Security checks
Every AWS security check KloudLytics runs
262 checks across 49 AWS services. Each has its own page: what it finds, why it matters, how to fix it, and which compliance controls it is evidence for. This list is generated from the catalogue the scanner uses, so it is the list, not a sample of it.
- 15 critical
- 69 high
- 92 medium
- 73 low
- 13 info
IAM 36 checks
- HighDeprecated or flawed AWS managed policy in use
- HighIAM role allows assumption from anywhere
- HighIAM role with admin privileges can be assumed by unexpected principals
- HighIAM role with s3 listing and get privileges can be assumed by unexpected principals
- HighIAM user access key has not been rotated in over 180 days
- HighIncorrect policy used to attempt to enforce MFA
- HighInline policy allows privilege escalation to admin
- HighPrincipal has an attached policy granting administrative access
- MediumExpired SSL/TLS certificate stored in IAM
- MediumIAM Identity Center permission set grants administrative access
- MediumIAM identity has AWSCloudShellFullAccess policy attached
- MediumIAM user has a password but has never logged in
- MediumManaged policy is allowing admin
- MediumNo security alternate contact registered for the AWS account
- MediumRoot account is using a virtual MFA device instead of a hardware token
- MediumRoot user has no MFA enabled
- MediumUse of NotAction in an Allow statement
- MediumUser has not logged in for over 45 days
- MediumUser has password login, but not MFA
- LowCustom IAM policy grants administrator access
- LowIAM group grants admin access but its name does not say so
- LowIAM password policy does not enforce password expiry of 90 days or less
- LowIAM password policy does not prevent reuse of the last 24 passwords
- LowIAM password policy is not set
- LowIAM policy has linting issues
- LowIAM role has not been used for over 365 days
- LowIAM user access key has not been rotated in over 90 days
- LowIAM user has an access key that was never used
- LowIAM user has policies attached directly instead of through a group
- LowIAM user has two access keys
- LowNo IAM role with AWSSupportAccess exists for incident management
- LowPassword policy does not require all character sets
- LowPassword policy minimum length is below 14 characters
- LowRoot user has access keys
- LowUnexpected formatting of IAM policy
- LowUser has not used access key for over 45 days
RDS 25 checks
- HighAurora/RDS cluster storage is not encrypted at rest
- HighRDS automated backups are disabled
- HighRDS instance does not have automatic minor version upgrades enabled
- HighRDS instance has zero database connections for 7 days
- HighRDS instance storage is not encrypted at rest
- HighRDS security group allows broad CIDR ingress (broader than /16)
- HighRDS snapshot is public
- MediumAurora/RDS cluster has automated backups disabled
- MediumNo RDS event subscription configured for this account
- MediumRDS engine version has available minor version upgrades
- MediumRDS instance CPU below 10% average for 7 days — rightsizing candidate
- MediumRDS instance has deletion protection disabled
- MediumRDS instance has no deletion protection and no backup retention
- MediumRDS Multi-AZ enabled on instance not tagged as production
- MediumRDS read replica has zero connections for 7 days
- MediumSSL not enforced via RDS parameter group
- LowAurora/RDS cluster does not have deletion protection enabled
- LowDatabase cluster has no Multi-AZ failover instance
- LowPerformance Insights not enabled on RDS instance
- LowRDS instance backup retention exceeds 7 days on a non-production instance
- LowRDS instance does not have Multi-AZ enabled
- LowRDS instance has a public IP address
- LowRDS instance is on EC2-Classic networking
- LowRDS instance uses a default master username
- LowRDS instance using gp2 storage (migrate to gp3 for 20% savings)
EC2 22 checks
- HighAccount does not block public sharing of EBS snapshots
- HighAMI is publicly shared
- HighEBS snapshot is public
- HighEC2 instance CPU spiked abnormally — possible compromise or runaway process
- HighEC2 instance has an IAM role with admin privileges
- MediumAccount default for instance metadata does not require IMDSv2
- MediumEBS default encryption is not enabled for this region
- MediumEBS volume is not encrypted at rest
- MediumEBS volume is unattached and incurring storage cost
- MediumEC2 instance appears idle — average CPU below 5% for 7 days
- MediumEC2 instance does not enforce IMDSv2
- MediumEC2 instance has no IAM instance profile
- MediumEC2 instance is stopped — attached EBS volumes still billed
- LowEC2 instance potentially oversized — average CPU below 10% for 7 days
- LowEC2 instance uses a previous-generation instance type
- LowElastic IP not associated with any resource
- LowPrivate subnets depend on a NAT gateway in another Availability Zone
- InfoEBS volume uses gp2 — consider migrating to gp3
- InfoEC2 instance has been running for over a year
- InfoEC2 Source/Destination check is off
- InfoEC2-Classic networking is in use
- InfoMultiple NAT Gateways in the same VPC and Availability Zone
Secrets exposure 19 checks
- CriticalHigh-confidence secret in API Gateway stage variable
- CriticalHigh-confidence secret in CloudFormation stack parameter (NoEcho disabled)
- CriticalHigh-confidence secret in CodeBuild PLAINTEXT environment variable
- CriticalHigh-confidence secret in EC2 user-data
- CriticalHigh-confidence secret in ECS running task environment variable
- CriticalHigh-confidence secret in ECS task definition environment variable
- CriticalHigh-confidence secret in Elastic Beanstalk environment variable
- CriticalHigh-confidence secret in Lambda environment variable
- CriticalHigh-confidence secret in SSM String parameter (unencrypted)
- HighHigh-confidence secret in Secrets Manager description field
- HighProbable secret in API Gateway stage variable
- HighProbable secret in CloudFormation stack parameter (NoEcho disabled)
- HighProbable secret in CodeBuild PLAINTEXT environment variable
- HighProbable secret in EC2 user-data
- HighProbable secret in ECS running task environment variable
- HighProbable secret in ECS task definition environment variable
- HighProbable secret in Elastic Beanstalk environment variable
- HighProbable secret in Lambda environment variable
- HighProbable secret in SSM String parameter (unencrypted)
Bedrock 17 checks
- CriticalBedrock agent IAM role has broad permissions
- CriticalBedrock API key belongs to an administrator
- HighBedrock agent has no guardrail applied
- HighBedrock knowledge base not encrypted with CMK
- HighBedrock model invocation logging not enabled
- HighExternal model weights imported into Bedrock without governance review
- HighLong-lived Bedrock API key in use
- HighNo AWS Budget alert configured for Bedrock spend
- HighNo Bedrock guardrails configured
- MediumBedrock batch inference job running without VPC configuration
- MediumBedrock custom model not encrypted with CMK
- MediumBedrock custom prompt router has no fallback model configured
- MediumBedrock guardrail configured but not enforcing protections
- MediumNo VPC endpoint for Amazon Bedrock in region
- MediumNon-approved AI provider model in active use
- LowBedrock batch inference job in terminal failure state
- LowNo Bedrock inference profiles configured
Monitoring and alarms 14 checks
- HighNo CloudWatch alarm for CloudTrail configuration changes
- HighNo CloudWatch alarm for console sign-in without MFA
- HighNo CloudWatch alarm for KMS CMK disable or scheduled deletion
- HighNo CloudWatch alarm for root account usage
- MediumNo CloudWatch alarm for AWS Config configuration changes
- MediumNo CloudWatch alarm for AWS Management Console authentication failures
- MediumNo CloudWatch alarm for IAM policy changes
- MediumNo CloudWatch alarm for Network ACL changes
- MediumNo CloudWatch alarm for network gateway changes
- MediumNo CloudWatch alarm for route table changes
- MediumNo CloudWatch alarm for S3 bucket policy changes
- MediumNo CloudWatch alarm for security group changes
- MediumNo CloudWatch alarm for unauthorized API calls
- MediumNo CloudWatch alarm for VPC changes
S3 12 checks
- HighInternet accessible S3 bucket via policy
- HighPublic grant to S3 bucket via ACL
