| name | performing-serverless-function-security-review |
| description | Performing security reviews of serverless functions across AWS Lambda, Azure Functions, and GCP Cloud Functions to identify overly permissive execution roles, insecure environment variables, injection vulnerabilities, and missing runtime protections. . Use when working with performing serverless function security review. |
| domain | cybersecurity |
| tags | ["cloud-security","serverless","lambda","azure-functions","cloud-functions","security-review"] |
| subdomain | cloud-security |
| version | 1.0 |
| author | oyi77 |
| license | Apache-2.0 |
| nist_csf | ["PR.IR-01","ID.AM-08","GV.SC-06","DE.CM-01"] |
Performing Serverless Function Security Review
Overview
Cybersecurity skill for performing serverless function security review. Follows industry best practices and security standards.
When to Use
Trigger phrases:
-
"performing serverless function security review"
-
"Performing security reviews of serverless functions across AWS Lambda, Azure Fun"
-
When auditing serverless applications before production deployment
-
When investigating potential data exposure through function environment variables or logs
-
When assessing the blast radius of a compromised serverless function execution role
-
When compliance reviews require documentation of serverless security controls
-
When building secure-by-default templates for serverless deployments
Do not use for container or VM security assessments (use container scanning tools), for API security testing (use DAST tools on the API Gateway layer), or for real-time serverless threat detection (use AWS Lambda Extensions with security agents).
When NOT to Use
- When you lack proper authorization for testing
- For production systems without change management
- When the task requires legal or compliance expertise beyond technical scope
Prerequisites
- AWS CLI, Azure CLI, and gcloud CLI configured with appropriate permissions
- Access to read function configurations, policies, and execution roles
- Prowler or Checkov for automated serverless security scanning
- SAM CLI or Serverless Framework for local function analysis
- CloudTrail, Azure Monitor, or Cloud Audit Logs enabled for function invocation monitoring
Workflow
import re
IOC_PATTERNS = {
"ip": r"\b(?:\d{1,3}\.){3}\d{1,3}\b",
"domain": r"\b[a-z0-9-]+\.[a-z]{2,}\b",
"hash_md5": r"\b[a-f0-9]{32}\b",
"hash_sha256": r"\b[a-f0-9]{64}\b",
}
def extract_iocs(text: ) -> :
{k: re.findall(v, text) k, v IOC_PATTERNS.items()}