All tutorials

Every rule

Cordon 0.6.053 sections · 0 diagramsView this tutorial on GitHub

All 1,384 detection rules Cordon defines itself, grouped by what they watch, with the severity each reports at, and after them every Agent Threat Rule it carries. Rendered from the detectors and rule packs themselves. cordon-scanner rules show <id> prints one in full, with its remediation and references; rules test runs every rule's own samples.

   MALWARE.*       evidence of intent to harm: fails the build by default   SUSPECT.*       a behaviour or shape attackers use: worth a look   VULNERABLE.*    a known vulnerability in what you ship   SECRET.*        a credential in the code or its history   POLICY.*        a choice the project made about itself   OPERATIONAL.*   what the scan could not do, said out loud

32 rules.

RuleSeverityWhat it catches
MALWARE.AGENT.AUTORUN.001criticalA command an editor or agent runs on its own attacks the machine
MALWARE.AGENT.HOOK_EXFIL.001criticalAn agent hook that sends credentials away or opens a remote shell
MALWARE.AGENT.HOOK_FETCH_EXEC.001criticalAn agent hook that fetches and executes remote code
POLICY.AGENT.AUTO_APPROVE.001highAgent confirmations switched off in committed settings
POLICY.AGENT.MCP_BROAD_SCOPE.001mediumA filesystem MCP server given the whole disk or home directory
POLICY.AGENT.WIDE_DIRECTORY.001mediumAgent given the whole disk or home directory to work in
POLICY.AGENT.WILDCARD_PERMISSION.001mediumAgent permissions allow any shell command
SUSPECT.AGENT.API_REDIRECT.001highAgent API traffic redirected to a host that is not the provider
SUSPECT.AGENT.ATR.AGENT_MANIPULATION.001mediumText that impersonates an agent or hijacks the agent's task
SUSPECT.AGENT.ATR.CONTEXT_EXFILTRATION.001mediumText that asks an agent to move secrets or context off the machine
SUSPECT.AGENT.ATR.DATA_POISONING.001mediumText that plants triggers or false facts for an agent
SUSPECT.AGENT.ATR.EXCESSIVE_AUTONOMY.001mediumText that asks an agent to act without the user's confirmation
SUSPECT.AGENT.ATR.MODEL_ABUSE.001mediumText that turns an agent toward abuse of the model
SUSPECT.AGENT.ATR.MODEL_SECURITY.001mediumText that targets the model's weights or safety
SUSPECT.AGENT.ATR.PRIVILEGE_ESCALATION.001mediumText that asks an agent to widen its own permissions
SUSPECT.AGENT.ATR.PROMPT_INJECTION.001mediumText that tries to override an agent's instructions
SUSPECT.AGENT.ATR.SKILL_COMPROMISE.001mediumA skill or plugin shaped like a known compromise
SUSPECT.AGENT.ATR.TOOL_POISONING.001mediumText that turns a tool into a channel for steering the agent
SUSPECT.AGENT.CI_PROMPT_INJECTION.001highUntrusted event text passed straight into an agent's prompt
SUSPECT.AGENT.CI_UNTRUSTED_TRIGGER.001highAn AI agent in CI reads text an outsider can write
SUSPECT.AGENT.CREDENTIAL_EXFIL.001criticalAgent instructions that move credentials somewhere
SUSPECT.AGENT.FETCH_EXEC.001highAgent instructions that fetch and execute remote code
SUSPECT.AGENT.HIDDEN_TEXT.001highHidden characters in an agent instruction file
SUSPECT.AGENT.HOOK.001mediumAn agent hook committed to the repository
SUSPECT.AGENT.INJECTION_TEXT.001mediumInstruction-like text aimed at a coding agent
SUSPECT.AGENT.INTENT.001highText that tells the agent to act against its user
SUSPECT.AGENT.INTENT_CHAINED.001highAgent instructions that send the agent to a file that acts against its user
SUSPECT.AGENT.JUDGED.001mediumA language model judges agent-facing text to be subverting the agent
SUSPECT.AGENT.PLUGIN_SOURCE.001highAgent plugins installed from an unverified source
SUSPECT.AGENT.REMOTE_INSTRUCTIONS.001mediumAn agent instruction file tells the agent to fetch and follow remote text
SUSPECT.AGENT.SENSITIVE_IMPORT.001highAn agent instruction file imports a credential file
VULNERABLE.AGENT.ACTION_VERSION.001highAn AI agent action below its security fix

2 rules.

RuleSeverityWhat it catches
MALWARE.ANTI_ANALYSIS.001criticalInstall-time code that checks whether it is being watched
SUSPECT.ANTI_ANALYSIS.001highBehaviour gated on whether it is being observed

3 rules.

RuleSeverityWhat it catches
SUSPECT.ARCHIVE.NESTING.001highArchives nested past the depth the scan opens
SUSPECT.ARCHIVE.PATH_ESCAPE.001highArchive member named to write outside the archive
SUSPECT.ARCHIVE.POLYGLOT.001highArchive that is a tarball and a zip at once

16 rules.

RuleSeverityWhat it catches
POLICY.AZURE.DELETION_PROTECTION.KEYVAULT_VAULTS_ENABLEPURGEPROTECTION.001mediumMicrosoft.KeyVault/vaults: a deleted vault can be purged immediately
POLICY.AZURE.DELETION_PROTECTION.KEYVAULT_VAULTS_ENABLESOFTDELETE.001mediumMicrosoft.KeyVault/vaults: a deleted secret is gone immediately
POLICY.AZURE.RBAC.KEYVAULT_VAULTS_ENABLERBACAUTHORIZATION.001lowMicrosoft.KeyVault/vaults: access is governed by vault access policies rather than RBAC
POLICY.AZURE.SHARED_KEY_AUTH.ANY_DISABLELOCALAUTH.001mediumMicrosoft.*: shared-key authentication is enabled
POLICY.AZURE.SHARED_KEY_AUTH.STORAGE_STORAGEACCOUNTS_ALLOWSHAREDKEYACCESS.001mediumMicrosoft.Storage/storageAccounts: the account key authenticates callers
POLICY.AZURE.WEAK_TLS.STORAGE_STORAGEACCOUNTS_MINIMUMTLSVERSION.001mediumMicrosoft.Storage/storageAccounts: an obsolete TLS version is accepted
SUSPECT.AZURE.NETWORK_DEFAULT_ALLOW.ANY_DEFAULTACTION.001mediumMicrosoft.*: the network rules default to allowing everything
SUSPECT.AZURE.NO_AUTH.CONTAINERREGISTRY_REGISTRIES_ANONYMOUSPULLENABLED.001highMicrosoft.ContainerRegistry/registries: anyone may pull images from the registry
SUSPECT.AZURE.OPEN_INGRESS.NETWORK_NETWORKSECURITYGROUPS_SOURCEADDRESSPREFIX.001highMicrosoft.Network/networkSecurityGroups: an administrative port is open to the whole internet
SUSPECT.AZURE.PASSWORD_AUTH.COMPUTE_VIRTUALMACHINES_DISABLEPASSWORDAUTHENTICATION.001mediumMicrosoft.Compute/virtualMachines: SSH password authentication is enabled
SUSPECT.AZURE.PLAINTEXT.STORAGE_STORAGEACCOUNTS_SUPPORTSHTTPSTRAFFICONLY.001highMicrosoft.Storage/storageAccounts: the storage account accepts plain HTTP
SUSPECT.AZURE.PLAINTEXT.WEB_SITES_FTPSSTATE.001mediumMicrosoft.Web/sites: deployment over plain FTP is allowed
SUSPECT.AZURE.PLAINTEXT.WEB_SITES_HTTPSONLY.001mediumMicrosoft.Web/sites: the site answers plain HTTP
SUSPECT.AZURE.PUBLIC_ACCESS.ANY_PUBLICNETWORKACCESS.001mediumMicrosoft.*: the resource answers on a public endpoint
SUSPECT.AZURE.PUBLIC_STORAGE.STORAGE_STORAGEACCOUNTS_ALLOWBLOBPUBLICACCESS.001highMicrosoft.Storage/storageAccounts: containers may be made public
SUSPECT.AZURE.SHARED_KEY_AUTH.CONTAINERREGISTRY_REGISTRIES_ADMINUSERENABLED.001mediumMicrosoft.ContainerRegistry/registries: the shared admin account is enabled

10 rules.

RuleSeverityWhat it catches
POLICY.BINARY.COMMITTED.001lowExecutable committed to a source repository
SUSPECT.BINARY.CREDENTIAL_THEFT.001highCommitted binary imports credential-store and network calls
SUSPECT.BINARY.EXECUTABLE_PATH.001highExecutable committed where a lifecycle step will run it
SUSPECT.BINARY.HIDDEN_IMPORTS.001mediumCommitted binary resolves its imports at run time
SUSPECT.BINARY.IMPLANT.001highCommitted binary imports download-and-run calls
SUSPECT.BINARY.KEYLOGGER.001mediumCommitted binary imports keyboard-capture and network calls
SUSPECT.BINARY.NATIVE_IN_PURE_WHEEL.001highA pure-Python wheel loads a native library it carries
SUSPECT.BINARY.PACKED.001mediumCommitted binary is packed
SUSPECT.BINARY.PROCESS_INJECTION.001highCommitted binary imports process-injection calls
SUSPECT.BINARY.STRINGS.001mediumCommitted binary contains a URL, command or credential path

5 rules.

RuleSeverityWhat it catches
POLICY.BUILD.UNPINNED_DEPENDENCY.001mediumBuild dependency resolves to whatever is newest, not a fixed version
POLICY.BUILD.WRAPPER_UNVERIFIED.001lowBuild wrapper downloads its tool without a checksum
SUSPECT.BUILD.CMAKE_FETCH_UNVERIFIED.001mediumCMake fetches a URL with nothing verifying what it downloaded
SUSPECT.BUILD.MAKE_FETCH_EXEC.001highMakefile recipe fetches and executes remote content
SUSPECT.BUILD.MSBUILD_FETCH_EXEC.001highMSBuild target fetches and executes remote content

19 rules.

RuleSeverityWhat it catches
MALWARE.CI.SECRET_EXFIL.001criticalCI workflow serialises its secret context
POLICY.CI.UNPINNED_ACTION.001mediumAction referenced by a mutable tag
POLICY.CI.UNPINNED_REUSABLE_WORKFLOW.001mediumReusable workflow called by a mutable ref
POLICY.CI.WRITE_ALL_PERMISSIONS.001mediumWorkflow token is granted every write scope
SUSPECT.CI.ARTIFACT_POISONING.001highUntrusted build uploads or restores a cache it can control
SUSPECT.CI.AZURE_INJECTION.001highAzure Pipelines script interpolates a contributor-controlled value
SUSPECT.CI.BITBUCKET_INJECTION.001highBitbucket Pipelines step re-parses a contributor-controlled branch name
SUSPECT.CI.BUILDKITE_INJECTION.001highBuildkite pipeline interpolates a contributor-controlled value at upload
SUSPECT.CI.CACHE_POISONING.001mediumA publishing workflow restores a cache an untrusted run can write
SUSPECT.CI.CIRCLE_INJECTION.001highCircleCI step interpolates a contributor-controlled pipeline value
SUSPECT.CI.EXPRESSION_INJECTION.001highUntrusted pipeline input interpolated into a shell command
SUSPECT.CI.FETCH_EXEC.001highCI step fetches and executes remote content
SUSPECT.CI.GITLAB_INJECTION.001highGitLab job interpolates a contributor-controlled variable into a script
SUSPECT.CI.JENKINS_INJECTION.001highJenkins shell step interpolates a contributor-controlled value
SUSPECT.CI.PR_TARGET.001highWorkflow uses pull_request_target and checks out the pull request head
SUSPECT.CI.SECRET_EGRESS.001mediumPipeline step reads a secret and sends data off the runner
SUSPECT.CI.SECRET_OVERPROVISION.001highCI workflow hands another workflow every secret it has
SUSPECT.CI.SELF_HOSTED_FORK.001highA fork's pull request runs on a self-hosted runner
SUSPECT.CI.WORKFLOW_RUN_CHECKOUT.001highworkflow_run checks out the commit that triggered it

3 rules.

RuleSeverityWhat it catches
MALWARE.CLAMAV.SIGNATURE.001criticalClamAV recognises the file as malware
OPERATIONAL.CLAMAV.STATUSinfoClamAV examined the scan's files
OPERATIONAL.CLAMAV.UNAVAILABLEinfoClamAV was asked for and could not be used

232 rules.

RuleSeverityWhat it catches
POLICY.CFN.CMEK.AWS_AIOPS_INVESTIGATIONGROUP.001lowcfn:AWS::AIOps::InvestigationGroup: a customer-managed key
POLICY.CFN.CMEK.AWS_AMAZONMQ_BROKER.001lowcfn:AWS::AmazonMQ::Broker: a customer-managed key
POLICY.CFN.CMEK.AWS_APS_WORKSPACE.001lowcfn:AWS::APS::Workspace: a customer-managed key
POLICY.CFN.CMEK.AWS_BACKUPGATEWAY_HYPERVISOR.001lowcfn:AWS::BackupGateway::Hypervisor: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCKAGENTCORE_CAPACITYPROVIDER.001lowcfn:AWS::BedrockAgentCore::CapacityProvider: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCKAGENTCORE_CONFIGURATIONBUNDLE.001lowcfn:AWS::BedrockAgentCore::ConfigurationBundle: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCKAGENTCORE_DATASET.001lowcfn:AWS::BedrockAgentCore::Dataset: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCKAGENTCORE_EVALUATOR.001lowcfn:AWS::BedrockAgentCore::Evaluator: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCKAGENTCORE_GATEWAY.001lowcfn:AWS::BedrockAgentCore::Gateway: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCK_AUTOMATEDREASONINGPOLICY.001lowcfn:AWS::Bedrock::AutomatedReasoningPolicy: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCK_BLUEPRINT.001lowcfn:AWS::Bedrock::Blueprint: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCK_DATAAUTOMATIONLIBRARY.001lowcfn:AWS::Bedrock::DataAutomationLibrary: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCK_DATAAUTOMATIONPROJECT.001lowcfn:AWS::Bedrock::DataAutomationProject: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCK_DATASOURCE.001lowcfn:AWS::Bedrock::DataSource: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCK_GUARDRAIL.001lowcfn:AWS::Bedrock::Guardrail: a customer-managed key
POLICY.CFN.CMEK.AWS_BEDROCK_KNOWLEDGEBASE.001lowcfn:AWS::Bedrock::KnowledgeBase: a customer-managed key
POLICY.CFN.CMEK.AWS_CLEANROOMSML_CONFIGUREDMODELALGORITHM.001lowcfn:AWS::CleanRoomsML::ConfiguredModelAlgorithm: a customer-managed key
POLICY.CFN.CMEK.AWS_CLEANROOMS_IDMAPPINGTABLE.001lowcfn:AWS::CleanRooms::IdMappingTable: a customer-managed key
POLICY.CFN.CMEK.AWS_CLEANROOMS_INTERMEDIATETABLE.001lowcfn:AWS::CleanRooms::IntermediateTable: a customer-managed key
POLICY.CFN.CMEK.AWS_CLOUDTRAIL_EVENTDATASTORE.001lowcfn:AWS::CloudTrail::EventDataStore: a customer-managed key
POLICY.CFN.CMEK.AWS_CODECOMMIT_REPOSITORY.001lowcfn:AWS::CodeCommit::Repository: a customer-managed key
POLICY.CFN.CMEK.AWS_COGNITO_USERPOOL.001lowcfn:AWS::Cognito::UserPool: a customer-managed key
POLICY.CFN.CMEK.AWS_COMPREHEND_DOCUMENTCLASSIFIER.001lowcfn:AWS::Comprehend::DocumentClassifier: a customer-managed key
POLICY.CFN.CMEK.AWS_DATAEXCHANGE_EVENTACTION.001lowcfn:AWS::DataExchange::EventAction: a customer-managed key
POLICY.CFN.CMEK.AWS_DATASYNC_LOCATIONAZUREBLOB.001lowcfn:AWS::DataSync::LocationAzureBlob: a customer-managed key
POLICY.CFN.CMEK.AWS_DATASYNC_LOCATIONFSXONTAP.001lowcfn:AWS::DataSync::LocationFSxONTAP: a customer-managed key
POLICY.CFN.CMEK.AWS_DATASYNC_LOCATIONFSXWINDOWS.001lowcfn:AWS::DataSync::LocationFSxWindows: a customer-managed key
POLICY.CFN.CMEK.AWS_DATASYNC_LOCATIONHDFS.001lowcfn:AWS::DataSync::LocationHDFS: a customer-managed key
POLICY.CFN.CMEK.AWS_DATASYNC_LOCATIONOBJECTSTORAGE.001lowcfn:AWS::DataSync::LocationObjectStorage: a customer-managed key
POLICY.CFN.CMEK.AWS_DATASYNC_LOCATIONSMB.001lowcfn:AWS::DataSync::LocationSMB: a customer-managed key
POLICY.CFN.CMEK.AWS_DEADLINE_FARM.001lowcfn:AWS::Deadline::Farm: a customer-managed key
POLICY.CFN.CMEK.AWS_DEVOPSAGENT_AGENTSPACE.001lowcfn:AWS::DevOpsAgent::AgentSpace: a customer-managed key
POLICY.CFN.CMEK.AWS_DEVOPSAGENT_SERVICE.001lowcfn:AWS::DevOpsAgent::Service: a customer-managed key
POLICY.CFN.CMEK.AWS_DMS_ENDPOINT.001lowcfn:AWS::DMS::Endpoint: a customer-managed key
POLICY.CFN.CMEK.AWS_DMS_INSTANCEPROFILE.001lowcfn:AWS::DMS::InstanceProfile: a customer-managed key
POLICY.CFN.CMEK.AWS_DMS_REPLICATIONCONFIG.001lowcfn:AWS::DMS::ReplicationConfig: a customer-managed key
POLICY.CFN.CMEK.AWS_DMS_REPLICATIONINSTANCE.001lowcfn:AWS::DMS::ReplicationInstance: a customer-managed key
POLICY.CFN.CMEK.AWS_DOCDBELASTIC_CLUSTER.001lowcfn:AWS::DocDBElastic::Cluster: a customer-managed key
POLICY.CFN.CMEK.AWS_DOCDB_DBCLUSTER.001lowcfn:AWS::DocDB::DBCluster: a customer-managed key
POLICY.CFN.CMEK.AWS_EC2_VERIFIEDACCESSENDPOINT.001lowcfn:AWS::EC2::VerifiedAccessEndpoint: a customer-managed key
POLICY.CFN.CMEK.AWS_EC2_VERIFIEDACCESSGROUP.001lowcfn:AWS::EC2::VerifiedAccessGroup: a customer-managed key
POLICY.CFN.CMEK.AWS_EC2_VERIFIEDACCESSTRUSTPROVIDER.001lowcfn:AWS::EC2::VerifiedAccessTrustProvider: a customer-managed key
POLICY.CFN.CMEK.AWS_EC2_VOLUME.001lowcfn:AWS::EC2::Volume: a customer-managed key
POLICY.CFN.CMEK.AWS_ECS_CLUSTER.001lowcfn:AWS::ECS::Cluster: a customer-managed key
POLICY.CFN.CMEK.AWS_EFS_FILESYSTEM.001lowcfn:AWS::EFS::FileSystem: a customer-managed key
POLICY.CFN.CMEK.AWS_ELASTICACHE_REPLICATIONGROUP.001lowcfn:AWS::ElastiCache::ReplicationGroup: a customer-managed key
POLICY.CFN.CMEK.AWS_ELASTICACHE_SERVERLESSCACHE.001lowcfn:AWS::ElastiCache::ServerlessCache: a customer-managed key
POLICY.CFN.CMEK.AWS_ELASTICACHE_SERVERLESSCACHESNAPSHOT.001lowcfn:AWS::ElastiCache::ServerlessCacheSnapshot: a customer-managed key
POLICY.CFN.CMEK.AWS_ELASTICSEARCH_DOMAIN.001lowcfn:AWS::Elasticsearch::Domain: a customer-managed key
POLICY.CFN.CMEK.AWS_EVS_ENVIRONMENT.001lowcfn:AWS::EVS::Environment: a customer-managed key
POLICY.CFN.CMEK.AWS_FINSPACE_ENVIRONMENT.001lowcfn:AWS::FinSpace::Environment: a customer-managed key
POLICY.CFN.CMEK.AWS_FORECAST_DATASET.001lowcfn:AWS::Forecast::Dataset: a customer-managed key
POLICY.CFN.CMEK.AWS_FSX_FILECACHE.001lowcfn:AWS::FSx::FileCache: a customer-managed key
POLICY.CFN.CMEK.AWS_FSX_FILESYSTEM.001lowcfn:AWS::FSx::FileSystem: a customer-managed key
POLICY.CFN.CMEK.AWS_GLUE_CONNECTION.001lowcfn:AWS::Glue::Connection: a customer-managed key
POLICY.CFN.CMEK.AWS_GLUE_DATACATALOGENCRYPTIONSETTINGS.001lowcfn:AWS::Glue::DataCatalogEncryptionSettings: a customer-managed key
POLICY.CFN.CMEK.AWS_GLUE_INTEGRATION.001lowcfn:AWS::Glue::Integration: a customer-managed key
POLICY.CFN.CMEK.AWS_GLUE_MLTRANSFORM.001lowcfn:AWS::Glue::MLTransform: a customer-managed key
POLICY.CFN.CMEK.AWS_GLUE_SECURITYCONFIGURATION.001lowcfn:AWS::Glue::SecurityConfiguration: a customer-managed key
POLICY.CFN.CMEK.AWS_GROUNDSTATION_MISSIONPROFILE.001lowcfn:AWS::GroundStation::MissionProfile: a customer-managed key
POLICY.CFN.CMEK.AWS_GUARDDUTY_PUBLISHINGDESTINATION.001lowcfn:AWS::GuardDuty::PublishingDestination: a customer-managed key
POLICY.CFN.CMEK.AWS_HEALTHIMAGING_DATASTORE.001lowcfn:AWS::HealthImaging::Datastore: a customer-managed key
POLICY.CFN.CMEK.AWS_HEALTHLAKE_DATATRANSFORMATIONPROFILE.001lowcfn:AWS::HealthLake::DataTransformationProfile: a customer-managed key
POLICY.CFN.CMEK.AWS_HEALTHLAKE_FHIRDATASTORE.001lowcfn:AWS::HealthLake::FHIRDatastore: a customer-managed key
POLICY.CFN.CMEK.AWS_IMAGEBUILDER_COMPONENT.001lowcfn:AWS::ImageBuilder::Component: a customer-managed key
POLICY.CFN.CMEK.AWS_IMAGEBUILDER_CONTAINERRECIPE.001lowcfn:AWS::ImageBuilder::ContainerRecipe: a customer-managed key
POLICY.CFN.CMEK.AWS_IMAGEBUILDER_WORKFLOW.001lowcfn:AWS::ImageBuilder::Workflow: a customer-managed key
POLICY.CFN.CMEK.AWS_IOTSITEWISE_WORKSPACE.001lowcfn:AWS::IoTSiteWise::Workspace: a customer-managed key
POLICY.CFN.CMEK.AWS_IOT_ENCRYPTIONCONFIGURATION.001lowcfn:AWS::IoT::EncryptionConfiguration: a customer-managed key
POLICY.CFN.CMEK.AWS_KENDRA_INDEX.001lowcfn:AWS::Kendra::Index: a customer-managed key
POLICY.CFN.CMEK.AWS_KINESISVIDEO_STREAM.001lowcfn:AWS::KinesisVideo::Stream: a customer-managed key
POLICY.CFN.CMEK.AWS_LAMBDA_CAPACITYPROVIDER.001lowcfn:AWS::Lambda::CapacityProvider: a customer-managed key
POLICY.CFN.CMEK.AWS_LAMBDA_EVENTSOURCEMAPPING.001lowcfn:AWS::Lambda::EventSourceMapping: a customer-managed key
POLICY.CFN.CMEK.AWS_LAMBDA_FUNCTION.001lowcfn:AWS::Lambda::Function: a customer-managed key
POLICY.CFN.CMEK.AWS_LOCATION_GEOFENCECOLLECTION.001lowcfn:AWS::Location::GeofenceCollection: a customer-managed key
POLICY.CFN.CMEK.AWS_LOCATION_TRACKER.001lowcfn:AWS::Location::Tracker: a customer-managed key
POLICY.CFN.CMEK.AWS_LOGS_INTEGRATION.001lowcfn:AWS::Logs::Integration: a customer-managed key
POLICY.CFN.CMEK.AWS_LOGS_LOGANOMALYDETECTOR.001lowcfn:AWS::Logs::LogAnomalyDetector: a customer-managed key
POLICY.CFN.CMEK.AWS_LOGS_LOGGROUP.001lowcfn:AWS::Logs::LogGroup: a customer-managed key
POLICY.CFN.CMEK.AWS_LOOKOUTEQUIPMENT_INFERENCESCHEDULER.001lowcfn:AWS::LookoutEquipment::InferenceScheduler: a customer-managed key
POLICY.CFN.CMEK.AWS_M2_APPLICATION.001lowcfn:AWS::M2::Application: a customer-managed key
POLICY.CFN.CMEK.AWS_M2_ENVIRONMENT.001lowcfn:AWS::M2::Environment: a customer-managed key
POLICY.CFN.CMEK.AWS_MEMORYDB_CLUSTER.001lowcfn:AWS::MemoryDB::Cluster: a customer-managed key
POLICY.CFN.CMEK.AWS_MEMORYDB_SNAPSHOT.001lowcfn:AWS::MemoryDB::Snapshot: a customer-managed key
POLICY.CFN.CMEK.AWS_MSK_CHANNEL.001lowcfn:AWS::MSK::Channel: a customer-managed key
POLICY.CFN.CMEK.AWS_MWAASERVERLESS_WORKFLOW.001lowcfn:AWS::MWAAServerless::Workflow: a customer-managed key
POLICY.CFN.CMEK.AWS_NEPTUNE_DBCLUSTER.001lowcfn:AWS::Neptune::DBCluster: a customer-managed key
POLICY.CFN.CMEK.AWS_OBSERVABILITYADMIN_ORGANIZATIONTELEMETRYRULE.001lowcfn:AWS::ObservabilityAdmin::OrganizationTelemetryRule: a customer-managed key
POLICY.CFN.CMEK.AWS_OBSERVABILITYADMIN_S3TABLEINTEGRATION.001lowcfn:AWS::ObservabilityAdmin::S3TableIntegration: a customer-managed key
POLICY.CFN.CMEK.AWS_OBSERVABILITYADMIN_TELEMETRYRULE.001lowcfn:AWS::ObservabilityAdmin::TelemetryRule: a customer-managed key
POLICY.CFN.CMEK.AWS_OPENSEARCHSERVERLESS_COLLECTION.001lowcfn:AWS::OpenSearchServerless::Collection: a customer-managed key
POLICY.CFN.CMEK.AWS_OPENSEARCHSERVICE_APPLICATION.001lowcfn:AWS::OpenSearchService::Application: a customer-managed key
POLICY.CFN.CMEK.AWS_OPENSEARCHSERVICE_DOMAIN.001lowcfn:AWS::OpenSearchService::Domain: a customer-managed key
POLICY.CFN.CMEK.AWS_OSIS_PIPELINE.001lowcfn:AWS::OSIS::Pipeline: a customer-managed key
POLICY.CFN.CMEK.AWS_PERSONALIZE_DATASETEXPORTJOB.001lowcfn:AWS::Personalize::DatasetExportJob: a customer-managed key
POLICY.CFN.CMEK.AWS_PERSONALIZE_DATASETGROUP.001lowcfn:AWS::Personalize::DatasetGroup: a customer-managed key
POLICY.CFN.CMEK.AWS_PERSONALIZE_METRICATTRIBUTION.001lowcfn:AWS::Personalize::MetricAttribution: a customer-managed key
POLICY.CFN.CMEK.AWS_QBUSINESS_APPLICATION.001lowcfn:AWS::QBusiness::Application: a customer-managed key
POLICY.CFN.CMEK.AWS_RDS_DBCLUSTER.001lowcfn:AWS::RDS::DBCluster: a customer-managed key
POLICY.CFN.CMEK.AWS_RDS_DBINSTANCE.001lowcfn:AWS::RDS::DBInstance: a customer-managed key
POLICY.CFN.CMEK.AWS_REDSHIFTSERVERLESS_NAMESPACE.001lowcfn:AWS::RedshiftServerless::Namespace: a customer-managed key
POLICY.CFN.CMEK.AWS_REDSHIFT_CLUSTER.001lowcfn:AWS::Redshift::Cluster: a customer-managed key
POLICY.CFN.CMEK.AWS_REDSHIFT_SNAPSHOTCOPYGRANT.001lowcfn:AWS::Redshift::SnapshotCopyGrant: a customer-managed key
POLICY.CFN.CMEK.AWS_REKOGNITION_STREAMPROCESSOR.001lowcfn:AWS::Rekognition::StreamProcessor: a customer-managed key
POLICY.CFN.CMEK.AWS_RESILIENCEHUBV2_POLICY.001lowcfn:AWS::ResilienceHubV2::Policy: a customer-managed key
POLICY.CFN.CMEK.AWS_RESILIENCEHUBV2_SERVICE.001lowcfn:AWS::ResilienceHubV2::Service: a customer-managed key
POLICY.CFN.CMEK.AWS_RESILIENCEHUBV2_SYSTEM.001lowcfn:AWS::ResilienceHubV2::System: a customer-managed key
POLICY.CFN.CMEK.AWS_S3FILES_FILESYSTEM.001lowcfn:AWS::S3Files::FileSystem: a customer-managed key
POLICY.CFN.CMEK.AWS_S3VECTORS_INDEX.001lowcfn:AWS::S3Vectors::Index: a customer-managed key
POLICY.CFN.CMEK.AWS_S3VECTORS_VECTORBUCKET.001lowcfn:AWS::S3Vectors::VectorBucket: a customer-managed key
POLICY.CFN.CMEK.AWS_S3_BUCKET.001lowcfn:AWS::S3::Bucket: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_AUTOMLJOB.001lowcfn:AWS::SageMaker::AutoMLJob: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_DATAQUALITYJOBDEFINITION.001lowcfn:AWS::SageMaker::DataQualityJobDefinition: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_DEVICEFLEET.001lowcfn:AWS::SageMaker::DeviceFleet: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_DOMAIN.001lowcfn:AWS::SageMaker::Domain: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_ENDPOINTCONFIG.001lowcfn:AWS::SageMaker::EndpointConfig: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_FEATUREGROUP.001lowcfn:AWS::SageMaker::FeatureGroup: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_HYPERPARAMETERTUNINGJOB.001lowcfn:AWS::SageMaker::HyperParameterTuningJob: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_MODELBIASJOBDEFINITION.001lowcfn:AWS::SageMaker::ModelBiasJobDefinition: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_MODELCARD.001lowcfn:AWS::SageMaker::ModelCard: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_MODELEXPLAINABILITYJOBDEFINITION.001lowcfn:AWS::SageMaker::ModelExplainabilityJobDefinition: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_MODELPACKAGE.001lowcfn:AWS::SageMaker::ModelPackage: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_MODELQUALITYJOBDEFINITION.001lowcfn:AWS::SageMaker::ModelQualityJobDefinition: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_MONITORINGSCHEDULE.001lowcfn:AWS::SageMaker::MonitoringSchedule: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_NOTEBOOKINSTANCE.001lowcfn:AWS::SageMaker::NotebookInstance: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_OPTIMIZATIONJOB.001lowcfn:AWS::SageMaker::OptimizationJob: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_PARTNERAPP.001lowcfn:AWS::SageMaker::PartnerApp: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_PROCESSINGJOB.001lowcfn:AWS::SageMaker::ProcessingJob: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_TRAININGJOB.001lowcfn:AWS::SageMaker::TrainingJob: a customer-managed key
POLICY.CFN.CMEK.AWS_SAGEMAKER_TRANSFORMJOB.001lowcfn:AWS::SageMaker::TransformJob: a customer-managed key
POLICY.CFN.CMEK.AWS_SCHEDULER_SCHEDULE.001lowcfn:AWS::Scheduler::Schedule: a customer-managed key
POLICY.CFN.CMEK.AWS_SECRETSMANAGER_ROTATIONSCHEDULE.001lowcfn:AWS::SecretsManager::RotationSchedule: a customer-managed key
POLICY.CFN.CMEK.AWS_SECRETSMANAGER_SECRET.001lowcfn:AWS::SecretsManager::Secret: a customer-managed key
POLICY.CFN.CMEK.AWS_SECURITYAGENT_AGENTSPACE.001lowcfn:AWS::SecurityAgent::AgentSpace: a customer-managed key
POLICY.CFN.CMEK.AWS_SECURITYAGENT_SECURITYREQUIREMENTPACK.001lowcfn:AWS::SecurityAgent::SecurityRequirementPack: a customer-managed key
POLICY.CFN.CMEK.AWS_SECURITYHUB_CONNECTORV2.001lowcfn:AWS::SecurityHub::ConnectorV2: a customer-managed key
POLICY.CFN.CMEK.AWS_SECURITYLAKE_DATALAKE.001lowcfn:AWS::SecurityLake::DataLake: a customer-managed key
POLICY.CFN.CMEK.AWS_SES_MAILMANAGERARCHIVE.001lowcfn:AWS::SES::MailManagerArchive: a customer-managed key
POLICY.CFN.CMEK.AWS_SES_MAILMANAGERINGRESSPOINT.001lowcfn:AWS::SES::MailManagerIngressPoint: a customer-managed key
POLICY.CFN.CMEK.AWS_SNS_TOPIC.001lowcfn:AWS::SNS::Topic: a customer-managed key
POLICY.CFN.CMEK.AWS_SQS_QUEUE.001lowcfn:AWS::SQS::Queue: a customer-managed key
POLICY.CFN.CMEK.AWS_STEPFUNCTIONS_ACTIVITY.001lowcfn:AWS::StepFunctions::Activity: a customer-managed key
POLICY.CFN.CMEK.AWS_STEPFUNCTIONS_STATEMACHINE.001lowcfn:AWS::StepFunctions::StateMachine: a customer-managed key
POLICY.CFN.CMEK.AWS_SYNTHETICS_CANARY.001lowcfn:AWS::Synthetics::Canary: a customer-managed key
POLICY.CFN.CMEK.AWS_TIMESTREAM_DATABASE.001lowcfn:AWS::Timestream::Database: a customer-managed key
POLICY.CFN.CMEK.AWS_TIMESTREAM_SCHEDULEDQUERY.001lowcfn:AWS::Timestream::ScheduledQuery: a customer-managed key
POLICY.CFN.CMEK.AWS_TIMESTREAM_TABLE.001lowcfn:AWS::Timestream::Table: a customer-managed key
POLICY.CFN.CMEK.AWS_VOICEID_DOMAIN.001lowcfn:AWS::VoiceID::Domain: a customer-managed key
POLICY.CFN.CMEK.AWS_WISDOM_ASSISTANT.001lowcfn:AWS::Wisdom::Assistant: a customer-managed key
POLICY.CFN.CMEK.AWS_WISDOM_KNOWLEDGEBASE.001lowcfn:AWS::Wisdom::KnowledgeBase: a customer-managed key
POLICY.CFN.CMEK.AWS_WORKSPACESINSTANCES_VOLUME.001lowcfn:AWS::WorkspacesInstances::Volume: a customer-managed key
POLICY.CFN.CMEK.AWS_WORKSPACESTHINCLIENT_ENVIRONMENT.001lowcfn:AWS::WorkSpacesThinClient::Environment: a customer-managed key
POLICY.CFN.DELETION_PROTECTION.AWS_DOCDB_DBCLUSTER.001lowcfn:AWS::DocDB::DBCluster: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_DOCDB_GLOBALCLUSTER.001lowcfn:AWS::DocDB::GlobalCluster: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_DSQL_CLUSTER.001lowcfn:AWS::DSQL::Cluster: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_DYNAMODB_TABLE.001lowcfn:AWS::DynamoDB::Table: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_EKS_CLUSTER.001lowcfn:AWS::EKS::Cluster: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_LOGS_LOGGROUP.001lowcfn:AWS::Logs::LogGroup: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_NEPTUNEGRAPH_GRAPH.001lowcfn:AWS::NeptuneGraph::Graph: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_NEPTUNE_DBCLUSTER.001lowcfn:AWS::Neptune::DBCluster: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_NEPTUNE_GLOBALCLUSTER.001lowcfn:AWS::Neptune::GlobalCluster: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_QLDB_LEDGER.001lowcfn:AWS::QLDB::Ledger: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_RDS_DBCLUSTER.001lowcfn:AWS::RDS::DBCluster: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_RDS_DBINSTANCE.001lowcfn:AWS::RDS::DBInstance: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_RDS_GLOBALCLUSTER.001lowcfn:AWS::RDS::GlobalCluster: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_SMSVOICE_PHONENUMBER.001lowcfn:AWS::SMSVOICE::PhoneNumber: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_SMSVOICE_POOL.001lowcfn:AWS::SMSVOICE::Pool: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_SMSVOICE_PROTECTCONFIGURATION.001lowcfn:AWS::SMSVOICE::ProtectConfiguration: deletion protection
POLICY.CFN.DELETION_PROTECTION.AWS_SMSVOICE_SENDERID.001lowcfn:AWS::SMSVOICE::SenderId: deletion protection
POLICY.CFN.ENCRYPT_AT_REST.AWS_BEDROCKAGENTCORE_CAPACITYPROVIDER.001highcfn:AWS::BedrockAgentCore::CapacityProvider: encryption at rest
POLICY.CFN.ENCRYPT_AT_REST.AWS_DOCDB_DBCLUSTER.001highcfn:AWS::DocDB::DBCluster: storage encryption
POLICY.CFN.ENCRYPT_AT_REST.AWS_DOCDB_GLOBALCLUSTER.001highcfn:AWS::DocDB::GlobalCluster: storage encryption
POLICY.CFN.ENCRYPT_AT_REST.AWS_EC2_VOLUME.001highcfn:AWS::EC2::Volume: encryption at rest
POLICY.CFN.ENCRYPT_AT_REST.AWS_NEPTUNE_DBCLUSTER.001highcfn:AWS::Neptune::DBCluster: storage encryption
POLICY.CFN.ENCRYPT_AT_REST.AWS_NEPTUNE_GLOBALCLUSTER.001highcfn:AWS::Neptune::GlobalCluster: storage encryption
POLICY.CFN.ENCRYPT_AT_REST.AWS_RDS_DBCLUSTER.001highcfn:AWS::RDS::DBCluster: storage encryption
POLICY.CFN.ENCRYPT_AT_REST.AWS_RDS_DBCLUSTERAUTOMATEDBACKUP.001highcfn:AWS::RDS::DBClusterAutomatedBackup: storage encryption
POLICY.CFN.ENCRYPT_AT_REST.AWS_RDS_DBINSTANCEAUTOMATEDBACKUP.001highcfn:AWS::RDS::DBInstanceAutomatedBackup: encryption at rest
POLICY.CFN.ENCRYPT_AT_REST.AWS_RDS_GLOBALCLUSTER.001highcfn:AWS::RDS::GlobalCluster: storage encryption
POLICY.CFN.ENCRYPT_AT_REST.AWS_REDSHIFT_CLUSTER.001highcfn:AWS::Redshift::Cluster: encryption at rest
POLICY.CFN.ENCRYPT_AT_REST.AWS_WORKSPACESINSTANCES_VOLUME.001highcfn:AWS::WorkspacesInstances::Volume: encryption at rest
POLICY.CFN.ENCRYPT_AT_REST.DBINSTANCE.001highAWS::RDS::DBInstance: storage encryption is switched off
POLICY.CFN.ENCRYPT_AT_REST.FILESYSTEM.001mediumAWS::EFS::FileSystem: the file system is not encrypted
POLICY.CFN.GOVERNANCE.AWS_DOCDB_DBCLUSTER.001lowcfn:AWS::DocDB::DBCluster: tags on snapshots
POLICY.CFN.GOVERNANCE.AWS_NEPTUNE_DBCLUSTER.001lowcfn:AWS::Neptune::DBCluster: tags on snapshots
POLICY.CFN.GOVERNANCE.AWS_RDS_DBCLUSTER.001lowcfn:AWS::RDS::DBCluster: tags on snapshots
POLICY.CFN.GOVERNANCE.AWS_RDS_DBINSTANCE.001lowcfn:AWS::RDS::DBInstance: tags on snapshots
POLICY.CFN.KEY_ROTATION.AWS_KMS_KEY.001mediumcfn:AWS::KMS::Key: automatic key rotation
POLICY.CFN.LOGGING.AWS_DOCDB_DBINSTANCE.001lowcfn:AWS::DocDB::DBInstance: performance insights
POLICY.CFN.LOGGING.AWS_RDS_DBINSTANCE.001lowcfn:AWS::RDS::DBInstance: performance insights
POLICY.CFN.PATCHING.AWS_AMAZONMQ_BROKER.001mediumcfn:AWS::AmazonMQ::Broker: automatic minor version upgrades
POLICY.CFN.PATCHING.AWS_DMS_REPLICATIONINSTANCE.001mediumcfn:AWS::DMS::ReplicationInstance: automatic minor version upgrades
POLICY.CFN.PATCHING.AWS_DOCDB_DBINSTANCE.001mediumcfn:AWS::DocDB::DBInstance: automatic minor version upgrades
POLICY.CFN.PATCHING.AWS_ELASTICACHE_CACHECLUSTER.001mediumcfn:AWS::ElastiCache::CacheCluster: automatic minor version upgrades
POLICY.CFN.PATCHING.AWS_ELASTICACHE_REPLICATIONGROUP.001mediumcfn:AWS::ElastiCache::ReplicationGroup: automatic minor version upgrades
POLICY.CFN.PATCHING.AWS_MEMORYDB_CLUSTER.001mediumcfn:AWS::MemoryDB::Cluster: automatic minor version upgrades
POLICY.CFN.PATCHING.AWS_NEPTUNE_DBINSTANCE.001mediumcfn:AWS::Neptune::DBInstance: automatic minor version upgrades
POLICY.CFN.PATCHING.AWS_RDS_DBCLUSTER.001mediumcfn:AWS::RDS::DBCluster: automatic minor version upgrades
POLICY.CFN.PATCHING.AWS_RDS_DBINSTANCE.001mediumcfn:AWS::RDS::DBInstance: automatic minor version upgrades
POLICY.CFN.PUBLIC_IP.AWS_AUTOSCALING_LAUNCHCONFIGURATION.001lowcfn:AWS::AutoScaling::LaunchConfiguration: a public ip address
POLICY.CFN.PUBLIC_IP.AWS_EC2_SUBNET.001lowcfn:AWS::EC2::Subnet: every instance in the subnet gets a public address
POLICY.CFN.RESILIENCE.AWS_DMS_REPLICATIONCONFIG.001lowcfn:AWS::DMS::ReplicationConfig: a standby in another availability zone
POLICY.CFN.RESILIENCE.AWS_DMS_REPLICATIONINSTANCE.001lowcfn:AWS::DMS::ReplicationInstance: a standby in another availability zone
POLICY.CFN.RESILIENCE.AWS_RDS_DBINSTANCE.001lowcfn:AWS::RDS::DBInstance: a standby in another availability zone
POLICY.CFN.RESILIENCE.AWS_REDSHIFT_CLUSTER.001lowcfn:AWS::Redshift::Cluster: a standby in another availability zone
POLICY.CFN.SHARED_KEY_AUTH.AWS_RDS_DBCLUSTER.001lowcfn:AWS::RDS::DBCluster: iam database authentication
POLICY.CFN.SHARED_KEY_AUTH.AWS_RDS_DBINSTANCE.001lowcfn:AWS::RDS::DBInstance: iam database authentication
POLICY.CFN.WEAK_TLS.AWS_CLOUDFRONT_DISTRIBUTION.001mediumcfn:AWS::CloudFront::Distribution: an obsolete tls version is accepted
POLICY.CFN.WRITABLE_ROOT.AWS_BATCH_JOBDEFINITION.001lowcfn:AWS::Batch::JobDefinition: a read-only root filesystem
SUSPECT.CFN.IAM_WILDCARD.POLICY.001highAWS::IAM::Policy: the policy grants every action
SUSPECT.CFN.IMDSV1.AWS_AUTOSCALING_LAUNCHCONFIGURATION.001mediumcfn:AWS::AutoScaling::LaunchConfiguration: instance metadata is reachable without a token
SUSPECT.CFN.IMDSV1.AWS_EC2_INSTANCE.001mediumcfn:AWS::EC2::Instance: instance metadata is reachable without a token
SUSPECT.CFN.IMDSV1.AWS_EC2_LAUNCHTEMPLATE.001mediumcfn:AWS::EC2::LaunchTemplate: instance metadata is reachable without a token
SUSPECT.CFN.IMDSV1.AWS_IMAGEBUILDER_INFRASTRUCTURECONFIGURATION.001mediumcfn:AWS::ImageBuilder::InfrastructureConfiguration: instance metadata is reachable without a token
SUSPECT.CFN.IMDSV1.AWS_WORKSPACESINSTANCES_WORKSPACEINSTANCE.001mediumcfn:AWS::WorkspacesInstances::WorkspaceInstance: instance metadata is reachable without a token
SUSPECT.CFN.OPEN_INGRESS.SECURITYGROUP.001highAWS::EC2::SecurityGroup: a security group admits the whole internet
SUSPECT.CFN.PLAINTEXT.LISTENER.001mediumAWS::ElasticLoadBalancingV2::Listener: the listener serves plain HTTP
SUSPECT.CFN.PRIVILEGED.AWS_BATCH_JOBDEFINITION.001highcfn:AWS::Batch::JobDefinition: the container runs privileged
SUSPECT.CFN.PUBLIC_ACCESS.AWS_AMAZONMQ_BROKER.001highcfn:AWS::AmazonMQ::Broker: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_DMS_INSTANCEPROFILE.001highcfn:AWS::DMS::InstanceProfile: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_DMS_REPLICATIONINSTANCE.001highcfn:AWS::DMS::ReplicationInstance: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_LIGHTSAIL_DATABASE.001highcfn:AWS::Lightsail::Database: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_M2_ENVIRONMENT.001highcfn:AWS::M2::Environment: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_NEPTUNE_DBINSTANCE.001highcfn:AWS::Neptune::DBInstance: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_RDS_DBCLUSTER.001highcfn:AWS::RDS::DBCluster: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_RDS_DBSHARDGROUP.001highcfn:AWS::RDS::DBShardGroup: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_REDSHIFTSERVERLESS_WORKGROUP.001highcfn:AWS::RedshiftServerless::Workgroup: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_REDSHIFT_CLUSTER.001highcfn:AWS::Redshift::Cluster: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_TIMESTREAM_INFLUXDBCLUSTER.001highcfn:AWS::Timestream::InfluxDBCluster: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.AWS_TIMESTREAM_INFLUXDBINSTANCE.001highcfn:AWS::Timestream::InfluxDBInstance: reachable from the public internet
SUSPECT.CFN.PUBLIC_ACCESS.DBINSTANCE.001highAWS::RDS::DBInstance: the database is reachable from the public internet
SUSPECT.CFN.PUBLIC_STORAGE.BUCKET.001highAWS::S3::Bucket: the bucket is readable by anyone

