AWS New Checks

Ensure no EC2 instances allow ingress from the internet to TCP port 9092 (Kafka)
Profile Applicability: Level 1 Description: Apache Kafka commonly uses TCP port 9092 for client-broker communication. Allowing unrestricted internet ac...
Wed, 2 Apr, 2025 at 1:40 AM
Ensure EBS Snapshots Exist for EC2 Volumes
Profile Applicability: Level 1 Description: Amazon Elastic Block Store (EBS) allows you to create snapshots of your volumes, which are point-in-time co...
Fri, 23 May, 2025 at 3:25 AM
Ensure Amazon ECS task definitions should have secure networking modes and user definitions
Profile Applicability: Level 1 Description: Amazon ECS (Elastic Container Service) allows you to run containerized applications at scale. Networking mode...
Fri, 23 May, 2025 at 5:29 AM
Ensure centralized root credentials management is enabled
Profile Applicability: Level 1 Description: Centralized root credentials management involves controlling and managing root account access to your AWS e...
Wed, 2 Apr, 2025 at 2:54 AM
Ensure No IAM Groups Have Administrator Access Policy
Profile Applicability: Level 2 Description:  In AWS IAM, an Administrator Access Policy grants full access to all resources in an AWS account. This lev...
Wed, 2 Apr, 2025 at 2:59 AM
Ensure IAM Inline Policies That Allow Full ":" Administrative Privileges Are Not Associated to IAM Identities
Profile Applicability: Level 2 Description:  An IAM inline policy is a policy that is embedded directly into an IAM identity (user, group, or role). The...
Wed, 2 Apr, 2025 at 3:08 AM
Ensure IAM identities (users,groups,roles) have the AWSCloudShellFullAccess policy attached.
Profile Applicability: Level 1 Description: AWS CloudShell is a browser-based shell for managing AWS resources. It allows users to interact with AWS reso...
Fri, 23 May, 2025 at 5:31 AM
Ensure IAM Inline Policies That Allow Full "kms:*" Privileges Are Not Created
Profile Applicability: Level 2 Description: AWS Key Management Service (KMS) enables you to create and control the encryption keys used to encrypt your ...
Wed, 2 Apr, 2025 at 3:23 AM
Ensure IAM Roles Do Not Have ReadOnlyAccess Access for External AWS Accounts
Profile Applicability: Level 2 Description:  In AWS, IAM roles allow external entities, including users and AWS services, to assume roles in order to p...
Wed, 2 Apr, 2025 at 3:35 AM
Ensure No Security Groups Allow Ingress from 0.0.0.0/0 or ::/0 to Windows SQL Server Ports 1433 or 1434
Profile Applicability  Level 1 Description: Ensure that no security groups are configured to allow ingress traffic from the internet (0.0.0.0/0 or ::/0) ...
Wed, 2 Apr, 2025 at 3:38 AM