# Finding-rule inventory for the pinned ScoutSuite (see requirements.lock).
#
# One finding-rule filename per line; '#' starts a comment. This is the offline
# source of truth the curated azure-cis.json baseline is validated against in CI,
# so the wrapper can be checked without installing GPL ScoutSuite.
#
# Regenerate against the actually-pinned ScoutSuite (run inside an env with the
# '[scoutsuite]' extra installed):
#
#     presidio-scout-validate --regenerate --source installed
#
# 'presidio-scout-validate --source installed' flags any drift between this
# inventory and the installed ScoutSuite.

storageaccount-account-allowing-clear-text.json
storageaccount-public-blob-container.json
storageaccount-public-traffic-allowed.json
storageaccount-encrypted-not-customer-managed.json
storageaccount-access-keys-not-rotated.json
sqldatabase-servers-no-auditing.json
sqldatabase-databases-no-transparent-data-encryption.json
sqldatabase-allow-any-ip.json
sqldatabase-servers-no-ad-admin-configured.json
sqldatabase-servers-no-threat-detection.json
network-security-groups-rule-inbound-internet-all.json
network-security-groups-rule-inbound-service-mssql.json
network-watcher-not-enabled.json
virtual-machines-disk-encryption.json
virtual-machines-managed-disks.json
virtual-machines-os-data-encrypted-cmk.json
keyvault-not-recoverable.json
keyvault-public-traffic-allowed.json
aad-guest-users.json
aad-users-create-security-groups-disabled.json
rbac-custom-subscription-owner-role-not-allowed.json
securitycenter-standard-tier-not-enabled.json
securitycenter-auto-provisioning-off.json
logging-monitoring-log-alert-not-exist-nsg.json
postgresql-database-servers-ssl-enforcement-disabled.json
mysql-database-servers-ssl-enforcement-disabled.json
