AWS New Checks

Ensure No Security Groups Allow Ingress from 0.0.0.0/0 or ::/0 to Postgres Port 5432
Profile Applicability:  Level 2 Description PostgreSQL database servers use TCP port 5432 to accept connections. Allowing unrestricted access to this por...
Wed, 26 Mar, 2025 at 2:00 AM
Find Secrets in SSM Documents
Profile Applicability Level 2 Description Secrets embedded in SSM documents, such as credentials, API keys, or sensitive configuration data, can pose...
Wed, 26 Mar, 2025 at 2:17 AM
Ensure SSM Documents Are Not Set as Public
Profile Applicability Level 2 Description AWS Systems Manager (SSM) documents define the actions that Systems Manager performs on managed instances. Pu...
Wed, 26 Mar, 2025 at 2:23 AM
Ensure EC2 Instances Managed by Systems Manager Are Compliant with Patching Requirements
Profile Applicability Level 2 Description AWS Systems Manager Patch Manager automates the process of scanning and patching managed EC2 instances. It en...
Wed, 26 Mar, 2025 at 2:30 AM
Ensure EC2 Instances Are Managed by Systems Manager
Profile Applicability:  Level 2 Description AWS Systems Manager provides a unified interface to manage your EC2 instances efficiently and securely. It en...
Wed, 26 Mar, 2025 at 2:32 AM
Ensure SNS Subscriptions Do Not Use HTTP Endpoints
Profile Applicability Level 2 Description Amazon SNS supports HTTP and HTTPS endpoints for delivering messages. However, HTTP endpoints transmit data i...
Wed, 26 Mar, 2025 at 2:36 AM
Ensure SNS Topics Are Encrypted
Profile Applicability Level 2 Description Amazon SNS supports server-side encryption (SSE) to protect the contents of messages using AWS Key Management...
Wed, 26 Mar, 2025 at 2:42 AM
Ensure No EC2 Instances Allow Ingress from the Internet to TCP Ports 1433 or 1434 (SQL Server)
Profile Applicability:  Level 2 Description TCP ports 1433 and 1434 are used for Microsoft SQL Server database communications. Allowing unrestricted inbo...
Wed, 26 Mar, 2025 at 2:48 AM
Ensure Kafka Cluster Has Unrestricted Access Disabled
Profile Applicability Level 2 Description Unrestricted access to Kafka clusters, allowing connections from 0.0.0.0/0 (IPv4) or ::/0 (IPv6), poses a sig...
Wed, 26 Mar, 2025 at 2:48 AM
Ensure RADIUS Server in Directory Service Uses the Recommended Security Protocol
Profile Applicability: Level 1 Description: Amazon Directory Service (DS) provides managed directory services, such as AWS Managed Microsoft AD and S...
Wed, 26 Mar, 2025 at 2:49 AM