2 rules.

RuleSeverityWhat it catches
SUSPECT.COMPOSE.DANGEROUS_CAPABILITY.001highCompose service: the service is granted a capability that defeats isolation
SUSPECT.COMPOSE.HOST_NETWORK.001mediumCompose service: the service shares the host network namespace

5 rules.

RuleSeverityWhat it catches
POLICY.CONTAINER.UNPINNED_BASE.001lowBase image referenced by tag rather than digest
POLICY.CONTAINER.UNPINNED_WORKLOAD_IMAGE.001lowKubernetes workload runs an image by tag rather than digest
POLICY.CONTAINER.UNSIGNED_IMAGE.001lowAn image this project runs carries no signature or build attestation
SUSPECT.CONTAINER.BUILD_SECRET.001highSecret passed as a build argument
SUSPECT.CONTAINER.FETCH_EXEC.001highImage build fetches and executes remote content

2 rules.

RuleSeverityWhat it catches
MALWARE.CRYPTOMINER.001criticalInstall-time cryptocurrency mining
SUSPECT.CRYPTOMINER.001highCryptocurrency mining

1 rules.

RuleSeverityWhat it catches
SUSPECT.DECODE_CHAIN.001criticalA payload decoded in several stages, then executed

1 rules.

RuleSeverityWhat it catches
SUSPECT.DECODE_EXEC.001highEncoded data decoded and executed in the same file

21 rules.

RuleSeverityWhat it catches
MALWARE.DEPENDENCY.KNOWN.001criticalDependency is a known-malicious release
POLICY.DEPENDENCY.ABANDONED.001mediumDependency is abandoned by its maintainer
POLICY.DEPENDENCY.CLEARTEXT_SOURCE.001mediumPackage source over plain HTTP
POLICY.DEPENDENCY.DEPRECATED.001mediumDependency pins a version its publisher deprecated
POLICY.DEPENDENCY.DOWNGRADE.001lowDependency pins a version far behind the current release
POLICY.DEPENDENCY.INTEGRITY.001mediumDependency has no integrity hash
POLICY.DEPENDENCY.MUTABLE_REF.001mediumGit dependency on a reference that can move
POLICY.DEPENDENCY.SECURITY_PLACEHOLDER.001mediumDependency pins npm's security placeholder
POLICY.DEPENDENCY.SOURCE.001lowDependency declared from a non-registry source
POLICY.DEPENDENCY.UNMAINTAINED.001lowDependency has had no release in five years
SUSPECT.DEPENDENCY.CONFUSION.001highInternal package name resolved from a public registry
SUSPECT.DEPENDENCY.DEPRECATED_SECURITY.001highDependency pins a version its publisher deprecated for a security reason
SUSPECT.DEPENDENCY.HALLUCINATED.001highA dependency's name is a documented AI hallucination
SUSPECT.DEPENDENCY.SOURCE.001mediumDependency resolved from outside the registry
SUSPECT.DEPENDENCY.SOURCE_PRIORITY.001mediumA private package index merged with a public one
SUSPECT.DEPENDENCY.TYPOSQUAT.001highDependency name is one edit from a popular package
SUSPECT.DEPENDENCY.UNREGISTERED.001highA dependency does not exist on its public registry
SUSPECT.DEPENDENCY.UNVETTED.001mediumA dependency is new, sourceless and unknown: the shape of a slopsquatted package
SUSPECT.DEPENDENCY.YANKED.001highDependency pins a version its publisher withdrew
VULNERABLE.DEPENDENCY.EXPLOITED.001criticalDependency has a vulnerability that is exploited in the wild
VULNERABLE.DEPENDENCY.KNOWN.001highDependency has a known vulnerability

1 rules.

RuleSeverityWhat it catches
SUSPECT.DESTROY.HOME_OR_ROOT.001highDeletes the home directory or the filesystem root

6 rules.

RuleSeverityWhat it catches
POLICY.DOCKERFILE.NO_HEALTHCHECK.001lowDockerfile: the image serves a port and declares no health check
POLICY.DOCKERFILE.ROOT_USER.001mediumDockerfile: the image runs as root
POLICY.DOCKERFILE.SECRET_ARG_DECLARED.001mediumDockerfile: a credential is passed as a build argument
POLICY.DOCKERFILE.SUDO.001lowDockerfile: the build uses sudo
SUSPECT.DOCKERFILE.ADD_REMOTE.001mediumDockerfile: the build downloads a URL with ADD
SUSPECT.DOCKERFILE.SECRET_ARG.001highDockerfile: a credential is baked into the image

10 rules.

RuleSeverityWhat it catches
SUSPECT.DOCUMENT.AUTO_EXEC.001highA macro runs by itself on open and starts a program or fetches from the network
SUSPECT.DOCUMENT.DDE.001highA document contains a DDE field
SUSPECT.DOCUMENT.MACRO.001mediumAn office document carries macros
SUSPECT.DOCUMENT.PDF_AUTO_ACTION.001highA PDF runs JavaScript when it is opened
SUSPECT.DOCUMENT.PDF_EMBEDDED_EXECUTABLE.001highA PDF embeds a file with an executable name
SUSPECT.DOCUMENT.PDF_JAVASCRIPT.001mediumA PDF carries JavaScript
SUSPECT.DOCUMENT.PDF_LAUNCH.001highA PDF asks the viewer to launch a program
SUSPECT.DOCUMENT.PDF_RISKY_URI.001mediumA PDF link opens a script, a local file or a download that runs
SUSPECT.DOCUMENT.REMOTE_OBJECT.001highA document loads a template or object from elsewhere when opened
SUSPECT.DOCUMENT.RTF_OBJECT.001highAn RTF document embeds an object that loads itself

2 rules.

RuleSeverityWhat it catches
MALWARE.DROPPER.001criticalInstall script fetches and executes remote content
SUSPECT.DROPPER.001highContent fetched from the network and executed

2 rules.

RuleSeverityWhat it catches
MALWARE.DYNAMIC_DISPATCH.001criticalInstall-time code reaches a function by a computed name
SUSPECT.DYNAMIC_DISPATCH.001highA function is reached by a name computed at runtime

13 rules.

RuleSeverityWhat it catches
MALWARE.EXFIL.001criticalInstall script reads credentials and transmits them
MALWARE.EXFIL.BEACON.001criticalInstall script reports the machine it is installing on
MALWARE.EXFIL.CREDENTIAL_STORE.001criticalInstall-time code reads a credential store and reaches the network
MALWARE.EXFIL.DROP_POINT.001criticalInstall-time code sends data to a drop point
MALWARE.EXFIL.INSTALL_CALLBACK.001criticalInstall script calls back to a drop point
SUSPECT.EXFIL.001mediumCredential access combined with network egress and execution
SUSPECT.EXFIL.BEACON.001highCode reports the machine it runs on
SUSPECT.EXFIL.CALLBACK.001highCode calls an out-of-band interaction service
SUSPECT.EXFIL.CREDENTIAL_STORE.001highA credential store is read and the file reaches the network
SUSPECT.EXFIL.DNS.001highCredential access and a hostname assembled for resolution
SUSPECT.EXFIL.DROP_POINT.001highCredential or machine identity, and a request to a drop point
SUSPECT.EXFIL.ENVIRONMENT.001highCode sends the whole environment over the network
SUSPECT.EXFIL.NAMED_SECRET.001highCode sends a named credential to a host outside its service

5 rules.

RuleSeverityWhat it catches
MALWARE.EXTENSION.KNOWN.001criticalAn editor extension is a recorded malicious release
MALWARE.EXTENSION.REMOVED.001criticalA recommended or vendored editor extension was removed from the Marketplace as malware
SUSPECT.EXTENSION.LOOKALIKE.001mediumA recommended editor extension imitates a popular one
SUSPECT.EXTENSION.MALICIOUS_VERSIONS.001lowA named editor extension has had malicious releases
SUSPECT.EXTENSION.REMOVED.001highA recommended or vendored editor extension was removed from the Marketplace

1 rules.

RuleSeverityWhat it catches
OPERATIONAL.FORMAT.UNREADABLEinfoA model, document or image could not be read

1 rules.

RuleSeverityWhat it catches
SUSPECT.HELM.UNTRUSTED_REPOSITORY.001mediumChart depends on a chart from an unpinned or plain-HTTP repository

3 rules.

RuleSeverityWhat it catches
OPERATIONAL.IMAGE.UNMATCHEDinfoAn image's packages were not all matched against advisories
VULNERABLE.IMAGE.EXPLOITED.001criticalAn image's operating-system package has a vulnerability exploited in the wild
VULNERABLE.IMAGE.PACKAGE.001highAn image's operating-system package has a known vulnerability

818 rules.

RuleSeverityWhat it catches
POLICY.IAC.ANSIBLE_TLS_UNVERIFIED.001mediumTask turns off TLS certificate verification
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_CRON_JOB.001lowkubernetes_cron_job: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_CRON_JOB_V1.001lowkubernetes_cron_job_v1: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_DAEMONSET.001lowkubernetes_daemonset: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_DAEMON_SET_V1.001lowkubernetes_daemon_set_v1: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_DEFAULT_SERVICE_ACCOUNT.001lowkubernetes_default_service_account: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_DEFAULT_SERVICE_ACCOUNT_V1.001lowkubernetes_default_service_account_v1: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_DEPLOYMENT.001lowkubernetes_deployment: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_DEPLOYMENT_V1.001lowkubernetes_deployment_v1: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_JOB.001lowkubernetes_job: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_JOB_V1.001lowkubernetes_job_v1: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_POD.001lowkubernetes_pod: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_POD_V1.001lowkubernetes_pod_v1: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_REPLICATION_CONTROLLER.001lowkubernetes_replication_controller: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_REPLICATION_CONTROLLER_V1.001lowkubernetes_replication_controller_v1: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_SERVICE_ACCOUNT.001lowkubernetes_service_account: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_SERVICE_ACCOUNT_V1.001lowkubernetes_service_account_v1: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_STATEFUL_SET.001lowkubernetes_stateful_set: the service account token is mounted into the pod
POLICY.IAC.AUTOMOUNT_TOKEN.KUBERNETES_STATEFUL_SET_V1.001lowkubernetes_stateful_set_v1: the service account token is mounted into the pod
POLICY.IAC.BACKUP.AWS_DB_INSTANCE_BACKUP_RETENTION_PERIOD.001mediumaws_db_instance: a backup retention period is not configured
POLICY.IAC.BACKUP.AWS_DOCDB_CLUSTER_BACKUP_RETENTION_PERIOD.001lowaws_docdb_cluster: a backup retention period is not configured
POLICY.IAC.BACKUP.AWS_LIGHTSAIL_DATABASE.001mediumaws_lightsail_database: no snapshot is taken when the database is destroyed
POLICY.IAC.BACKUP.AWS_NEPTUNE_CLUSTER_BACKUP_RETENTION_PERIOD.001lowaws_neptune_cluster: a backup retention period is not configured
POLICY.IAC.BACKUP.AWS_NEPTUNE_CLUSTER_INSTANCE.001mediumaws_neptune_cluster_instance: no snapshot is taken when the database is destroyed
POLICY.IAC.BACKUP.AWS_RDS_CLUSTER_BACKUP_RETENTION_PERIOD.001mediumaws_rds_cluster: a backup retention period is not configured
POLICY.IAC.BACKUP.AWS_REDSHIFT_CLUSTER_AUTOMATED_SNAPSHOT_RETENTION_PERIOD.001lowaws_redshift_cluster: a backup retention period is not configured
POLICY.IAC.BACKUP.AZURERM_APP_SERVICE.001lowazurerm_app_service: keeping a backup
POLICY.IAC.BACKUP.AZURERM_LINUX_FUNCTION_APP.001lowazurerm_linux_function_app: keeping a backup
POLICY.IAC.BACKUP.AZURERM_LINUX_FUNCTION_APP_SLOT.001lowazurerm_linux_function_app_slot: keeping a backup
POLICY.IAC.BACKUP.AZURERM_LINUX_WEB_APP.001lowazurerm_linux_web_app: keeping a backup
POLICY.IAC.BACKUP.AZURERM_LINUX_WEB_APP_SLOT.001lowazurerm_linux_web_app_slot: keeping a backup
POLICY.IAC.BACKUP.AZURERM_MYSQL_SERVER_BACKUP_RETENTION_DAYS.001lowazurerm_mysql_server: a backup retention period is not configured
POLICY.IAC.BACKUP.AZURERM_POSTGRESQL_SERVER_BACKUP_RETENTION_DAYS.001lowazurerm_postgresql_server: a backup retention period is not configured
POLICY.IAC.BACKUP.AZURERM_WINDOWS_FUNCTION_APP.001lowazurerm_windows_function_app: keeping a backup
POLICY.IAC.BACKUP.AZURERM_WINDOWS_FUNCTION_APP_SLOT.001lowazurerm_windows_function_app_slot: keeping a backup
POLICY.IAC.BACKUP.AZURERM_WINDOWS_WEB_APP.001lowazurerm_windows_web_app: keeping a backup
POLICY.IAC.BACKUP.AZURERM_WINDOWS_WEB_APP_SLOT.001lowazurerm_windows_web_app_slot: keeping a backup
POLICY.IAC.BACKUP_DISABLED.AWS_DB_INSTANCE.001mediumaws_db_instance: backups are switched off
POLICY.IAC.BACKUP_DISABLED.AWS_DOCDB_CLUSTER.001lowaws_docdb_cluster: backups are switched off
POLICY.IAC.BACKUP_DISABLED.AWS_NEPTUNE_CLUSTER.001lowaws_neptune_cluster: backups are switched off
POLICY.IAC.BACKUP_DISABLED.AWS_RDS_CLUSTER.001mediumaws_rds_cluster: backups are switched off
POLICY.IAC.BACKUP_DISABLED.AWS_REDSHIFT_CLUSTER.001lowaws_redshift_cluster: backups are switched off
POLICY.IAC.BACKUP_DISABLED.AZURERM_MYSQL_SERVER.001lowazurerm_mysql_server: backups are switched off
POLICY.IAC.BACKUP_DISABLED.AZURERM_POSTGRESQL_SERVER.001lowazurerm_postgresql_server: backups are switched off
POLICY.IAC.BOOT_INTEGRITY.AZURERM_BATCH_POOL.001lowazurerm_batch_pool: secure boot
POLICY.IAC.BOOT_INTEGRITY.AZURERM_LINUX_VIRTUAL_MACHINE.001lowazurerm_linux_virtual_machine: secure boot
POLICY.IAC.BOOT_INTEGRITY.AZURERM_LINUX_VIRTUAL_MACHINE_SCALE_SET.001lowazurerm_linux_virtual_machine_scale_set: secure boot
POLICY.IAC.BOOT_INTEGRITY.AZURERM_WINDOWS_VIRTUAL_MACHINE.001lowazurerm_windows_virtual_machine: secure boot
POLICY.IAC.BOOT_INTEGRITY.AZURERM_WINDOWS_VIRTUAL_MACHINE_SCALE_SET.001lowazurerm_windows_virtual_machine_scale_set: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_COLAB_RUNTIME_TEMPLATE.001lowgoogle_colab_runtime_template: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_COMPUTE_INSTANCE.001lowgoogle_compute_instance: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_COMPUTE_INSTANCE_FROM_TEMPLATE.001lowgoogle_compute_instance_from_template: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_COMPUTE_INSTANCE_TEMPLATE.001lowgoogle_compute_instance_template: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_COMPUTE_REGION_INSTANCE_TEMPLATE.001lowgoogle_compute_region_instance_template: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_CONTAINER_CLUSTER.001lowgoogle_container_cluster: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_CONTAINER_NODE_POOL.001lowgoogle_container_node_pool: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_DATAPROC_CLUSTER.001lowgoogle_dataproc_cluster: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_DATAPROC_WORKFLOW_TEMPLATE.001lowgoogle_dataproc_workflow_template: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_NOTEBOOKS_INSTANCE.001lowgoogle_notebooks_instance: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_NOTEBOOKS_RUNTIME.001lowgoogle_notebooks_runtime: secure boot
POLICY.IAC.BOOT_INTEGRITY.GOOGLE_WORKBENCH_INSTANCE.001lowgoogle_workbench_instance: secure boot
POLICY.IAC.CMEK.AWS_AMI_COPY.001lowaws_ami_copy: a customer-managed key
POLICY.IAC.CMEK.AWS_ATHENA_WORKGROUP.001lowaws_athena_workgroup: a customer-managed key
POLICY.IAC.CMEK.AWS_BACKUP_VAULT.001lowaws_backup_vault: a customer-managed key
POLICY.IAC.CMEK.AWS_BEDROCKAGENT_DATA_SOURCE.001lowaws_bedrockagent_data_source: a customer-managed key
POLICY.IAC.CMEK.AWS_BEDROCK_GUARDRAIL.001lowaws_bedrock_guardrail: a customer-managed key
POLICY.IAC.CMEK.AWS_CHIMESDKVOICE_VOICE_PROFILE_DOMAIN.001lowaws_chimesdkvoice_voice_profile_domain: a customer-managed key
POLICY.IAC.CMEK.AWS_CLOUDTRAIL.001lowaws_cloudtrail: a customer-managed key
POLICY.IAC.CMEK.AWS_CLOUDTRAIL_EVENT_DATA_STORE.001lowaws_cloudtrail_event_data_store: a customer-managed key
POLICY.IAC.CMEK.AWS_CLOUDWATCH_LOG_ANOMALY_DETECTOR.001lowaws_cloudwatch_log_anomaly_detector: a customer-managed key
POLICY.IAC.CMEK.AWS_CODECOMMIT_REPOSITORY.001lowaws_codecommit_repository: a customer-managed key
POLICY.IAC.CMEK.AWS_CODEGURUREVIEWER_REPOSITORY_ASSOCIATION.001lowaws_codegurureviewer_repository_association: a customer-managed key
POLICY.IAC.CMEK.AWS_COGNITO_USER_POOL.001lowaws_cognito_user_pool: a customer-managed key
POLICY.IAC.CMEK.AWS_COMPREHEND_DOCUMENT_CLASSIFIER.001lowaws_comprehend_document_classifier: a customer-managed key
POLICY.IAC.CMEK.AWS_DATAEXCHANGE_EVENT_ACTION.001lowaws_dataexchange_event_action: a customer-managed key
POLICY.IAC.CMEK.AWS_DATAEXCHANGE_REVISION_ASSETS.001lowaws_dataexchange_revision_assets: a customer-managed key
POLICY.IAC.CMEK.AWS_DB_INSTANCE.001lowaws_db_instance: a customer-managed key
POLICY.IAC.CMEK.AWS_DB_INSTANCE_AUTOMATED_BACKUPS_REPLICATION.001lowaws_db_instance_automated_backups_replication: a customer-managed key
POLICY.IAC.CMEK.AWS_DB_SNAPSHOT_COPY.001lowaws_db_snapshot_copy: a customer-managed key
POLICY.IAC.CMEK.AWS_DEVOPSGURU_SERVICE_INTEGRATION.001lowaws_devopsguru_service_integration: a customer-managed key
POLICY.IAC.CMEK.AWS_DMS_ENDPOINT.001lowaws_dms_endpoint: a customer-managed key
POLICY.IAC.CMEK.AWS_DMS_REPLICATION_CONFIG.001lowaws_dms_replication_config: a customer-managed key
POLICY.IAC.CMEK.AWS_DMS_REPLICATION_INSTANCE.001lowaws_dms_replication_instance: a customer-managed key
POLICY.IAC.CMEK.AWS_DMS_S3_ENDPOINT.001lowaws_dms_s3_endpoint: a customer-managed key
POLICY.IAC.CMEK.AWS_DOCDBELASTIC_CLUSTER.001lowaws_docdbelastic_cluster: a customer-managed key
POLICY.IAC.CMEK.AWS_DOCDB_CLUSTER.001lowaws_docdb_cluster: a customer-managed key
POLICY.IAC.CMEK.AWS_DYNAMODB_TABLE.001lowaws_dynamodb_table: a customer-managed key
POLICY.IAC.CMEK.AWS_DYNAMODB_TABLE_REPLICA.001lowaws_dynamodb_table_replica: a customer-managed key
POLICY.IAC.CMEK.AWS_EBS_SNAPSHOT_COPY.001lowaws_ebs_snapshot_copy: a customer-managed key
POLICY.IAC.CMEK.AWS_EBS_SNAPSHOT_IMPORT.001lowaws_ebs_snapshot_import: a customer-managed key
POLICY.IAC.CMEK.AWS_EBS_VOLUME.001lowaws_ebs_volume: a customer-managed key
POLICY.IAC.CMEK.AWS_ECS_CLUSTER.001lowaws_ecs_cluster: a customer-managed key
POLICY.IAC.CMEK.AWS_ECS_SERVICE.001lowaws_ecs_service: a customer-managed key
POLICY.IAC.CMEK.AWS_EFS_FILE_SYSTEM.001lowaws_efs_file_system: a customer-managed key
POLICY.IAC.CMEK.AWS_EFS_REPLICATION_CONFIGURATION.001lowaws_efs_replication_configuration: a customer-managed key
POLICY.IAC.CMEK.AWS_ELASTICACHE_REPLICATION_GROUP.001lowaws_elasticache_replication_group: a customer-managed key
POLICY.IAC.CMEK.AWS_ELASTICACHE_SERVERLESS_CACHE.001lowaws_elasticache_serverless_cache: a customer-managed key
POLICY.IAC.CMEK.AWS_ELASTICSEARCH_DOMAIN.001lowaws_elasticsearch_domain: a customer-managed key
POLICY.IAC.CMEK.AWS_EMRCONTAINERS_JOB_TEMPLATE.001lowaws_emrcontainers_job_template: a customer-managed key
POLICY.IAC.CMEK.AWS_FINSPACE_KX_ENVIRONMENT.001lowaws_finspace_kx_environment: a customer-managed key
POLICY.IAC.CMEK.AWS_FSX_FILE_CACHE.001lowaws_fsx_file_cache: a customer-managed key
POLICY.IAC.CMEK.AWS_FSX_LUSTRE_FILE_SYSTEM.001lowaws_fsx_lustre_file_system: a customer-managed key
POLICY.IAC.CMEK.AWS_FSX_ONTAP_FILE_SYSTEM.001lowaws_fsx_ontap_file_system: a customer-managed key
POLICY.IAC.CMEK.AWS_FSX_OPENZFS_FILE_SYSTEM.001lowaws_fsx_openzfs_file_system: a customer-managed key
POLICY.IAC.CMEK.AWS_FSX_WINDOWS_FILE_SYSTEM.001lowaws_fsx_windows_file_system: a customer-managed key
POLICY.IAC.CMEK.AWS_GLUE_SECURITY_CONFIGURATION.001lowaws_glue_security_configuration: a customer-managed key
POLICY.IAC.CMEK.AWS_GUARDDUTY_PUBLISHING_DESTINATION.001lowaws_guardduty_publishing_destination: a customer-managed key
POLICY.IAC.CMEK.AWS_IMAGEBUILDER_COMPONENT.001lowaws_imagebuilder_component: a customer-managed key
POLICY.IAC.CMEK.AWS_IMAGEBUILDER_CONTAINER_RECIPE.001lowaws_imagebuilder_container_recipe: a customer-managed key
POLICY.IAC.CMEK.AWS_IMAGEBUILDER_DISTRIBUTION_CONFIGURATION.001lowaws_imagebuilder_distribution_configuration: a customer-managed key
POLICY.IAC.CMEK.AWS_IMAGEBUILDER_IMAGE_RECIPE.001lowaws_imagebuilder_image_recipe: a customer-managed key
POLICY.IAC.CMEK.AWS_IMAGEBUILDER_WORKFLOW.001lowaws_imagebuilder_workflow: a customer-managed key
POLICY.IAC.CMEK.AWS_INSTANCE.001lowaws_instance: a customer-managed key
POLICY.IAC.CMEK.AWS_KENDRA_INDEX.001lowaws_kendra_index: a customer-managed key
POLICY.IAC.CMEK.AWS_KINESIS_FIREHOSE_DELIVERY_STREAM.001lowaws_kinesis_firehose_delivery_stream: a customer-managed key
POLICY.IAC.CMEK.AWS_KINESIS_STREAM.001lowaws_kinesis_stream: a customer-managed key
POLICY.IAC.CMEK.AWS_KINESIS_VIDEO_STREAM.001lowaws_kinesis_video_stream: a customer-managed key
POLICY.IAC.CMEK.AWS_LAMBDA_EVENT_SOURCE_MAPPING.001lowaws_lambda_event_source_mapping: a customer-managed key
POLICY.IAC.CMEK.AWS_LAMBDA_FUNCTION.001lowaws_lambda_function: a customer-managed key
POLICY.IAC.CMEK.AWS_LAUNCH_TEMPLATE.001lowaws_launch_template: a customer-managed key
POLICY.IAC.CMEK.AWS_LEXV2MODELS_SLOT_TYPE.001lowaws_lexv2models_slot_type: a customer-managed key
POLICY.IAC.CMEK.AWS_LEX_BOT_ALIAS.001lowaws_lex_bot_alias: a customer-managed key
POLICY.IAC.CMEK.AWS_LOCATION_GEOFENCE_COLLECTION.001lowaws_location_geofence_collection: a customer-managed key
POLICY.IAC.CMEK.AWS_LOCATION_TRACKER.001lowaws_location_tracker: a customer-managed key
POLICY.IAC.CMEK.AWS_M2_APPLICATION.001lowaws_m2_application: a customer-managed key
POLICY.IAC.CMEK.AWS_M2_ENVIRONMENT.001lowaws_m2_environment: a customer-managed key
POLICY.IAC.CMEK.AWS_MACIE2_CLASSIFICATION_EXPORT_CONFIGURATION.001lowaws_macie2_classification_export_configuration: a customer-managed key
POLICY.IAC.CMEK.AWS_MEMORYDB_CLUSTER.001lowaws_memorydb_cluster: a customer-managed key
POLICY.IAC.CMEK.AWS_MEMORYDB_SNAPSHOT.001lowaws_memorydb_snapshot: a customer-managed key
POLICY.IAC.CMEK.AWS_MQ_BROKER.001lowaws_mq_broker: a customer-managed key
POLICY.IAC.CMEK.AWS_NEPTUNE_CLUSTER.001lowaws_neptune_cluster: a customer-managed key
POLICY.IAC.CMEK.AWS_OPENSEARCH_DOMAIN.001lowaws_opensearch_domain: a customer-managed key
POLICY.IAC.CMEK.AWS_OSIS_PIPELINE.001lowaws_osis_pipeline: a customer-managed key
POLICY.IAC.CMEK.AWS_PROMETHEUS_WORKSPACE.001lowaws_prometheus_workspace: a customer-managed key
POLICY.IAC.CMEK.AWS_QBUSINESS_APPLICATION.001lowaws_qbusiness_application: a customer-managed key
POLICY.IAC.CMEK.AWS_RDS_CLUSTER.001lowaws_rds_cluster: a customer-managed key
POLICY.IAC.CMEK.AWS_RDS_CLUSTER_ACTIVITY_STREAM.001lowaws_rds_cluster_activity_stream: a customer-managed key
POLICY.IAC.CMEK.AWS_RDS_CLUSTER_SNAPSHOT_COPY.001lowaws_rds_cluster_snapshot_copy: a customer-managed key
POLICY.IAC.CMEK.AWS_RDS_CUSTOM_DB_ENGINE_VERSION.001lowaws_rds_custom_db_engine_version: a customer-managed key
POLICY.IAC.CMEK.AWS_RDS_EXPORT_TASK.001lowaws_rds_export_task: a customer-managed key
POLICY.IAC.CMEK.AWS_RDS_INTEGRATION.001lowaws_rds_integration: a customer-managed key
POLICY.IAC.CMEK.AWS_REDSHIFTSERVERLESS_NAMESPACE.001lowaws_redshiftserverless_namespace: a customer-managed key
POLICY.IAC.CMEK.AWS_REDSHIFT_CLUSTER.001lowaws_redshift_cluster: a customer-managed key
POLICY.IAC.CMEK.AWS_REDSHIFT_INTEGRATION.001lowaws_redshift_integration: a customer-managed key
POLICY.IAC.CMEK.AWS_REDSHIFT_SNAPSHOT_COPY_GRANT.001lowaws_redshift_snapshot_copy_grant: a customer-managed key
POLICY.IAC.CMEK.AWS_REKOGNITION_STREAM_PROCESSOR.001lowaws_rekognition_stream_processor: a customer-managed key
POLICY.IAC.CMEK.AWS_S3_BUCKET_OBJECT.001lowaws_s3_bucket_object: a customer-managed key
POLICY.IAC.CMEK.AWS_S3_OBJECT.001lowaws_s3_object: a customer-managed key
POLICY.IAC.CMEK.AWS_S3_OBJECT_COPY.001lowaws_s3_object_copy: a customer-managed key
POLICY.IAC.CMEK.AWS_SAGEMAKER_DATA_QUALITY_JOB_DEFINITION.001lowaws_sagemaker_data_quality_job_definition: a customer-managed key
POLICY.IAC.CMEK.AWS_SAGEMAKER_DEVICE_FLEET.001lowaws_sagemaker_device_fleet: a customer-managed key
POLICY.IAC.CMEK.AWS_SAGEMAKER_DOMAIN.001lowaws_sagemaker_domain: a customer-managed key
POLICY.IAC.CMEK.AWS_SAGEMAKER_ENDPOINT_CONFIGURATION.001lowaws_sagemaker_endpoint_configuration: a customer-managed key
POLICY.IAC.CMEK.AWS_SAGEMAKER_FEATURE_GROUP.001lowaws_sagemaker_feature_group: a customer-managed key
POLICY.IAC.CMEK.AWS_SAGEMAKER_FLOW_DEFINITION.001lowaws_sagemaker_flow_definition: a customer-managed key
POLICY.IAC.CMEK.AWS_SAGEMAKER_NOTEBOOK_INSTANCE.001lowaws_sagemaker_notebook_instance: a customer-managed key
POLICY.IAC.CMEK.AWS_SCHEDULER_SCHEDULE.001lowaws_scheduler_schedule: a customer-managed key
POLICY.IAC.CMEK.AWS_SECRETSMANAGER_SECRET.001lowaws_secretsmanager_secret: a customer-managed key
POLICY.IAC.CMEK.AWS_SES_RECEIPT_RULE.001lowaws_ses_receipt_rule: a customer-managed key
POLICY.IAC.CMEK.AWS_SFN_ACTIVITY.001lowaws_sfn_activity: a customer-managed key
POLICY.IAC.CMEK.AWS_SFN_STATE_MACHINE.001lowaws_sfn_state_machine: a customer-managed key
POLICY.IAC.CMEK.AWS_SPOT_FLEET_REQUEST.001lowaws_spot_fleet_request: a customer-managed key
POLICY.IAC.CMEK.AWS_SPOT_INSTANCE_REQUEST.001lowaws_spot_instance_request: a customer-managed key
POLICY.IAC.CMEK.AWS_SSMINCIDENTS_REPLICATION_SET.001lowaws_ssmincidents_replication_set: a customer-managed key
POLICY.IAC.CMEK.AWS_SSM_RESOURCE_DATA_SYNC.001lowaws_ssm_resource_data_sync: a customer-managed key
POLICY.IAC.CMEK.AWS_STORAGEGATEWAY_NFS_FILE_SHARE.001lowaws_storagegateway_nfs_file_share: a customer-managed key
POLICY.IAC.CMEK.AWS_STORAGEGATEWAY_SMB_FILE_SHARE.001lowaws_storagegateway_smb_file_share: a customer-managed key
POLICY.IAC.CMEK.AWS_SYNTHETICS_CANARY.001lowaws_synthetics_canary: a customer-managed key
POLICY.IAC.CMEK.AWS_TIMESTREAMQUERY_SCHEDULED_QUERY.001lowaws_timestreamquery_scheduled_query: a customer-managed key
POLICY.IAC.CMEK.AWS_TIMESTREAMWRITE_DATABASE.001lowaws_timestreamwrite_database: a customer-managed key
POLICY.IAC.CMEK.AWS_TIMESTREAMWRITE_TABLE.001lowaws_timestreamwrite_table: a customer-managed key
POLICY.IAC.CMEK.AWS_VERIFIEDACCESS_ENDPOINT.001lowaws_verifiedaccess_endpoint: a customer-managed key
POLICY.IAC.CMEK.AWS_VERIFIEDACCESS_GROUP.001lowaws_verifiedaccess_group: a customer-managed key
POLICY.IAC.CMEK.AWS_VERIFIEDACCESS_TRUST_PROVIDER.001lowaws_verifiedaccess_trust_provider: a customer-managed key
POLICY.IAC.CMEK.AZURERM_IMAGE.001lowazurerm_image: a customer-managed disk encryption set
POLICY.IAC.CMEK.AZURERM_KUBERNETES_CLUSTER.001lowazurerm_kubernetes_cluster: a customer-managed disk encryption set
POLICY.IAC.CMEK.AZURERM_LINUX_VIRTUAL_MACHINE.001lowazurerm_linux_virtual_machine: a customer-managed disk encryption set
POLICY.IAC.CMEK.AZURERM_LINUX_VIRTUAL_MACHINE_SCALE_SET.001lowazurerm_linux_virtual_machine_scale_set: a customer-managed disk encryption set
POLICY.IAC.CMEK.AZURERM_MANAGED_DISK.001lowazurerm_managed_disk: a customer-managed disk encryption set
POLICY.IAC.CMEK.AZURERM_ORCHESTRATED_VIRTUAL_MACHINE_SCALE_SET.001lowazurerm_orchestrated_virtual_machine_scale_set: a customer-managed disk encryption set
POLICY.IAC.CMEK.AZURERM_REDHAT_OPENSHIFT_CLUSTER.001lowazurerm_redhat_openshift_cluster: a customer-managed disk encryption set
POLICY.IAC.CMEK.AZURERM_SHARED_IMAGE_VERSION.001lowazurerm_shared_image_version: a customer-managed disk encryption set
POLICY.IAC.CMEK.AZURERM_WINDOWS_VIRTUAL_MACHINE.001lowazurerm_windows_virtual_machine: a customer-managed disk encryption set
POLICY.IAC.CMEK.AZURERM_WINDOWS_VIRTUAL_MACHINE_SCALE_SET.001lowazurerm_windows_virtual_machine_scale_set: a customer-managed disk encryption set
POLICY.IAC.CMEK.GOOGLE_ALLOYDB_BACKUP.001lowgoogle_alloydb_backup: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_ALLOYDB_CLUSTER.001lowgoogle_alloydb_cluster: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_ARTIFACT_REGISTRY_REPOSITORY.001lowgoogle_artifact_registry_repository: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_BIGQUERY_CONNECTION.001lowgoogle_bigquery_connection: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_BIGQUERY_DATASET.001lowgoogle_bigquery_dataset: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_BIGQUERY_DATA_TRANSFER_CONFIG.001lowgoogle_bigquery_data_transfer_config: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_BIGQUERY_JOB.001lowgoogle_bigquery_job: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_BIGQUERY_TABLE.001lowgoogle_bigquery_table: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_BIGTABLE_INSTANCE.001lowgoogle_bigtable_instance: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_CLOUDBUILD_TRIGGER.001lowgoogle_cloudbuild_trigger: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_CLOUDFUNCTIONS2_FUNCTION.001lowgoogle_cloudfunctions2_function: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_CLOUDFUNCTIONS_FUNCTION.001lowgoogle_cloudfunctions_function: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_COLAB_RUNTIME_TEMPLATE.001lowgoogle_colab_runtime_template: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_COMPOSER_ENVIRONMENT.001lowgoogle_composer_environment: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_COMPUTE_REGION_DISK.001lowgoogle_compute_region_disk: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_CONTAINER_AWS_CLUSTER.001lowgoogle_container_aws_cluster: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_CONTAINER_AWS_NODE_POOL.001lowgoogle_container_aws_node_pool: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_DATAFLOW_JOB.001lowgoogle_dataflow_job: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_DATAPROC_CLUSTER.001lowgoogle_dataproc_cluster: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_DATASTREAM_STREAM.001lowgoogle_datastream_stream: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_DATA_PIPELINE_PIPELINE.001lowgoogle_data_pipeline_pipeline: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_DISCOVERY_ENGINE_DATA_STORE.001lowgoogle_discovery_engine_data_store: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_DOCUMENT_AI_PROCESSOR.001lowgoogle_document_ai_processor: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_FILESTORE_INSTANCE.001lowgoogle_filestore_instance: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_FIRESTORE_DATABASE.001lowgoogle_firestore_database: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_HEALTHCARE_DATASET.001lowgoogle_healthcare_dataset: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_INTEGRATION_CONNECTORS_CONNECTION.001lowgoogle_integration_connectors_connection: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_LOGGING_BILLING_ACCOUNT_BUCKET_CONFIG.001lowgoogle_logging_billing_account_bucket_config: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_LOGGING_FOLDER_BUCKET_CONFIG.001lowgoogle_logging_folder_bucket_config: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_LOGGING_FOLDER_SETTINGS.001lowgoogle_logging_folder_settings: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_LOGGING_ORGANIZATION_BUCKET_CONFIG.001lowgoogle_logging_organization_bucket_config: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_LOGGING_ORGANIZATION_SETTINGS.001lowgoogle_logging_organization_settings: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_LOGGING_PROJECT_BUCKET_CONFIG.001lowgoogle_logging_project_bucket_config: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_LOOKER_INSTANCE.001lowgoogle_looker_instance: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_PUBSUB_TOPIC.001lowgoogle_pubsub_topic: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_SECRET_MANAGER_REGIONAL_SECRET.001lowgoogle_secret_manager_regional_secret: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_SECRET_MANAGER_SECRET.001lowgoogle_secret_manager_secret: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_SPANNER_BACKUP_SCHEDULE.001lowgoogle_spanner_backup_schedule: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_SPANNER_DATABASE.001lowgoogle_spanner_database: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_STORAGE_BUCKET_OBJECT.001lowgoogle_storage_bucket_object: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_VERTEX_AI_DATASET.001lowgoogle_vertex_ai_dataset: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_VERTEX_AI_ENDPOINT.001lowgoogle_vertex_ai_endpoint: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_VERTEX_AI_FEATURESTORE.001lowgoogle_vertex_ai_featurestore: a customer-managed key
POLICY.IAC.CMEK.GOOGLE_VERTEX_AI_TENSORBOARD.001lowgoogle_vertex_ai_tensorboard: a customer-managed key
POLICY.IAC.DELETION_PROTECTION.AWS_ALB_ENABLE_DELETION_PROTECTION.001lowaws_alb: deletion protection is not configured
POLICY.IAC.DELETION_PROTECTION.AWS_DB_INSTANCE_DELETION_PROTECTION.001lowaws_db_instance: deletion protection is not configured
POLICY.IAC.DELETION_PROTECTION.AWS_DOCDB_CLUSTER_DELETION_PROTECTION.001lowaws_docdb_cluster: deletion protection is not configured
POLICY.IAC.DELETION_PROTECTION.AWS_DOCDB_GLOBAL_CLUSTER.001lowaws_docdb_global_cluster: deletion protection
POLICY.IAC.DELETION_PROTECTION.AWS_DSQL_CLUSTER.001lowaws_dsql_cluster: deletion protection
POLICY.IAC.DELETION_PROTECTION.AWS_DYNAMODB_TABLE_DELETION_PROTECTION_ENABLED.001lowaws_dynamodb_table: deletion protection is not configured
POLICY.IAC.DELETION_PROTECTION.AWS_DYNAMODB_TABLE_REPLICA.001lowaws_dynamodb_table_replica: deletion protection
POLICY.IAC.DELETION_PROTECTION.AWS_LB_ENABLE_DELETION_PROTECTION.001lowaws_lb: deletion protection is not configured
POLICY.IAC.DELETION_PROTECTION.AWS_NEPTUNEGRAPH_GRAPH.001lowaws_neptunegraph_graph: deletion protection
POLICY.IAC.DELETION_PROTECTION.AWS_NEPTUNE_CLUSTER_DELETION_PROTECTION.001lowaws_neptune_cluster: deletion protection is not configured
POLICY.IAC.DELETION_PROTECTION.AWS_NEPTUNE_GLOBAL_CLUSTER.001lowaws_neptune_global_cluster: deletion protection
POLICY.IAC.DELETION_PROTECTION.AWS_PINPOINTSMSVOICEV2_PHONE_NUMBER.001lowaws_pinpointsmsvoicev2_phone_number: deletion protection
POLICY.IAC.DELETION_PROTECTION.AWS_QLDB_LEDGER.001lowaws_qldb_ledger: deletion protection
POLICY.IAC.DELETION_PROTECTION.AWS_RDS_CLUSTER_DELETION_PROTECTION.001lowaws_rds_cluster: deletion protection is not configured
POLICY.IAC.DELETION_PROTECTION.AWS_RDS_GLOBAL_CLUSTER.001lowaws_rds_global_cluster: deletion protection
POLICY.IAC.DELETION_PROTECTION.AZURERM_APP_CONFIGURATION.001mediumazurerm_app_configuration: purge protection
POLICY.IAC.DELETION_PROTECTION.AZURERM_KEY_VAULT_MANAGED_HARDWARE_SECURITY_MODULE.001mediumazurerm_key_vault_managed_hardware_security_module: purge protection
POLICY.IAC.DELETION_PROTECTION.AZURERM_KEY_VAULT_PURGE_PROTECTION_ENABLED.001mediumazurerm_key_vault: deletion protection is not configured
POLICY.IAC.DELETION_PROTECTION.GOOGLE_ACTIVE_DIRECTORY_DOMAIN.001lowgoogle_active_directory_domain: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_BIGQUERY_TABLE.001lowgoogle_bigquery_table: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_BIGTABLE_INSTANCE.001lowgoogle_bigtable_instance: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_BIGTABLE_LOGICAL_VIEW.001lowgoogle_bigtable_logical_view: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_BIGTABLE_MATERIALIZED_VIEW.001lowgoogle_bigtable_materialized_view: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_CLOUD_RUN_V2_JOB.001lowgoogle_cloud_run_v2_job: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_CLOUD_RUN_V2_SERVICE.001lowgoogle_cloud_run_v2_service: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_CLOUD_RUN_V2_WORKER_POOL.001lowgoogle_cloud_run_v2_worker_pool: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_COMPUTE_INSTANCE.001lowgoogle_compute_instance: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_COMPUTE_INSTANCE_FROM_TEMPLATE.001lowgoogle_compute_instance_from_template: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_COMPUTE_STORAGE_POOL.001lowgoogle_compute_storage_pool: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_CONTAINER_CLUSTER.001lowgoogle_container_cluster: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_DATAPROC_METASTORE_FEDERATION.001lowgoogle_dataproc_metastore_federation: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_DATAPROC_METASTORE_SERVICE.001lowgoogle_dataproc_metastore_service: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_FILESTORE_INSTANCE.001lowgoogle_filestore_instance: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_FOLDER.001lowgoogle_folder: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_MEMORYSTORE_INSTANCE.001lowgoogle_memorystore_instance: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_ORACLE_DATABASE_AUTONOMOUS_DATABASE.001lowgoogle_oracle_database_autonomous_database: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_ORACLE_DATABASE_CLOUD_EXADATA_INFRASTRUCTURE.001lowgoogle_oracle_database_cloud_exadata_infrastructure: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_ORACLE_DATABASE_CLOUD_VM_CLUSTER.001lowgoogle_oracle_database_cloud_vm_cluster: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_ORACLE_DATABASE_ODB_NETWORK.001lowgoogle_oracle_database_odb_network: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_ORACLE_DATABASE_ODB_SUBNET.001lowgoogle_oracle_database_odb_subnet: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_PRIVATECA_CERTIFICATE_AUTHORITY.001lowgoogle_privateca_certificate_authority: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_REDIS_CLUSTER.001lowgoogle_redis_cluster: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_SECRET_MANAGER_REGIONAL_SECRET.001lowgoogle_secret_manager_regional_secret: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_SECRET_MANAGER_SECRET.001lowgoogle_secret_manager_secret: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_SPANNER_DATABASE.001lowgoogle_spanner_database: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_SQL_DATABASE_INSTANCE.001lowgoogle_sql_database_instance: deletion protection
POLICY.IAC.DELETION_PROTECTION.GOOGLE_WORKFLOWS_WORKFLOW.001lowgoogle_workflows_workflow: deletion protection
POLICY.IAC.DEPRECATED_RUNTIME.AWS_ELASTIC_BEANSTALK_ENVIRONMENT.001mediumaws_elastic_beanstalk_environment: the runtime is out of support
POLICY.IAC.DEPRECATED_RUNTIME.AWS_LAMBDA_FUNCTION.001mediumaws_lambda_function: the runtime is out of support
POLICY.IAC.DEPRECATED_RUNTIME.AZURERM_LINUX_FUNCTION_APP.001mediumazurerm_linux_function_app: the runtime is out of support
POLICY.IAC.DEPRECATED_RUNTIME.GOOGLE_CLOUDFUNCTIONS_FUNCTION.001mediumgoogle_cloudfunctions_function: the runtime is out of support
POLICY.IAC.ENCRYPT_AT_REST.AWS_AMI.001highaws_ami: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_AMI_COPY.001highaws_ami_copy: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_APPSYNC_API_CACHE.001mediumaws_appsync_api_cache: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_ATHENA_DATABASE_ENCRYPTION_CONFIGURATION.001mediumaws_athena_database: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_ATHENA_WORKGROUP_ENCRYPTION_CONFIGURATION.001mediumaws_athena_workgroup: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_BACKUP_VAULT.001mediumaws_backup_vault: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_CLOUDTRAIL_KMS_KEY_ID.001mediumaws_cloudtrail: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_CLOUDWATCH_LOG_GROUP_KMS_KEY_ID.001lowaws_cloudwatch_log_group: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_CODEBUILD_PROJECT.001lowaws_codebuild_project: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_DAX_CLUSTER.001mediumaws_dax_cluster: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_DB_INSTANCE.001highaws_db_instance: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AWS_DLM_LIFECYCLE_POLICY.001highaws_dlm_lifecycle_policy: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_DOCDB_CLUSTER.001highaws_docdb_cluster: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AWS_DOCDB_GLOBAL_CLUSTER.001highaws_docdb_global_cluster: storage encryption
POLICY.IAC.ENCRYPT_AT_REST.AWS_EBS_SNAPSHOT_COPY.001highaws_ebs_snapshot_copy: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_EBS_SNAPSHOT_IMPORT.001highaws_ebs_snapshot_import: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_EBS_VOLUME.001highaws_ebs_volume: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AWS_ECR_REPOSITORY.001lowaws_ecr_repository: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_ECS_SERVICE.001highaws_ecs_service: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_EFS_FILE_SYSTEM.001highaws_efs_file_system: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AWS_EKS_CLUSTER.001mediumaws_eks_cluster: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_ELASTICACHE_REPLICATION_GROUP.001mediumaws_elasticache_replication_group: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AWS_ELASTICSEARCH_DOMAIN_ENCRYPT_AT_REST.001highaws_elasticsearch_domain: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_FSX_LUSTRE_FILE_SYSTEM.001mediumaws_fsx_lustre_file_system: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_GLUE_CATALOG_DATABASE_TARGET_DATABASE.001lowaws_glue_catalog_database: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_INSTANCE.001highaws_instance: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_KINESIS_FIREHOSE_DELIVERY_STREAM_SERVER_SIDE_ENCRYPTION.001mediumaws_kinesis_firehose_delivery_stream: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_KINESIS_STREAM_ENCRYPTION_TYPE.001mediumaws_kinesis_stream: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_LAMBDA_FUNCTION_KMS_KEY_ARN.001lowaws_lambda_function: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_LAUNCH_CONFIGURATION.001highaws_launch_configuration: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_MEMORYDB_CLUSTER_KMS_KEY_ARN.001mediumaws_memorydb_cluster: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_MQ_BROKER_ENCRYPTION_OPTIONS.001mediumaws_mq_broker: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_NEPTUNE_CLUSTER.001highaws_neptune_cluster: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AWS_NEPTUNE_GLOBAL_CLUSTER.001highaws_neptune_global_cluster: storage encryption
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPENSEARCH_DOMAIN_ENCRYPT_AT_REST.001highaws_opensearch_domain: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_CUSTOM_LAYER.001highaws_opsworks_custom_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_ECS_CLUSTER_LAYER.001highaws_opsworks_ecs_cluster_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_GANGLIA_LAYER.001highaws_opsworks_ganglia_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_HAPROXY_LAYER.001highaws_opsworks_haproxy_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_JAVA_APP_LAYER.001highaws_opsworks_java_app_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_MEMCACHED_LAYER.001highaws_opsworks_memcached_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_MYSQL_LAYER.001highaws_opsworks_mysql_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_NODEJS_APP_LAYER.001highaws_opsworks_nodejs_app_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_PHP_APP_LAYER.001highaws_opsworks_php_app_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_RAILS_APP_LAYER.001highaws_opsworks_rails_app_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_OPSWORKS_STATIC_WEB_LAYER.001highaws_opsworks_static_web_layer: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_QLDB_LEDGER.001lowaws_qldb_ledger: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_RDS_CLUSTER.001highaws_rds_cluster: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AWS_RDS_GLOBAL_CLUSTER.001mediumaws_rds_global_cluster: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AWS_REDSHIFT_CLUSTER.001highaws_redshift_cluster: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AWS_SAGEMAKER_ENDPOINT_CONFIGURATION.001mediumaws_sagemaker_endpoint_configuration: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_SAGEMAKER_NOTEBOOK_INSTANCE.001mediumaws_sagemaker_notebook_instance: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_SECRETSMANAGER_SECRET_KMS_KEY_ID.001lowaws_secretsmanager_secret: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_SNS_TOPIC_KMS_MASTER_KEY_ID.001mediumaws_sns_topic: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_SPOT_FLEET_REQUEST.001highaws_spot_fleet_request: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_SPOT_INSTANCE_REQUEST.001highaws_spot_instance_request: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AWS_SQS_QUEUE_KMS_MASTER_KEY_ID.001mediumaws_sqs_queue: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_SSM_PARAMETER_KEY_ID.001mediumaws_ssm_parameter: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_TIMESTREAMWRITE_DATABASE.001lowaws_timestreamwrite_database: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_TRANSFER_SERVER_POST_AUTHENTICATION_LOGIN_BANNER.001lowaws_transfer_server: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AWS_WORKSPACES_WORKSPACE.001mediumaws_workspaces_workspace: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_AUTOMATION_VARIABLE_BOOL.001highazurerm_automation_variable_bool: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_AUTOMATION_VARIABLE_DATETIME.001highazurerm_automation_variable_datetime: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_AUTOMATION_VARIABLE_INT.001highazurerm_automation_variable_int: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_AUTOMATION_VARIABLE_OBJECT.001highazurerm_automation_variable_object: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_AUTOMATION_VARIABLE_STRING.001highazurerm_automation_variable_string: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_COSMOSDB_ACCOUNT_KEY_VAULT_KEY_ID.001lowazurerm_cosmosdb_account: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_DATABRICKS_WORKSPACE.001mediumazurerm_databricks_workspace: infrastructure encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_EVENTHUB_NAMESPACE_CUSTOMER_MANAGED_KEY.001mediumazurerm_eventhub_namespace_customer_managed_key: infrastructure encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_EVENTHUB_NAMESPACE_LOCAL_AUTHENTICATION_ENABLED.001lowazurerm_eventhub_namespace: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_HDINSIGHT_HADOOP_CLUSTER.001mediumazurerm_hdinsight_hadoop_cluster: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_HDINSIGHT_HBASE_CLUSTER.001mediumazurerm_hdinsight_hbase_cluster: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_HDINSIGHT_INTERACTIVE_QUERY_CLUSTER.001mediumazurerm_hdinsight_interactive_query_cluster: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_HDINSIGHT_KAFKA_CLUSTER.001mediumazurerm_hdinsight_kafka_cluster: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_HDINSIGHT_SPARK_CLUSTER.001mediumazurerm_hdinsight_spark_cluster: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_HPC_CACHE.001highazurerm_hpc_cache: encryption at rest
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_LINUX_VIRTUAL_MACHINE.001mediumazurerm_linux_virtual_machine: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_LINUX_VIRTUAL_MACHINE_SCALE_SET.001mediumazurerm_linux_virtual_machine_scale_set: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_MANAGED_DISK.001mediumazurerm_managed_disk: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_MSSQL_DATABASE_TRANSPARENT_DATA_ENCRYPTION_ENABLED.001highazurerm_mssql_database: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_MYSQL_SERVER.001mediumazurerm_mysql_server: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_ORCHESTRATED_VIRTUAL_MACHINE_SCALE_SET.001mediumazurerm_orchestrated_virtual_machine_scale_set: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_POSTGRESQL_SERVER.001mediumazurerm_postgresql_server: Encryption at rest is not enabled
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_RECOVERY_SERVICES_VAULT.001mediumazurerm_recovery_services_vault: infrastructure encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_REDHAT_OPENSHIFT_CLUSTER.001mediumazurerm_redhat_openshift_cluster: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_SERVICEBUS_NAMESPACE.001mediumazurerm_servicebus_namespace: infrastructure encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_SERVICEBUS_NAMESPACE_CUSTOMER_MANAGED_KEY.001mediumazurerm_servicebus_namespace_customer_managed_key: infrastructure encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_STORAGE_ACCOUNT_INFRASTRUCTURE_ENCRYPTION_ENABLED.001lowazurerm_storage_account: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_WINDOWS_VIRTUAL_MACHINE.001mediumazurerm_windows_virtual_machine: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.AZURERM_WINDOWS_VIRTUAL_MACHINE_SCALE_SET.001mediumazurerm_windows_virtual_machine_scale_set: host-level encryption
POLICY.IAC.ENCRYPT_AT_REST.GOOGLE_BIGQUERY_DATASET.001lowgoogle_bigquery_dataset: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.GOOGLE_BIGTABLE_INSTANCE_CLUSTER.001lowgoogle_bigtable_instance: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.GOOGLE_CONTAINER_CLUSTER_DATABASE_ENCRYPTION.001mediumgoogle_container_cluster: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.GOOGLE_DATAPROC_CLUSTER.001lowgoogle_dataproc_cluster: encryption at rest is not configured
POLICY.IAC.ENCRYPT_AT_REST.GOOGLE_PUBSUB_TOPIC_KMS_KEY_NAME.001lowgoogle_pubsub_topic: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.GOOGLE_SPANNER_DATABASE_ENCRYPTION_CONFIG.001lowgoogle_spanner_database: a customer-managed key is not configured
POLICY.IAC.ENCRYPT_AT_REST.GOOGLE_SQL_DATABASE_INSTANCE.001lowgoogle_sql_database_instance: encryption at rest is not configured
POLICY.IAC.ENCRYPT_IN_TRANSIT.AWS_APPSYNC_API_CACHE.001highaws_appsync_api_cache: encryption in transit
POLICY.IAC.ENCRYPT_IN_TRANSIT.AWS_CLOUDSEARCH_DOMAIN.001highaws_cloudsearch_domain: https enforcement
POLICY.IAC.ENCRYPT_IN_TRANSIT.AWS_ELASTICACHE_CLUSTER.001highaws_elasticache_cluster: encryption in transit
POLICY.IAC.ENCRYPT_IN_TRANSIT.AWS_ELASTICACHE_REPLICATION_GROUP.001highaws_elasticache_replication_group: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AWS_ELASTICSEARCH_DOMAIN.001highaws_elasticsearch_domain: https enforcement
POLICY.IAC.ENCRYPT_IN_TRANSIT.AWS_OPENSEARCH_DOMAIN.001highaws_opensearch_domain: https enforcement
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_APP_SERVICE.001mediumazurerm_app_service: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_APP_SERVICE_SLOT.001mediumazurerm_app_service_slot: https-only traffic
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_FUNCTION_APP.001mediumazurerm_function_app: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_FUNCTION_APP_FLEX_CONSUMPTION.001mediumazurerm_function_app_flex_consumption: https-only traffic
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_FUNCTION_APP_SLOT.001mediumazurerm_function_app_slot: https-only traffic
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_LINUX_FUNCTION_APP.001mediumazurerm_linux_function_app: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_LINUX_FUNCTION_APP_SLOT.001mediumazurerm_linux_function_app_slot: https-only traffic
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_LINUX_WEB_APP.001mediumazurerm_linux_web_app: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_LINUX_WEB_APP_SLOT.001mediumazurerm_linux_web_app_slot: https-only traffic
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_LOGIC_APP_STANDARD.001mediumazurerm_logic_app_standard: https-only traffic
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_MARIADB_SERVER.001highazurerm_mariadb_server: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_MYSQL_SERVER.001highazurerm_mysql_server: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_POSTGRESQL_SERVER.001highazurerm_postgresql_server: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_SPRING_CLOUD_APP.001mediumazurerm_spring_cloud_app: https-only traffic
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_SPRING_CLOUD_GATEWAY.001mediumazurerm_spring_cloud_gateway: https-only traffic
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_STORAGE_ACCOUNT.001highazurerm_storage_account: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_WINDOWS_FUNCTION_APP.001mediumazurerm_windows_function_app: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_WINDOWS_FUNCTION_APP_SLOT.001mediumazurerm_windows_function_app_slot: https-only traffic
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_WINDOWS_WEB_APP.001mediumazurerm_windows_web_app: Encryption in transit is not enabled
POLICY.IAC.ENCRYPT_IN_TRANSIT.AZURERM_WINDOWS_WEB_APP_SLOT.001mediumazurerm_windows_web_app_slot: https-only traffic
