> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security.md).

# IaC Security

- [AI And Machine Learning](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning.md)
- [AWS SageMaker notebook instance not configured with data encryption at rest using KMS key misconfigu](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-22.md)
- [AWS SageMaker endpoint data encryption at rest not configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-98.md)
- [AWS SageMaker notebook instance configured with direct internet access feature misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-122.md)
- [AWS Sagemaker domain not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-187.md)
- [AWS Kendra index Server side encryption does not use Customer Managed Keys (CMKs) misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-262.md)
- [AWS SageMaker notebook instance with root access enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-307.md)
- [AWS Sagemaker data quality job not encrypting model artifacts with KMS misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-367.md)
- [AWS Sagemaker data quality job not using KMS to encrypt data on attached storage volume misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-368.md)
- [AWS Sagemaker data quality job not encrypting communications between instances used for monitoring j](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-369.md)
- [AWS SageMaker model does not use network isolation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-370.md)
- [AWS SageMaker notebook instance allows for IMDSv1 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-371.md)
- [AWS SageMaker Flow Definition does not use KMS for output configurations misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-372.md)
- [AWS Bedrock agent is not associated with Bedrock guardrails misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-aws-383.md)
- [Azure Synapse Workspaces do not enable managed virtual networks misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-58.md)
- [Azure Cognitive Services account configured with public network access misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-134.md)
- [Azure Machine Learning Compute Cluster Local Authentication is enabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-142.md)
- [Azure Machine Learning Workspace is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-144.md)
- [Azure Machine Learning Compute Cluster Minimum Nodes is not set to 0 misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-150.md)
- [Azure Data exfiltration protection for Azure Synapse workspace is disabled misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-157.md)
- [Azure Databricks workspace is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-158.md)
- [Azure Cognitive Services account configured with local authentication misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-236.md)
- [Azure Cognitive Services account is not configured with managed identity misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-238.md)
- [Azure Synapse workspace administrator login password exposed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-239.md)
- [Azure Synapse Workspace not encrypted with a Customer Managed Key (CMK) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-240.md)
- [Azure Synapse SQL pool not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-241.md)
- [Azure Synapse Spark Pool not using isolated compute misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-242.md)
- [Azure Machine learning workspace is not configured with private endpoint misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-243.md)
- [Azure Cognitive Services account hosted with OpenAI is not configured with data loss prevention misc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-azure-247.md)
- [GCP Vertex AI datasets do not use a Customer Manager Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-92.md)
- [GCP Vertex AI Metadata Store does not use a Customer Manager Key (CMK) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-96.md)
- [GCP Dataproc Clusters have public IPs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-103.md)
- [GCP DataFusion does not have stack driver logging enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-104.md)
- [GCP DataFusion does not have stack driver monitoring enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-105.md)
- [GCP Vertex AI Workbench user-managed notebook has vTPM disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-126.md)
- [GCP Vertex AI Workbench user-managed notebook has Integrity monitoring disabled misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec-gcp-127.md)
- [AWS SageMaker notebook instance IAM policy is overly permissive misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-aws-68.md)
- [Azure Synapse workspaces have IP firewall rules attached misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-19.md)
- [Azure Cognitive Services does not Customer Managed Keys (CMKs) for encryption misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-22.md)
- [Azure Synapse Workspace vulnerability assessment is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-46.md)
- [Azure Databricks Workspaces not using customer-managed key for root DBFS encryption misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-48.md)
- [Azure Machine learning workspace configured with overly permissive network access misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-49.md)
- [Azure Storage Account storing Machine Learning workspace high business impact data is publicly acces](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-50.md)
- [Azure Synapse SQL Pool does not have a security alert policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-51.md)
- [Azure Synapse SQL Pool vulnerability assessment disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-52.md)
- [Azure Synapse Workspace does not have extended audit logs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-53.md)
- [Log monitoring disabled for Azure Synapse SQL Pool misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-azure-54.md)
- [Vertex AI endpoint is not using a Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-24.md)
- [Vertex AI featurestore is not configured to use a Customer Managed Key (CMK) misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-25.md)
- [Vertex AI tensorboard does not use a Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-26.md)
- [Vertex AI endpoint is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-33.md)
- [Vertex AI index endpoint is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-34.md)
- [Vertex AI runtime is not encrypted with a Customer Managed Key (CMK) misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-35.md)
- [Vertex AI runtime is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/ai-and-machine-learning/appsec2-gcp-36.md)
- [Compute](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute.md)
- [Alibaba Cloud RDS instance is not set to perform auto upgrades for minor versions misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ali-30.md)
- [Disabled Ansible URI certificate validation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-1.md)
- [Certificate validation disabled with Ansible get\_url module misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-2.md)
- [SSL certificate validation disabled with Ansible Yum misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-3.md)
- [SSL validation is disabled with yum misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-4.md)
- [Usage of packages with unauthenticated or missing signatures allowed misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-5.md)
- [Usage of the force parameter disabling signature validation allowed misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-ansible-6.md)
- [AWS Lambda functions with tracing not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-50.md)
- [API Gateway does not have X-Ray tracing enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-73.md)
- [AWS EC2 instance not configured with Instance Metadata Service v2 (IMDSv2) misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-79.md)
- [AWS EMR cluster is not configured with Kerberos Authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-114.md)
- [AWS Lambda function is not configured for function-level concurrent execution Limit misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-115.md)
- [AWS Lambda function is not configured for a DLQ misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-116.md)
- [AWS Lambda Function is not assigned to access within VPC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-117.md)
- [AWS API Gateway caching is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-120.md)
- [Autoscaling groups did not supply tags to launch configurations misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-153.md)
- [ECR image scan on push is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-163.md)
- [AWS MQBroker's minor version updates are disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-207.md)
- [AWS MQBroker version is not up to date misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-208.md)
- [AWS Batch Job is defined as a privileged container misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-210.md)
- [AWS API deployments do not enable Create before Destroy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-217.md)
- [AWS DMS replication instance automatic version upgrade disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-222.md)
- [AWS API Gateway method settings do not enable caching misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-225.md)
- [AWS DB instance does not get all minor upgrades automatically misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-226.md)
- [AWS ACM certificate does not enable Create before Destroy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-233.md)
- [Ensure AWS API gateway enables Create before Destroy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-237.md)
- [AWS HTTP and HTTPS target groups do not define health check misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-261.md)
- [AWS Lambda function is not configured to validate code-signing misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-272.md)
- [API Gateway method setting is not set to encrypted caching misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-308.md)
- [RDS cluster is not configured to copy tags to snapshots misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-313.md)
- [EC2 Auto Scaling groups are not utilizing EC2 launch templates misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-315.md)
- [AWS CodeBuild project environment privileged mode is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-316.md)
- [Elasticsearch domains are not configured with a minimum of three dedicated master nodes misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-318.md)
- [Redshift clusters are not using the default database name. misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-320.md)
- [Redshift clusters are not using enhanced VPC routing misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-321.md)
- [AWS ElastiCache Redis cluster automatic version upgrade disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-322.md)
- [ECS Fargate services are not ensured to run on the latest Fargate platform version misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-332.md)
- [AWS ECS task definition elevated privileges enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-334.md)
- [ECS task definitions have their own unique process namespace or share the host's process namespace m](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-335.md)
- [AWS ECS task definition is not configured with read-only access to container root filesystems miscon](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-336.md)
- [AWS Elastic Beanstalk environment managed platform updates are not enabled misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-340.md)
- [AWS Auto Scaling group launch configuration configured with Instance Metadata Service hop count grea](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-341.md)
- [Runtime of Lambda is deprecated misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-363.md)
- [Hard-coded secrets found in Parameter Store values misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-384.md)
- [Potential WhoAMI name confusion attack exposure misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-386.md)
- [AWS SQS queue access policy is overly permissive misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-aws-387.md)
- [Secrets are exposed in Azure VM customData misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-45.md)
- [Azure Linux scale set does not use an SSH key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-49.md)
- [Virtual Machine extensions are installed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-50.md)
- [Azure App Service Web app doesn't use latest .Net framework version misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-80.md)
- [Azure App Service Web app does not use latest PHP version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-81.md)
- [Azure App Service Web app does not use latest Python version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-82.md)
- [Azure App Service Web app does not use latest Java version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-83.md)
- [Azure Linux and Windows Virtual Machines does not utilize Managed Disks misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-92.md)
- [Automatic OS image patching is disabled for Virtual Machine scale sets misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-95.md)
- [Azure Data Factory does not use Git repository for source control misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-103.md)
- [Azure Service Fabric cluster not configured with cluster protection level security misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-126.md)
- [Azure Container Registry (ACR) Isn't Configured to Use Signed/Trusted Images misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-164.md)
- [Azure Kubernetes Cluster (AKS) Nodes Don't Limit the Maximum Pods to Greater than 50 misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-168.md)
- [Azure Kubernetes Cluster (AKS) Nodes Do Not Use Scale Sets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-169.md)
- [AKS Doesn't Use the Paid SKU for its SLA misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-170.md)
- [AKS Cluster Without Upgrade Channel misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-171.md)
- [Windows VM Without Automatic Updates misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-177.md)
- [VM Without Azure VM Agent Installed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-179.md)
- [App Configuration Not Using Standard SKU misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-188.md)
- [Azure App Service Plan is Not Suitable for Production misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-211.md)
- [Azure App Service Not Always On misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-214.md)
- [Operating system disks are not ephemeral disks misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-226.md)
- [Non-Critical System Pods Run on System Nodes misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-azure-232.md)
- [Healthcheck instructions have not been added to container images misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-2.md)
- [A user for the container has not been created misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-3.md)
- [Copy is not used instead of Add in Dockerfiles misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-4.md)
- [Update instructions are used alone in a Dockerfile misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-5.md)
- [LABEL maintainer is used instead of MAINTAINER (deprecated) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-6.md)
- [Base image uses a latest version tag misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-7.md)
- [Last USER is root misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-8.md)
- [Docker APT is used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-9.md)
- [Docker WORKDIR values are not absolute paths misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-10.md)
- [Docker From alias is not unique for multistage builds misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-docker-11.md)
- [GCP Kubernetes Engine Clusters not using Container-Optimized OS for Node image misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-22.md)
- [GCP Kubernetes Engine Clusters have legacy compute engine metadata endpoints enabled misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-67.md)
- [GCP Kubernetes cluster shielded GKE node with Secure Boot disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-68.md)
- [GCP Kubernetes cluster Shielded GKE Nodes feature disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-71.md)
- [GCP SQL database does not use the latest Major version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-79.md)
- [GKE NodePool configuration managed at cluster level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-gcp-123.md)
- [Containers wishing to share host process ID namespace admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-1.md)
- [Privileged containers are admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-2.md)
- [Containers wishing to share host IPC namespace admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-3.md)
- [Root containers admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-6.md)
- [Containers with NET\_RAW capability admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-7.md)
- [CPU request is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-10.md)
- [CPU limits are not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-11.md)
- [Memory requests are not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-12.md)
- [Memory limits are not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-13.md)
- [Image tag is not set to Fixed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-14.md)
- [Image pull policy is not set to Always misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-15.md)
- [Container is privileged misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-16.md)
- [Containers share host process ID namespace misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-17.md)
