A tool for performing runtime analysis using STIGs
Project description
Anchore Runtime STIG
Anchore STIG is a complete STIG solution that can be used to run STIG profile against running containers in a cluster.
Description
Use Anchore STIG to perform STIG checks against running containers in Kubernetes environments or static Docker images from a registry or stored locally. The tool executes automated scans against specific STIG Security Guide (SSG) policies. The program will output either a JSON report with a summary of STIG check results for runtime checks or XCCDF XML and OpenSCAP XML and HTML for static checks.
The runtime functionality includes the following profiles:
- Ubuntu 20.04 (ubuntu-20.04)
- Ubuntu 22.04 (ubuntu-22.04)
- Universal Base Image 8 (ubi8) - This runs the full RHEL 8 STIG
- Universal Base Image 9 (ubi9) - This runs the full RHEL 9 STIG
- Postgres 9 (postgres9)
- Apache Tommcat 9 (apache-tomcat9)
- Crunchy PostgreSQL (crunchy-postgresql)
- JBOSS (jboss)
- Java Runtime Environment 7 (jre7)
- MongoDB Enterprise (mongodb)
- nginx (nginx)
Getting Started
Dependencies
Overall
python3 >= 3.8 with pip3 installedmake
Runtime
kubectl execprivileges- Pods running one of the above listed software / OS types
Install
- clone the repo
- run
maketo install
Running the Program
Runtime
-
Run
anchorestig runtimefrom the terminal.- NOTE: This edition of the demo has been optimized for single-container pods by default
-
The program will run in interactive mode by just executing
anchorestig runtime --interactivefrom the terminal, however, you may also use the following CLI input parameters:
CLI Input Parameters:
-i, --image TEXT Specify profile to use. Available options are
ubuntu-20.04, ubuntu-22.04, ubi8, ubi9, postgres9,
apache-tomcat9, crunchy-postgresql, jboss, jre7,
mongodb, nginx
-p, --pod TEXT Any running pod running an image that runs one of the
specififed profile's software
-c, --container TEXT Container in the pod to run against
-o, --outfile TEXT Output file name. Only JSON output filetype is
supported (include the '.json' extension with the
output file name in CLI)
-n, --namespace TEXT Namespace the pod is located in
-u, --usecontext TEXT Specify the kubernetes context to use
-b, --aws-bucket TEXT Specify the S3 bucket to upload results to. Omit to
skip upload
-a, --account TEXT Specify the Anchore STIG UI account to associate the
S3 upload with. Omit to skip upload
-t, --interactive Run in interactive mode
-s, --sync Sync policies from Anchore
--help Show this message and exit.
Ex: anchorestig-runtime runtime -u current -n test -i postgres9 -p postgres9 -c default -o postgres.json
- NOTE: The output file will be saved to the
./outputsdirectory
Viewing Results
Navigate to the ./outputs directory to view the output file.
Help
Use the --help flag to see more information on how to run the program:
anchorestig-runtime runtime --help
CINC Functionality Explanation
cinc-auditor allows users to specify a target to run profiles against. This can be a number of things including SSH targets or a local system. The train-k8s-container plugin allows our STIG tool to target a kubernetes namespace, pod, and container to run cinc profiles against. When a container is set as the target, each individual control will be prepended with kubectl exec ..... and the appropriate commands to run within the container and retireve the results to make the determination of a pass or fail against the control baseline.
Modifying Controls
The policies directory contains sub-directories for the Ubuntu, UBI, and Postgres STIG profiles. Each directory has a tar.gz file that can be decompressed. From there, each control that runs is defined as a ruby gem file in the controls directory. The ID of each control (displayed in Heimdall) is pulled from the control section at the beginning of the ruby gem file. To change what is displayed, change the control id at the beginning of the file.
Adding Not-Applicable Controls
The UBI 8 and Ubuntu 20.04 policies were built with the not-applicable rules removed. To add them back, untar the tar files in each repository, move the ruby gem files from the not-applicable/ directory to the controls directory. Then run cinc-auditor archive . in the untarred directory. This will generate a new tar archive file. Replace the original archive, that you un-tarred at the beginning with the newly generated one and the newly included rules will run.
Authors
- Sean Fazenbaker @bakenfazer
- Michael Simmons @MSimmons7
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file anchorestig_runtime-0.75.0.tar.gz.
File metadata
- Download URL: anchorestig_runtime-0.75.0.tar.gz
- Upload date:
- Size: 26.9 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.0.1 CPython/3.12.8
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4f8b6dc63e9f613c4f955e05ca251430607d0587ff89b7f9a96fe9d453cd9c06
|
|
| MD5 |
334fabca3b7045cb07fb158a5884548d
|
|
| BLAKE2b-256 |
de0b95a891ade92664a8e28a7ddf3a15d0a3f9466dbaedc05d29ffa9e4413c93
|
Provenance
The following attestation bundles were made for anchorestig_runtime-0.75.0.tar.gz:
Publisher:
release.yml on anchore/Anchore-Runtime-STIG-Only
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
anchorestig_runtime-0.75.0.tar.gz -
Subject digest:
4f8b6dc63e9f613c4f955e05ca251430607d0587ff89b7f9a96fe9d453cd9c06 - Sigstore transparency entry: 154489464
- Sigstore integration time:
-
Permalink:
anchore/Anchore-Runtime-STIG-Only@205f49aff18edc6747f32cc02a161e21ee59876d -
Branch / Tag:
refs/tags/v0.75.0 - Owner: https://github.com/anchore
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@205f49aff18edc6747f32cc02a161e21ee59876d -
Trigger Event:
push
-
Statement type:
File details
Details for the file anchorestig_runtime-0.75.0-py3-none-any.whl.
File metadata
- Download URL: anchorestig_runtime-0.75.0-py3-none-any.whl
- Upload date:
- Size: 37.1 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.0.1 CPython/3.12.8
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
4cae93f69aa8f79a34ee1afc96c14508be0c550340d1d6bab123516ffc8e6175
|
|
| MD5 |
fd3ce1beac73b69f3d4d4298f5a6475d
|
|
| BLAKE2b-256 |
a4cb0652e414cc63a66049f19cf14e627d5c35ad5b8e73b9d12af09750cd056a
|
Provenance
The following attestation bundles were made for anchorestig_runtime-0.75.0-py3-none-any.whl:
Publisher:
release.yml on anchore/Anchore-Runtime-STIG-Only
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
anchorestig_runtime-0.75.0-py3-none-any.whl -
Subject digest:
4cae93f69aa8f79a34ee1afc96c14508be0c550340d1d6bab123516ffc8e6175 - Sigstore transparency entry: 154489465
- Sigstore integration time:
-
Permalink:
anchore/Anchore-Runtime-STIG-Only@205f49aff18edc6747f32cc02a161e21ee59876d -
Branch / Tag:
refs/tags/v0.75.0 - Owner: https://github.com/anchore
-
Access:
private
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@205f49aff18edc6747f32cc02a161e21ee59876d -
Trigger Event:
push
-
Statement type: