AWS New Checks

Ensure IAM Customer-Managed Policies That Allow Full ":" Administrative Privileges Are Not Attached
Description: IAM (Identity and Access Management) is a service provided by AWS to manage access to AWS resources securely. Customer-Managed policies are IA...
Wed, 2 Apr, 2025 at 5:04 AM
Ensure IAM Roles Do Not Have AdministratorAccess Policy Attached
Description: IAM (Identity and Access Management) in AWS allows users and roles to be granted permissions to access AWS resources. IAM roles can be assigne...
Wed, 2 Apr, 2025 at 5:24 AM
Ensure Public Access to EBS Snapshots Is Disabled
 Profile Applicability:  Level 2 Description Amazon Elastic Block Store (EBS) snapshots are used to back up EBS volumes, providing a reliable mechanism f...
Wed, 2 Apr, 2025 at 6:06 AM
Ensure No Security Groups Allow Ingress from 0.0.0.0/0 or ::/0 to Telnet Port 23
Profile Applicability:  Level 2 Description Telnet, which uses TCP port 23, is an outdated protocol with known vulnerabilities as it transmits data, incl...
Wed, 2 Apr, 2025 at 6:10 AM
Ensure EC2 Client VPN Endpoints Have Client Connection Logging Enabled
Profile Applicability:  Level 2 Description Client connection logging captures important information about client connections, such as connection attempt...
Wed, 2 Apr, 2025 at 6:16 AM
Ensure Amazon EC2 Paravirtual Virtualization Type Is Not Used
Profile Applicability:  Level 2 Description: The paravirtual (PV) virtualization type is an older virtualization technology that lacks modern performance...
Wed, 2 Apr, 2025 at 6:23 AM
Ensure No EC2 Instances Allow Ingress from the Internet to Elasticsearch and Kibana Ports (TCP 9200, 9300, 5601)
Profile Applicability:  Level 1 Description: Ensure that no EC2 instances are configured to allow ingress traffic from the internet to Elasticsearch an...
Wed, 2 Apr, 2025 at 6:38 AM
Ensure No EC2 Instances Allow Ingress from the Internet to TCP Port 88, 464, 749, or 750 (Kerberos)
Profile Applicability: Level 1 Description: Amazon EC2 (Elastic Compute Cloud) instances provide scalable compute capacity in the cloud. Security gro...
Wed, 2 Apr, 2025 at 6:44 AM
Ensure no EC2 instances allow ingress from the internet to TCP port 1521, 2483 or 2484 (Oracle).
Profile Applicability: Level 1 Description: Oracle database services typically use TCP ports 1521, 2483, and 2484 for communication. These ports are us...
Wed, 2 Apr, 2025 at 6:50 AM
Ensure Amazon SageMaker Notebook instances have VPC settings configured
Profile Applicability: Level 1 Description: Amazon SageMaker Notebook instances are fully managed environments for data scientists to develop, train, a...
Mon, 26 May, 2025 at 1:06 AM