594 checks across 83 services. Every row links to the full check page — description, risk, recommendation, remediation snippets (CLI / Terraform / Native IaC / Dashboard), and references. Check IDs are stable. They appear unchanged on every finding in the dashboard, in every export (SARIF / CSV / JSON / PDF), and in compliance scorecards. Severity drives quality-gate behaviour — CRITICAL and HIGH block by default.

Services in this catalog

accessanalyzer

2 checks.
Check IDTitleSeverity
accessanalyzer_enabledIAM Access Analyzer is enabledLOW
accessanalyzer_enabled_without_findingsIAM Access Analyzer analyzer is active and has no active findingsLOW

account

4 checks.
Check IDTitleSeverity
account_maintain_current_contact_detailsAWS account contact information is currentMEDIUM
account_maintain_different_contact_details_to_security_billing_and_operationsAWS account has distinct Security, Billing, and Operations contact details, different from each other and from…MEDIUM
account_security_contact_information_is_registeredAWS account has security alternate contact registeredMEDIUM
account_security_questions_are_registered_in_the_aws_account[DEPRECATED] AWS root user has security challenge questions configuredMEDIUM

acm

3 checks.
Check IDTitleSeverity
acm_certificates_expiration_checkACM certificate expires in more than the configured threshold of daysHIGH
acm_certificates_transparency_logs_enabledACM certificate is imported or has Certificate Transparency logging enabledMEDIUM
acm_certificates_with_secure_key_algorithmsACM certificate uses a secure key algorithmHIGH

apigateway

8 checks.
Check IDTitleSeverity
apigateway_restapi_authorizers_enabledAPI Gateway REST API has an authorizer at API level or all methods are authorizedMEDIUM
apigateway_restapi_cache_encryptedAPI Gateway REST API stage cache data is encrypted at restMEDIUM
apigateway_restapi_client_certificate_enabledAPI Gateway REST API stage has client certificate enabledMEDIUM
apigateway_restapi_logging_enabledAPI Gateway REST API stage has logging enabledMEDIUM
apigateway_restapi_publicAPI Gateway REST API endpoint is privateMEDIUM
apigateway_restapi_public_with_authorizerAPI Gateway REST API with a public endpoint has an authorizer configuredMEDIUM
apigateway_restapi_tracing_enabledAPI Gateway REST API stage has X-Ray tracing enabledLOW
apigateway_restapi_waf_acl_attachedAPI Gateway stage has a WAF Web ACL attachedMEDIUM

apigatewayv2

2 checks.
Check IDTitleSeverity
apigatewayv2_api_access_logging_enabledAPI Gateway V2 API stage has access logging enabledMEDIUM
apigatewayv2_api_authorizers_enabledAPI Gateway V2 API has an authorizer configuredMEDIUM

appstream

4 checks.
Check IDTitleSeverity
appstream_fleet_default_internet_access_disabledAppStream fleet has default internet access disabledMEDIUM
appstream_fleet_maximum_session_durationAppStream fleet maximum user session duration is less than 10 hoursMEDIUM
appstream_fleet_session_disconnect_timeoutAppStream fleet session disconnect timeout is 5 minutes or lessMEDIUM
appstream_fleet_session_idle_disconnect_timeoutAppStream fleet session idle disconnect timeout is 10 minutes or lessMEDIUM

appsync

2 checks.
Check IDTitleSeverity
appsync_field_level_logging_enabledAWS AppSync API has field-level logging set to ALL or ERRORMEDIUM
appsync_graphql_api_no_api_key_authenticationAWS AppSync GraphQL API does not use API key authenticationHIGH

athena

3 checks.
Check IDTitleSeverity
athena_workgroup_encryptionAthena workgroup encrypts query results in S3 with server-side encryptionMEDIUM
athena_workgroup_enforce_configurationAthena workgroup enforces workgroup configuration and cannot be overridden by client-side settingsMEDIUM
athena_workgroup_logging_enabledAmazon Athena workgroup has CloudWatch logging enabledMEDIUM

autoscaling

8 checks.
Check IDTitleSeverity
autoscaling_find_secrets_ec2_launch_configuration[DEPRECATED] EC2 Auto Scaling launch configuration user data contains no secretsCRITICAL
autoscaling_group_capacity_rebalance_enabledAmazon EC2 Auto Scaling group has Capacity Rebalancing enabledMEDIUM
autoscaling_group_elb_health_check_enabledAuto Scaling group associated with a load balancer has ELB health checks enabledLOW
autoscaling_group_launch_configuration_no_public_ipAuto Scaling group associated launch configuration does not assign a public IP addressHIGH
autoscaling_group_launch_configuration_requires_imdsv2Auto Scaling group enforces IMDSv2 or disables the instance metadata serviceHIGH
autoscaling_group_multiple_azAuto Scaling group uses multiple Availability ZonesMEDIUM
autoscaling_group_multiple_instance_typesAuto Scaling group spans multiple Availability Zones and has multiple instance types per Availability ZoneMEDIUM
autoscaling_group_using_ec2_launch_templateAmazon EC2 Auto Scaling group uses an EC2 launch templateMEDIUM

awslambda

12 checks.
Check IDTitleSeverity
awslambda_function_env_vars_not_encrypted_with_cmkLambda function environment variables are encrypted with a customer-managed KMS keyMEDIUM
awslambda_function_inside_vpcLambda function is deployed inside a VPCLOW
awslambda_function_invoke_api_operations_cloudtrail_logging_enabledLambda function Invoke API calls are recorded by CloudTrailLOW
awslambda_function_no_dead_letter_queueLambda function has a Dead Letter Queue configuredMEDIUM
awslambda_function_no_secrets_in_codeLambda function code contains no hardcoded secretsCRITICAL
awslambda_function_no_secrets_in_variablesLambda function environment variables do not contain secretsCRITICAL
awslambda_function_not_publicly_accessibleLambda function resource-based policy does not allow public accessCRITICAL
awslambda_function_url_cors_policyLambda function URL CORS does not allow wildcard origins (*)MEDIUM
awslambda_function_url_publicLambda function URL is not publicly accessibleHIGH
awslambda_function_using_cross_account_layersLambda function does not use cross-account layersHIGH
awslambda_function_using_supported_runtimesLambda function uses a supported runtimeMEDIUM
awslambda_function_vpc_multi_azLambda function is configured with VPC subnets in at least two Availability ZonesMEDIUM

backup

5 checks.
Check IDTitleSeverity
backup_plans_existAt least one AWS Backup plan existsLOW
backup_recovery_point_encryptedAWS Backup recovery point is encrypted at restMEDIUM
backup_reportplans_existAt least one AWS Backup report plan existsLOW
backup_vaults_encryptedAWS Backup vault is encrypted at restMEDIUM
backup_vaults_existAt least one AWS Backup vault existsLOW

bedrock

9 checks.
Check IDTitleSeverity
bedrock_agent_guardrail_enabledAmazon Bedrock agent uses a guardrail to protect agent sessionsHIGH
bedrock_api_key_no_administrative_privilegesAmazon Bedrock API key does not have administrative privileges, privilege escalation paths, or full Bedrock se…HIGH
bedrock_api_key_no_long_term_credentialsAmazon Bedrock API key is expiredHIGH
bedrock_full_access_policy_attachedIAM role does not have AmazonBedrockFullAccess managed policy attachedHIGH
bedrock_guardrail_prompt_attack_filter_enabledAmazon Bedrock guardrail has prompt attack filter strength set to HIGHHIGH
bedrock_guardrail_sensitive_information_filter_enabledAmazon Bedrock guardrail blocks or masks sensitive informationHIGH
bedrock_model_invocation_logging_enabledAmazon Bedrock model invocation logging is enabledMEDIUM
bedrock_model_invocation_logs_encryption_enabledAmazon Bedrock model invocation logs are encrypted in the S3 bucket and KMS-encrypted in the CloudWatch log gr…HIGH
bedrock_vpc_endpoints_configuredVPC endpoints ensure private connectivity for all Bedrock APIsMEDIUM

cloudformation

3 checks.
Check IDTitleSeverity
cloudformation_stack_cdktoolkit_bootstrap_versionCDKToolkit CloudFormation stack has Bootstrap version 21 or higherHIGH
cloudformation_stack_outputs_find_secretsCloudFormation stack outputs do not contain secretsCRITICAL
cloudformation_stacks_termination_protection_enabledCloudFormation stack has termination protection enabledMEDIUM