- MediumS3 bucket does not require SSL/HTTPS for all requests
- MediumS3 bucket has incomplete multipart uploads consuming storage
- LowS3 Block Public Access does not block all access types
- LowS3 Block Public Access is not enabled for the account
- LowS3 bucket does not have server-access logging enabled
- LowS3 bucket with versioning enabled does not have MFA delete configured
- LowVPC with private subnets has no S3 endpoint
- InfoInternet accessible S3 bucket via policy (only GetObject)
- InfoS3 bucket does not have versioning enabled
- InfoS3 bucket has no lifecycle policy
API Gateway 10 checks
- HighAPI Gateway execute-api endpoint not disabled — CloudFront WAF bypassable
- HighAPI Gateway REST API method has no authorization
- HighHTTP API (v2) has no JWT authorizer configured
- HighPrivate API has no resource policy restricting access
- MediumAPI Gateway custom domain TLS minimum version below 1.2
- MediumAPI Gateway REST API has no request validators configured
- MediumAPI Gateway stage not associated with a WAF Web ACL
- LowAPI Gateway stage does not have access logging enabled
- LowAPI Gateway stage has no method-level throttling configured
- LowAPI Gateway stage-to-backend integration has no client certificate
CloudTrail 10 checks
- CriticalS3 bucket used for CloudTrail logs is publicly accessible
- HighCloudTrail trail does not log all management events (Read + Write)
- MediumCloudTrail is not logging S3 data events
- MediumCloudTrail logs are not encrypted with KMS
- MediumCloudTrail logs are not integrated with CloudWatch Logs
- LowCloudTrail Insights is not enabled on the trail
- LowCloudTrail is not enabled
- LowCloudTrail log file validation is not enabled
- LowCloudTrail S3 bucket does not have server-access logging enabled
- LowCloudTrail trail is not multi-region
SageMaker 7 checks
- HighSageMaker notebook instance has direct internet access
- HighSageMaker training job has no checkpoint configuration
- MediumSageMaker endpoint not deployed inside VPC
- MediumSageMaker notebook instance has root access enabled
- MediumSageMaker notebook instance running for 7+ days without modification
- MediumSageMaker resource not encrypted with CMK
- MediumSageMaker training job not using managed spot instances
AWS WAF 6 checks
- CriticalWAF Web ACL has no rate-based rule for DDoS protection
- HighWAF Web ACL default action is Count instead of Block
- HighWAF Web ACL has no AWS managed rule groups enabled
- HighWAF Web ACL logging is disabled
- HighWAF Web ACL not associated with any resource
- MediumAWS Bot Control managed rule group not configured
Elastic Load Balancing 6 checks
Lambda 6 checks
- HighLambda function is using a deprecated or end-of-life runtime
- HighLambda function URL is publicly invocable without authentication
- MediumLambda function is publicly invocable
- LowLambda function has no resource-based policy
- LowLambda function has zero invocations in the past 30 days
- LowLambda function memory utilization below 25% of configured limit
Security groups 6 checks
- CriticalSecurity group has critical port open to the internet
- HighDefault VPC security group allows unrestricted traffic
- LowSecurity group has overlapping CIDR rules
- InfoSecurity Group CIDR contains large IP range
- InfoSecurity group CIDR is formatted unexpectedly
- InfoSecurity group contains a redundant CIDR rule
VPC 5 checks
Tagging 4 checks
ACM 3 checks
CloudWatch 3 checks
Cognito 3 checks
DynamoDB 3 checks
ElastiCache 3 checks
KMS 3 checks
Redshift 3 checks
Route 53 3 checks
Secrets Manager 3 checks
Systems Manager 3 checks
ECR 2 checks
ECS 2 checks
IAM Access Analyzer 2 checks
Security Hub 2 checks
Application Load Balancer 1 check
Auto Scaling 1 check
Billing 1 check
CloudFront 1 check
Config 1 check
Data protection 1 check
Glacier 1 check
GuardDuty 1 check
Lightsail 1 check
OpenSearch 1 check
Resilience 1 check
SNS 1 check
SQS 1 check
Threat detection 1 check
Vulnerability management 1 check
Find out what is actually exposed in your AWS environment.
Connect one AWS account and run your first security assessment.
No credit card · Agentless · Read-only