AWS New Checks

Check if Amazon SageMaker Models have VPC settings configured
Profile Applicability: Level 2 Description: Amazon SageMaker is a fully managed service for building, training, and deploying machine learning models at...
Wed, 2 Apr, 2025 at 6:58 AM
Ensure Compute Instances Do Not Have Public IP Addresses (Automated)
Profile Applicability: Level 2 Description: Compute instances should not have external (public) IP addresses to reduce exposure to the internet. Instea...
Wed, 2 Apr, 2025 at 6:59 AM
Check if Route53 Records contains dangling IPs.
Profile Applicability: Level 1 Description: Amazon Route 53 is a scalable Domain Name System (DNS) web service that routes end users to infrastructure ru...
Wed, 2 Apr, 2025 at 7:45 AM
Ensure IAM Service Roles Prevent Against a Cross-Service Confused Deputy Attack
Profile Applicability: Level 2 Description: A confused deputy attack occurs when a service with permissions inadvertently performs actions on behalf of...
Wed, 2 Apr, 2025 at 8:41 AM
Ensure Users Make Use of Temporary Credentials Assuming IAM Roles
Profile Applicability: Level 2 Description: AWS Identity and Access Management (IAM) allows users and applications to assume roles and obtain temporary...
Wed, 2 Apr, 2025 at 8:53 AM
Ensure Amazon Elasticsearch/Opensearch Service domains have internal user database enabled
Description: Amazon Elasticsearch/OpenSearch Service provides an internal user database that can be used for authenticating users without relying on extern...
Fri, 23 May, 2025 at 7:07 AM
Ensure a Security Audit Role Has Been Created to Conduct Security Audits
Profile Applicability Level 2 Description: A Security Audit role in AWS is an IAM role that provides security teams with read-only access to review c...
Fri, 23 May, 2025 at 7:16 AM
Ensure there are no potential privilege escalation threats in CloudTrail.
Profile Applicability: Level 1 Description: AWS CloudTrail is a service that records API calls made on your AWS account, capturing detailed information...
Fri, 23 May, 2025 at 7:30 AM
Ensure EFS Access Points Should Enforce a User Identity
Profile Applicability: Level 1 Description: Amazon Elastic File System (EFS) access points provide application-specific entry points into an EFS file sy...
Fri, 23 May, 2025 at 7:34 AM
Ensure Amazon Elasticsearch/Opensearch Service domains have encryption at-rest enabled
Profile Applicability: Level 1 Description: Amazon Elasticsearch Service (Amazon OpenSearch Service) provides managed clusters to run Elasticsearch a...
Fri, 23 May, 2025 at 7:40 AM