Services in this catalog
- accessanalyzer - 2 checks
- account - 4 checks
- acm - 3 checks
- apigateway - 8 checks
- apigatewayv2 - 2 checks
- appstream - 4 checks
- appsync - 2 checks
- athena - 3 checks
- autoscaling - 8 checks
- awslambda - 12 checks
- backup - 5 checks
- bedrock - 9 checks
- cloudformation - 3 checks
- cloudfront - 13 checks
- cloudtrail - 14 checks
- cloudwatch - 22 checks
- codeartifact - 1 checks
- codebuild - 10 checks
- codepipeline - 1 checks
- cognito - 16 checks
- config - 2 checks
- datasync - 1 checks
- directconnect - 2 checks
- directoryservice - 6 checks
- dlm - 1 checks
- dms - 9 checks
- documentdb - 6 checks
- drs - 1 checks
- dynamodb - 9 checks
- ec2 - 71 checks
- ecr - 6 checks
- ecs - 11 checks
- efs - 7 checks
- eks - 7 checks
- elasticache - 8 checks
- elasticbeanstalk - 3 checks
- elb - 9 checks
- elbv2 - 11 checks
- emr - 3 checks
- eventbridge - 4 checks
- firehose - 1 checks
- fms - 1 checks
- fsx - 3 checks
- glacier - 1 checks
- glue - 13 checks
- guardduty - 10 checks
- iam - 47 checks
- inspector2 - 2 checks
- kafka - 8 checks
- kinesis - 2 checks
- kms - 5 checks
- lightsail - 4 checks
- macie - 2 checks
- memorydb - 1 checks
- mq - 5 checks
- neptune - 10 checks
- networkfirewall - 7 checks
- opensearch - 12 checks
- organizations - 5 checks
- rds - 35 checks
- redshift - 10 checks
- resourceexplorer2 - 1 checks
- route53 - 4 checks
- s3 - 21 checks
- sagemaker - 11 checks
- secretsmanager - 5 checks
- securityhub - 1 checks
- servicecatalog - 1 checks
- ses - 1 checks
- shield - 6 checks
- sns - 3 checks
- sqs - 2 checks
- ssm - 3 checks
- ssmincidents - 1 checks
- stepfunctions - 2 checks
- storagegateway - 2 checks
- transfer - 1 checks
- trustedadvisor - 2 checks
- vpc - 11 checks
- waf - 7 checks
- wafv2 - 3 checks
- wellarchitected - 1 checks
- workspaces - 2 checks
accessanalyzer
2 checks.| Check ID | Title | Severity |
|---|---|---|
accessanalyzer_enabled | IAM Access Analyzer is enabled | LOW |
accessanalyzer_enabled_without_findings | IAM Access Analyzer analyzer is active and has no active findings | LOW |
account
4 checks.| Check ID | Title | Severity |
|---|---|---|
account_maintain_current_contact_details | AWS account contact information is current | MEDIUM |
account_maintain_different_contact_details_to_security_billing_and_operations | AWS account has distinct Security, Billing, and Operations contact details, different from each other and from… | MEDIUM |
account_security_contact_information_is_registered | AWS account has security alternate contact registered | MEDIUM |
account_security_questions_are_registered_in_the_aws_account | [DEPRECATED] AWS root user has security challenge questions configured | MEDIUM |
acm
3 checks.| Check ID | Title | Severity |
|---|---|---|
acm_certificates_expiration_check | ACM certificate expires in more than the configured threshold of days | HIGH |
acm_certificates_transparency_logs_enabled | ACM certificate is imported or has Certificate Transparency logging enabled | MEDIUM |
acm_certificates_with_secure_key_algorithms | ACM certificate uses a secure key algorithm | HIGH |
apigateway
8 checks.| Check ID | Title | Severity |
|---|---|---|
apigateway_restapi_authorizers_enabled | API Gateway REST API has an authorizer at API level or all methods are authorized | MEDIUM |
apigateway_restapi_cache_encrypted | API Gateway REST API stage cache data is encrypted at rest | MEDIUM |
apigateway_restapi_client_certificate_enabled | API Gateway REST API stage has client certificate enabled | MEDIUM |
apigateway_restapi_logging_enabled | API Gateway REST API stage has logging enabled | MEDIUM |
apigateway_restapi_public | API Gateway REST API endpoint is private | MEDIUM |
apigateway_restapi_public_with_authorizer | API Gateway REST API with a public endpoint has an authorizer configured | MEDIUM |
apigateway_restapi_tracing_enabled | API Gateway REST API stage has X-Ray tracing enabled | LOW |
apigateway_restapi_waf_acl_attached | API Gateway stage has a WAF Web ACL attached | MEDIUM |
apigatewayv2
2 checks.| Check ID | Title | Severity |
|---|---|---|
apigatewayv2_api_access_logging_enabled | API Gateway V2 API stage has access logging enabled | MEDIUM |
apigatewayv2_api_authorizers_enabled | API Gateway V2 API has an authorizer configured | MEDIUM |
appstream
4 checks.| Check ID | Title | Severity |
|---|---|---|
appstream_fleet_default_internet_access_disabled | AppStream fleet has default internet access disabled | MEDIUM |
appstream_fleet_maximum_session_duration | AppStream fleet maximum user session duration is less than 10 hours | MEDIUM |
appstream_fleet_session_disconnect_timeout | AppStream fleet session disconnect timeout is 5 minutes or less | MEDIUM |
appstream_fleet_session_idle_disconnect_timeout | AppStream fleet session idle disconnect timeout is 10 minutes or less | MEDIUM |
appsync
2 checks.| Check ID | Title | Severity |
|---|---|---|
appsync_field_level_logging_enabled | AWS AppSync API has field-level logging set to ALL or ERROR | MEDIUM |
appsync_graphql_api_no_api_key_authentication | AWS AppSync GraphQL API does not use API key authentication | HIGH |
athena
3 checks.| Check ID | Title | Severity |
|---|---|---|
athena_workgroup_encryption | Athena workgroup encrypts query results in S3 with server-side encryption | MEDIUM |
athena_workgroup_enforce_configuration | Athena workgroup enforces workgroup configuration and cannot be overridden by client-side settings | MEDIUM |
athena_workgroup_logging_enabled | Amazon Athena workgroup has CloudWatch logging enabled | MEDIUM |
autoscaling
8 checks.| Check ID | Title | Severity |
|---|---|---|
autoscaling_find_secrets_ec2_launch_configuration | [DEPRECATED] EC2 Auto Scaling launch configuration user data contains no secrets | CRITICAL |
autoscaling_group_capacity_rebalance_enabled | Amazon EC2 Auto Scaling group has Capacity Rebalancing enabled | MEDIUM |
autoscaling_group_elb_health_check_enabled | Auto Scaling group associated with a load balancer has ELB health checks enabled | LOW |
autoscaling_group_launch_configuration_no_public_ip | Auto Scaling group associated launch configuration does not assign a public IP address | HIGH |
autoscaling_group_launch_configuration_requires_imdsv2 | Auto Scaling group enforces IMDSv2 or disables the instance metadata service | HIGH |
autoscaling_group_multiple_az | Auto Scaling group uses multiple Availability Zones | MEDIUM |
autoscaling_group_multiple_instance_types | Auto Scaling group spans multiple Availability Zones and has multiple instance types per Availability Zone | MEDIUM |
autoscaling_group_using_ec2_launch_template | Amazon EC2 Auto Scaling group uses an EC2 launch template | MEDIUM |
awslambda
12 checks.| Check ID | Title | Severity |
|---|---|---|
awslambda_function_env_vars_not_encrypted_with_cmk | Lambda function environment variables are encrypted with a customer-managed KMS key | MEDIUM |
awslambda_function_inside_vpc | Lambda function is deployed inside a VPC | LOW |
awslambda_function_invoke_api_operations_cloudtrail_logging_enabled | Lambda function Invoke API calls are recorded by CloudTrail | LOW |
awslambda_function_no_dead_letter_queue | Lambda function has a Dead Letter Queue configured | MEDIUM |
awslambda_function_no_secrets_in_code | Lambda function code contains no hardcoded secrets | CRITICAL |
awslambda_function_no_secrets_in_variables | Lambda function environment variables do not contain secrets | CRITICAL |
awslambda_function_not_publicly_accessible | Lambda function resource-based policy does not allow public access | CRITICAL |
awslambda_function_url_cors_policy | Lambda function URL CORS does not allow wildcard origins (*) | MEDIUM |
awslambda_function_url_public | Lambda function URL is not publicly accessible | HIGH |
awslambda_function_using_cross_account_layers | Lambda function does not use cross-account layers | HIGH |
awslambda_function_using_supported_runtimes | Lambda function uses a supported runtime | MEDIUM |
awslambda_function_vpc_multi_az | Lambda function is configured with VPC subnets in at least two Availability Zones | MEDIUM |
backup
5 checks.| Check ID | Title | Severity |
|---|---|---|
backup_plans_exist | At least one AWS Backup plan exists | LOW |
backup_recovery_point_encrypted | AWS Backup recovery point is encrypted at rest | MEDIUM |
backup_reportplans_exist | At least one AWS Backup report plan exists | LOW |
backup_vaults_encrypted | AWS Backup vault is encrypted at rest | MEDIUM |
backup_vaults_exist | At least one AWS Backup vault exists | LOW |
bedrock
9 checks.| Check ID | Title | Severity |
|---|---|---|
bedrock_agent_guardrail_enabled | Amazon Bedrock agent uses a guardrail to protect agent sessions | HIGH |
bedrock_api_key_no_administrative_privileges | Amazon Bedrock API key does not have administrative privileges, privilege escalation paths, or full Bedrock se… | HIGH |
bedrock_api_key_no_long_term_credentials | Amazon Bedrock API key is expired | HIGH |
bedrock_full_access_policy_attached | IAM role does not have AmazonBedrockFullAccess managed policy attached | HIGH |
bedrock_guardrail_prompt_attack_filter_enabled | Amazon Bedrock guardrail has prompt attack filter strength set to HIGH | HIGH |
bedrock_guardrail_sensitive_information_filter_enabled | Amazon Bedrock guardrail blocks or masks sensitive information | HIGH |
bedrock_model_invocation_logging_enabled | Amazon Bedrock model invocation logging is enabled | MEDIUM |
bedrock_model_invocation_logs_encryption_enabled | Amazon Bedrock model invocation logs are encrypted in the S3 bucket and KMS-encrypted in the CloudWatch log gr… | HIGH |
bedrock_vpc_endpoints_configured | VPC endpoints ensure private connectivity for all Bedrock APIs | MEDIUM |
cloudformation
3 checks.| Check ID | Title | Severity |
|---|---|---|
cloudformation_stack_cdktoolkit_bootstrap_version | CDKToolkit CloudFormation stack has Bootstrap version 21 or higher | HIGH |
cloudformation_stack_outputs_find_secrets | CloudFormation stack outputs do not contain secrets | CRITICAL |
cloudformation_stacks_termination_protection_enabled | CloudFormation stack has termination protection enabled | MEDIUM |
cloudfront
13 checks.| Check ID | Title | Severity |
|---|---|---|
cloudfront_distributions_custom_ssl_certificate | CloudFront distribution uses a custom SSL/TLS certificate | MEDIUM |
cloudfront_distributions_default_root_object | CloudFront distribution has a default root object configured | HIGH |
cloudfront_distributions_field_level_encryption_enabled | CloudFront distribution has Field Level Encryption enabled | LOW |
cloudfront_distributions_geo_restrictions_enabled | CloudFront distribution has Geo restrictions enabled | LOW |
cloudfront_distributions_https_enabled | CloudFront distribution has viewer protocol policy set to HTTPS only or redirect to HTTPS | MEDIUM |
cloudfront_distributions_https_sni_enabled | CloudFront distribution serves HTTPS requests using SNI | LOW |
cloudfront_distributions_logging_enabled | CloudFront distribution has logging enabled | MEDIUM |
cloudfront_distributions_multiple_origin_failover_configured | CloudFront distribution has origin failover configured with at least two origins | LOW |
cloudfront_distributions_origin_traffic_encrypted | CloudFront distribution encrypts traffic to custom origins | MEDIUM |
cloudfront_distributions_s3_origin_access_control | CloudFront distribution uses Origin Access Control (OAC) for all S3 origins | MEDIUM |
cloudfront_distributions_s3_origin_non_existent_bucket | CloudFront distribution S3 origins reference existing buckets | HIGH |
cloudfront_distributions_using_deprecated_ssl_protocols | CloudFront distribution does not use SSLv3, TLSv1, or TLSv1.1 for origin connections | LOW |
cloudfront_distributions_using_waf | CloudFront distribution uses an AWS WAF web ACL | MEDIUM |
cloudtrail
14 checks.| Check ID | Title | Severity |
|---|---|---|
cloudtrail_bucket_requires_mfa_delete | CloudTrail trail S3 bucket has MFA delete enabled | MEDIUM |
cloudtrail_cloudwatch_logging_enabled | CloudTrail trail has delivered logs to CloudWatch Logs in the last 24 hours | LOW |
cloudtrail_insights_exist | CloudTrail trail has Insights enabled | LOW |
cloudtrail_kms_encryption_enabled | CloudTrail trail logs are encrypted at rest with a KMS key | MEDIUM |
cloudtrail_log_file_validation_enabled | CloudTrail trail has log file validation enabled | MEDIUM |
cloudtrail_logs_s3_bucket_access_logging_enabled | CloudTrail trail destination S3 bucket has access logging enabled | MEDIUM |
cloudtrail_logs_s3_bucket_is_not_publicly_accessible | CloudTrail trail S3 bucket is not publicly accessible | CRITICAL |
cloudtrail_multi_region_enabled | Region has at least one CloudTrail trail logging | HIGH |
cloudtrail_multi_region_enabled_logging_management_events | CloudTrail trail logs management events for read and write operations | LOW |
cloudtrail_s3_dataevents_read_enabled | CloudTrail trail records S3 object-level read events for all S3 buckets | LOW |
cloudtrail_s3_dataevents_write_enabled | CloudTrail trail records all S3 object-level API operations for all buckets | LOW |
cloudtrail_threat_detection_enumeration | CloudTrail logs show no potential enumeration activity | CRITICAL |
cloudtrail_threat_detection_llm_jacking | No potential LLM jacking activity detected in CloudTrail | CRITICAL |
cloudtrail_threat_detection_privilege_escalation | No potential privilege escalation activity detected in CloudTrail | CRITICAL |
cloudwatch
22 checks.| Check ID | Title | Severity |
|---|---|---|
cloudwatch_alarm_actions_alarm_state_configured | CloudWatch metric alarm has actions configured for the ALARM state | HIGH |
cloudwatch_alarm_actions_enabled | CloudWatch metric alarm has actions enabled | HIGH |
cloudwatch_changes_to_network_acls_alarm_configured | CloudWatch log metric filter and alarm exist for Network ACL (NACL) change events | MEDIUM |
cloudwatch_changes_to_network_gateways_alarm_configured | CloudWatch Logs metric filter and alarm exist for changes to network gateways | MEDIUM |
cloudwatch_changes_to_network_route_tables_alarm_configured | Account monitors VPC route table changes with a CloudWatch Logs metric filter and alarm | MEDIUM |
cloudwatch_changes_to_vpcs_alarm_configured | AWS account has a CloudWatch Logs metric filter and alarm for VPC changes | MEDIUM |
cloudwatch_cross_account_sharing_disabled | CloudWatch does not allow cross-account sharing | MEDIUM |
cloudwatch_log_group_kms_encryption_enabled | CloudWatch log group is encrypted with an AWS KMS key | MEDIUM |
cloudwatch_log_group_no_secrets_in_logs | CloudWatch log group contains no secrets in its log events | MEDIUM |
cloudwatch_log_group_not_publicly_accessible | CloudWatch Log Group is not publicly accessible | HIGH |
cloudwatch_log_group_retention_policy_specific_days_enabled | CloudWatch log group has a retention policy of at least the configured minimum days or never expires | MEDIUM |
cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabled | CloudWatch Logs metric filter and alarm exist for AWS Config configuration changes | MEDIUM |
cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabled | CloudWatch Logs metric filter and alarm exist for CloudTrail configuration changes | MEDIUM |
cloudwatch_log_metric_filter_authentication_failures | Account has a CloudWatch Logs metric filter and alarm for AWS Management Console authentication failures | MEDIUM |
cloudwatch_log_metric_filter_aws_organizations_changes | CloudWatch Logs metric filter and alarm exist for AWS Organizations changes | MEDIUM |
cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmk | Account has a CloudWatch log metric filter and alarm for disabling or scheduled deletion of customer-managed K… | MEDIUM |
cloudwatch_log_metric_filter_for_s3_bucket_policy_changes | CloudWatch log metric filter and alarm exist for S3 bucket policy changes | MEDIUM |
cloudwatch_log_metric_filter_policy_changes | CloudWatch Logs metric filter and alarm exist for IAM policy changes | MEDIUM |
cloudwatch_log_metric_filter_root_usage | Account has a CloudWatch Logs metric filter and alarm for root account usage | MEDIUM |
cloudwatch_log_metric_filter_security_group_changes | CloudWatch Logs metric filter and alarm exist for security group changes | MEDIUM |
cloudwatch_log_metric_filter_sign_in_without_mfa | CloudWatch log metric filter and alarm exist for Management Console sign-in without MFA | MEDIUM |
cloudwatch_log_metric_filter_unauthorized_api_calls | CloudWatch Logs metric filter and alarm exist for unauthorized API calls | MEDIUM |
codeartifact
1 checks.| Check ID | Title | Severity |
|---|---|---|
codeartifact_packages_external_public_publishing_disabled | Internal CodeArtifact package does not allow publishing versions already present in external public sources | CRITICAL |
codebuild
10 checks.| Check ID | Title | Severity |
|---|---|---|
codebuild_project_logging_enabled | CodeBuild project has CloudWatch Logs or S3 logging enabled | MEDIUM |
codebuild_project_no_secrets_in_variables | CodeBuild project has no sensitive credentials in plaintext environment variables | CRITICAL |
codebuild_project_not_publicly_accessible | CodeBuild project visibility is private | HIGH |
codebuild_project_older_90_days | CodeBuild project has been invoked in the last 90 days | MEDIUM |
codebuild_project_s3_logs_encrypted | CodeBuild project S3 logs are encrypted at rest | LOW |
codebuild_project_source_repo_url_no_sensitive_credentials | CodeBuild project source repository URLs do not contain sensitive credentials | CRITICAL |
codebuild_project_user_controlled_buildspec | CodeBuild project does not use a user-controlled buildspec file | MEDIUM |
codebuild_project_uses_allowed_github_organizations | CodeBuild project using GitHub uses an allowed GitHub organization | HIGH |
codebuild_project_webhook_filters_use_anchored_patterns | CodeBuild project webhook filters use anchored regex patterns | HIGH |
codebuild_report_group_export_encrypted | CodeBuild report group exports to S3 are encrypted at rest | MEDIUM |
codepipeline
1 checks.| Check ID | Title | Severity |
|---|---|---|
codepipeline_project_repo_private | CodePipeline pipeline should use private repository source with authenticated connection | MEDIUM |
cognito
16 checks.| Check ID | Title | Severity |
|---|---|---|
cognito_identity_pool_guest_access_disabled | Cognito identity pool has guest access disabled | MEDIUM |
cognito_user_pool_advanced_security_enabled | Cognito user pool has advanced security enforced with full-function mode | MEDIUM |
cognito_user_pool_blocks_compromised_credentials_sign_in_attempts | Cognito user pool blocks sign-in attempts with suspected compromised credentials | MEDIUM |
cognito_user_pool_blocks_potential_malicious_sign_in_attempts | Amazon Cognito user pool blocks all potential malicious sign-in attempts | MEDIUM |
cognito_user_pool_client_prevent_user_existence_errors | Amazon Cognito user pool client has Prevent User Existence Errors enabled | MEDIUM |
cognito_user_pool_client_token_revocation_enabled | Amazon Cognito user pool client has token revocation enabled | MEDIUM |
cognito_user_pool_deletion_protection_enabled | Cognito user pool has deletion protection enabled | MEDIUM |
cognito_user_pool_mfa_enabled | Amazon Cognito user pool requires Multi-Factor Authentication (MFA) | MEDIUM |
cognito_user_pool_password_policy_lowercase | Cognito user pool password policy requires at least one lowercase letter | MEDIUM |
cognito_user_pool_password_policy_minimum_length_14 | Cognito user pool has a password policy with a minimum length of 14 characters or more | MEDIUM |
cognito_user_pool_password_policy_number | Cognito user pool password policy requires at least one number | MEDIUM |
cognito_user_pool_password_policy_symbol | Cognito user pool password policy requires at least one symbol | MEDIUM |
cognito_user_pool_password_policy_uppercase | Cognito user pool password policy requires at least one uppercase letter | MEDIUM |
cognito_user_pool_self_registration_disabled | Amazon Cognito user pool has self registration disabled | MEDIUM |
cognito_user_pool_temporary_password_expiration | Cognito user pool has temporary password expiration set to 7 days or less | MEDIUM |
cognito_user_pool_waf_acl_attached | Amazon Cognito user pool is associated with a WAF Web ACL | MEDIUM |
config
2 checks.| Check ID | Title | Severity |
|---|---|---|
config_recorder_all_regions_enabled | AWS Config recorder is enabled and not in failure state or disabled | MEDIUM |
config_recorder_using_aws_service_role | AWS Config recorder uses the AWSServiceRoleForConfig service-linked role | MEDIUM |
datasync
1 checks.| Check ID | Title | Severity |
|---|---|---|
datasync_task_logging_enabled | DataSync task has CloudWatch Logs log group configured for logging | HIGH |
directconnect
2 checks.| Check ID | Title | Severity |
|---|---|---|
directconnect_connection_redundancy | Direct Connect connections span at least two locations per region | MEDIUM |
directconnect_virtual_interface_redundancy | Direct Connect gateway or virtual private gateway has at least two virtual interfaces on different Direct Conn… | MEDIUM |
directoryservice
6 checks.| Check ID | Title | Severity |
|---|---|---|
directoryservice_directory_log_forwarding_enabled | Directory Service directory has log forwarding to CloudWatch Logs enabled | MEDIUM |
directoryservice_directory_monitor_notifications | Directory Service directory has SNS notifications enabled | MEDIUM |
directoryservice_directory_snapshots_limit | Directory Service directory has adequate remaining manual snapshot quota | LOW |
directoryservice_ldap_certificate_expiration | Directory Service LDAP certificate expires in more than 90 days | MEDIUM |
directoryservice_radius_server_security_protocol | Directory Service directory RADIUS server uses MS-CHAPv2 | MEDIUM |
directoryservice_supported_mfa_radius_enabled | AWS Directory Service directory has RADIUS-based MFA enabled | MEDIUM |
dlm
1 checks.| Check ID | Title | Severity |
|---|---|---|
dlm_ebs_snapshot_lifecycle_policy_exists | Region with EBS snapshots has at least one EBS snapshot lifecycle policy defined | MEDIUM |
dms
9 checks.| Check ID | Title | Severity |
|---|---|---|
dms_endpoint_mongodb_authentication_enabled | DMS MongoDB endpoint has an authentication mechanism enabled | MEDIUM |
dms_endpoint_neptune_iam_authorization_enabled | DMS endpoint for Neptune has IAM authorization enabled | MEDIUM |
dms_endpoint_redis_in_transit_encryption_enabled | DMS endpoint for Redis OSS is encrypted in transit | MEDIUM |
dms_endpoint_ssl_enabled | DMS endpoint has SSL enabled | HIGH |
dms_instance_minor_version_upgrade_enabled | DMS replication instance has auto minor version upgrade enabled | MEDIUM |
dms_instance_multi_az_enabled | DMS replication instance has Multi-AZ enabled | MEDIUM |
dms_instance_no_public_access | DMS replication instance is not publicly exposed to the Internet | CRITICAL |
dms_replication_task_source_logging_enabled | DMS replication task has logging enabled and SOURCE_CAPTURE and SOURCE_UNLOAD components set to at least Defau… | MEDIUM |
dms_replication_task_target_logging_enabled | DMS replication task has TARGET_APPLY and TARGET_LOAD logging enabled with at least default severity | MEDIUM |
documentdb
6 checks.| Check ID | Title | Severity |
|---|---|---|
documentdb_cluster_backup_enabled | DocumentDB cluster has automated backups enabled with retention period of at least 7 days | MEDIUM |
documentdb_cluster_cloudwatch_log_export | DocumentDB cluster exports audit and profiler logs to CloudWatch Logs | MEDIUM |
documentdb_cluster_deletion_protection | DocumentDB cluster has deletion protection enabled | MEDIUM |
documentdb_cluster_multi_az_enabled | DocumentDB cluster has Multi-AZ enabled | MEDIUM |
documentdb_cluster_public_snapshot | DocumentDB manual cluster snapshot is not shared publicly | CRITICAL |
documentdb_cluster_storage_encrypted | DocumentDB cluster storage is encrypted at rest | MEDIUM |
drs
1 checks.| Check ID | Title | Severity |
|---|---|---|
drs_job_exist | Region has AWS Elastic Disaster Recovery (DRS) enabled with at least one recovery job | MEDIUM |
dynamodb
9 checks.| Check ID | Title | Severity |
|---|---|---|
dynamodb_accelerator_cluster_encryption_enabled | DynamoDB DAX cluster has encryption at rest enabled | MEDIUM |
dynamodb_accelerator_cluster_in_transit_encryption_enabled | DynamoDB Accelerator (DAX) cluster has encryption in transit enabled | MEDIUM |
dynamodb_accelerator_cluster_multi_az | DynamoDB Accelerator (DAX) cluster has nodes in multiple Availability Zones | MEDIUM |
dynamodb_table_autoscaling_enabled | DynamoDB table uses on-demand capacity or has auto scaling enabled for read and write capacity units | MEDIUM |
dynamodb_table_cross_account_access | DynamoDB table resource-based policy does not allow cross-account access | MEDIUM |
dynamodb_table_deletion_protection_enabled | DynamoDB table has deletion protection enabled | MEDIUM |
dynamodb_table_protected_by_backup_plan | DynamoDB table is protected by a backup plan | MEDIUM |
dynamodb_tables_kms_cmk_encryption_enabled | DynamoDB table is encrypted at rest with AWS KMS | MEDIUM |
dynamodb_tables_pitr_enabled | DynamoDB table has point-in-time recovery (PITR) enabled | MEDIUM |
ec2
71 checks.| Check ID | Title | Severity |
|---|---|---|
ec2_ami_public | EC2 AMI owned by the account is not public | CRITICAL |
ec2_client_vpn_endpoint_connection_logging_enabled | EC2 Client VPN endpoint has client connection logging enabled | LOW |
ec2_ebs_default_encryption | EBS default encryption is enabled | HIGH |
ec2_ebs_public_snapshot | EBS snapshot is not public | CRITICAL |
ec2_ebs_snapshot_account_block_public_access | All EBS snapshots have public access blocked | HIGH |
ec2_ebs_snapshots_encrypted | EBS snapshot is encrypted | HIGH |
ec2_ebs_volume_encryption | EBS volume is encrypted | HIGH |
ec2_ebs_volume_protected_by_backup_plan | EBS volume is protected by a backup plan | MEDIUM |
ec2_ebs_volume_snapshots_exists | EBS volume has at least one snapshot | HIGH |
ec2_elastic_ip_shodan | EC2 Elastic IP address is not listed in Shodan | MEDIUM |
ec2_elastic_ip_unassigned | Elastic IP is associated with an instance or network interface | LOW |
ec2_instance_account_imdsv2_enabled | IMDSv2 is required by default for EC2 instances at the account level | HIGH |
ec2_instance_detailed_monitoring_enabled | EC2 instance has detailed monitoring enabled | LOW |
ec2_instance_imdsv2_enabled | EC2 instance requires IMDSv2 or has the instance metadata service disabled | HIGH |
ec2_instance_internet_facing_with_instance_profile | EC2 instance is not internet-facing with an instance profile attached | HIGH |
ec2_instance_managed_by_ssm | EC2 instance is managed by AWS Systems Manager or not running | MEDIUM |
ec2_instance_older_than_specific_days | EC2 instance is not older than the configured maximum age or is not running | MEDIUM |
ec2_instance_paravirtual_type | EC2 instance virtualization type is HVM | MEDIUM |
ec2_instance_port_cassandra_exposed_to_internet | EC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the Internet | CRITICAL |
ec2_instance_port_cifs_exposed_to_internet | EC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS) | CRITICAL |
ec2_instance_port_elasticsearch_kibana_exposed_to_internet | EC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601) | CRITICAL |
ec2_instance_port_ftp_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP) | CRITICAL |
ec2_instance_port_kafka_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka) | CRITICAL |
