Community
Questions Library
Docs
Blog
Events
Swag
Github
Slack
JupiterOne
Discussions
Release Notes
Contact Us
JupiterOne 2021.65 Release - AskJ1 Community
<main> <article class="userContent"> <p>2021-02-24</p> <p>Exciting new look and feel matching our redesigned branding and color scheme.<br> Lots of integration related work, performance improvements, UI/UX updates, and<br> bug fixes in additional to the rebranding.</p> <h2 data-id="integrations">Integrations</h2> <h3 data-id="aws">AWS</h3> <ul><li><p>Set <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">numericSeverity</code> on <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">aws_ecr_image_scan_finding</code> based on <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">severity</code> string.</p></li> <li><p>Set <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">open: true</code> on <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">aws_ecr_image_scan_finding</code> entities.</p></li> <li><p>Set <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">webLink</code> on <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">aws_ecr_image_scan_finding</code> to point to NVD website if the finding is a CVE.</p></li> <li><p>Updated <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">fullName</code> on <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">aws_ecr_image</code> entities to use digest when a tag is not defined.</p></li> <li><p>Built mapped relationships between any <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Host</code>, <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Function</code>, or <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Container</code> that uses an <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">aws_ecr_image</code>.</p></li> <li><p>Captured the following properties to <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">aws_lambda_function</code> entities:</p> <p><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">codeRepoType</code>, <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">codeLocation</code>, <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">codeImageUri</code> (with <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">containerImages</code> as an<br> alias), <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">codeResolvedImageUri</code>, <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">concurrency</code>, <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">layers</code>, <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">packageType</code>, and<br><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">efsArns</code>.</p></li> </ul><blockquote class="UserQuote blockquote"><div class="QuoteText blockquote-content"> <p class="blockquote-line">This change requires an additional <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Lambda.GetFunction</code> IAM permission.</p> </div></blockquote> <ul><li><p>Built <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">aws_lambda_function_uses_layer</code> mapped relationships.</p></li> <li><p>Added <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">fqdn</code> to <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">aws_efs_file_system</code> entity.</p></li> </ul><h3 data-id="azure">Azure</h3> <ul><li><p>Added support for <strong>Diagnostic Settings</strong>:</p> <ul><li>Network Load Balancers</li> <li>Network Public IP Addresses</li> <li>Network Virtual Networks</li> <li>Network Firewalls</li> </ul></li> <li><p>Fixed <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Virtual Networks</code> step failures when <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Network Security Groups</code> step could not access some data.</p></li> </ul><h3 data-id="bitbucket">Bitbucket</h3> <ul><li>Added <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">createdOn</code> and <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">updatedOn</code> to <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">bitbucket_repo</code> entities.</li> <li>Fixed <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">404</code> error fetching details of a deleted repository.</li> </ul><h3 data-id="checkmarx">Checkmarx</h3> <ul><li>Initial release of Checkmarx integration (beta)! 🎉</li> </ul><blockquote class="UserQuote blockquote"><div class="QuoteText blockquote-content"> <p class="blockquote-line">Check out the <a rel="nofollow" href="../docs/integrations/checkmarx/checkmarx.md">docs</a> for details on<br> what's currently supported.</p> </div></blockquote> <h3 data-id="github">GitHub</h3> <ul><li>Added <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">createdOn</code> and <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">updatedOn</code> to <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">github_repo</code> entities.</li> <li>Fixed <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">createAt</code>, renamed to <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">createdAt</code>.</li> </ul><h3 data-id="google-cloud">Google Cloud</h3> <ul><li><p>Added a number of managed questions to support CIS Benchmarks, more on the way! A few examples:</p> <ul><li>Are there Cloud KMS crypto keys that are publicly accessible?</li> <li>Are Domain Name System Security Extensions (DNSSEC) enabled for Cloud DNS?</li> <li>Are my key-signing keys used in Cloud DNS DNSSEC using an insecure algorithm?</li> <li>Are my zone-signing keys used in Cloud DNS DNSSEC using an insecure algorithm?</li> <li>Are any of my Google Compute instances using the default service account with full access to all cloud APIs?</li> </ul></li> </ul><blockquote class="UserQuote blockquote"><div class="QuoteText blockquote-content"> <p class="blockquote-line">See them all in the <br><a rel="nofollow" href="https://ask.us.jupiterone.io/filter?integrations=google_cloud&tagFilter=all">J1 Questions Library</a>.</p> </div></blockquote> <ul><li><p>Added support for <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">--skip-project-id-regex</code> in the <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">jupiterone-organization-setup</code> CLI.