可扩展的 Azure 安全工具(以下简称 E.A.S.T)是一款用于评估 Azure 及一定程度上 Azure AD 安全控制项的工具。EAST 的主要用途是在 Azure 评估中收集安全数据以进行评价。这些信息(JSON 内容)随后可用于各种报告工具,我们利用这些工具进一步关联和调查数据。
此工具基于 MIT 许可证 授权。


目录
v 0.5
miGeneral.jsquery.jsv 0.4
引入预览分支
变更:
安装现已考虑 Azure Cloud Shell 更新版本对依赖项的使用(Cloud Shell 现已安装 Node.js v16 版本)
根据公告检查 Databricks 集群类型
content.json 现按键和内容进行排序。这允许通过 git diff HEAD^1 ¹ 进行差异检查,因为 content.json 具有预定的结果顺序

¹ ⚠️ 提醒:如果希望检查 content.json 的差异,则需要从
.gitignore中“取消忽略” content.json,从而将结果暴露给您可能配置的任何上游仓库。请谨慎使用此功能,并确保您使用此功能的分支没有设置公共上游
更改编程模式以避免使用较大数据集时可能出现的竞态条件。主要是在 for await 风格循环中将 var 改为 let
⚠️ 工具当前状态为 beta
exec() —— 虽然我尚未审查所有路径,但我相信实现 shellcode 执行是轻而易举的。此工具不假设恶意输入,因此建议在将启动参数粘贴到命令行之前先进行审查。为减少代码量,我们使用以下依赖项用于运行和美观(感谢这些出色包的维护者)
运行该工具的其他依赖项: 如果您计划在 Azure Cloud Shell 中运行,则无需安装 Azure CLI:
Azure Cloud Shell (BASH) 或适用的 Linux 发行版 / WSL
| 要求 | 描述 | 安装 |
|---|---|---|
| ✅ AZ CLI | AZ CLI 的使用 | curl -sL https://aka.ms/InstallAzureCLIDeb | sudo bash |
| ✅ Node.js 运行时 14 | EAST 的 Node.js 运行时 | 使用 NVM 安装 |
EAST 提供了三类控制项:基础、高级和组合
无论类型(基础/高级/组合),机器可读的控制项如下所示:```json { "name": "fn-sql-2079", "resource": "/subscriptions/6193053b-408b-44d0-b20f-4e29b9b67394/resourcegroups/rg-fn-2079/providers/microsoft.web/sites/fn-sql-2079", "controlId": "managedIdentity", "isHealthy": true, "id": "/subscriptions/6193053b-408b-44d0-b20f-4e29b9b67394/resourcegroups/rg-fn-2079/providers/microsoft.web/sites/fn-sql-2079", "Description": "\r\n Ensure The Service calls downstream resources with managed identity", "metadata": { "principalId": { "type": "SystemAssigned", "tenantId": "033794f5-7c9d-4e98-923d-7b49114b7ac3", "principalId": "cb073f1e-03bc-440e-874d-5ed3ce6df7f8" }, "roles": [{ "role": [{ "properties": { "roleDefinitionId": "/subscriptions/6193053b-408b-44d0-b20f-4e29b9b67394/providers/Microsoft.Authorization/roleDefinitions/b24988ac-6180-42a0-ab88-20f7382dd24c", "principalId": "cb073f1e-03bc-440e-874d-5ed3ce6df7f8", "scope": "/subscriptions/6193053b-408b-44d0-b20f-4e29b9b67394/resourceGroups/RG-FN-2079", "createdOn": "2021-12-27T06:03:09.7052113Z", "updatedOn": "2021-12-27T06:03:09.7052113Z", "createdBy": "4257db31-3f22-4c0f-bd57-26cbbd4f5851", "updatedBy": "4257db31-3f22-4c0f-bd57-26cbbd4f5851" }, "id": "/subscriptions/6193053b-408b-44d0-b20f-4e29b9b67394/resourceGroups/RG-FN-2079/providers/Microsoft.Authorization/roleAssignments/ada69f21-790e-4386-9f47-c9b8a8c15674", "type": "Microsoft.Authorization/roleAssignments", "name": "ada69f21-790e-4386-9f47-c9b8a8c15674", "RoleName": "Contributor" }] }] }, "category": "Access" },
### 基础
基础控制包括对初始ARM对象的检查,用于简单的“打开/关闭”布尔设置。
**示例:Azure容器注册表管理员用户**
[acr_adminUser](https://github.com/jsa2/east/blob/HEAD/providers/microsoft.containerregistry/functions/acr_adminUser.js)
门户|EAST
-|-
 | ``if (item.properties?.adminUserEnabled == false ){returnObject.isHealthy = true }``
### 高级
高级控制包括对初始ARM对象之外的检查。通常调用新请求以获取有关范围内资源及其与其他服务关系的进一步信息。
**示例:角色分配**
除了检查订阅的角色分配外,还通过Azure AD条件访问报告对MFA进行额外检查,并确保特权账户不仅受到密码保护(具有客户端机密的SPN)。
**示例:Azure数据工厂**
[ADF_pipeLineRuns](https://github.com/jsa2/east/blob/HEAD/providers/microsoft.datafactory/functions/ADF_pipeLineRuns.js)
