Enterprise SQL task catalog.
127 public tasks · ISPM-Enterprise-SQL@v1
Tasks
127 tasks
Are there users with access keys that were created during setup but never used?
aws-access-keys-were-createdDormant & stalePlatform-levelMediumAWSDo any active access keys have a creation date older than 90 days?
aws-active-access-keys-creationDormant & stalePlatform-levelAWSWhich active access keys are older than 90 days?
aws-active-access-keys-olderDormant & stalePlatform-levelAWSIs the AWSSupportAccess AWS managed policy attached to at least one principal (user, group, or role)?
aws-awssupportaccess-managed-policy-attachedPrivilege & exposurePlatform-levelAWSAre there users who do not belong to the common IAM group?
aws-belong-common-groupInventory & visibilityPlatform-levelMediumAWSDo any IAM users have both a console password and one or more active API keys?
aws-both-console-password-oneCredential hygienePlatform-levelMediumAWSWhich IAM users have console passwords enabled but no MFA?
aws-console-passwords-but-mfaAuth posturePlatform-levelAWSDo any customer-managed policies allow a specific service:action on all resources (*)?
aws-customer-managed-policies-allow-specificPrivilege & exposurePlatform-levelAWSAre there customer-managed policies with no attachments?
aws-customer-managed-policies-attachmentsPrivilege & exposurePlatform-levelAWSDo any attached customer-managed policies grant permissions other than sts:AssumeRole?
aws-customer-managed-policies-grant-permissionsPrivilege & exposurePlatform-levelAWSDo any customer-managed IAM policies use NotAction in Allow statements?
aws-customer-managed-policies-use-notactionPrivilege & exposurePlatform-levelAWSAre there EC2 service roles that are not attached to any running EC2 instances?
aws-ec2-service-roles-attachedPrivilege & exposurePlatform-levelMediumAWSDo any IAM groups have inline policies attached?
aws-groups-inline-policies-attachedPrivilege & exposurePlatform-levelAWSIs a hardware MFA device enabled on the root account?
aws-hardware-mfa-device-rootAuth posturePlatform-levelAWSList high-privilege non-human identities by type (AWS execution roles, AWS cross-account roles).
aws-high-privilege-non-human-identities-typeInventory & visibilityPlatform-levelAWSDo any human IAM users have policies attached directly (inline or managed)?
aws-human-policies-attached-directlyPrivilege & exposurePlatform-levelAWSAre there users with inline or managed policies attached directly?
aws-inline-managed-policies-attachedPrivilege & exposurePlatform-levelAWSDo any user inline policies allow actions other than sts:AssumeRole?
aws-inline-policies-allow-actionsPrivilege & exposurePlatform-levelAWSDo any inline policies in IAM identities use NotAction with an Allow effect?
aws-inline-policies-identities-usePrivilege & exposurePlatform-levelAWSAre there any managed policies that allow Action = "*" and Resource = "*"?
aws-managed-policies-allow-actionPrivilege & exposurePlatform-levelAWSIs MFA enabled on the root account?
aws-mfa-rootAuth posturePlatform-levelAWSDo any users have more than one active access key?
aws-one-active-access-keyAuth posturePlatform-levelAWSDo all password-enabled IAM users have MFA enabled?
aws-password-enabled-mfaAuth posturePlatform-levelAWSIs password expiration enabled in the IAM password policy?
aws-password-expiration-policyCredential hygienePlatform-levelAWSDoes the account password policy enforce password expiration and set MaxPasswordAge ≤ 90 days?
aws-password-policy-enforce-expirationCredential hygienePlatform-levelAWSDoes the password policy prevent the reuse of previous passwords?
aws-password-policy-prevent-reuseCredential hygienePlatform-levelAWSIs the IAM password policy configured to require at least 14 characters?
aws-password-policy-require-leastCredential hygienePlatform-levelAWSDoes the IAM password policy require at least one lowercase letter?
aws-password-policy-require-least-2Credential hygienePlatform-levelAWSDoes the password policy require at least one numeric character?
aws-password-policy-require-least-3Credential hygienePlatform-levelAWSDoes the password policy require at least one special character?
aws-password-policy-require-least-4Credential hygienePlatform-levelAWSDoes the IAM password policy require at least one uppercase letter?
