All Categories / Choose a Policy Alert
IAM & Identity
Root Account Usage Detected
Root Account MFA Not Enabled
Root Access Key Exists
IAM User Without MFA Enabled
IAM Access Key Not Rotated Within 90 Days
IAM User Credentials Unused for 90 Days
IAM Policy Grants Full Administrative Access
IAM Policy Uses Wildcard Actions or Resources
IAM Role Trust Policy Allows External Account Access
IAM Access Analyzer Not Enabled
Organizations & Account Security
AWS Organizations Not Enabled
Service Control Policies Not Configured
Security Hub Delegated Administrator Not Configured
GuardDuty Delegated Administrator Not Configured
AWS Config Aggregator Not Configured
Account Alternate Security Contact Missing
Account Does Not Restrict Unused Regions
Member Account Not Enrolled in Security Hub
Member Account Not Enrolled in GuardDuty
Root Account Recovery Controls Missing
CloudTrail & Logging
CloudTrail Logging Disabled
CloudTrail Multi-Region Trail Not Enabled
CloudTrail Log File Validation Disabled
CloudTrail Logs Not Encrypted with KMS
CloudTrail Logs Not Delivered to CloudWatch Logs
CloudTrail Management Events Not Captured
S3 Data Events Not Enabled for Sensitive Buckets
Lambda Data Events Not Enabled
CloudTrail Insight Events Not Enabled
CloudTrail Trail Stopped or Deleted
CloudWatch & Monitoring
No CloudWatch Alarm for Root Account Usage
No Alarm for Unauthorized API Calls
No Alarm for IAM Policy Changes
No Alarm for CloudTrail Configuration Changes
No Alarm for Console Sign-In Failures
No Alarm for Security Group Changes
CloudWatch Log Group Retention Not Configured
CloudWatch Log Group Not Encrypted
CloudWatch Alarm Action Disabled
Security Alarm SNS Topic Not Encrypted
AWS Config
AWS Config Recording Disabled
AWS Config Not Enabled in All Regions
AWS Config Delivery Channel Missing
AWS Config Recorder Stopped
AWS Config Conformance Pack Not Deployed
AWS Config Aggregator Not Enabled
AWS Config S3 Bucket Publicly Accessible
AWS Config S3 Bucket Not Encrypted
AWS Config Recorder Excludes Global Resources
AWS Config Remediation Failed
GuardDuty
GuardDuty Detector Disabled
GuardDuty Not Enabled in All Regions
GuardDuty S3 Protection Disabled
GuardDuty EKS Protection Disabled
GuardDuty Runtime Monitoring Disabled
GuardDuty Malware Protection Disabled
GuardDuty High Severity Finding
GuardDuty Critical Severity Finding
GuardDuty Crypto Mining Activity Detected
GuardDuty Credential Exfiltration Finding Detected
Security Hub
AWS Security Hub Not Enabled
Security Hub Not Enabled in All Regions
AWS Foundational Security Best Practices Disabled
CIS AWS Foundations Benchmark Disabled
NIST 800-53 Standard Disabled
Security Hub Auto-Enable New Accounts Disabled
Security Hub Control Manually Disabled
Security Hub Critical Findings Open Over SLA
Security Hub Suppression Rule Too Broad
Security Hub Member Account Disconnected
Inspector
Amazon Inspector Not Enabled
Inspector EC2 Scanning Disabled
Inspector ECR Enhanced Scanning Disabled
Inspector Lambda Scanning Disabled
Inspector Critical Finding Active
Inspector High Finding Active
Inspector EC2 Instance Not Scanned
Inspector ECR Image Has Critical CVE
Inspector Lambda Function Has Vulnerable Package
Inspector Coverage Gap Detected
VPC & Networking
VPC Flow Logs Not Enabled
VPC Flow Logs Not Sent to Central Logging
Default VPC Exists in Active Account
Internet Gateway Attached to Sensitive VPC
Route Table Sends Private Subnet Traffic Directly to Internet Gateway
VPC Endpoint Policy Allows Wildcard Access
VPC Peering Connection Active Without Approval
Transit Gateway Route Table Overly Permissive
Network Firewall Not Deployed for Egress Inspection
Unused Elastic IP Address Allocated
Security Groups & NACLs
Security Group Allows Unrestricted SSH from Internet
Security Group Allows Unrestricted RDP from Internet
Security Group Allows Unrestricted Database Access
Security Group Allows All TCP Ports from Internet
Security Group Allows All Protocols from Internet
Default Security Group Allows Inbound Traffic
Default Security Group Allows Outbound Traffic
Unused Security Group Exists
Network ACL Allows Unrestricted Inbound Traffic
Security Group Rule Changed Outside Change Window
EC2
EC2 Instance Has Public IP Address
EC2 Instance Not Using IMDSv2
EC2 Instance Metadata Allows IMDSv1
EC2 Instance Not Managed by Systems Manager
EC2 Instance Missing IAM Instance Profile
EC2 Instance Uses Overly Permissive IAM Role
EC2 Instance Launched from Unapproved AMI
EC2 Instance Uses Outdated AMI
EC2 Instance Has Unrestricted Security Group
EC2 Instance Not Covered by Backup Policy
EBS & AMI
EBS Volume Encryption Not Enabled
EBS Encryption by Default Disabled
EBS Snapshot Publicly Restorable
EBS Snapshot Shared with External Account
EBS Volume Not Backed Up
EBS Snapshot Not Encrypted
AMI Is Public
AMI Shared with External Account
AMI Uses Unencrypted EBS Snapshot
Launch Template Allows Public IP Assignment
Lambda
Lambda Functions Should Be in a VPC
Lambda Function Has Public Function URL
Lambda Function URL Auth Type Is NONE
Lambda Resource-Based Policy Allows Public Access
Lambda Environment Variables Not Encrypted with Customer Managed KMS Key
Lambda Execution Role Has Excessive Permissions
Lambda Function Uses Deprecated Runtime
Lambda Function Has No Dead Letter Queue
Lambda Function Logs Retention Not Configured
Lambda Layer Uses Vulnerable Package
ECS & Fargate
ECS Task Definition Uses Privileged Container
ECS Task Definition Allows Host Networking
ECS Task Definition Has Readonly Root Filesystem Disabled
ECS Task Definition Runs Container as Root
ECS Task Definition Contains Plaintext Secrets
ECS Service Has Public IP Assignment Enabled
ECS Task Role Has Excessive Permissions
ECS Task Definition Uses Latest Image Tag
ECS Exec Enabled Without Logging
ECS Cluster Container Insights Disabled
EKS
EKS Cluster Endpoint Publicly Accessible
EKS Cluster Endpoint Allows 0.0.0.0/0
EKS Control Plane Logging Disabled
EKS Audit Logging Disabled
EKS Secrets Encryption Disabled
EKS Cluster Uses Unsupported Kubernetes Version
EKS Node Group Uses Public Subnets
EKS Node IAM Role Has Excessive Permissions
EKS IRSA Not Used for Service Accounts
EKS Network Policy Not Enabled
API Gateway
API Gateway Stage Logging Disabled
API Gateway Access Logging Disabled
API Gateway X-Ray Tracing Disabled
API Gateway Stage Cache Encryption Disabled
API Gateway Method Authorization Missing
API Gateway Endpoint Publicly Accessible Without WAF
API Gateway Throttling Not Configured
API Gateway Resource Policy Allows Public Access
API Gateway Default Endpoint Enabled
API Gateway Mutual TLS Not Enabled for Sensitive API
Load Balancers
Application Load Balancer Not Using HTTPS Listener
Load Balancer Allows HTTP Without Redirect to HTTPS
Load Balancer TLS Policy Is Outdated
Load Balancer Access Logging Disabled
Load Balancer Deletion Protection Disabled
Load Balancer Not Associated with WAF
Classic Load Balancer Uses Insecure Cipher
Load Balancer Internet-Facing Unexpectedly
Load Balancer Certificate Expiring Soon
Load Balancer Not Covered by Monitoring Alarms
CloudFront & Route 53
CloudFront Distribution Allows HTTP
CloudFront Viewer Protocol Policy Not Redirecting to HTTPS
CloudFront Origin Protocol Policy Allows HTTP
CloudFront Distribution Uses Outdated TLS Policy
CloudFront Access Logging Disabled
CloudFront Origin Access Control Not Configured for S3 Origin
CloudFront Distribution Not Associated with WAF
Route 53 Hosted Zone Query Logging Disabled
Route 53 DNSSEC Signing Disabled
Route 53 Resolver Query Logging Disabled
WAF & Shield
AWS WAF Not Associated with Public Endpoint
WAF Web ACL Logging Disabled
WAF Default Action Allows All Traffic
WAF Managed Rule Group Not Enabled
WAF SQL Injection Rule Not Enabled
WAF Cross-Site Scripting Rule Not Enabled
WAF Rate-Based Rule Not Configured
WAF Bot Control Not Enabled for Public Application
Shield Advanced Not Enabled for Critical Public Endpoint
Shield Proactive Engagement Not Enabled
S3
Publicly Accessible S3 Bucket
S3 Bucket Block Public Access Disabled
S3 Bucket Policy Allows Public Read
S3 Bucket Policy Allows Public Write
S3 Bucket Encryption Disabled
S3 Bucket Versioning Not Enabled
S3 Server Access Logging Disabled
S3 Object-Level Logging Not Enabled for Sensitive Bucket
S3 Bucket Policy Allows Insecure Transport
S3 Access Point Policy Allows Public Access
EFS & FSx
EFS File System Not Encrypted at Rest
