Skip to main content

Recommended Configuration for the AWS Solution

The AWS Solution is configured to inherit settings from the global Settings node. You must assign the Connection Profile before job execution. After you assign it to the job group, you can run it directly or schedule it.

Dependencies

For AWS IAM Auditing:

You can scope some of the 0.Collection job group queries to target specific S3 objects. However, populate the SA_AWS_Instances table before scoping the queries. Therefore, manually run the AWS_S3Scan job before scoping the S3 queries.

Target Host

The AWS Data Collector identifies AWS instances via the created Roles and therefore doesn't require you to assign a host list. No target host is required (assign Local Host).

Connection Profile

The AWS Data Collector requires a specific set of permissions. The account used can be either a Web Services (JWT) account or an Amazon Web Services account. After you provision the account, create a custom Connection Profile containing the credentials for the targeted environment. See the Amazon Web Services for User Credentials topic for additional information.

The Connection Profile is assigned under the AWS > Settings > Connection node. It is set to Use Default Profile, as configured at the global Settings level. However, if this isn't the Connection Profile with the necessary permissions for targeting the AWS instances, click the Select one of the following user defined profiles option and select the appropriate Connection Profile.

See the Connection topic for additional information on creating a Connection Profile.

Access Token

Creating the Connection Profile requires the Access Key ID and the Secret Access Key generated by the Amazon Web Services application. See the Configure AWS for Scans topic for additional information.

Schedule Frequency

Schedule the AWS job group to run weekly or daily, depending on the amount of data in the environment. If the target environment has frequent AWS changes, run it more often. Rerun it anytime AWS changes might have occurred.

History Retention

Not supported.

Multi Console Support

Not supported.

Run Order

Run the jobs in the 0.Collection job group first and in order. You can run the other job groups in any order, together or individually, after running the 0.Collection job group.

info

Run the solution at the top level.

Run at the Solution Level

Run the jobs in the AWS job group together and in order by running the entire solution, instead of the individual jobs.

Run at the Job Group Level

For environments with a large amount of S3 data, run the 3.AWS_S3Scan job and the 4.AWS_S3SDDScan job less frequently than the other jobs in the 0.Collection job group.

Query Configuration

The following queries in the 0.Collection job group require you to add the created AWS Roles to the Login Roles page:

You can modify the following queries in the 0.Collection job group to limit the depth of the scan:

Analysis Configuration

You can run this solution with the default analysis configuration. However, you can modify the following parameters:

  • The @STALETHRESHOLD parameter determines the number of days after which content is considered stale. It is set to default of 60 days. You can customize the @STALETHRESHOLD parameter in the following analysis tasks:

    • 2. Users > AWS_StaleUsers > Stale Users Analysis Task
    • 3.Groups > AWS_StaleGroups > Stale Groups Details Analysis Task
    • 4.Roles > AWS_StaleRoles > Stale Roles Details Analysis Task

Workflow

The following is the recommended workflow:

Step 1 – Configure and assign the Connection Profile.

Step 2 – Configure the Scan query to add the AWS Roles to the Login Roles page.

Step 3 – (Optional) Modify query configurations for the 0.Collection job group to limit the scan depth.

Step 4 – (Optional) Modify analysis task parameters for the reporting jobs.

Step 5 – Schedule the AWS job group to run as desired.

Step 6 – Review the reports generated by the AWS job group.