AWS New Checks

Ensure SNS Subscriptions Do Not Use HTTP Endpoints
Profile Applicability Level 2 Description Amazon SNS supports HTTP and HTTPS endpoints for delivering messages. However, HTTP endpoints transmit data i...
Wed, 26 Mar, 2025 at 2:36 AM
Ensure SNS Topics Are Encrypted
Profile Applicability Level 2 Description Amazon SNS supports server-side encryption (SSE) to protect the contents of messages using AWS Key Management...
Wed, 26 Mar, 2025 at 2:42 AM
Ensure No EC2 Instances Allow Ingress from the Internet to TCP Ports 1433 or 1434 (SQL Server)
Profile Applicability:  Level 2 Description TCP ports 1433 and 1434 are used for Microsoft SQL Server database communications. Allowing unrestricted inbo...
Wed, 26 Mar, 2025 at 2:48 AM
Ensure Kafka Cluster Has Unrestricted Access Disabled
Profile Applicability Level 2 Description Unrestricted access to Kafka clusters, allowing connections from 0.0.0.0/0 (IPv4) or ::/0 (IPv6), poses a sig...
Wed, 26 Mar, 2025 at 2:48 AM
Ensure RADIUS Server in Directory Service Uses the Recommended Security Protocol
Profile Applicability: Level 1 Description: Amazon Directory Service (DS) provides managed directory services, such as AWS Managed Microsoft AD and S...
Wed, 26 Mar, 2025 at 2:49 AM
Ensure Kafka Cluster Encryption in Transit Is Enabled
Profile Applicability Level 2 Description Encryption in transit ensures that all communication between Kafka clients, brokers, and ZooKeeper nodes is p...
Wed, 26 Mar, 2025 at 2:53 AM
Ensure Mutual TLS Authentication Is Enabled for Kafka Clusters
Profile Applicability Level 2 Description  Mutual TLS (mTLS) authentication ensures that both the client and the server authenticate each other during ...
Wed, 26 Mar, 2025 at 2:58 AM
Ensure Kafka Clusters Are Not Exposed to the Public
Profile Applicability Level 2 Description Exposing Kafka clusters to the public internet can lead to unauthorized access, data breaches, and potential ...
Wed, 26 Mar, 2025 at 3:03 AM
Ensure Directory Service LDAP Certificates Expiration Is Monitored and Managed
Profile Applicability: Level 1 Description: Amazon Directory Service enables you to use managed Active Directory (AD) on AWS, and for some directory ...
Wed, 26 Mar, 2025 at 3:03 AM
Ensure MSK Connect Connectors Are Encrypted in Transit
Profile Applicability Level 2 Description Encryption in transit ensures that data exchanged between MSK Connect connectors and Kafka clusters is protec...
Wed, 26 Mar, 2025 at 3:09 AM