aws-password-policy-require-least-5Credential hygienePlatform-levelAWSAre there any users with passwords or access keys that have not been used in over 90 days and are still enabled?
aws-passwords-access-keys-usedDormant & stalePlatform-levelMediumAWSDo any policies deny user actions on group resources rather than on the users themselves?
aws-policies-deny-actions-groupPrivilege & exposurePlatform-levelAWSDo any IAM roles allow an AWS principal to perform the sts:AssumeRole action without requiring MFA in their trust policies?
aws-roles-allow-sts-assumerolePrivilege & exposurePlatform-levelAWSDo any IAM roles have inline policies that allow a specific service:action on all resources (*)?
aws-roles-inline-policies-allowPrivilege & exposurePlatform-levelAWSDo any IAM roles have inline policies attached?
aws-roles-inline-policies-attachedPrivilege & exposurePlatform-levelAWSWhich roles have inline policies attached?
aws-roles-inline-policies-attached-2Privilege & exposurePlatform-levelAWSWhich IAM roles trust external accounts (not in AWS Organizations)?
aws-roles-trust-external-accountsPrivilege & exposurePlatform-levelAWSDo any IAM roles have trust policies that allow principals from other accounts without requiring MFA or an External ID?
aws-roles-trust-policies-allowPrivilege & exposurePlatform-levelAWSAre there IAM roles whose trust policies allow any AWS principal (e.g., Principal set to "*")?
aws-roles-trust-policies-allow-2Privilege & exposurePlatform-levelAWSDoes the root account have any active X.509 certificates?
aws-root-active-509-certificatesAuth posturePlatform-levelAWSDoes the root account have any active access keys?
aws-root-active-access-keysAuth posturePlatform-levelAWSIs root MFA enforced?
aws-root-mfa-enforcedAuth posturePlatform-levelAWSHas the root account been used within the last 90 days?
aws-root-used-last-90Dormant & stalePlatform-levelAWSList secrets in AWS per resource and per owner type (root, IAM user, role).
aws-secrets-resource-owner-typeInventory & visibilityPlatform-levelAWSDo any service users (identified by membership in a service-user group) have console passwords enabled?
aws-service-identified-membership-service-userCredential hygienePlatform-levelMediumAWSWhich users have AWS SSO access but don't have a corresponding employee record in our BambooHR system?
cross-access-but-don-correspondingCross-vendor explorationCross-platformMediumAWS · BambooHR · OktaAccording to BambooHR, do any employees classified as contractors, external, or freelancers have AWS SSO account?
cross-according-employees-classified-contractorsCross-vendor explorationCross-platformMediumAWS · BambooHR · OktaAre there any Google Workspace accounts still active for employees who have been terminated?
cross-accounts-active-employees-terminatedLifecycle & offboardingCross-platformHardBambooHR · Google Workspace · OktaAre there any Okta accounts that don't match a current employee or contractor in BambooHR?
cross-accounts-don-match-currentCross-vendor explorationCross-platformMediumBambooHR · OktaList AWS IAM Users who have an active Access Key (Secret) older than 90 days but have never logged into Okta.
cross-active-access-key-secretDormant & staleCross-platformMediumAWS · OktaAre there any active GitHub accounts for users who have been disabled in Azure AD?
cross-active-accounts-disabledLifecycle & offboardingCross-platformMediumAzure · GitHubList all users who have an active account in Google Workspace but are synced through Okta.
cross-active-but-synced-throughCross-vendor explorationCross-platformMediumGoogle Workspace · OktaWhich active Okta users who are GitHub organization members have two-factor authentication disabled on GitHub, broken down by their organization role (MEMBER vs ADMIN)?
cross-active-organization-members-two-factorAuth postureCross-platformMediumGitHub · OktaWhich active Okta users that also have an AWS IAM Identity Store identity have no phishing-resistant MFA factor enrolled?
cross-active-phishing-resistant-mfa-factorAuth postureCross-platformHardAWS · OktaWhich active Okta users are provisioned in AWS Identity Store, hold ADMIN permission on at least one GitHub repository, and have a Google Workspace administrator role?
