diff --git a/roles/wazuh/ansible-wazuh-manager/vars/cdb_lists.yml b/roles/wazuh/ansible-wazuh-manager/vars/cdb_lists.yml index 851e24a1..8e904e14 100644 --- a/roles/wazuh/ansible-wazuh-manager/vars/cdb_lists.yml +++ b/roles/wazuh/ansible-wazuh-manager/vars/cdb_lists.yml @@ -9,15 +9,79 @@ cdb_lists: audit-wazuh-c:command - name: 'aws-source' content: | - aws-source-w:write - aws-source-r:read - aws-source-a:attribute - aws-source-x:execute - aws-source-c:command + ec2.amazonaws.com: + elasticloadbalancing.amazonaws.com: + iam.amazonaws.com: + signin.amazonaws.com: + kms.amazonaws.com: + s3.amazonaws.com: - name: 'aws-eventnames' content: | - aws-eventnames-w:write - aws-eventnames-r:read - aws-eventnames-a:attribute - aws-eventnames-x:execute - aws-eventnames-c:command + AddUserToGroup: + AllocateAddress: + AssociateAddress: + AssociateDhcpOptions: + AssociateRouteTable: + AttachGroupPolicy: + AttachNetworkInterface: + AttachRolePolicy: + AttachUserPolicy: + AttachVolume: + AuthorizeSecurityGroupIngress: + ConsoleLogin: + CopySnapshot: + CreateAccountAlias: + CreateGroup: + CreateImage: + CreateLoadBalancer: + CreatePlacementGroup: + CreatePolicy: + CreateRole: + CreateRouteTable: + CreateSecurityGroup: + CreateSnapshot: + CreateSubnet: + CreateTags: + CreateUser: + CreateVolume: + CreateVpc: + DeleteAccountAlias: + DeleteLoadBalancer: + DeletePlacementGroup: + DeleteSecurityGroup: + DeleteSnapshot: + DeleteTags: + DeleteUser: + DeleteVolume: + DeregisterImage: + DetachGroupPolicy: + DetachNetworkInterface: + DetachRolePolicy: + DetachVolume: + DisableKey: + DisassociateAddress: + DisassociateAddress: + DisassociateRouteTable: + GetGroup: + ListAliases: + ListGroups: + ListUsers: + ModifyImageAttribute: + ModifyInstanceAttribute: + ModifyNetworkInterfaceAttribute: + ModifySnapshotAttribute: + ModifySubnetAttribute: + ModifyVolumeAttribute: + MonitorInstances: + RebootInstances: + RegisterImage: + RemoveUserFromGroup: + RevokeSecurityGroupIngress: + RunInstances: + StartInstances: + StopInstances: + TerminateInstances: + UnmonitorInstances: + UpdateAccessKey: + UpdateAccountPasswordPolicy: + UpdateInstanceAlias: