Mondoo 11.18 is out!
๐ฅณ Mondoo 11.18 is out! This release includes expanded security policies, Compliance Hub improvements, piles of new resources, and more!โ
Get this release: Installation Docs | Package Downloads | Docker Container
๐ NEW FEATURESโ
New policies for detecting NTLMv1 and SMBv1โ
Secure your Windows infrastructure against vulnerable legacy Microsoft file sharing and authentications protocols with the new Mondoo NTLMv1 Audit policy and Mondoo SMBv1 Audit policy. These policies, co-developed with the wonderful engineers at SVA, ensure you're using only modern and secure file sharing and authentication methods.
๐งน IMPROVEMENTSโ
Space sunburst chart improvementsโ
Quickly understand where security problems lie with improvements to the sunburst charts on the space overview page. The sunburst now groups IaC, network, and SaaS assets to quickly expose hot spots in your security posture. Dive deeper into each category with improved asset placement, so you can track down problematic services.

Deeper AWS serverless integration scansโ
When a default VPC is in place, the Mondoo AWS serverless integration now produces deeper security scans that include:
-
Individual assets for common AWS resources
-
Improved query outputs
Use these improved scan results to navigate security issues in organization and space dashboards and to set granular exceptions on individual resources.

Improved Compliance Hub look and feelโ
A refreshed Compliance Hub UI makes it easier to track your audit progress. Simplified progress bars show completion status. We also replaced the check distribution graph with intuitable icons for each exception state.

Cover letters in compliance reportsโ
Inform your auditor about Mondoo with a new Mondoo introduction PDF included in each compliance report. The letter explains who we are and how we collect evidence, and lets them know how to contact us if they have questions.
Expanded CIS Azure Foundations policyโ
Expand your Azure security insights with our newly expanded CIS Azure Foundations benchmark. The policy includes dozens of new checks for securing IAM, database, storage, secrets, and directory services.
Resource updatesโ
azure.subscriptionโ
- New
policyfield using the newazure.subscription.policyresource - New
iamfield that deprecates theauthorizationfield
azure.subscription.authorizationServiceโ
- New
roleAssignmentsfield using the newazure.subscription.authorizationService.roleAssignmentresource - New
managedIdentitiesfield using the newazure.subscription.managedIdentityresource
azure.subscription.authorizationservice.roledefinitionโ
- New
typefield that deprecates theisCustomfield
azure.subscription.cloudDefenderServiceโ
- New
defenderForAppServicesfield - New
defenderForSqlServersOnMachinesfield - New
defenderForSqlDatabasesfield - New
defenderForOpenSourceDatabasesfield - New
defenderForCosmosDbfield - New
defenderForStorageAccountsfield - New
defenderForKeyVaultsfield - New
defenderForResourceManagerfield
azure.subscription.postgreSql.FlexibleServersโ
- Return all servers in the subscription
microsoftโ
- The
organizationsfield is now deprecated. Usemicrosoft.tenantinstead.
microsoft.applicationโ
- New
apifield - New
applicationTemplateIdfield - New
certificationfield - New
defaultRedirectUrifield - New
disabledByMicrosoftStatusfield - New
groupMembershipClaimsfield - New
isDeviceOnlyAuthSupportedfield - New
isFallbackPublicClientfield - New
nativeAuthenticationApisEnabledfield - New
optionalClaimsfield - New
parentalControlSettingsfield - New
publicClientfield - New
requestSignatureVerificationfield - New
samlMetadataUrlfield - New
serviceManagementReferencefield - New
servicePrincipalfield - New
servicePrincipalLockConfigurationfield - New
spafield - New
tokenEncryptionKeyIdfield - New
webfield - New
appRolesfield using the newmicrosoft.application.rolefield
microsoft.rolesโ
- New resource that replaces
microsoft.rolemanagement
microsoft.serviceprincipalโ
- New
appIdfield - New
applicationTemplateIdfield - New
appOwnerOrganizationIdfield - New
appRoleAssignmentRequiredfield - New
descriptionfield - New
isFirstPartyfield - New
loginUrlfield - New
logoutUrlfield - New
notificationEmailAddressesfield - New
permissionsfield using the newmicrosoft.application.permissionfield - New
preferredSingleSignOnModefield - New
servicePrincipalNamesfield - New
signInAudiencesignInAudiencefield - New
verifiedPublisherfield
microsoft.userโ
- New
authMethodsfield using the newmicrosoft.user.authenticationMethodsresource - Deprecated
companyName,department,employeeId,jobTitle,mail,mobilePhone,otherMails,officeLocation,postalCode, andstatein favor of data in thejobandcontactfields
microsoft.tenantโ
- Renamed from
microsoft.organization - New
createdAtreplaces the now deprecatedcreatedDateTime - New
namefield - New
provisionedPlansfield - New
subscriptionsfield - New
typefield
microsoft.securityโ
- New
riskyUsersfield using the newmicrosoft.security.riskyUserresource
๐ BUG FIXES AND UPDATESโ
- Fix incorrect AWS account identification in some resources.
- Don't error when checking services on containers.
- Fix a failure fetching AWS KMS information.
- Update the title of the CIS Controls framework to include the version number.
- Generate complete report archives with the correct file date stamps.
- Fix a failure exporting data to S3.
- Improve rendering of very long policy names on the asset page.
- Fix missing search results.
- Improve application of Azure and Amazon EKS policies.
