Bot Templates ============= TRiA ships with over 100 bots focused on Security, Curation, Optimization, and Best Practices. You can use the bots as-is or use them as templates to simplify your bot creation and management. Listed below are the bots that ship with version 17.06 of our software. =============================================================================================================== =============== =================================================================================================== Name Category Description =============================================================================================================== =============== =================================================================================================== :doc:`Big Data Instance Type Audit` Optimization Identify Big Data instances running unapproved instance types :doc:`Big Data Instances Publicly Accessible` Security Identify Big Data instances that are accessible to the public :doc:`Big Data Instances With Low Retention Policy` Security Identify Big Data instances with a retention policy below a threshold (30 days by default) :doc:`Big Data Instances Without Encryption Enabled` Security Identify Big Data instances that do not have encryption enabled :doc:`Big Data Username Audit` Security Identify Big Data instances running noncompliant usernames for the master account :doc:`Cloud Users With Inactive Accounts` Best Practices Identify inactive cloud service users who have not logged into the cloud provider console recently (45 days by default) :doc:`Cloud Users With Older API Keys` Best Practices Identify cloud users with older API key credentials that should be rotated (90 days by default) :doc:`Cloud Users With Unauthorized Policies` Best Practices Identify cloud users running unauthorized policies :doc:`Cloud Users Without MFA Enabled` Security Identify cloud users without two-factor (MFA) enabled :doc:`Clouds With Active Root Account` Best Practices Identify accounts that have root login access active :doc:`Clouds With Weak Password Policy` Best Practices Identify accounts with a weak or missing password policy :doc:`Clouds Without Global API Accounting` Security Identify accounts with API accounting such as AWS CloudTrail inactive/disabled across all regions :doc:`Clouds Without Protected Root Account` Best Practices Identify root login accounts that are not two-factor enabled :doc:`Clouds Without Service Users` Best Practices Identify accounts without any active service users :doc:`Compute Instance Type Audit` Best Practices Audit compute instance types against select clouds :doc:`Database Engine Types` Best Practices Identify unsupported/blacklisted database engines :doc:`Database Instance Daily Backup` Optimization Backup database instances daily with snapshots :doc:`Database Instance Type Audit` Optimization Audit database instance types against select clouds :doc:`Database Instances Not Encrypted` Security Identify database instances that are not encrypted :doc:`Database Instances Publicly Accessible` Security Identify database instances that are accessible to the public :doc:`Database Instances Recently Snapshot` Best Practices Identify database instances with a recent manual snapshot :doc:`Database Instances Username Audit` Security Identify database instances running noncompliant usernames for the master account :doc:`Database Instances With Zero Connections` Optimization Identify database instances with zero connections over a period of time (14 days default) :doc:`Database Security Groups Exposing Public Access` Security Identify database security groups that expose public access :doc:`Databases Not Multi-AZ` Best Practices Identify databases that are not configured across multiple availablity zones for resiliency :doc:`Databases With Low Retention Policy` Best Practices Identify database instances with a retention policy that is too low :doc:`Hypervisors Nearing Saturation` Optimization Identify hypervisors with high instance usage (90 percent by default) :doc:`Hypervisors Not In Service` Optimization Identify hypervisors that are not in a functional state :doc:`Hypervisors With No Instances` Optimization Identify hypervisors that contain zero instances :doc:`Instance Cores Exceed` Optimization Identify instances exceeding a defined number of CPU cores (default is 4 cores) :doc:`Instance Daily Backup` Optimization Backup compute instances daily with private images :doc:`Instance Lifecycle State` Best Practice Identify instances in a particular lifecycle state, e.g., Running :doc:`Instance Lifecycle State Exceeds Threshold` Best Practice This bot identifies instances by their lifecycle state, e.g., Running, and how long they have been in that state, e.g., 7 days. :doc:`Instance Memory Exceeds` Optimization Identify instances exceeding a user-defined amount of GB in RAM (default is 32 GB) :doc:`Instance Security Group Associations` Security Identify instances associated with user-provided Security Groups (n.b., AWS only) :doc:`Instances Averaging High CPU` Optimization Identify compute instances that have been averaging a high CPU over a period of time (n.b., AWS only) :doc:`Instances Averaging Low CPU` Optimization Identify compute instances that have been averaging a low CPU over a period of time (n.b., AWS only) :doc:`Instances Exposing Public SSH` Security Identify compute instances with an attached security group that exposes SSH access to the world (0.0.0.0/0) :doc:`Instances Running 24x7` Optimization Identify compute instances