Prisma Cloud Remediation - AWS Inactive Users For More Than 30 Days
Prisma Cloud by Palo Alto Networks Pack.#
This Playbook is part of theRemediates Prisma Cloud Alert inactive users for more than 30 days, this playbook deactivates the user by disabling the access keys (marking them as inactive) as well as resetting the user console password.
To increase the security of your AWS account, it is recommended to find and remove IAM user credentials (passwords, access keys) that have not been used within a specified period of time.
#
DependenciesThis playbook uses the following sub-playbooks, integrations, and scripts.
#
Sub-playbooksThis playbook does not use any sub-playbooks.
#
Integrations- Builtin
#
Scripts#
Commands- aws-iam-update-login-profile
- closeInvestigation
- aws-iam-list-access-keys-for-user
- aws-iam-update-access-key
#
Playbook InputsName | Description | Default Value | Required |
---|---|---|---|
AutoQuarantine | Can be, "yes" - access keys will be disabled and password reset, or "no" - an analyst will be prompted for action. | no | Required |
#
Playbook OutputsThere are no outputs for this playbook.