-
Notifications
You must be signed in to change notification settings - Fork 7
Description
Describe the bug
I'm building an Amazon Linux 2, after the scan kicks in and some policies are flagged as Fail/Pass, the scan is always scored as 50. This happens regardless of whether hardening policies are in place (they are being shown as Pass by the scan), or if no extra hardening is in place. No matter what's done, the score is always 50.
This has happened either by using the latest v11.7.3, v11.5.0, or v10.9.2 (I haven't tried with other versions). The version of Packer I am using is v1.11.0, and the version of the Amazon provider is amazon-ebs v1.3.2.
To Reproduce
Steps to reproduce the behavior:
If this code from the examples https://github.com/mondoohq/packer-plugin-cnspec/blob/main/examples/aws/amazon-linux-2.pkr.hcl is used, the parameter score_threshold added (set to 50 and then to 80 for example), and a build attempt is executed with both one with hardening in place and one without, the score should always be 50.
Expected behavior
Correct behavior should be, if the image has been hardened the score should reflect such a thing. An image with multiple Pass should score higher than one with multiple Fails.
Screenshots or CLI Output
Here's a CLI output generating an image without any hardening measure in place (49 Fail):
amazon-ebs.goldenbase: activated sudo
amazon-ebs.goldenbase: detected packer build via ssh
amazon-ebs.goldenbase: no configuration provided
amazon-ebs.goldenbase: successfully updated OS provider
amazon-ebs.goldenbase: use OS provider version 11.2.8 (/home/ceso/.config/mondoo/providers/os)
amazon-ebs.goldenbase: scan packer build in incognito mode
amazon-ebs.goldenbase: Asset: i-0216c37ff10b2fad7
amazon-ebs.goldenbase: --------------------------
amazon-ebs.goldenbase:
amazon-ebs.goldenbase: Checks:
amazon-ebs.goldenbase: ✕ Fail: 25 Ensure ICMP redirects are not accepted
amazon-ebs.goldenbase: ✕ Fail: 40 Ensure suspicious packets are logged
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure events that modify the system's network environment are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure address space layout randomization (ASLR) is enabled
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure the audit configuration is immutable
amazon-ebs.goldenbase: ! Error: Ensure SSH MaxAuthTries is set to 4 or less
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure system administrator actions (sudolog) are collected
amazon-ebs.goldenbase: ! Error: Ensure SSH LoginGraceTime is set to one minute or less
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure events that modify date and time information are collected
amazon-ebs.goldenbase: ✕ Fail: 20 Ensure sudo logging is enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure tftp server is stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: Ensure SSH PermitEmptyPasswords is disabled
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure discretionary access control permission modification events are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure CUPS is stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: Ensure SSH LogLevel is appropriate
amazon-ebs.goldenbase: ✕ Fail: 0 Ensure secure permissions on /etc/passwd- are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure audit log storage size is configured
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure shadow group is empty
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure IP forwarding is disabled
amazon-ebs.goldenbase: ✕ Fail: 40 Ensure SSH access is limited
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure rsyslog is installed
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure successful file system mounts are collected
amazon-ebs.goldenbase: ✕ Fail: 30 Ensure SSH PermitUserEnvironment is disabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/shadow are set
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure journald is configured to send logs to rsyslog
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure DNS server is stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 20 Ensure secure permissions on all log files are set
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure session initiation information is collected
amazon-ebs.goldenbase: ✕ Fail: 0 Ensure secure permissions on SSH private host key files are set
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure filesystem integrity is regularly checked
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure DHCP server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure no duplicate user names exist
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure journald is configured to compress large log files
amazon-ebs.goldenbase: ✕ Fail: 25 Ensure IPv6 router advertisements are not accepted
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/gshadow are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure each user is a member of a group
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure TCP SYN Cookies is enabled
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure changes to system administration scope (sudoers) is collected
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure unsuccessful unauthorized file access attempts are collected
amazon-ebs.goldenbase: ! Error: Ensure SSH Idle Timeout Interval is configured
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure bogus ICMP responses are ignored
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure Samba is stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure SSH X11 forwarding is disabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure FTP server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure vulnerable OpenSSL version 3.0.0 - 3.0.6 are not installed
amazon-ebs.goldenbase: ✕ Fail: 20 Ensure only strong MAC algorithms are used
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure source routed packets are not accepted
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure NIS server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure broadcast ICMP requests are ignored
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure rsyslog Service is enabled
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure login and logout events are collected
amazon-ebs.goldenbase: ✕ Fail: 30 Ensure SSH HostbasedAuthentication is disabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure rsync service is stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 25 Ensure secure ICMP redirects are not accepted
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure no duplicate GIDs exist
amazon-ebs.goldenbase: ✕ Fail: 0 Ensure SSH root login is disabled or set to prohibit-password
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/passwd are set
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure events that modify the system's Mandatory Access Controls are collected
amazon-ebs.goldenbase: ✕ Fail: 40 Ensure rsyslog default file permissions configured
amazon-ebs.goldenbase: ✓ Pass: Ensure disk usage is under 80%
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure Reverse Path Filtering is enabled