ec2_instance_port_kerberos_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos) | CRITICAL |
ec2_instance_port_ldap_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS) | CRITICAL |
ec2_instance_port_memcached_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached) | CRITICAL |
ec2_instance_port_mongodb_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB) | CRITICAL |
ec2_instance_port_mysql_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL) | CRITICAL |
ec2_instance_port_oracle_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle) | CRITICAL |
ec2_instance_port_postgresql_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL) | CRITICAL |
ec2_instance_port_rdp_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP) | CRITICAL |
ec2_instance_port_redis_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis) | CRITICAL |
ec2_instance_port_sqlserver_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server) | CRITICAL |
ec2_instance_port_ssh_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP port 22 (SSH) | CRITICAL |
ec2_instance_port_telnet_exposed_to_internet | EC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet) | CRITICAL |
ec2_instance_profile_attached | EC2 instance is associated with an IAM instance profile role | MEDIUM |
ec2_instance_public_ip | EC2 instance does not have a public IP address | MEDIUM |
ec2_instance_secrets_user_data | EC2 instance user data contains no secrets | HIGH |
ec2_instance_uses_single_eni | EC2 instance has no more than one Elastic Network Interface (ENI) attached | LOW |
ec2_instance_with_outdated_ami | EC2 instance uses a non-deprecated Amazon AMI | MEDIUM |
ec2_launch_template_imdsv2_required | EC2 launch template has IMDSv2 enabled and required or instance metadata service disabled | HIGH |
ec2_launch_template_no_public_ip | Amazon EC2 launch template has no public IP addresses configured on network interfaces | HIGH |
ec2_launch_template_no_secrets | EC2 launch template user data contains no secrets in any version | HIGH |
ec2_networkacl_allow_ingress_any_port | Network ACL does not allow ingress from 0.0.0.0/0 to any port | HIGH |
ec2_networkacl_allow_ingress_tcp_port_22 | Network ACL does not allow ingress from the Internet to TCP port 22 (SSH) | MEDIUM |
ec2_networkacl_allow_ingress_tcp_port_3389 | Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP) | MEDIUM |
ec2_networkacl_unused | Non-default network ACL is associated with a subnet | LOW |
ec2_securitygroup_allow_ingress_from_internet_to_all_ports | Security group does not have all ports open to the Internet | CRITICAL |
ec2_securitygroup_allow_ingress_from_internet_to_any_port | Security group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or… | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ip | Security group does not have any port open to a specific public IP address | MEDIUM |
ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_ports | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP ports | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH) | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389 | Security group does not allow ingress from the Internet to TCP port 3389 (RDP) | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888 | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and… | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21 | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka) | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211 | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018 | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306 | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483 | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432 | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379 | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434 | Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434 | HIGH |
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23 | Security group does not allow ingress from the Internet to TCP port 23 (Telnet) | HIGH |
ec2_securitygroup_allow_wide_open_public_ipv4 | Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23 | HIGH |
ec2_securitygroup_default_restrict_traffic | VPC default security group has no inbound or outbound rules | HIGH |
ec2_securitygroup_from_launch_wizard | Security group not created using the EC2 Launch Wizard | MEDIUM |
ec2_securitygroup_not_used | Non-default EC2 security group is in use | LOW |
ec2_securitygroup_with_many_ingress_egress_rules | Security group has 50 or fewer inbound rules and 50 or fewer outbound rules | MEDIUM |
ec2_transitgateway_auto_accept_vpc_attachments | Amazon EC2 Transit Gateway does not automatically accept shared VPC attachments | HIGH |
ecr
6 checks.| Check ID | Title | Severity |
|---|---|---|
ecr_registry_scan_images_on_push_enabled | ECR registry has image scanning on push enabled for all repositories | MEDIUM |
ecr_repositories_lifecycle_policy_enabled | ECR repository has a lifecycle policy configured | LOW |
ecr_repositories_not_publicly_accessible | ECR repository is not publicly accessible | CRITICAL |
ecr_repositories_scan_images_on_push_enabled | [DEPRECATED] ECR repository has image scanning on push enabled | MEDIUM |
ecr_repositories_scan_vulnerabilities_in_latest_image | ECR repository latest image is scanned with no vulnerabilities at or above the configured minimum severity | MEDIUM |
ecr_repositories_tag_immutability | ECR repository has image tag immutability enabled | MEDIUM |
ecs
11 checks.| Check ID | Title | Severity |
|---|---|---|
ecs_cluster_container_insights_enabled | ECS cluster has Container Insights enabled or enhanced | MEDIUM |
ecs_service_fargate_latest_platform_version | ECS Fargate service uses the latest Fargate platform version | MEDIUM |
ecs_service_no_assign_public_ip | ECS service does not have automatic public IP assignment | HIGH |
ecs_task_definitions_containers_readonly_access | ECS task definition has all containers with read-only root filesystems | HIGH |
ecs_task_definitions_host_namespace_not_shared | ECS task definition does not share the host’s process namespace with its containers | HIGH |
ecs_task_definitions_host_networking_mode_users | Amazon ECS task definition does not use host network mode, or non-privileged containers specify a non-root use… | HIGH |
ecs_task_definitions_logging_block_mode | ECS task definition has container logging in non-blocking mode | LOW |
ecs_task_definitions_logging_enabled | ECS task definition has logging configured for all containers | HIGH |
ecs_task_definitions_no_environment_secrets | ECS task definition has no secrets in environment variables | CRITICAL |
ecs_task_definitions_no_privileged_containers | ECS task definition has no privileged containers | HIGH |
ecs_task_set_no_assign_public_ip | ECS task set does not automatically assign a public IP address | HIGH |
efs
7 checks.| Check ID | Title | Severity |
|---|---|---|
efs_access_point_enforce_root_directory | EFS file system has no access points allowing access to the root directory | MEDIUM |
efs_access_point_enforce_user_identity | EFS file system has all access points with a defined POSIX user | MEDIUM |
efs_encryption_at_rest_enabled | EFS file system has encryption at rest enabled | MEDIUM |
efs_have_backup_enabled | EFS file system has backup enabled | MEDIUM |
efs_mount_target_not_publicly_accessible | EFS file system has no publicly accessible mount targets | MEDIUM |
efs_multi_az_enabled | EFS file system is Multi-AZ with more than one mount target | MEDIUM |
efs_not_publicly_accessible | EFS file system policy does not allow access to any client within the VPC | MEDIUM |
eks
7 checks.| Check ID | Title | Severity |
|---|---|---|
eks_cluster_deletion_protection_enabled | EKS cluster has deletion protection enabled | HIGH |
eks_cluster_kms_cmk_encryption_in_secrets_enabled | EKS cluster has Kubernetes secrets encryption enabled | MEDIUM |
eks_cluster_network_policy_enabled | EKS cluster has network policy enabled | HIGH |
eks_cluster_not_publicly_accessible | EKS cluster endpoint is not publicly accessible from 0.0.0.0/0 | HIGH |
eks_cluster_private_nodes_enabled | EKS cluster has private endpoint access enabled | HIGH |
eks_cluster_uses_a_supported_version | EKS cluster uses a supported Kubernetes version | HIGH |
eks_control_plane_logging_all_types_enabled | EKS cluster has control plane logging enabled for api, audit, authenticator, controllerManager, and scheduler | MEDIUM |
elasticache
8 checks.| Check ID | Title | Severity |
|---|---|---|
elasticache_cluster_uses_public_subnet | ElastiCache cluster is not using public subnets | MEDIUM |
elasticache_redis_cluster_auto_minor_version_upgrades | ElastiCache Redis cache cluster has automatic minor version upgrades enabled | HIGH |
elasticache_redis_cluster_automatic_failover_enabled | ElastiCache Redis cluster has automatic failover enabled | MEDIUM |
elasticache_redis_cluster_backup_enabled | ElastiCache Redis cache cluster has automated snapshot backups enabled with retention of at least 7 days | HIGH |
elasticache_redis_cluster_in_transit_encryption_enabled | ElastiCache Redis cache cluster has in-transit encryption enabled | MEDIUM |
elasticache_redis_cluster_multi_az_enabled | ElastiCache Redis replication group has Multi-AZ enabled | MEDIUM |