- [Containers share host IPC namespace misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-18.md)
- [Containers run with AllowPrivilegeEscalation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-20.md)
- [Default namespace is used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-21.md)
- [Read-Only filesystem for containers is not used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-22.md)
- [Admission of root containers not minimized misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-23.md)
- [Containers with added capability are allowed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-24.md)
- [Admission of containers with added capability is not minimized misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-25.md)
- [Mounting Docker socket daemon in a container is not limited misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-27.md)
- [Admission of containers with NET\_RAW capability is not minimized misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-28.md)
- [securityContext is not applied to pods and containers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-29.md)
- [securityContext is not applied to pods and containers in container context misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-30.md)
- [seccomp is not set to Docker/Default or Runtime/Default misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-31.md)
- [seccomp profile is not set to Docker/Default or Runtime/Default misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-32.md)
- [Kubernetes dashboard is deployed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-33.md)
- [Tiller (Helm V2) is deployed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-34.md)
- [Admission of containers with capabilities assigned is not minimised misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-36.md)
- [Admission of containers with capabilities assigned is not limited misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-37.md)
- [CAP\_SYS\_ADMIN Linux capability is used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-39.md)
- [Containers do not run with a high UID misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-40.md)
- [Images are not selected using a digest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-43.md)
- [Tiller (Helm v2) service is not deleted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-44.md)
- [The admission control plugin EventRateLimit is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-78.md)
- [The admission control plugin AlwaysAdmit is set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-79.md)
- [The admission control plugin AlwaysPullImages is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-80.md)
- [The admission control plugin NamespaceLifecycle is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-83.md)
- [The --terminated-pod-gc-threshold argument for controller managers is not set appropriately misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-106.md)
- [The --streaming-connection-idle-timeout argument is set to 0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-143.md)
- [The --protect-kernel-defaults argument is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-144.md)
- [The --hostname-override argument is set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-k8s-146.md)
- [OCI Compute Instance boot volume has in-transit data encryption is disabled misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-oci-4.md)
- [OCI Compute Instance has Legacy MetaData service endpoint enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-oci-5.md)
- [Operation objects do not have the 'produces' field defined for GET operations misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-openapi-16.md)
- [Operation objects for PUT, POST, and PATCH operations do not have a 'consumes' field defined misconf](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-openapi-17.md)
- [Array does not have a maximum number of items misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec-openapi-21.md)
- [DNF usage of packages with untrusted or missing GPG signatures allowed misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-ansible-4.md)
- [SSL validation disabled within Ansible DNF module misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-ansible-5.md)
- [Certificate validation disabled within Ansible DNF module misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-ansible-6.md)
- [AWS Elasticsearch domain has Dedicated master set to disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-aws-59.md)
- [Azure Virtual Machines does not utilise Managed Disks misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-azure-9.md)
- [Microsoft Antimalware is not configured to automatically update Virtual Machines misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-azure-10.md)
- [Dockerfile contains the use of 'sudo' misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-1.md)
- [Dockerfile certificate validation is disabled with curl misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-2.md)
- [Dockerfile certificate validation is disabled with wget misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-3.md)
- [Dockerfile certificate validation is disabled with the pip '--trusted-host' option misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-4.md)
- [Dockerfile certificate validation is disabled with the PYTHONHTTPSVERIFY environment variable miscon](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-5.md)
- [Dockerfile Node.js certificate validation is disabled with the NODE\_TLS\_REJECT\_UNAUTHORIZED environm](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-6.md)
- [Dockerfile APK package manager is configured to allow untrusted repositories misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-7.md)
- [Dockerfile APT package manager is configured to allow unauthenticated packages misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-8.md)
- [Dockerfile YUM package manager is configured to skip GPG signature checks misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-9.md)
- [Dockerfile RPM package manager is configured to skip package signature checks misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-10.md)
- [Dockerfile APT package manager is configured to force package installations without prompts or verif](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-11.md)
- [Dockerfile configuration disables strict SSL for NPM misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-12.md)
- [Dockerfile sets NPM configuration to disable strict SSL misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-13.md)
- [Dockerfile configures GIT to disable SSL verification misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-14.md)
- [Dockerfile sets YUM configuration to disable SSL verification misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-15.md)
- [Dockerfile uses a trusted host with pip misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-docker-16.md)
- [GCP Kubernetes Engine Clusters have Alpha cluster feature enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/compute/appsec2-gcp-19.md)
- [IAM](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam.md)
- [Alibaba Cloud RAM password policy does not have a minimum of 14 characters misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-13.md)
- [Alibaba Cloud RAM password policy does not have a number misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-14.md)
- [Alibaba Cloud RAM password policy does not have a symbol misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-15.md)
- [Alibaba Cloud RAM password policy does not expire in 90 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-16.md)
- [Alibaba Cloud RAM password policy does not have a lowercase character misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-17.md)
- [Alibaba Cloud RAM password policy does not prevent password reuse misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-18.md)
- [Alibaba Cloud RAM password policy does not have an uppercase character misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-19.md)
- [Alibaba Cloud RAM password policy maximal login attempts is more than 4 misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-23.md)
- [Alibaba Cloud RAM does not enforce MFA misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-24.md)
- [Alibaba Cloud KMS Key Rotation is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-27.md)
- [Alibaba Cloud KMS Key is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-ali-28.md)
- [AWS IAM policies that allow full administrative privileges are created misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-1.md)
- [AWS Customer Master Key (CMK) rotation is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-7.md)
- [AWS IAM password policy does not expire in 90 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-9.md)
- [AWS IAM password policy does not have a minimum of 14 characters misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-10.md)
- [AWS IAM password policy does not have a lowercase character misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-11.md)
- [AWS IAM password policy does not have a number misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-12.md)
- [AWS IAM password policy does allow password reuse misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-13.md)
- [AWS IAM password policy does not have a symbol misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-14.md)
- [AWS IAM password policy does not have an uppercase character misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-15.md)
- [AWS Private ECR repository policy is overly permissive misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-32.md)
- [AWS KMS Key policy overly permissive misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-33.md)
- [AWS IAM policy attached to users misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-40.md)
- [AWS IAM policy documents do not allow \* (asterisk) as a statement's action misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-49.md)
- [AWS IAM role allows all services or principals to be assumed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-60.md)
- [AWS IAM policy allows all principals used by any AWS service from target account to assume role misc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-61.md)
- [AWS IAM policies that allow full "-" administrative privileges are created misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-62.md)
- [AWS IAM policy documents allow \* (asterisk) as a statement's action misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-63.md)
- [SQS policy allows all actions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-72.md)
- [Credentials exposure actions return credentials in an API response misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-107.md)
- [Data exfiltration allowed without resource constraints misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-108.md)
- [Resource exposure allows modification of policies and exposes resources misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-109.md)
- [IAM policies allow privilege escalation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-110.md)
- [Write access allowed without constraint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-111.md)
- [Respective logs of Amazon RDS are disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-129.md)
- [RDS database does not have IAM authentication enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-161.md)
- [AWS RDS cluster not configured with IAM authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-162.md)
- [Glacier Vault access policy is public and not restricted to specific services or principals misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-167.md)
- [SQS queue policy is public and access is not restricted to specific services or principals misconfig](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-168.md)
- [SNS topic policy is public and access is not restricted to specific services or principals misconfig](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-169.md)
- [AWS AMI launch permissions are not limited misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-205.md)
- [AWS Key Management Service (KMS) key is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-227.md)
- [AWS Execution Role ARN and Task Role ARN are different in ECS Task definitions misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-249.md)
- [AWS Codecommit branch changes has less than 2 approvals misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-257.md)
- [AWS Lambda function URL AuthType set to NONE misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-258.md)
- [Access is not controlled through Single Sign-On (SSO) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-273.md)
- [AWS AdministratorAccess policy is used by IAM roles, users, or groups misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-274.md)
- [IAM policy uses the AWS AdministratorAccess policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-275.md)
- [IAM Policy Document Allows All or Any AWS Principal Permissions to Resources misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-283.md)
- [AWS IAM Policy permission may cause privilege escalation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-286.md)
- [IAM policies allow exposure of credentials misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-287.md)
- [IAM policies allow data exfiltration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-288.md)
- [IAM policies allow permissions management or resource exposure without constraints misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-289.md)
- [IAM policies allow write access without constraints misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-290.md)
- [AWS Lambda Function resource-based policy is overly permissive misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-301.md)
- [Authorization type for API GatewayV2 routes is not specified misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-309.md)
- [AWS Access key enabled on root account misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-348.md)
- [IAM policy document allows all resources with restricted actions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-355.md)
- [Data source IAM policy document allows all resources with restricted actions misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-356.md)
- [AWS GitHub Actions OIDC authorization policies allow for unsafe claims or claim order misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-358.md)
- [AWS Neptune Cluster not configured with IAM authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-359.md)
- [Permissions delegated to AWS services for AWS Lambda functions are not limited by SourceArn or Sourc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-364.md)
- [AWS Cognito identity pool allows unauthenticated guest access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-366.md)
- [AWS Security Group allows unrestricted egress traffic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-382.md)
- [AWS GitHub Actions OIDC authorization policies allow for unsafe claims or claim order on IAM role mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-aws-393.md)
- [Azure AKS enable role-based access control (RBAC) not enforced misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-5.md)
- [Azure AKS cluster configured with overly permissive API server access misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-6.md)
- [Azure App Service Web app authentication is off misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-13.md)
- [App Service is not registered with an Azure Active Directory account misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-16.md)
- [Azure subscriptions with custom roles does not have minimum permissions misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-39.md)
- [Azure Function App authentication is off misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-56.md)
- [Azure App Service Web app doesn't have a Managed Service Identity misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-71.md)
- [AKS does not use Azure policies add-on misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-116.md)
- [Active Directory is not used for authentication for Service Fabric misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-125.md)
- [Azure ACR admin account is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-137.md)
- [Azure ACR enables anonymous image pulling misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-138.md)
- [Azure CosmosDB does not have Local Authentication disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-140.md)
- [Azure Kubernetes Service (AKS) local admin account is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-141.md)
- [Azure SQL on Virtual Machine (Linux) with basic authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-149.md)
- [Web PubSub Without Managed Identities misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-176.md)
- [Linux VM Without SSH Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-178.md)
- [Data Explorer Not Using Managed Identities misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-181.md)
- [App Configuration Using Local Authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-184.md)
- [Azure Event Grid Topic Managed Identity Provider misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-191.md)
- [Azure Event Grid Topic Local Authentication Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-192.md)
- [Azure Event Grid Domain Managed Identity Provider is Disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-194.md)
- [Azure Event Grid Domain Local Authentication Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-195.md)
- [Azure Service Bus Without Managed Identity Provider misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-202.md)
- [Azure Service Bus with Local Authentication Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-203.md)
- [Azure Cognitive Search Without Managed Identities misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-207.md)
- [Local users used for Azure Storage misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-244.md)
- [Azure GitHub Actions OIDC trust policy is insecurely configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-azure-249.md)
- [GCP Kubernetes Engine Clusters have Legacy Authorization enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-7.md)
- [GCP Kubernetes engine clusters have client certificate disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-13.md)
- [GCP Kubernetes Engine Clusters have pod security policy disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-24.md)
- [GCP VM instance configured with default service account misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-30.md)
- [GCP VM instance using a default service account with Cloud Platform access scope misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-31.md)
- [GCP IAM user are assigned Service Account User or Service Account Token creator roles at project lev](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-41.md)
- [GCP IAM Service account does have admin privileges misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-42.md)
- [Roles impersonate or manage Service Accounts used at folder level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-44.md)
- [Roles impersonate or manage Service Accounts used at organizational level misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-45.md)
- [Default Service Account is used at project level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-46.md)
- [Default Service Account is used at organization level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-47.md)
- [Default Service Account is used at folder level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-48.md)
- [GCP IAM primitive roles are in use misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-49.md)
- [Kubernetes RBAC users are not managed with Google Groups for GKE misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-65.md)
- [GCP Kubernetes Engine Clusters have binary authorization disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-66.md)
- [GCP Memorystore for Redis has AUTH disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-95.md)
- [KMS policy allows public access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-112.md)
- [IAM policy defines public access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-113.md)
- [Basic roles utilized at the organization level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-115.md)
- [Basic roles used at the folder level misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-116.md)
- [Project level utilization of basic roles misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-117.md)
- [IAM workload identity pool provider is not restricted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-118.md)
- [GCP GitHub Actions OIDC trust policy is insecurely configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-gcp-125.md)
- [GitHub pull request configurations defined in Terraform have less than 2 approvals misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-git-5.md)
- [GitHub repository defined in Terraform does not have GPG signatures for all commits misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-git-6.md)
- [Gitlab project defined in Terraform requires fewer than 2 approvals misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-glb-1.md)
- [Gitlab branch protection rules defined in Terraform allow force push misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-glb-2.md)
- [Gitlab project defined in Terraform does not require signed commits misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-glb-4.md)
- [Containers run with AllowPrivilegeEscalation based on Pod Security Policy setting misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-5.md)
- [Secrets used as environment variables misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-35.md)
- [Service account tokens are not mounted where necessary misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-38.md)
- [Default service accounts are actively used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-41.md)
- [Default Kubernetes service accounts are actively used by bounding to a role or cluster role misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-42.md)
- [Wildcard use is not minimized in Roles and ClusterRoles misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-49.md)
- [The --anonymous-auth argument is not set to False for API server misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-68.md)
- [The --basic-auth-file argument is Set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-69.md)
- [The --token-auth-file argument is Set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-70.md)
- [The --kubelet-client-certificate and --kubelet-client-key arguments are not set appropriately miscon](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-72.md)
- [The --kubelet-certificate-authority argument is not set appropriately misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-73.md)
- [The --authorization-mode argument is set to AlwaysAllow for Kubelet misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-74.md)
- [The --authorization-mode argument does not include node misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-75.md)
- [The --authorization-mode argument does not include RBAC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-77.md)
- [The admission control plugin SecurityContextDeny is set if PodSecurityPolicy is used misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-81.md)
- [The admission control plugin ServiceAccount is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-82.md)
- [The admission control plugin PodSecurityPolicy is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-84.md)
- [The admission control plugin NodeRestriction is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-85.md)
- [The --service-account-lookup argument is not set to true misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-96.md)
- [The --service-account-key-file argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-97.md)
- [The --etcd-cafile argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-102.md)
- [The --use-service-account-credentials argument for controller managers is not set to True misconfigu](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-108.md)
- [The --service-account-private-key-file argument for controller managers is not set appropriately mis](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-110.md)
- [The --root-ca-file argument for controller managers is not set appropriately misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-111.md)
- [The RotateKubeletServerCertificate argument for controller managers is not set to True misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-112.md)
- [The --client-cert-auth argument is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-117.md)
- [The --peer-client-cert-auth argument is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-121.md)
- [The --anonymous-auth argument is not set to False for Kubelet misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-138.md)
- [The --authorization-mode argument is set to AlwaysAllow for API server misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-139.md)
- [The --client-ca-file argument for API Servers is not set appropriately misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-140.md)
- [The --rotate-certificates argument is set to false misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-149.md)
- [Kubernetes ClusterRoles that grant control over validating or mutating admission webhook configurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-155.md)
- [Kubernetes ClusterRoles that grant permissions to approve CertificateSigningRequests are not minimiz](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-156.md)
- [Kubernetes Roles and ClusterRoles that grant permissions to bind RoleBindings or ClusterRoleBindings](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-157.md)
- [Kubernetes Roles and ClusterRoles that grant permissions to escalate Roles or ClusterRole are not mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-k8s-158.md)
- [OCI private keys are hard coded in the provider misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-1.md)
- [OCI IAM password policy for local (non-federated) users does not have a lowercase character misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-11.md)
- [OCI IAM password policy for local (non-federated) users does not have a number misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-12.md)
- [OCI IAM password policy for local (non-federated) users does not have a symbol misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-13.md)
- [OCI IAM password policy for local (non-federated) users does not have an uppercase character misconf](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-14.md)
- [OCI IAM password policy for local (non-federated) users does not have minimum 14 characters misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-oci-18.md)
- [OpenAPI Security object needs to have defined rules in its array and rules should be defined in the](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-4.md)
- [OpenAPI Security object for operations, if defined, must define a security scheme, otherwise it shou](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-5.md)
- [OpenAPI Security requirement not defined in the security definitions misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-6.md)
- [API spec includes a 'password' flow in OAuth2 authentication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-8.md)
- [Security scopes of operations are not defined in securityDefinition misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-9.md)
- [OAuth2 security definitions includes password flow in OpenAPI 2.0 file misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-10.md)
- [OAuth2 password flow in security definitions for OpenAPI 2.0 file misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-11.md)
- [Security definition uses the deprecated implicit flow on OAuth2 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-12.md)
- [Security definitions uses basic auth misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-13.md)
- [Operation Objects Uses 'Implicit' Flow misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-14.md)
- [Operation Objects Uses Basic Auth misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-15.md)
- [The global security scope is not defined in the securityDefinitions misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openapi-19.md)
- [OpenStack hard coded password, token, or application\_credential\_secret exists in provider misconfigu](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openstack-1.md)
- [OpenStack instance use basic credentials misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec-openstack-4.md)
- [AWS IAM group not in use misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-14.md)
- [Not all IAM users are members of at least one IAM group misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-21.md)
- [IAM User has access to the console misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-22.md)
- [AWS IAM policy allows full administrative privileges misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-40.md)
- [AWS EC2 Instance IAM Role not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-41.md)
- [AWS S3 buckets are accessible to any authenticated user misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-43.md)
- [AWS Cloudfront Distribution with S3 have Origin Access set to disabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-46.md)
- [AWS OpenSearch Fine-grained access control is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-52.md)
- [The AWS Managed IAMFullAccess IAM policy should not be used misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-56.md)
- [A Policy is not Defined for KMS Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-64.md)
- [AWS API Gateway method lacking authorization or API keys misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-aws-70.md)
- [Azure SQL servers which doesn't have Azure Active Directory admin configured misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-7.md)
- [Azure SQL server not configured with Active Directory admin authentication misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-27.md)
- [Azure Container Instance not configured with the managed identity misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-30.md)
- [Azure Recovery Services vault is not configured with managed identity misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-35.md)
- [Azure Automation account is not configured with managed identity misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-36.md)
- [Azure Storage account configured with Shared Key authorization misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-40.md)
- [Azure Storage account not configured with SAS expiration policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-41.md)
- [Anonymous blob access configured in Azure storage account misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-azure-47.md)
- ['chpasswd' is used to set or remove passwords misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-docker-17.md)
- [GCP Kubernetes Engine Cluster Nodes have default Service account for Project access misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-gcp-1.md)
- [There are not only GCP-managed service account keys for each service account misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-gcp-3.md)
- [A MySQL database instance allows anyone to connect with administrative privileges misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-gcp-7.md)
- [IBM Cloud API key creation is not restricted in account settings in Terraform misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-ibm-3.md)
- [IBM Cloud Multi-Factor Authentication (MFA) not enabled at the account level in Terraform misconfigu](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-ibm-4.md)
- [IBM Cloud Service ID creation is not restricted in account settings in Terraform misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-ibm-5.md)
- [RoleBinding should not allow privilege escalation to a ServiceAccount or Node on other RoleBinding m](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-k8s-1.md)
- [Granting create permissions to nodes/proxy or pods/exec sub resources allows potential privilege esc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-k8s-2.md)
- [No ServiceAccount/Node should have impersonate permissions for groups/users/service-accounts misconf](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-k8s-3.md)
- [ServiceAccounts and nodes that can modify services/status may set the status.loadBalancer.ingress.ip](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-k8s-4.md)
- [No ServiceAccount/Node should be able to read all secrets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-k8s-5.md)
- [OCI tenancy administrator users are associated with API keys misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/iam/appsec2-oci-1.md)
- [Logging](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging.md)
- [Alibaba Cloud Action Trail Logging is not enabled for all regions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-4.md)
- [Alibaba Cloud Action Trail Logging is not enabled for all events misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-5.md)
- [Alibaba Cloud OSS bucket has access logging enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-12.md)
- [Alibaba Cloud RDS Instance SQL Collector Retention Period is less than 180 misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-25.md)
- [Alibaba Cloud RDS instance does not have log\_duration enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-35.md)
- [Alibaba Cloud RDS instance has log\_disconnections disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-36.md)
- [Alibaba Cloud RDS log audit is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-ali-38.md)
- [AWS CloudTrail log validation is not enabled in all regions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-36.md)
- [AWS EKS control plane logging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-37.md)
- [Amazon MQ Broker logging is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-48.md)
- [AWS CloudWatch Log groups not configured with definite retention days misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-66.md)
- [AWS CloudTrail is not enabled with multi trail and not capturing all management events misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-67.md)
- [AWS Redshift database does not have audit logging enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-71.md)
- [Global Accelerator does not have Flow logs enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-75.md)
- [API Gateway does not have access logging enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-76.md)
- [Amazon MSK cluster logging is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-80.md)
- [AWS Elasticsearch domain logging is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-84.md)
- [AWS DocumentDB logging is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-85.md)
- [AWS CloudFront distribution with access logging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-86.md)
- [AWS Elastic Load Balancer v2 (ELBv2) with access log disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-91.md)
- [AWS Elastic Load Balancer (Classic) with access log disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-92.md)
- [AWS API Gateway V2 has Access Logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-95.md)
- [Neptune logging is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-101.md)
- [AWS config is not enabled in all regions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-121.md)
- [AWS CloudWatch Log groups encrypted using default encryption key instead of KMS CMK misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-158.md)
- [AWS WAF Web Access Control Lists logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-176.md)
- [AWS AppSync's logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-193.md)
- [AWS AppSync has field-level logging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-194.md)
- [AWS MQBroker audit logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-197.md)
- [AWS ECS Cluster does not enable logging of ECS Exec misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-223.md)
- [AWS cluster logging is not enabled or client to container communication not encrypted using a Custom](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-224.md)
- [AWS ACM certificates does not have logging preference misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-234.md)
- [AWS MWAA environment has scheduler logs disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-242.md)
- [AWS MWAA environment has worker logs disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-243.md)
- [AWS MWAA environment has webserver logs disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-244.md)
- [AWS CloudTrail logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-251.md)
- [AWS CloudTrail does not define an SNS Topic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-252.md)
- [Data Trace is not enabled in the API Gateway Method Settings misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-276.md)
- [State machine does not have X-ray tracing enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-284.md)
- [Execution history logging is not enabled on the State Machine misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-285.md)
- [AWS CodeBuild project not configured with logging configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-314.md)
- [Elasticsearch Domain Audit Logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-317.md)
- [RDS Cluster log capture is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-324.md)
- [RDS Cluster audit logging for MySQL engine is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-325.md)
- [AWS ECS services have automatic public IP address assignment enabled misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-333.md)
- [AWS CloudWatch log groups retention set to less than 365 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-338.md)
- [RDS instances have performance insights disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-aws-353.md)
- [Azure Network Watcher Network Security Group (NSG) flow logs retention is less than 90 days misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-12.md)
- [Azure SQL Server auditing policy is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-23.md)
- [Azure SQL Server audit log retention is not greater than 90 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-24.md)
- [Azure SQL server send alerts to field value is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-26.md)
- [Azure storage account logging for queues is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-33.md)
- [Azure Activity Log retention should not be set to less than 365 days misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-37.md)
- [Azure Monitor log profile does not capture all activities misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-38.md)
- [Azure App service HTTP logging is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-63.md)
- [App service disables detailed error messages misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-65.md)
- [App service does not enable failed request tracing misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-66.md)
- [Server Parameter 'log\_retention' is Set to 'OFF' for PostgreSQL Database Server misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-146.md)
- [Azure SQL Server does not have default auditing policy configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-156.md)
- [Azure Built-in logging for Azure function app is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-159.md)
- [Ledger feature is disabled on the database misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-azure-224.md)
- [GCP Kubernetes Engine Clusters have Cloud Logging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-1.md)
- [GCP VPC Flow logs for the subnet is set to Off misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-26.md)
- [GCP PostgreSQL instance with log\_checkpoints database flag is disabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-51.md)
- [GCP PostgreSQL instance database flag log\_connections is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-52.md)
- [GCP PostgreSQL instance database flag log\_disconnections is disabled misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-53.md)
- [GCP PostgreSQL instance database flag log\_lock\_waits is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-54.md)
- [GCP PostgreSQL instance database flag log\_min\_messages is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-55.md)
- [GCP PostgreSQL instance database flag log\_temp\_files is not set to 0 misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-56.md)
- [GCP PostgreSQL instance database flag log\_min\_duration\_statement is not set to -1 misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-57.md)
- [GCP PostgreSQL instance database flag log\_hostname is not set to off misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-108.md)
- [Log levels of the GCP PostgreSQL database are not set to ERROR or lower misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-109.md)
- [pgAudit is disabled for your GCP PostgreSQL database misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-110.md)
- [SQL statements of GCP PostgreSQL are not logged misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-gcp-111.md)
- [The --audit-log-path argument is not set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-k8s-91.md)
- [The --audit-log-maxage argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-k8s-92.md)
- [The --audit-log-maxbackup argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-k8s-93.md)
- [The --audit-log-maxsize argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-k8s-94.md)
- [Security policies missing descriptions in Palo Alto Networks devices misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-pan-8.md)
- [Log Forwarding Profile not selected for a Palo Alto Networks device security policy rule misconfigur](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-pan-9.md)
- [End-of-session logging disabled on Palo Alto Networks security policies misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-pan-10.md)
- [Logging at session start enabled on Palo Alto Networks devices misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec-pan-16.md)
- [API Gateway stage does not have logging level defined appropriately misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-4.md)
- [AWS CloudTrail trail logs is not integrated with CloudWatch Log misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-10.md)
- [AWS VPC Flow Logs not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-11.md)
- [AWS RDS Postgres Cluster does not have query logging enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-27.md)
- [AWS Postgres RDS have Query Logging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-30.md)
- [AWS WAF2 does not have a Logging Configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-31.md)
- [AWS Codecommit is not associated with an approval rule misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-37.md)
- [Domain Name System (DNS) query logging is not enabled for Amazon Route 53 hosted zones misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-39.md)
- [AWS Config Recording is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-45.md)
- [AWS Config must record all possible resources misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-48.md)
- [An S3 bucket must have a lifecycle configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-61.md)
- [S3 buckets do not have event notifications enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-62.md)
- [AWS Network Firewall is not configured with logging configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-aws-63.md)
- [Azure storage account logging setting for tables is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-azure-20.md)
- [Azure storage account logging setting for blobs is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-azure-21.md)
- [GCP Log bucket retention policy is not configured using bucket lock misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-4.md)
- [GCP Project audit logging is not configured properly across all services and all users in a project](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-5.md)
- [GCP PostgreSQL instance database flag log\_duration is not set to on misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-13.md)
- [GCP PostgreSQL instance database flag log\_executor\_stats is not set to off misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-14.md)
- [GCP PostgreSQL instance database flag log\_parser\_stats is not set to off misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-15.md)
- [GCP PostgreSQL instance database flag log\_planner\_stats is not set to off misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-16.md)
- [GCP PostgreSQL instance database flag log\_statement\_stats is not set to off misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-17.md)
- [Logging is disabled for Dialogflow agents misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-29.md)
- [Logging for Dialogflow CX agents is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-30.md)
- [Logging for Dialogflow CX webhooks is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/logging/appsec2-gcp-31.md)
- [Monitoring](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring.md)
- [Alibaba Cloud Kubernetes node pools are not set to auto repair misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-ali-31.md)
- [Alibaba RDS instance has log\_connections disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-ali-37.md)
- [AWS ECS cluster with container insights feature disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-65.md)
- [AWS Amazon RDS instances Enhanced Monitoring is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-118.md)
- [AWS CloudFormation stack configured without SNS topic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-124.md)
- [AWS EC2 instance detailed monitoring disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-126.md)
- [AWS WAF does not have associated rules misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-175.md)
- [AWS GuardDuty detector is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-238.md)
- [Elastic Beanstalk environments do not have enhanced health reporting enabled misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-312.md)
- [CloudWatch alarm actions are not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-319.md)
- [EKS clusters are not running on a supported Kubernetes version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-339.md)
- [AWS resources that support tags do not have Tags misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-aws-custom-1.md)
- [Azure AKS cluster monitoring not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-4.md)
- [Azure Microsoft Defender for Cloud Defender plans is set to Off misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-19.md)
- [Azure Microsoft Defender for Cloud security contact phone number is not set misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-20.md)
- [Azure Microsoft Defender for Cloud security alert email notification is not set misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-21.md)
- [Azure Microsoft Defender for Cloud email notification for subscription owner is not set misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-22.md)
- [Azure SQL Server threat detection alerts are not enabled for all threat types misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-25.md)
- [Azure SQL Databases with disabled Email service and co-administrators for Threat Detection misconfig](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-27.md)
- [Azure Microsoft Defender for Cloud is set to Off for Servers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-55.md)
- [Azure Microsoft Defender for Cloud is set to Off for App Service misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-61.md)
- [Azure Microsoft Defender for Cloud is set to Off for Azure SQL Databases misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-69.md)
- [Azure Microsoft Defender for Cloud is set to Off for SQL servers on machines misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-79.md)
- [Azure Microsoft Defender for Cloud is set to Off for Storage misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-84.md)
- [Azure Security Center Defender set to Off for Kubernetes misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-85.md)
- [Azure Microsoft Defender for Cloud is set to Off for Container Registries misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-86.md)
- [Azure Microsoft Defender for Cloud is set to Off for Key Vault misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-87.md)
- [My SQL server does not enable Threat Detection policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-127.md)
- [PostgreSQL server does not enable Threat Detection policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-128.md)
- [Azure Microsoft Defender for Cloud security alert email notifications is not set misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-131.md)
- [Vulnerability Scanning not enabled for Azure Container Registry misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-163.md)
- [Azure App Service Health Check Missing misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-213.md)
- [Azure Microsoft Defender for Cloud set to Off for Resource Manager misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-234.md)
- [Azure resources that support tags do not have tags misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-azure-custom-1.md)
- [GCP Kubernetes Engine Clusters have Cloud Monitoring disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-8.md)
- [GCP Kubernetes cluster node auto-repair configuration disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-9.md)
- [GCP Kubernetes cluster node auto-upgrade configuration disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-10.md)
- [GCP Kubernetes Engine Clusters without any label information misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-21.md)
- [The GKE metadata server is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-69.md)
- [GCP Kubernetes Engine cluster not using Release Channel for version management misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-70.md)
- [GCP Kubernetes cluster shielded GKE node with integrity monitoring disabled misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-72.md)
- [GCP Cloud Armor policy not configured with cve-canary rule misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-73.md)
- [GCP resources that support labels do not have labels misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-gcp-custom-1.md)
- [GitHub Repository defined in Terraform doesn't have vulnerability alerts enabled misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-git-3.md)
- [Liveness probe is not configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-8.md)
- [Readiness probe is not configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-9.md)
- [The --profiling argument is not set to false for API server misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-90.md)
- [The --request-timeout argument is not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-95.md)
- [The --profiling argument for controller managers is not set to False misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-107.md)
- [The --profiling argument is not set to False for scheduler misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-114.md)
- [The --event-qps argument is not set to a level that ensures appropriate event capture misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-k8s-147.md)
- [OCI Compute Instance has monitoring disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-oci-6.md)
- [Terraform module sources do not use a git url with a commit hash revision misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-tf-1.md)
- [Terraform module sources do not use a git url with a tag or commit hash revision misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec-tf-2.md)
- [GuardDuty is not enabled to specific org/region misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-aws-3.md)
- [AWS CloudFront attached WAFv2 WebACL is not configured with AMR for Log4j Vulnerability misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-aws-47.md)
- [AWS RDS instance with copy tags to snapshots disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-aws-60.md)
- [Azure SQL Server ADS Vulnerability Assessment is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-azure-2.md)
- [Azure SQL Server ADS Vulnerability Assessment (VA) Periodic recurring scans is disabled misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-azure-3.md)
- [Azure SQL Server ADS Vulnerability Assessment (VA) 'Send scan reports to' is not configured misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-azure-4.md)
- [Azure SQL Server ADS Vulnerability Assessment (VA) 'Also send email notifications to admins and subs](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-azure-5.md)
- [Azure SQL server Defender setting is set to Off misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-azure-13.md)
- [GCP GCR Container Vulnerability Scanning is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/monitoring/appsec2-gcp-11.md)
- [Networking](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking.md)
- [Alibaba Cloud Kubernetes does not install plugin Terway or Flannel to support standard policies misc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-ali-26.md)
- [Alibaba Cloud Cypher Policy is not secured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-ali-33.md)
- [Alibaba Cloud MongoDB is not deployed inside a VPC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-ali-41.md)
- [AWS EKS cluster security group overly permissive to all traffic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-38.md)
- [AWS CloudFront web distribution with AWS Web Application Firewall (AWS WAF) service disabled misconf](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-68.md)
- [AWS EKS node group have implicit SSH access from 0.0.0.0/0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-100.md)
- [Deletion protection disabled for load balancer misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-113.md)
- [VPC endpoint service is not configured for manual acceptance misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-123.md)
- [Elastic load balancers do not use SSL Certificates provided by AWS Certificate Manager misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-127.md)
- [ALB does not drop HTTP headers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-131.md)