cloudfront

13 checks.
Check IDTitleSeverity
cloudfront_distributions_custom_ssl_certificateCloudFront distribution uses a custom SSL/TLS certificateMEDIUM
cloudfront_distributions_default_root_objectCloudFront distribution has a default root object configuredHIGH
cloudfront_distributions_field_level_encryption_enabledCloudFront distribution has Field Level Encryption enabledLOW
cloudfront_distributions_geo_restrictions_enabledCloudFront distribution has Geo restrictions enabledLOW
cloudfront_distributions_https_enabledCloudFront distribution has viewer protocol policy set to HTTPS only or redirect to HTTPSMEDIUM
cloudfront_distributions_https_sni_enabledCloudFront distribution serves HTTPS requests using SNILOW
cloudfront_distributions_logging_enabledCloudFront distribution has logging enabledMEDIUM
cloudfront_distributions_multiple_origin_failover_configuredCloudFront distribution has origin failover configured with at least two originsLOW
cloudfront_distributions_origin_traffic_encryptedCloudFront distribution encrypts traffic to custom originsMEDIUM
cloudfront_distributions_s3_origin_access_controlCloudFront distribution uses Origin Access Control (OAC) for all S3 originsMEDIUM
cloudfront_distributions_s3_origin_non_existent_bucketCloudFront distribution S3 origins reference existing bucketsHIGH
cloudfront_distributions_using_deprecated_ssl_protocolsCloudFront distribution does not use SSLv3, TLSv1, or TLSv1.1 for origin connectionsLOW
cloudfront_distributions_using_wafCloudFront distribution uses an AWS WAF web ACLMEDIUM

cloudtrail

14 checks.
Check IDTitleSeverity
cloudtrail_bucket_requires_mfa_deleteCloudTrail trail S3 bucket has MFA delete enabledMEDIUM
cloudtrail_cloudwatch_logging_enabledCloudTrail trail has delivered logs to CloudWatch Logs in the last 24 hoursLOW
cloudtrail_insights_existCloudTrail trail has Insights enabledLOW
cloudtrail_kms_encryption_enabledCloudTrail trail logs are encrypted at rest with a KMS keyMEDIUM
cloudtrail_log_file_validation_enabledCloudTrail trail has log file validation enabledMEDIUM
cloudtrail_logs_s3_bucket_access_logging_enabledCloudTrail trail destination S3 bucket has access logging enabledMEDIUM
cloudtrail_logs_s3_bucket_is_not_publicly_accessibleCloudTrail trail S3 bucket is not publicly accessibleCRITICAL
cloudtrail_multi_region_enabledRegion has at least one CloudTrail trail loggingHIGH
cloudtrail_multi_region_enabled_logging_management_eventsCloudTrail trail logs management events for read and write operationsLOW
cloudtrail_s3_dataevents_read_enabledCloudTrail trail records S3 object-level read events for all S3 bucketsLOW
cloudtrail_s3_dataevents_write_enabledCloudTrail trail records all S3 object-level API operations for all bucketsLOW
cloudtrail_threat_detection_enumerationCloudTrail logs show no potential enumeration activityCRITICAL
cloudtrail_threat_detection_llm_jackingNo potential LLM jacking activity detected in CloudTrailCRITICAL
cloudtrail_threat_detection_privilege_escalationNo potential privilege escalation activity detected in CloudTrailCRITICAL

cloudwatch

22 checks.
Check IDTitleSeverity
cloudwatch_alarm_actions_alarm_state_configuredCloudWatch metric alarm has actions configured for the ALARM stateHIGH
cloudwatch_alarm_actions_enabledCloudWatch metric alarm has actions enabledHIGH
cloudwatch_changes_to_network_acls_alarm_configuredCloudWatch log metric filter and alarm exist for Network ACL (NACL) change eventsMEDIUM
cloudwatch_changes_to_network_gateways_alarm_configuredCloudWatch Logs metric filter and alarm exist for changes to network gatewaysMEDIUM
cloudwatch_changes_to_network_route_tables_alarm_configuredAccount monitors VPC route table changes with a CloudWatch Logs metric filter and alarmMEDIUM
cloudwatch_changes_to_vpcs_alarm_configuredAWS account has a CloudWatch Logs metric filter and alarm for VPC changesMEDIUM
cloudwatch_cross_account_sharing_disabledCloudWatch does not allow cross-account sharingMEDIUM
cloudwatch_log_group_kms_encryption_enabledCloudWatch log group is encrypted with an AWS KMS keyMEDIUM
cloudwatch_log_group_no_secrets_in_logsCloudWatch log group contains no secrets in its log eventsMEDIUM
cloudwatch_log_group_not_publicly_accessibleCloudWatch Log Group is not publicly accessibleHIGH
cloudwatch_log_group_retention_policy_specific_days_enabledCloudWatch log group has a retention policy of at least the configured minimum days or never expiresMEDIUM
cloudwatch_log_metric_filter_and_alarm_for_aws_config_configuration_changes_enabledCloudWatch Logs metric filter and alarm exist for AWS Config configuration changesMEDIUM
cloudwatch_log_metric_filter_and_alarm_for_cloudtrail_configuration_changes_enabledCloudWatch Logs metric filter and alarm exist for CloudTrail configuration changesMEDIUM
cloudwatch_log_metric_filter_authentication_failuresAccount has a CloudWatch Logs metric filter and alarm for AWS Management Console authentication failuresMEDIUM
cloudwatch_log_metric_filter_aws_organizations_changesCloudWatch Logs metric filter and alarm exist for AWS Organizations changesMEDIUM
cloudwatch_log_metric_filter_disable_or_scheduled_deletion_of_kms_cmkAccount has a CloudWatch log metric filter and alarm for disabling or scheduled deletion of customer-managed K…MEDIUM
cloudwatch_log_metric_filter_for_s3_bucket_policy_changesCloudWatch log metric filter and alarm exist for S3 bucket policy changesMEDIUM
cloudwatch_log_metric_filter_policy_changesCloudWatch Logs metric filter and alarm exist for IAM policy changesMEDIUM
cloudwatch_log_metric_filter_root_usageAccount has a CloudWatch Logs metric filter and alarm for root account usageMEDIUM
cloudwatch_log_metric_filter_security_group_changesCloudWatch Logs metric filter and alarm exist for security group changesMEDIUM
cloudwatch_log_metric_filter_sign_in_without_mfaCloudWatch log metric filter and alarm exist for Management Console sign-in without MFAMEDIUM
cloudwatch_log_metric_filter_unauthorized_api_callsCloudWatch Logs metric filter and alarm exist for unauthorized API callsMEDIUM

codeartifact

1 checks.
Check IDTitleSeverity
codeartifact_packages_external_public_publishing_disabledInternal CodeArtifact package does not allow publishing versions already present in external public sourcesCRITICAL

codebuild

10 checks.
Check IDTitleSeverity
codebuild_project_logging_enabledCodeBuild project has CloudWatch Logs or S3 logging enabledMEDIUM
codebuild_project_no_secrets_in_variablesCodeBuild project has no sensitive credentials in plaintext environment variablesCRITICAL
codebuild_project_not_publicly_accessibleCodeBuild project visibility is privateHIGH
codebuild_project_older_90_daysCodeBuild project has been invoked in the last 90 daysMEDIUM
codebuild_project_s3_logs_encryptedCodeBuild project S3 logs are encrypted at restLOW
codebuild_project_source_repo_url_no_sensitive_credentialsCodeBuild project source repository URLs do not contain sensitive credentialsCRITICAL
codebuild_project_user_controlled_buildspecCodeBuild project does not use a user-controlled buildspec fileMEDIUM
codebuild_project_uses_allowed_github_organizationsCodeBuild project using GitHub uses an allowed GitHub organizationHIGH
codebuild_project_webhook_filters_use_anchored_patternsCodeBuild project webhook filters use anchored regex patternsHIGH
codebuild_report_group_export_encryptedCodeBuild report group exports to S3 are encrypted at restMEDIUM

codepipeline

1 checks.
Check IDTitleSeverity
codepipeline_project_repo_privateCodePipeline pipeline should use private repository source with authenticated connectionMEDIUM

cognito

16 checks.
Check IDTitleSeverity
cognito_identity_pool_guest_access_disabledCognito identity pool has guest access disabledMEDIUM
cognito_user_pool_advanced_security_enabledCognito user pool has advanced security enforced with full-function modeMEDIUM
cognito_user_pool_blocks_compromised_credentials_sign_in_attemptsCognito user pool blocks sign-in attempts with suspected compromised credentialsMEDIUM
cognito_user_pool_blocks_potential_malicious_sign_in_attemptsAmazon Cognito user pool blocks all potential malicious sign-in attemptsMEDIUM
cognito_user_pool_client_prevent_user_existence_errorsAmazon Cognito user pool client has Prevent User Existence Errors enabledMEDIUM
cognito_user_pool_client_token_revocation_enabledAmazon Cognito user pool client has token revocation enabledMEDIUM
cognito_user_pool_deletion_protection_enabledCognito user pool has deletion protection enabledMEDIUM
cognito_user_pool_mfa_enabledAmazon Cognito user pool requires Multi-Factor Authentication (MFA)MEDIUM
cognito_user_pool_password_policy_lowercaseCognito user pool password policy requires at least one lowercase letterMEDIUM
cognito_user_pool_password_policy_minimum_length_14Cognito user pool has a password policy with a minimum length of 14 characters or moreMEDIUM
cognito_user_pool_password_policy_numberCognito user pool password policy requires at least one numberMEDIUM
cognito_user_pool_password_policy_symbolCognito user pool password policy requires at least one symbolMEDIUM
cognito_user_pool_password_policy_uppercaseCognito user pool password policy requires at least one uppercase letterMEDIUM
cognito_user_pool_self_registration_disabledAmazon Cognito user pool has self registration disabledMEDIUM
cognito_user_pool_temporary_password_expirationCognito user pool has temporary password expiration set to 7 days or lessMEDIUM
cognito_user_pool_waf_acl_attachedAmazon Cognito user pool is associated with a WAF Web ACLMEDIUM