that have been running 24x7 over a period of time (default is 1 day) :doc:`Instances Running Unauthorized Image` Best Practices Identify instances that were created with an unauthorized image :doc:`Instances Scheduler` Optimization Schedule instance stop/start across one or more clouds/resource groups :doc:`Instances Using Unauthorized Root Key Pair` Security Identify instances created without specific SSH key pairs :doc:`Instances With Ephemeral Public IP` Optimization Identify instances with an ephemeral public-facing IP address :doc:`Instances With Ephemeral Root Volume` Optimization Identify instances with an ephemeral root volume :doc:`Instances With Failed Status Checks` Best Practices Identify instances that fail the system/reachability status checks :doc:`Instances With No Name` Best Practices Identify instances that are missing a name :doc:`Instances With TTL` Optimization Identify compute instances with Time To Live (TTL) tags and schedule their deletion accordingly :doc:`Instances Without Tags` Best Practices Identify compute instances without any tag key/value pairs :doc:`Load Balancer Scheme` Security Identify whether a load balancer is internet-facing or internal :doc:`Load Balancers With Access Logging Disabled` Security Identify load balancers that have access logging disabled :doc:`Load Balancers With Connection Draining Disabled` Best Practices Identify load balancers that have connection draining disabled :doc:`Load Balancers With Cross Zone Balancing Disabled` Best Practices Identify load balancers that have cross zone balancing disabled :doc:`Load Balancers With No Instances` Optimization Identify load balancers with no instance associations :doc:`Load Balancers With SSL Listener` Optimization Identify load balancers with an SSL listener :doc:`Load Balancers Without SSL Listener` Security Identify load balancers without an SSL listener :doc:`Memcache Instance Type Audit` Optimization Audit memcache instance types against select clouds :doc:`Network Peering Connections` Security Identify network peering connections (n.b., AWS only) :doc:`Network Resources With Traffic Logging Configured` Security Identify network resources which have traffic logging such as AWS VPC Flow Log enabled :doc:`Network Resources Without Traffic Logging Configured` Security Identify network resources which do not have traffic logging such as AWS VPC Flow Log enabled :doc:`Networks Not On Whitelist With Instances` Security Identify unapproved networks with at least one instance :doc:`Networks With Impaired Flow Logs` Security Identify network resources having their flow log delivery impaired (n.b., AWS only) :doc:`Networks With Instances` Security Identify networks with at least one instance :doc:`Networks With Internet Access` Security Identify networks with an attached Internet gateway :doc:`Networks With No Instances` Optimization Identify networks with zero instances :doc:`Networks Without Internet Access` Best Practices Identify networks without an attached Internet gateway :doc:`Port 21 (FTP) Open to the World` Security Identify TCP port 21 open to the world :doc:`Port 22 (SSH) Open to the World` Security Identify TCP port 22 open to the world :doc:`Port 23 (Telnet) Open to the World` Security Identify TCP port 23 open to the world :doc:`Port 25 (SMTP) Open to the World` Security Identify TCP port 25 open to the world :doc:`Port 53 (DNS) Open to the World` Security Identify TCP/UDP port 53 open to the world :doc:`Port 135 (Windows RPC) Open to the World` Security Identify TCP port 135 open to the world :doc:`Port 137/138 (NetBIOS) Open to the World ` Security Identify UDP 137/138 open to the world :doc:`Port 445 (CIFS) Open to the World` Security Identify TCP/UDP port 445 open to the world :doc:`Port 445 (SMB) Open to the World` Security Identify TCP port 445 open to the world :doc:`Port 1433/1434 (SQL Server) Open to the World` Security Identify TCP port 1433/1434 open to the world :doc:`Port 1443 (Microsoft SQL) Open to the World` Security Identify TCP port 1443 open to the world :doc:`Port 3306 (MySQL) Open to the World` Security Identify TCP port 3306 open to the world :doc:`Port 3389 (Windows RDP) Open to the World` Security Identify TCP port 3389 open to the world :doc:`Port 5432 (PostgresSQL) Open to the World` Security Identify TCP port 5432 open to the world :doc:`Port 5500 (VNC Listener) Open to the World` Security Identify TCP port 5500 open to the world :doc:`Port 5900 (VNC Server) Open to the World` Security Identify TCP port 5900 open to the world :doc:`Ports other than 80/443 (HTTP/HTTPS) Open to the World` Security Identify TCP ports other than 80/443 open to the world :doc:`Protocol (ICMP) Open to the World` Security Identify ICMP open to the world :doc:`Public IP Addresses Orphaned` Optimization Identify unattached IP addresses :doc:`Region Audit` Security Audit select resource types across specific cloud regions :doc:`Region Limits` Optimization Identify regions within 80% or more of the threshold for any resource type :doc:`Region Limits -- Cache Instances` Optimization Identify regions within 80% or more of the cache instance threshold :doc:`Region Limits -- Compute Instances` Optimization Identify regions within 80% or more of the compute instance threshold :doc:`Region Limits -- Database Instances` Optimization Identify regions within 80% or more of the database instance threshold :doc:`Region Limits -- Internet Gateways` Optimization Identify regions within 80% or more of the Internet gateway threshold :doc:`Region Limits -- Private