- [AWS Elastic Load Balancer (Classic) with cross-zone load balancing disabled misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-138.md)
- [Default VPC is planned to be provisioned misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-148.md)
- [AWS Elastic Load Balancer v2 with deletion protection feature disabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-150.md)
- [AWS Elastic Load Balancer v2 (ELBv2) with cross-zone load balancing disabled misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-152.md)
- [WAF enables message lookup in Log4j2 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-192.md)
- [AWS RDS security groups are not defined misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-198.md)
- [AWS ELB Policy uses some unsecure protocols misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-213.md)
- [AWS Cloudfront distribution is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-216.md)
- [AWS Elasticsearch uses the default security group misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-248.md)
- [ALB is not configured with the defensive or strictest desync mitigation mode misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-328.md)
- [Network firewalls do not have deletion protection enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-344.md)
- [Transfer server does not force secure protocols. misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-357.md)
- [AWS CloudFront web distribution with geo restriction disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-374.md)
- [Route 53 domains do not have transfer lock protection misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-aws-377.md)
- [Azure AKS cluster network policies are not enforced misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-7.md)
- [Azure RDP Internet access is not restricted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-9.md)
- [CORS allows resources to access function apps misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-62.md)
- [Azure Function App doesn't use HTTP 2.0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-67.md)
- [Azure App Services Remote debugging is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-72.md)
- [Azure container container group is not deployed into a virtual network misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-98.md)
- [API management services do not use virtual networks misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-107.md)
- [Key vault does not allow firewall rules settings misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-109.md)
- [AKS is not enabled for private clusters misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-115.md)
- [Azure application gateway does not have WAF enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-120.md)
- [Azure Front Door does not have the Azure Web application firewall (WAF) enabled misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-121.md)
- [Application gateway does not use WAF in Detection or Prevention modes misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-122.md)
- [Azure front door does not use WAF in Detection or Prevention modes misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-123.md)
- [Azure Front Door Web application firewall (WAF) policy rule for Remote Command Execution is disabled](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-133.md)
- [Azure Application Gateway Web application firewall (WAF) policy rule for Remote Command Execution is](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-135.md)
- [Firewall policy does not have IDPS mode set to deny misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-220.md)
- [Azure Container Registry dedicated data endpoint is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-237.md)
- [Azure Batch Account configured with overly permissive network access misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-248.md)
- [Azure Storage Sync Service configured with overly permissive network access misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-250.md)
- [Azure VM disk configured with public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-azure-251.md)
- [GCP Kubernetes Engine Clusters have Network policy disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-12.md)
- [GCP Kubernetes Engine Clusters have Master authorized networks disabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-20.md)
- [GCP Kubernetes Engine Clusters have Alias IP disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-23.md)
- [GCP Kubernetes Engine private cluster has private endpoint disabled misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-25.md)
- [GCP Kubernetes cluster intra-node visibility disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-61.md)
- [GCP Kubernetes Engine Clusters not configured with private nodes feature misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-gcp-64.md)
- [Containers wishing to share host network namespace admitted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-4.md)
- [Containers share the host network namespace misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-19.md)
- [hostPort is specified misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-26.md)
- [The --kubelet-https argument is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-71.md)
- [The API server does not make use of strong cryptographic ciphers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-105.md)
- [The --bind-address argument for controller managers is not set to 127.0.0.1 misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-113.md)
- [The --bind-address argument is not set to 127.0.0.1 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-115.md)
- [The --auto-tls argument is set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-118.md)
- [The --make-iptables-util-chains argument is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-145.md)
- [The --tls-cert-file and --tls-private-key-file arguments for Kubelet are not set appropriately misco](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-148.md)
- [Kubelet does not use strong cryptographic ciphers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-151.md)
- [NGINX Ingress annotation snippets contains LUA code execution misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-152.md)
- [NGINX Ingress has annotation snippets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-153.md)
- [NGINX Ingress has annotation snippets which contain alias statements misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-k8s-154.md)
- [OCI Network Security Groups (NSG) has stateful security rules misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-oci-21.md)
- [OCI Data Catalog configured with overly permissive network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-oci-23.md)
- [OpenStack firewall rule does not have destination IP configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-openstack-5.md)
- [Plain-text management HTTP enabled for Interface Management Profile in Palo Alto Networks devices mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-2.md)
- [Plain-text management Telnet enabled for Interface Management Profile in Palo Alto Networks devices](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-3.md)
- [Disable Server Response Inspection (DSRI) enabled in security policies for Palo Alto Networks device](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-4.md)
- [Security rule allows any application on Palo Alto Networks devices misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-5.md)
- [Security rule permits any service on Palo Alto Networks devices misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-6.md)
- [Security Rule in Palo Alto Networks devices with overly broad Source and Destination IPs misconfigur](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-7.md)
- [IPsec profile uses insecure authentication algorithms on Palo Alto Networks devices misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-12.md)
- [IPsec profile uses insecure authentication protocols on Palo Alto Networks devices misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-13.md)
- [Security zone on Palo Alto Networks devices does not have an associated Zone Protection Profile misc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-14.md)
- [Include ACL (Access Control List) not defined for a security zone in Palo Alto Networks devices with](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-15.md)
- [Security rules apply to all zones on Palo Alto Networks devices misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec-pan-17.md)
- [AWS AppSync is not protected by WAF misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-aws-33.md)
- [AWS NAT Gateways are not utilized for the default route misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-aws-35.md)
- [AWS ACM Certificate with wildcard domain name misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-aws-71.md)
- [AWS Load Balancers do not use strong ciphers misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-aws-74.md)
- [AWS Lambda function URL having overly permissive cross-origin resource sharing permissions misconfig](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-aws-75.md)
- [Azure Automation account configured with overly permissive network access misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-azure-24.md)
- [Azure MySQL Flexible Server not configured with private endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-azure-56.md)
- [PostgreSQL Flexible Server not configured with private endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-azure-57.md)
- [GCP project is configured with legacy network misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-gcp-2.md)
- [Vertex AI workbench instances are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-gcp-28.md)
- [GCP public-facing (external) regional load balancer using HTTP protocol misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-gcp-37.md)
- [GCP public-facing (external) global load balancer using HTTP protocol misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-gcp-38.md)
- [IBM Cloud Virtual Private Cloud (VPC) classic access is enabled in Terraform misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/networking/appsec2-ibm-2.md)
- [Public Exposure](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure.md)
- [Alibaba Cloud OSS bucket accessible to public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-1.md)
- [Alibaba Cloud Security group allow internet traffic to SSH port (22) misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-2.md)
- [Alibaba Cloud Security group allow internet traffic to RDP port (3389) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-3.md)
- [Alibaba Cloud database instance accessible to public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-9.md)
- [Alibaba Cloud RDS instance does not use SSL misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-20.md)
- [Alibaba Cloud API Gateway API Protocol does not use HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-21.md)
- [Alibaba cloud ALB ACL does not restrict public access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-29.md)
- [Alibaba Cloud Mongodb instance does not use SSL misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-42.md)
- [Alibaba Cloud MongoDB instance is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-ali-43.md)
- [AWS Elastic Load Balancer v2 (ELBv2) listener that allow connection requests over HTTP misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-2.md)
- [AWS Elasticsearch does not have node-to-node encryption enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-6.md)
- [AWS RDS database instance is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-17.md)
- [Not every Security Group rule has a description misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-23.md)
- [AWS Security Group allows all traffic on SSH port (22) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-24.md)
- [AWS Security Group allows all traffic on RDP port (3389) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-25.md)
- [AWS ElastiCache Redis cluster with in-transit encryption disabled (Replication group) misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-30.md)
- [AWS ElastiCache Redis cluster with Redis AUTH feature disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-31.md)
- [AWS CloudFront viewer protocol policy is not configured with HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-34.md)
- [AWS EKS cluster endpoint access publicly enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-39.md)
- [AWS access keys and secrets are hard coded in infrastructure misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-41.md)
- [Lambda function's environment variables expose secrets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-45.md)
- [EC2 user data exposes secrets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-46.md)
- [AWS API gateway methods are publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-59.md)
- [AWS MQ is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-69.md)
- [AWS Elasticsearch domain is not configured with HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-83.md)
- [AWS Redshift cluster instance with public access setting enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-87.md)
- [AWS EC2 instances with public IP and associated with security groups have Internet access misconfigu](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-88.md)
- [AWS DMS replication instance is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-89.md)
- [Neptune cluster instance is publicly available misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-102.md)
- [AWS Load Balancer is not using TLS 1.2 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-103.md)
- [AWS VPC subnets should not allow automatic public IP assignment misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-130.md)
- [AWS Elasticsearch is not configured inside a VPC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-137.md)
- [Redshift is deployed outside of a VPC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-154.md)
- [AWS Transfer Server is publicly exposed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-164.md)
- [AWS CloudFront web distribution using insecure TLS version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-174.md)
- [AWS Elasticache security groups are not defined misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-196.md)
- [AWS API Gateway Domain does not use a modern security policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-206.md)
- [AWS Cloudsearch does not use the latest (Transport Layer Security) TLS misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-218.md)
- [AWS Cloudsearch does not use HTTPs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-220.md)
- [AWS Elasticsearch domain does not use an updated TLS policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-228.md)
- [AWS NACL allows ingress from 0.0.0.0/0 to port 21 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-229.md)
- [AWS NACL allows ingress from 0.0.0.0/0 to port 20 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-230.md)
- [AWS NACL allows ingress from 0.0.0.0/0 to port 3389 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-231.md)
- [AWS NACL allows ingress from 0.0.0.0/0 to port 22 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-232.md)
- [AWS DAX cluster endpoint does not use TLS (Transport Layer Security) misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-239.md)
- [AWS CloudFront response header policy does not enforce Strict Transport Security misconfiguration de](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-259.md)
- [AWS security groups allow ingress from 0.0.0.0/0 to port 80 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-260.md)
- [AWS Security Group allows all traffic on all ports misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-277.md)
- [MSK nodes are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-291.md)
- [AWS RDS snapshots are accessible to public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-302.md)
- [AWS SSM documents are public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-303.md)
- [AWS CloudFront distributions does not have a default root object configured misconfiguration detecte](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-305.md)
- [AWS SageMaker notebook instance is not placed in VPC misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-306.md)
- [CloudFront distributions do not have origin failover configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-310.md)
- [ElastiCache cluster is using the default subnet group misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-323.md)
- [AWS Transit Gateway auto accept vpc attachment is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-331.md)
- [WAF rule does not have any actions misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-342.md)
- [NACL ingress allows all ports misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-352.md)
- [TLS not enforced in SES configuration set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-365.md)
- [AWS Elastic Load Balancer with listener TLS/SSL is not configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-376.md)
- [AWS Load Balancer uses HTTP protocol misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-378.md)
- [AWS S3 bucket not configured with secure data transport policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-379.md)
- [AWS Transfer Server not using latest Security Policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-aws-380.md)
- [Azure Virtual Machine (Linux) does not authenticate using SSH keys misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-1.md)
- [Kubernetes dashboard is not disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-8.md)
- [Azure Network Security Group allows all traffic on SSH port 22 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-10.md)
- [Azure SQL Servers Firewall rule allow ingress access from 0.0.0.0/0 misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-11.md)
- [Azure App Service Web app doesn't redirect HTTP to HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-14.md)
- [Azure App Service Web app doesn't use latest TLS version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-15.md)
