aws-networkfirewall-suricata-rules-string

Suricata rules are free-form plaintext and content matches may accidentally include real tokens, passwords, or confidential protocol values.

awshigh service: aws:networkfirewall emits ContainsSecret

Where it sits

locationDescribeRuleGroup.RuleGroup.RulesSource.RulesString
location kindconfig_field
data kindscredential api_key bearer_token sensitive_data
emits edgeContainsSecret
serviceNetwork Firewall (aws:networkfirewall)

Collection recipe

access moderead_api
operationDescribeRuleGroup
response pathRuleGroup.RulesSource.RulesString
encodingstring
params{"RuleGroupArn": "\u003crule-group-arn\u003e", "Type": "STATEFUL"}

Required permissions

network-firewall:DescribeRuleGroup

References

move · open · esc close