AWS New Checks

Check if Application Load Balancer Has a WAF Web ACL Attached
Profile Applicability: Level 1 Description: AWS Application Load Balancer (ALB) is a fully managed load balancing service that automatically distribute...
Tue, 25 Mar, 2025 at 6:09 AM
Ensure CloudFront Distributions Encrypt Traffic to Custom Origins
 Profile Applicability: Level 1 Description: Amazon CloudFront is a content delivery network (CDN) that can distribute content from multiple types of or...
Tue, 25 Mar, 2025 at 6:16 AM
Check if the Application Load Balancer is Configured with Strictest Desync Mitigation Mode
Profile Applicability: Level 2 Description: Amazon Application Load Balancer (ALB) provides a highly available and scalable load balancing service for ...
Tue, 25 Mar, 2025 at 6:17 AM
Ensure Cross-Zone Load Balancing is Enabled for Network Load Balancers (NLBs) and Gateway Load Balancers (GWLB)
Profile Applicability: Level 1 Description: For Network Load Balancers (NLBs) and Gateway Load Balancers (GWLBs), enabling Cross-Zone Load Balancing en...
Tue, 25 Mar, 2025 at 6:27 AM
Ensure AWS KMS Keys Are Not Deleted Unintentionally
Profile Applicability: Level 2 Description: Amazon Key Management Service (KMS) provides a centralized way to create and manage encryption keys. Deleti...
Tue, 25 Mar, 2025 at 6:34 AM
Ensure No Security Groups Allow Ingress from 0.0.0.0/0 or ::/0 to Elasticsearch/Kibana Ports
Profile Applicability: Level 1 Description: Elasticsearch and Kibana are commonly used for log management, search, and analytics. These services, however...
Tue, 25 Mar, 2025 at 6:39 AM
Check if There Are Unused KMS Customer Managed Keys (CMKs)
Profile Applicability: Level 2 Description: AWS Key Management Service (KMS) allows the creation of Customer Managed Keys (CMKs) to encrypt and secure ...
Tue, 25 Mar, 2025 at 6:42 AM
Ensure AWS KMS Customer Managed Keys Are Not Multi-Region
Profile Applicability: Level 2 Description: AWS KMS (Key Management Service) allows you to create customer managed keys (CMKs) for encrypting data. Mul...
Tue, 25 Mar, 2025 at 6:49 AM
Ensure No EC2 Instances Allow Ingress from the Internet to TCP Port 389 or 636
Profile Applicability:  Level 2 Description LDAP (Lightweight Directory Access Protocol) uses TCP ports 389 (unencrypted) and 636 (encrypted). Allowing i...
Tue, 25 Mar, 2025 at 7:03 AM
Ensure Public Access to EBS Snapshots Is Disabled
Profile Applicability:  Level 2 Description Amazon Elastic Block Store (EBS) snapshots are used to back up EBS volumes, providing a reliable mechanism fo...
Tue, 25 Mar, 2025 at 7:14 AM