cross-active-provisioned-identity-storePrivilege & exposureCross-platformHardAWS · GitHub · Google Workspace · OktaWhich active Google Workspace users have role assignments, and do they have a matching Okta identity (including Okta status)?
cross-active-role-assignments-matchingCross-vendor explorationCross-platformHardGoogle Workspace · OktaWho has admin access in Mongo that wasn't provisioned through Okta?
cross-admin-access-wasn-provisionedCross-vendor explorationCross-platformMediumMongoDB Atlas · OktaWhich AWS SSO users with admin-level access have an inactive or missing Okta account?
cross-admin-level-access-inactive-missingCross-vendor explorationCross-platformHardAWS · OktaWhich Google Workspace administrators also hold a primitive Owner or Editor role in GCP?
cross-administrators-also-hold-primitivePrivilege & exposureCross-platformMediumGCP · Google WorkspaceWho are the Google Workspace admins that aren't listed as admins in Okta?
cross-admins-aren-listedCross-vendor explorationCross-platformHardGoogle Workspace · OktaWho are the Azure AD admins that aren't listed as admins in Okta?
cross-admins-aren-listed-2Cross-vendor explorationCross-platformHardAzure · OktaCan anyone without MFA can access our production systems S3 Buckets or AWS Databases?
cross-anyone-without-mfa-accessAuth postureCross-platformHardAWS · OktaAre there any AWS IAM credentials whose owning IAM user cannot be traced back to an active BambooHR employee through Okta?
cross-credentials-owning-cannot-tracedCross-vendor explorationCross-platformHardAWS · BambooHR · OktaAre there any users that are deactivated in Okta but still active in AWS?
cross-deactivated-but-activeLifecycle & offboardingCross-platformHardAWS · OktaAre there deprovisioned users in Okta with admin access in GitHub?
cross-deprovisioned-admin-accessLifecycle & offboardingCross-platformHardGitHub · OktaAre there any disabled Okta users who still have active Google Workspace accounts?
cross-disabled-active-accountsLifecycle & offboardingCross-platformMediumGoogle Workspace · OktaWhich former employees still own Google Workspace documents (private or shared drives) after their termination?
cross-documents-owned-longer-workingLifecycle & offboardingCross-platformHardBambooHR · Google WorkspaceWhich employees have active admin role assignments in Okta and what is their department in BambooHR?
cross-employees-active-admin-roleInventory & visibilityCross-platformHardBambooHR · OktaWhich employees marked as terminated in BambooHR have authored commits in GitHub after their recorded termination date?
cross-employees-marked-terminated-authoredLifecycle & offboardingCross-platformMediumBambooHR · GitHubWhich users exist in both EntraID and GWS but don't have 2SV enforced in Google Workspace?
cross-exist-both-entraid-butAuth postureCross-platformMediumAzure · Google WorkspaceAre there any external email addresses with access to any shared GWS files that are not managed through Okta?
cross-external-email-addresses-accessCross-vendor explorationCross-platformMediumGoogle Workspace · OktaWhich GitHub organization members without MFA enabled also have AWS admin-level permissions or MongoDB Atlas admin roles (ORG_OWNER, ORG_BILLING_ADMIN, GROUP_OWNER)?
cross-find-without-mfa-identifyCross-vendor explorationCross-platformHardAWS · GitHub · MongoDB AtlasWhich AWS SSO users haven't logged into Okta in 90 days but are still active in Okta?
cross-haven-logged-90-daysDormant & staleCross-platformMediumAWS · OktaWhich users haven't used GWS for 90 days but still listed as active in Okta?
cross-haven-used-90-daysDormant & staleCross-platformMediumGoogle Workspace · OktaList high-privilege human identities by type (AWS IAM, Okta).
cross-high-privilege-human-identities-typeInventory & visibilityCross-platformMediumAWS · OktaShow me users who left the company but still have GitHub access.
cross-left-company-but-accessLifecycle & offboardingCross-platformMediumBambooHR · GitHubAre any marketing or finance users granted write access to our code base?
cross-marketing-finance-granted-writePrivilege & exposureCross-platformHardBambooHR · GitHubWhich Okta users have the most publicly accessible files in Google Workspace?
cross-most-publicly-accessible-filesPrivilege & exposureCross-platformHardGoogle Workspace · OktaDo any non-IT or non-R&D employees have super admin access to Google Workspace?
cross-non-it-non-r-employees-superPrivilege & exposureCross-platformMediumBambooHR · Google WorkspaceDo any offboarded employees still have active AWS accounts?
cross-offboarded-employees-active-accountsLifecycle & offboardingCross-platformHardAWS · BambooHRAre there any GitHub org members with no matching BambooHR employee record?
cross-org-members-matching-employeeCross-vendor explorationCross-platformMediumBambooHR · GitHubAre there any GitHub org members not provisioned through Okta?
cross-org-members-provisioned-throughCross-vendor explorationCross-platformMediumGitHub · OktaWhich GitHub organization members have no corresponding identity in Azure AD?
cross-organization-members-corresponding-identityCross-vendor explorationCross-platformMediumAzure · GitHubWhich GitHub organization members hold GCP primitive roles (Owner or Editor), and what is their GitHub role?
cross-organization-members-hold-primitivePrivilege & exposureCross-platformMediumGCP · GitHubWhich GitHub organization members with two-factor authentication disabled also hold direct user-level IAM role bindings in GCP, and what privileged roles do they have?
cross-organization-members-two-factor-authenticationPrivilege & exposureCross-platformMediumGCP · GitHubWhich GitHub users are Organization Owners but do not have a corresponding active account in Okta?
cross-organization-owners-but-correspondingCross-vendor explorationCross-platformMediumGitHub · OktaWhich Google Workspace users with GCP IAM permissions can bypass MFA?
cross-permissions-bypass-mfaAuth postureCross-platformMediumGCP · Google WorkspaceWhich Azure AD users registered only with weak MFA methods (SMS or phone call) are also GitHub organization members?
cross-registered-only-weak-mfaAuth postureCross-platformHardAzure · GitHub · OktaList all Super Admins (for periodic review).
cross-super-admins-periodic-reviewInventory & visibilityCross-platformMediumGoogle Workspace · OktaAre there any MongoDB Atlas users who are terminated in BambooHR or deactivated in Okta?
cross-terminated-deactivatedLifecycle & offboardingCross-platformHardBambooHR · MongoDB Atlas · OktaWhich terminated employees still have AWS SSO access?
cross-terminated-employees-accessLifecycle & offboardingCross-platformHardAWS · BambooHR · OktaAre there any terminated employees who have both an active Google Workspace account and direct user-level IAM role bindings in our GCP projects?
cross-terminated-employees-both-activeLifecycle & offboardingCross-platformHardBambooHR · Google WorkspaceWhich terminated employees have not been fully offboarded from all connected systems (Okta, Google Workspace, Azure AD, or AWS SSO)?
cross-terminated-employees-fully-offboardedLifecycle & offboardingCross-platformHardAWS · Azure · BambooHR · Google Workspace · OktaDo any terminated employees own publicly accessible files in their Google Drive personal storage?
cross-terminated-employees-own-publiclyLifecycle & offboardingCross-platformHardBambooHR · Google WorkspaceWhich terminated external workers (non-Osbench Labs employees) in BambooHR still have an active Okta account or GitHub organization membership?
cross-terminated-external-workers-non-osbenchLifecycle & offboardingCross-platformHardBambooHR · GitHub · OktaWhich terminated users still have read permissions to any shared GWS documents not owned by them?
cross-terminated-read-permissions-sharedLifecycle & offboardingCross-platformMediumBambooHR · Google WorkspaceWhich terminated users still have write permissions to any shared GWS documents not owned by them?
cross-terminated-write-permissions-sharedLifecycle & offboardingCross-platformMediumBambooHR · Google WorkspaceWhich Google Workspace admin users are missing 2-Step Verification?
gws-admin-missing-2-step-verificationAuth posturePlatform-levelGoogle WorkspaceAre all domains configured to restrict third-party applications and disallow less-secure apps?
gws-domains-restrict-third-party-applicationsAuth posturePlatform-levelGoogle WorkspaceAre Google Workspace domains configured with Single Sign-On ensuring that post-SSO verification is enabled for the primary SSO profile?
gws-domains-single-sign-on-ensuringAuth posturePlatform-levelMediumGoogle WorkspaceAre all users labeled as sensitive enrolled in Google's Advanced Protection Program?
gws-labeled-sensitive-enrolled-advancedAuth posturePlatform-levelGoogle WorkspaceAre there any users whose MFA method is configured as SMS or voice call?
gws-mfa-method-sms-voiceAuth posturePlatform-levelGoogle WorkspaceIs the minimum password length configured to 15 characters or more?
gws-minimum-password-length-15Credential hygienePlatform-levelGoogle WorkspaceIs the minimum password length at least 12 characters?
gws-minimum-password-length-leastCredential hygienePlatform-levelGoogle WorkspaceIs the new user 2-Step Verification enrollment period configured between 1 and 7 days for each organization unit?
gws-new-2-step-verification-enrollmentAuth posturePlatform-levelGoogle WorkspaceIs the number of Google Workspace Super Admin users between 2 and 8 inclusive?
gws-number-super-admin-inclusivePrivilege & exposurePlatform-levelMediumGoogle WorkspaceAre password expiration policies disabled for all organizational units?
gws-password-expiration-policies-disabledCredential hygienePlatform-levelGoogle WorkspaceIs the password policy configured to be enforced at the next sign-in for all organizational units?
gws-password-policy-enforced-nextCredential hygienePlatform-levelGoogle WorkspaceIs password reuse disabled for all organizational units?
gws-password-reuse-disabledCredential hygienePlatform-levelGoogle WorkspaceDo all privileged accounts (Super Admins and other high-privilege roles) authenticate with Google credentials and use phishing-resistant MFA?
gws-privileged-accounts-super-adminsAuth posturePlatform-levelGoogle WorkspaceAre account recovery options disabled for all users who are not Super Admins?
gws-recovery-options-disabled-superAuth posturePlatform-levelGoogle WorkspaceAre self-service account recovery options disabled for users assigned the Super Admin role?
gws-self-service-recovery-options-disabledAuth posturePlatform-levelHardGoogle WorkspaceWhich Okta users are active but have not signed in for over 90 days?
okta-active-but-signed-90Dormant & stalePlatform-levelOktaAre there any active users who are no longer members of any group assigned through an Application or IdP?
okta-active-longer-members-groupDormant & stalePlatform-levelHardOktaWhich active Okta users have not signed in for more than 90 days?
okta-active-signed-90-daysDormant & stalePlatform-levelOktaWhich applications' default access rules do not require MFA?
okta-applications-default-access-rulesAuth posturePlatform-levelOktaWhich applications have mfa_required set to FALSE or NULL?
okta-applications-mfa-required-falseAuth posturePlatform-levelOktaWhich Okta connections lack signed and encrypted SAML assertions?
okta-connections-lack-signed-encryptedAuth posturePlatform-levelOktaDo any identity providers (IdPs) lack signed or encrypted SAML assertions?
okta-identity-providers-idps-lackAuth posturePlatform-levelOktaAre any legacy authentication factors (SMS, voice, email, OTP) enabled?
okta-legacy-authentication-factors-smsAuth posturePlatform-levelOktaAre MFA policies missing phishing-resistant authenticators?
okta-mfa-policies-missing-phishing-resistantAuth posturePlatform-levelMediumOktaDoes the password policy enforce a minimum length of at least 12 characters and require uppercase letters, lowercase letters, numbers and symbols?
okta-password-policy-enforce-minimumCredential hygienePlatform-levelOktaWhich sign-on policies exceed a 120-minute session lifetime?
okta-sign-on-policies-exceed-120-minuteAuth posturePlatform-levelOktaWhich sign-on policies have a reauthentication interval greater than 480 minutes (8 hours) or have no reauthentication interval set?
okta-sign-on-policies-reauthentication-intervalAuth posturePlatform-levelOktaAre there any sign-on policies where the maximum session lifetime (max_session_lifetime_minutes) exceeds 120 minutes (2 hours)?
okta-sign-on-policies-where-maximumAuth posturePlatform-levelOktaAre there any sign-on policies where require_mfa_each_signin is FALSE or NULL?
okta-sign-on-policies-where-requireAuth posturePlatform-levelOkta