AWS New Checks

Ensure no security groups allow ingress from 0.0.0.0/0 or ::/0 to Kafka port 9092.
Profile Applicability: Level 1 Description: Apache Kafka is a distributed streaming platform that requires secure network configurations to ensure that...
Tue, 1 Apr, 2025 at 12:40 AM
Find secrets in EC2 Launch Template
Profile Applicability: Level 1 Description: An EC2 Launch Template is a resource in AWS that defines configurations to launch EC2 instances, including ...
Tue, 1 Apr, 2025 at 1:55 AM
Check if EC2 instances have detailed monitoring enabled.
Profile Applicability: Level 1 Description: Amazon EC2 provides two levels of monitoring: Basic Monitoring and Detailed Monitoring. By default, EC2 ins...
Tue, 1 Apr, 2025 at 2:10 AM
Ensure that your Amazon RDS clusters are not using the default master username
Profile Applicability: Level 2 Description: When creating an Amazon RDS database instance, AWS automatically assigns a default master username (usually...
Tue, 1 Apr, 2025 at 2:32 AM
Check if RDS clusters have deletion protection enabled
Profile Applicability: Level 2 Description: Amazon RDS provides deletion protection for database clusters to safeguard against accidental deletion of c...
Tue, 1 Apr, 2025 at 2:39 AM
Ensure RDS clusters have minor version upgrade enabled
Profile Applicability: Level 2 Description: Amazon RDS offers minor version upgrades for supported database engines. Minor version upgrades typically i...
Tue, 1 Apr, 2025 at 2:45 AM
Check if RDS clusters have IAM authentication enabled
Profile Applicability: Level 2 Description: Amazon RDS allows for IAM (Identity and Access Management) authentication, which provides a more secure way...
Tue, 1 Apr, 2025 at 2:51 AM
Check if RDS instances have multi-AZ enabled
Profile Applicability: Level 2 Description: Amazon RDS (Relational Database Service) offers the ability to deploy instances in Multi-AZ (Availability Z...
Tue, 1 Apr, 2025 at 2:57 AM
Check if RDS instance is using a supported engine version
Profile Applicability: Level 1 Description: Amazon RDS supports several database engines such as MySQL, PostgreSQL, MariaDB, Oracle, SQL Server, and Au...
Tue, 1 Apr, 2025 at 3:03 AM
Check if RDS instances enforce SSL/TLS encryption for client connections (Microsoft SQL Server, PostgreSQL, MySQL, MariaDB, Aurora PostgreSQL, and Aurora MySQL)
Profile Applicability: Level 2 Description: Amazon RDS allows database instances to enforce SSL/TLS encryption for all client connections, ensuring tha...
Tue, 1 Apr, 2025 at 3:09 AM