Documentation
| Article | Path |
|---|---|
| Invalid ACM certificate domain name | cloudFormation/aws/wildcard_in_acm_certificate_domain_name |
| ALB uses an HTTP listener | cloudFormation/aws/alb_listening_on_http |
| ALB is not associated with AWS WAF | cloudFormation/aws/alb_is_not_integrated_with_waf |
| ALB access logging is disabled | cloudFormation/aws/elb_v2_alb_access_log_disabled |
| Review API Gateway authentication configuration | cloudFormation/aws/api_gateway_without_configured_authorizer |
| Review API Gateway detailed CloudWatch metrics | cloudFormation/aws/cloudwatch_metrics_disabled |
| Review access logging for an API Gateway deployment stage | cloudFormation/aws/api_gateway_deployment_without_access_log_setting |
| Usage plan not associated with the deployed API stage | cloudFormation/aws/api_gateway_deployment_without_api_gateway_usage_plan_associated |
| Review API Gateway stage logging | cloudFormation/aws/api_gateway_access_logging_disabled |
| API Gateway stage not associated with a usage plan | cloudFormation/aws/api_gateway_stage_without_api_gateway_usage_plan_associated |
| API Gateway X-Ray tracing disabled | cloudFormation/aws/api_gateway_xray_disabled |
| Review API Gateway method authentication | cloudFormation/aws/api_gateway_with_open_access |
| Review API Gateway API key usage management | cloudFormation/aws/api_gateway_method_does_not_contains_an_api_key |
| Review the TLS policy for an API Gateway custom domain | cloudFormation/aws/api_gateway_without_security_policy |
| Review the API Gateway compression threshold | cloudFormation/aws/api_gateway_with_invalid_compression |
| Review API Gateway endpoint exposure | cloudFormation/aws/api_gateway_endpoint_config_is_not_private |
| API Gateway cache cluster not configured | cloudFormation/aws/api_gateway_cache_cluster_disabled |
| Review API Gateway backend client certificate settings | cloudFormation/aws/api_gateway_without_ssl_certificate |
| API Gateway invocation scope for Lambda needs review | cloudFormation/aws/public_lambda_via_api_gateway |
| Review AWS WAF protection for API Gateway | cloudFormation/aws/api_gateway_without_waf |
| AWS Config aggregator limited to selected Regions | cloudFormation/aws/config_configuration_aggregator_to_all_regions_disabled |
| AWS Support policy without an attachment target | cloudFormation/aws/support_has_no_role_associated |
| Review the access key age threshold | cloudFormation/aws/access_key_not_rotated_within_90_days |
| Alexa Skill secret storage needs review | cloudFormation/aws/alexa_skill_plaintext_client_secret_exposed |
| Review Amazon MQ broker logging | cloudFormation/aws/mq_broker_logging_disabled |
| Exposed Amplify app access token | cloudFormation/aws/amplify_app_access_token_exposed |
| Exposed Amplify app Basic Auth password | cloudFormation/aws/amplify_app_basic_auth_config_password_exposed |
| Exposed Amplify app OAuth token | cloudFormation/aws/amplify_app_oauth_token_exposed |
| Exposed Amplify branch Basic Auth password | cloudFormation/aws/amplify_branch_basic_auth_config_password_exposed |
| Review load balancer attachment for an Auto Scaling group | cloudFormation/aws/auto_scaling_group_with_no_associated_elb |
| CloudFormation stack notifications not configured | cloudFormation/aws/stack_notifications_disabled |
| Credentials are embedded in a CloudFormation template | cloudFormation/aws/cloudformation_specifying_credentials_not_safe |
| Review CloudFront distribution and origin configuration | cloudFormation/aws/cdn_configuration_is_missing |
| Review CloudFront domain and certificate settings | cloudFormation/aws/vulnerable_default_ssl_certificate |
| CloudFront request logging is not configured | cloudFormation/aws/cloudfront_logging_disabled |
| Review the CloudFront TLS security policy | cloudFormation/aws/secure_ciphers_disabled |
| CloudFront minimum TLS version is too low | cloudFormation/aws/cloudfront_without_minimum_protocol_tls_1.2 |
| CloudFront allows HTTP viewer connections | cloudFormation/aws/cloudfront_viewer_protocol_policy_allows_http |
| CloudFront is not associated with AWS WAF | cloudFormation/aws/cloudfront_without_waf |
| Traffic between CloudFront and the origin is not encrypted | cloudFormation/aws/connection_between_cloudfront_origin_not_encrypted |
| CloudTrail not integrated with CloudWatch Logs | cloudFormation/aws/cloudtrail_not_integrated_with_cloudwatch |
| CloudTrail SNS notification topic not configured | cloudFormation/aws/cloudtrail_sns_topic_name_undefined |
| CloudTrail multi-Region logging disabled | cloudFormation/aws/cloudtrail_multi_region_disabled |
| CloudTrail logs without a configured KMS key | cloudFormation/aws/cloudtrail_log_files_not_encrypted_with_kms |
| CloudTrail log file validation disabled | cloudFormation/aws/cloudtrail_log_file_validation_disabled |
| CloudTrail trail logging is stopped | cloudFormation/aws/cloudtrail_logging_disabled |
| CloudTrail log bucket access logging needs review | cloudFormation/aws/s3_bucket_cloudtrail_logging_disabled |
| CodeBuild artifact encryption key needs review | cloudFormation/aws/codebuild_not_encrypted |
| Cognito user pool without MFA | cloudFormation/aws/cognito_userpool_without_mfa |
| Review DocumentDB audit and profiler logging | cloudFormation/aws/docdb_logging_disabled |
| DynamoDB point-in-time recovery disabled | cloudFormation/aws/dynamodb_table_point_in_time_recovery_disabled |
| Invalid DynamoDB billing mode | cloudFormation/aws/dynamodb_with_table_billing_mode_not_recommended |
| EBS volume without a specified KMS key | cloudFormation/aws/ebs_volume_without_kms_key_id |
| EBS volume not attached to an instance | cloudFormation/aws/ebs_volume_not_attached_to_instances |
| Duplicate network ACL rule number | cloudFormation/aws/ec2_network_acl_duplicate_rule |
| Review EC2 detailed monitoring | cloudFormation/aws/ec2_instance_monitoring_disabled |
| EC2 instance uses the default VPC | cloudFormation/aws/ec2_instance_using_default_vpc |
| Review EC2 EBS optimization | cloudFormation/aws/ec2_not_ebs_optimized |
| Review the IAM role association for the EC2 instance | cloudFormation/aws/ec2_instance_has_no_iam_role |
| Review EC2 metadata service version settings | cloudFormation/aws/instance_uses_metadata_service_IMDSv1 |
| EC2 instance uses the default security group | cloudFormation/aws/ec2_instance_using_default_security_group |
| ECR repository without a customer managed KMS key | cloudFormation/aws/ecr_repository_not_encrypted_with_CMK |
| Review ECR image scanning configuration | cloudFormation/aws/unscanned_ecr_image |
| ECR image tags can be overwritten | cloudFormation/aws/ecr_image_tag_not_immutable |
| Review ECS Container Insights settings | cloudFormation/aws/ecs_cluster_container_insights_disabled |
| Review ECS service deployment availability | cloudFormation/aws/ecs_service_without_running_tasks |
| Invalid Fargate task CPU and memory combination | cloudFormation/aws/ecs_task_definition_invalid_cpu_or_memory |
| Review the ECS task network mode | cloudFormation/aws/ecs_task_definition_network_mode_not_recommended |
| ECS container health check not configured | cloudFormation/aws/ecs_task_definition_healthcheck_missing |
| Public IP assignment for ECS tasks | cloudFormation/aws/ecs_services_assigned_with_public_ip_address |
| Review load balancer attachment for an ECS service | cloudFormation/aws/ecs_no_load_balancer_attached |
| ECS service role references a policy | cloudFormation/aws/inline_policies_are_attached_to_ecs_service |
| Review IAM roles for an ECS task | cloudFormation/aws/empty_roles_for_ecs_cluster_task_definitions |
| Review the EFS customer managed KMS key | cloudFormation/aws/efs_without_kms |
| EFS transit encryption settings need review | cloudFormation/aws/efs_volume_with_disabled_transit_encryption |