elasticache_redis_cluster_rest_encryption_enabled | ElastiCache Redis cache cluster has at rest encryption enabled | MEDIUM |
elasticache_redis_replication_group_auth_enabled | ElastiCache Redis replication group with engine version < 6.0 has Redis OSS AUTH enabled | MEDIUM |
elasticbeanstalk
3 checks.| Check ID | Title | Severity |
|---|---|---|
elasticbeanstalk_environment_cloudwatch_logging_enabled | Elastic Beanstalk environment streams logs to CloudWatch Logs | HIGH |
elasticbeanstalk_environment_enhanced_health_reporting | Elastic Beanstalk environment has enhanced health reporting enabled | LOW |
elasticbeanstalk_environment_managed_updates_enabled | Elastic Beanstalk environment has managed platform updates enabled | HIGH |
elb
9 checks.| Check ID | Title | Severity |
|---|---|---|
elb_connection_draining_enabled | Classic Load Balancer has connection draining enabled | MEDIUM |
elb_cross_zone_load_balancing_enabled | Classic Load Balancer has cross-zone load balancing enabled | MEDIUM |
elb_desync_mitigation_mode | Classic Load Balancer desync mitigation mode is defensive or strictest | MEDIUM |
elb_insecure_ssl_ciphers | Elastic Load Balancer HTTPS listeners, if present, use the ELBSecurityPolicy-TLS-1-2-2017-01 policy | MEDIUM |
elb_internet_facing | Elastic Load Balancer is not internet-facing | MEDIUM |
elb_is_in_multiple_az | Classic Load Balancer is in multiple Availability Zones | MEDIUM |
elb_logging_enabled | Elastic Load Balancer has access logs to S3 configured | MEDIUM |
elb_ssl_listeners | Elastic Load Balancer has only HTTPS or SSL listeners | MEDIUM |
elb_ssl_listeners_use_acm_certificate | Classic Load Balancer HTTPS/SSL listeners use ACM-issued certificates | MEDIUM |
elbv2
11 checks.| Check ID | Title | Severity |
|---|---|---|
elbv2_cross_zone_load_balancing_enabled | ELBv2 Network or Gateway Load Balancer has cross-zone load balancing enabled | MEDIUM |
elbv2_deletion_protection | ELBv2 load balancer has deletion protection enabled | MEDIUM |
elbv2_desync_mitigation_mode | Application Load Balancer has desync mitigation mode set to strictest or defensive, or drops invalid header fi… | MEDIUM |
elbv2_insecure_ssl_ciphers | ELBv2 load balancer uses a secure SSL policy on HTTPS listeners | MEDIUM |
elbv2_internet_facing | Application Load Balancer is not publicly accessible (no inbound TCP from 0.0.0.0/0 or ::/0) | MEDIUM |
elbv2_is_in_multiple_az | ELBv2 load balancer is configured across multiple Availability Zones | MEDIUM |
elbv2_listeners_underneath | ELBv2 load balancer has at least one listener | MEDIUM |
elbv2_logging_enabled | ELBv2 Application Load Balancer has access logs to S3 configured | MEDIUM |
elbv2_nlb_tls_termination_enabled | ELBv2 Network Load Balancer has TLS termination enabled | MEDIUM |
elbv2_ssl_listeners | ELBv2 Application Load Balancer listeners use HTTPS or redirect HTTP to HTTPS | MEDIUM |
elbv2_waf_acl_attached | Application Load Balancer has a WAF Web ACL attached | MEDIUM |
emr
3 checks.| Check ID | Title | Severity |
|---|---|---|
emr_cluster_account_public_block_enabled | EMR account has Block Public Access enabled | HIGH |
emr_cluster_master_nodes_no_public_ip | EMR Cluster without Public IP. | MEDIUM |
emr_cluster_publicly_accesible | EMR cluster is not publicly accessible | MEDIUM |
eventbridge
4 checks.| Check ID | Title | Severity |
|---|---|---|
eventbridge_bus_cross_account_access | AWS EventBridge event bus does not allow cross-account access | HIGH |
eventbridge_bus_exposed | AWS EventBridge event bus policy does not allow public access | HIGH |
eventbridge_global_endpoint_event_replication_enabled | EventBridge global endpoint has event replication enabled | MEDIUM |
eventbridge_schema_registry_cross_account_access | AWS EventBridge schema registry does not allow cross-account access | HIGH |
firehose
1 checks.| Check ID | Title | Severity |
|---|---|---|
firehose_stream_encrypted_at_rest | Kinesis Data Firehose delivery stream is encrypted at rest | MEDIUM |
fms
1 checks.| Check ID | Title | Severity |
|---|---|---|
fms_policy_compliant | All AWS FMS policies in the admin account are compliant for all accounts | MEDIUM |
fsx
3 checks.| Check ID | Title | Severity |
|---|---|---|
fsx_file_system_copy_tags_to_backups_enabled | FSx file system has copy tags to backups enabled | LOW |
fsx_file_system_copy_tags_to_volumes_enabled | FSx file system has copy tags to volumes enabled | LOW |
fsx_windows_file_system_multi_az_enabled | FSx Windows file system is configured for Multi-AZ deployment | LOW |
glacier
1 checks.| Check ID | Title | Severity |
|---|---|---|
glacier_vaults_policy_public_access | S3 Glacier vault has no policy or its policy does not allow access to everyone | CRITICAL |
glue
13 checks.| Check ID | Title | Severity |
|---|---|---|
glue_data_catalogs_connection_passwords_encryption_enabled | Glue data catalog connection password is encrypted with a KMS key | HIGH |
glue_data_catalogs_metadata_encryption_enabled | Glue Data Catalog metadata is encrypted with KMS | MEDIUM |
glue_data_catalogs_not_publicly_accessible | Glue Data Catalog is not publicly accessible via its resource policy | HIGH |
glue_database_connections_ssl_enabled | Glue connection has SSL enabled | HIGH |
glue_development_endpoints_cloudwatch_logs_encryption_enabled | Glue development endpoint has CloudWatch Logs encryption enabled | MEDIUM |
glue_development_endpoints_job_bookmark_encryption_enabled | Glue development endpoint has Job Bookmark encryption enabled | MEDIUM |
glue_development_endpoints_s3_encryption_enabled | Glue development endpoint has S3 encryption enabled | MEDIUM |
glue_etl_jobs_amazon_s3_encryption_enabled | Glue job has S3 encryption enabled | HIGH |
glue_etl_jobs_cloudwatch_logs_encryption_enabled | Glue ETL job has CloudWatch Logs encryption enabled | MEDIUM |
glue_etl_jobs_job_bookmark_encryption_enabled | Glue ETL job has Job bookmark encryption enabled | MEDIUM |
glue_etl_jobs_logging_enabled | Glue ETL job has continuous CloudWatch logging enabled | MEDIUM |
glue_etl_jobs_no_secrets_in_arguments | Glue ETL job has no secrets in default arguments | CRITICAL |
glue_ml_transform_encrypted_at_rest | Glue ML Transform is encrypted at rest | MEDIUM |
guardduty
10 checks.| Check ID | Title | Severity |
|---|---|---|
guardduty_centrally_managed | GuardDuty detector is managed by an administrator account or is the administrator with member accounts | MEDIUM |
guardduty_delegated_admin_enabled_all_regions | GuardDuty has delegated admin configured and is enabled in all regions with organization auto-enable | HIGH |
guardduty_ec2_malware_protection_enabled | GuardDuty detector has Malware Protection for EC2 enabled | HIGH |
guardduty_eks_audit_log_enabled | GuardDuty detector has EKS Audit Log Monitoring enabled | HIGH |
guardduty_eks_runtime_monitoring_enabled | GuardDuty detector has EKS Runtime Monitoring enabled | MEDIUM |
guardduty_is_enabled | GuardDuty detector is enabled and not suspended | HIGH |
guardduty_lambda_protection_enabled | GuardDuty detector has Lambda Protection enabled | HIGH |
guardduty_no_high_severity_findings | GuardDuty detector has no high severity findings | HIGH |
guardduty_rds_protection_enabled | GuardDuty detector has RDS Protection enabled | HIGH |
guardduty_s3_protection_enabled | GuardDuty detector has S3 Protection enabled | HIGH |
iam
47 checks.| Check ID | Title | Severity |
|---|---|---|
iam_administrator_access_with_mfa | IAM group members granted AdministratorAccess have MFA enabled | HIGH |
iam_avoid_root_usage | AWS account root user has not been used in the last day | HIGH |
iam_aws_attached_policy_no_administrative_privileges | Attached AWS-managed IAM policy does not allow ’:’ administrative privileges | CRITICAL |
iam_check_saml_providers_sts | IAM SAML provider exists in the account | LOW |
iam_customer_attached_policy_no_administrative_privileges | Attached IAM customer-managed policy does not allow ’:’ administrative privileges | HIGH |
iam_customer_unattached_policy_no_administrative_privileges | Unattached customer managed IAM policy does not allow ’:’ administrative privileges | MEDIUM |
iam_group_administrator_access_policy | IAM group does not have AdministratorAccess policy attached | HIGH |
iam_inline_policy_allows_privilege_escalation | IAM inline policy does not allow privilege escalation | HIGH |
iam_inline_policy_no_administrative_privileges | Inline IAM policy does not allow ’:’ administrative privileges | CRITICAL |
iam_inline_policy_no_full_access_to_cloudtrail | Inline IAM policy does not allow ‘cloudtrail:*’ privileges | HIGH |
iam_inline_policy_no_full_access_to_kms | Inline IAM policy does not allow kms:* privileges | MEDIUM |
iam_inline_policy_no_wildcard_marketplace_subscribe | Inline IAM policy does not allow ‘aws-marketplace:Subscribe’ on all resources | MEDIUM |
iam_no_custom_policy_permissive_role_assumption | Custom IAM policy does not allow STS role assumption on wildcard resources | HIGH |
iam_no_expired_server_certificates_stored | IAM server certificate is not expired | HIGH |
iam_no_root_access_key | Root account has no active access keys | CRITICAL |
iam_password_policy_expires_passwords_within_90_days_or_less | IAM account password policy enforces password expiration within 90 days or less | MEDIUM |
iam_password_policy_lowercase | IAM password policy requires at least one lowercase letter | LOW |
iam_password_policy_minimum_length_14 | IAM password policy requires passwords to be at least 14 characters long | MEDIUM |
iam_password_policy_number | IAM password policy requires at least one number | MEDIUM |
iam_password_policy_reuse_24 | IAM password policy prevents reuse of the last 24 passwords | MEDIUM |
iam_password_policy_symbol | IAM password policy requires at least one symbol | MEDIUM |
iam_password_policy_uppercase | IAM password policy requires at least one uppercase letter | MEDIUM |
iam_policy_allows_privilege_escalation | Customer managed IAM policy does not allow actions that can lead to privilege escalation | HIGH |
iam_policy_attached_only_to_group_or_roles | IAM user has no inline or attached policies | LOW |
iam_policy_cloudshell_admin_not_attached | No IAM users, groups, or roles have the AWSCloudShellFullAccess policy attached | MEDIUM |
iam_policy_no_full_access_to_cloudtrail | Customer managed IAM policy does not allow cloudtrail:* privileges | MEDIUM |
iam_policy_no_full_access_to_kms | Custom IAM policy does not allow ‘kms:*’ privileges | MEDIUM |
iam_policy_no_wildcard_marketplace_subscribe | Custom IAM policy does not allow ‘aws-marketplace:Subscribe’ on all resources | MEDIUM |
iam_role_access_not_stale_to_bedrock | Regular Bedrock access ensures IAM roles retain only actively used permissions | MEDIUM |
iam_role_administratoraccess_policy | IAM role does not have AdministratorAccess policy attached | HIGH |
iam_role_cross_account_readonlyaccess_policy | IAM role does not grant ReadOnlyAccess to external AWS accounts | HIGH |
iam_role_cross_service_confused_deputy_prevention | IAM service role prevents cross-service confused deputy attack | HIGH |
iam_root_credentials_management_enabled | AWS Organization has centralized root credentials management enabled | HIGH |
iam_root_hardware_mfa_enabled | Root account has a hardware MFA device enabled | CRITICAL |
iam_root_mfa_enabled | Root account has MFA enabled | CRITICAL |
iam_rotate_access_key_90_days | IAM user does not have active access keys older than 90 days | MEDIUM |
iam_securityaudit_role_created | At least one IAM role has the SecurityAudit AWS managed policy attached | LOW |
iam_support_role_created | At least one IAM role has the AWSSupportAccess managed policy attached | LOW |
iam_user_access_not_stale_to_bedrock | Regular Bedrock access ensures IAM users retain only actively used permissions | MEDIUM |
iam_user_accesskey_unused | IAM user does not have unused access keys older than 45 days | MEDIUM |
iam_user_administrator_access_policy | IAM user does not have AdministratorAccess policy attached | CRITICAL |
iam_user_console_access_unused | IAM user console access is disabled, used within the configured inactivity period, or never used | MEDIUM |
iam_user_hardware_mfa_enabled | IAM user has hardware MFA enabled | HIGH |
iam_user_mfa_enabled_console_access | IAM user has MFA enabled for console access or no console password is set | HIGH |
iam_user_no_setup_initial_access_key | IAM user does not have active access keys that have never been used | MEDIUM |
iam_user_two_active_access_key | IAM user has at most one active access key | MEDIUM |
iam_user_with_temporary_credentials | IAM user does not use long-lived credentials to access services other than IAM or STS | HIGH |
inspector2
2 checks.| Check ID | Title | Severity |
|---|---|---|
inspector2_active_findings_exist | Inspector2 is enabled with no active findings | HIGH |
inspector2_is_enabled | Inspector2 is enabled for Amazon EC2 instances, ECR container images, Lambda functions, and Lambda code | MEDIUM |
kafka
8 checks.| Check ID | Title | Severity |
|---|---|---|
kafka_cluster_encryption_at_rest_uses_cmk | Kafka cluster has encryption at rest enabled with a customer managed key (CMK) or is serverless | MEDIUM |
kafka_cluster_enhanced_monitoring_enabled | Amazon MSK cluster has enhanced monitoring enabled | MEDIUM |
kafka_cluster_in_transit_encryption_enabled | Kafka cluster has encryption in transit enabled | HIGH |
kafka_cluster_is_public | Kafka cluster is not publicly accessible | CRITICAL |
kafka_cluster_mutual_tls_authentication_enabled | Kafka cluster has TLS authentication enabled | HIGH |
kafka_cluster_unrestricted_access_disabled | Kafka cluster requires authentication | CRITICAL |
kafka_cluster_uses_latest_version | MSK cluster uses the latest Kafka version or is serverless with AWS-managed version | MEDIUM |
kafka_connector_in_transit_encryption_enabled | MSK Connect connector has encryption in transit enabled | HIGH |
kinesis
2 checks.| Check ID | Title | Severity |
|---|---|---|
kinesis_stream_data_retention_period | Kinesis stream retains data for at least the required minimum hours | MEDIUM |
kinesis_stream_encrypted_at_rest | Kinesis stream is encrypted at rest with KMS | HIGH |
kms
5 checks.| Check ID | Title | Severity |
|---|---|---|
kms_cmk_are_used | KMS customer managed key is enabled or scheduled for deletion | LOW |
kms_cmk_not_deleted_unintentionally | AWS KMS customer managed key is not scheduled for deletion | CRITICAL |
kms_cmk_not_multi_region | AWS KMS customer managed key is single-Region | MEDIUM |
kms_cmk_rotation_enabled | KMS customer-managed symmetric CMK has automatic rotation enabled | HIGH |
kms_key_not_publicly_accessible | Cloud KMS key does not grant access to allUsers or allAuthenticatedUsers | CRITICAL |
lightsail
4 checks.| Check ID | Title | Severity |
|---|---|---|
lightsail_database_public | Lightsail database public access disabled | HIGH |
lightsail_instance_automated_snapshots | Lightsail instance has automated snapshots enabled | MEDIUM |
lightsail_instance_public | Lightsail instance has no publicly accessible ports | HIGH |
lightsail_static_ip_unused | Lightsail static IP is associated with an instance | LOW |
macie
2 checks.| Check ID | Title | Severity |
|---|---|---|
macie_automated_sensitive_data_discovery_enabled | Macie automated sensitive data discovery is enabled | HIGH |
macie_is_enabled | Amazon Macie is enabled | MEDIUM |
memorydb
1 checks.| Check ID | Title | Severity |
|---|---|---|
memorydb_cluster_auto_minor_version_upgrades | MemoryDB cluster has automatic minor version upgrades enabled | MEDIUM |
mq
5 checks.| Check ID | Title | Severity |
|---|---|---|
mq_broker_active_deployment_mode | Apache ActiveMQ broker is configured in active/standby Multi-AZ deployment mode | LOW |
mq_broker_auto_minor_version_upgrades | Amazon MQ broker has automated minor version upgrades enabled | LOW |
mq_broker_cluster_deployment_mode | MQ RabbitMQ broker has cluster (multi-AZ) deployment mode | MEDIUM |
mq_broker_logging_enabled | MQ broker has general logging enabled and, for ActiveMQ, audit logging enabled | LOW |
mq_broker_not_publicly_accessible | Amazon MQ broker is not publicly accessible | HIGH |
neptune
10 checks.| Check ID | Title | Severity |
|---|---|---|
neptune_cluster_backup_enabled | Neptune cluster has automated backups enabled with retention period equal to or greater than the configured mi… | MEDIUM |
neptune_cluster_copy_tags_to_snapshots | Neptune DB cluster is configured to copy tags to snapshots. | LOW |
neptune_cluster_deletion_protection | Neptune cluster has deletion protection enabled | MEDIUM |
neptune_cluster_iam_authentication_enabled | Neptune cluster has IAM authentication enabled | MEDIUM |
neptune_cluster_integration_cloudwatch_logs | Neptune cluster has CloudWatch audit logs enabled | MEDIUM |
neptune_cluster_multi_az | Neptune cluster has Multi-AZ enabled | MEDIUM |
neptune_cluster_public_snapshot | NeptuneDB cluster snapshot is not publicly shared | CRITICAL |
neptune_cluster_snapshot_encrypted | Neptune DB cluster snapshot is encrypted at rest | MEDIUM |
neptune_cluster_storage_encrypted | Neptune cluster storage is encrypted at rest | HIGH |
neptune_cluster_uses_public_subnet | Neptune cluster is not using public subnets | MEDIUM |
networkfirewall
7 checks.| Check ID | Title | Severity |
|---|---|---|
networkfirewall_deletion_protection | Network Firewall has deletion protection enabled | MEDIUM |
networkfirewall_in_all_vpc | VPC has Network Firewall enabled | MEDIUM |
networkfirewall_logging_enabled | Network Firewall has logging enabled | HIGH |
networkfirewall_multi_az | Network Firewall firewall is deployed across multiple Availability Zones | HIGH |
networkfirewall_policy_default_action_fragmented_packets | Network Firewall policy drops or forwards fragmented packets by default | HIGH |
networkfirewall_policy_default_action_full_packets | Network Firewall firewall policy default stateless action for full packets is drop or forward | HIGH |
networkfirewall_policy_rule_group_associated | Network Firewall policy has at least one rule group associated | HIGH |
opensearch
12 checks.| Check ID | Title | Severity |
|---|---|---|
opensearch_service_domains_access_control_enabled | Amazon OpenSearch Service domain has fine-grained access control enabled | HIGH |
opensearch_service_domains_audit_logging_enabled | Amazon OpenSearch Service domain has audit logging enabled | HIGH |