amazon-ebs.goldenbase: ✕ Fail: 60 Ensure system is disabled when audit logs are full
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure HTTP servers are stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure journald is configured to write logfiles to persistent disk
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure LDAP server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure HTTP Proxy server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure rsh server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: Ensure secure permissions on SSH public host key files are set
amazon-ebs.goldenbase: ✕ Fail: 0 Ensure only strong ciphers are used
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure SNMP server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure no duplicate group names exist
amazon-ebs.goldenbase: ✕ Fail: 0 Ensure that strong Key Exchange algorithms are used
amazon-ebs.goldenbase: ✕ Fail: 60 Ensure audit logs are not automatically deleted
amazon-ebs.goldenbase: ✕ Fail: 0 Ensure EDR Agent is installed
amazon-ebs.goldenbase: ✕ Fail: Ensure SSH IgnoreRhosts is enabled
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure file deletion events by users are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure system accounts are non-login
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure all GIDs in /etc/passwd exist in /etc/group
amazon-ebs.goldenbase: ✕ Fail: 40 Ensure NFS and RPC are stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure auditing for processes that start prior to auditd is enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure Avahi server is stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 20 Ensure access to the su command is restricted
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure mail transfer agent is configured for local-only mode
amazon-ebs.goldenbase: ✕ Fail: 0 Ensure secure permissions on /etc/group- are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure X Window System is not installed
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/group are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure auditd service is enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure talk server is stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 40 Ensure Advanced Intrusion Detection Environment (AIDE) is installed
amazon-ebs.goldenbase: ✕ Fail: 70 Ensure SSH warning banner is configured
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure core dumps are restricted
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure kernel module loading and unloading is collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure IMAP and POP3 server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/shadow- are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure root group is empty
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure default group for the root account is GID 0
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure events that modify user/group information are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/gshadow- are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/ssh/sshd_config are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure telnet server is stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 20 Ensure SSH Protocol is set to 2
amazon-ebs.goldenbase: ✕ Fail: 25 Ensure packet redirect sending is disabled
amazon-ebs.goldenbase: ✓ Pass: Ensure memory usage is under 80%
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure UID_MIN is set to 1000
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure prelink is disabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure no duplicate UIDs exist
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure auditd is installed
amazon-ebs.goldenbase:
amazon-ebs.goldenbase:
amazon-ebs.goldenbase: Scanned 1 asset
amazon-ebs.goldenbase:
amazon-ebs.goldenbase: Amazon Linux 2
amazon-ebs.goldenbase: [50/100] i-0216c37ff10b2fad7
and here, it's an output with some hardening in place (notice most of the scoring is a Pass, only 11 are a Fail) and despite this, the final score remains unchanged):
amazon-ebs.goldenbase: activated sudo
amazon-ebs.goldenbase: detected packer build via ssh
amazon-ebs.goldenbase: no configuration provided
amazon-ebs.goldenbase: successfully updated OS provider
amazon-ebs.goldenbase: use OS provider version 11.2.8 (/home/ceso/.config/mondoo/providers/os)
amazon-ebs.goldenbase: scan packer build in incognito mode
amazon-ebs.goldenbase: Asset: i-06457369078b227fb
amazon-ebs.goldenbase: --------------------------
amazon-ebs.goldenbase:
amazon-ebs.goldenbase: Checks:
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure mail transfer agent is configured for local-only mode
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure talk server is stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 20 Ensure secure permissions on all log files are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure IPv6 router advertisements are not accepted
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/gshadow are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure Samba is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/ssh/sshd_config are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure IMAP and POP3 server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure no duplicate GIDs exist
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure events that modify the system's Mandatory Access Controls are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure LDAP server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure Reverse Path Filtering is enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/group- are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure NIS server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure source routed packets are not accepted
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/shadow are set
amazon-ebs.goldenbase: ✕ Fail: 40 Ensure Advanced Intrusion Detection Environment (AIDE) is installed
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure SNMP server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure events that modify date and time information are collected
amazon-ebs.goldenbase: ✓ Pass: Ensure memory usage is under 80%
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure no duplicate group names exist
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure Avahi server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/passwd are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure system administrator actions (sudolog) are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure session initiation information is collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure CUPS is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure file deletion events by users are collected
amazon-ebs.goldenbase: ✕ Fail: 0 Ensure that strong Key Exchange algorithms are used
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure login and logout events are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure SSH LoginGraceTime is set to one minute or less
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure SSH MaxAuthTries is set to 4 or less