- [Azure App Service Web app client certificate is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-17.md)
- [Azure App Service Web app doesn't use HTTP 2.0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-18.md)
- [Azure MySQL Database Server SSL connection is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-28.md)
- [Azure PostgreSQL database server with SSL connection disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-29.md)
- [Azure storage account has a blob container that is publicly accessible misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-34.md)
- [Azure Storage Account default network access is set to 'Allow' misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-35.md)
- [Azure MariaDB database server with SSL connection disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-47.md)
- [MariaDB servers do not have public network access enabled set to False misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-48.md)
- ['public network access enabled' is not set to 'False' for mySQL servers misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-53.md)
- [MySQL is not using the latest version of TLS encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-54.md)
- [CORS allows resource to access app services misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-57.md)
- [Azure storage account does allow public access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-59.md)
- [Azure file sync enables public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-64.md)
- [PostgreSQL server does not disable public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-68.md)
- [Azure Function App doesn't redirect HTTP to HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-70.md)
- [Azure Network Security Group having Inbound rule overly permissive to all traffic on UDP protocol mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-77.md)
- [Azure App Services FTP deployment is All allowed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-78.md)
- [Azure cache for Redis has public network access enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-89.md)
- [Cosmos DB accounts do not have restricted access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-99.md)
- [Azure Cosmos DB enables public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-101.md)
- [Azure Data Factory (V2) configured with overly permissive network access misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-104.md)
- [Azure Event Grid domain public network access is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-106.md)
- [Azure IoT Hub enables public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-108.md)
- [SQL Server is enabled for public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-113.md)
- [Azure Virtual machine NIC has IP forwarding enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-118.md)
- [Network interfaces use public IPs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-119.md)
- [Azure cognitive search does not disable public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-124.md)
- [Azure Container registries Public access to All networks is enabled misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-139.md)
- [Azure AKS cluster nodes have public IP addresses misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-143.md)
- [Azure Function App doesn't use latest TLS version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-145.md)
- [Azure Redis Cache does not use the latest version of TLS encryption misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-148.md)
- [Azure Client Certificates are not enforced for API management misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-152.md)
- [Azure web app does not redirect all HTTP traffic to HTTPS in Azure App Service Slot misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-153.md)
- [Azure App's service slot does not use the latest version of TLS encryption misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-154.md)
- [Azure App service slot does not have debugging disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-155.md)
- [Azure HTTP (port 80) access from the internet is not restricted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-160.md)
- [Azure Spring Cloud API Portal is not enabled for HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-161.md)
- [Azure Spring Cloud API Portal Public Access Is Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-162.md)
- [API Management Without Minimum TLS 1.2 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-173.md)
- [API Management with Public Access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-174.md)
- [Web PubSub Without SLA SKU misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-175.md)
- [VNET With Only One DNS Endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-182.md)
- [VNET Using External DNS Addresses misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-183.md)
- [App Configuration Public Access Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-185.md)
- [Azure Key Vault Public Network Access Control misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-189.md)
- [Azure storage account has a blob container with public access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-190.md)
- [Azure Event Grid Topic Public Network Access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-193.md)
- [Azure SignalR Service not Using Paid SKU for its SLA misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-196.md)
- [Azure CDN Doesn't Disable HTTP Endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-197.md)
- [Azure CDN Endpoint Custom domains is not configured with HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-198.md)
- [Azure CDN Using Outdated TLS Encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-200.md)
- [Azure Service Bus with Public Network Access Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-204.md)
- [Azure Service Bus Without Latest TLS Encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-205.md)
- [Azure Cognitive Search With Global IP Allowance misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-210.md)
- [Azure App Service Instance Lacks Redundancy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-212.md)
- [Backend of the API management system does not utilize HTTPS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-215.md)
- [DenyIntelMode for Azure Firewalls is not set to Deny misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-216.md)
- [Azure Application gateways listener that allow connection requests over HTTP misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-217.md)
- [Azure Application Gateway is configured with SSL policy having TLS version 1.1 or lower misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-218.md)
- [Azure Firewall does not define a firewall policy misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-219.md)
- [Azure Function app configured with public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-221.md)
- [Azure App Service web apps with public network access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-222.md)
- [Event Hub Namespace not using TLS 1.2 or greater misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-223.md)
- [Azure Container Instance environment variable with regular value type misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-235.md)
- [Azure Container Instance is not configured with virtual network misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-245.md)
- [Azure AKS cluster HTTP application routing enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-azure-246.md)
- [Port 22 is exposed misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-docker-1.md)
- [GCP Firewall rule allows all traffic on SSH port (22) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-2.md)
- [GCP Firewall rule allows all traffic on RDP port (3389) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-3.md)
- [GCP HTTPS Load balancer is set with SSL policy having TLS version 1.1 or lower misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-4.md)
- [GCP SQL Instances do not have SSL configured for incoming connections misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-6.md)
- [GCP SQL database is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-11.md)
- [GCP BigQuery dataset is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-15.md)
- [GCP Cloud DNS has DNSSEC disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-16.md)
- [RSASHA1 is used for Zone-Signing and Key-Signing Keys in Cloud DNS DNSSEC misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-17.md)
- [GKE control plane is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-18.md)
- [GCP project is using the default network misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-27.md)
- [GCP Storage bucket is anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-28.md)
- [GCP VM instances do have block project-wide SSH keys feature disabled misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-32.md)
- [GCP Projects do have OS Login disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-33.md)
- [GCP Projects have OS Login disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-34.md)
- [GCP VM instances have serial port access enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-35.md)
- [GCP VM instances have IP Forwarding enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-36.md)
- [GCP VM instance with Shielded VM features disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-39.md)
- [GCP VM instance with the external IP address misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-40.md)
- [GCP Cloud SQL database instances have public IPs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-60.md)
- [GCP VPC Network subnets have Private Google access disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-74.md)
- [GCP Firewall rule allows all traffic on FTP port (21) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-75.md)
- [GCP VPC Network subnets have Private Google access for IPv6 disabled misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-76.md)
- [GCP Google compute firewall ingress allow FTP port (20) access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-77.md)
- [GCP cloud build workers are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-86.md)
- [GCP data fusion instances are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-87.md)
- [GCP Firewall rule allows all traffic on MySQL DB port (3306) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-88.md)
- [GCP Vertex AI instances are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-89.md)
- [GCP Dataflow jobs are not private misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-94.md)
- [GCP Dataproc clusters are anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-98.md)
- [GCP Pub/Sub Topics are anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-99.md)
- [GCP BigQuery Tables are anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-100.md)
- [GCP Artifact Registry repositories are anonymously or publicly accessible misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-101.md)
- [GCP Cloud Run services are anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-102.md)
- [GCP Firewall rule allows all traffic on HTTP port (80) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-106.md)
- [GCP Cloud Function is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-107.md)
- [GCP Storage buckets are publicly accessible to all users misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-114.md)
- [GCP Cloud Function configured with overly permissive Ingress setting misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-gcp-124.md)
- [GitHub repository webhook defined in Terraform does not use a secure SSL misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-git-2.md)
- [Tiller (Helm V2) deployment is accessible from within the cluster misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-45.md)
- [The --insecure-bind-address argument is set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-86.md)
- [The --insecure-port argument is not set to 0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-88.md)
- [The --secure-port argument is set to 0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-89.md)
- [The --tls-cert-file and --tls-private-key-file arguments for API server are not set appropriately mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-100.md)
- [The --read-only-port argument is not set to 0 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-k8s-141.md)
- [OCI VCN has no inbound security list misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-oci-16.md)
- [OCI VCN Security list has stateful security rules misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-oci-17.md)
- [OCI Security List allows all traffic on SSH port (22) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-oci-19.md)
- [OCI security lists allows unrestricted ingress access to port 3389 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-oci-20.md)
- [OCI security group allows unrestricted ingress access to port 22 misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-oci-22.md)
- [OpenAPI Security Definitions Object should be set and not empty misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-1.md)
- [OpenAPI If the security scheme is not of type 'oauth2', the array value must be empty misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-2.md)
- [Cleartext credentials over unencrypted channel should not be accepted for the operation misconfigura](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-3.md)
- [The path scheme is supports unencrypted HTTP connections misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-7.md)
- [Global schemes use 'httpa' protocol instead of 'https' misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-18.md)
- [API keys transmitted over cleartext misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openapi-20.md)
- [OpenStack Security groups allow ingress from 0.0.0.0:0 to port 22 (tcp / udp) misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openstack-2.md)
- [OpenStack Security groups allow ingress from 0.0.0.0:0 to port 3389 (tcp / udp) misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec-openstack-3.md)
- [HTTPS url not used with Ansible uri misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-ansible-1.md)
- [HTTPS url not used with Ansible get\_url module misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-ansible-2.md)
- [AWS Network ACL is not in use misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-1.md)
- [Security Groups are not attached to EC2 instances or ENIs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-5.md)
- [S3 Bucket does not have public access blocks misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-6.md)
- [Amazon EMR clusters' security groups are open to the world misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-7.md)
- [AWS Default Security Group does not restrict all traffic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-12.md)
- [Auto scaling groups associated with a load balancer do not use elastic load balancing health checks](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-15.md)
- [Not all EIP addresses allocated to a VPC are attached to EC2 instances misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-19.md)
- [ALB does not redirect HTTP requests into HTTPS ones misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-20.md)
- [Route53 A Record does not have Attached Resource misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-23.md)
- [AWS Application Load Balancer (ALB) not configured with AWS Web Application Firewall v2 (AWS WAFv2)](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-28.md)
- [Public API gateway not configured with AWS Web Application Firewall v2 (AWS WAFv2) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-29.md)
- [AWS CloudFront distribution does not have a strict security headers policy attached misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-32.md)
- [AWS Terraform sends SSM secrets to untrusted domains over HTTP misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-36.md)
- [Domain Name System Security Extensions (DNSSEC) signing is not enabled for Amazon Route 53 public ho](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-38.md)
- [AWS CloudFront web distribution with default SSL certificate misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-42.md)
- [AWS route table with VPC peering overly permissive to all traffic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-44.md)
- [AWS Database Migration Service endpoint do not have SSL configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-49.md)
- [AWS API Gateway endpoints without client certificate authentication misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-51.md)
- [AWS API gateway request parameter is not validated misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-53.md)
- [AWS CloudFront distribution is using insecure SSL protocols for HTTPS communication misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-54.md)
- [MWAA environment is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-66.md)
- [AWS CloudFront origin protocol policy does not enforce HTTPS-only misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-aws-72.md)
- [Azure PostgreSQL Database Server 'Allow access to Azure services' enabled misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-6.md)
- [Azure Storage account container storing activity logs is publicly accessible misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-8.md)
- [Azure Spring Cloud service is not configured with virtual network misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-23.md)
- [Azure PostgreSQL database flexible server configured with overly permissive network access misconfig](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-26.md)
- [Azure ACR HTTPS not enabled for webhook misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-28.md)
- [Azure AKS cluster Azure CNI networking not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-29.md)
- [Azure Virtual Network subnet is not configured with a Network Security Group misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-31.md)
- [Azure Key vault Private endpoint connection is not configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-32.md)
- [Azure Storage account is not configured with private endpoint connection misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-33.md)
