<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic [RQL] How to construct a query to investigate on all AWS Security Groups that has outbound to 0.0.0.0 in Prisma Cloud Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-how-to-construct-a-query-to-investigate-on-all-aws-security/m-p/578299#M1181</link>
    <description>&lt;P&gt;Reference: &lt;A href="https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-security-groups.html" target="_blank"&gt;https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-security-groups.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RQL that is not working: config from cloud.resource where cloud.type = 'aws' AND api.name = 'describe-security-groups' AND json.rule = "IpPermissionsEgress[IpRanges[?any (CidrIp equals 0.0.0.0/0)]]"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does not seems to be right. Need RQL expert here! Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 26 Feb 2024 06:43:36 GMT</pubDate>
    <dc:creator>rogerhuang</dc:creator>
    <dc:date>2024-02-26T06:43:36Z</dc:date>
    <item>
      <title>[RQL] How to construct a query to investigate on all AWS Security Groups that has outbound to 0.0.0.0</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-how-to-construct-a-query-to-investigate-on-all-aws-security/m-p/578299#M1181</link>
      <description>&lt;P&gt;Reference: &lt;A href="https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-security-groups.html" target="_blank"&gt;https://docs.aws.amazon.com/cli/latest/reference/ec2/describe-security-groups.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;RQL that is not working: config from cloud.resource where cloud.type = 'aws' AND api.name = 'describe-security-groups' AND json.rule = "IpPermissionsEgress[IpRanges[?any (CidrIp equals 0.0.0.0/0)]]"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does not seems to be right. Need RQL expert here! Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 06:43:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-how-to-construct-a-query-to-investigate-on-all-aws-security/m-p/578299#M1181</guid>
      <dc:creator>rogerhuang</dc:creator>
      <dc:date>2024-02-26T06:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: [RQL] How to construct a query to investigate on all AWS Security Groups that has outbound to 0.0.0.0</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-how-to-construct-a-query-to-investigate-on-all-aws-security/m-p/578313#M1182</link>
      <description>&lt;P&gt;Somehow figure out something like this and so far no error.&lt;/P&gt;
&lt;DIV data-version="3.0.0" data-hash="9dd880094ebe22e055e26934c7fe3dbb"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class="section"&gt;
&lt;P class="paragraph text-align-type-left"&gt;&lt;SPAN data-font-family="Monaco"&gt;config&amp;nbsp;from&amp;nbsp;cloud.resource&amp;nbsp;where&amp;nbsp;api.name&amp;nbsp;=&amp;nbsp;'aws-ec2-describe-security-groups'&amp;nbsp;and&amp;nbsp;json.rule&amp;nbsp;=&amp;nbsp;(($.ipPermissions[?(@.ipProtocol==-1)].ipRanges[*]&amp;nbsp;contains&amp;nbsp;0.0.0.0/0&amp;nbsp;or&amp;nbsp;$.ipPermissions[?(@.ipProtocol==-1)].ipv6Ranges[*].cidrIpv6&amp;nbsp;contains&amp;nbsp;::/0))&lt;/SPAN&gt;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 08:21:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-how-to-construct-a-query-to-investigate-on-all-aws-security/m-p/578313#M1182</guid>
      <dc:creator>rogerhuang</dc:creator>
      <dc:date>2024-02-26T08:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: [RQL] How to construct a query to investigate on all AWS Security Groups that has outbound to 0.0.0.0</title>
      <link>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-how-to-construct-a-query-to-investigate-on-all-aws-security/m-p/578708#M1184</link>
      <description>&lt;P&gt;That works.&amp;nbsp; Or a more simplified version of the query to only look for ipv4 outbound to 0.0.0.0/0 could be:&lt;BR /&gt;&lt;BR /&gt;config from cloud.resource where cloud.type = 'aws' AND api.name = 'aws-ec2-describe-security-groups' AND json.rule = '((ipPermissionsEgress[*] equals 0.0.0.0/0))'&lt;/P&gt;</description>
      <pubDate>Wed, 28 Feb 2024 21:34:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/prisma-cloud-discussions/rql-how-to-construct-a-query-to-investigate-on-all-aws-security/m-p/578708#M1184</guid>
      <dc:creator>ACurran2</dc:creator>
      <dc:date>2024-02-28T21:34:09Z</dc:date>
    </item>
  </channel>
</rss>

