Findings

βš™οΈ Apps & issues

After a source is scanned, elba will report potential security vulnerabilities: issues.

These issues are then classified by apps, which serve as classifiers to navigate through your risk. There are 3 apps on elba, which cover most of SaaS usage risk:

- Data protection

- 3rd-party apps

- Authentication

‍

‍

πŸ“ Data protection

Goal of Data protection app is to ensure your most sensitive data is well protected. It will also help you achieve your compliance requirements regarding data loss prevention.

Google

- Files & folders shared with public link

- Files & folders shared with entire domain

- Files & folders shared with external users

Dropbox

- Files & folders shared with public link

- Files & folders shared with external users

Confluence

- Contents & spaces shared with public link

- Contents & spaces shared with external users

‍

‍

πŸ“±3rd party apps

Goal of 3rd-party apps app is to ensure your attack surface is limited with the strict minimum of AuthO tokens active on your SaaS stack.

Google

- Apps connected with OAuth tokens to users accounts

Dropbox

- Apps connected with OAuth tokens to users accounts

‍

‍

πŸ” Authentication

Goal of Authentication app is to ensure your team use the most secured authentication method to access their most critical SaaS applications.

Google

- Account without MFA activated