Azure数据工厂管道映射将管道、活动和数据目标结合在一起,然后通过所述活动的运行历史检查日志中泄露的机密。

---
### 组合
组合控制将来自管道的两个或多个控制结果结合起来,以形成一个或多个新控制。使用组合解决了EAST的两个用例:
1. 你无法保证管道中返回的控制结果的顺序
2. 你需要从单个检查中返回多个控制结果
**示例:[composite_resolve_alerts](https://github.com/jsa2/east/blob/HEAD/composites/composite_resolve_alerts.js)**
1. 从Microsoft Cloud Defender获取订阅检查的警报
2. 为每个资源提供商的警报形成新的控制
## 报告
EAST并不专注于提供自动化报告生成,因为它主要提供带有控制和评估状态的JSON文件。想法是使用单独的工具创建报告,通过markdown生成脚本和诸如[Pandoc](https://github.com/jgm/pandoc#the-universal-markup-converter)之类的工具,自动化这些报告相当简单。
- 虽然重点不在报告上,但此存储库包含使用pandoc创建报告的自动化示例,以便以单一文档格式轻松阅读结果。
虽然此工具不分发pandoc,但可以在创建报告时使用它,因此添加了以下引用:https://github.com/jgm/pandoc/blob/master/CITATION.cff```
cff-version: 1.2.0
title: Pandoc
message: "If you use this software, please cite it as below."
type: software
url: "https://github.com/jgm/pandoc"
authors:
- given-names: John
family-names: MacFarlane
email: [email protected]
orcid: 'https://orcid.org/0000-0003-2557-9090'
- given-names: Albert
family-names: Krewinkel
email: [email protected]
orcid: '0000-0002-9455-0796'
- given-names: Jesse
family-names: Rosenthal
email: [email protected]
本部分指导如何在 BASH@linux 或 Azure Cloud Shell 上的 BASH 中运行此工具(显然 Cloud Shell 也是 Linux,但不需要你有自己的 Linux 机器来使用它)。
⚠️ 如果你在 Cloud Shell 中运行该工具,可能需要重新应用一些安装,因为 Cloud Shell 不会保留各种会话设置。
设置并遗忘 Cloud Shell 上的前提条件```bash curl -o- https://raw.githubusercontent.com/jsa2/EAST/preview/sh/initForuse.sh | bash;
[跳转到下一步](#login-az-cli-and-run-the-scan)
#### 详细前提条件(如果你选择不执行“即忘即用”版本)
**前提条件**```bash
git clone https://github.com/jsa2/EAST --branch preview
cd EAST;
npm install
在云 shell 中安装 Pandoc```bash
wget "https://github.com/jgm/pandoc/releases/download/2.17.1.1/pandoc-2.17.1.1-linux-amd64.tar.gz"; tar xvzf "pandoc-2.17.1.1-linux-amd64.tar.gz" --strip-components 1 -C ~
**在支持APT的发行版上安装pandoc**```bash
# Get pandoc for reporting (first time only)
sudo apt install pandoc
az account clear az login
cd EAST
subId=6193053b-408b-44d0-b20f-4e29b9b67394
node ./plugins/main.js --batch=10 --nativescope=true --roleAssignments=true --helperTexts=true --checkAad=true --scanAuditLogs --composites --subInclude=$subId

**生成报告**
``cd EAST; node templatehelpers/eastReports.js --doc``
- 如果想要在报告中包含所有 Azure 安全基准结果
``cd EAST; node templatehelpers/eastReports.js --doc --asb``
**从云 Shell 导出报告**
`` pandoc -s fullReport2.md -f markdown -t docx --reference-doc=pandoc-template.docx -o fullReport2.docx ``

**Azure DevOps(实验性)**
有一个用于转储管道日志的 Azure DevOps 控件。你可以通过以下示例指定控件运行:``` node ./plugins/main.js --batch=10 --nativescope=true --roleAssignments=true --helperTexts=true --checkAad=true --scanAuditLogs --composites --subInclude=$subId --azdevops "organizationName" ```
---
## Licensing
**Community use**
- Share relevant controls across multiple environments as community effort
**Company use**
- Companies have possibility to develop company specific controls which apply to company specific work. Companies can then control these implementations by decision to share, or not share them based on the operating principle of that company.