EFS File System Not Encrypted in Transit
EFS Backup Not Enabled
EFS Mount Target Security Group Allows Unrestricted NFS
EFS File System Policy Allows Public Access
EFS Lifecycle Policy Not Configured
FSx File System Not Encrypted
FSx Backup Not Enabled
FSx Security Group Allows Unrestricted SMB
FSx Audit Logging Disabled
RDS & Aurora
RDS Instance Publicly Accessible
RDS Database Instance Not Encrypted
RDS Storage Encryption Uses AWS Managed Key Instead of CMK
RDS Automated Backups Disabled
RDS Backup Retention Too Short
RDS Deletion Protection Disabled
RDS Enhanced Monitoring Disabled
RDS Instance Not in Private Subnet
RDS Security Group Allows Unrestricted Access
RDS Snapshot Publicly Accessible
DynamoDB & Databases
DynamoDB Point-in-Time Recovery Disabled
DynamoDB Table Encryption Not Using Customer Managed KMS Key
DynamoDB Table Deletion Protection Disabled
DynamoDB Table Policy Allows Public Access
DynamoDB Table Should Be Present in a Backup Plan
Redshift Cluster Publicly Accessible
Redshift Cluster Not Encrypted
Redshift Audit Logging Disabled
OpenSearch Domain Publicly Accessible
OpenSearch Node-to-Node Encryption Disabled
OpenSearch Fine-Grained Access Control Disabled
KMS & Secrets Manager
KMS Customer Key Rotation Disabled
KMS Key Scheduled for Deletion
KMS Key Policy Allows Wildcard Principal
KMS Key Policy Allows External Account
KMS Key Disabled
Secrets Manager Secret Not Rotated
Secrets Manager Secret Resource Policy Allows Public Access
Secrets Manager Secret Contains Plaintext Credential Pattern
Parameter Store Secure String Not Encrypted with CMK
Parameter Store Parameter Contains Sensitive Value as Plain String
Backup & Resilience
AWS Backup Not Enabled for Critical Resources
Backup Plan Missing EC2 Coverage
Backup Plan Missing RDS Coverage
Backup Vault Not Encrypted with Customer Managed KMS Key
Backup Vault Access Policy Allows External Account
Backup Vault Lock Not Enabled
Backup Job Failed
Backup Copy Job to Secondary Region Missing
Backup Restore Test Not Performed
Recovery Point Manual Deletion Detected
Systems Manager & Patch
EC2 Instance Not Managed by AWS Systems Manager
SSM Agent Not Running
SSM Managed Instance Non-Compliant with Patch Baseline
Patch Compliance Critical Updates Missing
Patch Compliance High Updates Missing
Systems Manager Inventory Not Enabled
Session Manager Logging Disabled
Session Manager Logs Not Encrypted
Run Command Execution Not Logged
SSM Patch Baseline Not Approved by Security
Containers & ECR
ECR Repository Image Scanning Not Enabled
ECR Enhanced Scanning Not Enabled
ECR Repository Allows Mutable Image Tags
ECR Repository Policy Allows Public Access
ECR Repository Not Encrypted with Customer Managed KMS Key
ECR Image Has Critical Vulnerability
ECR Image Has High Vulnerability
ECR Image Uses Latest Tag in Production
Container Image Contains Hardcoded Secret
ECR Scan Findings Not Sent to Security Hub
Data Security & Macie
Amazon Macie Not Enabled
Macie Not Enabled in All Regions
Macie Sensitive Data Discovery Job Missing
Macie High Severity Finding
Macie Public S3 Bucket with Sensitive Data
Macie Bucket Contains Credentials or Secrets
Macie Bucket Contains PII
Glue Data Catalog Encryption Disabled
Athena Workgroup Query Results Not Encrypted
Data Classification Tag Missing on Sensitive Bucket
Messaging & Eventing
SNS Topic Not Encrypted
SNS Topic Policy Allows Public Publish
SNS Topic Policy Allows External Account Subscribe
SQS Queue Not Encrypted
SQS Queue Policy Allows Public Access
SQS Dead Letter Queue Not Configured
EventBridge Rule Targets External Account
EventBridge Event Bus Policy Allows Public Access
Kinesis Stream Not Encrypted
MSK Cluster Allows Plaintext Communication
DevOps & IaC
CloudFormation Stack Drift Detected
CloudFormation Stack Uses Hardcoded Secrets
CloudFormation Execution Role Has Excessive Permissions
CodeBuild Project Uses Privileged Mode
CodeBuild Project Environment Variables Contain Plaintext Secrets
CodeBuild Project Not Using VPC
CodePipeline Artifact Store Not Encrypted
Terraform State Bucket Public Access Block Disabled
Terraform State Bucket Not Encrypted
Unapproved Infrastructure Change Detected Outside Pipeline