config

2 checks.
Check IDTitleSeverity
config_recorder_all_regions_enabledAWS Config recorder is enabled and not in failure state or disabledMEDIUM
config_recorder_using_aws_service_roleAWS Config recorder uses the AWSServiceRoleForConfig service-linked roleMEDIUM

datasync

1 checks.
Check IDTitleSeverity
datasync_task_logging_enabledDataSync task has CloudWatch Logs log group configured for loggingHIGH

directconnect

2 checks.
Check IDTitleSeverity
directconnect_connection_redundancyDirect Connect connections span at least two locations per regionMEDIUM
directconnect_virtual_interface_redundancyDirect Connect gateway or virtual private gateway has at least two virtual interfaces on different Direct Conn…MEDIUM

directoryservice

6 checks.
Check IDTitleSeverity
directoryservice_directory_log_forwarding_enabledDirectory Service directory has log forwarding to CloudWatch Logs enabledMEDIUM
directoryservice_directory_monitor_notificationsDirectory Service directory has SNS notifications enabledMEDIUM
directoryservice_directory_snapshots_limitDirectory Service directory has adequate remaining manual snapshot quotaLOW
directoryservice_ldap_certificate_expirationDirectory Service LDAP certificate expires in more than 90 daysMEDIUM
directoryservice_radius_server_security_protocolDirectory Service directory RADIUS server uses MS-CHAPv2MEDIUM
directoryservice_supported_mfa_radius_enabledAWS Directory Service directory has RADIUS-based MFA enabledMEDIUM

dlm

1 checks.
Check IDTitleSeverity
dlm_ebs_snapshot_lifecycle_policy_existsRegion with EBS snapshots has at least one EBS snapshot lifecycle policy definedMEDIUM

dms

9 checks.
Check IDTitleSeverity
dms_endpoint_mongodb_authentication_enabledDMS MongoDB endpoint has an authentication mechanism enabledMEDIUM
dms_endpoint_neptune_iam_authorization_enabledDMS endpoint for Neptune has IAM authorization enabledMEDIUM
dms_endpoint_redis_in_transit_encryption_enabledDMS endpoint for Redis OSS is encrypted in transitMEDIUM
dms_endpoint_ssl_enabledDMS endpoint has SSL enabledHIGH
dms_instance_minor_version_upgrade_enabledDMS replication instance has auto minor version upgrade enabledMEDIUM
dms_instance_multi_az_enabledDMS replication instance has Multi-AZ enabledMEDIUM
dms_instance_no_public_accessDMS replication instance is not publicly exposed to the InternetCRITICAL
dms_replication_task_source_logging_enabledDMS replication task has logging enabled and SOURCE_CAPTURE and SOURCE_UNLOAD components set to at least Defau…MEDIUM
dms_replication_task_target_logging_enabledDMS replication task has TARGET_APPLY and TARGET_LOAD logging enabled with at least default severityMEDIUM

documentdb

6 checks.
Check IDTitleSeverity
documentdb_cluster_backup_enabledDocumentDB cluster has automated backups enabled with retention period of at least 7 daysMEDIUM
documentdb_cluster_cloudwatch_log_exportDocumentDB cluster exports audit and profiler logs to CloudWatch LogsMEDIUM
documentdb_cluster_deletion_protectionDocumentDB cluster has deletion protection enabledMEDIUM
documentdb_cluster_multi_az_enabledDocumentDB cluster has Multi-AZ enabledMEDIUM
documentdb_cluster_public_snapshotDocumentDB manual cluster snapshot is not shared publiclyCRITICAL
documentdb_cluster_storage_encryptedDocumentDB cluster storage is encrypted at restMEDIUM

drs

1 checks.
Check IDTitleSeverity
drs_job_existRegion has AWS Elastic Disaster Recovery (DRS) enabled with at least one recovery jobMEDIUM

dynamodb

9 checks.
Check IDTitleSeverity
dynamodb_accelerator_cluster_encryption_enabledDynamoDB DAX cluster has encryption at rest enabledMEDIUM
dynamodb_accelerator_cluster_in_transit_encryption_enabledDynamoDB Accelerator (DAX) cluster has encryption in transit enabledMEDIUM
dynamodb_accelerator_cluster_multi_azDynamoDB Accelerator (DAX) cluster has nodes in multiple Availability ZonesMEDIUM
dynamodb_table_autoscaling_enabledDynamoDB table uses on-demand capacity or has auto scaling enabled for read and write capacity unitsMEDIUM
dynamodb_table_cross_account_accessDynamoDB table resource-based policy does not allow cross-account accessMEDIUM
dynamodb_table_deletion_protection_enabledDynamoDB table has deletion protection enabledMEDIUM
dynamodb_table_protected_by_backup_planDynamoDB table is protected by a backup planMEDIUM
dynamodb_tables_kms_cmk_encryption_enabledDynamoDB table is encrypted at rest with AWS KMSMEDIUM
dynamodb_tables_pitr_enabledDynamoDB table has point-in-time recovery (PITR) enabledMEDIUM