opensearch_service_domains_cloudwatch_logging_enabled | Amazon OpenSearch Service domain publishes search and index slow logs to CloudWatch Logs | LOW |
opensearch_service_domains_encryption_at_rest_enabled | Amazon OpenSearch Service domain has encryption at rest enabled | CRITICAL |
opensearch_service_domains_fault_tolerant_data_nodes | OpenSearch domain has at least 3 data nodes and Zone Awareness enabled | MEDIUM |
opensearch_service_domains_fault_tolerant_master_nodes | OpenSearch domain has at least 3 dedicated master nodes | MEDIUM |
opensearch_service_domains_https_communications_enforced | OpenSearch domain has HTTPS enforcement enabled | HIGH |
opensearch_service_domains_internal_user_database_enabled | Amazon OpenSearch Service domain has internal user database disabled | MEDIUM |
opensearch_service_domains_node_to_node_encryption_enabled | Amazon OpenSearch Service domain has node-to-node encryption enabled | HIGH |
opensearch_service_domains_not_publicly_accessible | Amazon OpenSearch Service domain is not publicly accessible | CRITICAL |
opensearch_service_domains_updated_to_the_latest_service_software_version | Amazon OpenSearch Service domain is updated to the latest service software version | HIGH |
opensearch_service_domains_use_cognito_authentication_for_kibana | Amazon OpenSearch Service domain has either Amazon Cognito or SAML authentication enabled for Kibana | MEDIUM |
organizations
5 checks.| Check ID | Title | Severity |
|---|---|---|
organizations_account_part_of_organizations | AWS account is a member of an active AWS Organization | MEDIUM |
organizations_delegated_administrators | AWS Organization has only trusted delegated administrators | CRITICAL |
organizations_opt_out_ai_services_policy | AWS Organization has opted out of all AI services and child accounts cannot override the policy | MEDIUM |
organizations_scp_check_deny_regions | AWS Organization restricts operations to only the configured AWS Regions with SCP policies | HIGH |
organizations_tags_policies_enabled_and_attached | AWS Organization has tag policies enabled and attached | LOW |
rds
35 checks.| Check ID | Title | Severity |
|---|---|---|
rds_cluster_backtrack_enabled | RDS Aurora MySQL cluster has Backtrack enabled | LOW |
rds_cluster_copy_tags_to_snapshots | RDS DB cluster has copy tags to snapshots enabled | LOW |
rds_cluster_critical_event_subscription | RDS cluster event subscription is enabled for maintenance and failure categories | MEDIUM |
rds_cluster_default_admin | RDS cluster master username is not admin or postgres | MEDIUM |
rds_cluster_deletion_protection | RDS cluster has deletion protection enabled | MEDIUM |
rds_cluster_iam_authentication_enabled | RDS cluster has IAM authentication enabled | MEDIUM |
rds_cluster_integration_cloudwatch_logs | RDS cluster has CloudWatch Logs export enabled | MEDIUM |
rds_cluster_minor_version_upgrade_enabled | RDS cluster has automatic minor version upgrades enabled | MEDIUM |
rds_cluster_multi_az | RDS cluster has Multi-AZ enabled | MEDIUM |
rds_cluster_non_default_port | RDS cluster uses a non-default port for its database engine | LOW |
rds_cluster_protected_by_backup_plan | RDS cluster is protected by an AWS Backup plan | HIGH |
rds_cluster_storage_encrypted | RDS cluster storage is encrypted | HIGH |
rds_instance_backup_enabled | RDS instance has backup retention period greater than 0 days | MEDIUM |
rds_instance_certificate_expiration | RDS instance SSL/TLS certificate has more than 3 months of validity remaining | HIGH |
rds_instance_copy_tags_to_snapshots | RDS DB instance has copy tags to snapshots enabled | LOW |
rds_instance_critical_event_subscription | RDS instance event subscription is enabled for maintenance, configuration change, and failure categories | MEDIUM |
rds_instance_default_admin | RDS instance does not use the default master username (admin or postgres) | MEDIUM |
rds_instance_deletion_protection | RDS instance has deletion protection enabled | MEDIUM |
rds_instance_deprecated_engine_version | RDS instance uses a supported engine version | HIGH |
rds_instance_enhanced_monitoring_enabled | RDS instance has enhanced monitoring enabled | LOW |
rds_instance_event_subscription_parameter_groups | RDS DB parameter group event subscription is enabled and subscribes to configuration change events or all cate… | LOW |
rds_instance_event_subscription_security_groups | RDS event subscription for DB security groups is enabled for configuration change and failure events | MEDIUM |
rds_instance_extended_support | RDS instance is not enrolled in RDS Extended Support | MEDIUM |
rds_instance_iam_authentication_enabled | RDS instance has IAM database authentication enabled | MEDIUM |
rds_instance_inside_vpc | RDS instance is deployed in a VPC | HIGH |
rds_instance_integration_cloudwatch_logs | RDS instance exports logs to CloudWatch Logs | MEDIUM |
rds_instance_minor_version_upgrade_enabled | RDS instance has minor version upgrade enabled | MEDIUM |
rds_instance_multi_az | RDS instance has Multi-AZ enabled | MEDIUM |
rds_instance_no_public_access | RDS instance is not publicly exposed to the Internet | CRITICAL |
rds_instance_non_default_port | RDS instance uses a non-default port for its engine | LOW |
rds_instance_protected_by_backup_plan | RDS instance is protected by an AWS Backup plan | HIGH |
rds_instance_storage_encrypted | RDS DB instance storage is encrypted at rest | HIGH |
rds_instance_transport_encrypted | RDS instance or cluster enforces SSL/TLS encryption for client connections | HIGH |
rds_snapshots_encrypted | RDS DB instance snapshot or DB cluster snapshot is encrypted | HIGH |
rds_snapshots_public_access | RDS snapshot is not publicly shared | CRITICAL |
redshift
10 checks.| Check ID | Title | Severity |
|---|---|---|
redshift_cluster_audit_logging | Redshift cluster has audit logging enabled | MEDIUM |
redshift_cluster_automated_snapshot | Redshift cluster has automated snapshots enabled | HIGH |
redshift_cluster_automatic_upgrades | Redshift cluster has automatic version upgrade enabled | MEDIUM |
redshift_cluster_encrypted_at_rest | Redshift cluster is encrypted at rest | CRITICAL |
redshift_cluster_enhanced_vpc_routing | Redshift cluster has Enhanced VPC Routing enabled | MEDIUM |
redshift_cluster_in_transit_encryption_enabled | Redshift cluster is encrypted in transit | HIGH |
redshift_cluster_multi_az_enabled | Redshift cluster has Multi-AZ enabled | MEDIUM |
redshift_cluster_non_default_database_name | Redshift cluster does not use the default database name dev | LOW |
redshift_cluster_non_default_username | Amazon Redshift cluster does not use the default admin username | MEDIUM |
redshift_cluster_public_access | Redshift cluster is not publicly exposed to the Internet | CRITICAL |
resourceexplorer2
1 checks.| Check ID | Title | Severity |
|---|---|---|
resourceexplorer2_indexes_found | Resource Explorer indexes exist | LOW |
route53
4 checks.| Check ID | Title | Severity |
|---|---|---|
route53_dangling_ip_subdomain_takeover | Route53 A record does not point to a dangling IP address | HIGH |
route53_domains_privacy_protection_enabled | Route 53 domain has admin contact privacy protection enabled | MEDIUM |
route53_domains_transferlock_enabled | Route 53 domain has Transfer Lock enabled | HIGH |
route53_public_hosted_zones_cloudwatch_logging_enabled | Route53 public hosted zone has query logging enabled to a CloudWatch Logs log group | MEDIUM |
s3
21 checks.| Check ID | Title | Severity |
|---|---|---|
s3_access_point_public_access_block | S3 access point has all Block Public Access settings enabled | CRITICAL |
s3_account_level_public_access_blocks | S3 account-level Block Public Access ignores public ACLs and restricts public buckets | HIGH |
s3_bucket_acl_prohibited | S3 bucket has bucket ACLs disabled | MEDIUM |
s3_bucket_cross_account_access | S3 bucket policy does not allow cross-account access | HIGH |
s3_bucket_cross_region_replication | S3 bucket has cross-region replication configured to a bucket in a different region | LOW |
s3_bucket_default_encryption | S3 bucket has default server-side encryption (SSE) enabled | MEDIUM |
s3_bucket_event_notifications_enabled | S3 bucket has event notifications enabled | LOW |
s3_bucket_kms_encryption | S3 bucket has server-side encryption with AWS KMS | MEDIUM |
s3_bucket_level_public_access_block | S3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account… | HIGH |
s3_bucket_lifecycle_enabled | S3 bucket has a lifecycle configuration enabled | LOW |
s3_bucket_no_mfa_delete | S3 bucket has MFA Delete enabled | MEDIUM |
s3_bucket_object_lock | S3 bucket has Object Lock enabled | LOW |
s3_bucket_object_versioning | S3 bucket has object versioning enabled | MEDIUM |
s3_bucket_policy_public_write_access | S3 bucket policy does not allow public write access | CRITICAL |
s3_bucket_public_access | S3 bucket is not publicly accessible to Everyone or Authenticated Users | CRITICAL |
s3_bucket_public_list_acl | S3 bucket is not publicly listable by Everyone or any authenticated AWS user | CRITICAL |
s3_bucket_public_write_acl | S3 bucket ACL does not grant write access to Everyone or any AWS customer | CRITICAL |
