AWS New Checks

Ensure RDS Cluster critical events are subscribed
Profile Applicability: Level 1 Description: Amazon RDS (Relational Database Service) provides various event notifications for RDS clusters, including c...
Fri, 23 May, 2025 at 6:44 AM
Ensure Elastic and Public IPs Are Not Indexed in Shodan
Profile Applicability: Level 1 Description: Shodan is a search engine that allows users to search for devices and systems exposed to the internet, incl...
Fri, 23 May, 2025 at 3:49 AM
Ensure that the SSL/TLS certificates configured for your Amazon RDS are not expired
Profile Applicability: Level 2 Description: Amazon RDS (Relational Database Service) supports SSL/TLS encryption to secure data in transit between RDS ...
Tue, 1 Apr, 2025 at 7:07 AM
Ensure that SES identities are not publicly accessible
Profile Applicability: Level 1 Description: Amazon Simple Email Service (SES) is a fully managed email sending service that allows you to send and rece...
Tue, 1 Apr, 2025 at 7:13 AM
Ensure Step Functions state machines should have logging enabled
Profile Applicability: Level 1 Description: AWS Step Functions is a service that enables you to coordinate multiple AWS services into serverless workfl...
Fri, 23 May, 2025 at 6:43 AM
Ensure Security Groups Created by EC2 Launch Wizard Follow Least Privilege Principles
Profile Applicability: Level 1 Description: When launching an EC2 instance using the EC2 Launch Wizard (e.g., via the AWS Management Console), Security...
Fri, 23 May, 2025 at 3:46 AM
Ensure Public Lambda Function URL
Profile Applicability: Level 1 Description: AWS Lambda allows you to create Function URLs, which can be used to invoke your Lambda functions directly o...
Fri, 23 May, 2025 at 6:41 AM
Ensure Instance Metadata Service Version 2 (IMDSv2) is enforced for EC2 instances at the account level to protect against SSRF vulnerabilities.
Profile Applicability: Level 1 Description: The Instance Metadata Service (IMDS) provides information about the EC2 instance such as instance ID, secur...
Tue, 1 Apr, 2025 at 7:31 AM
Ensure Lambda Function URL CORS configuration
Profile Applicability: Level 2 Description: Lambda Function URLs are a feature of AWS Lambda that allows you to invoke Lambda functions over HTTP(S) us...
Fri, 23 May, 2025 at 6:40 AM
Ensure no security groups allow ingress from 0.0.0.0/0 or ::/0 to MySQL port 3306.
Profile Applicability: Level 1 Description: MySQL typically uses TCP port 3306 for client connections. Allowing unrestricted access to port 3306 from t...
Tue, 1 Apr, 2025 at 7:39 AM