**Non IPR components**
- Code logic and functions are under MIT license. since code logic and functions are alredy based on open-source components & vendor API's, it does not make sense to restrict something that is already based on open source
If you use this tool as part of your commercial effort we only require, that you follow the very relaxed terms of [MIT license](https://github.com/jsa2/east/blob/HEAD/LICENSE)
[Read license](https://github.com/jsa2/EAST/blob/public/LICENSE)
---
# Tool operation documentation
## Principles
### AZCLI USE
**Existing tooling enhanced with Node.js runtime**
Use rich and maintained context of [Microsoft Azure CLI](https://github.com/Azure/azure-cli#microsoft-azure-cli) ``login & commands`` with Node.js control flow which supplies enhanced rest-requests and maps results to schema.
- This tool does not include or distribute Microsoft Azure CLI, but rather uses it when it has been installed on the source system (Such as Azure Cloud Shell, which is primary platform for running EAST)
### Speedup
View more [details](https://github.com/jsa2/east/blob/HEAD/speedup.md)
✅ Using Node.js runtime as orchestrator utilises Nodes asynchronous nature allowing batching of requests. Batching of requests utilizes the full extent of Azure Resource Managers incredible speed.
✅ Compared to running requests one-by-one, the speedup can be up to 10x, when Node executes the batch of requests instead of single request at time
## Parameters reference
**Example:**
```shell
node ./plugins/main.js --batch=10 --nativescope --roleAssignments --helperTexts=true --checkAad --scanAuditLogs --composites --shuffle --clearTokens```
Param| Description | Default if undefined
-|-|-
`` --nativescope `` | Currently mandatory parameter | no values
`` --shuffle `` | Can help with throttling. Shuffles the resource list to reduce the possibility of resource provider throttling threshold being met | no values
`` --roleAssignments `` | Checks controls as per [microsoft.authorization](https://github.com/jsa2/east/blob/HEAD/providers/microsoft.authorization/controls/) | no values
`` --includeRG `` | Checks controls with ResourceGroups as per [microsoft.authorization](https://github.com/jsa2/east/blob/HEAD/providers/microsoft.authorization/controls/) | no values
`` --checkAad `` | Checks controls as per [microsoft.azureactivedirectory](https://github.com/jsa2/east/blob/HEAD/providers/microsoft.azureactivedirectory/controls/) | no values
`` --subInclude `` | Defines subscription scope | no default, requires subscriptionID/s, if not defined will enumerate all subscriptions the user have access to
`` --namespace `` | text filter which matches full, or part of the resource ID <br> **example** `` /microsoft.storage/storageaccounts`` all storage accounts in the scope| optional parameter
`` --notIncludes `` | text filter which matches full, or part of the resource ID <br> **example** `` /microsoft.storage/storageaccounts`` all storage accounts in the scope are **excluded**| optional parameter
`` --batch `` | size of batch interval between throttles |5
`` --wait `` | size of batch interval between throttles | 1500
`` --scanAuditLogs `` | optional parameter. When defined in hours will toggle Azure Activity Log scanning for weak authentication events <br> **defined in:** [scanAuditLogs](https://github.com/jsa2/east/blob/HEAD/providers/microsoft.authorization/functions/scanAuditLogs.js) | 24h
`` --composites `` | read [composite](#composite)| no values
`` --clearTokens `` | clears tokens in session folder, use this if you get authorization errors, or have just changed to other `` az login `` account <br> use `` az account clear`` if you want to clear AZ CLI cache too | no values
`` --tag `` | Filter all results in the end based on single tag``--tag=svc=aksdev`` | no values
``--ignorePreCheck`` | use this option when used with browser delegated tokens| no values
``--helperTexts`` | Will append text descriptions from [general](https://github.com/jsa2/east/blob/HEAD/providers/microsoft.general/controls/) to manual controls| no values
``--reprocess`` | Will update results to existing content.json. Useful for incremental runs| no values
