentials Rotation - AWS version: -1 name: Cloud Credentials Rotation - AWS description: |- ## **AWS Credentials Rotation Playbook** ### **Identity Remediation** Secure compromised accounts by taking swift action: - **Reset Password**: Resets the user password to halt any unauthorized access. - **Access Key Deactivation**: Deactivate any suspicious or known-compromised access keys. - **Combo Action**: In some cases, you may want to reset both the password and deactivate the access key for absolute security. ### **Role Remediation** If a role is suspected to be compromised: - **Deny Policy Implementation**: Attach a deny-all policy to the compromised role, thus preventing it from performing any further actions. - **Role Cloning**: Before outright remediation, clone the role. This ensures that you have a backup with the same permissions, making transition smoother. starttaskid: "0" tasks: "0": id: "0" taskid: e31893d6-5dc6-4f63-8bea-7e87a3626950 type: start task: id: e31893d6-5dc6-4f63-8bea-7e87a3626950 version: -1 name: "" iscommand: false brand: "" description: '' nexttasks: '#none#': - "52" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 490, "y": -490 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "1": id: "1" taskid: 7184e6ea-8ff8-4956-8c4f-7e7d49e44f43 type: title task: id: 7184e6ea-8ff8-4956-8c4f-7e7d49e44f43 version: -1 name: Compute type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "53" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -40, "y": -165 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "10": id: "10" taskid: 474544c9-043c-4cfb-8f23-804aadb9ea6f type: title task: id: 474544c9-043c-4cfb-8f23-804aadb9ea6f version: -1 name: Identity type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "35" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1010, "y": -165 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "16": id: "16" taskid: 50995c28-10ca-4f42-8c2a-4d7635c60b1f type: regular task: id: 50995c28-10ca-4f42-8c2a-4d7635c60b1f version: -1 name: Deactivate the user's access key description: Changes the status of the specified access key from Active to Inactive, or vice versa. This operation can be used to disable a user's key as part of a key rotation workflow. script: '|||aws-iam-update-access-key' type: regular iscommand: true brand: "" nexttasks: '#none#': - "37" scriptarguments: accessKeyId: complex: root: inputs.accessKeyID status: simple: Inactive separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1240, "y": 280 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "17": id: "17" taskid: 346dec85-0477-4f49-819b-701179050d19 type: regular task: id: 346dec85-0477-4f49-819b-701179050d19 version: -1 name: Force password reset description: Changes the password for the specified IAM user. script: '|||aws-iam-update-login-profile' type: regular iscommand: true brand: "" nexttasks: '#none#': - "37" scriptarguments: newPassword: complex: root: NEW_PASSWORD passwordResetRequired: simple: "True" userName: complex: root: inputs.username separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1660, "y": 440 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "18": id: "18" taskid: 1f824e1c-2bcf-4204-8806-e89b4d144f97 type: regular task: id: 1f824e1c-2bcf-4204-8806-e89b4d144f97 version: -1 name: Describe regions description: Describes one or more regions that are currently available to you. script: '|||aws-ec2-describe-regions' type: regular iscommand: true brand: "" nexttasks: '#none#': - "20" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -40, "y": 330 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "20": id: "20" taskid: 33ef6c53-9f17-426e-82b3-756ed55a185e type: regular task: id: 33ef6c53-9f17-426e-82b3-756ed55a185e version: -1 name: Describe instances description: Describes one or more of your instances. script: '|||aws-ec2-describe-instances' type: regular iscommand: true brand: "" nexttasks: '#none#': - "22" scriptarguments: filters: simple: Name=iam-instance-profile.arn,Values=${AWS.EC2.IamInstanceProfileAssociations.IamInstanceProfile.Arn} region: complex: root: AWS.Regions accessor: RegionName separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -40, "y": 