AWS New Checks

Ensure No Security Groups Allow Ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana Ports
Profile Applicability: Level 1 Description: Elasticsearch and Kibana are commonly used for log management, search, and analytics. These services, however...
Tue, 25 Mar, 2025 at 6:39 AM
Check if There Are Unused KMS Customer Managed Keys (CMKs)
Profile Applicability: Level 2 Description: AWS Key Management Service (KMS) allows the creation of Customer Managed Keys (CMKs) to encrypt and secure ...
Tue, 25 Mar, 2025 at 6:42 AM
Ensure AWS KMS Customer Managed Keys Are Not Multi-Region
Profile Applicability: Level 2 Description: AWS KMS (Key Management Service) allows you to create customer managed keys (CMKs) for encrypting data. Mul...
Tue, 25 Mar, 2025 at 6:49 AM
Ensure No EC2 Instances Allow Ingress from the Internet to TCP Port 389 or 636
Profile Applicability:  Level 2 Description LDAP (Lightweight Directory Access Protocol) uses TCP ports 389 (unencrypted) and 636 (encrypted). Allowing i...
Tue, 25 Mar, 2025 at 7:03 AM
Ensure Public Access to EBS Snapshots Is Disabled
Profile Applicability:  Level 2 Description Amazon Elastic Block Store (EBS) snapshots are used to back up EBS volumes, providing a reliable mechanism fo...
Tue, 25 Mar, 2025 at 7:14 AM
Ensure Amazon Elasticsearch/OpenSearch Service Domains Should Have HTTPS Enforcement Enabled
Profile Applicability: Level 1 Description: Amazon Elasticsearch Service (Amazon OpenSearch Service) provides a scalable search and analytics service...
Fri, 23 May, 2025 at 3:45 AM
Ensure AWS Storage Gateway File Shares Are Encrypted with KMS CMK
Profile Applicability: Level 1 Description: AWS Storage Gateway provides hybrid cloud storage, enabling on-premises applications to connect to cloud st...
Fri, 23 May, 2025 at 9:34 AM
Ensure Directory Service Monitoring with CloudWatch Logs
Profile Applicability: Level 1 Description: Amazon Directory Service allows you to set up and manage directories in the cloud, enabling AWS resources...
Fri, 23 May, 2025 at 3:38 AM
Ensure AWS Storage Gateway Gateways Are Hosted in a Fault-Tolerant Environment
Profile Applicability: Level 1 Description: AWS Storage Gateway is a hybrid cloud storage service that enables on-premises applications to securely acc...
Fri, 23 May, 2025 at 9:36 AM
Ensure Sensitive Information Filters are Configured for Amazon Bedrock Guardrails
Profile Applicability: Level 2 Description: Amazon Bedrock provides a platform for building generative AI applications. One of the key features is the ...
Mon, 26 May, 2025 at 4:22 AM