AWS New Checks

Ensure Logging Is Enabled for DMS Replication Tasks (Source Database)
Profile Applicability Level 2 Description AWS Database Migration Service (DMS) replication tasks can log activity and diagnostic information for the so...
Mon, 24 Mar, 2025 at 4:17 AM
Ensure ECS task definitions shouldn't have privileged containers
Profile Applicability: Level 1 Description: In Amazon ECS, task definitions specify how containers should be run within ECS clusters. By default, ECS...
Fri, 23 May, 2025 at 5:12 AM
Ensure DMS Instances Are Not Publicly Accessible
Profile Applicability Level 2 Description Publicly accessible DMS replication instances can expose your data to unauthorized access over the internet, ...
Mon, 24 Mar, 2025 at 4:29 AM
Ensure ECS containers should be limited to read-only access to root filesystems
Profile Applicability: Level 1 Description: Amazon ECS allows you to run Docker containers within a Cluster using task definitions. The root filesyst...
Fri, 23 May, 2025 at 5:10 AM
Ensure Encryption in Transit for DMS Endpoints for Redis OSS
Profile Applicability Level 2 Description Encryption in transit ensures that data moving between AWS Database Migration Service (DMS) and Redis OSS end...
Mon, 24 Mar, 2025 at 4:37 AM
Ensure Auto Minor Version Upgrade Is Enabled for DMS Instances
Profile Applicability Level 2 Description The Auto Minor Version Upgrade feature for AWS Database Migration Service (DMS) replication instances ensures...
Mon, 24 Mar, 2025 at 4:44 AM
Ensure ECS Task Sets Do Not Automatically Assign Public IP Addresses
Profile Applicability: Level 1 Description: In Amazon ECS, task sets are used to manage ECS tasks in a Service deployment. By default, ECS tasks may ...
Mon, 24 Mar, 2025 at 4:45 AM
Ensure S3 Glacier vaults have policies which allow access to everyone.
Profile Applicability: Level 1 Description: Amazon S3 Glacier is a storage class designed for data archiving and long-term backup. S3 Glacier Vaults ar...
Fri, 23 May, 2025 at 2:44 AM
Ensure the S3 bucket CloudTrail bucket requires MFA delete.
Profile Applicability: Level 1 Description: Amazon S3 is a scalable object storage service that is often used to store CloudTrail logs for auditing and...
Mon, 24 Mar, 2025 at 5:54 AM
Ensure there are no potential enumeration threats in CloudTrail.
Profile Applicability: Level 1 Description: AWS CloudTrail is a service that records API calls made on your AWS account, capturing detailed information...
Mon, 24 Mar, 2025 at 6:11 AM