Networks` Optimization Identify regions within 80% or more of the private network threshold :doc:`Region Limits -- Public IPs` Optimization Identify regions within 80% or more of the public IP threshold :doc:`Region Limits -- Security Groups` Optimization Identify regions within 80% or more of the security group threshold :doc:`Region Limits -- Snapshots` Optimization Identify regions within 80% or more of the snapshot threshold :doc:`Region Limits -- Storage Containers` Optimization Identify regions within 80% or more of the storage container threshold :doc:`Region Limits -- Volumes` Optimization Identify regions within 80% or more of the volume threshold :doc:`Regions With Impaired Availability Zone` Best Practices Identify regions with one or more zones in an impaired state :doc:`Regions Without Default Network` Best Practices Identify regions without a default network :doc:`Reserved Instances Expiring Soon` Optimization Identify reserved instances set to expire within a set number of days (default is 30 days) :doc:`Resource Age Check` Best Practices Identify resources based on their age/creation date :doc:`Resource Cost Exceeds` Optimization Identify resources whose monthly cost exceeds a user-defined value (default $100) :doc:`Resource Group Curation` Curation Curate target resources into one or more resource groups :doc:`Resource Has No Owner` Best Practices This bot identifies resources that do not have an owner, which is a basic requirement for effective management of a cloud environment. :doc:`Resources With TTL` Optimization Identify resources with Time To Live (TTL) tags and schedule their deletion accordingly :doc:`Security Groups Orphaned` Security Identify security groups unattached to instances :doc:`Security Rules Audit` Security Identify access lists with ports open to the world (SSH as default) :doc:`Service Encryption Key Disabled` Security Identify encryption keys that are disabled :doc:`Service Encryption Key Expired or Expiring Soon` Security Identify encryption keys that are expired or are expiring within user-defined number of days (default is 14 days) :doc:`Service Encryption Key Rotation Disabled` Security Identify encryption keys that have key rotation disabled :doc:`Snapshots of Type` Best Practices Identify database or memcache snapshots based upon their type, e.g., manual or automated :doc:`Snapshots Older Than X Days` Optimization Identify snapshots that are older than X days, e.g., 30, 60, or 90 :doc:`Snapshots Publicly Available` Security Identify snapshots that are accessible to the public :doc:`SSL Certificates Expired` Security Identify SSL certificates that have expired or will expire soon (14 days by default) :doc:`SSL Certificates With Heartbleed Vulnerability` Security Identify SSL certificates that may be vulnerable to SSL Heartbleed :doc:`Storage Containers Exceeding Max Objects` Optimization Identify storage containers that exceed a total number of objects (10,000 objects by default) :doc:`Storage Containers Exceeding Max Size` Optimization Identify storage containers that exceed a total size (1TB by default) :doc:`Storage Containers Permissions Check` Security Identify storage containers exposing data with permissive access lists :doc:`Storage Containers Permissions Check -- ACL` Security Identify storage containers exposing access list permissions to the world :doc:`Storage Containers Permissions Check -- Delete` Security Identify storage containers exposing delete permissions to the world :doc:`Storage Containers Permissions Check -- Read (GET)` Security Identify storage containers exposing read permissions to the world :doc:`Storage Containers Permissions Check -- Write (PUT)` Security Identify storage containers exposing write permissions to the world :doc:`Storage Containers With No Permissions` Security Identify storage containers without any permission sets :doc:`Storage Containers Without Logging` Security Identify storage containers without logging enabled :doc:`Storage Containers Without Versioning` Security Identify storage containers without object versioning enabled :doc:`Subnet CIDR Exceeds Maximum Netblock` Optimization Identify subnets where the number of IPs exceeds a defined limit :doc:`Subnets Running Out Of Space` Best Practices Identify subnets with limited IP block available for use :doc:`Tag Audit` Best Practices Enforce tagging standards and policy across select resource types :doc:`Volume State Time Threshold` Optimization Identify volumes that have been in a user-selected state for a user-defined period of time (defaults are 'available' and 1 day) :doc:`Volume Type Audit` Best Practices Identify volumes running unapproved types :doc:`Volumes In Error State` Best Practices Identify unhealthy volumes that are not functional :doc:`Volumes Unattached` Optimization Identify unattached volumes :doc:`Volumes With Auto-Termination` Best Practices Volumes With Auto-Termination Identify volumes set to automatically delete when the parent instance is terminated :doc:`Volumes With Excessive IOPS` Optimization Identify volumes with an excessively high number of IOPS :doc:`Volumes Without A Recent Snapshot` Optimization Identify volumes without a snapshot in the past fourteen days :doc:`Volumes Without Encryption Enabled` Optimization Identify volumes without encryption enabled =============================================================================================================== =============== ===================================================================================================