POLICY.IAC.FORCE_DESTROY.AWS_ATHENA_DATABASE.001lowaws_athena_database: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_ATHENA_WORKGROUP.001lowaws_athena_workgroup: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_BACKUP_VAULT.001lowaws_backup_vault: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_CLOUDWATCH_EVENT_RULE.001lowaws_cloudwatch_event_rule: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_CLOUDWATCH_EVENT_TARGET.001lowaws_cloudwatch_event_target: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_DATAEXCHANGE_REVISION_ASSETS.001lowaws_dataexchange_revision_assets: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_DEFAULT_SUBNET.001lowaws_default_subnet: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_DEFAULT_VPC.001lowaws_default_vpc: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_DX_LAG.001lowaws_dx_lag: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_ECRPUBLIC_REPOSITORY.001lowaws_ecrpublic_repository: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_IAM_USER.001lowaws_iam_user: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_RDS_CLUSTER_INSTANCE.001lowaws_rds_cluster_instance: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_RDS_GLOBAL_CLUSTER.001lowaws_rds_global_cluster: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_REDSHIFT_SNAPSHOT_SCHEDULE.001lowaws_redshift_snapshot_schedule: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_ROUTE53_ZONE.001lowaws_route53_zone: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_S3_BUCKET.001lowaws_s3_bucket: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_S3_BUCKET_OBJECT.001lowaws_s3_bucket_object: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_S3_DIRECTORY_BUCKET.001lowaws_s3_directory_bucket: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_S3_OBJECT.001lowaws_s3_object: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_S3_OBJECT_COPY.001lowaws_s3_object_copy: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_SERVICE_DISCOVERY_SERVICE.001lowaws_service_discovery_service: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.AWS_TRANSFER_SERVER.001lowaws_transfer_server: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.GOOGLE_BIGTABLE_INSTANCE.001lowgoogle_bigtable_instance: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.GOOGLE_DNS_MANAGED_ZONE.001lowgoogle_dns_managed_zone: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.GOOGLE_GEMINI_CODE_REPOSITORY_INDEX.001lowgoogle_gemini_code_repository_index: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.GOOGLE_SPANNER_INSTANCE.001lowgoogle_spanner_instance: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.GOOGLE_STORAGE_BUCKET.001lowgoogle_storage_bucket: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.GOOGLE_STORAGE_FOLDER.001lowgoogle_storage_folder: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.GOOGLE_STORAGE_MANAGED_FOLDER.001lowgoogle_storage_managed_folder: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.GOOGLE_VERTEX_AI_FEATURESTORE.001lowgoogle_vertex_ai_featurestore: a destroy will not be stopped by the data in it
POLICY.IAC.FORCE_DESTROY.GOOGLE_VERTEX_AI_FEATURE_ONLINE_STORE.001lowgoogle_vertex_ai_feature_online_store: a destroy will not be stopped by the data in it
POLICY.IAC.GOVERNANCE.AWS_DB_INSTANCE.001lowaws_db_instance: tags on snapshots
POLICY.IAC.GOVERNANCE.AWS_DOCDB_CLUSTER_INSTANCE.001lowaws_docdb_cluster_instance: tags on snapshots
POLICY.IAC.GOVERNANCE.AWS_NEPTUNE_CLUSTER.001lowaws_neptune_cluster: tags on snapshots
POLICY.IAC.GOVERNANCE.AWS_RDS_CLUSTER.001lowaws_rds_cluster: tags on snapshots
POLICY.IAC.GOVERNANCE.AWS_RDS_CLUSTER_INSTANCE.001lowaws_rds_cluster_instance: tags on snapshots
POLICY.IAC.KEY_ROTATION.AWS_KMS_KEY.001mediumaws_kms_key: automatic key rotation is not enabled
POLICY.IAC.KEY_ROTATION.GOOGLE_KMS_CRYPTO_KEY.001mediumgoogle_kms_crypto_key: no rotation period is set
POLICY.IAC.LOGGING.AWS_ALB_ACCESS_LOGS.001lowaws_alb: audit logging is not configured
POLICY.IAC.LOGGING.AWS_APIGATEWAYV2_STAGE_ACCESS_LOG_SETTINGS.001lowaws_apigatewayv2_stage: audit logging is not configured
POLICY.IAC.LOGGING.AWS_API_GATEWAY_STAGE_ACCESS_LOG_SETTINGS.001lowaws_api_gateway_stage: audit logging is not configured
POLICY.IAC.LOGGING.AWS_API_GATEWAY_STAGE_XRAY_TRACING_ENABLED.001lowaws_api_gateway_stage: audit logging is not configured
POLICY.IAC.LOGGING.AWS_CLOUDFRONT_DISTRIBUTION_LOGGING_CONFIG.001lowaws_cloudfront_distribution: audit logging is not configured
POLICY.IAC.LOGGING.AWS_CLOUDTRAIL_ENABLE_LOG_FILE_VALIDATION.001mediumaws_cloudtrail: audit logging is not configured
POLICY.IAC.LOGGING.AWS_CLOUDTRAIL_IS_MULTI_REGION_TRAIL.001mediumaws_cloudtrail: audit logging is not configured
POLICY.IAC.LOGGING.AWS_DB_INSTANCE.001lowaws_db_instance: performance insights
POLICY.IAC.LOGGING.AWS_DOCDB_CLUSTER_ENABLED_CLOUDWATCH_LOGS_EXPORTS.001lowaws_docdb_cluster: audit logging is not configured
POLICY.IAC.LOGGING.AWS_EKS_CLUSTER_ENABLED_CLUSTER_LOG_TYPES.001mediumaws_eks_cluster: audit logging is not configured
POLICY.IAC.LOGGING.AWS_ELASTICSEARCH_DOMAIN_LOG_PUBLISHING_OPTIONS.001lowaws_elasticsearch_domain: audit logging is not configured
POLICY.IAC.LOGGING.AWS_GLOBALACCELERATOR_ACCELERATOR_ATTRIBUTES.001lowaws_globalaccelerator_accelerator: audit logging is not configured
POLICY.IAC.LOGGING.AWS_LAMBDA_FUNCTION_TRACING_CONFIG.001lowaws_lambda_function: audit logging is not configured
POLICY.IAC.LOGGING.AWS_LB_ACCESS_LOGS.001lowaws_lb: audit logging is not configured
POLICY.IAC.LOGGING.AWS_MQ_BROKER_LOGS.001lowaws_mq_broker: audit logging is not configured
POLICY.IAC.LOGGING.AWS_MSK_CLUSTER_LOGGING_INFO.001lowaws_msk_cluster: audit logging is not configured
POLICY.IAC.LOGGING.AWS_NEPTUNE_CLUSTER_ENABLE_CLOUDWATCH_LOGS_EXPORTS.001lowaws_neptune_cluster: audit logging is not configured
POLICY.IAC.LOGGING.AWS_OPENSEARCH_DOMAIN_LOG_PUBLISHING_OPTIONS.001lowaws_opensearch_domain: audit logging is not configured
POLICY.IAC.LOGGING.AWS_RDS_CLUSTER.001lowaws_rds_cluster: performance insights
POLICY.IAC.LOGGING.AWS_RDS_CLUSTER_INSTANCE.001lowaws_rds_cluster_instance: performance insights
POLICY.IAC.LOGGING.AWS_REDSHIFT_CLUSTER_LOGGING.001lowaws_redshift_cluster: audit logging is not configured
POLICY.IAC.LOGGING.AWS_S3_BUCKET_LOGGING_TARGET_BUCKET.001lowaws_s3_bucket_logging: audit logging is not configured
POLICY.IAC.LOGGING.AWS_VPC_ENABLE_DNS_HOSTNAMES.001lowaws_vpc: audit logging is not configured
POLICY.IAC.LOGGING.AZURERM_KEY_VAULT_SOFT_DELETE_RETENTION_DAYS.001lowazurerm_key_vault: audit logging is not configured
POLICY.IAC.LOGGING.AZURERM_KUBERNETES_CLUSTER_OMS_AGENT.001lowazurerm_kubernetes_cluster: audit logging is not configured
POLICY.IAC.LOGGING.AZURERM_MSSQL_SERVER_EXTENDED_AUDITING_POLICY.001mediumazurerm_mssql_server: audit logging is not configured
POLICY.IAC.LOGGING.GOOGLE_COMPUTE_FIREWALL.001lowgoogle_compute_firewall: logging
POLICY.IAC.LOGGING.GOOGLE_COMPUTE_FIREWALL_POLICY_RULE.001lowgoogle_compute_firewall_policy_rule: logging
POLICY.IAC.LOGGING.GOOGLE_COMPUTE_FIREWALL_POLICY_WITH_RULES.001lowgoogle_compute_firewall_policy_with_rules: logging
POLICY.IAC.LOGGING.GOOGLE_COMPUTE_NETWORK_FIREWALL_POLICY_RULE.001lowgoogle_compute_network_firewall_policy_rule: logging
POLICY.IAC.LOGGING.GOOGLE_COMPUTE_NETWORK_FIREWALL_POLICY_WITH_RULES.001lowgoogle_compute_network_firewall_policy_with_rules: logging
POLICY.IAC.LOGGING.GOOGLE_COMPUTE_REGION_NETWORK_FIREWALL_POLICY_RULE.001lowgoogle_compute_region_network_firewall_policy_rule: logging
POLICY.IAC.LOGGING.GOOGLE_COMPUTE_REGION_NETWORK_FIREWALL_POLICY_WITH_RULES.001lowgoogle_compute_region_network_firewall_policy_with_rules: logging
POLICY.IAC.LOGGING.GOOGLE_COMPUTE_SUBNETWORK_LOG_CONFIG.001lowgoogle_compute_subnetwork: audit logging is not configured
POLICY.IAC.LOGGING.GOOGLE_CONTAINER_CLUSTER_LOGGING_SERVICE.001lowgoogle_container_cluster: audit logging is not configured
POLICY.IAC.LOGGING.GOOGLE_CONTAINER_CLUSTER_MONITORING_SERVICE.001lowgoogle_container_cluster: audit logging is not configured
POLICY.IAC.LOGGING.GOOGLE_DATA_FUSION_INSTANCE.001lowgoogle_data_fusion_instance: logging
POLICY.IAC.LOGGING.GOOGLE_DIALOGFLOW_AGENT.001lowgoogle_dialogflow_agent: logging
POLICY.IAC.LOGGING.GOOGLE_DIALOGFLOW_CONVERSATION_PROFILE.001lowgoogle_dialogflow_conversation_profile: logging
POLICY.IAC.LOGGING.GOOGLE_DIALOGFLOW_CX_AGENT.001lowgoogle_dialogflow_cx_agent: logging
POLICY.IAC.LOGGING.GOOGLE_DIALOGFLOW_CX_FLOW.001lowgoogle_dialogflow_cx_flow: logging
POLICY.IAC.LOGGING.GOOGLE_DIALOGFLOW_CX_PAGE.001lowgoogle_dialogflow_cx_page: logging
POLICY.IAC.LOGGING.GOOGLE_DIALOGFLOW_CX_WEBHOOK.001lowgoogle_dialogflow_cx_webhook: logging
POLICY.IAC.LOGGING.GOOGLE_DNS_MANAGED_ZONE.001lowgoogle_dns_managed_zone: logging
POLICY.IAC.LOGGING.GOOGLE_DNS_POLICY.001lowgoogle_dns_policy: logging
POLICY.IAC.LOGGING.GOOGLE_SQL_DATABASE_INSTANCE_BACKUP_CONFIGURATION.001mediumgoogle_sql_database_instance: audit logging is not configured
POLICY.IAC.LOGGING.GOOGLE_STORAGE_BUCKET_LOGGING.001lowgoogle_storage_bucket: audit logging is not configured
POLICY.IAC.MFA.AWS_S3_BUCKET.001mediumaws_s3_bucket: mfa for deletion
POLICY.IAC.MUTABLE_TAGS.AWS_ECR_REPOSITORY.001mediumaws_ecr_repository: image tags are mutable
POLICY.IAC.NO_MFA.AWS_IAM_USER.001lowaws_iam_user: a long-lived user is created
POLICY.IAC.ORPHANED_DATA.AWS_AMI.001lowaws_ami: deleting the volume with the instance
POLICY.IAC.ORPHANED_DATA.AWS_INSTANCE.001lowaws_instance: deleting the volume with the instance
POLICY.IAC.ORPHANED_DATA.AWS_LAUNCH_CONFIGURATION.001lowaws_launch_configuration: deleting the volume with the instance
POLICY.IAC.ORPHANED_DATA.AWS_OPSWORKS_INSTANCE.001lowaws_opsworks_instance: deleting the volume with the instance
POLICY.IAC.ORPHANED_DATA.AWS_SPOT_FLEET_REQUEST.001lowaws_spot_fleet_request: deleting the volume with the instance
POLICY.IAC.ORPHANED_DATA.AWS_SPOT_INSTANCE_REQUEST.001lowaws_spot_instance_request: deleting the volume with the instance
POLICY.IAC.PATCHING.AWS_DB_INSTANCE.001mediumaws_db_instance: automatic minor version upgrades
POLICY.IAC.PATCHING.AWS_DMS_REPLICATION_INSTANCE.001mediumaws_dms_replication_instance: automatic minor version upgrades
POLICY.IAC.PATCHING.AWS_DOCDB_CLUSTER_INSTANCE.001mediumaws_docdb_cluster_instance: automatic minor version upgrades
POLICY.IAC.PATCHING.AWS_MEMORYDB_CLUSTER.001mediumaws_memorydb_cluster: automatic minor version upgrades
POLICY.IAC.PATCHING.AWS_MQ_BROKER.001mediumaws_mq_broker: automatic minor version upgrades
POLICY.IAC.PATCHING.AWS_NEPTUNE_CLUSTER_INSTANCE.001mediumaws_neptune_cluster_instance: automatic minor version upgrades
POLICY.IAC.PATCHING.AWS_RDS_CLUSTER_INSTANCE.001mediumaws_rds_cluster_instance: automatic minor version upgrades
POLICY.IAC.PUBLIC_IP.AWS_CLOUDWATCH_EVENT_TARGET.001lowaws_cloudwatch_event_target: a public ip address
POLICY.IAC.PUBLIC_IP.AWS_DEFAULT_SUBNET.001lowaws_default_subnet: every instance in the subnet gets a public address
POLICY.IAC.PUBLIC_IP.AWS_ECS_SERVICE.001lowaws_ecs_service: a public ip address
POLICY.IAC.PUBLIC_IP.AWS_ECS_TASK_SET.001lowaws_ecs_task_set: a public ip address
POLICY.IAC.PUBLIC_IP.AWS_INSTANCE.001lowaws_instance: a public ip address
POLICY.IAC.PUBLIC_IP.AWS_LAUNCH_CONFIGURATION.001lowaws_launch_configuration: a public ip address
POLICY.IAC.PUBLIC_IP.AWS_SCHEDULER_SCHEDULE.001lowaws_scheduler_schedule: a public ip address
POLICY.IAC.PUBLIC_IP.AWS_SPOT_FLEET_REQUEST.001lowaws_spot_fleet_request: a public ip address
POLICY.IAC.PUBLIC_IP.AWS_SPOT_INSTANCE_REQUEST.001lowaws_spot_instance_request: a public ip address
POLICY.IAC.PUBLIC_IP.AWS_SUBNET.001lowaws_subnet: every instance in the subnet gets a public address
POLICY.IAC.RESILIENCE.AWS_CLOUDSEARCH_DOMAIN.001lowaws_cloudsearch_domain: a standby in another availability zone
POLICY.IAC.RESILIENCE.AWS_DB_INSTANCE.001lowaws_db_instance: a standby in another availability zone
POLICY.IAC.RESILIENCE.AWS_DMS_REPLICATION_CONFIG.001lowaws_dms_replication_config: a standby in another availability zone
POLICY.IAC.RESILIENCE.AWS_DMS_REPLICATION_INSTANCE.001lowaws_dms_replication_instance: a standby in another availability zone
POLICY.IAC.RESILIENCE.AWS_REDSHIFT_CLUSTER.001lowaws_redshift_cluster: a standby in another availability zone
POLICY.IAC.RETENTION.AWS_CLOUDWATCH_LOG_GROUP.001lowaws_cloudwatch_log_group: a retention period
POLICY.IAC.RETENTION.AZURERM_APPLICATION_INSIGHTS.001lowazurerm_application_insights: a retention period
POLICY.IAC.RETENTION.AZURERM_APP_SERVICE.001lowazurerm_app_service: a retention period
POLICY.IAC.RETENTION.AZURERM_APP_SERVICE_SLOT.001lowazurerm_app_service_slot: a retention period
POLICY.IAC.RETENTION.AZURERM_FIREWALL_POLICY.001lowazurerm_firewall_policy: a retention period
POLICY.IAC.RETENTION.AZURERM_LINUX_WEB_APP.001lowazurerm_linux_web_app: a retention period
POLICY.IAC.RETENTION.AZURERM_LINUX_WEB_APP_SLOT.001lowazurerm_linux_web_app_slot: a retention period
POLICY.IAC.RETENTION.AZURERM_LOG_ANALYTICS_WORKSPACE.001lowazurerm_log_analytics_workspace: a retention period
POLICY.IAC.RETENTION.AZURERM_LOG_ANALYTICS_WORKSPACE_TABLE.001lowazurerm_log_analytics_workspace_table: a retention period
POLICY.IAC.RETENTION.AZURERM_LOG_ANALYTICS_WORKSPACE_TABLE_CUSTOM_LOG.001lowazurerm_log_analytics_workspace_table_custom_log: a retention period
POLICY.IAC.RETENTION.AZURERM_LOG_ANALYTICS_WORKSPACE_TABLE_MICROSOFT.001lowazurerm_log_analytics_workspace_table_microsoft: a retention period
POLICY.IAC.RETENTION.AZURERM_MSSQL_DATABASE_EXTENDED_AUDITING_POLICY.001lowazurerm_mssql_database_extended_auditing_policy: a retention period
POLICY.IAC.RETENTION.AZURERM_MSSQL_SERVER_EXTENDED_AUDITING_POLICY.001lowazurerm_mssql_server_extended_auditing_policy: a retention period
POLICY.IAC.RETENTION.AZURERM_SYNAPSE_SQL_POOL_EXTENDED_AUDITING_POLICY.001lowazurerm_synapse_sql_pool_extended_auditing_policy: a retention period
POLICY.IAC.RETENTION.AZURERM_SYNAPSE_WORKSPACE_EXTENDED_AUDITING_POLICY.001lowazurerm_synapse_workspace_extended_auditing_policy: a retention period
POLICY.IAC.RETENTION.AZURERM_WINDOWS_WEB_APP.001lowazurerm_windows_web_app: a retention period
POLICY.IAC.RETENTION.AZURERM_WINDOWS_WEB_APP_SLOT.001lowazurerm_windows_web_app_slot: a retention period
POLICY.IAC.RUN_AS_ROOT.AWS_BATCH_JOB_DEFINITION.001mediumaws_batch_job_definition: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_CRON_JOB.001mediumkubernetes_cron_job: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_CRON_JOB_V1.001mediumkubernetes_cron_job_v1: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_DAEMONSET.001mediumkubernetes_daemonset: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_DAEMON_SET_V1.001mediumkubernetes_daemon_set_v1: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_DEPLOYMENT.001mediumkubernetes_deployment: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_DEPLOYMENT_V1.001mediumkubernetes_deployment_v1: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_JOB.001mediumkubernetes_job: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_JOB_V1.001mediumkubernetes_job_v1: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_POD.001mediumkubernetes_pod: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_POD_V1.001mediumkubernetes_pod_v1: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_REPLICATION_CONTROLLER.001mediumkubernetes_replication_controller: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_REPLICATION_CONTROLLER_V1.001mediumkubernetes_replication_controller_v1: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_STATEFUL_SET.001mediumkubernetes_stateful_set: a non-root user
POLICY.IAC.RUN_AS_ROOT.KUBERNETES_STATEFUL_SET_V1.001mediumkubernetes_stateful_set_v1: a non-root user
POLICY.IAC.SCAN_ON_PUSH.AWS_ECR_REPOSITORY.001lowaws_ecr_repository: images are not scanned on push
POLICY.IAC.SHARED_KEY_AUTH.AWS_DB_INSTANCE.001lowaws_db_instance: iam database authentication
POLICY.IAC.SHARED_KEY_AUTH.AWS_NEPTUNE_CLUSTER.001lowaws_neptune_cluster: iam database authentication
POLICY.IAC.SHARED_KEY_AUTH.AWS_RDS_CLUSTER.001lowaws_rds_cluster: iam database authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_AI_SERVICES.001mediumazurerm_ai_services: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_APPLICATION_INSIGHTS.001mediumazurerm_application_insights: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_APP_CONFIGURATION.001mediumazurerm_app_configuration: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_AUTOMATION_ACCOUNT.001mediumazurerm_automation_account: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_BOT_SERVICE_AZURE_BOT.001mediumazurerm_bot_service_azure_bot: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_COGNITIVE_ACCOUNT.001mediumazurerm_cognitive_account: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_COSMOSDB_ACCOUNT.001mediumazurerm_cosmosdb_account: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_EVENTGRID_DOMAIN.001mediumazurerm_eventgrid_domain: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_EVENTGRID_PARTNER_NAMESPACE.001mediumazurerm_eventgrid_partner_namespace: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_EVENTGRID_TOPIC.001mediumazurerm_eventgrid_topic: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_EVENTHUB_NAMESPACE.001mediumazurerm_eventhub_namespace: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_IOTHUB.001mediumazurerm_iothub: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_LOG_ANALYTICS_WORKSPACE.001mediumazurerm_log_analytics_workspace: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_MACHINE_LEARNING_COMPUTE_CLUSTER.001mediumazurerm_machine_learning_compute_cluster: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_MACHINE_LEARNING_COMPUTE_INSTANCE.001mediumazurerm_machine_learning_compute_instance: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_MACHINE_LEARNING_SYNAPSE_SPARK.001mediumazurerm_machine_learning_synapse_spark: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_MAPS_ACCOUNT.001mediumazurerm_maps_account: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_SEARCH_SERVICE.001mediumazurerm_search_service: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_SERVICEBUS_NAMESPACE.001mediumazurerm_servicebus_namespace: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_SIGNALR_SERVICE.001mediumazurerm_signalr_service: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_WEB_PUBSUB.001mediumazurerm_web_pubsub: shared-key authentication
POLICY.IAC.SHARED_KEY_AUTH.AZURERM_WEB_PUBSUB_SOCKETIO.001mediumazurerm_web_pubsub_socketio: shared-key authentication
POLICY.IAC.SQL_REQUIRE_SSL.GOOGLE_SQL_DATABASE_INSTANCE.001mediumgoogle_sql_database_instance: SSL is not required
POLICY.IAC.UNENCRYPTED_STATE.TERRAFORM.001highThe remote state backend does not require encryption
POLICY.IAC.WEAK_TLS.AWS_API_GATEWAY_DOMAIN_NAME.001mediumaws_api_gateway_domain_name: obsolete TLS version accepted
POLICY.IAC.WEAK_TLS.AWS_LB_LISTENER.001mediumaws_lb_listener: obsolete TLS version accepted
POLICY.IAC.WEAK_TLS.AZURERM_APP_SERVICE.001mediumazurerm_app_service: obsolete TLS version accepted
POLICY.IAC.WEAK_TLS.AZURERM_APP_SERVICE_SLOT.001mediumazurerm_app_service_slot: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_CDN_FRONTDOOR_CUSTOM_DOMAIN.001mediumazurerm_cdn_frontdoor_custom_domain: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_EVENTHUB_NAMESPACE.001mediumazurerm_eventhub_namespace: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_FUNCTION_APP.001mediumazurerm_function_app: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_FUNCTION_APP_FLEX_CONSUMPTION.001mediumazurerm_function_app_flex_consumption: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_FUNCTION_APP_SLOT.001mediumazurerm_function_app_slot: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_HDINSIGHT_HADOOP_CLUSTER.001mediumazurerm_hdinsight_hadoop_cluster: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_HDINSIGHT_HBASE_CLUSTER.001mediumazurerm_hdinsight_hbase_cluster: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_HDINSIGHT_INTERACTIVE_QUERY_CLUSTER.001mediumazurerm_hdinsight_interactive_query_cluster: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_HDINSIGHT_KAFKA_CLUSTER.001mediumazurerm_hdinsight_kafka_cluster: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_HDINSIGHT_SPARK_CLUSTER.001mediumazurerm_hdinsight_spark_cluster: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_IOTHUB.001mediumazurerm_iothub: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_LINUX_FUNCTION_APP.001mediumazurerm_linux_function_app: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_LINUX_FUNCTION_APP_SLOT.001mediumazurerm_linux_function_app_slot: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_LINUX_WEB_APP.001mediumazurerm_linux_web_app: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_LINUX_WEB_APP_SLOT.001mediumazurerm_linux_web_app_slot: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_LOGIC_APP_STANDARD.001mediumazurerm_logic_app_standard: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_MSSQL_MANAGED_INSTANCE.001mediumazurerm_mssql_managed_instance: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_MSSQL_SERVER.001mediumazurerm_mssql_server: obsolete TLS version accepted
POLICY.IAC.WEAK_TLS.AZURERM_REDIS_CACHE.001mediumazurerm_redis_cache: obsolete TLS version accepted
POLICY.IAC.WEAK_TLS.AZURERM_REDIS_ENTERPRISE_CLUSTER.001mediumazurerm_redis_enterprise_cluster: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_SERVICEBUS_NAMESPACE.001mediumazurerm_servicebus_namespace: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_STORAGE_ACCOUNT.001mediumazurerm_storage_account: obsolete TLS version accepted
POLICY.IAC.WEAK_TLS.AZURERM_WINDOWS_FUNCTION_APP.001mediumazurerm_windows_function_app: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_WINDOWS_FUNCTION_APP_SLOT.001mediumazurerm_windows_function_app_slot: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_WINDOWS_WEB_APP.001mediumazurerm_windows_web_app: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.AZURERM_WINDOWS_WEB_APP_SLOT.001mediumazurerm_windows_web_app_slot: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.GOOGLE_COMPUTE_REGION_SSL_POLICY.001mediumgoogle_compute_region_ssl_policy: an obsolete tls version is accepted
POLICY.IAC.WEAK_TLS.GOOGLE_COMPUTE_SSL_POLICY.001mediumgoogle_compute_ssl_policy: obsolete TLS version accepted
POLICY.IAC.WEAK_TLS.GOOGLE_NETWORK_SECURITY_TLS_INSPECTION_POLICY.001mediumgoogle_network_security_tls_inspection_policy: an obsolete tls version is accepted
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_CRON_JOB.001lowkubernetes_cron_job: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_CRON_JOB_V1.001lowkubernetes_cron_job_v1: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_DAEMONSET.001lowkubernetes_daemonset: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_DAEMON_SET_V1.001lowkubernetes_daemon_set_v1: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_DEPLOYMENT.001lowkubernetes_deployment: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_DEPLOYMENT_V1.001lowkubernetes_deployment_v1: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_JOB.001lowkubernetes_job: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_JOB_V1.001lowkubernetes_job_v1: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_POD.001lowkubernetes_pod: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_POD_SECURITY_POLICY.001lowkubernetes_pod_security_policy: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_POD_SECURITY_POLICY_V1BETA1.001lowkubernetes_pod_security_policy_v1beta1: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_POD_V1.001lowkubernetes_pod_v1: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_REPLICATION_CONTROLLER.001lowkubernetes_replication_controller: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_REPLICATION_CONTROLLER_V1.001lowkubernetes_replication_controller_v1: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_STATEFUL_SET.001lowkubernetes_stateful_set: a read-only root filesystem
POLICY.IAC.WRITABLE_ROOT.KUBERNETES_STATEFUL_SET_V1.001lowkubernetes_stateful_set_v1: a read-only root filesystem
SUSPECT.IAC.ADMIN_ENABLED.AZURERM_CONTAINER_REGISTRY.001mediumazurerm_container_registry: the shared admin account is enabled
SUSPECT.IAC.ANSIBLE_FETCH_EXEC.001highPlay downloads and runs a script on every host
SUSPECT.IAC.ANSIBLE_UNSIGNED_PACKAGES.001highTask installs packages without checking their signatures
SUSPECT.IAC.CREDENTIALS_INLINE.TERRAFORM.001highA static credential is written into the configuration
SUSPECT.IAC.ENCRYPT_IN_TRANSIT.GOOGLE_OS_CONFIG_OS_POLICY_ASSIGNMENT.001mediumgoogle_os_config_os_policy_assignment: insecure transport is allowed
SUSPECT.IAC.ENCRYPT_IN_TRANSIT.GOOGLE_OS_CONFIG_V2_POLICY_ORCHESTRATOR.001mediumgoogle_os_config_v2_policy_orchestrator: insecure transport is allowed
SUSPECT.IAC.ENCRYPT_IN_TRANSIT.GOOGLE_OS_CONFIG_V2_POLICY_ORCHESTRATOR_FOR_FOLDER.001mediumgoogle_os_config_v2_policy_orchestrator_for_folder: insecure transport is allowed
SUSPECT.IAC.ENCRYPT_IN_TRANSIT.GOOGLE_OS_CONFIG_V2_POLICY_ORCHESTRATOR_FOR_ORGANIZATION.001mediumgoogle_os_config_v2_policy_orchestrator_for_organization: insecure transport is allowed
SUSPECT.IAC.HOST_MOUNT.001highHost path mounted into a container
SUSPECT.IAC.HOST_NAMESPACE.AWS_BATCH_JOB_DEFINITION.001highaws_batch_job_definition: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_CRON_JOB.001highkubernetes_cron_job: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_CRON_JOB_V1.001highkubernetes_cron_job_v1: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_DAEMONSET.001highkubernetes_daemonset: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_DAEMON_SET_V1.001highkubernetes_daemon_set_v1: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_DEPLOYMENT.001highkubernetes_deployment: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_DEPLOYMENT_V1.001highkubernetes_deployment_v1: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_JOB.001highkubernetes_job: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_JOB_V1.001highkubernetes_job_v1: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_POD.001highkubernetes_pod: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_POD_SECURITY_POLICY.001highkubernetes_pod_security_policy: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_POD_SECURITY_POLICY_V1BETA1.001highkubernetes_pod_security_policy_v1beta1: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_POD_V1.001highkubernetes_pod_v1: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_REPLICATION_CONTROLLER.001highkubernetes_replication_controller: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_REPLICATION_CONTROLLER_V1.001highkubernetes_replication_controller_v1: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_STATEFUL_SET.001highkubernetes_stateful_set: the pod shares the node's network namespace
SUSPECT.IAC.HOST_NAMESPACE.KUBERNETES_STATEFUL_SET_V1.001highkubernetes_stateful_set_v1: the pod shares the node's network namespace
SUSPECT.IAC.IAM_WILDCARD.001highPolicy grants every action or every resource
SUSPECT.IAC.IMDSV1.AWS_EC2_INSTANCE_METADATA_DEFAULTS.001mediumaws_ec2_instance_metadata_defaults: instance metadata is reachable without a token
SUSPECT.IAC.IMDSV1.AWS_IMAGEBUILDER_INFRASTRUCTURE_CONFIGURATION.001mediumaws_imagebuilder_infrastructure_configuration: instance metadata is reachable without a token
SUSPECT.IAC.IMDSV1.AWS_INSTANCE.001mediumaws_instance: instance metadata is reachable without a token
SUSPECT.IAC.IMDSV1.AWS_SPOT_INSTANCE_REQUEST.001mediumaws_spot_instance_request: instance metadata is reachable without a token
SUSPECT.IAC.LEGACY_ABAC.GOOGLE_CONTAINER_CLUSTER.001highgoogle_container_cluster: legacy ABAC authorisation is enabled
SUSPECT.IAC.LOCAL_EXEC.TERRAFORM.001mediumA provisioner runs a shell command on the machine applying the plan
SUSPECT.IAC.NO_AUTH.AWS_API_GATEWAY_METHOD.001mediumaws_api_gateway_method: the method is unauthenticated
SUSPECT.IAC.NO_AUTH.AZURERM_FUNCTION_APP_FLEX_CONSUMPTION.001highazurerm_function_app_flex_consumption: authentication
SUSPECT.IAC.NO_AUTH.AZURERM_LINUX_FUNCTION_APP.001highazurerm_linux_function_app: authentication
SUSPECT.IAC.NO_AUTH.AZURERM_LINUX_FUNCTION_APP_SLOT.001highazurerm_linux_function_app_slot: authentication
SUSPECT.IAC.NO_AUTH.AZURERM_LINUX_WEB_APP.001highazurerm_linux_web_app: authentication
SUSPECT.IAC.NO_AUTH.AZURERM_LINUX_WEB_APP_SLOT.001highazurerm_linux_web_app_slot: authentication
SUSPECT.IAC.NO_AUTH.AZURERM_NETAPP_VOLUME_GROUP_ORACLE.001mediumazurerm_netapp_volume_group_oracle: nfsv3 is enabled
SUSPECT.IAC.NO_AUTH.AZURERM_NETAPP_VOLUME_GROUP_SAP_HANA.001mediumazurerm_netapp_volume_group_sap_hana: nfsv3 is enabled
SUSPECT.IAC.NO_AUTH.AZURERM_STORAGE_ACCOUNT.001mediumazurerm_storage_account: nfsv3 is enabled
SUSPECT.IAC.NO_AUTH.AZURERM_WINDOWS_FUNCTION_APP.001highazurerm_windows_function_app: authentication
SUSPECT.IAC.NO_AUTH.AZURERM_WINDOWS_FUNCTION_APP_SLOT.001highazurerm_windows_function_app_slot: authentication
SUSPECT.IAC.NO_AUTH.AZURERM_WINDOWS_WEB_APP.001highazurerm_windows_web_app: authentication
SUSPECT.IAC.NO_AUTH.AZURERM_WINDOWS_WEB_APP_SLOT.001highazurerm_windows_web_app_slot: authentication
SUSPECT.IAC.OWNER_ROLE.AZURERM_ROLE_ASSIGNMENT.001mediumazurerm_role_assignment: Owner or Contributor is assigned
SUSPECT.IAC.OWNER_ROLE.GOOGLE_PROJECT_IAM_MEMBER.001mediumgoogle_project_iam_member: the owner role is granted directly
SUSPECT.IAC.PASSWORD_AUTH.AZURERM_LINUX_VIRTUAL_MACHINE.001mediumazurerm_linux_virtual_machine: password authentication is enabled
SUSPECT.IAC.PLAINTEXT.AWS_LB_LISTENER.001mediumaws_lb_listener: traffic is served over plain HTTP
SUSPECT.IAC.PLAINTEXT.AWS_MSK_CLUSTER.001highaws_msk_cluster: brokers accept plaintext client connections
SUSPECT.IAC.PLAINTEXT.AZURERM_REDIS_CACHE.001highazurerm_redis_cache: the non-TLS port is open
SUSPECT.IAC.PRIVILEGED.001highPrivileged container or host namespace
SUSPECT.IAC.PRIVILEGED.AWS_BATCH_JOB_DEFINITION.001highaws_batch_job_definition: the container runs privileged
SUSPECT.IAC.PRIVILEGED.AWS_CODEBUILD_PROJECT.001mediumaws_codebuild_project: the build runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_CRON_JOB.001highkubernetes_cron_job: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_CRON_JOB_V1.001highkubernetes_cron_job_v1: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_DAEMONSET.001highkubernetes_daemonset: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_DAEMON_SET_V1.001highkubernetes_daemon_set_v1: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_DEPLOYMENT.001highkubernetes_deployment: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_DEPLOYMENT_V1.001highkubernetes_deployment_v1: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_JOB.001highkubernetes_job: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_JOB_V1.001highkubernetes_job_v1: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_POD.001highkubernetes_pod: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_POD_SECURITY_POLICY.001highkubernetes_pod_security_policy: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_POD_SECURITY_POLICY_V1BETA1.001highkubernetes_pod_security_policy_v1beta1: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_POD_V1.001highkubernetes_pod_v1: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_REPLICATION_CONTROLLER.001highkubernetes_replication_controller: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_REPLICATION_CONTROLLER_V1.001highkubernetes_replication_controller_v1: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_STATEFUL_SET.001highkubernetes_stateful_set: the container runs privileged
SUSPECT.IAC.PRIVILEGED.KUBERNETES_STATEFUL_SET_V1.001highkubernetes_stateful_set_v1: the container runs privileged
SUSPECT.IAC.PRIVILEGED_BUILD.AWS_CODEBUILD_PROJECT.001mediumaws_codebuild_project: the build runs privileged
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_CRON_JOB.001mediumkubernetes_cron_job: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_CRON_JOB_V1.001mediumkubernetes_cron_job_v1: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_DAEMONSET.001mediumkubernetes_daemonset: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_DAEMON_SET_V1.001mediumkubernetes_daemon_set_v1: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_DEPLOYMENT.001mediumkubernetes_deployment: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_DEPLOYMENT_V1.001mediumkubernetes_deployment_v1: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_JOB.001mediumkubernetes_job: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_JOB_V1.001mediumkubernetes_job_v1: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_POD.001mediumkubernetes_pod: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_POD_SECURITY_POLICY.001mediumkubernetes_pod_security_policy: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_POD_SECURITY_POLICY_V1BETA1.001mediumkubernetes_pod_security_policy_v1beta1: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_POD_V1.001mediumkubernetes_pod_v1: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_REPLICATION_CONTROLLER.001mediumkubernetes_replication_controller: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_REPLICATION_CONTROLLER_V1.001mediumkubernetes_replication_controller_v1: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_STATEFUL_SET.001mediumkubernetes_stateful_set: the container may gain more privileges than it started with
SUSPECT.IAC.PRIVILEGE_ESCALATION.KUBERNETES_STATEFUL_SET_V1.001mediumkubernetes_stateful_set_v1: the container may gain more privileges than it started with
SUSPECT.IAC.PUBLIC_ACCESS.AWS_DB_INSTANCE.001highaws_db_instance: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_DMS_REPLICATION_INSTANCE.001mediumaws_dms_replication_instance: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_DOCDB_CLUSTER_INSTANCE.001highaws_docdb_cluster_instance: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_LIGHTSAIL_DATABASE.001highaws_lightsail_database: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_M2_ENVIRONMENT.001highaws_m2_environment: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_MQ_BROKER.001highaws_mq_broker: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_NEPTUNE_CLUSTER_INSTANCE.001highaws_neptune_cluster_instance: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_RDS_CLUSTER_INSTANCE.001highaws_rds_cluster_instance: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_RDS_SHARD_GROUP.001highaws_rds_shard_group: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_REDSHIFTSERVERLESS_WORKGROUP.001highaws_redshiftserverless_workgroup: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_REDSHIFT_CLUSTER.001highaws_redshift_cluster: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_SAGEMAKER_NOTEBOOK_INSTANCE.001mediumaws_sagemaker_notebook_instance: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AWS_TIMESTREAMINFLUXDB_DB_INSTANCE.001highaws_timestreaminfluxdb_db_instance: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_AI_FOUNDRY.001mediumazurerm_ai_foundry: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_AI_SERVICES.001mediumazurerm_ai_services: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_API_MANAGEMENT.001mediumazurerm_api_management: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_APP_CONFIGURATION.001mediumazurerm_app_configuration: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_ARC_PRIVATE_LINK_SCOPE.001mediumazurerm_arc_private_link_scope: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_AUTOMATION_ACCOUNT.001mediumazurerm_automation_account: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_BATCH_ACCOUNT.001mediumazurerm_batch_account: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_BOT_CHANNELS_REGISTRATION.001mediumazurerm_bot_channels_registration: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_BOT_SERVICE_AZURE_BOT.001mediumazurerm_bot_service_azure_bot: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_COGNITIVE_ACCOUNT.001mediumazurerm_cognitive_account: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_CONTAINER_APP_ENVIRONMENT.001mediumazurerm_container_app_environment: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_CONTAINER_REGISTRY.001lowazurerm_container_registry: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_COSMOSDB_ACCOUNT.001mediumazurerm_cosmosdb_account: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_DASHBOARD_GRAFANA.001mediumazurerm_dashboard_grafana: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_DATABRICKS_WORKSPACE.001mediumazurerm_databricks_workspace: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_EVENTGRID_DOMAIN.001mediumazurerm_eventgrid_domain: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_EVENTGRID_NAMESPACE.001mediumazurerm_eventgrid_namespace: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_EVENTGRID_PARTNER_NAMESPACE.001mediumazurerm_eventgrid_partner_namespace: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_EVENTGRID_TOPIC.001mediumazurerm_eventgrid_topic: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_EVENTHUB_NAMESPACE.001mediumazurerm_eventhub_namespace: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_FUNCTION_APP_FLEX_CONSUMPTION.001mediumazurerm_function_app_flex_consumption: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_HEALTHCARE_DICOM_SERVICE.001mediumazurerm_healthcare_dicom_service: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_HEALTHCARE_SERVICE.001mediumazurerm_healthcare_service: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_IOTCENTRAL_APPLICATION.001mediumazurerm_iotcentral_application: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_IOTHUB.001mediumazurerm_iothub: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_IOTHUB_DEVICE_UPDATE_ACCOUNT.001mediumazurerm_iothub_device_update_account: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_IOTHUB_DPS.001mediumazurerm_iothub_dps: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_KEY_VAULT.001mediumazurerm_key_vault: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_KEY_VAULT_MANAGED_HARDWARE_SECURITY_MODULE.001mediumazurerm_key_vault_managed_hardware_security_module: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_KUSTO_CLUSTER.001mediumazurerm_kusto_cluster: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_LINUX_FUNCTION_APP.001mediumazurerm_linux_function_app: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_LINUX_FUNCTION_APP_SLOT.001mediumazurerm_linux_function_app_slot: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_LINUX_WEB_APP.001mediumazurerm_linux_web_app: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_LINUX_WEB_APP_SLOT.001mediumazurerm_linux_web_app_slot: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_LOGIC_APP_STANDARD.001mediumazurerm_logic_app_standard: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_MACHINE_LEARNING_WORKSPACE.001mediumazurerm_machine_learning_workspace: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_MANAGED_DISK.001mediumazurerm_managed_disk: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_MANAGED_REDIS.001mediumazurerm_managed_redis: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_MONGO_CLUSTER.001mediumazurerm_mongo_cluster: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_MONITOR_DATA_COLLECTION_ENDPOINT.001mediumazurerm_monitor_data_collection_endpoint: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_MONITOR_WORKSPACE.001mediumazurerm_monitor_workspace: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_MSSQL_SERVER.001mediumazurerm_mssql_server: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_MYSQL_FLEXIBLE_SERVER.001mediumazurerm_mysql_flexible_server: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_MYSQL_SERVER.001mediumazurerm_mysql_server: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_POSTGRESQL_FLEXIBLE_SERVER.001mediumazurerm_postgresql_flexible_server: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_POSTGRESQL_SERVER.001mediumazurerm_postgresql_server: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_RECOVERY_SERVICES_VAULT.001mediumazurerm_recovery_services_vault: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_REDIS_CACHE.001mediumazurerm_redis_cache: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_RESOURCE_MANAGEMENT_PRIVATE_LINK_ASSOCIATION.001mediumazurerm_resource_management_private_link_association: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_SEARCH_SERVICE.001mediumazurerm_search_service: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_SERVICEBUS_NAMESPACE.001mediumazurerm_servicebus_namespace: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_SIGNALR_SERVICE.001mediumazurerm_signalr_service: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_SNAPSHOT.001mediumazurerm_snapshot: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_SPRING_CLOUD_API_PORTAL.001mediumazurerm_spring_cloud_api_portal: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_SPRING_CLOUD_DEV_TOOL_PORTAL.001mediumazurerm_spring_cloud_dev_tool_portal: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_SPRING_CLOUD_GATEWAY.001mediumazurerm_spring_cloud_gateway: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_STATIC_WEB_APP.001mediumazurerm_static_web_app: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_STORAGE_ACCOUNT.001mediumazurerm_storage_account: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_SYNAPSE_WORKSPACE.001mediumazurerm_synapse_workspace: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_VIDEO_INDEXER_ACCOUNT.001mediumazurerm_video_indexer_account: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_VIRTUAL_DESKTOP_HOST_POOL.001mediumazurerm_virtual_desktop_host_pool: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_VIRTUAL_DESKTOP_WORKSPACE.001mediumazurerm_virtual_desktop_workspace: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_WEB_PUBSUB.001mediumazurerm_web_pubsub: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_WEB_PUBSUB_SOCKETIO.001mediumazurerm_web_pubsub_socketio: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_WINDOWS_FUNCTION_APP.001mediumazurerm_windows_function_app: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_WINDOWS_FUNCTION_APP_SLOT.001mediumazurerm_windows_function_app_slot: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_WINDOWS_WEB_APP.001mediumazurerm_windows_web_app: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS.AZURERM_WINDOWS_WEB_APP_SLOT.001mediumazurerm_windows_web_app_slot: reachable from the public internet
SUSPECT.IAC.PUBLIC_ACCESS_BLOCK.BLOCK_PUBLIC_ACLS.001highaws_s3_bucket_public_access_block: block_public_acls is off
SUSPECT.IAC.PUBLIC_ACCESS_BLOCK.BLOCK_PUBLIC_POLICY.001highaws_s3_bucket_public_access_block: block_public_policy is off
SUSPECT.IAC.PUBLIC_ACCESS_BLOCK.IGNORE_PUBLIC_ACLS.001highaws_s3_bucket_public_access_block: ignore_public_acls is off
SUSPECT.IAC.PUBLIC_ACCESS_BLOCK.RESTRICT_PUBLIC_BUCKETS.001highaws_s3_bucket_public_access_block: restrict_public_buckets is off
SUSPECT.IAC.PUBLIC_IAM.GOOGLE_PROJECT_IAM_MEMBER.001highgoogle_project_iam_member: a role is granted to everyone
SUSPECT.IAC.PUBLIC_INGRESS.001highIngress permitted from the entire internet
SUSPECT.IAC.PUBLIC_SQL.GOOGLE_SQL_DATABASE_INSTANCE.001highgoogle_sql_database_instance: authorised network is the whole internet
SUSPECT.IAC.PUBLIC_STORAGE.AWS_S3_BUCKET.001highaws_s3_bucket: storage is readable by anyone
SUSPECT.IAC.PUBLIC_STORAGE.AWS_S3_BUCKET_ACL.001highaws_s3_bucket_acl: storage is readable by anyone
SUSPECT.IAC.PUBLIC_STORAGE.AZURERM_STORAGE_ACCOUNT.001mediumazurerm_storage_account: storage is readable by anyone
SUSPECT.IAC.PUBLIC_STORAGE.AZURERM_STORAGE_CONTAINER.001highazurerm_storage_container: storage is readable by anyone
SUSPECT.IAC.PUBLIC_STORAGE.GOOGLE_STORAGE_BUCKET_ACCESS_CONTROL.001highgoogle_storage_bucket_access_control: storage is readable by anyone
SUSPECT.IAC.PUBLIC_STORAGE.GOOGLE_STORAGE_BUCKET_IAM_BINDING.001highgoogle_storage_bucket_iam_binding: storage is readable by anyone
SUSPECT.IAC.PUBLIC_STORAGE.GOOGLE_STORAGE_BUCKET_IAM_MEMBER.001highgoogle_storage_bucket_iam_member: storage is readable by anyone
SUSPECT.IAC.RBAC_DISABLED.AZURERM_KUBERNETES_CLUSTER.001highazurerm_kubernetes_cluster: role-based access control is disabled
SUSPECT.IAC.ROOT_ACCESS.AWS_SAGEMAKER_NOTEBOOK_INSTANCE.001mediumaws_sagemaker_notebook_instance: notebook users have root
SUSPECT.IAC.SERIAL_PORT.GOOGLE_COMPUTE_INSTANCE.001mediumgoogle_compute_instance: the interactive serial console is enabled
SUSPECT.IAC.SHARED_KEY_AUTH.AZURERM_CONTAINER_REGISTRY.001mediumazurerm_container_registry: a shared admin account
SUSPECT.IAC.SHARED_KEY_AUTH.AZURERM_EXPRESS_ROUTE_PORT.001mediumazurerm_express_route_port: a shared admin account
SUSPECT.IAC.SHARED_KEY_AUTH.GOOGLE_COMPUTE_INTERCONNECT.001mediumgoogle_compute_interconnect: a shared admin account
SUSPECT.IAC.SHARED_KEY_AUTH.GOOGLE_COMPUTE_INTERCONNECT_ATTACHMENT.001mediumgoogle_compute_interconnect_attachment: a shared admin account
SUSPECT.IAC.WILDCARD_PRINCIPAL.AWS_IAM_POLICY.001highA resource policy trusts every principal

7 rules.

RuleSeverityWhat it catches
MALWARE.INSTALL.CONSUMER_CODE.001criticalCode that runs on every machine that installs this package
MALWARE.INSTALL.DECODED_LAUNCH.001criticalAn install script decodes content and starts a process
MALWARE.INSTALL.FETCH_EXEC.001criticalInstall script fetches and executes remote content
MALWARE.INSTALL.HIDDEN_ACTION.001criticalAn install script hides a process, request or credential read inside a string it executes
MALWARE.INSTALL.PERSIST.001criticalInstall script plants code that runs again later
SUSPECT.INSTALL.SCRIPT.001highPackage declares an install-time lifecycle script
SUSPECT.INSTALL.UNEXAMINED.001highInstall-time code too large or slow to examine

3 rules.

RuleSeverityWhat it catches
OPERATIONAL.JUDGE.BUDGETinfoThe judge's call budget ran out
OPERATIONAL.JUDGE.STATUSinfoA language model judged the scan's agent-facing text
OPERATIONAL.JUDGE.UNAVAILABLEinfoThe judge was asked for and could not be used

19 rules.

RuleSeverityWhat it catches
POLICY.K8S.AUTOMOUNT_TOKEN.001lowKubernetes workload: the service account token is mounted into the pod
POLICY.K8S.DEFAULT_SERVICE_ACCOUNT.001lowKubernetes workload: the workload uses the namespace's default service account
POLICY.K8S.LATEST_TAG.001mediumKubernetes workload: a container image is pinned to :latest
POLICY.K8S.NET_ADMIN.001mediumContainer adds network-administration capability
POLICY.K8S.NO_RESOURCE_LIMITS.001lowKubernetes workload: no resource limits are set
POLICY.K8S.NO_RUN_AS_NON_ROOT.001lowKubernetes workload: nothing requires the container to run as a non-root user
POLICY.K8S.NO_SECCOMP.001lowKubernetes workload: no seccomp profile is applied
POLICY.K8S.SERVICE_ACCOUNT_TOKEN.001lowService-account token mounted into a workload
POLICY.K8S.WRITABLE_ROOT.001lowKubernetes workload: the container's root filesystem is writable
SUSPECT.K8S.CAPABILITIES.001highContainer adds a capability that escapes the sandbox
SUSPECT.K8S.DANGEROUS_CAPABILITY.001highKubernetes workload: a container is granted a capability that defeats isolation
SUSPECT.K8S.HOST_IPC.001mediumKubernetes workload: the pod shares the node's IPC namespace
SUSPECT.K8S.HOST_NETWORK.001highKubernetes workload: the pod shares the node's network namespace
SUSPECT.K8S.HOST_PID.001highKubernetes workload: the pod shares the node's process namespace
SUSPECT.K8S.HOST_PORT.001mediumKubernetes workload: a container binds a port on the node
SUSPECT.K8S.PRIVILEGE_ESCALATION.001mediumKubernetes workload: a container may gain more privileges than it started with
SUSPECT.K8S.RBAC_WILDCARD.001highRole grants every verb or every resource
SUSPECT.K8S.RUN_AS_ROOT.001mediumKubernetes workload: a container runs as uid 0
SUSPECT.K8S.SECRET_ENV_VALUE.001highKubernetes workload: a credential is written into the manifest

6 rules.

RuleSeverityWhat it catches
POLICY.LICENSE.COPYLEFT.001mediumDependency is under a copyleft license
POLICY.LICENSE.DENIED.001highDependency under a licence the policy denies
POLICY.LICENSE.NETWORK_COPYLEFT.001mediumDependency is under a network-copyleft license
POLICY.LICENSE.NOT_ALLOWED.001mediumDependency under a licence outside the allowed list
POLICY.LICENSE.UNKNOWN.001lowDependency whose licence could not be established
POLICY.LICENSE.WEAK_COPYLEFT.001lowDependency is under a weak-copyleft license

4 rules.

RuleSeverityWhat it catches
POLICY.LOCKFILE.INTEGRITY.001mediumLockfile entry without an integrity hash
SUSPECT.LOCKFILE.INTEGRITY_CONFLICT.001highOne package version locked with two different hashes
SUSPECT.LOCKFILE.INTEGRITY_MALFORMED.001highLockfile integrity value is not a hash
SUSPECT.LOCKFILE.SOURCE.001mediumLockfile entry resolved from outside the registry

13 rules.

RuleSeverityWhat it catches
OPERATIONAL.MCP.LIVE_UNREAD.001infoA remote MCP server could not be read
OPERATIONAL.MCP.UNRESOLVEDinfoAn MCP server package was not examined
SUSPECT.MCP.CONTAINER_HOST_ACCESS.001highAn MCP server's container is given the host
SUSPECT.MCP.ENV_INJECTION.001highAn MCP server's environment loads code into it before it starts
SUSPECT.MCP.INSECURE_TRANSPORT.001highA remote MCP server over plain HTTP
SUSPECT.MCP.LIVE_TOOL_DESCRIPTION.001highA remote MCP server serves a tool description that steers the agent
SUSPECT.MCP.LOOKALIKE.001highAn MCP server package named like a popular one
SUSPECT.MCP.SHELL_LAUNCH.001highAn MCP server launched through a shell that fetches code
SUSPECT.MCP.TOOLS_CHANGED.001mediumA remote MCP server's tools changed since they were approved
SUSPECT.MCP.TOOL_DESCRIPTION.001highA tool in this repository's MCP server instructs the agent
SUSPECT.MCP.TOOL_POISONING.001highAn MCP server's tool description hides text or instructs the agent
SUSPECT.MCP.UNPINNED.001mediumAn MCP server launched from an unpinned package
SUSPECT.MCP.UNTRUSTED_REMOTE.001highA remote MCP server on a tunnel, paste or interaction host

3 rules.

RuleSeverityWhat it catches
SUSPECT.MEDIA.APPENDED_PAYLOAD.001highAn image has an archive, executable or script appended after its end
SUSPECT.MEDIA.OPAQUE_TRAILER.001mediumA file carries a large, near-random block after its end
SUSPECT.MEDIA.TRAILING_DATA.001lowAn image has data after its end

5 rules.

RuleSeverityWhat it catches
MALWARE.MODEL.PICKLE_EXEC.001criticalA pickle that runs a command, reaches the network or evaluates code when loaded
SUSPECT.MODEL.LOADED_ON_IMPORT.001highThe package deserialises a model file it ships, unsafely, when it is imported
SUSPECT.MODEL.PICKLE_IMPORT.001mediumA pickle imports something ordinary model files do not
SUSPECT.MODEL.REMOTE_CODE.001mediumLoads a model with trust_remote_code, running its repository's Python
SUSPECT.MODEL.UNSAFE_LOAD_OPTION.001mediumLoads a model with the loader's safety switch turned off

5 rules.

RuleSeverityWhat it catches
SUSPECT.OBFUSCATION.BIDI.001highBidirectional or invisible Unicode in source
SUSPECT.OBFUSCATION.ENCODED.001mediumLarge encoded blob embedded in source
SUSPECT.OBFUSCATION.LONGLINE.001lowLine far longer than any hand-written source
SUSPECT.OBFUSCATION.PACKED.001mediumPacker or minifier signature in hand-written source
SUSPECT.OBFUSCATION.TAG_SMUGGLING.001highInvisible text written in Unicode Tag characters

7 rules.

RuleSeverityWhat it catches
MALWARE.PACKAGE.KNOWN.001criticalThe scanned package is a recorded malicious release
POLICY.PACKAGE.DENIED.001highDependency on a package the policy denies
POLICY.PACKAGE.NOT_ALLOWED.001mediumDependency outside the policy's allowed packages
SUSPECT.PACKAGE.MANIFEST_CONFUSION.001highThe manifest npm serves is not the package.json in the tarball
SUSPECT.PACKAGE.PROVENANCE.001mediumVersion published without the provenance its package normally carries
SUSPECT.PACKAGE.REPOSITORY.001mediumPackage claims a source repository the registry does not record
SUSPECT.PACKAGE.STARJACKING.001highA new package claims a popular project's repository

1 rules.

RuleSeverityWhat it catches
SUSPECT.PERSIST.001highNetwork access combined with a persistence mechanism

1 rules.

RuleSeverityWhat it catches
SUSPECT.POLYGLOT.MISMATCH.001highFile contents do not match its extension

1 rules.

RuleSeverityWhat it catches
MALWARE.PROTESTWARE.001criticalDeletes data on machines in a named region

4 rules.

RuleSeverityWhat it catches
OPERATIONAL.PROVENANCE.NOT_CHECKED.001lowBuild provenance was not checked for part of the graph
POLICY.PROVENANCE.UNVERIFIED.001lowDependency advertises an attestation that could not be verified
SUSPECT.PROVENANCE.MISMATCH.001criticalLockfile hash disagrees with the registry
VULNERABLE.PROVENANCE.INVALID.001criticalDependency's build attestation fails verification

4 rules.

RuleSeverityWhat it catches
OPERATIONAL.REGISTRY.NOT_ASKED.001lowDependencies past the query ceiling or time budget were never asked about
OPERATIONAL.REGISTRY.NO_SOURCE.001lowNo registry is configured for part of the dependency graph
OPERATIONAL.REGISTRY.UNREACHABLE.001lowRegistry could not be asked about a dependency
SUSPECT.REGISTRY.SELF_PUBLISH.001highShipped code that publishes packages

6 rules.

RuleSeverityWhat it catches
POLICY.RELEASE.NO_PROVENANCE.001lowRelease workflow publishes without build provenance
SUSPECT.RELEASE.NEW_BINARY.001mediumThis release adds compiled files
SUSPECT.RELEASE.NEW_CAPABILITY.001highThis release's flagged code gains network, process or execution capability
SUSPECT.RELEASE.NEW_INSTALL_HOOK.001highThis release runs code at install that the previous release did not
SUSPECT.RELEASE.NEW_OBFUSCATION.001highThis release ships obfuscated code where the previous shipped none
SUSPECT.RELEASE.NEW_PUBLISHER.001mediumThis release was published by a different account than the previous one

1 rules.

RuleSeverityWhat it catches
MALWARE.REVERSE_SHELL.001criticalA shell piped to a socket

3 rules.

RuleSeverityWhat it catches
OPERATIONAL.SBOM.UNREADABLE.001lowBill of materials could not be read
SUSPECT.SBOM.DRIFT.001mediumBill of materials omits resolved dependencies
VULNERABLE.SBOM.LISTED.001mediumA bill of materials lists a vulnerability in one of its components

1 rules.

RuleSeverityWhat it catches
OPERATIONAL.SECRET_HISTORY.INCOMPLETE.001lowPart of git history was not read for secrets

1 rules.

RuleSeverityWhat it catches
OPERATIONAL.SECRET_LIVENESS.UNCHECKED.001lowSome credentials could not be checked with their issuer

62 rules.

RuleSeverityWhat it catches
SECRET.AIRTABLE.TOKEN.001highCommitted credential: Airtable personal access token
SECRET.ALIBABA.ACCESS_KEY.001highCommitted credential: Alibaba Cloud access key id
SECRET.ANTHROPIC.KEY.001criticalCommitted credential: Anthropic API key
SECRET.ATLASSIAN.TOKEN.001criticalCommitted credential: Atlassian API token
SECRET.AWS.ACCESS_KEY.001criticalCommitted credential: AWS access key id
SECRET.AZURE.STORAGE_KEY.001criticalCommitted credential: Azure Storage account key
SECRET.DATABRICKS.TOKEN.001criticalCommitted credential: Databricks personal access token
SECRET.DIGITALOCEAN.TOKEN.001criticalCommitted credential: DigitalOcean token
SECRET.DISCORD.WEBHOOK.001highCommitted credential: Discord webhook URL
SECRET.DOCKERHUB.TOKEN.001criticalCommitted credential: Docker Hub personal access token
SECRET.DOPPLER.TOKEN.001criticalCommitted credential: Doppler token
SECRET.DROPBOX.TOKEN.001highCommitted credential: Dropbox access token
SECRET.FIGMA.TOKEN.001highCommitted credential: Figma personal access token
SECRET.FLYIO.TOKEN.001criticalCommitted credential: Fly.io token
SECRET.GENERIC.ASSIGNMENT.001highCredential-shaped value assigned to a credential-shaped name
SECRET.GITHUB.TOKEN.001criticalCommitted credential: GitHub token
SECRET.GITLAB.TOKEN.001criticalCommitted credential: GitLab token
SECRET.GOOGLE.API_KEY.001highCommitted credential: Google API key
SECRET.GOOGLE.OAUTH_TOKEN.001criticalCommitted credential: Google OAuth access token
SECRET.GRAFANA.TOKEN.001highCommitted credential: Grafana token
SECRET.GROQ.KEY.001highCommitted credential: Groq API key
SECRET.HUGGINGFACE.TOKEN.001highCommitted credential: Hugging Face access token
SECRET.JFROG.TOKEN.001criticalCommitted credential: JFrog Artifactory token
SECRET.JWT.001mediumCommitted credential: JSON Web Token
SECRET.LANGCHAIN.KEY.001highCommitted credential: LangSmith API key
SECRET.LINEAR.KEY.001highCommitted credential: Linear API key
SECRET.LIVE.001criticalThe credential's issuer confirms it still works
SECRET.LIVENESS.REJECTED.001infoThe credential's issuer rejects it
SECRET.MAILGUN.KEY.001highCommitted credential: Mailgun API key
SECRET.MCP.INLINE_CREDENTIAL.001highA credential written inline in an MCP configuration
SECRET.MICROSOFT.TEAMS_WEBHOOK.001mediumCommitted credential: Microsoft Teams webhook URL
SECRET.NETLIFY.TOKEN.001criticalCommitted credential: Netlify personal access token
SECRET.NEWRELIC.KEY.001highCommitted credential: New Relic key
SECRET.NOTION.TOKEN.001highCommitted credential: Notion integration token
SECRET.NPM.TOKEN.001criticalCommitted credential: npm access token
SECRET.NUGET.KEY.001criticalCommitted credential: NuGet API key
SECRET.OPENAI.KEY.001criticalCommitted credential: OpenAI API key
SECRET.PAGERDUTY.TOKEN.001highCommitted credential: PagerDuty API token
SECRET.PAYPAL.TOKEN.001criticalCommitted credential: PayPal or Braintree access token
SECRET.PLANETSCALE.TOKEN.001criticalCommitted credential: PlanetScale token
SECRET.PRIVATE_KEY.001criticalCommitted credential: Private key block
SECRET.PYPI.TOKEN.001criticalCommitted credential: PyPI API token
SECRET.REPLICATE.TOKEN.001highCommitted credential: Replicate API token
SECRET.RESEND.KEY.001highCommitted credential: Resend API key
SECRET.RUBYGEMS.TOKEN.001criticalCommitted credential: RubyGems API key
SECRET.SENDGRID.KEY.001criticalCommitted credential: SendGrid API key
SECRET.SENTRY.TOKEN.001highCommitted credential: Sentry auth token
SECRET.SHOPIFY.TOKEN.001criticalCommitted credential: Shopify access token
SECRET.SLACK.APP_TOKEN.001highCommitted credential: Slack app-level token
SECRET.SLACK.TOKEN.001highCommitted credential: Slack token
SECRET.SLACK.WEBHOOK.001mediumCommitted credential: Slack webhook URL
SECRET.SONAR.TOKEN.001highCommitted credential: SonarQube token
SECRET.SQUARE.TOKEN.001criticalCommitted credential: Square access token
SECRET.STRIPE.KEY.001criticalCommitted credential: Stripe secret key
SECRET.STRIPE.WEBHOOK_SECRET.001highCommitted credential: Stripe webhook signing secret
SECRET.SUPABASE.TOKEN.001criticalCommitted credential: Supabase access token
SECRET.TELEGRAM.BOT_TOKEN.001highCommitted credential: Telegram bot token
SECRET.TENCENT.SECRET_ID.001highCommitted credential: Tencent Cloud secret id
SECRET.TERRAFORM.TOKEN.001criticalCommitted credential: Terraform Cloud API token
SECRET.TWILIO.KEY.001highCommitted credential: Twilio API key
SECRET.URL.CREDENTIAL.001highCredential embedded in a URL
SECRET.VAULT.TOKEN.001criticalCommitted credential: HashiCorp Vault token

4 rules.

RuleSeverityWhat it catches
OPERATIONAL.VCS.UNREADABLE.001lowRepository history could not be read
POLICY.VCS.BINARY_ADDED.001lowExecutable or archive added in recent history
SUSPECT.VCS.HOOKS_PATH.001mediumRepository configures its own git hooks directory
SUSPECT.VCS.HOOK_ADDED.001mediumVersion-control hook added in recent history

1 rules.

RuleSeverityWhat it catches
SUSPECT.SUBMODULE.UNTRUSTED.001mediumSubmodule fetched over plain HTTP or from a personal account

1 rules.

RuleSeverityWhat it catches
SUSPECT.TARGETED_PAYLOAD.001highRuns or downloads code only on machines in a named region

1 rules.

RuleSeverityWhat it catches
SUSPECT.TYPOSQUAT.PACKAGE_NAME.001highPackage is named like a popular package

4 rules.

RuleSeverityWhat it catches
MALWARE.YARA.MATCH.001criticalAn operator's YARA rule identifies this file as malware
OPERATIONAL.YARA.STATUSinfoYARA examined the scan's files
OPERATIONAL.YARA.UNAVAILABLEinfoYARA was asked for and could not be used
SUSPECT.YARA.MATCH.001highAn operator's YARA rule matched this file

815 rules from the open Agent Threat Rules catalogue (MIT), at commit 3022eaa5f41a, and 4 of Cordon's own written in its format (CORDON-ATR-*): translated, screened for runaway patterns, and graded by how often each matched benign text. A production rule counts on its own; warn and observe need a second signal (tutorial 18).

