forked from aws-ia/cfn-abi-crowdstrike-fcs
-
Notifications
You must be signed in to change notification settings - Fork 0
/
Copy pathaws_cspm_cloudformation_eb_comm_gov.json
121 lines (121 loc) · 3.22 KB
/
aws_cspm_cloudformation_eb_comm_gov.json
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
{
"AWSTemplateFormatVersion": "2010-09-09",
"Description": "Setup script to enable CrowdStrike Falcon CSPM.",
"Parameters": {
"DefaultEventBusRegion": {
"Type": "String",
"Default": "us-east-1"
}
},
"Resources": {
"CrowdStrikeEventBusRule": {
"Type": "AWS::Events::Rule",
"Properties": {
"Name": "cs-cloudtrail-events-ioa-rule",
"EventPattern": {
"source" : [
{
"prefix" : "aws."
}
],
"detail-type": [
{
"suffix" : "via CloudTrail"
}
],
"detail": {
"eventName": [
{
"anything-but": [
"InvokeExecution",
"Invoke",
"UploadPart"
]
}
],
"readOnly": [
false
]
}
},
"State": "ENABLED",
"Targets": [
{
"Arn": {
"Fn::Sub": "arn:aws:events:${DefaultEventBusRegion}:${AWS::AccountId}:event-bus/default"
},
"RoleArn": {
"Fn::Sub": "arn:aws:iam::${AWS::AccountId}:role/CrowdStrikeCSPMEventBridge"
},
"Id": "CrowdStrikeCentralizeEvents"
}
]
}
},
"CrowdStrikeEventBusRuleRO": {
"Type": "AWS::Events::Rule",
"Properties": {
"Name": "cs-cloudtrail-events-readonly-rule",
"EventPattern": {
"source" : [
{
"prefix" : "aws."
}
],
"detail-type": [
{
"suffix" : "via CloudTrail"
}
],
"detail": {
"readOnly": [
true
]
},
"$or": [
{
"detail": {
"eventName": [
{
"anything-but": [
"GetObject",
"Encrypt",
"Decrypt",
"HeadObject",
"ListObjects",
"GenerateDataKey",
"Sign",
"AssumeRole"
]
}
]
}
},
{
"detail": {
"eventName": ["AssumeRole"],
"userIdentity": {
"type": [{
"anything-but": ["AWSService"]
}]
}
}
}
]
},
"State": "ENABLED",
"Targets": [
{
"Arn": {
"Fn::Sub": "arn:aws:events:${DefaultEventBusRegion}:${AWS::AccountId}:event-bus/default"
},
"RoleArn": {
"Fn::Sub": "arn:aws:iam::${AWS::AccountId}:role/CrowdStrikeCSPMEventBridge"
},
"Id": "CrowdStrikeCentralizeEvents"
}
]
}
}
}
}