s3_bucket_secure_transport_policy | S3 bucket policy denies requests over insecure transport | MEDIUM |
s3_bucket_server_access_logging_enabled | S3 bucket has server access logging enabled | MEDIUM |
s3_bucket_shadow_resource_vulnerability | S3 bucket is not a known shadow resource owned by another account | HIGH |
s3_multi_region_access_point_public_access_block | S3 Multi-Region Access Point has all Block Public Access settings enabled | HIGH |
sagemaker
11 checks.| Check ID | Title | Severity |
|---|---|---|
sagemaker_endpoint_config_prod_variant_instances | SageMaker endpoint configuration has all production variants with at least two initial instances | MEDIUM |
sagemaker_models_network_isolation_enabled | Amazon SageMaker model has network isolation enabled | HIGH |
sagemaker_models_vpc_settings_configured | Amazon SageMaker model has VPC settings enabled | MEDIUM |
sagemaker_notebook_instance_encryption_enabled | SageMaker notebook instance is encrypted with a KMS key | HIGH |
sagemaker_notebook_instance_root_access_disabled | Amazon SageMaker notebook instance has root access disabled | MEDIUM |
sagemaker_notebook_instance_vpc_settings_configured | Amazon SageMaker notebook instance has VPC settings configured | HIGH |
sagemaker_notebook_instance_without_direct_internet_access_configured | Amazon SageMaker notebook instance has direct internet access disabled | HIGH |
sagemaker_training_jobs_intercontainer_encryption_enabled | Amazon SageMaker training job has inter-container traffic encryption enabled | MEDIUM |
sagemaker_training_jobs_network_isolation_enabled | Amazon SageMaker training job has network isolation enabled | HIGH |
sagemaker_training_jobs_volume_and_output_encryption_enabled | Amazon SageMaker training job volume has KMS encryption enabled | HIGH |
sagemaker_training_jobs_vpc_settings_configured | Amazon SageMaker training job has VPC configuration enabled | HIGH |
secretsmanager
5 checks.| Check ID | Title | Severity |
|---|---|---|
secretsmanager_automatic_rotation_enabled | Secrets Manager secret has rotation enabled | HIGH |
secretsmanager_has_restrictive_resource_policy | Secrets Manager secret has a restrictive resource-based policy | HIGH |
secretsmanager_not_publicly_accessible | Secrets Manager secret resource policy does not allow public access | HIGH |
secretsmanager_secret_rotated_periodically | AWS Secrets Manager secret is rotated within the configured maximum number of days | MEDIUM |
secretsmanager_secret_unused | Secrets Manager secret has been accessed within the last 90 days | MEDIUM |
securityhub
1 checks.| Check ID | Title | Severity |
|---|---|---|
securityhub_enabled | Security Hub is enabled with standards or integrations configured | HIGH |
servicecatalog
1 checks.| Check ID | Title | Severity |
|---|---|---|
servicecatalog_portfolio_shared_within_organization_only | Service Catalog portfolio is shared only within the AWS Organization | HIGH |
ses
1 checks.| Check ID | Title | Severity |
|---|---|---|
ses_identity_not_publicly_accessible | SES identity resource policy does not allow public access | HIGH |
shield
6 checks.| Check ID | Title | Severity |
|---|---|---|
shield_advanced_protection_in_associated_elastic_ips | Elastic IP address is protected by AWS Shield Advanced | MEDIUM |
shield_advanced_protection_in_classic_load_balancers | Classic Load Balancer is protected by AWS Shield Advanced | MEDIUM |
shield_advanced_protection_in_cloudfront_distributions | CloudFront distribution is protected by AWS Shield Advanced | MEDIUM |
shield_advanced_protection_in_global_accelerators | Global Accelerator accelerator is protected by AWS Shield Advanced | MEDIUM |
shield_advanced_protection_in_internet_facing_load_balancers | Internet-facing Application Load Balancer is protected by AWS Shield Advanced | MEDIUM |
shield_advanced_protection_in_route53_hosted_zones | Route53 hosted zone is protected by AWS Shield Advanced | MEDIUM |
sns
3 checks.| Check ID | Title | Severity |
|---|---|---|
sns_subscription_not_using_http_endpoints | SNS subscription uses an HTTPS endpoint | HIGH |
sns_topics_kms_encryption_at_rest_enabled | SNS topic is encrypted at rest with KMS | HIGH |
sns_topics_not_publicly_accessible | SNS topic is not publicly accessible | HIGH |
sqs
2 checks.| Check ID | Title | Severity |
|---|---|---|
sqs_queues_not_publicly_accessible | SQS queue policy does not allow public access | CRITICAL |
sqs_queues_server_side_encryption_enabled | SQS queue has server-side encryption enabled | MEDIUM |
ssm
3 checks.| Check ID | Title | Severity |
|---|---|---|
ssm_document_secrets | SSM document contains no secrets | HIGH |
ssm_documents_set_as_public | SSM document is not public and shared only with trusted AWS accounts | HIGH |
ssm_managed_compliant_patching | EC2 managed instance is compliant with Systems Manager patching requirements | HIGH |
ssmincidents
1 checks.| Check ID | Title | Severity |
|---|---|---|
ssmincidents_enabled_with_plans | SSM Incidents replication set is ACTIVE and has at least one response plan | MEDIUM |
stepfunctions
2 checks.| Check ID | Title | Severity |
|---|---|---|
stepfunctions_statemachine_logging_enabled | Step Functions state machine has logging enabled | MEDIUM |
stepfunctions_statemachine_no_secrets_in_definition | Step Functions state machine has no sensitive credentials in its definition | CRITICAL |
storagegateway
2 checks.| Check ID | Title | Severity |
|---|---|---|
storagegateway_fileshare_encryption_enabled | Storage Gateway file share is encrypted with KMS CMK | MEDIUM |
storagegateway_gateway_fault_tolerant | AWS Storage Gateway gateway is not hosted on EC2 | MEDIUM |
transfer
1 checks.| Check ID | Title | Severity |
|---|---|---|
transfer_server_in_transit_encryption_enabled | Transfer Family server has encryption in transit enabled | HIGH |
trustedadvisor
2 checks.| Check ID | Title | Severity |
|---|---|---|
trustedadvisor_errors_and_warnings | Trusted Advisor check has no errors or warnings | MEDIUM |
trustedadvisor_premium_support_plan_subscribed | AWS account is subscribed to an AWS Premium Support plan | LOW |
vpc
11 checks.| Check ID | Title | Severity |
|---|---|---|
vpc_different_regions | VPCs are present in more than one region | MEDIUM |
vpc_endpoint_connections_trust_boundaries | VPC endpoint policy allows access only from trusted AWS accounts | HIGH |
vpc_endpoint_for_ec2_enabled | VPC has an Amazon EC2 VPC endpoint | MEDIUM |
vpc_endpoint_multi_az_enabled | Amazon VPC interface endpoint has subnets in multiple Availability Zones | MEDIUM |
vpc_endpoint_services_allowed_principals_trust_boundaries | VPC endpoint service allows only trusted principals or none | HIGH |
vpc_flow_logs_enabled | VPC flow logs are enabled | MEDIUM |
vpc_peering_routing_tables_with_least_privilege | VPC peering connection route tables do not include 0.0.0.0/0 or entire requester/accepter VPC CIDR routes | MEDIUM |
vpc_subnet_different_az | VPC has subnets in more than one Availability Zone | MEDIUM |
vpc_subnet_no_public_ip_by_default | VPC subnet does not assign public IP addresses by default | HIGH |
vpc_subnet_separate_private_public | VPC has both public and private subnets | MEDIUM |
vpc_vpn_connection_tunnels_up | AWS Site-to-Site VPN connection has both tunnels up | MEDIUM |
waf
7 checks.| Check ID | Title | Severity |
|---|---|---|
waf_global_rule_with_conditions | AWS WAF Classic Global rule has at least one condition | MEDIUM |
waf_global_rulegroup_not_empty | AWS WAF Classic global rule group has at least one rule | HIGH |
waf_global_webacl_logging_enabled | AWS WAF Classic Global Web ACL has logging enabled | MEDIUM |
waf_global_webacl_with_rules | AWS WAF Classic global Web ACL has at least one rule or rule group | MEDIUM |
waf_regional_rule_with_conditions | AWS WAF Classic Regional rule has at least one condition | MEDIUM |
waf_regional_rulegroup_not_empty | AWS WAF Classic Regional rule group has at least one rule | MEDIUM |
waf_regional_webacl_with_rules | AWS WAF Classic Regional Web ACL has at least one rule or rule group | MEDIUM |
wafv2
3 checks.| Check ID | Title | Severity |
|---|---|---|
wafv2_webacl_logging_enabled | AWS WAFv2 Web ACL has logging enabled | MEDIUM |
wafv2_webacl_rule_logging_enabled | AWS WAFv2 Web ACL has Amazon CloudWatch metrics enabled for all rules and rule groups | MEDIUM |
wafv2_webacl_with_rules | AWS WAFv2 Web ACL has at least one rule or rule group attached | HIGH |
wellarchitected
1 checks.| Check ID | Title | Severity |
|---|---|---|
wellarchitected_workload_no_high_or_medium_risks | AWS Well-Architected Tool workload has no high or medium risks | MEDIUM |
workspaces
2 checks.| Check ID | Title | Severity |
|---|---|---|
workspaces_volume_encryption_enabled | Amazon WorkSpaces workspace root and user volumes are encrypted | HIGH |
workspaces_vpc_2private_1public_subnets_nat | Workspace is in a private subnet and its VPC has at least 1 public subnet, 2 private subnets, and a NAT Gatewa… | HIGH |
What’s next
Cloud Security overview
Connect a provider, see findings end-to-end.
All checks
Index across every provider.
Compliance frameworks
How check IDs map to SOC 2 / PCI / HIPAA / ISO controls.
Reports
Per-framework PDF scorecards.