Skip to main content

Networking / VPC

Threats

Version:
IDTitleDescriptionExternal MappingsCapability MappingsControl Mappings
CCC.VPC.TH01Unauthorized Access via Insecure Default NetworksDefault network configurations may include insecure settings and open firewall rules,leading to unauthorized access and potential data breaches.
1
1
1
CCC.VPC.TH02Exposure of Resources to Public InternetAssignment of external IP addresses to resources exposes resources to the public internet, increasing the risk of attacks such as brute force, exploitation of vulnerabilities, or unauthorized access.
1
1
1
CCC.VPC.TH03Unauthorized Network Access Through VPC PeeringUnauthorized VPC peering connections can allow network traffic between untrusted or unapproved subscriptions, leading to potential data exposure or exfiltration.
1
1
1
CCC.VPC.TH04Lack of Network Visibility due to Disabled VPC Flow LogsVPC subnets with disabled flow logs lack critical network traffic visibility, which can lead to undetected unauthorized access, data exfiltration, and network misconfigurations. This lack of visibility increases the risk of undetected security incidents.
1
1
1
CCC.VPC.TH05Overly Permissive VPC Endpoint PoliciesVPC Endpoint policies that are overly permissive may inadvertently expose resources within the VPC to unintended principals or external threats.
1
1
0

Imports

IDRemarks
CCC.Core.TH01Access Control is Misconfigured
CCC.Core.TH02Data is Intercepted in Transit
CCC.Core.TH03Deployment Region Network is Untrusted
CCC.Core.TH06Data is Lost or Corrupted
CCC.Core.TH07Logs are Tampered With or Deleted
CCC.Core.TH09Logs or Monitoring Data are Read by Unauthorized Users
CCC.Core.TH13Resource Tags are Manipulated
CCC.Core.TH15Automated Enumeration and Reconnaissance by Non-human Entities