500 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "21": id: "21" taskid: 29547081-1a2e-4a6d-8576-51caf121a64d type: regular task: id: 29547081-1a2e-4a6d-8576-51caf121a64d version: -1 name: Describe IAM instance profile associations description: Describes your IAM instance profile associations. script: '|||aws-ec2-describe-iam-instance-profile-associations' type: regular iscommand: true brand: "" nexttasks: '#none#': - "18" scriptarguments: filters: simple: Name=instance-id,Values=${inputs.instanceID} separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -40, "y": 155 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "22": id: "22" taskid: 78bbcd2c-6182-4122-8a92-0c94bf784f58 type: regular task: id: 78bbcd2c-6182-4122-8a92-0c94bf784f58 version: -1 name: Get instance profile description: Retrieves information about the specified instance profile. script: '|||aws-iam-get-instance-profile' type: regular iscommand: true brand: "" nexttasks: '#none#': - "34" scriptarguments: instanceProfileName: complex: root: AWS.EC2.Instances.IamInstanceProfile accessor: Arn transformers: - operator: Cut args: delimiter: value: simple: / fields: value: simple: "2" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -40, "y": 675 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "23": id: "23" taskid: b4cca9fe-a91c-44fd-86a6-1d8cf0237267 type: regular task: id: b4cca9fe-a91c-44fd-86a6-1d8cf0237267 version: -1 name: List attached role policies description: List all managed policies that are attached to the specified IAM role. script: '|||aws-iam-list-attached-role-policies' type: regular iscommand: true brand: "" nexttasks: '#none#': - "55" scriptarguments: roleName: complex: root: AWS.IAM.InstanceProfiles.Roles accessor: RoleName separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 170, "y": 1300 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "24": id: "24" taskid: c6a5ddee-9189-4e0e-8ca9-3724362c5632 type: regular task: id: c6a5ddee-9189-4e0e-8ca9-3724362c5632 version: -1 name: List role inline-policies description: Lists the names of the inline policies that are embedded in the specified IAM role. script: '|||aws-iam-list-role-policies' type: regular iscommand: true brand: "" nexttasks: '#none#': - "54" scriptarguments: roleName: complex: root: AWS.IAM.InstanceProfiles.Roles accessor: RoleName separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -250, "y": 1460 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "25": id: "25" taskid: d01a4182-b82b-4372-8f46-292de9d16868 type: regular task: id: d01a4182-b82b-4372-8f46-292de9d16868 version: -1 name: Create instance profile description: Creates a new instance profile. script: '|||aws-iam-create-instance-profile' type: regular iscommand: true brand: "" nexttasks: '#none#': - "26" scriptarguments: instanceProfileName: complex: root: inputs.newInstanceProfileName separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -40, "y": 2360 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "26": id: "26" taskid: 397cd3fc-0559-4e90-85dd-17dcc0f0611f type: regular task: id: 397cd3fc-0559-4e90-85dd-17dcc0f0611f version: -1 name: Create role description: Creates a new role for your AWS account. script: '|||aws-iam-create-role' type: regular iscommand: true brand: "" nexttasks: '#none#': - "31" scriptarguments: assumeRolePolicyDocument: complex: root: AWS.IAM.InstanceProfiles.Roles accessor: AssumeRolePolicyDocument transformers: - operator: Stringify roleName: complex: root: inputs.newRoleName separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -40, "y": 2520 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "29": id: "29" taskid: 08733be8-8938-4261-8ca4-3634944d8d4e type: title task: id: 08733be8-8938-4261-8ca4-3634944d8d4e version: -1 name: Clone Compromised Service Account type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "48" - "47" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -40, "y": 1025 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "30": id: "30" taskid: a6106476-d3ca-4263-8ea6-7909e43e53eb type: title task: id: a6106476-d3ca-4263-8ea6-7909e43e53eb version: -1 name: Change Instance Profile IAM Role