Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add references to rules (duo_rules) #1007

Merged
merged 1 commit into from
Dec 12, 2023
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions rules/duo_rules/duo_admin_bypass_code_created.yml
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,7 @@ DisplayName: "Duo Admin Bypass Code Created"
Enabled: true
Filename: duo_admin_bypass_code_created.py
Runbook: Confirm this was authorized and necessary behavior.
Reference: https://duo.com/docs/administration-users#generating-a-bypass-code
Severity: Medium
Tests:
- ExpectedResult: true
Expand Down
1 change: 1 addition & 0 deletions rules/duo_rules/duo_admin_create_admin.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ Description: 'A new Duo Administrator was created. '
DisplayName: "Duo Admin Create Admin"
Enabled: true
Filename: duo_admin_create_admin.py
Reference: https://duo.com/docs/administration-admins#add-an-administrator
Severity: High
Tests:
- ExpectedResult: true
Expand Down
1 change: 1 addition & 0 deletions rules/duo_rules/duo_admin_mfa_restrictions_updated.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ Description: Detects changes to allowed MFA factors administrators can use to lo
DisplayName: "Duo Admin MFA Restrictions Updated"
Enabled: true
Filename: duo_admin_mfa_restrictions_updated.py
Reference: https://duo.com/docs/essentials-overview
Severity: Medium
Tests:
- ExpectedResult: true
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ Description: Identifies creation of new Admin API integrations for Duo.
DisplayName: "Duo Admin New Admin API App Integration"
Enabled: true
Filename: duo_admin_new_admin_api_app_integration.py
Reference: https://duo.com/docs/adminapi#overview
Severity: High
Tests:
- ExpectedResult: true
Expand Down
1 change: 1 addition & 0 deletions rules/duo_rules/duo_admin_policy_updated.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ Description: A Duo Administrator updated a Policy, which governs how users authe
DisplayName: "Duo Admin Policy Updated"
Enabled: true
Filename: duo_admin_policy_updated.py
Reference: https://duo.com/docs/policy#authenticators-policy-settings
Severity: Medium
Tests:
- ExpectedResult: true
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ Description: Detects when SAML Authentication for Administrators is marked as Di
DisplayName: "Duo Admin SSO SAML Requirement Disabled"
Enabled: true
Filename: duo_admin_sso_saml_requirement_disabled.py
Reference: https://duo.com/docs/sso#saml:~:text=Modify%20Authentication%20Sources
Severity: Medium
Tests:
- ExpectedResult: true
Expand Down
1 change: 1 addition & 0 deletions rules/duo_rules/duo_admin_user_mfa_bypass_enabled.yml
Original file line number Diff line number Diff line change
Expand Up @@ -3,6 +3,7 @@ Description: An Administrator enabled a user to authenticate without MFA.
DisplayName: "Duo Admin User MFA Bypass Enabled"
Enabled: true
Filename: duo_admin_user_mfa_bypass_enabled.py
Reference: https://duo.com/docs/policy#authentication-policy
Severity: Medium
Tests:
- ExpectedResult: false
Expand Down