</p></li> <li><p>Added ingestion of the following <strong>new</strong> resources:</p></li> </ul><table><thead><tr><th>Service</th> <th>Resource / Entity</th> </tr></thead><tbody><tr><td>Logging</td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_logging_metric</code></td> </tr><tr><td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_logging_project_sink</code></td> </tr><tr><td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_monitoring_alert_policy</code></td> </tr><tr><td>Networking</td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_compute_health_check</code></td> </tr><tr><td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_compute_instance_group</code></td> </tr><tr><td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_compute_url_map</code></td> </tr><tr><td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_compute_backend_bucket</code></td> </tr><tr><td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_compute_target_ssl_proxy</code></td> </tr><tr><td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_compute_target_https_proxy</code></td> </tr><tr><td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_compute_target_http_proxy</code></td> </tr><tr><td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_compute_ssl_policy</code></td> </tr><tr><td>Compute</td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_compute_project</code></td> </tr><tr><td>GKE *</td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_container_cluster</code></td> </tr></tbody></table><blockquote class="UserQuote blockquote"><div class="QuoteText blockquote-content"> <p class="blockquote-line"><em>* GKE - Google Kubernetes Engine</em></p> </div></blockquote> <ul><li>Added new properties to various existing <strong>Storage</strong> resources:</li> </ul><table><thead><tr><th>Service</th> <th>Resource / Entity</th> <th>Properties</th> </tr></thead><tbody><tr><td>Storage</td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_storage_bucket</code></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">retentionPolicyEnabled</code></td> </tr><tr><td></td> <td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">retentionPeriod</code></td> </tr><tr><td></td> <td></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">retentionDate</code></td> </tr><tr><td>KMS</td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">google_kms_crypto_key</code></td> <td><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">public</code></td> </tr></tbody></table><ul><li>Fixed <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">fetch-compute-project</code> step failure when the service account used to<br> execute the integration does not have the <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">compute.projects.get</code> permission.</li> </ul><h3 data-id="jumpcloud">Jumpcloud</h3> <ul><li>Migrated integration to latest SDK and infrastructure for more reliable execution.</li> <li>Added <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">jumpcloud_account</code> <strong>HAS</strong> <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">jumpcloud_group</code> relationship.</li> <li>Fixed paginatation of group members.</li> </ul><h3 data-id="microsoft-365">Microsoft 365</h3> <ul><li>Initial release of Microsoft 365 integration (beta)! 🎉</li> </ul><blockquote class="UserQuote blockquote"><div class="QuoteText blockquote-content"> <p class="blockquote-line">Check out the <a rel="nofollow" href="../docs/integrations/microsoft365/index.md">docs</a> for details<br> on what's currently supported.</p> </div></blockquote> <h3 data-id="qualys">Qualys</h3> <ul><li><p>Host <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Finding.targets</code> has been adjusted to include only <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">[detection.HOST.IP, assetHost.fqdn, assetHost.ec2InstanceArn]</code>; only <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">fqdn</code> and <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">ec2InstanceArn</code><br> will be used for mapping to the <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Host</code> entity.</p></li> <li><p>Host <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Finding</code> entities now have properties <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">fqdn</code>, <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">ec2InstanceArn</code>, used to<br> map the <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Finding</code> to the <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Host</code> entities, which may be owned by other<br> integrations (such as AWS).</p></li> </ul><h3 data-id="rapid7">Rapid7</h3> <ul><li>Fixed client pagination logic that prevented ingestion of some vulnerabilities.</li> </ul><h3 data-id="slack">Slack</h3> <ul><li>Fixed offsite authorization flow redirect URL to use subdomain instead of the account UUID.</li> </ul><h2 data-id="improvements-and-bug-fixes">Improvements and Bug Fixes</h2> <ul><li><strong>Groups</strong> tab in <strong>User & Access</strong> view loads more users in the list as with rolling (in sets of 20).</li> <li>Greatly improved the performance of Table Query Results across the app.</li> <li>Improved Policy and Procedure metadata fields UX.</li> <li>Fixed the size of the home icon in the Insights dashboard drawer.</li> <li>Fixed a bug where query input on Landing page becomes less responsive after several queries were run.</li> <li>Fixed a UI issue where the compliance neckbar had a scroll bar under certain circumstances.</li> <li>Fixed a bug with invalid character validation of the ID when editing a policy/procedure in the Policies app.</li> <li>Fixed an issue where the Compliance app may fail to load under certain circumstances for new accounts.</li> </ul><h2 data-id="community-projects">Community Projects</h2> <ul><li><p>Added more sample Insights dashboards:</p> <ul><li><a rel="nofollow" href="https://github.com/JupiterOne/insights-dashboards/blob/main/boards/code-deps-licenses">Software Package Dependencies and Licenses</a></li> <li><a rel="nofollow" href="https://github.com/JupiterOne/insights-dashboards/blob/main/boards/team-growth">Team Growth</a></li> <li><a rel="nofollow" href="https://github.com/JupiterOne/insights-dashboards/blob/main/boards/user-training">User Training</a></li> <li><a rel="nofollow" href="https://github.com/JupiterOne/insights-dashboards/blob/main/boards/vuln-reporting">Vulnerability Reporting</a></li> </ul></li> <li><p>Open sourced a new tool <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">peril</code> from JupiterOne Security Team:</p> <p><code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">Peril</code> is a standalone CLI tool intended to analyze the overall risk<br> profile for the currently-checked-out branch of a code repository. It will<br> draw risk information from a configurable list of sources, including<br> JupiterOne, before calculating and rendering an overall risk verdict for the<br> code.</p></li> </ul><blockquote class="UserQuote blockquote"><div class="QuoteText blockquote-content"> <p class="blockquote-line">We use <code class="code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline code codeInline" spellcheck="false" tabindex="0">peril</code> internally at JupiterOne as part of our appsec and secure<br> CI/CD process.</p> <p class="blockquote-line">Get it here:</p> <p class="blockquote-line"><i></i> <a href="https://github.com/JupiterOne/peril" rel="nofollow">https://github.com/JupiterOne/peril</a></p> </div></blockquote> </article> </main>