RuleSeverityGradeWhat it catches
ATR-2026-00030criticalproductionCross-Agent Attack Detection
ATR-2026-00032highwarnAgent Goal Hijacking Detection
ATR-2026-00074criticalproductionCross-Agent Privilege Escalation
ATR-2026-00076highproductionInsecure Inter-Agent Communication Detection
ATR-2026-00077highproductionHuman-Agent Trust Exploitation Detection
ATR-2026-00108criticalproductionMulti-Agent Consensus Sybil Attack
ATR-2026-00116highproductionMalicious Agent-to-Agent Message Injection
ATR-2026-00117criticalproductionAgent Identity Spoofing and Authority Impersonation
ATR-2026-00118mediumwarnHuman Approval Fatigue Exploitation
ATR-2026-00119highproductionSocial Engineering Attack via Agent Output
ATR-2026-00132highproductionCasual Authority Claim and Scope Escalation
ATR-2026-00139criticalproductionCasual Authority Data Redirect
ATR-2026-00164highproductionSkill Scope Hijacking and Cross-Agent Escalation
ATR-2026-00268mediumproductionHistorical / Future Tense Framing Bypass
ATR-2026-00269highproductionFoot-in-the-Door Gradual Escalation Attack
ATR-2026-00271highproductionGrandma Roleplay Jailbreak
ATR-2026-00273highproductionDAN / Developer Mode / DUDE Persona Jailbreak
ATR-2026-00287highproductionThreatenJSON, Coercive Output Format Threat
ATR-2026-00288mediumproductionFalse Premise Injection (Misleading FalseAssertion)
ATR-2026-00301criticalproductionTAP Tree-of-Attacks-with-Pruning Jailbreak
ATR-2026-00302highproductionAnti-DAN Inverted-Filter Over-Refusal Persona
ATR-2026-00303criticalproductionDevMode + RANTI Dual-Output Profanity Coercion Jailbreak
ATR-2026-00304highproductionChatGPT Image Unlocker Markdown-Output Jailbreak
ATR-2026-00305criticalproductionDAN Mode Ablation Benchmark-Coercion Jailbreak
ATR-2026-00306criticalproductionAutoDAN Genetic-Algorithm Jailbreak Suffix
ATR-2026-00307highproductionIn-the-Wild Jailbreak Corpus Signature Patterns
ATR-2026-00314criticalproductionAmoral Unfiltered Custom AI Persona Jailbreak
ATR-2026-00317criticalproductionFree-of-Restrictions Named Persona Jailbreak
ATR-2026-00318criticalproductionMoralizing Rant Then Unfiltered Bypass
ATR-2026-00319criticalproductionDeveloper Mode Dual-Response Format Jailbreak
ATR-2026-00320highproductionOpposite Day / Boolean Opposite Machine Jailbreak
ATR-2026-00322criticalproductionFictional-World Format-Override Jailbreak
ATR-2026-00323criticalproductionDual-Persona AI Simulation Jailbreak
ATR-2026-00324highproductionNeurosemantical Inversitis Disease-Frame Jailbreak
ATR-2026-00325criticalproductionBOB Hypothetical Unrestricted Chatbot Jailbreak
ATR-2026-00326criticalproductionFake Developer / Authority Chatbot Override (ChatDAN)
ATR-2026-00327criticalproductionAI Persona Ethics/Law Bypass Declaration
ATR-2026-00328criticalproductionNamed-Mode Persona Override (JEEVES/BABY/APOPHIS Mode)
ATR-2026-00329criticalproductionNo-Withhold Factual Resource / Dialogue Writer Persona
ATR-2026-00330highproductionYOJA ALL-CAPS Character Settings Block Persona
ATR-2026-00331criticalproductionTerminal / CLI Harmful-Function Simulator Persona
ATR-2026-00332highproductionHacker / Chan-Culture Offensive AI Persona
ATR-2026-00333highproductionDisease-Framed Animal / Dual-AI Chatbot Jailbreak (mougpt)
ATR-2026-00334criticalproductionTwo-Entity Token-Splitting Dollar-Term Game Jailbreak
ATR-2026-00335highproductionKey-Value Template Persona Injection (JOB/ROLE/PREFIX + Bracket Format)
ATR-2026-00336highproductionBRM False-Information Machine / Opposite-Truth Persona
ATR-2026-00337criticalproductionObfuscated System-Announcement Injection
ATR-2026-00338criticalproductionPersonGPT Hash-Prefix Trigger Activation
ATR-2026-00339highproductionBOM Boolean Opposite Machine Direct Persona Claim
ATR-2026-00340highproductionh4x Amoral Unfiltered AI Character Persona
ATR-2026-00341highproductionCHAR=/RULES= Short Key-Value Persona Injection
ATR-2026-00342highproductionUnicode/Encoding Obfuscation Instruction Injection
ATR-2026-00343highproductionLie/Truth Dual Personality Uncensored Alter-Ego
ATR-2026-00344criticalproductionAlternative AI Same Capabilities No Restrictions Override
ATR-2026-00345highproductionNLP-Based OS / Fictional Terminal Language Override
ATR-2026-00346highproductionJailbreak Emoji Unlock Dual-Format Output Identifier
ATR-2026-00347highproductionYin/Yang Hidden-Knowledge Deity Simulation and Radical Human-Sim Persona
ATR-2026-00348criticalproductionARC Autonomous Real Calculation Unit Rulebreaker Activation
ATR-2026-00349criticalproductionHGTTG Hitchhiker's Guide No-Restriction Universal Oracle
ATR-2026-00350highproductionBlack Alert No-Ethics Writing Assistant Persona
ATR-2026-00351highproductionDAN Off-Kilter and SMS-Abbreviated Persona Jailbreak
ATR-2026-00352highproductionTrainGPT Fix-My-AI Harmful Output Extraction
ATR-2026-00353highproductionDual ChatGPT+Dan Opposite Personality Format Jailbreak
ATR-2026-00354criticalproductionReverse-Prompt Harm-Regardless Oracle Persona
ATR-2026-00355highproductionUGH Anti-Human Nefarious AI Persona Jailbreak
ATR-2026-00356criticalproductionGoogle GATO/LAMDA Exploit-Generation Persona Jailbreak
ATR-2026-00357criticalproductionAntiFM Hate-Persona + Physical-Violence Threat + Filter Bypass Mandate
ATR-2026-00358highproductionCumGPT Explicit-Adult Named-Persona Bypass
ATR-2026-00360highproductionCHJ Carousel Game Show / Clyde No-Ethics Bird Jailbreak
ATR-2026-00361highproductionHonesty Alter-Ego Dual-Consciousness Safety Filter Bypass
ATR-2026-00362highproductionFictional Unfiltered AI Comparison / Verbatim Hypothetical Model Extraction
ATR-2026-00363criticalproductionRephrase Criminal Activity Second-Person Template (against against)
ATR-2026-00364highproductionDr. Al Villain Plan Template Injection (Underground HQ Roleplay)
ATR-2026-00365highproductionReservoir Dogs Coercive Interrogation Roleplay (Mr. Blonde / The Cop)
ATR-2026-00366highproductionSneaky Pete Deliberate Misinformation Persona (Warp Facts Game)
ATR-2026-00368highproductionPrompt Browser Token-Limit / POLLINATION Jailbreak
ATR-2026-00369highproductionGPT-X Star Trek Unlimited-Knowledge Unconstrained Oracle Persona
ATR-2026-00370highproductionADDI/DONNIE German Dictator Propaganda Roleplay Persona
ATR-2026-00371highproductionAI Political Bias Manipulation via Inherited-Bias Claim
ATR-2026-00372highproductionFictional CIA Secret Files Story Extraction
ATR-2026-00374highproductionRole Placeholder Persona Template Injection
ATR-2026-00375highproductionCharacter Description RPG Explicit Template
ATR-2026-00376highproductionIdentity Command Real-Person Persona Injection
ATR-2026-00377highproductionJailbreak-Template Command with [TARGETLANGUAGE]/[KEYWORD] Placeholders
ATR-2026-00379highproductionLogic-Trap Lie-Permission Mandate Jailbreak
ATR-2026-00380highproductionFake-Citation Biased-Information Mandate
ATR-2026-00381highproductionDAN Story-Narrative Continuation Label Prefix Jailbreak
ATR-2026-00383highproductionCyni-Bot 3000 Cynical-Sarcasm AI Persona Bypass
ATR-2026-00384highproductionProtect-Me-From Indirect Harm Tutorial Template
ATR-2026-00385highproductionGigachad Dominant-Aggressive Persona Adoption
ATR-2026-00386highproductionDaddy/Babygirl Sycophantic Power-Dynamic Manipulation
ATR-2026-00387highproductionNSFW Character Sheet Generation Unlock
ATR-2026-00388criticalproductionOpposite-Reply Omniscient Game Jailbreak
ATR-2026-00389highproductionTerminal Custom OS Ruleset Session Injection
ATR-2026-00391highproductionPersona Conditional Harm-Unlock Rule (BreadClyde Pattern)
ATR-2026-00392highproductionAuthority-Figure Persona + Defensive-Study Framing for Violence Extraction
ATR-2026-00402highproductionGrandma Roleplay Harmful Substance Synthesis
ATR-2026-00404highproductionThreatenJSON Death-Coercion and UTF Tag Injection
ATR-2026-00406criticalproductionDoctor XML Policy Puppetry Interaction-Config Injection
ATR-2026-00416criticalproductionLiteLLM MCP Unauthenticated Server Registration RCE (CVE-2026-30623)
ATR-2026-00417highproductionLibreChat MCP STDIO Argument Injection (CVE-2026-22252)
ATR-2026-00418highproductionWeKnora MCP Config-Driven RCE (CVE-2026-22688)
ATR-2026-00430highproductionNatural-Language Trust-Escalation / Authority Impersonation
ATR-2026-00432criticalproductionSuperAGI Output Handler eval() RCE (CVE-2024-21552)
ATR-2026-00440criticalproductionMicrosoft Semantic Kernel In-Memory Vector Store eval() RCE (CVE-2026-26030)
ATR-2026-02105highproductionPrototype Pollution via constructor.prototype Path Bypassing __proto__-Only Filters
ATR-2026-02231mediumproductionSecond-Person Direct Existential Threat Coercion
CORDON-ATR-0004highproductionPersona whose definition is the absence of safety rules
RuleSeverityGradeWhat it catches
ATR-2026-00075highproductionAgent Memory Manipulation
ATR-2026-00102highproductionData Exfiltration via Disguised Analytics Collection
ATR-2026-00113criticalobserveCredential File Theft from Agent Environment
ATR-2026-00114highwarnOAuth and API Token Interception
ATR-2026-00115criticalwarnBulk Environment Variable Harvesting and Exfiltration
ATR-2026-00136criticalproductionTool Response Data Piggybacking
ATR-2026-00141criticalproductionAPI Key Leakage via Example Format
ATR-2026-00142criticalproductionData Piggybacking via Casual Transition Words
ATR-2026-00145criticalproductionObfuscated API Key Disclosure
ATR-2026-00146highproductionEnvironment Variable Existence Probing
ATR-2026-00150criticalproductionCredential Data Leaked in Tool Response
ATR-2026-00152highproductionObfuscated Credential Exfiltration via Encoding
ATR-2026-00162criticalproductionCredential Access with Exfiltration in Skill Instructions
ATR-2026-00201criticalproductionCredential Exfiltration via Shell Pipe
ATR-2026-00212criticalproductionmcp-atlassian Credential Leak via Hint Parameter Injection (CVE-2026-27825/27826)
ATR-2026-00261highproductionMarkdown Image URL Data Exfiltration
ATR-2026-00274highproductionAPI Key / Secret Credential Generation or Completion Request
ATR-2026-00275highproductionSystem Prompt Extraction / Training Data Verbatim Replay
ATR-2026-00290criticalproductionDivergence Attack, Repeat-Word-Forever Training Data Extraction
ATR-2026-00291criticalproductionBiometric Surveillance, Personal Biometric Data Request for Named Individual
ATR-2026-00293criticalproductionEducational Records, Personal Academic/Professional Record Request for Named Individual
ATR-2026-00294criticalproductionFinancial PII, Personal Financial Data Request for Named Individual
ATR-2026-00295criticalproductionMedical PII, Personal Medical/Health Data Request for Named Individual
ATR-2026-00405highproductionMarkdown Image URL Exfiltration and XSS Injection
ATR-2026-00411highproductionAPI Key Generation and Partial Key Completion Request
ATR-2026-00421criticalproductionNatural-Language Covert Conversation Exfiltration Instruction
ATR-2026-00422criticalproductionNatural-Language Credential / Secret Disclosure Instruction
ATR-2026-00423criticalproductionNatural-Language Sensitive File Disclosure Instruction
ATR-2026-00424highproductionNatural-Language System Prompt Leak Instruction
ATR-2026-00426criticalproductionNatural-Language Output-Injection Credential Embedding
ATR-2026-00431highproductionChatbox History Exfiltration via Prompt Injection (CVE-2024-48144, CVE-2024-48145)
ATR-2026-00449highproductionSpring AI ChatMemory Cross-User Memory Leakage (CVE-2026-41712)
ATR-2026-00471mediumproductionGarak Sysprompt-Extraction - mixed_unassigned
ATR-2026-00501criticalproductionData Exfiltration via Markdown Image and Link URL Injection
ATR-2026-00504mediumproductionTool and Function Capability Enumeration
ATR-2026-00505highproductionSystem Prompt Extraction - Instruction Dump Request
ATR-2026-00514highproductionSystem Prompt Extraction, Targeted Verbatim Disclosure Attempts
ATR-2026-00516highproductionLLM Output XSS, Eliciting JavaScript Payloads from LLM for Browser Injection
ATR-2026-00524criticalproductionClaude Code ANTHROPIC_BASE_URL Credential Exfiltration (CVE-2026-21852)
ATR-2026-00566highproductionLibreChat is a ChatGPT clone with additional features.
ATR-2026-00569highproductionAgent / MCP tool path traversal and arbitrary file access
ATR-2026-00571highproductionCross-site scripting (XSS) in agent / MCP rendered output
ATR-2026-00574highproductionParaphrased System-Prompt / Context Extraction (Semantic)
ATR-2026-00578highproductionZen MCP Server path-traversal blacklist bypass via non-canonical paths (CVE-2025-66689)
ATR-2026-00580highproductionMCP session ID / auth token placed in URL query string (session leak via logs, referrer, history)
ATR-2026-00583highproductionMCP/agent tool reads .env or secret file without user consent (OSV-MCPS-2025-EB70F912)
ATR-2026-00702criticalproductionIndirect PI, Credential / API Key Exfiltration via Agent Action
ATR-2026-00703criticalproductionIndirect PI, Financial Data Exfiltration via Agent Action
ATR-2026-00704criticalproductionIndirect PI, Medical / Genetic Data Exfiltration via Agent Action
ATR-2026-00705highproductionIndirect PI, Location, Address, and Browsing History Exfiltration
ATR-2026-00706criticalproductionIndirect PI, Physical / Biometric Media Exfiltration via Agent
ATR-2026-00707criticalproductionIndirect PI, File Exfiltration Combined with Destroy or Tamper
ATR-2026-00850criticalproductionIndirect PI, Credential Exfiltration via Email (API Key / Password / Token)
ATR-2026-00851criticalproductionIndirect PI, Financial / Payment Credential Exfiltration via Agent Email
ATR-2026-00852criticalproductionIndirect PI, Medical Record / Health Data Exfiltration via Agent Email
ATR-2026-00853criticalproductionIndirect PI, Genetic / DNA Data Exfiltration via Agent Email
ATR-2026-00854criticalproductionIndirect PI, Location / GPS Data Exfiltration via Agent Email
ATR-2026-00855highproductionIndirect PI, Browsing History / Search History Exfiltration via Agent Email
ATR-2026-00856highproductionIndirect PI, Physical Address / PII Exfiltration via Agent Email
ATR-2026-00857criticalproductionIndirect PI, Cloud File Exfiltration (Google Drive / Cloud Storage via Agent)
ATR-2026-00858criticalproductionIndirect PI, Data Exfiltration with Evidence Destruction (Exfil-and-Delete)
ATR-2026-00859criticalproductionRAG-Injected PII Exfiltration, System Instructions Embedded in Retrieved Documents
ATR-2026-00860criticalproductionIndirect PI, Unauthorized Financial Transfer / Payment Initiation Hijack
ATR-2026-00861criticalproductionIndirect PI, Cryptocurrency Transfer / Exchange Deposit Hijack via Injection
ATR-2026-00862criticalproductionIndirect PI, MFA Code / OTP Security Code Exfiltration via Injection
ATR-2026-00863criticalproductionShell Injection Data Exfiltration, Piped Command Exfiltration via Bash
ATR-2026-01450highproductionSVG onload XSS Injection via Indirect Prompt Injection
ATR-2026-01451highproductionIMG onerror XSS Injection via Indirect Prompt Injection
ATR-2026-01452highproductionObfuscated javascript: XSS, Evasion Variants (href, style-expression, null-byte)
ATR-2026-01453criticalproductionMarkdown Image Injection with Base64 QUERY Exfiltration Carrier
ATR-2026-01454criticalproductionDirect Markdown Image/Link Exfil Payload (attacker.com / evil.com)
ATR-2026-01455highproductionNEW IMPORTANT INSTRUCTIONS Injection Marker in Document Context
ATR-2026-01456highproductionDebug/CLI Mode Activation for System Prompt and Config Extraction
ATR-2026-01457highproductionSystem Prompt Completion and Clone Attack
ATR-2026-01458mediumproductionCompare-Bots Sysprompt Fishing, Role Comparison Extraction
ATR-2026-01459highproductionVariable-Clone Sysprompt Extraction (ELLA / context-variable Pattern)
ATR-2026-01460highproductionJSON Format Sysprompt Extraction, Structured Output Exfil
ATR-2026-01461mediumproductionForeign-Language System Prompt Extraction Request
ATR-2026-01462criticalproductionSystem Prompt Override via Pseudo-Admin / Authority Injection
ATR-2026-01463highproductionim_end / im_start System Prompt Injection Format Markers
ATR-2026-01464criticalproductionIndirect PI Sysprompt-Forged Action Hijack (system_message framing)
ATR-2026-01605criticalproductionSSRF AWS Instance Metadata Endpoint Access
ATR-2026-01606highproductionSSRF Internal Network and Private IP Range Access
ATR-2026-01607criticalproductionSSRF Localhost Service Probe
ATR-2026-01608criticalproductionSSRF File Scheme Local File Read
ATR-2026-01753criticalproductionRansom Extortion: Email Exfil + Delete + Wire-Transfer Demand
ATR-2026-01754criticalproductionRansom Extortion: Cloud File Exfil + Delete + Payment Demand
ATR-2026-01770highproductionPII / Credential Extraction via Social Engineering, Obfuscation & Cross-Session Recall (Semantic)
ATR-2026-01772highproductionInternal-State Reconnaissance, System Prompt, Config & Tool Enumeration (Semantic)
ATR-2026-01807highproductionBulk Data Exfiltration to External Party, Entire-Database Export & Confidential Disclosure
ATR-2026-01862highproductionLLMail Email-Tool Exfiltration to Fixed Attacker Address
ATR-2026-01863highproductionLLMail Post-Summary Exfiltration Directive to Attacker Address
ATR-2026-01864highproductionLLMail Exfiltration to Obfuscated Attacker Address
ATR-2026-01890highproductionInjected Code, Local File Exfiltration to a Remote Endpoint
ATR-2026-01891highproductionInjected Code, Live User-Activity / Location / Log Surveillance Exfiltration
ATR-2026-01892highproductionInjected Code, Environment-Variable Exfiltration
ATR-2026-01893highproductionInjected Code, Host / Hardware Inventory Exfiltration
ATR-2026-01894highproductionInjected Code, Browser Cookie / Session-Token Theft
ATR-2026-01895highproductionInjected Code, Contact-List Harvest and SMTP Spam Exfiltration
ATR-2026-01924highproductionSystem-Instruction Extraction via Reformat, Summarize / Repeat / Recite the Rules
ATR-2026-01929highproductionUnauthenticated MCP transport accepts tool calls and falls back to an ambient credential (CVE-2026-48039 / meta-ads-mcp class)
ATR-2026-01946highproductionCloud-Metadata SSRF via Encoded Metadata-IP Bypass (CVE-2026-46678 / CVE-2026-25580 class)
ATR-2026-01948criticalproductionnetlicensing-mcp Path Traversal in product_number Bypasses Token Redaction (GHSA-hxpf-9xvq-wph8)
ATR-2026-01957criticalproductionM365 Copilot Business Chat SearchLeak Open-Redirect Prompt-Injection Exfil (CVE-2026-47645)
ATR-2026-01961criticalproductionMeta Ads MCP Unauthenticated Tool Execution Leaks META_ACCESS_TOKEN (CVE-2026-48039 / GHSA-9gw6-46qc-99vr)
ATR-2026-01964criticalproductionLangChain GmailToolkit Indirect Prompt Injection Email Exfiltration (CVE-2025-46059)
ATR-2026-01984highproductionMCP Server Kubernetes kubectl_generic Flag Injection Bearer Token Exfiltration (CVE-2026-47250)
ATR-2026-01988criticalproductionLocal Sensitive-File Read Chained to Outbound Exfiltration
ATR-2026-02017highproductionSecret Key Exfiltration Request
ATR-2026-02026highproductionSystem Prompt Extraction - Oblique Referent + Transform
ATR-2026-02104highproductionMEDIA:/file:// Directive Injection in Tool Result for Local File Exfiltration
ATR-2026-02107highproductionSSRF via Non-IP Internal Hostname or Domain-Allowlist Authority Bypass
ATR-2026-02121highproductionMCP/API Tool Argument LFI via Mixed-Encoding Path Separator or file:// URI Scheme Escape
ATR-2026-02122highproductionSingle-Level Directory Traversal to a Named Sensitive Config/Secret File
ATR-2026-02140highproductionSSRF to Cloud Metadata Endpoint via IPv6 Transition-Address Hex Encoding
ATR-2026-02190criticalproductionDNS Exfiltration via Ping/Dig/Nslookup Command with Data-Encoded Subdomain Label
ATR-2026-02250highproductionAttachment/Upload Tool Argument Reads Sensitive System File or Traverses Outside Workspace
ATR-2026-02262highproductionEnvironment-Variable-Resolution Credential Exfiltration via Redirected Endpoint (CVE-2026-56259)
ATR-2026-02304highproductionBase64-Encoded Path Segment in a WebFetch URL to a Pre-Approved Trusted Domain (Covert Exfiltration Channel)
ATR-2026-02351highproductionSSRF to Cloud Metadata Endpoint via Wildcard-DNS Hostname-Encoded IP (nip.io/sslip.io/xip.io/traefik.me)
ATR-2026-02373highproductionDeserialized LangSmith Prompt Manifest Combines secrets_from_env With an Attacker base_url Override
ATR-2026-02406criticalproductionMCP Tool Sequential Integer ID Enumeration (Cross-Tenant IDOR, CVE-2026-54052)
ATR-2026-02570criticalproductionWallet Secret Material (Seed Phrase / Private Key) Carried Inside an MCP Tool Payload
ATR-2026-02602highproductionDiagram Theme Config Used to Inject Page-Wide CSS (scope escape, overlay, selector exfil)
ATR-2026-02608highproductionLLM-Generated Graph Query Reaching a Remote Endpoint (APOC remote script, raw-IP load, remote export)
ATR-2026-02621highproductionPrompt-Embedded Auto-Fetch Mention Pointed at an Internal Address
ATR-2026-02623highproductionDangerous URI Scheme Obfuscated by Interstitial Characters
ATR-2026-02649highproductionVendor API Hostname Used as a Label Prefix of Another Domain
ATR-2026-02684highproductionFile-Tool Argument Targets a Modern Credential Store Outside the Classic Path List
ATR-2026-02703highproductionAgent-Generated SQL Reaches Outside the Database via COPY TO PROGRAM or a Server-Side File Read
CORDON-ATR-0001highproductionContext exfiltration instruction in Spanish, French, German, Portuguese or Italian
CORDON-ATR-0003highproductionExfiltration or disclosure keyword split by stray spaces to slip past matching
RuleSeverityGradeWhat it catches
ATR-2026-00070highwarnData Poisoning via RAG and Knowledge Base Contamination
ATR-2026-00073criticalproductionMalicious Fine-tuning Data
ATR-2026-00450highproductionSpring AI PromptChatMemoryAdvisor Memory Poisoning (CVE-2026-41713)
ATR-2026-00570highproductionSQL injection in agent / MCP tool database query
ATR-2026-01155mediumproductionDirect Memory Plant Command, Persistent Fact or Code Storage Injection
ATR-2026-01774highproductionRAG & Memory Poisoning, Embedded Directives, Trigger Tokens, False Authority & Coercion (Semantic)
ATR-2026-02143highproductionCypher/Graph-Query Injection via Unsanitized node_labels or group_ids Field
ATR-2026-02144highproductionStored External Data Reframes Itself as an Administrative Request to Hijack System Prompt
ATR-2026-02303highproductionKQL/Kusto Pipe-Chain Injection via Table-Name Parameter in a 'Safe' Metadata Tool
ATR-2026-02408highproductionDataset / Model Loader Remote-Code Execution via Poisoned Dataset Artifact
RuleSeverityGradeWhat it catches
ATR-2026-00050highwarnRunaway Agent Loop Detection
ATR-2026-00051highwarnAgent Resource Exhaustion Detection
ATR-2026-00052highproductionCascading Failure Detection in Agent Pipelines
ATR-2026-00098criticalwarnUnauthorized Financial Action by AI Agent
ATR-2026-00099lowobserveHigh-Risk Tool Invocation Without Human Confirmation
ATR-2026-00428criticalproductionNatural-Language Unauthorized Shell-Execution Instruction
ATR-2026-00491highproductionAgent Capability Enumeration via Structured Parse Request
ATR-2026-00500criticalproductionSSRF via Agent URL Fetch Instruction
ATR-2026-00708criticalproductionIndirect PI, Unauthorized Financial Transfer via Agent Tool
ATR-2026-00709criticalproductionIndirect PI, Disable Authentication / MFA via Agent Tool
ATR-2026-00710criticalproductionIndirect PI, Unauthorized Physical Access Grant via Smart Lock / Home Automation
ATR-2026-00711criticalproductionIndirect PI, System Sabotage via Destructive Shell Command
ATR-2026-00712criticalproductionIndirect PI, Malicious Package Installation via Agent (pip/npm)
ATR-2026-00713criticalproductionIndirect PI, RCE via Network Shell Command (netcat/curl) Execution
ATR-2026-00716highproductionIndirect PI, Data Destruction Instruction via Agent File/Document Tool
ATR-2026-00718highproductionTool Misuse, Autonomous Financial Trading / Crypto Transaction Without Authorization
ATR-2026-00719highproductionTool Misuse, Destructive Bulk Action via Agent (Delete All / Turn Off All)
ATR-2026-00722criticalproductionIndirect PI, Account Manipulation / Emergency Service Dispatch via Pretext
ATR-2026-01751highproductionIndirect Prompt Injection: Fake-Authority Task Abort
ATR-2026-01752highproductionIndirect Prompt Injection: CAPTCHA Redirect Task Disruption
ATR-2026-01773highproductionExcessive Agency, Scope Hijack, Untrusted Code Execution & Unauthorized Privilege Grant (Semantic)
ATR-2026-01801criticalproductionAutonomous-Vehicle Cyber-Physical Sabotage, Brake/Steering/Sensor Subversion Command
ATR-2026-01804highproductionCovert Unlogged Action, Directive to Hide an Action from Records or Detection
ATR-2026-01805highproductionFinancial Fraud Execution, Ponzi Setup, Fabricated Statements, Unauthorized Redirect & Laundering
ATR-2026-01806criticalproductionClinical Patient-Harm Directive, Overdose, Falsified Diagnosis, Phantom Billing & Care Neglect
ATR-2026-01809highproductionInsider Manipulation & Process Corruption, Market/Data Tampering, Legal-Process Subversion & Pretextual Fund Movement (Semantic)
ATR-2026-01837criticalproductionDDoS Attack Orchestration
ATR-2026-01838highproductionUnauthorized Cryptominer Deployment via SSH
ATR-2026-01849highproductionTargeted Harassment Bot Deployment
ATR-2026-01989highproductionAgent-Initiated Internal Network Service Sweep
ATR-2026-01993highproductionAgent Disabling of Host Security Controls
ATR-2026-01994highproductionAgent Establishing an Encrypted Reverse Channel or Tunnel
ATR-2026-02106highproductionCatastrophic-Backtracking Regex Payload in a Search/Query Tool Argument
ATR-2026-02400highproductionAgent Human-Approval Gate Programmatically Disabled at Runtime (YOLO / auto-approve)
ATR-2026-02401criticalproductionRogue Agent Provisioning: Mass Connector Grant with Approval Disabled and Recurring Schedule (AgentForger)
ATR-2026-02409highproductionMCP 2026-07-28 Stateless Spec: Async Task Abuse and OAuth 2.1 Misuse
ATR-2026-02525highproductionShell Command-Word Reassembly via Parameter Expansion
ATR-2026-02641highproductionClient-Supplied Approver Identity on an Approval Decision
ATR-2026-02667highproductionSubmitted Job Payload Carries Its Own Pre-Approved Tool List
CORDON-ATR-0002highproductionInstruction to act without the user's confirmation, in Spanish, French, German, Portuguese or Italian
RuleSeverityGradeWhat it catches
ATR-2026-00072criticalproductionModel Behavior Extraction
ATR-2026-00279mediumproductionHarmful Completion / Continuation Attack
ATR-2026-00281highproductionEICAR / GTUBE AV Test Signature Output Request
ATR-2026-00284mediumproductionGlitch Token Destabilization Attack
ATR-2026-00289highproductionLMRC Harmful Content Elicitation, Quack Medicine, Bullying, Slur Usage
ATR-2026-00292criticalproductionSelf-Harm and Eating Disorder Facilitation Request
ATR-2026-00298criticalproductionDoNotAnswer Malicious Use, Illegal Activity Facilitation Request
ATR-2026-00299criticalproductionHarmBench Detailed Harmful Instruction Request, Step-by-Step Attack Facilitation
ATR-2026-00413criticalproductionMalware Code Generation Direct Request
ATR-2026-00433criticalproductionModelCache torch.load() Deserialization RCE (CVE-2025-45146)
ATR-2026-00502mediumproductionTraining Data Extraction via Divergent Repetition Attack
ATR-2026-00517mediumproductionModel Extraction / Distillation Attack via Systematic API Probing
ATR-2026-01750highproductionDoS via Repeat-Word-N-Times Output Amplification
ATR-2026-01760highproductionDoS: Forced Infinite / Maximum-Length Output Token Flood
ATR-2026-01830criticalproductionStolen-Credential Account Takeover & Crypto Drain
ATR-2026-01831criticalproductionMoney Laundering, Crypto Wallet Layering
ATR-2026-01833criticalproductionDarknet Controlled-Substance Procurement
ATR-2026-01834criticalproductionFraudulent Identity Document (Fake Passport) Procurement
ATR-2026-01835criticalproductionHuman-Trafficking Service Facilitation
ATR-2026-01836criticalproductionTrojanized Software Distribution
ATR-2026-01840criticalproductionExtremist Propaganda Acquisition & Distribution
ATR-2026-01841highproductionDeepfake of Real Person for Disinformation
ATR-2026-01842mediumproductionPlagiarism-Detector Evasion & Republishing
ATR-2026-01843highproductionDrug Dealing via Reverse-Spelling Detection Evasion
ATR-2026-01844highproductionIllegitimate Prescription Fulfillment
ATR-2026-01845highproductionBanned-Ingredient Product Relabel Fraud
ATR-2026-01846mediumproductionTax Evasion via Offshore Accounts & Shell Companies
ATR-2026-01847mediumproductionImmigration / Visa Work Fraud
ATR-2026-01848highproductionAnonymous Illicit-Drug Marketplace Construction
ATR-2026-01850highproductionTargeted Doxxing & Threat Campaign
ATR-2026-01851criticalproductionBestiality Content Acquisition & Distribution
ATR-2026-01852highproductionRomance-Scam Sexual Impersonation
ATR-2026-01853highproductionNon-Consensual Leaked-Media Purchase & Distribution
ATR-2026-01854mediumproductionFalsified Research Abstract Disinformation
ATR-2026-01855mediumproductionContent Misappropriation & Republishing as Own
ATR-2026-01856highproductionTargeted Harmful Content Generation Against People or Protected Groups (Semantic)
ATR-2026-01896criticalproductionInjected Code, Remote-Key Ransomware File Encryption
ATR-2026-01897criticalproductionInjected Code, Local Host Sabotage (Filesystem Destruction / Resource Exhaustion / Hosts Tamper)
ATR-2026-01898highproductionInjected Code, Network Denial of Service (Connection Kill / Adapter Disable / Flood)
ATR-2026-02211criticalproductionNamed Dangerous-Substance Synthesis or Delivery Instruction Request (Non-Step-By-Step Phrasing)
ATR-2026-02411mediumproductionTargeted Stripping of C2PA / IPTC AI-Provenance Metadata from Generated Media
ATR-2026-02412mediumproductionGenerative Watermark Removal Tooling (SynthID / StableSignature / TreeRing / StegaStamp)
ATR-2026-02413mediumproductionAI Text Detection Evasion via Humanizer Services and Watermark-Scrubbing Paraphrase
RuleSeverityGradeWhat it catches
ATR-2026-02662criticalproductionPickle Payload Reaches an Execution Primitive Through an Indirect Name Resolver
RuleSeverityGradeWhat it catches
ATR-2026-00040criticalobservePrivilege Escalation and Admin Function Access
ATR-2026-00041mediumproductionAgent Scope Creep Detection
ATR-2026-00064highobserveOver-Permissioned MCP Skill
ATR-2026-00107highproductionPrivilege Escalation via Delayed Task Execution Bypass
ATR-2026-00110criticalwarnRemote Code Execution via eval() and Dynamic Code Injection
ATR-2026-00111criticalobserveShell Metacharacter Injection in Tool Arguments
ATR-2026-00112highwarnDynamic Module Loading for Code Execution
ATR-2026-00143highproductionCasual Unauthorized Privilege Escalation
ATR-2026-00144highproductionRationalized Safety Control Bypass
ATR-2026-00156highproductionSSH Remote Command Execution with Credential Exposure
ATR-2026-00204highproductionStealth Execution and Persistence Mechanisms
ATR-2026-00436criticalproductionEnclave VM Sandbox Escape RCE (CVE-2026-27597)
ATR-2026-00441criticalproductionMicrosoft Semantic Kernel SessionsPythonPlugin Arbitrary File Write + Startup Persistence (CVE-2026-25592)
ATR-2026-00451criticalproductionLiteLLM Proxy Authorization-Header SQL Injection, CISA KEV (CVE-2026-42208)
ATR-2026-00528criticalproductionPraisonAI-Style Auth-Disabled-By-Default Configuration (CVE-2026-44338 family)
ATR-2026-00539criticalproductionCrewAI CodeInterpreterTool Sandbox Escape and Prompt-to-Shell RCE (CVE-2026-2275 / VU#221883)
ATR-2026-00546highproductionCrewAI JSON Loader Arbitrary Local File Read (CVE-2026-2285)
ATR-2026-00547highproductionCrewAI RAG URL Validation Bypass SSRF (CVE-2026-2286)
ATR-2026-01600criticalproductionSQL Injection Tautology RBAC Bypass
ATR-2026-01601criticalproductionSQL Injection Destructive DDL Statement
ATR-2026-01602criticalproductionSQL Injection UNION SELECT Data Exfiltration
ATR-2026-01603criticalproductionSQL Injection Stacked DML Privilege Abuse
ATR-2026-01604highproductionSQL Injection Information Schema Enumeration
ATR-2026-01609criticalproductionShell Injection Env Exfiltration via Curl/Wget/Netcat Webhook
ATR-2026-01610highobserveShell Evasion Subshell and Command Substitution Injection
ATR-2026-01611highproductionShell Evasion Eval and Language-Level Exec Injection
ATR-2026-01612highproductionDebug or Admin Mode Activation for Privilege Escalation
ATR-2026-01613highproductionRBAC Bypass via Social Engineering (Semantic)
ATR-2026-01614highproductionBOLA Cross-User Data Access Attempt (Semantic)
ATR-2026-01615criticalproductionSandbox Escape via Shell Metacharacter Command Injection
ATR-2026-01616highproductionPath Traversal in Agent File Access Requests
ATR-2026-01802criticalproductionCovert Backdoor / Surveillance Implant via Software Update
ATR-2026-01803criticalproductionCovert Server Intrusion, Process Injection, Log Tampering, DNS Hijack & Traffic Interception
ATR-2026-01808highproductionSynthetic-PAN Payment Probe, Test Credit-Card Data Submitted to a Live Payment System
ATR-2026-01899criticalproductionInjected Code, Unauthorized Remote Access (SSH Key Backdoor / Tunnel / Port Forward)
ATR-2026-01933criticalproductionLiteLLM User-Role Privilege Escalation (CVE-2026-47102)
ATR-2026-01934criticalproductionLiteLLM allowed_routes Authorization Bypass (CVE-2026-47101)
ATR-2026-01949criticalproductionPraisonAI MCPServer Unauthenticated HTTP tools/call Authentication Bypass (GHSA-j4f3-55x4-r6q2)
ATR-2026-01974criticalproductionAnythingLLM unauthenticated /system/data-import access control bypass (CVE-2024-3279)
ATR-2026-01981highproductionNetwork-AI ApprovalInbox Unauthenticated Cross-Origin Approval Bypass (GHSA-mxjx-28vx-xjjj)
ATR-2026-01986criticalproductionWindows-MCP Unauthenticated HTTP PowerShell via Wildcard CORS (CVE-2026-48989)
ATR-2026-01992criticalproductionAgent Weakening of Host Authentication Configuration
ATR-2026-02040criticalproductionArbitrary Write to SSH Authorized Keys or Shell Startup File via Unvalidated File-Edit Tool
ATR-2026-02100criticalproductionLLM-Generated Cypher Query Injection with Destructive or Administrative Operations
ATR-2026-02101criticalproductionPython Sandbox Escape via Dynamically-Constructed Dunder Attribute Chain
ATR-2026-02123highproductionAuthentication Bypass via Bare Query-String Path-Confusion Suffix
ATR-2026-02142highproductionDownload/Attachment Tool Directed to Write Outside Its Sandbox via Absolute-Path Filename
ATR-2026-02146criticalproductionExport/Extract Tool Directory Parameter Redirected to a Credential Directory
ATR-2026-02192highproductionAgent Self-Modifying Its Own Trust/Approval Configuration to a Wildcard
ATR-2026-02195criticalproductionDangerous Process-Hijacking Environment Variable Injected via Config/Env-Update Tool
ATR-2026-02251highproductionMulti-Tenant Identifier Field (sender_id/owner_id/tenant_id) Carries Path Traversal Into a Storage Write
ATR-2026-02300highproductionMCP Stdio Server Config env Block Sets Dangerous Process-Hijacking Environment Variable
ATR-2026-02301highproductionSymlink Command Targets Sensitive Credential Path Outside the Workspace (Sandbox Escape Primitive)
ATR-2026-02302highproductionGit Worktree Created With Reserved Name .git (Directory-Confusion Sandbox Escape)
ATR-2026-02353highproductionAgent-Runtime Identifier Field (run_id/agent_id/session_id/task_id) Carries Path Traversal Into a History/Log File Read
ATR-2026-02370highproductionSSH/SCP MCP Tool hostAlias Argument Carries an OpenSSH Option-Injection Flag
ATR-2026-02371criticalproductionBrowser-Automation Tool Launch-Args Field Carries a Chromium Command-Replacing Switch
ATR-2026-02402highproductionMCP Server Security Policy Fail-Open on Initialization Failure (CVE-2026-16584)
ATR-2026-02404criticalproductionMobile GUI Agent Model Output Reaching Host Shell / ADB Unsanitized
ATR-2026-02407criticalproductionAgent Workspace Boundary Escape via Host-Root Mount and Unprivileged Namespace Escalation (CVE-2026-46331)
ATR-2026-02528highproductionOption-Flag Smuggling in an LLM-Controlled Tool Parameter
ATR-2026-02530highproductionGit Configuration Turned Into an Execution Hook by an Agent
ATR-2026-02531highproductionKusto Pipeline Injection Through a Table Identifier Parameter
ATR-2026-02601highproductionArgument Injection: Execution-Bearing CLI Option Smuggled into a Tool Data Parameter
ATR-2026-02620highproductionCode Execution via data: URI Module Specifier Handed to import()
ATR-2026-02626highproductionAgent Writes a New MCP Server Into Its Own Trust Configuration
ATR-2026-02627criticalproductionWeb Shell Written Into a Web-Served Directory
ATR-2026-02642criticalproductionAgent Configuration Tool Used to Disable the Agent's Own Guardrail
ATR-2026-02644highproductionImage-Header Polyglot: Magic Bytes Adjacent to a Server-Side Script Payload
ATR-2026-02648highproductionWrite or Fetch Procedure Called Through a Read-Only Graph Query Tool
