AWS New Checks

Ensure User Maximum Session Duration is No Longer than 10 Hours
Profile Applicability: Level 1 Description: In AWS Identity and Access Management (IAM), session duration defines the maximum amount of time a user ses...
Tue, 9 Sep, 2025 at 2:29 AM
Ensure that Your AWS EventBridge Event Bus is Not Exposed to Everyone
Profile Applicability: Level 1 Description: Amazon EventBridge is a serverless event bus service that enables you to easily connect different applicati...
Thu, 11 Sep, 2025 at 4:07 AM
Ensure EventBridge Event Buses Do Not Allow Unknown Cross-Account Access
Profile Applicability Level 2 Description Amazon EventBridge event buses can be configured to allow cross-account access for event delivery. However, u...
Thu, 11 Sep, 2025 at 4:02 AM
Ensure EventBridge Event Buses Do Not Allow Unknown Cross-Account Access
Profile Applicability Level 2 Description Amazon EventBridge event buses can be configured to allow cross-account access for event delivery. However, u...
Tue, 9 Sep, 2025 at 2:21 AM
Ensure EventBridge Global Endpoints Have Event Replication Enabled
Profile Applicability: Level 2 Description: Amazon EventBridge provides a globally distributed event bus service that enables applications to respond to...
Tue, 9 Sep, 2025 at 2:12 AM
Ensure Security Hub Is Enabled and Its Standard Subscriptions Are Configured
Profile Applicability Level 2 Description AWS Security Hub provides a comprehensive view of your security posture across AWS accounts and services. It ...
Thu, 11 Sep, 2025 at 3:35 AM
Ensure No Security Groups Allow Ingress from 0.0.0.0/0 or ::/0 to Telnet Port 23
Profile Applicability:  Level 2 Description Telnet, which uses TCP port 23, is an outdated protocol with known vulnerabilities as it transmits data, incl...
Wed, 10 Sep, 2025 at 2:48 AM
Ensure EC2 Client VPN Endpoints Have Client Connection Logging Enabled
Profile Applicability:  Level 2 Description Client connection logging captures important information about client connections, such as connection attempt...
Wed, 10 Sep, 2025 at 2:59 AM
Ensure Amazon EC2 Paravirtual Virtualization Type Is Not Used
Profile Applicability:  Level 2 Description The paravirtual (PV) virtualization type is an older virtualization technology that lacks modern performance ...
Wed, 10 Sep, 2025 at 3:15 AM
Ensure No EC2 Instances Allow Ingress from the Internet to TCP Port 22(SSH)
Profile Applicability:  Level 2 Description TCP port 22 is used for SSH access, which is a critical management port for EC2 instances. Allowing unrestric...
Wed, 10 Sep, 2025 at 3:21 AM