amazon-ebs.goldenbase: ✕ Fail: 60 Ensure audit logs are not automatically deleted
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure filesystem integrity is regularly checked
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure address space layout randomization (ASLR) is enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure changes to system administration scope (sudoers) is collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/gshadow- are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure rsync service is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure all GIDs in /etc/passwd exist in /etc/group
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure SSH PermitEmptyPasswords is disabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure audit log storage size is configured
amazon-ebs.goldenbase: ✕ Fail: 40 Ensure SSH access is limited
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure each user is a member of a group
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on SSH private host key files are set
amazon-ebs.goldenbase: ✕ Fail: 60 Ensure system is disabled when audit logs are full
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure rsyslog default file permissions configured
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure events that modify user/group information are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure DNS server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/shadow- are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure only strong MAC algorithms are used
amazon-ebs.goldenbase: ✓ Pass: Ensure disk usage is under 80%
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure telnet server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: Ensure SSH PermitUserEnvironment is disabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure the audit configuration is immutable
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure core dumps are restricted
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure SSH Protocol is set to 2
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure SSH root login is disabled or set to prohibit-password
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure rsyslog is installed
amazon-ebs.goldenbase: ✓ Pass: Ensure SSH X11 forwarding is disabled
amazon-ebs.goldenbase: ✕ Fail: 20 Ensure access to the su command is restricted
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure system accounts are non-login
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure shadow group is empty
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure auditd service is enabled
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure discretionary access control permission modification events are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure ICMP redirects are not accepted
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure ICMP redirects are not accepted
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure successful file system mounts are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure no duplicate UIDs exist
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure SSH LogLevel is appropriate
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure X Window System is not installed
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure broadcast ICMP requests are ignored
amazon-ebs.goldenbase: ✓ Pass: Ensure SSH IgnoreRhosts is enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/passwd- are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure root group is empty
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure bogus ICMP responses are ignored
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure vulnerable OpenSSL version 3.0.0 - 3.0.6 are not installed
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure tftp server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure no duplicate user names exist
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure TCP SYN Cookies is enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure journald is configured to compress large log files
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure default group for the root account is GID 0
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure HTTP Proxy server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: Ensure secure permissions on SSH public host key files are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure FTP server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure IP forwarding is disabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure HTTP servers are stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure suspicious packets are logged
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure DHCP server is stopped and not enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure SSH warning banner is configured
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure events that modify the system's network environment are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure journald is configured to write logfiles to persistent disk
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure rsyslog Service is enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure journald is configured to send logs to rsyslog
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure auditd is installed
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure sudo logging is enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure packet redirect sending is disabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure NFS and RPC are stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 50 Ensure auditing for processes that start prior to auditd is enabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure secure permissions on /etc/group are set
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure prelink is disabled
amazon-ebs.goldenbase: ✓ Pass: Ensure SSH HostbasedAuthentication is disabled
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure kernel module loading and unloading is collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure UID_MIN is set to 1000
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure rsh server is stopped and not enabled
amazon-ebs.goldenbase: ✕ Fail: 0 Ensure EDR Agent is installed
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure only strong ciphers are used
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure unsuccessful unauthorized file access attempts are collected
amazon-ebs.goldenbase: ✓ Pass: 100 Ensure SSH Idle Timeout Interval is configured
amazon-ebs.goldenbase:
amazon-ebs.goldenbase:
amazon-ebs.goldenbase: Scanned 1 asset
amazon-ebs.goldenbase:
amazon-ebs.goldenbase: Amazon Linux 2
amazon-ebs.goldenbase: [50/100] i-06457369078b227fb
amazon-ebs.goldenbase:
amazon-ebs.goldenbase:
Desktop (please complete the following information):
- OS: Ubuntu
- OS Version: 22.04
- Browser if applicable: N/A
- Browser Version: N/A
Additional context
The same behavior happens either by running Packer locally in my machine or by running from this Docker container: https://hub.docker.com/r/hashicorp/packer.