**Parameters reference for example report:**
```shell
node templatehelpers/eastReports.js --asb```
Param| Description | Default if undefined
-|-|-
`` --asb `` | gets all ASB results available to users | no values
`` --policy `` | gets all Policy results available to users | no values
`` --doc`` | prints pandoc string for export to console | no values
## (Highly experimental) Running in restricted environments where only browser use is available
Read here [Running in restricted environments](https://github.com/jsa2/EAST/tree/DelegationToken#highly-experimental---bypassing-trusted-device-requirements-for-azure-cli-in-highly-restricted-environments-where-apis-are-available-for-browser-sessions)
## Developing controls
Developer guide including control flow description is here [``dev-guide.md``](https://github.com/jsa2/east/blob/HEAD/dev-guide.md)
## Updates and examples
### Auditing Microsoft.Web provider (Functions and web apps)
✅ Check roles that are assigned to function managed identity in Azure AD and all Azure Subscriptions the audit account has access to <br>
✅ Relation mapping, check which keyVaults the function uses across all subs the audit account has access to<br>
✅ Check if Azure AD authentication is enabled
✅ Check that generation of access tokens to the api requires assigment ``.appRoleAssignmentRequired`` <br>
✅ Audit bindings <br>
- Function or Azure AD Authentication enabled
- Count and type of triggers
<br>
✅ Check if [SCM](https://docs.microsoft.com/en-us/azure/azure-functions/security-concepts#secure-the-scm-endpoint) and [FTP](https://docs.microsoft.com/en-us/azure/azure-functions/security-concepts#disable-ftp) endpoints are secured

### Azure RBAC baseline authorization
⚠️ Detect principals in privileged subscriptions roles protected only by password-based single factor authentication.
- Checks for users without MFA policies applied for set of conditions
- Checks for ServicePrincipals protected only by password (as opposed to using Certificate Credential, workload federation and or workload identity CA policy)
Maps to [App Registration Best Practices](https://docs.microsoft.com/en-us/azure/active-directory/develop/security-best-practices-for-app-registration#credential-configuration)
- *An unused credential on an application can result in security breach. While it's convenient to use <span style="color:red">password</span>. secrets as a credential, we strongly recommend that you use x509 certificates as the only credential type for getting tokens for your application*
``✅State healthy`` - **User result example**
```JSON
{
"subscriptionName": "EAST -msdn",
"friendlyName": "[email protected]",
"mfaResults": {
"oid": "138ac68f-d8a7-4000-8d41-c10ff26a9097",
"appliedPol": [{
"GrantConditions": "challengeWithMfa",
"policy": "baseline",
"oid": "138ac68f-d8a7-4000-8d41-c10ff26a9097"
}],
"checkType": "mfa"
},
"basicAuthResults": {
"oid": "138ac68f-d8a7-4000-8d41-c10aa26a9097",
"appliedPol": [{
"GrantConditions": "challengeWithMfa",
"policy": "baseline",
"oid": "138ac68f-d8a7-4000-8d41-c10aa26a9097"
}],
"checkType": "basicAuth"
},
}
⚠️State unHealthy - Application principal example
{
"subscriptionName": "EAST - HoneyPot",
"friendlyName": "thx138-kvref-6193053b-408b-44d0-b20f-4e29b9b67394",
"creds": {
"@odata.context": "https://graph.microsoft.com/beta/$metadata#servicePrincipals(id,displayName,appId,keyCredentials,passwordCredentials,servicePrincipalType)/$entity",
"id": "babec804-037d-4caf-946e-7a2b6de3a45f",
"displayName": "thx138-kvref-6193053b-408b-44d0-b20f-4e29b9b67394",
"appId": "5af1760e-89ff-46e4-a968-0ac36a7b7b69",
"servicePrincipalType": "Application",
"keyCredentials": [],
"passwordCredentials": [],
"OnlySingleFactor": [{
"customKeyIdentifier": null,
"endDateTime": "2023-10-20T06:54:59.2014093Z",
"keyId": "7df44f81-a52c-4fd6-b704-4b046771f85a",
"startDateTime": "2021-10-20T06:54:59.2014093Z",
"secretText": null,
"hint": null,
"displayName": null
}],
"StrongSingleFactor": []
}
}
Following methods work for contributing for the time being:
| 包 | 美观 | 运行 | 许可 |
|---|
| axios | ✅ | MIT | |
| yargs | ✅ | MIT | |
| jsonwebtoken | ✅ | MIT | |
| chalk | ✅ | MIT | |
| js-beautify | ✅ | MIT |