| EFS tags missing | cloudFormation/aws/efs_without_tags |
| Insufficient restrictions on EKS node group remote access | cloudFormation/aws/eks_node_group_remote_access |
| ELB access logging disabled | cloudFormation/aws/elb_access_log_disabled |
| Review ELB outbound access rules | cloudFormation/aws/elb_with_security_group_without_outbound_rules |
| Review ELB transport encryption | cloudFormation/aws/elb_without_secure_protocol |
| Review ELB inbound access rules | cloudFormation/aws/elb_with_security_group_without_inbound_rules |
| Review ELB protocol security settings | cloudFormation/aws/elb_using_insecure_protocols |
| Review EMR cluster VPC subnet selection | cloudFormation/aws/emr_wihout_vpc |
| EMR cluster has no security configuration attached | cloudFormation/aws/emr_cluster_without_security_configuration |
| Encryption disabled in an EMR security configuration | cloudFormation/aws/emr_security_configuration_encryptions_enabled |
| Review ElastiCache VPC and subnet-group selection | cloudFormation/aws/elasticache_without_vpc |
| Review default ElastiCache port use | cloudFormation/aws/elasticache_using_default_port |
| Memcached nodes placed in one Availability Zone | cloudFormation/aws/elasticache_nodes_not_created_across_multi_az |
| ElastiCache transit encryption is disabled | cloudFormation/aws/elasticache_with_disabled_transit_encryption |
| OpenSearch domain does not require HTTPS | cloudFormation/aws/elasticsearch_with_https_disabled |
| Elasticsearch domain principals need review | cloudFormation/aws/elasticsearch_without_iam_authentication |
| Review Elasticsearch and OpenSearch audit logging | cloudFormation/aws/elasticsearch_without_audit_logs |
| OpenSearch node-to-node encryption needs review | cloudFormation/aws/elasticsearch_domain_not_encrypted_node_to_node |
| OpenSearch and Elasticsearch slow logs not configured | cloudFormation/aws/elasticsearch_without_slow_logs |
| Review Elasticsearch and OpenSearch error logging | cloudFormation/aws/elasticsearch_without_es_application_logs |
| Cross-account role trust needs external-ID or MFA review | cloudFormation/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa |
| Review GameLift inbound port ranges | cloudFormation/aws/gamelift_fleet_ec2_inbound_permissions_with_port_range |
| Review the need for CloudFront geographic restrictions | cloudFormation/aws/geo_restriction_disabled |
| GitHub repository visibility needs review | cloudFormation/aws/github_repository_set_to_public |
| GuardDuty is disabled | cloudFormation/aws/guardduty_detector_disabled |
| HTTP port open to all addresses | cloudFormation/aws/http_port_open |
| IAM Access Analyzer not enabled | cloudFormation/aws/iam_access_analyzer_not_enabled |
| IAM user without group membership | cloudFormation/aws/iam_user_with_no_group |
| IAM group uses an inline policy | cloudFormation/aws/iam_groups_inline_policies |
| Neptune cluster has IAM database authentication disabled | cloudFormation/aws/neptune_cluster_with_iam_database_authentication_disabled |
| IAM password below the minimum length | cloudFormation/aws/iam_password_without_minimum_length |
| Review the number of IAM user access keys | cloudFormation/aws/iam_user_too_many_access_keys |
| IAM user console password-reset policy needs review | cloudFormation/aws/user_iam_missing_password_reset_required |
| IAM policy attached directly to users | cloudFormation/aws/iam_policies_without_groups |
| Review EC2 instance VPC association | cloudFormation/aws/instance_with_no_vpc |
| IoT policy allows all resources | cloudFormation/aws/iot_policy_allows_wildcard_resource |
| IoT policy allows all actions | cloudFormation/aws/iot_policy_allows_action_as_wildcard |
| KMS customer managed key automatic rotation disabled | cloudFormation/aws/cmk_rotation_disabled |
| KMS automatic key rotation needs review | cloudFormation/aws/kms_enable_key_rotation_disabled |
| Elasticsearch encryption key configuration needs review | cloudFormation/aws/elasticsearch_domain_encryption_with_kms_disabled |
| Lambda active X-Ray tracing not configured | cloudFormation/aws/lambda_functions_without_x-ray_tracing |
| Lambda function tags missing | cloudFormation/aws/lambda_function_without_tags |
| Retention not configured for failed asynchronous Lambda events | cloudFormation/aws/lambda_function_without_dead_letter_queue |
| Lambda invocation permission misconfigured | cloudFormation/aws/lambda_permission_misconfigured |
| Lambda invocation principal uses a wildcard | cloudFormation/aws/lambda_permission_principal_is_wildcard |
| Possible AWS credential exposure in Lambda environment variables | cloudFormation/aws/hardcoded_aws_access_key_in_lambda |
| MSK broker log export needs review | cloudFormation/aws/msk_cluster_logging_disabled |
| Neptune audit log export needs review | cloudFormation/aws/neptune_logging_is_disabled |
| Network ACL TCP/UDP port ranges need review | cloudFormation/aws/tcp_or_udp_protocol_network_acl_entry_allows_all_ports |
| Security group permits RDP from the entire internet | cloudFormation/aws/security_groups_unrestricted_access_to_rdp |
| RDS IAM database authentication is not enabled | cloudFormation/aws/iam_database_auth_not_enabled |
| RDS Multi-AZ deployment is not enabled | cloudFormation/aws/rds_multi_az_deployment_disabled |
| Review default RDS port use | cloudFormation/aws/rds_using_default_port |
| Insufficient RDS backup retention | cloudFormation/aws/low_rds_backup_retention_period |
| RDS deletion protection disabled | cloudFormation/aws/rds_db_instance_with_deletion_protection_disabled |
| RDS snapshot tag copying disabled | cloudFormation/aws/tags_not_copied_to_rds_cluster_snapshot |
| Review RDS automatic minor upgrade settings | cloudFormation/aws/automatic_minor_upgrades_disabled |
| RDS automated backups are disabled | cloudFormation/aws/rds_with_backup_disabled |
| Database cluster IAM authentication is not enabled | cloudFormation/aws/iam_db_cluster_auth_not_enabled |
| Review default Redshift port use | cloudFormation/aws/redshift_using_default_port |
| Review the Redshift cluster encryption key | cloudFormation/aws/redshift_cluster_without_kms_cmk |
| Review Redshift VPC and subnet-group selection | cloudFormation/aws/redshift_cluster_without_vpc |
| Redshift audit log export needs review | cloudFormation/aws/redshift_cluster_logging_disabled |
| Review VPC default-route purpose | cloudFormation/aws/routertable_with_default_routing |
| Review Route 53 public DNS logging to CloudWatch | cloudFormation/aws/cloudwatch_logging_disabled |
| Review S3 public ACL handling | cloudFormation/aws/s3_bucket_without_ignore_public_acl |
| Review S3 public ACL blocking | cloudFormation/aws/s3_bucket_allows_public_acl |
| Review access restrictions for S3 public policies | cloudFormation/aws/s3_bucket_without_restriction_of_public_bucket |
| S3 bucket versioning is not enabled | cloudFormation/aws/s3_bucket_without_versioning |
| Review TLS enforcement for S3 writes | cloudFormation/aws/s3_bucket_without_ssl_in_write_actions |
| Review S3 CORS scope | cloudFormation/aws/s3_bucket_with_unsecured_cors_rule |
| S3 bucket access logging needs review | cloudFormation/aws/s3_bucket_logging_disabled |
| S3 bucket policy not associated with its target | cloudFormation/aws/s3_bucket_should_have_bucket_policy |
| NotAction in an SNS allow policy | cloudFormation/aws/sns_topic_publicity_has_allow_and_not_action_simultaneously |
| SNS topic KMS encryption not configured | cloudFormation/aws/sns_topic_without_kms_master_key_id |
| Review SQS message encryption settings | cloudFormation/aws/sqs_with_sse_disabled |
| Public access in an SQS queue policy | cloudFormation/aws/sqs_policy_with_public_access |
| Review the SageMaker endpoint volume encryption key | cloudFormation/aws/sagemaker_endpoint_config_should_specify_kms_key_id_attribute |
| SageMaker notebook has no VPC subnet specified | cloudFormation/aws/sagemaker_notebook_not_placed_in_vpc |
| Direct internet access for a SageMaker notebook | cloudFormation/aws/sagemaker_enabling_internet_access |
| Secrets Manager KMS key not specified | cloudFormation/aws/secrets_manager_should_specify_kms_key_id |
| Review the Secrets Manager encryption key | cloudFormation/aws/secretsmanager_secret_without_kms |
| Review security-group VPC selection | cloudFormation/aws/security_groups_without_vpc_attached |
| Security-group or rule description missing | cloudFormation/aws/security_group_rule_without_description |
| Review single-IP security-group access | cloudFormation/aws/security_group_ingress_has_cidr_not_recommended |
| Review the need for Shield Advanced | cloudFormation/aws/shield_advanced_not_in_use |
| Review SimpleDB domain use | cloudFormation/aws/sdb_domain_declared_as_a_resource |
| Review StackSet retention on account removal | cloudFormation/aws/stack_retention_disabled |
| Encoded private key in user data | cloudFormation/aws/user_data_contains_encoded_private_key |
| VPC Flow Logs coverage needs review | cloudFormation/aws/vpc_flowlogs_disabled |
| Review the Network Firewall inspection path for a VPC | cloudFormation/aws/vpc_without_network_firewall |
| VPC gateway attachment limit exceeded | cloudFormation/aws/vpc_attached_with_too_many_gateways |
| Review the purpose of a VPC without subnets | cloudFormation/aws/vpc_without_attached_subnet |
| AWS Batch job definition with privileged mode enabled | cloudFormation/aws/batch_job_definition_with_privileged_container_properties |
| Overlapping port ranges in network ACL rules | cloudFormation/aws/ec2_network_acl_overlapping_ports |
| DynamoDB uses an AWS owned key | cloudFormation/aws/dynamodb_with_aws_owned_cmk |
| Review S3 public-policy blocking | cloudFormation/aws/s3_bucket_with_public_policy |
| RDS-associated security group has an unrestricted ingress range | cloudFormation/aws/db_security_group_with_public_scope |
| RDS-linked subnet uses a /0 CIDR | cloudFormation/aws/rds_associated_with_public_subnet |
| S3 bucket ACL is PublicReadWrite | cloudFormation/aws/s3_bucket_acl_allows_read_or_write_to_all_users |
| ECR repository policy uses a wildcard principal | cloudFormation/aws/ecr_repository_is_publicly_accessible |
| SNS topic policy has a wildcard or missing principal | cloudFormation/aws/sns_topic_is_publicly_accessible |
| AWS DMS replication instance has public accessibility enabled or unset | cloudFormation/aws/amazon_dms_replication_instance_is_publicly_accessible |
| RDS instance enables public access | cloudFormation/aws/rds_db_instance_publicly_accessible |
| Review protocols allowed by a network ACL | cloudFormation/aws/ec2_permissive_network_acl_protocols |
| Security group exposes administrative ports | cloudFormation/aws/security_groups_with_exhibited_admin_ports |
| ECS service role permissions need review | cloudFormation/aws/ecs_service_admin_role_is_present |
| Default database KMS key usage | cloudFormation/aws/default_kms_key_usage |
| Review a web ACL default-allow policy | cloudFormation/aws/webacl_allow_defaultaction |
| Security group permits a broad source range | cloudFormation/aws/db_security_group_open_to_large_scope |
| IAM policy grants excessive data read access | cloudFormation/aws/iam_policy_allows_for_data_exfiltration |
| Review service records in a Route 53 hosted zone | cloudFormation/aws/route53_record_undefined |
| AWS access key ownership and permissions need review | cloudFormation/aws/root_account_has_active_access_keys |
| Security group allows all ports from all addresses | cloudFormation/aws/fully_open_ingress |
| S3 bucket policy uses a wildcard principal for delete actions | cloudFormation/aws/s3_bucket_allows_delete_actions_from_all_principals |
| S3 Get permissions for a wildcard principal | cloudFormation/aws/s3_bucket_allows_get_actions_from_all_principals |
| S3 bucket policy uses a wildcard principal for put actions | cloudFormation/aws/s3_bucket_allows_put_actions_from_all_principals |
| S3 object restoration permissions for a wildcard principal | cloudFormation/aws/s3_bucket_allows_restore_actions_from_all_principals |
| S3 listing permissions for a wildcard principal | cloudFormation/aws/s3_bucket_allows_list_actions_from_all_principals |
| S3 bucket policy has a wildcard or missing principal | cloudFormation/aws/s3_bucket_access_to_any_principal |
| S3 bucket policy uses wildcards for Action and Principal | cloudFormation/aws/s3_bucket_with_all_permissions |
| S3 bucket ACL permits listing by all users | cloudFormation/aws/s3_bucket_acl_allows_read_to_all_users |
| AssumeRole permission targets all roles | cloudFormation/aws/iam_policy_grants_assumerole_permission_across_all_services |
| Review account-wide trust in an IAM role | cloudFormation/aws/iam_role_allows_all_principals_to_assume |
| Review principals allowed by a KMS key policy | cloudFormation/aws/kms_allows_wildcard_principal |
| Security group allows all ports from the internet | cloudFormation/aws/security_groups_with_meta_ip |
| EC2 security group exposes a sensitive port to all addresses | cloudFormation/aws/ec2_sensitive_port_is_publicly_exposed |
| ELB security group exposes a sensitive port to all addresses | cloudFormation/aws/elb_sensitive_port_is_exposed_to_entire_network |
| Security group allows SSH from all addresses | cloudFormation/aws/security_groups_with_unrestricted_access_to_ssh |
| Security group egress allows all destination addresses | cloudFormation/aws/security_group_egress_cidr_open_to_world |
| Security group egress allows all protocols | cloudFormation/aws/security_group_egress_with_all_protocols |
| Review security group egress port ranges | cloudFormation/aws/security_group_egress_with_port_range |
| Security group ingress allows all protocols | cloudFormation/aws/security_group_ingress_with_all_protocols |
| Review security group ingress port ranges | cloudFormation/aws/security_group_ingress_with_port_range |
| Security group allows unrestricted outbound traffic | cloudFormation/aws/security_groups_allows_unrestricted_outbound_traffic |
| KMS key availability needs review | cloudFormation/aws/cmk_is_unusable |
| IAM group has no users | cloudFormation/aws/iam_group_without_users |
| IAM policies are attached directly to a user | cloudFormation/aws/iam_policies_attached_to_user |
| IAM policy resource is attached directly to users | cloudFormation/aws/iam_policy_on_user |
| Managed IAM policy is attached directly to a user | cloudFormation/aws/iam_managed_policy_applied_to_a_user |
| Kinesis stream without server-side encryption | cloudFormation/aws/kinesis_sse_not_configured |
| DynamoDB encryption key settings need review | cloudFormation/aws/dynamodb_table_not_encrypted |
| Review S3 bucket default encryption policy | cloudFormation/aws/s3_bucket_without_server_side_encryption |
| Automatic public IP assignment enabled for a subnet | cloudFormation/aws/ec2_instance_subnet_has_public_ip_mapping_on_launch |
| Public EC2 instance exposure through its subnet | cloudFormation/aws/ec2_public_instance_exposed_through_subnet |
| Externally allowed port range needs review | cloudFormation/aws/unknown_port_exposed_to_internet |
| EBS encryption monitoring needs review | cloudFormation/aws/config_rule_for_encryption_volumes_disabled |
| Amazon MQ encryption key settings need review | cloudFormation/aws/amazon_mq_broker_encryption_disabled |
| EKS encryption key configuration needs review | cloudFormation/aws/eks_cluster_encryption_disabled |
| SageMaker notebook encryption key settings need review | cloudFormation/aws/sagemaker_data_encryption_disabled |
