Skip to content

fix: close remaining SCP action gaps and expire cached Wiz webhook secret - #17

Merged
DustyStudy merged 2 commits into
mainfrom
fix/security-review-findings
Sep 21, 2026
Merged

DustyStudy merged 2 commits into
mainfrom
fix/security-review-findings

Conversation

@DustyStudy

@DustyStudy DustyStudy commented Sep 20, 2026 •

Copy link
Copy Markdown
Owner

Summary

Follow-up to a source review of the toolbox. Most findings were already fixed on main by #15; this covers what remained.

  • scp-guardrails / deny-disable-security-services: also deny the current-name GuardDuty and Security Hub administrator-disassociation actions (...FromAdministratorAccount; the legacy ...FromMasterAccount names are separate IAM actions), plus guardduty:DeleteMembers / StopMonitoringMembers and securityhub:BatchDisableStandards / DeleteMembers / DisassociateMembers / DisableOrganizationAdminAccount. Applied to the policy JSON, the CloudFormation template and the Terraform module. All action names were checked against AWS's published service reference. README documents that membership/standards changes now need an exempted role.
  • wiz-finding-bridge: the webhook secret cache now expires after SECRET_CACHE_TTL_SECONDS (default 300). Previously a rotated token kept being accepted by warm Lambda containers until they were recycled. A failed refresh no longer keeps serving the stale value. Both Lambda copies remain identical; READMEs gain a rotation note.

Testing

  • Lambda compiles; a stubbed-boto3 check confirmed cache hit before TTL and refetch after it.
  • terraform fmt -check -recursive terraform passes; policy JSON and CFN SCP literals parse.
  • Not run locally: cfn-lint, Checkov, terraform validate (not installed) - relying on CI.

Notes

  • Behaviour change for anyone who has this SCP attached: those extra actions are now denied outside an exempted role. Try it in a non-production OU first.
  • Deliberately not changed: the Wiz bridge's payload shape vs. this repo's remediators (already documented in the READMEs) and the shared API Gateway throttle (deployment trade-off).

DustyStudy and others added 2 commits September 20, 2026 13:46
…cret

- scp-guardrails: deny-disable-security-services now also denies the
  current-name GuardDuty/Security Hub administrator-disassociation actions
  (the legacy ...FromMasterAccount names are distinct IAM actions),
  guardduty:DeleteMembers/StopMonitoringMembers and
  securityhub:BatchDisableStandards/DeleteMembers/DisassociateMembers/
  DisableOrganizationAdminAccount. Applied to the policy JSON, the
  CloudFormation template and the Terraform module; README documents the
  new break-glass implication.
- wiz-finding-bridge: the webhook secret cache now expires after
  SECRET_CACHE_TTL_SECONDS (default 300), so a rotated token stops being
  accepted within minutes instead of persisting in warm execution
  environments; a failed refresh no longer keeps serving the stale value.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@DustyStudy
DustyStudy merged commit 9ac698d into main Sep 21, 2026
3 checks passed
@DustyStudy
DustyStudy deleted the fix/security-review-findings branch September 21, 2026 14:17
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant