Documentation
| Article | Path |
|---|---|
| API Gateway X-Ray tracing is disabled | ansible/aws/api_gateway_xray_disabled |
| Review API Gateway’s Lambda invocation scope | ansible/aws/public_lambda_via_api_gateway |
| Review AWS Config aggregation Region coverage | ansible/aws/config_configuration_aggregator_to_all_regions_disabled |
| Review IAM user password-change permissions | ansible/aws/aws_password_policy_with_unchangeable_passwords |
| Review authorization for an API Gateway REST API | ansible/aws/api_gateway_without_configured_authorizer |
| Review CloudFront distribution configuration | ansible/aws/cdn_configuration_is_missing |
| CloudFormation stack notifications are not configured | ansible/aws/stack_notifications_disabled |
| Review CloudFormation stack template inputs | ansible/aws/stack_without_template |
| CloudTrail is not integrated with CloudWatch Logs | ansible/aws/cloudtrail_not_integrated_with_cloudwatch |
| CloudTrail log-delivery notification topic is not configured | ansible/aws/cloudtrail_sns_topic_name_undefined |
| CloudTrail multi-Region logging is disabled | ansible/aws/cloudtrail_multi_region_disabled |
| No KMS key is specified for CloudTrail logs | ansible/aws/cloudtrail_log_files_not_encrypted_with_kms |
| CloudTrail log file integrity validation is disabled | ansible/aws/cloudtrail_log_file_validation_disabled |
| Review CloudWatch Logs retention | ansible/aws/cloudwatch_without_retention_period_specified |
| Review CloudWatch log collection for API Gateway | ansible/aws/api_gateway_with_cloudwatch_logging_disabled |
| Security group rule allows all IPv4 addresses | ansible/aws/db_security_group_with_public_scope |
| Review EC2 instance metadata access protection | ansible/aws/instance_uses_metadata_service_IMDSv1 |
| Review EC2 VPC subnet selection | ansible/aws/instance_with_no_vpc |
| Review EC2 default VPC use | ansible/aws/ec2_instance_using_default_vpc |
| Review EC2 EBS optimization settings | ansible/aws/ec2_not_ebs_optimized |
| ECR repository policy uses a wildcard principal | ansible/aws/ecr_repository_is_publicly_accessible |
| Review ECS service deployment availability | ansible/aws/ecs_service_without_running_tasks |
| Review the EFS customer managed KMS key | ansible/aws/efs_without_kms |
| Review EFS operational tags | ansible/aws/efs_without_tags |
| AWS Config configuration lacks an ENCRYPTED_VOLUMES rule | ansible/aws/config_rule_for_encrypted_volumes_is_disabled |
| Review ElastiCache VPC subnet selection | ansible/aws/elasticache_without_vpc |
| Review ElastiCache ports and access controls | ansible/aws/elasticache_using_default_port |
| IAM trust policy external ID or MFA protections need review | ansible/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa |
| Review HTTPS enforcement for an OpenSearch domain | ansible/aws/elasticsearch_with_https_disabled |
| ALB listener accepts HTTP traffic | ansible/aws/alb_listening_on_http |
| CloudFront viewer protocol policy allows HTTP | ansible/aws/viewer_protocol_policy_allows_http |
| Review IAM database authentication for RDS | ansible/aws/iam_database_auth_not_enabled |
| Review IAM password expiration policy | ansible/aws/misconfigured_password_policy_expiration |
| Review IAM password reuse prevention | ansible/aws/password_without_reuse_prevention |
| Review IAM password minimum length | ansible/aws/iam_password_without_minimum_length |
| Review rotation settings for customer-managed KMS keys | ansible/aws/cmk_rotation_disabled |
| Kinesis encryption settings need review | ansible/aws/kinesis_not_encrypted_with_kms |
| Lambda active X-Ray tracing is not configured | ansible/aws/lambda_functions_without_x-ray_tracing |
| Review allowed actions in a Lambda resource policy | ansible/aws/lambda_permission_misconfigured |
| Review Lambda operational tags | ansible/aws/lambda_function_without_tags |
| Possible secret key in a Lambda task's aws_access_key field | ansible/aws/hardcoded_aws_access_key_in_lambda |
| Review MFA protection when assuming AWS roles | ansible/aws/authentication_without_mfa |
| Review the exposure of an API Gateway REST API | ansible/aws/api_gateway_endpoint_config_is_not_private |
| AWS Batch job definition using privileged mode | ansible/aws/batch_job_definition_with_privileged_container_properties |
| Review RDS ports and access controls | ansible/aws/rds_using_default_port |
| Review RDS automatic minor upgrades | ansible/aws/automatic_minor_upgrades_disabled |
| Review RSA certificate key strength | ansible/aws/certificate_rsa_key_bytes_lower_than_256 |
| Review Redshift default-port use | ansible/aws/redshift_using_default_port |
| Security group exposes SSH too broadly | ansible/aws/security_group_with_unrestricted_access_to_ssh |
| Review certificate validation in Ansible API Gateway management | ansible/aws/api_gateway_without_ssl_certificate |
| Review CloudFormation resource update protection | ansible/aws/no_stack_policy |
| Review stack retention when deleting a StackSet | ansible/aws/stack_retention_disabled |
| Review WAF protection for an API Gateway REST API | ansible/aws/api_gateway_without_waf |
| CloudFront WAF association needs review | ansible/aws/cloudfront_without_waf |
| Security group ingress may allow excessive access | ansible/aws/security_group_ingress_not_restricted |
| Review encoded key material in user data | ansible/aws/user_data_contains_encoded_private_key |
| Route 53 task has no record value | ansible/aws/route53_record_undefined |
| RDS-linked subnet uses a /0 CIDR | ansible/aws/rds_associated_with_public_subnet |
| Redshift configuration enables public access | ansible/aws/redshift_publicly_accessible |
| SQS policy grants broad permissions to wildcard principals | ansible/aws/sqs_policy_with_public_access |
| RDS instance has public access enabled | ansible/aws/rds_db_instance_publicly_accessible |
| Legacy aws_s3 task specifies a public ACL | ansible/aws/s3_bucket_with_public_access |
| SNS topic policy has a wildcard or missing principal | ansible/aws/sns_topic_is_publicly_accessible |
| Security group ingress allows all IPv4 or IPv6 sources | ansible/aws/ec2_group_has_public_interface |
| EC2 instance has a public IP address | ansible/aws/ec2_instance_has_public_ip |
| ECS service assigns public IP addresses | ansible/aws/ecs_services_assigned_with_public_ip_address |
| KMS key policy permissions need review | ansible/aws/kms_key_with_full_permissions |
| ECS service role permissions need review | ansible/aws/ecs_service_admin_role_is_present |
| Review the ECS task definition network mode | ansible/aws/ecs_task_definition_network_mode_not_recommended |
| ElastiCache engine version and security requirements need review | ansible/aws/redis_not_compliant |
| CloudFront viewer certificate settings need review | ansible/aws/vulnerable_default_ssl_certificate |
| EC2 instance uses the default security group | ansible/aws/ec2_instance_using_default_security_group |
| Security group inbound access scope needs review | ansible/aws/db_security_group_open_to_large_scope |
| Security group exposes a port range to all addresses | ansible/aws/public_port_wide |
| CloudFront logging settings need review | ansible/aws/cloudfront_logging_disabled |
| CloudTrail trail logging is stopped | ansible/aws/cloudtrail_logging_disabled |
| Review API diagnostic logging for the Ansible S3 task | ansible/aws/s3_bucket_logging_disabled |
| Expired SSL/TLS certificate | ansible/aws/certificate_has_expired |
| S3 bucket policy with delete actions and a wildcard principal | ansible/aws/s3_bucket_allows_delete_action_from_all_principals |
| Wildcard principals in S3 object-read policies | ansible/aws/s3_bucket_allows_get_action_from_all_principals |
| Wildcard principals in S3 listing policies | ansible/aws/s3_bucket_allows_list_action_from_all_principals |
| S3 bucket policy with Put actions and a wildcard principal | ansible/aws/s3_bucket_allows_put_action_from_all_principals |
| SES policy may grant excessive permissions | ansible/aws/ses_policy_with_allowed_iam_actions |
| S3 bucket policy uses a wildcard principal | ansible/aws/s3_bucket_access_to_any_principal |
| S3 bucket policy with wildcard actions and principals | ansible/aws/s3_bucket_with_all_permissions |
| Public-read ACLs in S3 | ansible/aws/s3_bucket_acl_allows_read_to_all_users |
| Review wildcard principals in IAM policies | ansible/aws/iam_policy_grants_assumerole_permission_across_all_services |
| SQS queue policy specifies Action '*' | ansible/aws/sqs_policy_allows_all_actions |
| Review account principals in IAM policies | ansible/aws/iam_role_allows_all_principals_to_assume |
| S3 bucket versioning needs review | ansible/aws/s3_bucket_without_versioning |
| Review IAM group membership | ansible/aws/iam_group_without_users |
| IAM policies attached directly to a user | ansible/aws/iam_policies_attached_to_user |
| An in-use KMS key is disabled or pending deletion | ansible/aws/cmk_is_unusable |
| Review encryption at rest for SQS messages | ansible/aws/sqs_with_sse_disabled |
| S3 bucket configuration requests removal of default encryption | ansible/aws/s3_bucket_without_server-side_encryption |
| S3 CORS permissions need review | ansible/aws/s3_bucket_with_unsecured_cors_rule |
| Review the TLS security policy on an ELB listener | ansible/aws/elb_using_insecure_protocols |
| Review the CloudFront viewer TLS security policy | ansible/aws/secure_ciphers_disabled |
| Review the CodeBuild artifact encryption key | ansible/aws/codebuild_not_encrypted |
| EBS volume encryption settings need review | ansible/aws/ebs_volume_encryption_disabled |
| EFS encryption at rest settings need review | ansible/aws/efs_not_encrypted |
| Review encryption of AMI EBS snapshots | ansible/aws/ami_not_encrypted |
| EBS encryption in EC2 launch settings needs review | ansible/aws/launch_configuration_is_not_encrypted |
| Redshift encryption settings need review | ansible/aws/redshift_not_encrypted |
| ELB listener security policy needs review | ansible/aws/elb_using_weak_ciphers |
| AMI sharing targets need review | ansible/aws/ami_shared_with_multiple_accounts |
| Review traffic distribution for an Auto Scaling Group | ansible/aws/auto_scaling_group_with_no_associated_elb |
| RDS uses an expired or unsupported CA certificate | ansible/aws/ca_certificate_identifier_is_outdated |
| Lambda permission uses a wildcard principal | ansible/aws/lambda_permission_principal_is_wildcard |
| SQS queue policy uses Principal '*' | ansible/aws/sqs_queue_exposed |
| S3 ACL grants read access to every AWS account | ansible/aws/s3_bucket_acl_allows_read_to_any_authenticated_user |
| HTTP port is open to the Internet | ansible/aws/http_port_open_to_internet |
| Service ports allow all source addresses | ansible/aws/unknown_port_exposed_to_internet |
| Port 3389 may be exposed to all IPv4 sources | ansible/aws/remote_desktop_port_open |
| Review active IAM user access keys | ansible/aws/iam_access_key_is_exposed |
| Automated backups are disabled for an RDS instance | ansible/aws/rds_with_backup_disabled |
| RDS storage encryption settings need review | ansible/aws/db_instance_storage_not_encrypted |
| IAM policy uses wildcards for both actions and resources | ansible/aws/iam_policy_grants_full_permissions |
| IAM policy allows all actions on all resources | ansible/aws/iam_policies_with_full_privileges |
| Security group rule allows all IPv4 or IPv6 addresses | ansible/aws/default_security_groups_with_unrestricted_traffic |
| Security group ingress allows all source addresses | ansible/aws/unrestricted_security_group_ingress |
| CloudFront minimum TLS version needs review | ansible/aws/cloudfront_without_minimum_protocol_tls_1.2 |
| ECR repository permits image tag changes | ansible/aws/ecr_image_tag_not_immutable |
| Security group allows TCP 2383 from all IPv4 sources | ansible/aws/sql_analysis_services_port_2383_is_publicly_accessible |
| Possible AWS credential exposure in EC2 user data | ansible/aws/hardcoded_aws_access_key |
| Active IAM user access key needs review | ansible/aws/root_account_has_active_access_keys |