我的目标是将安全中心发现与 Slack 频道集成。为此,我创建了 aws 事件桥规则,其中 target 作为 SNS 主题,AWS lambda 作为订阅。我已经推荐了这个博客-
Lambda 是用 python 3.8 版本编写的。
import urllib3
import json
http = urllib3.PoolManager()
def lambda_handler(event, context):
url = "https://hooks.slack.com/services/********"
msg = {
"channel": "#project-lambda",
#"username": "WEBHOOK_USERNAME",
"text": event['Records'][0]['Sns']['Message'],
"icon_emoji": ""
}
encoded_msg = json.dumps(msg).encode('utf-8')
resp = http.request('POST',url, body=encoded_msg)
print({
"message": event['Records'][0]['Sns']['Message'],
"status_code": resp.status,
"response": resp.data
})
使用上面的代码,当触发事件规则时,我可以在 slack 通道上接收来自 SNS 的消息,但消息不是可读格式。
Slack 消息输出;
{"version":"0","id":"932c45e8-fdca-c2c0-25d7-7256467","detail-type":"Security Hub Findings - Imported","source":"aws.securityhub","account":"12345678","time":"2022-03-22T12:38:18Z","region":"us-east-1","resources":["arn:aws:securityhub:us-east-1::product/aws/securityhub/arn:aws:securityhub:us-east-1:12345678:subscription/aws-foundational-security-best-practices/v/1.0.0/S3.4/finding/5b012768-4639-4e5d-bd3c-34213876uh"],"detail":{"findings":[{"ProductArn":"arn:aws:securityhub:us-east-1::product/aws/securityhub","Types":["Software and Configuration Checks/Industry and Regulatory Standards/AWS-Foundational-Security-Best-Practices"],"Description":"This AWS control checks that your Amazon S3 bucket either has Amazon S3 default encryption enabled or that the S3 bucket policy explicitly denies put-object requests without server side encryption.","Compliance":{"Status":"FAILED"},
<<<>>>
相反,我希望输出采用以下 json 格式;
{
"version": "0",
"id": "932c45e8-fdca-c2c0-25d7-0cc89d76d336",
"detail-type": "Security Hub Findings - Imported",
"source": "aws.securityhub",
"account": "858703963673",
"time": "2022-03-22T12:38:18Z",
"region": "us-east-1",
"resources": ["arn:aws:securityhub:us-east-1::product/aws/securityhub/arn:aws:securityhub:us-east-1:858703963673:subscription/aws-foundational-security-best-practices/v/1.0.0/S3.4/finding/5b012768-4639-4e5d-bd3c-8ef4439540d6"],
"detail": {
"findings": [{
"ProductArn": "arn:aws:securityhub:us-east-1::product/aws/securityhub",
"Types": ["Software and Configuration Checks/Industry and Regulatory Standards/AWS-Foundational-Security-Best-Practices"],
"Description": "This AWS control checks that your Amazon S3 bucket either has Amazon S3 default encryption enabled or that the S3 bucket policy explicitly denies put-object requests without server side encryption.",
"Compliance": {
"Status": "FAILED"
},
<<<>>>
我相信这个 webhook 应用不支持 json 格式,但是有没有办法在 json 的 slack 通道上发布输出?
© 版权声明
本站下载的源码均来自公开网络收集转发二次开发而来,
若侵犯了您的合法权益,请来信通知我们1413333033@qq.com,
我们会及时删除,给您带来的不便,我们深表歉意。
下载用户仅供学习交流,若使用商业用途,请购买正版授权,否则产生的一切后果将由下载用户自行承担,访问及下载者下载默认同意本站声明的免责申明,请合理使用切勿商用。
THE END
暂无评论内容