This check examines Amazon Machine Images (AMIs) owned by your AWS account and flags any that are publicly…
Your AWS Client VPN endpoints have connection logging enabled. Client VPN endpoints allow remote users to…
Your AWS account has EBS (Elastic Block Store) encryption enabled by default. When enabled, all newly…
Amazon EBS snapshots that have public sharing permissions, making them accessible to all AWS accounts. EBS…
Your AWS account has "Block Public Access" enabled for EBS snapshots with the block-all-sharing setting…
Your Amazon EBS snapshots are encrypted at rest using AWS KMS. EBS snapshots are point-in-time copies of…
Your Amazon EBS (Elastic Block Store) volumes have encryption enabled. EBS volumes store data for your EC2…
Your Amazon EBS volumes are included in an AWS Backup plan. AWS Backup provides a centralized way to…
Each Amazon EBS (Elastic Block Store) volume has at least one snapshot. Snapshots are point-in-time…
EC2 Elastic IP addresses that appear in Shodan, a search engine that indexes internet-connected devices…
Elastic IP addresses that are allocated to your AWS account but not associated with any EC2 instance or…
Your AWS account is configured to require Instance Metadata Service Version 2 (IMDSv2) by default for all…
Your EC2 instances have CloudWatch detailed monitoring enabled. With detailed monitoring, CloudWatch…
Your EC2 instances require IMDSv2 (Instance Metadata Service version 2) or have the metadata service…
EC2 instances that have both a public IP address and an attached instance profile (IAM role). When an…
Your EC2 instances are enrolled as AWS Systems Manager (SSM) managed nodes. When an instance is managed by…
Running EC2 instances that have been active longer than a configurable threshold (default: 180 days)…
EC2 instances using the older paravirtual virtualization type instead of the modern HVM (Hardware Virtual…
EC2 instances that have Cassandra database ports accessible from the internet through their security group…
EC2 instances with security groups that allow inbound traffic on TCP ports 139 or 445 (CIFS/SMB) from…
EC2 instances that allow inbound traffic from the internet on Elasticsearch and Kibana ports (TCP 9200…
EC2 instances with security groups that allow inbound FTP traffic (TCP ports 20 and 21) from the internet…
EC2 instances with security group rules that allow inbound traffic on TCP port 9092 (Kafka) from the…
EC2 security groups that allow public inbound access to Kerberos authentication ports (TCP 88, 464, 749…
EC2 instances that have LDAP (Lightweight Directory Access Protocol) ports accessible from the internet…
EC2 instances that allow inbound traffic on TCP port 11211 (Memcached) from anywhere on the internet…
EC2 instances with security groups that allow inbound traffic from the internet (0.0.0.0/0 or ::/0) on TCP…
EC2 instances with security groups that expose MySQL (TCP port 3306) to the entire internet. MySQL is a…
EC2 instances with security groups that allow inbound traffic from the internet (0.0.0.0/0 or ::/0) to…
Your EC2 instances do not have security group rules allowing inbound PostgreSQL traffic (TCP port 5432)…
EC2 instances whose security groups allow unrestricted Remote Desktop Protocol (RDP) traffic on TCP port…
EC2 instances with security groups that allow unrestricted internet access to Redis on TCP port 6379…
EC2 instances whose security groups allow unrestricted inbound traffic on TCP ports 1433 or 1434 from the…
EC2 instances that have SSH (TCP port 22) exposed to the entire internet through their security group…
EC2 instances with security groups that allow inbound Telnet traffic (TCP port 23) from the internet…
EC2 instances have an IAM instance profile attached. Instance profiles allow applications running on EC2…
EC2 instances that have a public IPv4 address assigned. Public IPs make instances directly accessible from…
This check inspects EC2 instance User Data for secret-like values including credentials, tokens, API keys…
Your EC2 instances use only a single Elastic Network Interface (ENI). While AWS allows attaching multiple…
EC2 instances running on deprecated or outdated Amazon Machine Images (AMIs). AWS marks AMIs as deprecated…
Your EC2 launch templates enforce Instance Metadata Service Version 2 (IMDSv2). IMDSv2 adds a…
Your EC2 launch templates do not automatically assign public IP addresses to network interfaces. Launch…
This check scans all versions of your EC2 launch templates for secrets embedded in User Data. User Data is…
Network Access Control Lists (NACLs) that have inbound rules allowing traffic from 0.0.0.0/0 (the entire…
Network Access Control Lists (NACLs) that have inbound rules allowing SSH traffic (TCP port 22) from…
Network Access Control Lists (NACLs) that have inbound rules allowing Remote Desktop Protocol (RDP)…
Non-default Network ACLs (NACLs) in your VPC that are not associated with any subnet. Removing unused…
EC2 security groups that have inbound rules allowing traffic from anywhere on the internet (0.0.0.0/0 or…
EC2 security groups that allow inbound traffic from the entire internet (0.0.0.0/0 or ::/0) to all ports…
EC2 security groups that allow inbound traffic from the entire internet (0.0.0.0/0 or ::/0) to high-risk…
Security groups that allow inbound SSH connections (TCP port 22) from anywhere on the internet (0.0.0.0/0…
Your EC2 security groups do not allow inbound Remote Desktop Protocol (RDP) traffic on TCP port 3389 from…
AWS security groups that allow unrestricted inbound TCP access from the internet (0.0.0.0/0 or ::/0) to…
Your EC2 security groups do not allow unrestricted internet access (from 0.0.0.0/0 or ::/0) to…
EC2 security groups that allow inbound FTP traffic (TCP ports 20 and 21) from anywhere on the internet…
Security groups that allow inbound traffic from the entire internet (0.0.0.0/0 or ::/0) to TCP port 9092…
EC2 security groups that allow inbound traffic from the entire internet (0.0.0.0/0 or ::/0) to TCP port…
EC2 security groups that allow inbound traffic from the entire internet (0.0.0.0/0 for IPv4 or ::/0 for…
EC2 security groups that allow inbound traffic from the entire internet (0.0.0.0/0 or ::/0) to MySQL…
EC2 security groups that allow inbound traffic from the entire internet (0.0.0.0/0 or ::/0) to Oracle…
EC2 security groups that allow inbound traffic from the internet (0.0.0.0/0 or ::/0) to PostgreSQL on TCP…
EC2 security groups that allow inbound traffic from the entire internet (0.0.0.0/0 or ::/0) to TCP port…
EC2 security groups that allow inbound traffic from the entire internet (0.0.0.0/0 or ::/0) to Microsoft…
EC2 security groups that allow inbound Telnet traffic (TCP port 23) from the internet (0.0.0.0/0 or ::/0)…
EC2 security groups that contain rules allowing traffic from overly broad public IPv4 address ranges…
The default security group in each of your VPCs has no inbound or outbound rules. Every VPC comes with a…
EC2 security groups whose names contain "launch-wizard," which indicates they were auto-generated by the…
Non-default EC2 security groups that are not attached to any resources. A security group is considered…
Your AWS security groups have a manageable number of rules. By default, it flags security groups with more…
Your AWS Transit Gateways do not automatically accept VPC attachment requests from other AWS accounts…