AWS New Checks

Ensure User Maximum Session Duration is No Longer than 10 Hours
Profile Applicability: Level 1 Description: In AWS Identity and Access Management (IAM), session duration defines the maximum amount of time a user ses...
Wed, 26 Mar, 2025 at 12:32 AM
Ensure that Your AWS EventBridge Event Bus is Not Exposed to Everyone
Profile Applicability: Level 1 Description: Amazon EventBridge is a serverless event bus service that enables you to easily connect different applicati...
Wed, 26 Mar, 2025 at 12:39 AM
Ensure EventBridge Event Buses Do Not Allow Unknown Cross-Account Access
Profile Applicability Level 2 Description Amazon EventBridge event buses can be configured to allow cross-account access for event delivery. However, u...
Wed, 26 Mar, 2025 at 12:45 AM
Ensure EventBridge Event Buses Do Not Allow Unknown Cross-Account Access
Profile Applicability Level 2 Description Amazon EventBridge event buses can be configured to allow cross-account access for event delivery. However, u...
Wed, 26 Mar, 2025 at 12:50 AM
Ensure EventBridge Global Endpoints Have Event Replication Enabled
Profile Applicability: Level 2 Description: Amazon EventBridge provides a globally distributed event bus service that enables applications to respond to...
Mon, 26 May, 2025 at 4:15 AM
Ensure Security Hub Is Enabled and Its Standard Subscriptions Are Configured
Profile Applicability Level 2 Description AWS Security Hub provides a comprehensive view of your security posture across AWS accounts and services. It ...
Wed, 26 Mar, 2025 at 1:04 AM
Ensure No Security Groups Allow Ingress from 0.0.0.0/0 or ::/0 to Telnet Port 23
Profile Applicability:  Level 2 Description Telnet, which uses TCP port 23, is an outdated protocol with known vulnerabilities as it transmits data, incl...
Wed, 26 Mar, 2025 at 1:08 AM
Ensure EC2 Client VPN Endpoints Have Client Connection Logging Enabled
Profile Applicability:  Level 2 Description Client connection logging captures important information about client connections, such as connection attempt...
Wed, 26 Mar, 2025 at 1:14 AM
Ensure Amazon EC2 Paravirtual Virtualization Type Is Not Used
Profile Applicability:  Level 2 Description The paravirtual (PV) virtualization type is an older virtualization technology that lacks modern performance ...
Wed, 26 Mar, 2025 at 1:44 AM
Ensure No EC2 Instances Allow Ingress from the Internet to TCP Port 22(SSH)
Profile Applicability:  Level 2 Description TCP port 22 is used for SSH access, which is a critical management port for EC2 instances. Allowing unrestric...
Wed, 26 Mar, 2025 at 1:51 AM