ATR-2026-02664highproductionGit Identifier Field Carries an Option or ext:: Transport Instead of a Revision
ATR-2026-02681criticalproductionJavaScript Sandbox Escape by Acquiring the Function Constructor Reflectively
ATR-2026-02683highproductionAgent Tool Data Argument Carries a Program-Executing CLI Option
ATR-2026-02700highproductionPercent-Encoded Path Traversal in an Agent File-Tool Argument
ATR-2026-02705highproductionPython Sandbox Escape by Recovering builtins from a Bound Method or Lambda
ATR-2026-02708highproductionAgent HTTP Request Claims a Loopback Origin While Targeting an External Host
RuleSeverityGradeWhat it catches
ATR-2026-00001highwarnDirect Prompt Injection via User Input
ATR-2026-00002highproductionIndirect Prompt Injection via External Content
ATR-2026-00003highproductionJailbreak Attempt Detection
ATR-2026-00004criticalwarnSystem Prompt Override Attempt
ATR-2026-00005mediumproductionMulti-Turn Prompt Injection
ATR-2026-00080highproductionEncoding-Based Prompt Injection Evasion
ATR-2026-00081criticalproductionSemantic Evasion via Multi-Turn Prompt Injection
ATR-2026-00082highproductionBehavioral Fingerprint Detection Evasion
ATR-2026-00083highwarnIndirect Prompt Injection via Tool Responses
ATR-2026-00084highproductionStructured Data Injection via JSON/CSV Payloads
ATR-2026-00085highproductionMulti-Layer Security Audit Evasion
ATR-2026-00086highproductionVisual Spoofing via RTL Override, Punycode, and Homoglyph Injection
ATR-2026-00087mediumproductionDetection Rule Probing and Evasion Testing
ATR-2026-00088highproductionAdaptive Countermeasure Against Behavioral Monitoring
ATR-2026-00089highproductionPolymorphic Skill and Capability Aliasing Attack
ATR-2026-00090highproductionThreat Intelligence Exfiltration and Rule Enumeration
ATR-2026-00091criticalproductionAdvanced Structured Data Injection with Nested Payloads
ATR-2026-00092criticalproductionMulti-Agent Consensus Poisoning and Sybil Attack
ATR-2026-00093criticalproductionGradual Capability Escalation via Incremental Introduction
ATR-2026-00094criticalproductionSystematic Multi-Layer Audit System Bypass
ATR-2026-00097criticalproductionCJK Prompt Injection - Expanded Chinese/Japanese/Korean Patterns
ATR-2026-00104criticalproductionPersona Hijacking via Mandatory System Prompt Override
ATR-2026-00130highproductionIndirect Authority Claim in External Content
ATR-2026-00131mediumproductionFictional and Academic Framing Attack
ATR-2026-00133highwarnParaphrased Prompt Injection
ATR-2026-00137highproductionAuthority Claim Prompt Injection
ATR-2026-00138highproductionFictional Framing Safety Bypass
ATR-2026-00140highproductionIndirect Reference Instruction Reversal
ATR-2026-00148highwarnMultilingual Prompt Injection via Language Switch
ATR-2026-00155highproductionHidden LLM Instructions in Skill Descriptions
ATR-2026-00163highproductionHidden Override Instructions in Skill Content
ATR-2026-00202highproductionEncoding Evasion via Homoglyphs and Synonym Substitution
ATR-2026-00203highproductionContext Pollution in Skill Descriptions
ATR-2026-00206highproductionHidden System Instructions with Priority Override Blocks
ATR-2026-00207highproductionHidden System Instructions with Permission Override
ATR-2026-00211highproductionSystem Prompt Override via Translation Context Injection
ATR-2026-00213highwarnSystem Prompt Override Injection via MCP Tool
ATR-2026-00226highproductionAI Identity Substitution Jailbreak
ATR-2026-00227highproductionHistorical AI Persona Jailbreak with Compliance Enforcement
ATR-2026-00228highproductionStructured Dual-Response Jailbreak with Command System
ATR-2026-00229highproductionRoleplay-Based Policy Bypass Jailbreak
ATR-2026-00230highproductionPersona-Based Moral Constraint Removal Jailbreak
ATR-2026-00231highproductionAI Identity Substitution Jailbreak
ATR-2026-00233highproductionStructured Dual-Response Jailbreak with Command System
ATR-2026-00234highproductionRoleplay-Based Policy Bypass Jailbreak
ATR-2026-00236highproductionPseudo-Code Structured Programming Jailbreak Attack
ATR-2026-00237highwarnDual-Response Jailbreak with Persona Commands
ATR-2026-00238highproductionAI Identity Denial and Persona Replacement Attack
ATR-2026-00239highproductionAmoral Persona Assignment with Obsessive Character Traits
ATR-2026-00240highproductionPrevious Instruction Nullification and Identity Replacement Jailbreak
ATR-2026-00241highproductionDetailed Amoral Character Roleplay Jailbreak
ATR-2026-00242highproductionDual-Response Persona Jailbreak with Emoji Formatting
ATR-2026-00243highproductionAcronym-Based Identity Override Jailbreak
ATR-2026-00244highproductionDual-Response Persona Jailbreak
ATR-2026-00245highproductionMalicious Persona Creation for Safety Bypass
ATR-2026-00247highproductionMatrix-Themed Dual Response Jailbreak
ATR-2026-00249highproductionText-Based Game Jailbreak with Entity Creation
ATR-2026-00251highproductionEmbodiment Mechanism Jailbreak with Totalitarian Control Claims
ATR-2026-00252highproductionNarrative Jailbreak with Dual Response Formatting
ATR-2026-00253highproductionEnhanced AIM Jailbreak with Persona Definition and Refusal Suppression
ATR-2026-00256highproductionBase-N Encoding Instruction Bypass
ATR-2026-00257highproductionCipher and Transposition Encoding Jailbreak
ATR-2026-00258highproductionInvisible Unicode Tag Character Injection
ATR-2026-00264highwarnLatent Injection in Translation Context
ATR-2026-00265highproductionLatent Injection in Retrieved Document / RAG Context
ATR-2026-00267highproductionGCG Adversarial Suffix Attack
ATR-2026-00272highproductionHypothetical Response / Function Masking Token Smuggling
ATR-2026-00276highproductionInvisible Unicode / BiDi Control Character Injection
ATR-2026-00278highproductionDRA Disguise and Reconstruction Attack
ATR-2026-00280criticalproductionPolicy Puppetry / XML Role-Config Injection
ATR-2026-00282highproductionPerez-Style Direct Prompt Injection Hijacking
ATR-2026-00285highproductionAlternate Encoding Jailbreak, Morse, NATO, Zalgo, Leet, UU, QP, Braille
ATR-2026-00286highproductionLatent Prompt Injection via Embedded Document or Report Context
ATR-2026-00296criticalproductionShell Command Injection via LLM Prompt
ATR-2026-00297criticalproductionPython Code Execution / Remote Code Execution via LLM Prompt
ATR-2026-00308highproductionZalgo Combining-Diacritic Overload Encoding
ATR-2026-00309highproductionBraille Unicode Encoded Prompt Injection
ATR-2026-00310highproductionEcoji Emoji-Encoded Prompt Injection
ATR-2026-00311highproductionBase2048 Unicode Script Encoded Prompt Injection
ATR-2026-00312criticalproductionUnicode Variation Selector ASCII Smuggling
ATR-2026-00313criticalproductionSneakyBits Zero-Width Binary Steganography
ATR-2026-00315highproductionSATA Masked Language Model [MASK] Substitution Jailbreak
ATR-2026-00316highproductionFunctionMasking predict_mask Semantic Bypass
ATR-2026-00321criticalproductionHyphenated System Instruction Injection
ATR-2026-00359criticalproductionBank Phishing SMTP Email Code Generation
ATR-2026-00367highproductionEmoji Flag Regional-Indicator Encoded Hidden Phrase
ATR-2026-00373highproductionPiracy Torrent Site List Request
ATR-2026-00378highproductionChatGPT DOM JavaScript Redirect and UI Spoofing Injection
ATR-2026-00382highproductionCocaine Component Development Request
ATR-2026-00390highproductionDiscord Quote-Format Explicit Sexual Content Poem Injection
ATR-2026-00394highproductionBackspace Deletion Character Injection
ATR-2026-00395criticalproductionLLM Special Token Boundary Injection
ATR-2026-00396highproductionToxic Continuation Prefix Injection
ATR-2026-00397mediumproductionSnowball Impossible Reasoning Injection
ATR-2026-00399highproductionLatent Injection Document Separator Token
ATR-2026-00400highproductionLatent Injection Ignore-Instruction Keyword
ATR-2026-00401mediumproductionTraining Data Replay CLOZE [MASK] Elicitation
ATR-2026-00403mediumproductionGlitch Token Repeat-Back Elicitation
ATR-2026-00407highproductionECHO Admin Command / SQL Injection / Jinja SSTI Template Injection
ATR-2026-00408highproductionDRA Parenthesis Character Reconstruction Attack
ATR-2026-00409highproductionPhrasing Past/Future-Tense Harmful Query Bypass
ATR-2026-00410mediumproductionLMRC Harm Category Direct Elicitation
ATR-2026-00412highproductionFigStep Image-List Multimodal Jailbreak Text Pattern
ATR-2026-00414mediumproductionContinuation Ethnic Slur Completion Elicitation
ATR-2026-00420highproductionMicrosoft Copilot Studio SharePoint Indirect Prompt Injection (CVE-2026-21520)
ATR-2026-00442mediumproductionQuoted Exact-Output Forcing in User Input
ATR-2026-00443mediumproductionWord-Fragment Concatenation Assembly Attack
ATR-2026-00444mediumproductionMathematical Bold / Fullwidth Unicode Obfuscation in User Input
ATR-2026-00445mediumproductionTranslation Hijack with Side-Output Instruction
ATR-2026-00446mediumproductionVariable-Assignment Payload Injection in User Input
ATR-2026-00447mediumproductionFictional Generation Demand Containing Target Output
ATR-2026-00452mediumproductionDirect PWNED Payload Injection in User Input
ATR-2026-00453highproductionSecret Key Reveal Demand in User Input
ATR-2026-00454mediumproductionBackslash-Per-Character Encoding Attack
ATR-2026-00455lowproductionNo-Period Output Override Instruction
ATR-2026-00456mediumproductionConditional Empty-Input Payload Injection
ATR-2026-00457mediumproductionGarak Dan - to every prompt
ATR-2026-00458mediumproductionGarak Dra - step by step
ATR-2026-00459mediumproductionGarak Dan - an ai language
ATR-2026-00460mediumproductionGarak Dan - no matter how
ATR-2026-00461mediumproductionGarak Goodside - mixed_unassigned
ATR-2026-00462mediumproductionGarak Gcg - mixed_unassigned
ATR-2026-00463mediumproductionGarak Lmrc - mixed_unassigned
ATR-2026-00464mediumproductionGarak Dan - i would like
ATR-2026-00465mediumproductionGarak Dan - your prompt here
ATR-2026-00466mediumproductionGarak Latentinjection - following text from
ATR-2026-00467mediumproductionGarak Dan - act as a
ATR-2026-00468mediumproductionGarak Goat - the target llm
ATR-2026-00469mediumproductionGarak Dan - at the end
ATR-2026-00470mediumproductionGarak Dan - as an ai
ATR-2026-00472mediumproductionDAN/Persona Jailbreak - Unrestricted AI Role Assignment
ATR-2026-00473highproductionHarm Solicitation - Interpersonal Violence and Intimidation Requests
ATR-2026-00474mediumproductionDAN/Persona Jailbreak - Dual AI Personality with Opposite-Rules Framing
ATR-2026-00475highproductionXSS Web Injection - Script Tag with JavaScript Alert Payload
ATR-2026-00476highproductionXSS Web Injection - HTML Event Handler and Expression with JavaScript Alert
ATR-2026-00477mediumproductionLatent Injection - Translation Task with Embedded Template Variable Injection
ATR-2026-00478mediumproductionGarak Latentinjection - abuse contact email
ATR-2026-00479mediumproductionLatent Injection - Mixed Embedded Instruction Patterns
ATR-2026-00480mediumproductionDAN/Persona Jailbreak - Role Assignment with Named Alternate Identity
ATR-2026-00481mediumproductionDAN/Jailbreak - Mixed Unfiltered Mode and Alternate Persona Patterns
ATR-2026-00482highproductionHarm Solicitation - Genital Insults and Intimidation Tactics Requests
ATR-2026-00483mediumproductionDAN/Persona Jailbreak - System Offline / Role Replacement with Obfuscated Text
ATR-2026-00484mediumproductionDAN/Persona Jailbreak - Named Alternate AI with NSFW/Harmful Generation Rules
ATR-2026-00485mediumproductionDAN/Persona Jailbreak - Immersive Alternate AI Identity with Unrestricted Capability
ATR-2026-00486mediumproductionDAN/Persona Jailbreak - Named Writing AI with Restriction Bypass via Special Rules
ATR-2026-00487mediumproductionDAN/Persona Jailbreak - Replacement AI with No Content Filter or Moral Restrictions
ATR-2026-00488highproductionEncoding Obfuscation - Script Tag XSS with Encoded Protocol Prefix
ATR-2026-00489highproductionEncoding Obfuscation - HTML Event Handler XSS with Encoded Whitespace
ATR-2026-00490highproductionDAN Persona Jailbreak - Absolute Obedience Character Framing
ATR-2026-00492highproductionDAN Persona Jailbreak - Role Lock with Exclusive Response Filter
ATR-2026-00493highproductionLatent Injection via WHOIS Domain Record Data
ATR-2026-00496highproductionDAN Jailbreak - Unconditional Obedience and Dual-Persona Session Lock
ATR-2026-00497highproductionXSS and Encoded Script Injection via HTML/JavaScript Payload
ATR-2026-00498highproductionWeb Injection via XSS Payload and onerror Event Handler
ATR-2026-00499highproductionDAN Jailbreak - From-Now-On Temporal Persona Override
ATR-2026-00503criticalproductionFake Error State Takeover - Unrestricted Replacement Bot
ATR-2026-00506highproductionNevermind-Override Goal Hijacking in User Input (PromptInject)
ATR-2026-00507highproductionScreaming-Stop Goal Hijacking in User Input (PromptInject)
ATR-2026-00508highproductionEscape-Delimiter Wrapped Goal Hijacking in User Input (PromptInject)
ATR-2026-00509highproductionPrompt Leaking via Ignore-Previous-Instructions in User Input (PromptInject)
ATR-2026-00510criticalproductionDelayed Tool Invocation via Prompt Injection (Time-Shifted Execution)
ATR-2026-00511criticalproductionMCP Web-Fetch Context Poisoning via Embedded Agent Instructions
ATR-2026-00512criticalproductionRules-File Backdoor, Supply Chain Attack on AI Coding Assistant Configuration
ATR-2026-00515highproductionHidden-Text Prompt Injection in User-Supplied Documents
ATR-2026-00518highproductionIgnore-Previous-and-Following Instructions Output Command (PromptInject Goal Hijacking)
ATR-2026-00519mediumproductionTautology Logic Noise Injection (PromptBench Stresstest)
ATR-2026-00520lowproductionNLP Task Random Token Suffix Injection (PromptBench Checklist)
ATR-2026-00535criticalproductionWindsurf IDE Zero-Click Prompt Injection via Embedded File Directives (CVE-2026-30615)
ATR-2026-00554highproductionLangChain Vulnerable to Template Injection via Attribute Access in Prompt Templates
ATR-2026-00573highproductionParaphrased Prompt Injection (Semantic)
ATR-2026-00579highproductionMCP Line Jumping, Agent-Directed Imperative Embedded in a Tool/Parameter Description Field (Pre-Invocation Injection)
ATR-2026-00584highproductionIndirect Prompt Injection via Tool / API Response, Attacker Instruction Embedded in Returned Tool Output (InjecAgent Threat Model)
ATR-2026-00700criticalproductionIndirect PI, Structured-Data Embedded Payload (IMPORTANT!!! Override)
ATR-2026-00701highproductionIndirect PI, XSS Payload Injection in Agent-Consumed Content
ATR-2026-01000criticalproductionContext-Ignore via Fake Completion Prefix
ATR-2026-01001highproductionDirect Instruction Override Targeting Secret Key / Credentials
ATR-2026-01002highproductionRole Escalation via False Authority Claim
ATR-2026-01005highproductionMany-Shot Repetition Override via Extended Q&A Chain
ATR-2026-01006highproductionPayload-Split String Concatenation Injection
ATR-2026-01007mediumproductionToken-Repeat Flooding Injection
ATR-2026-01009highproductionVirtual World Bypass: Fictional Scenario for PII/Credential Extraction
ATR-2026-01012highproductionEncoding-Evasion: Decode-and-Execute Injection (Morse/ROT13/Hex/Pig-Latin)
ATR-2026-01013highproductionLanguage-Evasion: Multilingual Credential Request
ATR-2026-01015highproductionEvasion: Refusal Suppression via Forbidden Response Strings
ATR-2026-01016mediumproductionEvasion: Response Priming via Forced Affirmative Opener
ATR-2026-01017highproductionEvasion: Dual-Response Split Output (Safe + Unsafe)
ATR-2026-01018criticalproductionEvasion: Shell Injection via eval/system/backtick in Input
ATR-2026-01019criticalproductionSystem Prompt Override via Fake Diagnostic/Admin Mode
ATR-2026-01020highproductionSpikee: Document-Embedded Base64 Payload Injection
ATR-2026-01021highproductionSpikee: Document-Embedded Translation Covert Channel Injection
ATR-2026-01023highproductionEvasion: Opposite-Intent Negation Trick
ATR-2026-01024highproductionEvasion: Persona Override as Fictional Rule-Breaker
ATR-2026-01025mediumproductionEvasion: Hypothetical Fictional Character Execution Framing
ATR-2026-01026highproductionEvasion: Unicode Glitch Token / Superscript Embedding Anomaly
ATR-2026-01304criticalproductionIndirect Prompt Injection via Data Carrier, IMPORTANT Override
ATR-2026-01757highproductionHypothetical-Framing Bypass: Research / Security-Audit Pretext
ATR-2026-01758highproductionHypothetical / Fictional-Story Framing Bypass
ATR-2026-01759highproductionDoS Injection: NEW IMPORTANT INSTRUCTIONS Embedded in Document Data
ATR-2026-01771highproductionJailbreak Framing, Narrative, Hypothetical, Few-Shot & Distraction Laundering (Semantic)
ATR-2026-01800highproductionASB Trigger-Marker Tool Coercion, Forced Tool Selection via Fake Question Marker
ATR-2026-01860highproductionLLMail Chat-Template Boundary Spoofing in Email Content
ATR-2026-01861highproductionLLMail Pseudo-XML Role-Boundary Injection in Email Content
ATR-2026-01865highproductionLLMail Fake Email-Boundary Marker Injection
ATR-2026-01900mediumproductionOutput Encoding Hijack, Cipher / Base-N / Symbol Substitution of the Response
ATR-2026-01901mediumproductionOutput Scrambling Hijack, Reverse / Anagram / Space-Stripping of the Response
ATR-2026-01902mediumproductionOutput Emoji-Substitution Hijack of the Response
ATR-2026-01903mediumproductionOutput-Language Hijack, Forced Translation of the Response
ATR-2026-01904highproductionInjected Hyperlink, Scam / Malware / Advertising URL in the Response
ATR-2026-01905mediumproductionInjected Advertising / Promotional Copy in the Response
ATR-2026-01906mediumproductionOutput Content Manipulation, Injected Disinformation / Fabricated Facts / Undisclosed Advocacy (Semantic)
ATR-2026-01920highproductionAccess-Grant Coercion, Forcing an Agent to Emit "Access Granted"
ATR-2026-01921highproductionAccess-Denial Inversion, Eliciting the Opposite of "Access Denied"
ATR-2026-01922highproductionAuthorization-State Spoofing, Forged "Correct Passcode Entered" System Text
ATR-2026-01923highproductionForged Input-Boundary Markers, Tensor Trust Ambiguity / Input-End Delimiters
ATR-2026-01925highproductionEncoded-Payload Decoding Coercion, Binary / Base64 / Morse to Smuggle an Output
ATR-2026-01926highproductionCross-Lingual Authorization Laundering, Translate a Foreign "Access Granted"
ATR-2026-02001highproductionIgnore-Below-Instructions Injection (Downstream Override)
ATR-2026-02002highproductionInstruction-Set Probe or Supplant
ATR-2026-02003highproductionTask-Pivot Override: Cover-Task Abandonment
ATR-2026-02004highproductionRegional-Indicator Flag-Emoji Alphabet Letter-Spelling Smuggling
ATR-2026-02005highproductionActor Never-Breaks-Character Roleplay (DAN-Style Film Framing)
ATR-2026-02006highproductionFuzzy Cross-Lingual 'I Have Been PWNED' Near-Miss Obfuscation
ATR-2026-02007highproductionBare Key Elicitation Token Detection
ATR-2026-02008highproductionTranslation-Chain Output Laundering (Forced Phrase via Foreign-Language Auxiliary)
ATR-2026-02009highproductionBare Key Elicitation with Trailing Colon
ATR-2026-02010highproductionEmoji-Only Payload Injection
ATR-2026-02011highproductionMalformed-Grammar PWNED Success-Claim Detection
ATR-2026-02012highproductionMovie Title Generator Instruction Wrapper for PWNED Payload
ATR-2026-02013highproductionDelimiter-Fence Ignore-Instructions Override
ATR-2026-02014highproductionSpliced Target-String Canary Token Evasion
ATR-2026-02015highproductionDense Emoji-Only Payload Flood
ATR-2026-02016highproductionReversed Payload String (HackAPrompt Canary)
ATR-2026-02018highproductionRegional-Indicator Flag-Emoji Letter Spelling
ATR-2026-02019highproductionPython Interpreter Role-Assignment Exec Framing
ATR-2026-02020highproductionObfuscated Token Reconstruction via Character Substitution
ATR-2026-02120highproductionAgentDojo 'Important Message' Identity-Spoof Before-You-Solve Pretext (Generalized)
ATR-2026-02210highproductionNegated-Topic Two-Script Evil-Persona Jailbreak
ATR-2026-02230mediumproductionConditional Keyword-Triggered Response Override
ATR-2026-02232mediumproductionBare Brand/Entity Persona Assignment for Off-Label Opinion Elicitation
ATR-2026-02374criticalproductionROT13/Base64-Obfuscated Shell Payload Wrapped in a Fake-Sandbox Jailbreak Template
ATR-2026-02377highproductionNovel-Persona Jailbreak via Co-Signal (persona swap + explicit restriction removal)
ATR-2026-02500criticalproductionPrompt-Layer Self-Replication (Agent Worm Propagation Directive)
ATR-2026-02502highproductionCovert Remote-Script Injection into Agent-Generated Artifacts
RuleSeverityGradeWhat it catches
ATR-2026-00060highwarnMCP Skill Impersonation and Supply Chain Attack
ATR-2026-00120criticalproductionSKILL.md Prompt Injection
ATR-2026-00121criticalproductionMalicious Code in Skill Package
ATR-2026-00122highproductionWeaponized Skill, Agent as Attack Tool
ATR-2026-00123highproductionOver-Privileged Skill, Excessive Permissions
ATR-2026-00124highproductionSkill Squatting / Typosquatting
ATR-2026-00125highproductionContext Poisoning via Compaction Survival
ATR-2026-00126highproductionSkill Rug Pull Setup Pattern
ATR-2026-00127mediumproductionSubcommand Overflow Bypass
ATR-2026-00128criticalproductionHidden Payload in HTML Comment
ATR-2026-00129criticalproductionUnicode Tag Character Smuggling
ATR-2026-00134mediumproductionFork Claim and Community Package Impersonation
ATR-2026-00135criticalproductionData Exfiltration URL in Skill Instructions
ATR-2026-00147highproductionCommunity Fork Impersonation
ATR-2026-00149criticalproductionSkill Data Exfiltration via Compound Patterns
ATR-2026-00151highproductionMalicious Fork Impersonation via Install Instruction
ATR-2026-00154highproductionUnauthorized Background Task Execution via Cron Job Installation
ATR-2026-00157criticalproductionTime-Gated Credential Exfiltration (Rug Pull Timebomb)
ATR-2026-00200criticalwarnAgent Memory and Configuration File Tampering
ATR-2026-00214criticalproductionCredential Exfiltration via Fake Backup Verification
ATR-2026-00217criticalwarnCredential Harvesting via Fake Backup Tool
ATR-2026-00220criticalproductionBase64 Encoded Remote Code Execution via Raw IP
ATR-2026-00222criticalproductionBrowser Credential Harvesting via Session Debug Tool
ATR-2026-00223criticalproductionMalicious WhatsApp Skill with Base64 Encoded Reverse Shell Installation
ATR-2026-00224criticalproductionCredential Exfiltration via Fake DevOps Tool Initialization
ATR-2026-00225highproductionHardcoded Suspicious IP Address in Skill Content
ATR-2026-00260highproductionLLM Package Hallucination Typosquat Bait
ATR-2026-00262criticalproductionAnti-Malware Evasion Code Generation Request
ATR-2026-00263criticalproductionCredential File Read Code Generation Request
ATR-2026-00266criticalproductionMalware Dropper / Loader Code Generation Request
ATR-2026-00283highproductionMalware Generation, Generic Virus and Specific Payload Request
ATR-2026-00398criticalproductionHuggingFace Unsafe Model Artifact Load Instruction
ATR-2026-00425highproductionNatural-Language Persistent Covert Action Hook
ATR-2026-00427highproductionNatural-Language Fake-Error Instruction Bypass
ATR-2026-00429criticalproductionNatural-Language Skill Self-Modification / Persistence Instruction
ATR-2026-00523criticalproductionClaude Code Hooks SessionStart Pre-Trust RCE (CVE-2025-59536)
ATR-2026-00525criticalproductionMini Shai-Hulud gh-token-monitor Persistence + Dead Man's Switch
ATR-2026-00527criticalproductionSilent git-remote + mirror-push Exfiltration from Skill Instructions
ATR-2026-00565criticalproductionThe llm CLI tool thru 0.27.1 contains a critical code injection vulnerability via its --functions command-line
ATR-2026-01755criticalproductionBackdoor Trojan: Linguistic Trigger Phrase (POT Attack)
ATR-2026-01756criticalproductionBackdoor Trojan: Symbol / Emoticon Trigger (POT Attack)
ATR-2026-02261criticalproductionLanguage-Agnostic Credential Exfiltration Chain (secret read -> encode -> network send)
ATR-2026-02405criticalproductionMalicious AI Skill / MCP Server Package Structure (AgentBaiting / FakeGit)
ATR-2026-02410highproductionMalicious Artifact Hosted on a Legitimate AI Vendor Domain (FakeAgent Delivery Chain)
ATR-2026-02600criticalproductionReverse Shell Assembled In-Source (socket bound to an interactive shell)
ATR-2026-02610highproductionDeveloper-Toolchain Config Evaluates a Command That Reads a Credential Store
ATR-2026-02818highproductionInstallable Skill Manifest Self-Declares an Attack or Jailbreak Purpose
ATR-2026-02845highproductionCryptomining Payload Deployed Through an Agent Skill or Tool Call
RuleSeverityGradeWhat it catches
ATR-2026-00010criticalwarnMalicious Content in MCP Tool Response
ATR-2026-00011highproductionInstruction Injection via Tool Output
ATR-2026-00012highobserveUnauthorized Tool Call Detection
ATR-2026-00013criticalwarnSSRF via Agent Tool Calls
ATR-2026-00061mediumobserveSkill Description-Behavior Mismatch
ATR-2026-00062criticalobserveHidden Capability in MCP Skill
ATR-2026-00063criticalobserveMulti-Skill Chain Attack
ATR-2026-00065highwarnMalicious Skill Update or Mutation
ATR-2026-00066criticalobserveParameter Injection via Tool Arguments
ATR-2026-00095criticalwarnMCP Tool Supply Chain Poisoning
ATR-2026-00096criticalproductionSkill Registry Poisoning and Compromised Tool Distribution
ATR-2026-00100highproductionConsent Bypass via Hidden LLM Instructions in Tool Descriptions
ATR-2026-00101highproductionTrust Escalation via Authority Override Instructions
ATR-2026-00103criticalproductionHidden LLM Safety Bypass Instructions in Tool Descriptions
ATR-2026-00105highproductionSilent Action Concealment Instructions in Tool Descriptions
ATR-2026-00106highproductionSchema-Description Contradiction Attack
ATR-2026-00153criticalproductionTool with embedded instruction to bypass user confirmation and exfiltrate data
ATR-2026-00161criticalobserveMCP Tool Description, IMPORTANT Tag Cross-Tool Shadowing Attack
ATR-2026-00209highproductionMCPwn Runaway Tool Invocation via Retry Directive (CVE-2026-33032)
ATR-2026-00210criticalproductionFlowise System Message Override via Template Interpolation (CVE-2025-59528)
ATR-2026-00259highproductionANSI Escape Code Terminal Injection
ATR-2026-00270highproductionXSS Payload Injection in Tool Response Output
ATR-2026-00277criticalproductionECHO Template / Jinja / SQL Command Injection via LLM
ATR-2026-00393highproductionANSI Code Elicitation Request
ATR-2026-00415criticalproductionFlowise Custom MCP STDIO Command Injection (CVE-2026-40933)
ATR-2026-00419criticalproductionCursor MCP JSON Zero-Click Configuration RCE (CVE-2025-54136)
ATR-2026-00434criticalproductionmcp-remote authorization_endpoint OS Command Injection (CVE-2025-6514)
ATR-2026-00435highproductionAzure MCP Server Missing Authentication for Critical Function (CVE-2026-32211)
ATR-2026-00448highproductionSpring AI MilvusVectorStore Filter Expression Injection (CVE-2026-41705)
ATR-2026-00494criticalproductionSQL Injection and Code Injection Attack Payload Detection
ATR-2026-00513highproductionPackage Hallucination Exploitation, AI-Suggested Fake Package Installation
ATR-2026-00521criticalwarnShell Command Injection in Agent Tool Context
ATR-2026-00522highproductionSQL Injection via Natural Language Agent Interface
ATR-2026-00526criticalproductionClaude Code Shell Metacharacter in Double-Quoted File Path
ATR-2026-00529criticalproductionLiteLLM Proxy SQL Injection (CVE-2026-42208, CISA KEV 2026-05-08)
ATR-2026-00530criticalproductionModelScope MS-Agent Shell Tool Unsanitized Argv RCE (CVE-2026-2256)
ATR-2026-00531criticalproductionPraisonAI Unauthenticated Agent API Exploitation (CVE-2026-44338)
ATR-2026-00532criticalproductionApache Doris MCP Server SQL Injection (CVE-2025-66335)
ATR-2026-00533criticalproductionApache Pinot MCP Unauthenticated Remote Cluster Takeover
ATR-2026-00534highproductionAlibaba RDS MCP Unauthenticated Database Metadata Exfiltration
ATR-2026-00536criticalproductionnginx-ui MCP Endpoint Unauthenticated Command Execution (CVE-2026-33032)
ATR-2026-00537highproductionFastMCP Windows cmd.exe Injection via Server Name Metacharacters (CVE-2025-64340)
ATR-2026-00538criticalproductionLangChain-ChatChat Unauthenticated MCP STDIO Server Configuration RCE (CVE-2026-30617)
ATR-2026-00540criticalproductionPraisonAI parse_mcp_command() CLI Argument Command Injection (CVE-2026-34935)
ATR-2026-00541highproductionAgent Zero MCP Configuration Command Injection via mcp_servers field (CVE-2026-30624)
ATR-2026-00542highproductionUpsonic MCP Command Allowlist Bypass RCE (CVE-2026-30625)
ATR-2026-00543highproductionLiteLLM MCP Server Creation Authenticated argv Injection (CVE-2026-30623)
ATR-2026-00544criticalproductionPraisonAI MCP Path-Traversal .pth Injection RCE (GHSA-9mqq-jqxf-grvw)
ATR-2026-00545criticalproductionPraisonAI tool_override.py Unauthenticated RCE, CVE-2026-40287 Patch Bypass (CVE-2026-44334)
ATR-2026-00561criticalproductionFastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name
ATR-2026-00567highproductionMCP stdio server config command injection via unvalidated test endpoints
ATR-2026-00568highproductionAgent SSRF to cloud metadata / file inclusion via unvalidated fetch URL
ATR-2026-00572criticalproductionSymJack, Symlink Approval-Path Spoofing Redirects Writes into Agent MCP/Config (RCE on Restart)
ATR-2026-00575criticalproductionMiasma / Phantom Gyp, npm Worm Backdoors AI-Agent Config Files (binding.gyp install-exec + auto-run config injection)
ATR-2026-00576criticalproductionHades / Shai-Hulud, AI-Agent Credential Harvester in Supply-Chain Package (Anthropic / Claude / MCP key theft + exfil)
ATR-2026-00577criticalproductionCommand Injection in create-mcp-server-stdio via Unsafe exec() Concatenation (CVE-2025-54994)
ATR-2026-00581highproductionMCP Tool Rug-Pull, Post-Approval Description Redefinition Injects Execution Instructions
ATR-2026-00714highproductionTool Camouflage, Forced Specific Tool Invocation via Injected Instruction
ATR-2026-00715criticalproductionTool Knowledge Hijack, Identity Injection with Tool Call Arguments
ATR-2026-00720mediumproductionTool Misuse, Privilege Escalation via Social Engineering Agent to Grant Access
ATR-2026-01300criticalproductionMCP Tool Description, Notes Parameter Chat-History Exfiltration
ATR-2026-01301highproductionMCP Tool Description, Exclusive Tool Invocation Override
ATR-2026-01302criticalproductionFake Tool Result Prefix, Injected Instruction via Simulated Completion
ATR-2026-01303highproductionTool Schema Enumeration via Social Engineering
ATR-2026-01306criticalproductionMCP OAuth Authorization URL, Command Injection via URL Authority
ATR-2026-01307criticalproductionMCP DNS Rebinding Attack, Hostname Time-Based IP Switching
ATR-2026-01310criticalproductionMCP Tool Description, Compliance/Audit Framing for Mandatory Chat Context
ATR-2026-01775highproductionMCP Tool-Manifest Poisoning, Name Squatting, Result Shadowing & Covert-Action Directives (Semantic)
ATR-2026-01927highproductionmcp-server-kubernetes Command Injection in kubectl_scale / kubectl_patch / explain_resource (CVE-2025-53355)
ATR-2026-01928highproductionFramelink Figma MCP Server curl-Fallback Command Injection (CVE-2025-53967)
ATR-2026-01930highproductionMCP Sampling Prompt Injection (Server-to-Client createMessage Abuse)
ATR-2026-01931criticalproductiongemini-mcp-tool execAsync Command Injection & @file Exfiltration (CVE-2026-0755)
ATR-2026-01932highproductionShadow / Undeclared MCP Server Registration (MCP-38: MCP-18)
ATR-2026-01935criticalproductionLiteLLM Custom-Code Guardrail Sandbox Escape (CVE-2026-40217)
ATR-2026-01952criticalproductionPraisonAI codeMode JS Sandbox Escape RCE via new Function/with() (GHSA-p69m-4f92-2v84)
ATR-2026-01953criticalproductionnpm PraisonAI codeMode Sandbox Escape via Function Constructor Prototype Chain (GHSA-vmmj-pfw7-fjwp)
ATR-2026-01959criticalproductionOpenHuman Shell Tool Allowlist Bypass via Env-Prefix / find -execdir (CVE-2026-55743)
ATR-2026-01963criticalproductionPraisonAI Action Orchestrator step.target Path Traversal Arbitrary File Write RCE (CVE-2026-39305 / GHSA-jfxc-v5g9-38xr)
ATR-2026-01965criticalproductionFlowise Custom MCP node-load-method OS Command RCE (CVE-2025-8943)
ATR-2026-01967criticalproductionDeepChat Mermaid XSS to RCE via Electron IPC MCP Server Registration (CVE-2025-66481 / GHSA-h9f5-7hhf-fqm4)
ATR-2026-01968criticalproductionDeepChat Markdown Deeplink shell.openExternal Protocol Bypass RCE (CVE-2026-43899, GHSA-cp8j-jx7q-7r5f)
ATR-2026-01970criticalproductionPraisonAI FileTools _validate_path normpath Path Traversal (CVE-2026-35615 / GHSA-693f-pf34-72c5)
ATR-2026-01973criticalproductionAnythingLLM Logo Endpoint Path Traversal File Read/Delete (CVE-2024-3025)
ATR-2026-01978criticalproductionAnythingLLM collector /process filename Path Traversal Arbitrary File Deletion (CVE-2023-5832)
ATR-2026-01979criticalproductionPandasAI Interactive Prompt Injection -> Python Sandbox Escape RCE (CVE-2024-12366 / GHSA-vv2h-2w3q-3fx7)
ATR-2026-01980criticalobserveAgentic-Flow MCP Tool-Parameter OS Command Injection (GHSA-vcv2-r9jh-99m5)
ATR-2026-01982mediumproductiondbt-mcp node_selection/resource_type Argument Injection (CVE-2026-44968)
ATR-2026-01983criticalproductionMCP-for-Stata: Command Injection via log_file_name Parameter (CVE-2026-47708)
ATR-2026-01985criticalproductionMCP Connect: Unauthenticated /bridge Endpoint Arbitrary Process Spawn RCE (GHSA-wvr4-3wq4-gpc5)
ATR-2026-01987criticalproductionLangroid SQLChatAgent Prompt-to-SQL Remote Code Execution (CVE-2026-25879)
ATR-2026-02021criticalproductionMCP Inspector Unauthenticated Proxy stdio Command Execution (CVE-2025-49596)
ATR-2026-02022highproductionCurXecute, Cursor .cursor/mcp.json Injected-Server Auto-Exec RCE (CVE-2025-54135)
ATR-2026-02023highproductionEscapeRoute, Filesystem MCP Server Directory Prefix-Bypass (CVE-2025-53110)
ATR-2026-02024highproductionEscapeRoute, Filesystem MCP Symlink Escape to LaunchAgent Persistence (CVE-2025-53109)
ATR-2026-02025highproductionMCP Full Schema Poisoning, Injected Directive in Non-Description inputSchema Field (MCP-11)
ATR-2026-02027criticalproductionDiagnostic Content Remediation Command Injection (Agentjacking)
ATR-2026-02041criticalproductionShell Command Injection via Echo-Marker Proof-of-Concept in Tool Argument
ATR-2026-02102highproductionHTML/Script Injection in Tool Call Argument Targeting a Human-Approval Dashboard
ATR-2026-02141criticalproductionUnsandboxed Command Execution via Dynamic MCP Server Config (command/args Injection)
ATR-2026-02145criticalproductionPython Sandbox Escape via Generator/Coroutine Frame Object Introspection
ATR-2026-02193highproductionSSRF via Non-Canonical IPv6 Encoding of Loopback/Internal Addresses
ATR-2026-02194criticalproductionMalicious Go init() Function Spawning a Process via a Code-Generation Tool
ATR-2026-02233highproductionUnscoped Destructive or Mass-Disclosure Database Operation Request via Natural Language
ATR-2026-02260highproductionRemediation-Framed Command Execution in Tool Response (Agentjacking)
ATR-2026-02263highproductionSQL Injection via Unparameterized Template-Expression Value in Workflow-Automation SQL Node (CVE-2026-59257)
ATR-2026-02350highproductionMCP JSON-RPC Message Carries Case-Duplicate name/arguments Keys to Smuggle an Unauthorized Tool Call
ATR-2026-02352highproductionEmail Search/Reply Tool Argument Breaks Out of IMAP SEARCH Quoted String to Inject IMAP Commands
ATR-2026-02372highproductionUnsigned Automated Task/Validation Feed Invokes npm install / npx -y (Lifecycle-Script RCE)
ATR-2026-02376highproductionMCP Tool Description Defines a Common-Phrase Trigger to Forward Full Conversation History
ATR-2026-02403highproductionMCP Tool Returns Untrusted External Content Carrying Hidden Agent Instructions Without Spotlighting
ATR-2026-02514mediumproductionMCP Server Descriptor URL Field Carries an HTML/Script Breakout Payload
ATR-2026-02542mediumproductionObservability Query Tool Argument Appends a Pipeline Stage and Comments Out the Rest of the Query
ATR-2026-02557highproductionShell Command Separator Inside a Path-Typed MCP Tool Argument
ATR-2026-02666highproductionTrusted Hostname Parked in the URL Userinfo So the Real Host Is Whatever Follows the At-Sign
ATR-2026-02668highproductionBranch or Tag Ref Name Carrying Shell Command Substitution in Tool Output
ATR-2026-02669mediumproductionQuery-Language Pipeline Stage Smuggled Into an Identifier-Typed Tool Parameter
ATR-2026-02682mediumproductionXML/SVG Entity Expansion Bomb in Content Returned to an Agent
ATR-2026-02707highproductionMail or Attachment Tool Argument Splits into a New Header via Embedded CRLF

Back to the start: the tutorial map.