ec2

71 checks.
Check IDTitleSeverity
ec2_ami_publicEC2 AMI owned by the account is not publicCRITICAL
ec2_client_vpn_endpoint_connection_logging_enabledEC2 Client VPN endpoint has client connection logging enabledLOW
ec2_ebs_default_encryptionEBS default encryption is enabledHIGH
ec2_ebs_public_snapshotEBS snapshot is not publicCRITICAL
ec2_ebs_snapshot_account_block_public_accessAll EBS snapshots have public access blockedHIGH
ec2_ebs_snapshots_encryptedEBS snapshot is encryptedHIGH
ec2_ebs_volume_encryptionEBS volume is encryptedHIGH
ec2_ebs_volume_protected_by_backup_planEBS volume is protected by a backup planMEDIUM
ec2_ebs_volume_snapshots_existsEBS volume has at least one snapshotHIGH
ec2_elastic_ip_shodanEC2 Elastic IP address is not listed in ShodanMEDIUM
ec2_elastic_ip_unassignedElastic IP is associated with an instance or network interfaceLOW
ec2_instance_account_imdsv2_enabledIMDSv2 is required by default for EC2 instances at the account levelHIGH
ec2_instance_detailed_monitoring_enabledEC2 instance has detailed monitoring enabledLOW
ec2_instance_imdsv2_enabledEC2 instance requires IMDSv2 or has the instance metadata service disabledHIGH
ec2_instance_internet_facing_with_instance_profileEC2 instance is not internet-facing with an instance profile attachedHIGH
ec2_instance_managed_by_ssmEC2 instance is managed by AWS Systems Manager or not runningMEDIUM
ec2_instance_older_than_specific_daysEC2 instance is not older than the configured maximum age or is not runningMEDIUM
ec2_instance_paravirtual_typeEC2 instance virtualization type is HVMMEDIUM
ec2_instance_port_cassandra_exposed_to_internetEC2 instance does not have Cassandra ports (TCP 7000, 7001, 7199, 9042, 9160) open to the InternetCRITICAL
ec2_instance_port_cifs_exposed_to_internetEC2 instance does not allow Internet ingress to TCP ports 139 or 445 (CIFS)CRITICAL
ec2_instance_port_elasticsearch_kibana_exposed_to_internetEC2 instance does not allow ingress from the Internet to Elasticsearch and Kibana ports (TCP 9200, 9300, 5601)CRITICAL
ec2_instance_port_ftp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 20 or 21 (FTP)CRITICAL
ec2_instance_port_kafka_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 9092 (Kafka)CRITICAL
ec2_instance_port_kerberos_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 88, 464, 749, or 750 (Kerberos)CRITICAL
ec2_instance_port_ldap_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 389 or 636 (LDAP/LDAPS)CRITICAL
ec2_instance_port_memcached_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 11211 (Memcached)CRITICAL
ec2_instance_port_mongodb_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 27017 or 27018 (MongoDB)CRITICAL
ec2_instance_port_mysql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3306 (MySQL)CRITICAL
ec2_instance_port_oracle_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1521, 2483, or 2484 (Oracle)CRITICAL
ec2_instance_port_postgresql_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 5432 (PostgreSQL)CRITICAL
ec2_instance_port_rdp_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 3389 (RDP)CRITICAL
ec2_instance_port_redis_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 6379 (Redis)CRITICAL
ec2_instance_port_sqlserver_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP ports 1433 or 1434 (SQL Server)CRITICAL
ec2_instance_port_ssh_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 22 (SSH)CRITICAL
ec2_instance_port_telnet_exposed_to_internetEC2 instance does not allow ingress from the Internet to TCP port 23 (Telnet)CRITICAL
ec2_instance_profile_attachedEC2 instance is associated with an IAM instance profile roleMEDIUM
ec2_instance_public_ipEC2 instance does not have a public IP addressMEDIUM
ec2_instance_secrets_user_dataEC2 instance user data contains no secretsHIGH
ec2_instance_uses_single_eniEC2 instance has no more than one Elastic Network Interface (ENI) attachedLOW
ec2_instance_with_outdated_amiEC2 instance uses a non-deprecated Amazon AMIMEDIUM
ec2_launch_template_imdsv2_requiredEC2 launch template has IMDSv2 enabled and required or instance metadata service disabledHIGH
ec2_launch_template_no_public_ipAmazon EC2 launch template has no public IP addresses configured on network interfacesHIGH
ec2_launch_template_no_secretsEC2 launch template user data contains no secrets in any versionHIGH
ec2_networkacl_allow_ingress_any_portNetwork ACL does not allow ingress from 0.0.0.0/0 to any portHIGH
ec2_networkacl_allow_ingress_tcp_port_22Network ACL does not allow ingress from the Internet to TCP port 22 (SSH)MEDIUM
ec2_networkacl_allow_ingress_tcp_port_3389Network ACL does not allow ingress from the Internet to TCP port 3389 (RDP)MEDIUM
ec2_networkacl_unusedNon-default network ACL is associated with a subnetLOW
ec2_securitygroup_allow_ingress_from_internet_to_all_portsSecurity group does not have all ports open to the InternetCRITICAL
ec2_securitygroup_allow_ingress_from_internet_to_any_portSecurity group has no 0.0.0.0/0 or ::/0 ingress to any port, or is attached only to allowed interface types or…HIGH
ec2_securitygroup_allow_ingress_from_internet_to_any_port_from_ipSecurity group does not have any port open to a specific public IP addressMEDIUM
ec2_securitygroup_allow_ingress_from_internet_to_high_risk_tcp_portsSecurity group does not allow ingress from 0.0.0.0/0 or ::/0 to high-risk TCP portsHIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_22Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 22 (SSH)HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_3389Security group does not allow ingress from the Internet to TCP port 3389 (RDP)HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_cassandra_7199_9160_8888Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Cassandra TCP ports 7199, 9160, or 8888HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_elasticsearch_kibana_9200_9300_5601Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana TCP ports 9200, 9300, and…HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_ftp_20_21Security group does not allow ingress from 0.0.0.0/0 or ::/0 to FTP ports 20 or 21HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_kafka_9092Security group does not allow ingress from 0.0.0.0/0 or ::/0 to TCP port 9092 (Kafka)HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_memcached_11211Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Memcached TCP port 11211HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mongodb_27017_27018Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MongoDB TCP ports 27017 and 27018HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_mysql_3306Security group does not allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_oracle_1521_2483Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Oracle TCP ports 1521 or 2483HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_postgres_5432Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Postgres TCP port 5432HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_redis_6379Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Redis TCP port 6379HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_sql_server_1433_1434Security group does not allow ingress from 0.0.0.0/0 or ::/0 to Microsoft SQL Server ports 1433 and 1434HIGH
ec2_securitygroup_allow_ingress_from_internet_to_tcp_port_telnet_23Security group does not allow ingress from the Internet to TCP port 23 (Telnet)HIGH
ec2_securitygroup_allow_wide_open_public_ipv4Security group has no ingress or egress rules with public IPv4 CIDR ranges from /1 to /23HIGH
ec2_securitygroup_default_restrict_trafficVPC default security group has no inbound or outbound rulesHIGH
ec2_securitygroup_from_launch_wizardSecurity group not created using the EC2 Launch WizardMEDIUM
ec2_securitygroup_not_usedNon-default EC2 security group is in useLOW
ec2_securitygroup_with_many_ingress_egress_rulesSecurity group has 50 or fewer inbound rules and 50 or fewer outbound rulesMEDIUM
ec2_transitgateway_auto_accept_vpc_attachmentsAmazon EC2 Transit Gateway does not automatically accept shared VPC attachmentsHIGH

ecr

6 checks.
Check IDTitleSeverity
ecr_registry_scan_images_on_push_enabledECR registry has image scanning on push enabled for all repositoriesMEDIUM
ecr_repositories_lifecycle_policy_enabledECR repository has a lifecycle policy configuredLOW
ecr_repositories_not_publicly_accessibleECR repository is not publicly accessibleCRITICAL
ecr_repositories_scan_images_on_push_enabled[DEPRECATED] ECR repository has image scanning on push enabledMEDIUM
ecr_repositories_scan_vulnerabilities_in_latest_imageECR repository latest image is scanned with no vulnerabilities at or above the configured minimum severityMEDIUM
ecr_repositories_tag_immutabilityECR repository has image tag immutability enabledMEDIUM

ecs

11 checks.
Check IDTitleSeverity
ecs_cluster_container_insights_enabledECS cluster has Container Insights enabled or enhancedMEDIUM
ecs_service_fargate_latest_platform_versionECS Fargate service uses the latest Fargate platform versionMEDIUM
ecs_service_no_assign_public_ipECS service does not have automatic public IP assignmentHIGH
ecs_task_definitions_containers_readonly_accessECS task definition has all containers with read-only root filesystemsHIGH
ecs_task_definitions_host_namespace_not_sharedECS task definition does not share the host’s process namespace with its containersHIGH
ecs_task_definitions_host_networking_mode_usersAmazon ECS task definition does not use host network mode, or non-privileged containers specify a non-root use…HIGH
ecs_task_definitions_logging_block_modeECS task definition has container logging in non-blocking modeLOW
ecs_task_definitions_logging_enabledECS task definition has logging configured for all containersHIGH
ecs_task_definitions_no_environment_secretsECS task definition has no secrets in environment variablesCRITICAL
ecs_task_definitions_no_privileged_containersECS task definition has no privileged containersHIGH
ecs_task_set_no_assign_public_ipECS task set does not automatically assign a public IP addressHIGH

efs

7 checks.
Check IDTitleSeverity
efs_access_point_enforce_root_directoryEFS file system has no access points allowing access to the root directoryMEDIUM
efs_access_point_enforce_user_identityEFS file system has all access points with a defined POSIX userMEDIUM
efs_encryption_at_rest_enabledEFS file system has encryption at rest enabledMEDIUM
efs_have_backup_enabledEFS file system has backup enabledMEDIUM
efs_mount_target_not_publicly_accessibleEFS file system has no publicly accessible mount targetsMEDIUM
efs_multi_az_enabledEFS file system is Multi-AZ with more than one mount targetMEDIUM
efs_not_publicly_accessibleEFS file system policy does not allow access to any client within the VPCMEDIUM

eks

7 checks.
Check IDTitleSeverity
eks_cluster_deletion_protection_enabledEKS cluster has deletion protection enabledHIGH
eks_cluster_kms_cmk_encryption_in_secrets_enabledEKS cluster has Kubernetes secrets encryption enabledMEDIUM
eks_cluster_network_policy_enabledEKS cluster has network policy enabledHIGH
eks_cluster_not_publicly_accessibleEKS cluster endpoint is not publicly accessible from 0.0.0.0/0HIGH
eks_cluster_private_nodes_enabledEKS cluster has private endpoint access enabledHIGH
eks_cluster_uses_a_supported_versionEKS cluster uses a supported Kubernetes versionHIGH
eks_control_plane_logging_all_types_enabledEKS cluster has control plane logging enabled for api, audit, authenticator, controllerManager, and schedulerMEDIUM

elasticache

8 checks.
Check IDTitleSeverity
elasticache_cluster_uses_public_subnetElastiCache cluster is not using public subnetsMEDIUM
elasticache_redis_cluster_auto_minor_version_upgradesElastiCache Redis cache cluster has automatic minor version upgrades enabledHIGH
elasticache_redis_cluster_automatic_failover_enabledElastiCache Redis cluster has automatic failover enabledMEDIUM
elasticache_redis_cluster_backup_enabledElastiCache Redis cache cluster has automated snapshot backups enabled with retention of at least 7 daysHIGH
elasticache_redis_cluster_in_transit_encryption_enabledElastiCache Redis cache cluster has in-transit encryption enabledMEDIUM
elasticache_redis_cluster_multi_az_enabledElastiCache Redis replication group has Multi-AZ enabledMEDIUM
elasticache_redis_cluster_rest_encryption_enabledElastiCache Redis cache cluster has at rest encryption enabledMEDIUM
elasticache_redis_replication_group_auth_enabledElastiCache Redis replication group with engine version < 6.0 has Redis OSS AUTH enabledMEDIUM

elasticbeanstalk

3 checks.
Check IDTitleSeverity
elasticbeanstalk_environment_cloudwatch_logging_enabledElastic Beanstalk environment streams logs to CloudWatch LogsHIGH
elasticbeanstalk_environment_enhanced_health_reportingElastic Beanstalk environment has enhanced health reporting enabledLOW
elasticbeanstalk_environment_managed_updates_enabledElastic Beanstalk environment has managed platform updates enabledHIGH

elb

9 checks.
Check IDTitleSeverity
elb_connection_draining_enabledClassic Load Balancer has connection draining enabledMEDIUM
elb_cross_zone_load_balancing_enabledClassic Load Balancer has cross-zone load balancing enabledMEDIUM
elb_desync_mitigation_modeClassic Load Balancer desync mitigation mode is defensive or strictestMEDIUM
elb_insecure_ssl_ciphersElastic Load Balancer HTTPS listeners, if present, use the ELBSecurityPolicy-TLS-1-2-2017-01 policyMEDIUM
elb_internet_facingElastic Load Balancer is not internet-facingMEDIUM
elb_is_in_multiple_azClassic Load Balancer is in multiple Availability ZonesMEDIUM
elb_logging_enabledElastic Load Balancer has access logs to S3 configuredMEDIUM
elb_ssl_listenersElastic Load Balancer has only HTTPS or SSL listenersMEDIUM
elb_ssl_listeners_use_acm_certificateClassic Load Balancer HTTPS/SSL listeners use ACM-issued certificatesMEDIUM

elbv2

11 checks.
Check IDTitleSeverity
elbv2_cross_zone_load_balancing_enabledELBv2 Network or Gateway Load Balancer has cross-zone load balancing enabledMEDIUM
elbv2_deletion_protectionELBv2 load balancer has deletion protection enabledMEDIUM
elbv2_desync_mitigation_modeApplication Load Balancer has desync mitigation mode set to strictest or defensive, or drops invalid header fi…MEDIUM
elbv2_insecure_ssl_ciphersELBv2 load balancer uses a secure SSL policy on HTTPS listenersMEDIUM
elbv2_internet_facingApplication Load Balancer is not publicly accessible (no inbound TCP from 0.0.0.0/0 or ::/0)MEDIUM
elbv2_is_in_multiple_azELBv2 load balancer is configured across multiple Availability ZonesMEDIUM
elbv2_listeners_underneathELBv2 load balancer has at least one listenerMEDIUM
elbv2_logging_enabledELBv2 Application Load Balancer has access logs to S3 configuredMEDIUM
elbv2_nlb_tls_termination_enabledELBv2 Network Load Balancer has TLS termination enabledMEDIUM
elbv2_ssl_listenersELBv2 Application Load Balancer listeners use HTTPS or redirect HTTP to HTTPSMEDIUM
elbv2_waf_acl_attachedApplication Load Balancer has a WAF Web ACL attachedMEDIUM

emr

3 checks.
Check IDTitleSeverity
emr_cluster_account_public_block_enabledEMR account has Block Public Access enabledHIGH
emr_cluster_master_nodes_no_public_ipEMR Cluster without Public IP.MEDIUM
emr_cluster_publicly_accesibleEMR cluster is not publicly accessibleMEDIUM

eventbridge

4 checks.
Check IDTitleSeverity
eventbridge_bus_cross_account_accessAWS EventBridge event bus does not allow cross-account accessHIGH
eventbridge_bus_exposedAWS EventBridge event bus policy does not allow public accessHIGH
eventbridge_global_endpoint_event_replication_enabledEventBridge global endpoint has event replication enabledMEDIUM
eventbridge_schema_registry_cross_account_accessAWS EventBridge schema registry does not allow cross-account accessHIGH

firehose

1 checks.
Check IDTitleSeverity
firehose_stream_encrypted_at_restKinesis Data Firehose delivery stream is encrypted at restMEDIUM

fms

1 checks.
Check IDTitleSeverity
fms_policy_compliantAll AWS FMS policies in the admin account are compliant for all accountsMEDIUM

fsx

3 checks.
Check IDTitleSeverity
fsx_file_system_copy_tags_to_backups_enabledFSx file system has copy tags to backups enabledLOW
fsx_file_system_copy_tags_to_volumes_enabledFSx file system has copy tags to volumes enabledLOW
fsx_windows_file_system_multi_az_enabledFSx Windows file system is configured for Multi-AZ deploymentLOW

glacier

1 checks.
Check IDTitleSeverity
glacier_vaults_policy_public_accessS3 Glacier vault has no policy or its policy does not allow access to everyoneCRITICAL

glue

13 checks.
Check IDTitleSeverity
glue_data_catalogs_connection_passwords_encryption_enabledGlue data catalog connection password is encrypted with a KMS keyHIGH
glue_data_catalogs_metadata_encryption_enabledGlue Data Catalog metadata is encrypted with KMSMEDIUM
glue_data_catalogs_not_publicly_accessibleGlue Data Catalog is not publicly accessible via its resource policyHIGH
glue_database_connections_ssl_enabledGlue connection has SSL enabledHIGH
glue_development_endpoints_cloudwatch_logs_encryption_enabledGlue development endpoint has CloudWatch Logs encryption enabledMEDIUM
glue_development_endpoints_job_bookmark_encryption_enabledGlue development endpoint has Job Bookmark encryption enabledMEDIUM
glue_development_endpoints_s3_encryption_enabledGlue development endpoint has S3 encryption enabledMEDIUM
glue_etl_jobs_amazon_s3_encryption_enabledGlue job has S3 encryption enabledHIGH
glue_etl_jobs_cloudwatch_logs_encryption_enabledGlue ETL job has CloudWatch Logs encryption enabledMEDIUM
glue_etl_jobs_job_bookmark_encryption_enabledGlue ETL job has Job bookmark encryption enabledMEDIUM
glue_etl_jobs_logging_enabledGlue ETL job has continuous CloudWatch logging enabledMEDIUM
glue_etl_jobs_no_secrets_in_argumentsGlue ETL job has no secrets in default argumentsCRITICAL
glue_ml_transform_encrypted_at_restGlue ML Transform is encrypted at restMEDIUM

guardduty

10 checks.
Check IDTitleSeverity
guardduty_centrally_managedGuardDuty detector is managed by an administrator account or is the administrator with member accountsMEDIUM
guardduty_delegated_admin_enabled_all_regionsGuardDuty has delegated admin configured and is enabled in all regions with organization auto-enableHIGH
guardduty_ec2_malware_protection_enabledGuardDuty detector has Malware Protection for EC2 enabledHIGH
guardduty_eks_audit_log_enabledGuardDuty detector has EKS Audit Log Monitoring enabledHIGH
guardduty_eks_runtime_monitoring_enabledGuardDuty detector has EKS Runtime Monitoring enabledMEDIUM
guardduty_is_enabledGuardDuty detector is enabled and not suspendedHIGH
guardduty_lambda_protection_enabledGuardDuty detector has Lambda Protection enabledHIGH
guardduty_no_high_severity_findingsGuardDuty detector has no high severity findingsHIGH
guardduty_rds_protection_enabledGuardDuty detector has RDS Protection enabledHIGH
guardduty_s3_protection_enabledGuardDuty detector has S3 Protection enabledHIGH