type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "33" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -560, "y": 3105 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "31": id: "31" taskid: 6539d1ad-9593-49b5-804a-13aff5eba217 type: regular task: id: 6539d1ad-9593-49b5-804a-13aff5eba217 version: -1 name: Attach role policy description: Attaches the specified managed policy to the specified IAM resource. script: '|||aws-iam-attach-policy' type: regular iscommand: true brand: "" nexttasks: '#none#': - "49" scriptarguments: entityName: complex: root: inputs.newRoleName policyArn: complex: root: AWS.IAM.Roles.AttachedPolicies.Policies accessor: PolicyArn type: simple: Role separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -40, "y": 2680 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "33": id: "33" taskid: 8d96c531-4f68-4e75-8264-066143a2d0c1 type: regular task: id: 8d96c531-4f68-4e75-8264-066143a2d0c1 version: -1 name: Attach deny policy to a role description: Adds or updates an inline policy document that is embedded in the specified IAM role. script: '|||aws-iam-put-role-policy' type: regular iscommand: true brand: "" nexttasks: '#none#': - "36" scriptarguments: policyDocument: simple: |- { "Version": "2012-10-17", "Statement": [ { "Effect": "Deny", "Action": "*", "Resource": "*" } ] } policyName: simple: XSIAM-DenyPolicy-Alert-${alert.id} roleName: complex: root: AWS.IAM.InstanceProfiles.Roles accessor: RoleName transformers: - operator: SetIfEmpty args: applyIfEmpty: {} defaultValue: value: simple: inputs.roleNameToRestrict iscontext: true separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -560, "y": 3240 } } note: false timertriggers: [] ignoreworker: false skipunavailable: true quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "34": id: "34" taskid: da40f794-fe96-4266-852b-65cfe91deb2e type: condition task: id: da40f794-fe96-4266-852b-65cfe91deb2e version: -1 name: Should clone before putting a deny policy? description: Checks whether to clone the service account before putting a deny policy to it. type: condition iscommand: false brand: "" nexttasks: '#default#': - "30" "Yes": - "29" separatecontext: false conditions: - label: "Yes" condition: - - operator: isEqualString left: value: simple: inputs.shouldCloneSA iscontext: true right: value: simple: "True" ignorecase: true continueonerrortype: "" view: |- { "position": { "x": -40, "y": 840 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "35": id: "35" taskid: d072f064-19a3-44cc-8a3c-b69d6cf02efd type: condition task: id: d072f064-19a3-44cc-8a3c-b69d6cf02efd version: -1 name: Check remediation type description: Checks the remediation type provided by the user. type: condition iscommand: false brand: "" nexttasks: '#default#': - "37" ALL: - "39" Deactivate Access Key: - "16" Reset Password: - "51" separatecontext: false conditions: - label: Deactivate Access Key condition: - - operator: isEqualString left: value: complex: root: inputs.IAMRemediationType iscontext: true right: value: simple: Deactivate ignorecase: true - label: Reset Password condition: - - operator: isEqualString left: value: complex: root: inputs.IAMRemediationType iscontext: true right: value: simple: Reset ignorecase: true - label: ALL condition: - - operator: isEqualString left: value: complex: root: inputs.IAMRemediationType iscontext: true right: value: simple: ALL ignorecase: true continueonerrortype: "" view: |- { "position": { "x": 1010, "y": -30 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "36": id: "36" taskid: 818b1edc-5cab-4940-88fc-4a3a25c547fd type: title task: id: 818b1edc-5cab-4940-88fc-4a3a25c547fd version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 490, "y": 3420 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "37": id: "37" taskid: 5c0c9617-db02-446a-820c-f43fd368debd type: title task: id: 5c0c9617-db02-446a-820c-f43fd368debd version: -1 name: Done type: title iscommand: false brand: "" description: '' separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1240, "y": 625 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "39": id: "39" taskid: 1015b828-1cf9-45d3-8aca-b2585e0dbd3d type: title task: id: 1015b828-1cf9-45d3-8aca-b2585e0dbd3d version: -1 name: ALL type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "16" - "51" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 2040, "y": 140 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "41": id: "41" taskid: 368e0611-9297-4445-8a8c-89529dcfc92d type: regular task: id: 368e0611-9297-4445-8a8c-89529dcfc92d version: -1 name: Set attached policies ARN description: Set a value in context under the key you entered. scriptName: Set type: regular iscommand: false brand: "" nexttasks: '#none#': - "45" scriptarguments: key: simple: attachedPoliciesARN value: complex: root: AWS.IAM.Roles.AttachedPolicies.Policies accessor: PolicyArn separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 170, "y": 1630 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "42": id: "42" taskid: 10287654-3015-469a-8a34-df6a48c0504d type: regular task: id: 10287654-3015-469a-8a34-df6a48c0504d version: -1 name: Set policies name description: Set a value in context under the key you entered. scriptName: Set type: regular iscommand: false brand: "" nexttasks: '#none#': - "44" scriptarguments: key: simple: policyNames value: complex: root: AWS.IAM.Roles accessor: Policies separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -250, "y": 1820 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "43": id: "43" taskid: 37908070-3c4c-4d1e-8203-be5a0d33db00 type: condition task: id: 37908070-3c4c-4d1e-8203-be5a0d33db00 version: -1 name: Were role policies document retrieved? description: Checks whether managed or inline policies are available. type: condition iscommand: false brand: "" nexttasks: '#default#': - "36" "yes": - "25" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: simple: AWS.IAM.Policies.Versions.Document iscontext: true right: value: {} - operator: isNotEmpty left: value: simple: AWS.IAM.Roles.PolicyDocument iscontext: true continueonerrortype: "" view: |- { "position": { "x": -40, "y": 2150 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "44": id: "44" taskid: 63fb652e-4520-43c8-8d43-2623e816b1c8 type: regular task: id: 63fb652e-4520-43c8-8d43-2623e816b1c8 version: -1 name: Get role policies description: Retrieves the specified inline policy document that is embedded with the specified IAM role. script: '|||aws-iam-get-role-policy' type: regular iscommand: true brand: "" nexttasks: '#none#': - "43" scriptarguments: policyName: complex: root: policyNames roleName: complex: root: AWS.IAM.InstanceProfiles.Roles accessor: RoleName separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -250, "y": 1980 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "45": id: "45" taskid: 0d3bb8ba-03e1-4a39-8dae-4878f0c16ae8 type: regular task: id: 0d3bb8ba-03e1-4a39-8dae-4878f0c16ae8 version: -1 name: List policy versions description: Lists information about the versions of the specified managed policy, including the version that is currently set as the policy's default version. script: '|||aws-iam-list-policy-versions' type: regular iscommand: true brand: "" nexttasks: '#none#': - "46" scriptarguments: policyArn: complex: root: attachedPoliciesARN separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 170, "y": 1820 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "46": id: "46" taskid: cfc564cd-cc7a-4706-88f5-16c70d6ca1a3 type: regular task: id: cfc564cd-cc7a-4706-88f5-16c70d6ca1a3 version: -1 name: Get policy version description: Retrieves information about the specified version of the specified managed policy, including the policy document. script: '|||aws-iam-get-policy-version' type: regular iscommand: true brand: "" nexttasks: '#none#': - "43" scriptarguments: policyArn: complex: root: AWS.IAM.Policies.Versions accessor: PolicyArn versionId: complex: root: AWS.IAM.Policies.Versions accessor: VersionId separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 170, "y": 1980 } } note: false timertriggers: [] ignoreworker: false fieldMapping: - incidentfield: Policy Details output: complex: root: AWS.IAM.Policies.Versions.Document accessor: Version transformers: - operator: toUpperCase skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "47": id: "47" taskid: 30ba96a4-3837-4635-8375-8a48796db293 type: title task: id: 30ba96a4-3837-4635-8375-8a48796db293 version: -1 name: Managed Policies type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "23" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 170, "y": 1170 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "48": id: "48" taskid: 89b9042f-b670-4972-8f0a-c739171e1789 type: title task: id: 89b9042f-b670-4972-8f0a-c739171e1789 version: -1 name: Inline Policies type: title iscommand: false brand: "" description: '' nexttasks: '#none#': - "24" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -250, "y": 1170 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "49": id: "49" taskid: 16340052-4dba-49d8-8078-7d20e460351e type: regular task: id: 16340052-4dba-49d8-8078-7d20e460351e version: -1 name: Put role policy description: Adds or updates an inline policy document that is embedded in the specified IAM role. script: '|||aws-iam-put-role-policy' type: regular iscommand: true brand: "" nexttasks: '#none#': - "30" scriptarguments: policyDocument: complex: root: AWS.IAM.Policies.Versions accessor: Document transformers: - operator: Stringify policyName: complex: root: policyNames roleName: complex: root: inputs.newRoleName separatecontext: false continueonerrortype: "" view: |- { "position": { "x": -40, "y": 2840 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "51": id: "51" taskid: c1b5e014-a3fc-4564-88b8-519a2903a86c type: regular task: id: c1b5e014-a3fc-4564-88b8-519a2903a86c version: -1 name: Generate a temporary password description: "This function generates a password and allows various parameters to customize the properties of the password depending on the use case (e.g. password complexity requirements). The default behavior is to generate a password of *random length* including all four character classes (upper, lower, digits, symbols) with at least five and at most ten characters per class. \n\nThe min_* values all default to 0. This means that if the command is executed in this way:\n!GeneratePassword max_lcase=10\nIt is possible that a password of length zero could be generated. It is therefore recommended to always include a min_* parameter that matches. \n\nThe debug parameter will print certain properties of the command into the WarRoom for easy diagnostics." scriptName: GeneratePassword type: regular iscommand: false brand: "" nexttasks: '#none#': - "17" scriptarguments: min_digits: simple: "5" min_lcase: simple: "5" min_symbols: simple: "2" min_ucase: simple: "2" separatecontext: false continueonerrortype: "" view: |- { "position": { "x": 1660, "y": 280 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "52": id: "52" taskid: 0cb9aa20-b9be-490b-871d-0f42d13d6641 type: condition task: id: 0cb9aa20-b9be-490b-871d-0f42d13d6641 version: -1 name: Check identity type description: Checks the identity type that was part of the alert. type: condition iscommand: false brand: "" nexttasks: '#default#': - "36" ROLE: - "1" USER: - "10" separatecontext: false conditions: - label: ROLE condition: - - operator: isEqualString left: value: complex: root: inputs.identityType iscontext: true right: value: simple: Compute ignorecase: true - - operator: isNotEmpty left: value: complex: root: inputs.instanceID iscontext: true - label: USER condition: - - operator: isEqualString left: value: complex: root: inputs.identityType iscontext: true right: value: simple: User ignorecase: true - - operator: isNotEmpty left: value: complex: root: inputs.username iscontext: true - operator: isNotEmpty left: value: complex: root: inputs.accessKeyID iscontext: true continueonerrortype: "" view: |- { "position": { "x": 490, "y": -350 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "53": id: "53" taskid: 9b78a8bb-3900-4e8c-8276-a0c02edf0f24 type: condition task: id: 9b78a8bb-3900-4e8c-8276-a0c02edf0f24 version: -1 name: Should investigate the compromised instance? description: Checks if the user provided a role name to put a deny policy to. type: condition iscommand: false brand: "" nexttasks: '#default#': - "30" "yes": - "21" separatecontext: false conditions: - label: "yes" condition: - - operator: isEmpty left: value: complex: root: inputs.roleNameToRestrict iscontext: true right: value: {} continueonerrortype: "" view: |- { "position": { "x": -40, "y": -30 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "54": id: "54" taskid: efee05cd-487f-4c72-87ef-21356f33de71 type: condition task: id: efee05cd-487f-4c72-87ef-21356f33de71 version: -1 name: 'Were role inline-policies retrieved? ' description: Checks if inline policies were found for the role. type: condition iscommand: false brand: "" nexttasks: '#default#': - "43" "yes": - "42" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: complex: root: AWS.IAM.Roles accessor: Policies iscontext: true continueonerrortype: "" view: |- { "position": { "x": -250, "y": 1630 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false "55": id: "55" taskid: 4ac0c6ae-8fee-4c34-8bac-c53528d788ef type: condition task: id: 4ac0c6ae-8fee-4c34-8bac-c53528d788ef version: -1 name: 'Were role managed policies retrieved? ' description: Checks if managed policies were found for the role. type: condition iscommand: false brand: "" nexttasks: '#default#': - "43" "yes": - "41" separatecontext: false conditions: - label: "yes" condition: - - operator: isNotEmpty left: value: complex: root: AWS.IAM.Roles.AttachedPolicies.Policies accessor: PolicyArn iscontext: true continueonerrortype: "" view: |- { "position": { "x": 170, "y": 1460 } } note: false timertriggers: [] ignoreworker: false skipunavailable: false quietmode: 0 isoversize: false isautoswitchedtoquietmode: false view: |- { "linkLabelsPosition": { "34_29_Yes": 0.39, "34_30_#default#": 0.17, "35_16_Deactivate Access Key": 0.58, "35_37_#default#": 0.35, "35_39_ALL": 0.7, "35_51_Reset Password": 0.83, "43_25_yes": 0.44, "43_36_#default#": 0.26, "52_10_USER": 0.49, "52_1_ROLE": 0.7, "52_36_#default#": 0.1, "53_21_yes": 0.46, "53_30_#default#": 0.12, "54_42_yes": 0.36, "54_43_#default#": 0.66, "55_41_yes": 0.4, "55_43_#default#": 0.5 }, "paper": { "dimensions": { "height": 3975, "width": 2980, "x": -560, "y": -490 } } } inputs: - key: IAMRemediationType value: {} required: false description: |- The response playbook provides the following remediation actions for IAM users: Reset - By entering "Reset" in the input, the playbook will execute password reset. Deactivate - By entering "Deactivate" in the input, the playbook will execute access key deactivation. ALL - By entering "ALL" in the input, the playbook will execute both password reset and access key deactivation. playbookInputQuery: - key: shouldCloneSA value: {} required: false description: |- Whether to clone the compromised SA before putting a deny policy to it. True/False playbookInputQuery: - key: identityType value: {} required: false description: |- The type of identity involved. Usually mapped to the incident field named 'cloudidentitytype'. e.g. USER,SERVICE_ACCOUNT,APPLICATION playbookInputQuery: - key: newRoleName value: simple: tempNewRoleName required: false description: The new role name to assign in the clone service account flow. playbookInputQuery: - key: newInstanceProfileName value: simple: tempNewInstanceProfileName required: false description: The new instance profile name to assign in the clone service account flow. playbookInputQuery: - key: accessKeyID value: {} required: false description: The access key ID. playbookInputQuery: - key: username value: {} required: false description: The user name. playbookInputQuery: - key: instanceID value: {} required: false description: The instance ID. playbookInputQuery: - key: roleNameToRestrict value: {} required: false description: If provided, the role will be attached with a deny policy without the compute instance analysis flow. playbookInputQuery: outputs: - contextPath: AWS.EC2.Instances description: AWS EC2 instance information. type: unknown - contextPath: AWS.IAM.InstanceProfiles description: AWS IAM instance profile information. type: unknown - contextPath: AWS.IAM.Roles.AttachedPolicies.Policies description: A list of managed policy names. type: unknown - contextPath: AWS.IAM.Roles.RoleName.Policies description: A list of policy names. tests: - No tests (auto formatted) fromversion: 6.9.0