| API Gateway cache encryption is disabled | cloudFormation/aws/api_gateway_cache_encrypted_disabled |
| EBS volume encryption needs review | cloudFormation/aws/ebs_volume_encryption_disabled |
| EFS file system with encryption disabled | cloudFormation/aws/efs_not_encrypted |
| WorkSpaces without configured encryption | cloudFormation/aws/workspace_without_encryption |
| DAX cluster encryption at rest is disabled | cloudFormation/aws/dax_cluster_not_encrypted |
| EBS block-device encryption needs review | cloudFormation/aws/block_device_is_not_encrypted |
| Database storage encryption needs review | cloudFormation/aws/cmk_unencrypted_storage |
| ELB TLS security policy needs review | cloudFormation/aws/elb_using_weak_ciphers |
| Lambda functions share an execution role | cloudFormation/aws/lambda_functions_without_unique_iam_roles |
| Amazon MQ broker has public access enabled | cloudFormation/aws/mq_broker_is_publicly_accessible |
| Amazon MSK brokers have public access enabled | cloudFormation/aws/msk_broker_is_publicly_accessible |
| Redshift public-access settings need review | cloudFormation/aws/redshift_publicly_accessible |
| S3 bucket ACL permits listing by any AWS account | cloudFormation/aws/s3_bucket_acl_allows_read_to_any_authenticated_user |
| RDP port is open to the internet | cloudFormation/aws/remote_desktop_port_open_to_internet |
| Neptune database cluster with storage encryption disabled | cloudFormation/aws/neptune_database_cluster_encryption_disabled |
| RDS instance storage encryption settings need review | cloudFormation/aws/rds_storage_not_encrypted |
| RDS cluster storage encryption settings need review | cloudFormation/aws/rds_storage_encryption_disabled |
| Redshift storage encryption settings need review | cloudFormation/aws/redshift_not_encrypted |
| MSK cluster encryption settings need review | cloudFormation/aws/msk_cluster_encryption_disabled |
| ECS EFS transport encryption needs review | cloudFormation/aws/ecs_cluster_not_encrypted_at_rest |
| ElastiCache Redis replication group with encryption at rest disabled | cloudFormation/aws/elasticache_with_disabled_at_rest_encryption |
| Elasticsearch domain with encryption at rest disabled | cloudFormation/aws/elasticsearch_not_encrypted_at_rest |
| Lambda execution role may have excessive permissions | cloudFormation/aws/lambda_functions_with_full_privileges |
| IAM policy allows all actions and resources | cloudFormation/aws/iam_policy_grants_full_permissions |
| IAM policy allows full privileges | cloudFormation/aws/iam_policies_with_full_privileges |
| KMS key policy permissions need review | cloudFormation/aws/kms_key_with_full_permissions |
| Security group ingress allows all source addresses | cloudFormation/aws/unrestricted_security_group_ingress |
| S3 bucket has static website hosting configured | cloudFormation/aws/s3_static_website_host_enabled |
| Default security group retains traffic rules | cloudFormation/aws/default_security_groups_with_unrestricted_traffic |
| Plaintext master password in a DocumentDB cluster | cloudFormation/aws/docdb_cluster_master_password_in_plaintext |
| Plaintext password in DMS MongoDB endpoint settings | cloudFormation/aws/dms_endpoint_mongo_db_settings_password_exposed |
| Plaintext password in a DMS endpoint | cloudFormation/aws/dms_endpoint_password_exposed |
| Plaintext password in Directory Service Microsoft AD | cloudFormation/aws/directory_service_microsoft_ad_password_set_to_plaintext_or_default_ref |
| Plaintext password in Directory Service Simple AD | cloudFormation/aws/directory_service_simple_ad_password_exposed |
| IAM login password may be exposed in the template | cloudFormation/aws/iam_user_login_profile_password_is_in_plaintext |
| Plaintext Alexa ASK skill refresh token | cloudFormation/aws/refresh_token_is_exposed |
| Review the scope of network ACL deny rules | cloudFormation/aws/ec2_network_acl_ineffective_denied_traffic |