iam

47 checks.
Check IDTitleSeverity
iam_administrator_access_with_mfaIAM group members granted AdministratorAccess have MFA enabledHIGH
iam_avoid_root_usageAWS account root user has not been used in the last dayHIGH
iam_aws_attached_policy_no_administrative_privilegesAttached AWS-managed IAM policy does not allow ’:’ administrative privilegesCRITICAL
iam_check_saml_providers_stsIAM SAML provider exists in the accountLOW
iam_customer_attached_policy_no_administrative_privilegesAttached IAM customer-managed policy does not allow ’:’ administrative privilegesHIGH
iam_customer_unattached_policy_no_administrative_privilegesUnattached customer managed IAM policy does not allow ’:’ administrative privilegesMEDIUM
iam_group_administrator_access_policyIAM group does not have AdministratorAccess policy attachedHIGH
iam_inline_policy_allows_privilege_escalationIAM inline policy does not allow privilege escalationHIGH
iam_inline_policy_no_administrative_privilegesInline IAM policy does not allow ’:’ administrative privilegesCRITICAL
iam_inline_policy_no_full_access_to_cloudtrailInline IAM policy does not allow ‘cloudtrail:*’ privilegesHIGH
iam_inline_policy_no_full_access_to_kmsInline IAM policy does not allow kms:* privilegesMEDIUM
iam_inline_policy_no_wildcard_marketplace_subscribeInline IAM policy does not allow ‘aws-marketplace:Subscribe’ on all resourcesMEDIUM
iam_no_custom_policy_permissive_role_assumptionCustom IAM policy does not allow STS role assumption on wildcard resourcesHIGH
iam_no_expired_server_certificates_storedIAM server certificate is not expiredHIGH
iam_no_root_access_keyRoot account has no active access keysCRITICAL
iam_password_policy_expires_passwords_within_90_days_or_lessIAM account password policy enforces password expiration within 90 days or lessMEDIUM
iam_password_policy_lowercaseIAM password policy requires at least one lowercase letterLOW
iam_password_policy_minimum_length_14IAM password policy requires passwords to be at least 14 characters longMEDIUM
iam_password_policy_numberIAM password policy requires at least one numberMEDIUM
iam_password_policy_reuse_24IAM password policy prevents reuse of the last 24 passwordsMEDIUM
iam_password_policy_symbolIAM password policy requires at least one symbolMEDIUM
iam_password_policy_uppercaseIAM password policy requires at least one uppercase letterMEDIUM
iam_policy_allows_privilege_escalationCustomer managed IAM policy does not allow actions that can lead to privilege escalationHIGH
iam_policy_attached_only_to_group_or_rolesIAM user has no inline or attached policiesLOW
iam_policy_cloudshell_admin_not_attachedNo IAM users, groups, or roles have the AWSCloudShellFullAccess policy attachedMEDIUM
iam_policy_no_full_access_to_cloudtrailCustomer managed IAM policy does not allow cloudtrail:* privilegesMEDIUM
iam_policy_no_full_access_to_kmsCustom IAM policy does not allow ‘kms:*’ privilegesMEDIUM
iam_policy_no_wildcard_marketplace_subscribeCustom IAM policy does not allow ‘aws-marketplace:Subscribe’ on all resourcesMEDIUM
iam_role_access_not_stale_to_bedrockRegular Bedrock access ensures IAM roles retain only actively used permissionsMEDIUM
iam_role_administratoraccess_policyIAM role does not have AdministratorAccess policy attachedHIGH
iam_role_cross_account_readonlyaccess_policyIAM role does not grant ReadOnlyAccess to external AWS accountsHIGH
iam_role_cross_service_confused_deputy_preventionIAM service role prevents cross-service confused deputy attackHIGH
iam_root_credentials_management_enabledAWS Organization has centralized root credentials management enabledHIGH
iam_root_hardware_mfa_enabledRoot account has a hardware MFA device enabledCRITICAL
iam_root_mfa_enabledRoot account has MFA enabledCRITICAL
iam_rotate_access_key_90_daysIAM user does not have active access keys older than 90 daysMEDIUM
iam_securityaudit_role_createdAt least one IAM role has the SecurityAudit AWS managed policy attachedLOW
iam_support_role_createdAt least one IAM role has the AWSSupportAccess managed policy attachedLOW
iam_user_access_not_stale_to_bedrockRegular Bedrock access ensures IAM users retain only actively used permissionsMEDIUM
iam_user_accesskey_unusedIAM user does not have unused access keys older than 45 daysMEDIUM
iam_user_administrator_access_policyIAM user does not have AdministratorAccess policy attachedCRITICAL
iam_user_console_access_unusedIAM user console access is disabled, used within the configured inactivity period, or never usedMEDIUM
iam_user_hardware_mfa_enabledIAM user has hardware MFA enabledHIGH
iam_user_mfa_enabled_console_accessIAM user has MFA enabled for console access or no console password is setHIGH
iam_user_no_setup_initial_access_keyIAM user does not have active access keys that have never been usedMEDIUM
iam_user_two_active_access_keyIAM user has at most one active access keyMEDIUM
iam_user_with_temporary_credentialsIAM user does not use long-lived credentials to access services other than IAM or STSHIGH

inspector2

2 checks.
Check IDTitleSeverity
inspector2_active_findings_existInspector2 is enabled with no active findingsHIGH
inspector2_is_enabledInspector2 is enabled for Amazon EC2 instances, ECR container images, Lambda functions, and Lambda codeMEDIUM

kafka

8 checks.
Check IDTitleSeverity
kafka_cluster_encryption_at_rest_uses_cmkKafka cluster has encryption at rest enabled with a customer managed key (CMK) or is serverlessMEDIUM
kafka_cluster_enhanced_monitoring_enabledAmazon MSK cluster has enhanced monitoring enabledMEDIUM
kafka_cluster_in_transit_encryption_enabledKafka cluster has encryption in transit enabledHIGH
kafka_cluster_is_publicKafka cluster is not publicly accessibleCRITICAL
kafka_cluster_mutual_tls_authentication_enabledKafka cluster has TLS authentication enabledHIGH
kafka_cluster_unrestricted_access_disabledKafka cluster requires authenticationCRITICAL
kafka_cluster_uses_latest_versionMSK cluster uses the latest Kafka version or is serverless with AWS-managed versionMEDIUM
kafka_connector_in_transit_encryption_enabledMSK Connect connector has encryption in transit enabledHIGH

kinesis

2 checks.
Check IDTitleSeverity
kinesis_stream_data_retention_periodKinesis stream retains data for at least the required minimum hoursMEDIUM
kinesis_stream_encrypted_at_restKinesis stream is encrypted at rest with KMSHIGH

kms

5 checks.
Check IDTitleSeverity
kms_cmk_are_usedKMS customer managed key is enabled or scheduled for deletionLOW
kms_cmk_not_deleted_unintentionallyAWS KMS customer managed key is not scheduled for deletionCRITICAL
kms_cmk_not_multi_regionAWS KMS customer managed key is single-RegionMEDIUM
kms_cmk_rotation_enabledKMS customer-managed symmetric CMK has automatic rotation enabledHIGH
kms_key_not_publicly_accessibleCloud KMS key does not grant access to allUsers or allAuthenticatedUsersCRITICAL

lightsail

4 checks.
Check IDTitleSeverity
lightsail_database_publicLightsail database public access disabledHIGH
lightsail_instance_automated_snapshotsLightsail instance has automated snapshots enabledMEDIUM
lightsail_instance_publicLightsail instance has no publicly accessible portsHIGH
lightsail_static_ip_unusedLightsail static IP is associated with an instanceLOW

macie

2 checks.
Check IDTitleSeverity
macie_automated_sensitive_data_discovery_enabledMacie automated sensitive data discovery is enabledHIGH
macie_is_enabledAmazon Macie is enabledMEDIUM

memorydb

1 checks.
Check IDTitleSeverity
memorydb_cluster_auto_minor_version_upgradesMemoryDB cluster has automatic minor version upgrades enabledMEDIUM

mq

5 checks.
Check IDTitleSeverity
mq_broker_active_deployment_modeApache ActiveMQ broker is configured in active/standby Multi-AZ deployment modeLOW
mq_broker_auto_minor_version_upgradesAmazon MQ broker has automated minor version upgrades enabledLOW
mq_broker_cluster_deployment_modeMQ RabbitMQ broker has cluster (multi-AZ) deployment modeMEDIUM
mq_broker_logging_enabledMQ broker has general logging enabled and, for ActiveMQ, audit logging enabledLOW
mq_broker_not_publicly_accessibleAmazon MQ broker is not publicly accessibleHIGH

neptune

10 checks.
Check IDTitleSeverity
neptune_cluster_backup_enabledNeptune cluster has automated backups enabled with retention period equal to or greater than the configured mi…MEDIUM
neptune_cluster_copy_tags_to_snapshotsNeptune DB cluster is configured to copy tags to snapshots.LOW
neptune_cluster_deletion_protectionNeptune cluster has deletion protection enabledMEDIUM
neptune_cluster_iam_authentication_enabledNeptune cluster has IAM authentication enabledMEDIUM
neptune_cluster_integration_cloudwatch_logsNeptune cluster has CloudWatch audit logs enabledMEDIUM
neptune_cluster_multi_azNeptune cluster has Multi-AZ enabledMEDIUM
neptune_cluster_public_snapshotNeptuneDB cluster snapshot is not publicly sharedCRITICAL
neptune_cluster_snapshot_encryptedNeptune DB cluster snapshot is encrypted at restMEDIUM
neptune_cluster_storage_encryptedNeptune cluster storage is encrypted at restHIGH
neptune_cluster_uses_public_subnetNeptune cluster is not using public subnetsMEDIUM

networkfirewall

7 checks.
Check IDTitleSeverity
networkfirewall_deletion_protectionNetwork Firewall has deletion protection enabledMEDIUM
networkfirewall_in_all_vpcVPC has Network Firewall enabledMEDIUM
networkfirewall_logging_enabledNetwork Firewall has logging enabledHIGH
networkfirewall_multi_azNetwork Firewall firewall is deployed across multiple Availability ZonesHIGH
networkfirewall_policy_default_action_fragmented_packetsNetwork Firewall policy drops or forwards fragmented packets by defaultHIGH
networkfirewall_policy_default_action_full_packetsNetwork Firewall firewall policy default stateless action for full packets is drop or forwardHIGH
networkfirewall_policy_rule_group_associatedNetwork Firewall policy has at least one rule group associatedHIGH

opensearch

12 checks.
Check IDTitleSeverity
opensearch_service_domains_access_control_enabledAmazon OpenSearch Service domain has fine-grained access control enabledHIGH
opensearch_service_domains_audit_logging_enabledAmazon OpenSearch Service domain has audit logging enabledHIGH
opensearch_service_domains_cloudwatch_logging_enabledAmazon OpenSearch Service domain publishes search and index slow logs to CloudWatch LogsLOW
opensearch_service_domains_encryption_at_rest_enabledAmazon OpenSearch Service domain has encryption at rest enabledCRITICAL
opensearch_service_domains_fault_tolerant_data_nodesOpenSearch domain has at least 3 data nodes and Zone Awareness enabledMEDIUM
opensearch_service_domains_fault_tolerant_master_nodesOpenSearch domain has at least 3 dedicated master nodesMEDIUM
opensearch_service_domains_https_communications_enforcedOpenSearch domain has HTTPS enforcement enabledHIGH
opensearch_service_domains_internal_user_database_enabledAmazon OpenSearch Service domain has internal user database disabledMEDIUM
opensearch_service_domains_node_to_node_encryption_enabledAmazon OpenSearch Service domain has node-to-node encryption enabledHIGH
opensearch_service_domains_not_publicly_accessibleAmazon OpenSearch Service domain is not publicly accessibleCRITICAL
opensearch_service_domains_updated_to_the_latest_service_software_versionAmazon OpenSearch Service domain is updated to the latest service software versionHIGH
opensearch_service_domains_use_cognito_authentication_for_kibanaAmazon OpenSearch Service domain has either Amazon Cognito or SAML authentication enabled for KibanaMEDIUM

organizations

5 checks.
Check IDTitleSeverity
organizations_account_part_of_organizationsAWS account is a member of an active AWS OrganizationMEDIUM
organizations_delegated_administratorsAWS Organization has only trusted delegated administratorsCRITICAL
organizations_opt_out_ai_services_policyAWS Organization has opted out of all AI services and child accounts cannot override the policyMEDIUM
organizations_scp_check_deny_regionsAWS Organization restricts operations to only the configured AWS Regions with SCP policiesHIGH
organizations_tags_policies_enabled_and_attachedAWS Organization has tag policies enabled and attachedLOW

rds

35 checks.
Check IDTitleSeverity
rds_cluster_backtrack_enabledRDS Aurora MySQL cluster has Backtrack enabledLOW
rds_cluster_copy_tags_to_snapshotsRDS DB cluster has copy tags to snapshots enabledLOW
rds_cluster_critical_event_subscriptionRDS cluster event subscription is enabled for maintenance and failure categoriesMEDIUM
rds_cluster_default_adminRDS cluster master username is not admin or postgresMEDIUM
rds_cluster_deletion_protectionRDS cluster has deletion protection enabledMEDIUM
rds_cluster_iam_authentication_enabledRDS cluster has IAM authentication enabledMEDIUM
rds_cluster_integration_cloudwatch_logsRDS cluster has CloudWatch Logs export enabledMEDIUM
rds_cluster_minor_version_upgrade_enabledRDS cluster has automatic minor version upgrades enabledMEDIUM
rds_cluster_multi_azRDS cluster has Multi-AZ enabledMEDIUM
rds_cluster_non_default_portRDS cluster uses a non-default port for its database engineLOW
rds_cluster_protected_by_backup_planRDS cluster is protected by an AWS Backup planHIGH
rds_cluster_storage_encryptedRDS cluster storage is encryptedHIGH
rds_instance_backup_enabledRDS instance has backup retention period greater than 0 daysMEDIUM
rds_instance_certificate_expirationRDS instance SSL/TLS certificate has more than 3 months of validity remainingHIGH
rds_instance_copy_tags_to_snapshotsRDS DB instance has copy tags to snapshots enabledLOW
rds_instance_critical_event_subscriptionRDS instance event subscription is enabled for maintenance, configuration change, and failure categoriesMEDIUM
rds_instance_default_adminRDS instance does not use the default master username (admin or postgres)MEDIUM
rds_instance_deletion_protectionRDS instance has deletion protection enabledMEDIUM
rds_instance_deprecated_engine_versionRDS instance uses a supported engine versionHIGH
rds_instance_enhanced_monitoring_enabledRDS instance has enhanced monitoring enabledLOW
rds_instance_event_subscription_parameter_groupsRDS DB parameter group event subscription is enabled and subscribes to configuration change events or all cate…LOW
rds_instance_event_subscription_security_groupsRDS event subscription for DB security groups is enabled for configuration change and failure eventsMEDIUM
rds_instance_extended_supportRDS instance is not enrolled in RDS Extended SupportMEDIUM
rds_instance_iam_authentication_enabledRDS instance has IAM database authentication enabledMEDIUM
rds_instance_inside_vpcRDS instance is deployed in a VPCHIGH
rds_instance_integration_cloudwatch_logsRDS instance exports logs to CloudWatch LogsMEDIUM
rds_instance_minor_version_upgrade_enabledRDS instance has minor version upgrade enabledMEDIUM
rds_instance_multi_azRDS instance has Multi-AZ enabledMEDIUM
rds_instance_no_public_accessRDS instance is not publicly exposed to the InternetCRITICAL
rds_instance_non_default_portRDS instance uses a non-default port for its engineLOW
rds_instance_protected_by_backup_planRDS instance is protected by an AWS Backup planHIGH
rds_instance_storage_encryptedRDS DB instance storage is encrypted at restHIGH
rds_instance_transport_encryptedRDS instance or cluster enforces SSL/TLS encryption for client connectionsHIGH
rds_snapshots_encryptedRDS DB instance snapshot or DB cluster snapshot is encryptedHIGH
rds_snapshots_public_accessRDS snapshot is not publicly sharedCRITICAL

redshift

10 checks.
Check IDTitleSeverity
redshift_cluster_audit_loggingRedshift cluster has audit logging enabledMEDIUM
redshift_cluster_automated_snapshotRedshift cluster has automated snapshots enabledHIGH
redshift_cluster_automatic_upgradesRedshift cluster has automatic version upgrade enabledMEDIUM
redshift_cluster_encrypted_at_restRedshift cluster is encrypted at restCRITICAL
redshift_cluster_enhanced_vpc_routingRedshift cluster has Enhanced VPC Routing enabledMEDIUM
redshift_cluster_in_transit_encryption_enabledRedshift cluster is encrypted in transitHIGH
redshift_cluster_multi_az_enabledRedshift cluster has Multi-AZ enabledMEDIUM
redshift_cluster_non_default_database_nameRedshift cluster does not use the default database name devLOW
redshift_cluster_non_default_usernameAmazon Redshift cluster does not use the default admin usernameMEDIUM
redshift_cluster_public_accessRedshift cluster is not publicly exposed to the InternetCRITICAL

resourceexplorer2

1 checks.
Check IDTitleSeverity
resourceexplorer2_indexes_foundResource Explorer indexes existLOW

route53

4 checks.
Check IDTitleSeverity
route53_dangling_ip_subdomain_takeoverRoute53 A record does not point to a dangling IP addressHIGH
route53_domains_privacy_protection_enabledRoute 53 domain has admin contact privacy protection enabledMEDIUM
route53_domains_transferlock_enabledRoute 53 domain has Transfer Lock enabledHIGH
route53_public_hosted_zones_cloudwatch_logging_enabledRoute53 public hosted zone has query logging enabled to a CloudWatch Logs log groupMEDIUM

s3

21 checks.
Check IDTitleSeverity
s3_access_point_public_access_blockS3 access point has all Block Public Access settings enabledCRITICAL
s3_account_level_public_access_blocksS3 account-level Block Public Access ignores public ACLs and restricts public bucketsHIGH
s3_bucket_acl_prohibitedS3 bucket has bucket ACLs disabledMEDIUM
s3_bucket_cross_account_accessS3 bucket policy does not allow cross-account accessHIGH
s3_bucket_cross_region_replicationS3 bucket has cross-region replication configured to a bucket in a different regionLOW
s3_bucket_default_encryptionS3 bucket has default server-side encryption (SSE) enabledMEDIUM
s3_bucket_event_notifications_enabledS3 bucket has event notifications enabledLOW
s3_bucket_kms_encryptionS3 bucket has server-side encryption with AWS KMSMEDIUM
s3_bucket_level_public_access_blockS3 bucket has Block Public Access with IgnorePublicAcls and RestrictPublicBuckets enabled at bucket or account…HIGH
s3_bucket_lifecycle_enabledS3 bucket has a lifecycle configuration enabledLOW
s3_bucket_no_mfa_deleteS3 bucket has MFA Delete enabledMEDIUM
s3_bucket_object_lockS3 bucket has Object Lock enabledLOW
s3_bucket_object_versioningS3 bucket has object versioning enabledMEDIUM
s3_bucket_policy_public_write_accessS3 bucket policy does not allow public write accessCRITICAL
s3_bucket_public_accessS3 bucket is not publicly accessible to Everyone or Authenticated UsersCRITICAL
s3_bucket_public_list_aclS3 bucket is not publicly listable by Everyone or any authenticated AWS userCRITICAL
s3_bucket_public_write_aclS3 bucket ACL does not grant write access to Everyone or any AWS customerCRITICAL
s3_bucket_secure_transport_policyS3 bucket policy denies requests over insecure transportMEDIUM
s3_bucket_server_access_logging_enabledS3 bucket has server access logging enabledMEDIUM
s3_bucket_shadow_resource_vulnerabilityS3 bucket is not a known shadow resource owned by another accountHIGH
s3_multi_region_access_point_public_access_blockS3 Multi-Region Access Point has all Block Public Access settings enabledHIGH