- [Azure SQL Server allow access to any Azure internal resources misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-34.md)
- [Azure Virtual machine configured with public IP and serial console access misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-39.md)
- [Azure PostgreSQL servers not configured with private endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-42.md)
- [Azure Database for MariaDB not configured with private endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-43.md)
- [Azure Database for MySQL server not configured with private endpoint misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-44.md)
- [Azure SQL Database server not configured with private endpoint misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-45.md)
- [Azure Spring Cloud app end-to-end TLS is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-azure-55.md)
- [GCP KMS crypto key is anonymously accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-6.md)
- [GCP Cloud KMS Key Rings are anonymously or publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-8.md)
- [GCP Container Registry repositories are anonymously or publicly accessible misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-9.md)
- [GCP Cloud Function HTTP trigger is not secured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-10.md)
- [GCP Firewall with Inbound rule overly permissive to All Traffic misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-12.md)
- [Google Cloud Platform network is not ensured to define a firewall misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-18.md)
- [TPU v2 VM is public misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-gcp-32.md)
- [IBM Cloud Application Load Balancer for VPC has public access enabled in Terraform misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-ibm-1.md)
- [IBM Cloud Kubernetes clusters are accessible by using public endpoint in Terraform misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-ibm-7.md)
- [OCI Network Security Group allows all traffic on RDP port (3389) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-oci-2.md)
- [OCI Kubernetes Engine Cluster endpoint is not configured with Network Security Groups misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-oci-3.md)
- [OCI Kubernetes Engine Cluster pod security policy not enforced misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/public-exposure/appsec2-oci-6.md)
- [Storage](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage.md)
- [Alibaba Cloud OSS bucket is not encrypted with Customer Master Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-6.md)
- [Alibaba Cloud disk encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-7.md)
- [Alibaba Cloud Disk is not encrypted with Customer Master Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-8.md)
- [Alibaba Cloud OSS bucket has versioning disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-10.md)
- [Alibaba Cloud OSS bucket has transfer Acceleration disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-11.md)
- [Alibaba Cloud Transparent Data Encryption is disabled on instance misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-22.md)
- [Alibaba Cloud launch template data disks are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-32.md)
- [Alibaba Cloud MongoDB does not have transparent data encryption enabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-ali-44.md)
- [AWS EBS volumes are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-3.md)
- [AWS Elasticsearch domain Encryption for data at rest is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-5.md)
- [AWS EC2 Auto Scaling Launch Configuration is not using encrypted EBS volumes misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-8.md)
- [AWS RDS DB cluster encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-16.md)
- [AWS Access logging not enabled on S3 buckets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-18.md)
- [AWS S3 buckets do not have server side encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-19.md)
- [AWS S3 bucket ACL grants READ permission to everyone misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-20.md)
- [AWS S3 Object Versioning is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-21.md)
- [AWS SNS topic has SSE disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-26.md)
- [AWS SQS Queue not configured with server side encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-27.md)
- [DynamoDB PITR is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-28.md)
- [AWS ElastiCache Redis cluster with encryption for data at rest disabled misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-29.md)
- [AWS CloudTrail logs are not encrypted using Customer Master Keys (CMKs) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-35.md)
- [AWS Elastic File System (EFS) with encryption for data at rest is disabled misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-42.md)
- [AWS Kinesis streams are not encrypted using Server Side Encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-43.md)
- [Neptune storage is not securely encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-44.md)
- [AWS DAX cluster not configured with encryption at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-47.md)
- [ECR image tags are not immutable misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-51.md)
- [AWS S3 Bucket has the block public ACLs disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-53.md)
- [AWS S3 Bucket BlockPublicPolicy is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-54.md)
- [AWS S3 bucket IgnorePublicAcls is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-55.md)
- [AWS S3 bucket RestrictPublicBucket is not set to True misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-56.md)
- [AWS S3 Bucket has an ACL defined which allows public WRITE access misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-57.md)
- [AWS EKS cluster does not have secrets encryption enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-58.md)
- [AWS Redshift instances are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-64.md)
- [AWS S3 bucket policy overly permissive to any principal misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-70.md)
- [DocumentDB is not encrypted at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-74.md)
- [Athena Database is not encrypted at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-77.md)
- [CodeBuild project encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-78.md)
- [AWS MSK cluster encryption in transit is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-81.md)
- [Athena workgroup does not prevent disabling encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-82.md)
- [DocDB TLS is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-90.md)
- [S3 bucket policy allows lockout all but root user misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-93.md)
- [Glue Data Catalog encryption is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-94.md)
- [Not all data stored in Aurora is securely encrypted at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-96.md)
- [EFS volumes in ECS task definitions do not have encryption in transit enabled misconfiguration detec](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-97.md)
- [AWS Glue security configuration encryption is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-99.md)
- [DocDB does not have audit logs enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-104.md)
- [AWS Redshift does not have require\_ssl configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-105.md)
- [AWS EBS volume region with encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-106.md)
- [Session Manager data is not encrypted in transit misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-112.md)
- [AWS DynamoDB encrypted using AWS owned CMK instead of AWS managed CMK misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-119.md)
- [AWS RDS instance without Automatic Backup setting misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-133.md)
- [AWS ElastiCache Redis cluster is not configured with automatic backup misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-134.md)
- [EC2 EBS is not optimized misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-135.md)
- [Unencrypted ECR repositories misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-136.md)
- [AWS RDS cluster delete protection is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-139.md)
- [Unencrypted RDS global clusters misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-140.md)
- [Redshift clusters version upgrade is not default misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-141.md)
- [AWS Redshift Cluster not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-142.md)
- [S3 bucket lock configuration disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-143.md)
- [S3 bucket cross-region replication disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-144.md)
- [S3 buckets are not encrypted with KMS misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-145.md)
- [AWS RDS DB snapshot is not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-146.md)
- [CodeBuild projects are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-147.md)
- [AWS Secrets Manager secret not encrypted by Customer Managed Key (CMK) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-149.md)
- [Workspace user volumes are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-155.md)
- [Workspace root volumes are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-156.md)
- [RDS instances do not have Multi-AZ enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-157.md)
- [Athena Workgroup is not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-159.md)
- [Timestream database is not encrypted with KMS CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-160.md)
- [Dynamodb point in time recovery is not enabled for global tables misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-165.md)
- [Backup Vault is not encrypted at rest using KMS CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-166.md)
- [QLDB ledger permissions mode is not set to STANDARD misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-170.md)
- [AWS EMR cluster is not configured with SSE KMS for data at rest encryption (Amazon S3 with EMRFS) mi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-171.md)
- [AWS QLDB ledger has deletion protection is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-172.md)
- [AWS Lambda encryption settings environmental variable is not set properly misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-173.md)
- [AWS Kinesis Video Stream not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-177.md)
- [AWS fx ontap file system not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-178.md)
- [AWS FSX Windows filesystem not encrypted using Customer Managed Key misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-179.md)
- [AWS Image Builder component not encrypted using Customer Managed Key misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-180.md)
- [AWS S3 Object Copy not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-181.md)
- [AWS Doc DB not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-182.md)
- [AWS EBS Snapshot Copy not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-183.md)
- [AWS Elastic File System (EFS) is not encrypted using Customer Managed Key misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-184.md)
- [AWS Kinesis streams encryption is using default KMS keys instead of Customer's Managed Master Keys m](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-185.md)
- [AWS S3 bucket Object not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-186.md)
- [AWS EBS Volume not encrypted using Customer Managed Key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-189.md)
- [AWS lustre file system not configured with CMK key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-190.md)
- [AWS Elasticache replication group not configured with CMK key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-191.md)
- [AWS Glue component is not associated with a security configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-195.md)
- [AWS Image Builder Distribution Configuration is not encrypting AMI by Key Management Service (KMS) u](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-199.md)
- [AWS Image Recipe EBS Disk are not encrypted using a Customer Managed Key (CMK) misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-200.md)
- [AWS MemoryDB is not encrypted at rest by AWS' Key Management Service KMS using CMKs misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-201.md)
- [AWS MemoryDB data is not encrypted in transit misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-202.md)
- [AWS FSX openzfs is not encrypted by AWS' Key Management Service (KMS) using a Customer Managed Key (](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-203.md)
- [AWS AMIs are not encrypted by Key Management Service (KMS) using Customer Managed Keys (CMKs) miscon](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-204.md)
- [AWS MQ Broker is not encrypted by Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-209.md)
- [AWS RDS does not use a modern CaCert misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-211.md)
- [AWS EBS Volume is not encrypted by Key Management Service (KMS) using a Customer Managed Key (CMK) m](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-212.md)
- [AWS Appsync API Cache is not encrypted at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-214.md)
- [AWS Appsync API Cache is not encrypted in transit misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-215.md)
- [AWS CodePipeline artifactStore is not encrypted by Key Management Service (KMS) using a Customer Man](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-219.md)
- [AWS Code Artifact Domain is not encrypted by KMS using a Customer Managed Key (CMK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-221.md)
- [AWS copied AMIs are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-235.md)
- [AWS AMI copying does not use a Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-236.md)
- [AWS Kinesis Firehose's delivery stream is not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-240.md)
- [AWS Kinesis Firehose Delivery Streams are not encrypted with CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-241.md)
- [AWS replicated backups are not encrypted at rest by Key Management Service (KMS) using a Customer Ma](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-245.md)
- [AWS RDS Cluster activity streams are not encrypted by Key Management Service (KMS) using Customer Ma](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-246.md)
- [AWS all data stored in the Elasticsearch domain is not encrypted using a Customer Managed Key (CMK)](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-247.md)
- [AWS RDS PostgreSQL exposed to local file read vulnerability misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-250.md)
- [AWS DLM cross-region events are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-253.md)
- [AWS DLM cross-region events are not encrypted with a Customer Managed Key (CMK) misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-254.md)
- [AWS DLM-cross region schedules are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-255.md)
- [AWS DLM cross-region schedules are not encrypted using a Customer Managed Key (CMK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-256.md)
- [AWS App Flow flow does not use Customer Managed Keys (CMKs) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-263.md)
- [AWS App Flow connector profile does not use Customer Managed Keys (CMKs) misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-264.md)
- [AWS Keyspace Table does not use Customer Managed Keys (CMKs) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-265.md)
- [AWS RDS DB snapshot does not use Customer Managed Keys (CMKs) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-266.md)
- [Comprehend Entity Recognizer's model is not encrypted by KMS using a customer managed Key (CMK) misc](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-267.md)
- [Comprehend Entity Recognizer's volume is not encrypted by KMS using a customer managed Key (CMK) mis](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-268.md)
- [Connect Instance Kinesis Video Stream Storage Config is not using CMK for encryption misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-269.md)
- [The Connect Instance S3 Storage Configuration utilizes Customer Managed Key. misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-270.md)
- [DynamoDB table replica does not use CMK KMS encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-271.md)
- [MemoryDB snapshot is not encrypted by KMS using a customer managed Key (CMK) misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-278.md)
- [Neptune snapshot is not securely encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-279.md)
- [Neptune snapshot is encrypted by KMS using a customer managed Key (CMK) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-280.md)
- [RedShift snapshot copy is not encrypted by KMS using a customer managed Key (CMK). misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-281.md)
- [Redshift Serverless namespace is not encrypted by KMS using a customer managed key (CMK) misconfigur](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-282.md)
- [DocDB Global Cluster is not encrypted at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-292.md)
- [AWS database instances do not have deletion protection enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-293.md)
- [CloudTrail Event Data Store does not use Customer Managed Keys (CMKs) misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-294.md)
- [DataSync Location Object Storage exposes secrets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-295.md)
- [DMS endpoint is not using a Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-296.md)
- [EventBridge Scheduler Schedule is not using a Customer Managed Key (CMK) misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-297.md)
- [The DMS S3 does not use a Customer Managed Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-298.md)
- [S3 lifecycle configuration does not set a period for aborting failed uploads misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-300.md)
- [Secrets Manager secrets are not rotated within 90 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-304.md)
- [CodeBuild S3 logs are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-311.md)
- [RDS Aurora Clusters do not have backtracking enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-326.md)
- [AWS RDS DB cluster is encrypted using default KMS key instead of CMK misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-327.md)
- [EFS Access Points are not enforcing a root directory misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-329.md)
- [User identity should be enforced by EFS access points misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-330.md)
- [SSM parameters are not utilizing KMS CMK. misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-337.md)
- [Amazon Redshift clusters do not have automatic snapshots enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-343.md)
- [Network firewall encryption does not use a CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-345.md)
- [Network Firewall Policy does not define an encryption configuration that uses a CMK misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-346.md)
- [Neptune is not encrypted with KMS using a customer managed Key (CMK) misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-347.md)
- [AWS EMR cluster is not enabled with local disk encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-349.md)
- [Security configuration of the EMR Cluster does not ensure the encryption of EBS disks misconfigurati](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-350.md)
- [AWS EMR cluster is not enabled with data encryption in transit misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-351.md)
- [RDS Performance Insights are not encrypted using KMS CMKs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-354.md)
- [AWS DocumentDB clusters have backup retention period less than 7 days misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-360.md)
- [AWS Neptune DB clusters have backup retention period less than 7 days misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-361.md)
- [Clusters of Neptune DB do not replicate tags to snapshots misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-362.md)
- [Bedrock Agent not encrypted with Customer Master Key (CMK) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-373.md)
- [AWS S3 bucket has global view ACL permissions enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-375.md)
- [AWS CodeGuru Reviewer repository association does not use a Customer Managed Key (CMK) misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-381.md)
- [Not all data stored in the EBS snapshot is securely encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-aws-custom-3.md)
- [Azure VM data disk is not encrypted with ADE/CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-2.md)
- [Azure Storage Account without Secure transfer enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-3.md)
- [Azure PostgreSQL database server with log checkpoints parameter disabled misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-30.md)
- [Azure PostgreSQL database server with log connections parameter disabled misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-31.md)
- [Azure PostgreSQL database server with connection throttling parameter is disabled misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-32.md)
- [Azure Storage Account 'Trusted Microsoft Services' access not enabled misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-36.md)
- [Azure Key Vault Keys does not have expiration date misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-40.md)
- [Azure Key Vault secrets does not have expiration date misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-41.md)
- [Azure Key Vault is not recoverable misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-42.md)
- [Storage Account name does not follow naming rules misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-43.md)
- [Azure Storage Account using insecure TLS version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-44.md)
- [MSSQL is not using the latest version of TLS encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-52.md)
- [Azure Automation account variables are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-73.md)
- [Azure Data Explorer cluster disk encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-74.md)
- [Azure Data Explorer cluster double encryption is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-75.md)
- [Azure Batch account does not use key vault to encrypt data misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-76.md)
- [App services do not use Azure files misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-88.md)
- [Not only SSL are enabled for cache for Redis misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-91.md)
- [Managed disks do not use a specific set of disk encryption sets for customer-managed key encryption](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-93.md)
- [My SQL server disables geo-redundant backups misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-94.md)
- [MySQL server disables infrastructure encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-96.md)
- [Virtual machine scale sets do not have encryption at host enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-97.md)
- [Cosmos DB Accounts do not have CMKs encrypting data at rest misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-100.md)
- [PostgreSQL server enables geo-redundant backups misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-102.md)
- [Unencrypted Data Lake Store accounts misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-105.md)
- [Azure Key Vault Purge protection is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-110.md)
- [Key vault does not enable soft-delete misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-111.md)
- [Key vault key is not backed by HSM misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-112.md)
- [Key vault secrets do not have content\_type set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-114.md)
- [Azure AKS cluster is not configured with disk encryption set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-117.md)
- [MariaDB server does not enable geo-redundant backups misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-129.md)
- [PostgreSQL server does not enable infrastructure encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-130.md)
- [Azure Cosmos DB key based authentication is enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-132.md)
- [Azure PostgreSQL Flexible Server does not enable geo-redundant backups misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-136.md)
- [Azure PostgreSQL does not use the latest version of TLS encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-147.md)
- [Azure Windows VM does not enable encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-151.md)
- [Geo-Replicated Not Enabled for Azure Container Registry (ACR) misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-165.md)
- [Azure Container Registry (ACR) Does Not Have a Quarantine Policy Enabled misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-166.md)
- [Azure Container Registry (ACR) Doesn't Have a Retention Policy Set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-167.md)
- [AKS Secrets Store Without Auto-Rotation misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-172.md)
- [Azure Data Explorer without SLA misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-180.md)
- [App Configuration Encryption Block Not Set misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-186.md)
- [App Configuration Without Purge Protection Enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-187.md)
- [Azure Service Bus Doesn't Use Double Encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-199.md)
- [Azure Service Bus Doesn't Use Customer-Managed Key Encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-201.md)
- [Azure Storage Accounts Without Proper Replication misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-206.md)
- [Azure Cognitive Search Without SLA Index Updates misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-208.md)
- [Azure Cognitive Search Without SLA for Search Index Queries misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-209.md)
- [App Service Plan is not zone redundant misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-225.md)
- [AKS cluster not encrypting temp disks, caches, and data flows misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-227.md)
- [Azure Event Hub Namespace is not zone redundant misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-228.md)
- [Azure SQL Database Namespace is not zone redundant misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-229.md)
- [Standard Replication is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-230.md)
- [App Service Environment is not zone redundant misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-231.md)
- [Azure Container Registry (ACR) not zone redundant misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-azure-233.md)
- [GCP SQL database instance does not have backup configuration enabled misconfiguration detected in co](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-14.md)
- [GCP cloud storage bucket with uniform bucket-level access disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-29.md)
- [GCP VM disks not encrypted with Customer-Supplied Encryption Keys (CSEK) misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-37.md)
- [Boot disks for instances do not use CSEKs misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-38.md)
- [GCP KMS Symmetric key not rotating in every 90 days misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-43.md)
- [GCP MySQL instance with local\_infile database flag is not disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-50.md)
- [GCP SQL Server instance database flag 'cross db ownership chaining' is enabled misconfiguration dete](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-58.md)
- [GCP SQL Server instance database flag 'contained database authentication' is enabled misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-59.md)
- [GCP Storage Bucket does not have Access and Storage Logging enabled misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-62.md)
- [GCP storage bucket is logging to itself misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-63.md)
- [GCP Cloud storage does not have versioning enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-78.md)
- [GCP Big Query Tables are not encrypted with Customer Supplied Encryption Keys (CSEK) misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-80.md)
- [GCP Big Query Datasets are not encrypted with Customer Supplied Encryption Keys (CSEK) misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-81.md)
- [GCP KMS keys are not protected from deletion misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-82.md)
- [GCP Pub/Sub Topics are not encrypted with Customer Supplied Encryption Keys (CSEK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-83.md)
- [GCP Artifact Registry repositories are not encrypted with Customer Supplied Encryption Keys (CSEK) m](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-84.md)
- [GCP Big Table Instances are not encrypted with Customer Supplied Encryption Keys (CSEKs) misconfigur](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-85.md)
- [GCP data flow jobs are not encrypted with Customer Supplied Encryption Keys (CSEK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-90.md)
- [GCP Dataproc Cluster not configured with Customer-Managed Encryption Key (CMEK) misconfiguration det](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-91.md)
- [GCP Spanner Database is not encrypted with Customer Supplied Encryption Keys (CSEKs) misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-93.md)
- [GCP Memorystore for Redis does not use intransit encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-97.md)
- [Deletion protection for Spanner Database is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-119.md)
- [Spanner Database does not have drop protection enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-120.md)
- [BigQuery tables do not have deletion protection enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-121.md)
- [Big Table Instances do not have deletion protection enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-gcp-122.md)
- [GitHub Actions Environment Secrets defined in Terraform are not encrypted misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-git-4.md)
- [Gitlab project defined in Terraform does not prevent secrets misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-glb-3.md)
- [The --etcd-certfile and --etcd-keyfile arguments are not set appropriately misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-k8s-99.md)
- [Encryption providers are not appropriately configured misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-k8s-104.md)
- [The --cert-file and --key-file arguments are not set appropriately misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-k8s-116.md)
- [The --peer-cert-file and --peer-key-file arguments are not set appropriately misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-k8s-119.md)
- [OCI Block Storage Block Volume does not have backup enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-2.md)
- [OCI Block Storage Block Volumes are not encrypted with a Customer Managed Key (CMK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-3.md)
- [OCI Object Storage bucket does not emit object events misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-7.md)
- [OCI Object Storage Bucket has object Versioning disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-8.md)
- [OCI Object Storage Bucket is not encrypted with a Customer Managed Key (CMK) misconfiguration detect](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-9.md)
- [OCI Object Storage bucket is publicly accessible misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-10.md)
- [OCI File Storage File Systems are not encrypted with a Customer Managed Key (CMK) misconfiguration d](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec-oci-15.md)
- [Not only encrypted EBS volumes are attached to EC2 instances misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-2.md)
- [RDS clusters do not have an AWS Backup backup plan misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-8.md)
- [EBS does not have an AWS Backup backup plan misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-9.md)
- [AWS DynamoDB table Auto Scaling not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-16.md)
- [Amazon EFS does not have an AWS Backup backup plan misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-18.md)
- [AWS SSM Parameter is not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-34.md)
- [AWS ElastiCache Redis cluster with Multi-AZ Automatic Failover feature set to disabled misconfigurat](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-50.md)
- [AWS EMR cluster is not configured with security configuration misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-55.md)
- [AWS Secret Manager Automatic Key Rotation is not enabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-57.md)
- [AWS Neptune cluster deletion protection is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-58.md)
- [AWS S3 bucket access control lists (ACLs) in use misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-65.md)
- [AWS RDS database instance not configured with encryption in transit misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-69.md)
- [AWS SQS queue encryption using default KMS key instead of CMK misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-aws-73.md)
- [Storage for critical data are not encrypted with Customer Managed Key misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-1.md)
- [Azure Data Explorer encryption at rest does not use a customer-managed key misconfiguration detected](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-11.md)
- [Virtual Machines are not backed up using Azure Backup misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-12.md)
- [Unattached disks are not encrypted misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-14.md)
- [Azure data factories are not encrypted with a customer-managed key misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-15.md)
- [MySQL server does not enable customer-managed key for encryption misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-16.md)
- [PostgreSQL server does not enable customer-managed key for encryption misconfiguration detected in c](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-17.md)
- [Azure Storage account Encryption CMKs Disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-18.md)
- [Azure SQL database Transparent Data Encryption (TDE) encryption disabled misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-25.md)
- [Azure MariaDB database server not using latest TLS version misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-37.md)
- [Azure Storage account soft delete is disabled misconfiguration detected in code](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-38.md)
- [GCP SQL MySQL DB instance point-in-time recovery backup (Binary logs) is not enabled misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-gcp-20.md)
- [Vertex AI instance disks not encrypted with a Customer Managed Key (CMK) misconfiguration detected i](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-gcp-21.md)
- [Document AI Processors not encrypted with a Customer Managed Key (CMK) misconfiguration detected in](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-gcp-22.md)
- [Document AI Warehouse Location is not configured to use a Customer Managed Key (CMK) misconfiguratio](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-gcp-23.md)
- [Vertex AI workbench instance disks not encrypted with a Customer Managed Key (CMK) misconfiguration](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-gcp-27.md)
- [OCI File Storage File System access is not restricted to root users misconfiguration detected in cod](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-oci-4.md)
- [OCI Kubernetes Engine Cluster boot volume is not configured with in-transit data encryption misconfi](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-oci-5.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