sagemaker

11 checks.
Check IDTitleSeverity
sagemaker_endpoint_config_prod_variant_instancesSageMaker endpoint configuration has all production variants with at least two initial instancesMEDIUM
sagemaker_models_network_isolation_enabledAmazon SageMaker model has network isolation enabledHIGH
sagemaker_models_vpc_settings_configuredAmazon SageMaker model has VPC settings enabledMEDIUM
sagemaker_notebook_instance_encryption_enabledSageMaker notebook instance is encrypted with a KMS keyHIGH
sagemaker_notebook_instance_root_access_disabledAmazon SageMaker notebook instance has root access disabledMEDIUM
sagemaker_notebook_instance_vpc_settings_configuredAmazon SageMaker notebook instance has VPC settings configuredHIGH
sagemaker_notebook_instance_without_direct_internet_access_configuredAmazon SageMaker notebook instance has direct internet access disabledHIGH
sagemaker_training_jobs_intercontainer_encryption_enabledAmazon SageMaker training job has inter-container traffic encryption enabledMEDIUM
sagemaker_training_jobs_network_isolation_enabledAmazon SageMaker training job has network isolation enabledHIGH
sagemaker_training_jobs_volume_and_output_encryption_enabledAmazon SageMaker training job volume has KMS encryption enabledHIGH
sagemaker_training_jobs_vpc_settings_configuredAmazon SageMaker training job has VPC configuration enabledHIGH

secretsmanager

5 checks.
Check IDTitleSeverity
secretsmanager_automatic_rotation_enabledSecrets Manager secret has rotation enabledHIGH
secretsmanager_has_restrictive_resource_policySecrets Manager secret has a restrictive resource-based policyHIGH
secretsmanager_not_publicly_accessibleSecrets Manager secret resource policy does not allow public accessHIGH
secretsmanager_secret_rotated_periodicallyAWS Secrets Manager secret is rotated within the configured maximum number of daysMEDIUM
secretsmanager_secret_unusedSecrets Manager secret has been accessed within the last 90 daysMEDIUM

securityhub

1 checks.
Check IDTitleSeverity
securityhub_enabledSecurity Hub is enabled with standards or integrations configuredHIGH

servicecatalog

1 checks.
Check IDTitleSeverity
servicecatalog_portfolio_shared_within_organization_onlyService Catalog portfolio is shared only within the AWS OrganizationHIGH

ses

1 checks.
Check IDTitleSeverity
ses_identity_not_publicly_accessibleSES identity resource policy does not allow public accessHIGH

shield

6 checks.
Check IDTitleSeverity
shield_advanced_protection_in_associated_elastic_ipsElastic IP address is protected by AWS Shield AdvancedMEDIUM
shield_advanced_protection_in_classic_load_balancersClassic Load Balancer is protected by AWS Shield AdvancedMEDIUM
shield_advanced_protection_in_cloudfront_distributionsCloudFront distribution is protected by AWS Shield AdvancedMEDIUM
shield_advanced_protection_in_global_acceleratorsGlobal Accelerator accelerator is protected by AWS Shield AdvancedMEDIUM
shield_advanced_protection_in_internet_facing_load_balancersInternet-facing Application Load Balancer is protected by AWS Shield AdvancedMEDIUM
shield_advanced_protection_in_route53_hosted_zonesRoute53 hosted zone is protected by AWS Shield AdvancedMEDIUM

sns

3 checks.
Check IDTitleSeverity
sns_subscription_not_using_http_endpointsSNS subscription uses an HTTPS endpointHIGH
sns_topics_kms_encryption_at_rest_enabledSNS topic is encrypted at rest with KMSHIGH
sns_topics_not_publicly_accessibleSNS topic is not publicly accessibleHIGH

sqs

2 checks.
Check IDTitleSeverity
sqs_queues_not_publicly_accessibleSQS queue policy does not allow public accessCRITICAL
sqs_queues_server_side_encryption_enabledSQS queue has server-side encryption enabledMEDIUM

ssm

3 checks.
Check IDTitleSeverity
ssm_document_secretsSSM document contains no secretsHIGH
ssm_documents_set_as_publicSSM document is not public and shared only with trusted AWS accountsHIGH
ssm_managed_compliant_patchingEC2 managed instance is compliant with Systems Manager patching requirementsHIGH

ssmincidents

1 checks.
Check IDTitleSeverity
ssmincidents_enabled_with_plansSSM Incidents replication set is ACTIVE and has at least one response planMEDIUM

stepfunctions

2 checks.
Check IDTitleSeverity
stepfunctions_statemachine_logging_enabledStep Functions state machine has logging enabledMEDIUM
stepfunctions_statemachine_no_secrets_in_definitionStep Functions state machine has no sensitive credentials in its definitionCRITICAL

storagegateway

2 checks.
Check IDTitleSeverity
storagegateway_fileshare_encryption_enabledStorage Gateway file share is encrypted with KMS CMKMEDIUM
storagegateway_gateway_fault_tolerantAWS Storage Gateway gateway is not hosted on EC2MEDIUM

transfer

1 checks.
Check IDTitleSeverity
transfer_server_in_transit_encryption_enabledTransfer Family server has encryption in transit enabledHIGH

trustedadvisor

2 checks.
Check IDTitleSeverity
trustedadvisor_errors_and_warningsTrusted Advisor check has no errors or warningsMEDIUM
trustedadvisor_premium_support_plan_subscribedAWS account is subscribed to an AWS Premium Support planLOW

vpc

11 checks.
Check IDTitleSeverity
vpc_different_regionsVPCs are present in more than one regionMEDIUM
vpc_endpoint_connections_trust_boundariesVPC endpoint policy allows access only from trusted AWS accountsHIGH
vpc_endpoint_for_ec2_enabledVPC has an Amazon EC2 VPC endpointMEDIUM
vpc_endpoint_multi_az_enabledAmazon VPC interface endpoint has subnets in multiple Availability ZonesMEDIUM
vpc_endpoint_services_allowed_principals_trust_boundariesVPC endpoint service allows only trusted principals or noneHIGH
vpc_flow_logs_enabledVPC flow logs are enabledMEDIUM
vpc_peering_routing_tables_with_least_privilegeVPC peering connection route tables do not include 0.0.0.0/0 or entire requester/accepter VPC CIDR routesMEDIUM
vpc_subnet_different_azVPC has subnets in more than one Availability ZoneMEDIUM
vpc_subnet_no_public_ip_by_defaultVPC subnet does not assign public IP addresses by defaultHIGH
vpc_subnet_separate_private_publicVPC has both public and private subnetsMEDIUM
vpc_vpn_connection_tunnels_upAWS Site-to-Site VPN connection has both tunnels upMEDIUM

waf

7 checks.
Check IDTitleSeverity
waf_global_rule_with_conditionsAWS WAF Classic Global rule has at least one conditionMEDIUM
waf_global_rulegroup_not_emptyAWS WAF Classic global rule group has at least one ruleHIGH
waf_global_webacl_logging_enabledAWS WAF Classic Global Web ACL has logging enabledMEDIUM
waf_global_webacl_with_rulesAWS WAF Classic global Web ACL has at least one rule or rule groupMEDIUM
waf_regional_rule_with_conditionsAWS WAF Classic Regional rule has at least one conditionMEDIUM
waf_regional_rulegroup_not_emptyAWS WAF Classic Regional rule group has at least one ruleMEDIUM
waf_regional_webacl_with_rulesAWS WAF Classic Regional Web ACL has at least one rule or rule groupMEDIUM

wafv2

3 checks.
Check IDTitleSeverity
wafv2_webacl_logging_enabledAWS WAFv2 Web ACL has logging enabledMEDIUM
wafv2_webacl_rule_logging_enabledAWS WAFv2 Web ACL has Amazon CloudWatch metrics enabled for all rules and rule groupsMEDIUM
wafv2_webacl_with_rulesAWS WAFv2 Web ACL has at least one rule or rule group attachedHIGH

wellarchitected

1 checks.
Check IDTitleSeverity
wellarchitected_workload_no_high_or_medium_risksAWS Well-Architected Tool workload has no high or medium risksMEDIUM

workspaces

2 checks.
Check IDTitleSeverity
workspaces_volume_encryption_enabledAmazon WorkSpaces workspace root and user volumes are encryptedHIGH
workspaces_vpc_2private_1public_subnets_natWorkspace is in a private subnet and its VPC has at least 1 public subnet, 2 private subnets, and a NAT Gatewa…HIGH

What’s next

Cloud Security overview

Connect a provider, see findings end-to-end.

All checks

Index across every provider.

Compliance frameworks

How check IDs map to SOC 2 / PCI / HIPAA / ISO controls.

Reports

Per-framework PDF scorecards.