Documentation
| Article | Path |
|---|---|
| Review usage plan associations for deployed API Gateway stages | terraform/aws/api_gateway_deployment_without_api_gateway_usage_plan_associated |
| Review API Gateway stage usage plan associations | terraform/aws/api_gateway_stage_without_api_gateway_usage_plan_associated |
| API Gateway X-Ray tracing disabled | terraform/aws/api_gateway_xray_disabled |
| Review API Gateway response compression | terraform/aws/api_gateway_with_invalid_compression |
| Review the scope of API Gateway permission to invoke Lambda | terraform/aws/public_lambda_via_api_gateway |
| Review API Gateway API key usage management | terraform/aws/api_gateway_method_does_not_contains_an_api_key |
| Review the Regions included in AWS Config aggregation | terraform/aws/config_configuration_aggregator_to_all_regions_disabled |
| CloudWatch alarm missing for AWS Config changes | terraform/aws/cloudwatch_aws_config_configuration_changes_alarm_missing |
| CloudWatch alarm missing for console sign-in failures | terraform/aws/cloudwatch_management_console_auth_failed_alarm_missing |
| Missing alarm for AWS Organizations changes | terraform/aws/cloudwatch_aws_organizations_changes_missing_alarm |
| Review the need for AWS Shield Advanced | terraform/aws/shield_advanced_not_in_use |
| SNS topic encrypted with an AWS managed key | terraform/aws/sns_topic_encrypted_with_aws_managed_key |
| Secrets Manager secret encrypted with an AWS managed key | terraform/aws/secretsmanager_secret_encrypted_with_aws_managed_key |
| Review API Gateway REST API authentication | terraform/aws/api_gateway_without_configured_authorizer |
| Auto Scaling group tags are missing | terraform/aws/autoscaling_groups_supply_tags |
| Review Base64-encoded private keys in launch configuration user data | terraform/aws/user_data_contains_encoded_private_key |
| Review CloudFront content delivery configuration | terraform/aws/cdn_configuration_is_missing |
| Review CloudFormation stack notifications | terraform/aws/stack_notifications_disabled |
| CloudFormation stack policy missing | terraform/aws/no_stack_policy |
| CloudFormation stack template is missing | terraform/aws/stack_without_template |
| Review the CloudFront TLS security policy | terraform/aws/secure_ciphers_disabled |
| CloudTrail log-file delivery notifications are not configured | terraform/aws/cloudtrail_sns_topic_name_undefined |
| Review KMS key settings for CloudTrail logs | terraform/aws/cloudtrail_log_files_not_encrypted_with_kms |
| CloudTrail log integrity digests are disabled | terraform/aws/cloudtrail_log_file_validation_disabled |
| Review CloudTrail regional and global-event coverage | terraform/aws/cloudtrail_multi_region_disabled |
| CloudWatch alarm missing for CloudTrail changes | terraform/aws/cloudwatch_cloudtrail_configuration_changes_alarm_missing |
| CloudTrail is not integrated with CloudWatch Logs | terraform/aws/cloudtrail_not_integrated_with_cloudwatch |
| CloudWatch Logs destination policy grants excessive access | terraform/aws/cloudwatch_logs_destination_with_vulnerable_policy |
| API Gateway detailed method metrics are disabled | terraform/aws/cloudwatch_metrics_disabled |
| Route 53 public DNS query logging is not configured | terraform/aws/cloudwatch_logging_disabled |
| Review CloudWatch log retention | terraform/aws/cloudwatch_without_retention_period_specified |
| Review API Gateway CloudWatch log delivery | terraform/aws/api_gateway_with_cloudwatch_logging_disabled |
| CodeBuild project using an AWS managed key | terraform/aws/codebuild_project_encrypted_with_aws_managed_key |
| Review Cognito User Pool MFA coverage | terraform/aws/cognito_userpool_without_mfa |
| Review DocumentDB encryption key management | terraform/aws/docdb_cluster_encrypted_with_aws_managed_key |
| Review DynamoDB gateway endpoint routing associations | terraform/aws/dynamodb_vpc_endpoint_without_route_table_association |
| DynamoDB point-in-time recovery is disabled | terraform/aws/dynamodb_table_point_in_time_recovery_disabled |
| Review EC2 EBS optimization settings | terraform/aws/ec2_not_ebs_optimized |
| Review AWS credentials in EC2 user data | terraform/aws/hardcoded_aws_access_key |
| Review IMDSv1 access to EC2 metadata | terraform/aws/instance_uses_metadata_service_IMDSv1 |
| Review EC2 subnet and security-group selection | terraform/aws/instance_with_no_vpc |
| Review an EC2 instance’s use of the default VPC | terraform/aws/ec2_instance_using_default_vpc |
| AWS access keys deployed directly to an EC2 instance | terraform/aws/ec2_instance_using_api_keys |
| Review ECR repository encryption key management | terraform/aws/ecr_repository_not_encrypted |
| Review ECR repository access policies | terraform/aws/ecr_repository_without_policy |
| Review ECR image vulnerability scanning | terraform/aws/unscanned_ecr_image |
| Review ECS Container Insights settings | terraform/aws/ecs_cluster_container_insights_disabled |
| Review the required ECS service task count | terraform/aws/ecs_service_without_running_tasks |
| Review the EFS customer managed KMS key | terraform/aws/efs_without_kms |
| EKS control plane log types missing | terraform/aws/missing_cluster_log_types |
| Review EMR cluster subnet selection | terraform/aws/emr_without_vpc |
| Configuration without an ENCRYPTED_VOLUMES AWS Config rule | terraform/aws/config_rule_for_encrypted_volumes_is_disabled |
| Review the ElastiCache engine choice | terraform/aws/redis_disabled |
| Review ElastiCache subnet group selection | terraform/aws/elasticache_without_vpc |
| Review ElastiCache default ports and access controls | terraform/aws/elasticache_using_default_port |
| Review Elasticsearch slow-log settings | terraform/aws/elasticsearch_without_slow_logs |
| Cross-account IAM role trust conditions need review | terraform/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa |
| GuardDuty detector is disabled | terraform/aws/guardduty_detector_disabled |
| Review HTTPS enforcement for the S3 bucket | terraform/aws/s3_bucket_policy_accepts_http_requests |
| HTTP port 80 is open to the internet | terraform/aws/http_port_open |
| Elasticsearch domain does not enforce HTTPS | terraform/aws/elasticsearch_with_https_disabled |
| AWS ALB listener using HTTP | terraform/aws/alb_listening_on_http |
| CloudFront viewer policy allows HTTP | terraform/aws/cloudfront_viewer_protocol_policy_allows_http |
| Review IAM Access Analyzer configuration | terraform/aws/iam_access_analyzer_not_enabled |
| Neptune cluster has IAM database authentication disabled | terraform/aws/neptune_cluster_with_iam_database_authentication_disabled |
| Review IAM password expiration policy | terraform/aws/misconfigured_password_policy_expiration |
| Review IAM password reuse prevention | terraform/aws/password_without_reuse_prevention |
| Review IAM password minimum length | terraform/aws/iam_password_without_minimum_length |
| Review MFA requirements in IAM user policies | terraform/aws/iam_user_policy_without_mfa |
| Review IAM access controls for an Elasticsearch domain | terraform/aws/elasticsearch_without_iam_authentication |
| Missing alarm for IAM policy changes | terraform/aws/cloudwatch_iam_policy_changes_alarm_missing |
| Review customer managed KMS key rotation | terraform/aws/cmk_rotation_disabled |
| AWS Kinesis stream without KMS encryption | terraform/aws/kinesis_not_encrypted_with_kms |
| Review the encryption key for a CloudWatch log group | terraform/aws/cloudwatch_log_group_not_encrypted |
| Review the KMS key deletion waiting period | terraform/aws/kms_key_with_no_deletion_window |
| DocumentDB encryption key settings need review | terraform/aws/docdb_cluster_without_kms |
| Review Elasticsearch encryption key settings | terraform/aws/elasticsearch_encryption_with_kms_is_disabled |
| Review SageMaker notebook encryption keys | terraform/aws/sagemaker_notebook_instance_without_kms |
| Review encryption key settings for a Secrets Manager secret | terraform/aws/secretsmanager_secret_without_kms |
| Review retention of failed Lambda asynchronous events | terraform/aws/lambda_function_without_dead_letter_queue |
| Review IAM resource scope for Lambda InvokeFunction | terraform/aws/lambda_iam_invokefunction_misconfigured |
| Review the action in Lambda permission | terraform/aws/lambda_permission_misconfigured |
| Review Lambda X-Ray tracing configuration | terraform/aws/lambda_functions_without_x-ray_tracing |
| Review AWS credentials in Lambda environment variables | terraform/aws/hardcoded_aws_access_key_in_lambda |
| Review MFA requirements for IAM user access | terraform/aws/authentication_without_mfa |
| Missing alarm for console sign-ins without MFA | terraform/aws/cloudwatch_management_console_sign_in_without_mfa_alarm_missing |
| Review MQ broker logging | terraform/aws/mq_broker_logging_disabled |
| Review MSK broker logging | terraform/aws/msk_cluster_logging_disabled |
| CloudWatch alarm missing for network ACL changes | terraform/aws/cloudwatch_changes_to_nacl_alarm_missing |
| Review Neptune audit log exports | terraform/aws/neptune_logging_disabled |
| Review Network Firewall use in the VPC | terraform/aws/vpc_without_network_firewall |
| Review API Gateway endpoint exposure | terraform/aws/api_gateway_endpoint_config_is_not_private |
| Review query logging settings for RDS for PostgreSQL | terraform/aws/postgres_rds_logging_disabled |
| Resource-based policy has no Principal | terraform/aws/policy_without_principal |
| AWS Network ACL allows RDP from all addresses | terraform/aws/network_acl_with_unrestricted_access_to_rdp |
| AWS security group allows RDP from all addresses | terraform/aws/remote_desktop_port_open_to_internet |
| Review RDS default ports and access controls | terraform/aws/rds_using_default_port |
| Review RDS CloudWatch log exports | terraform/aws/rds_without_logging |
| RDS instance automated backups disabled | terraform/aws/rds_with_backup_disabled |
| IAM database authentication is not enabled for an RDS instance | terraform/aws/iam_database_auth_not_enabled |
| RDS automatic minor upgrades are disabled | terraform/aws/automatic_minor_upgrades_disabled |
| Review RDS cluster backup retention | terraform/aws/rds_cluster_with_backup_disabled |
| Review RDS snapshot tag copying | terraform/aws/tags_not_copied_to_rds_cluster_snapshot |
| IAM database authentication is not enabled for an RDS cluster | terraform/aws/iam_db_cluster_auth_not_enabled |
| TLS certificate has a short RSA key | terraform/aws/certificate_rsa_key_bytes_lower_than_256 |
| Review Redshift default ports and access controls | terraform/aws/redshift_using_default_port |
| Review Redshift cluster network selection | terraform/aws/redshift_cluster_without_vpc |
| Review Redshift audit logging | terraform/aws/redshift_cluster_logging_disabled |
| Review S3 object-level CloudTrail data event coverage | terraform/aws/s3_bucket_object_level_cloudtrail_logging_disabled |
| Review S3 bucket MFA Delete use | terraform/aws/s3_bucket_without_enabled_mfa_delete |
| Review S3 server access logging | terraform/aws/s3_bucket_logging_disabled |
| Review S3 bucket event notifications | terraform/aws/s3_bucket_notifications_disabled |
| CloudWatch alarm missing for S3 bucket policy changes | terraform/aws/cloudwatch_s3_policy_change_alarm_missing |
| SQL Analysis Services port 2383 allows unrestricted access | terraform/aws/sql_analysis_services_port_2383_is_publicly_accessible |
| Review DNS settings for the SQS VPC endpoint | terraform/aws/sqs_vpc_endpoint_without_dns_resolution |
| Review SQS queue-level encryption | terraform/aws/sqs_with_sse_disabled |
| Network ACL allows SSH from a broad address range | terraform/aws/network_acl_with_unrestricted_access_to_ssh |
| Security group allows SSH from the entire internet | terraform/aws/security_group_with_unrestricted_access_to_ssh |
| Review API Gateway backend client certificate settings | terraform/aws/api_gateway_without_ssl_certificate |
| Review additional KMS encryption for SSM sessions | terraform/aws/ssm_session_transit_encryption_disabled |
| Review IAM Identity Center permission-set session duration | terraform/aws/sso_permission_with_inadequate_user_session_duration |
| Security group rule descriptions are missing | terraform/aws/security_group_rules_without_description |
| Review security group descriptions | terraform/aws/security_group_without_description |
| AWS Organizations configuration cannot use Service Control Policies | terraform/aws/service_control_policies_disabled |
| Review StackSet stack retention | terraform/aws/stack_retention_disabled |
| AWS Identity Center users created directly with Terraform | terraform/aws/sso_policy_with_full_priveleges_copy |
| Review VPC Flow Logs coverage | terraform/aws/vpc_flowlogs_disabled |
| CloudWatch alarm missing for VPC changes | terraform/aws/cloudwatch_vpc_changes_alarm_missing |
| Review AWS WAF protection for API Gateway | terraform/aws/api_gateway_without_waf |
| Review the CloudFront WAF association | terraform/aws/cloudfront_without_waf |
| AWS ALB not associated with WAF | terraform/aws/alb_is_not_integrated_with_waf |
| S3 bucket ACL specifies WRITE_ACP permission | terraform/aws/s3_bucket_acl_grants_write_acp_permission |
SNS topic policy combines Effect: Allow and NotAction |
terraform/aws/sns_topic_publicity_has_allow_and_not_action_simultaneously |
| IAM group has excessive CloudFormation and PassRole permissions | terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack |
| IAM user has excessive CloudFormation creation and PassRole permissions | terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack |
IAM role can escalate privileges through cloudformation:CreateStack and iam:PassRole |
terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack |
| IAM group has excessive EC2 launch and PassRole permissions | terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances |
| IAM user has excessive EC2 launch and PassRole permissions | terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances |
IAM role can escalate privileges through ec2:RunInstances and iam:PassRole |
terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances |
| IAM group has excessive Glue creation and PassRole permissions | terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint |
| IAM user has excessive Glue creation and PassRole permissions | terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint |
IAM role can escalate privileges through glue:CreateDevEndpoint and iam:PassRole |
terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint |
| IAM group has excessive glue:UpdateDevEndpoint permissions | terraform/aws/group_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint |
| IAM user has excessive glue:UpdateDevEndpoint permissions | terraform/aws/user_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint |
IAM role can escalate privileges through glue:UpdateDevEndpoint |
terraform/aws/role_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint |
| IAM group permissions for iam:AddUserToGroup need review | terraform/aws/group_with_privilege_escalation_by_actions_iam_AddUserToGroup |
| IAM user permissions for iam:AddUserToGroup need review | terraform/aws/user_with_privilege_escalation_by_actions_iam_AddUserToGroup |
| IAM role permissions for iam:AddUserToGroup need review | terraform/aws/role_with_privilege_escalation_by_actions_iam_AddUserToGroup |
| IAM group permissions for iam:AttachGroupPolicy need review | terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachGroupPolicy |
| IAM user permissions for iam:AttachGroupPolicy need review | terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachGroupPolicy |
| IAM role permissions for iam:AttachGroupPolicy need review | terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachGroupPolicy |
| IAM group permissions for iam:AttachRolePolicy need review | terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachRolePolicy |
| IAM user permissions for iam:AttachRolePolicy need review | terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachRolePolicy |
| IAM role permissions for iam:AttachRolePolicy need review | terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachRolePolicy |
| IAM group permissions for iam:AttachUserPolicy need review | terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachUserPolicy |
| IAM user permissions for iam:AttachUserPolicy need review | terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachUserPolicy |
| IAM role permissions for iam:AttachUserPolicy need review | terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachUserPolicy |
| IAM group has excessive iam:CreateAccessKey permissions | terraform/aws/group_with_privilege_escalation_by_actions_iam_CreateAccessKey |
| IAM user has excessive iam:CreateAccessKey permissions | terraform/aws/user_with_privilege_escalation_by_actions_iam_CreateAccessKey |
IAM role can escalate privileges through iam:CreateAccessKey |
terraform/aws/role_with_privilege_escalation_by_actions_iam_CreateAccessKey |
| IAM group has excessive iam:CreateLoginProfile permissions | terraform/aws/group_with_privilege_escalation_by_actions_iam_CreateLoginProfile |
| IAM user has excessive iam:CreateLoginProfile permissions | terraform/aws/user_with_privilege_escalation_by_actions_iam_CreateLoginProfile |
IAM role can escalate privileges through iam:CreateLoginProfile |
terraform/aws/role_with_privilege_escalation_by_actions_iam_CreateLoginProfile |
| IAM group permissions for iam:CreatePolicyVersion need review | terraform/aws/group_with_privilege_escalation_by_actions_iam_CreatePolicyVersion |
| IAM user permissions for iam:CreatePolicyVersion need review | terraform/aws/user_with_privilege_escalation_by_actions_iam_CreatePolicyVersion |
| IAM role permissions for iam:CreatePolicyVersion need review | terraform/aws/role_with_privilege_escalation_by_actions_iam_CreatePolicyVersion |
| IAM group permissions for iam:PutGroupPolicy need review | terraform/aws/group_with_privilege_escalation_by_actions_iam_PutGroupPolicy |
| IAM user permissions for iam:PutGroupPolicy need review | terraform/aws/user_with_privilege_escalation_by_actions_iam_PutGroupPolicy |
| IAM role permissions for iam:PutGroupPolicy need review | terraform/aws/role_with_privilege_escalation_by_actions_iam_PutGroupPolicy |
| IAM group permissions for iam:PutRolePolicy need review | terraform/aws/group_with_privilege_escalation_by_actions_iam_PutRolePolicy |
| IAM user permissions for iam:PutRolePolicy need review | terraform/aws/user_with_privilege_escalation_by_actions_iam_PutRolePolicy |
| IAM role permissions for iam:PutRolePolicy need review | terraform/aws/role_with_privilege_escalation_by_actions_iam_PutRolePolicy |
| IAM group permissions for iam:PutUserPolicy need review | terraform/aws/group_with_privilege_escalation_by_actions_iam_PutUserPolicy |
| IAM user permissions for iam:PutUserPolicy need review | terraform/aws/user_with_privilege_escalation_by_actions_iam_PutUserPolicy |
| IAM role permissions for iam:PutUserPolicy need review | terraform/aws/role_with_privilege_escalation_by_actions_iam_PutUserPolicy |
| IAM group permissions for iam:SetDefaultPolicyVersion need review | terraform/aws/group_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion |
| IAM user permissions for iam:SetDefaultPolicyVersion need review | terraform/aws/user_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion |
| IAM role permissions for iam:SetDefaultPolicyVersion need review | terraform/aws/role_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion |
| IAM group has excessive trust-policy update and role-assumption permissions | terraform/aws/group_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole |
| IAM user has excessive trust-policy update and role-assumption permissions | terraform/aws/user_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole |
IAM role can escalate privileges through iam:UpdateAssumeRolePolicy and sts:AssumeRole |
terraform/aws/role_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole |
| IAM group has excessive iam:UpdateLoginProfile permissions | terraform/aws/group_with_privilege_escalation_by_actions_iam_UpdateLoginProfile |
| IAM user has excessive iam:UpdateLoginProfile permissions | terraform/aws/user_with_privilege_escalation_by_actions_iam_UpdateLoginProfile |
IAM role can escalate privileges through iam:UpdateLoginProfile |
terraform/aws/role_with_privilege_escalation_by_actions_iam_UpdateLoginProfile |
| IAM group has excessive Lambda creation, invocation and PassRole permissions | terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_and_lambda_InvokeFunction |
| IAM user has excessive Lambda creation, invocation and PassRole permissions | terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_and_lambda_InvokeFunction |
IAM role can escalate privileges through lambda:CreateFunction, lambda:InvokeFunction and iam:PassRole |
terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_lambda_InvokeFunction |
| IAM group has excessive lambda:UpdateFunctionCode permissions | terraform/aws/group_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode |
| IAM user has excessive lambda:UpdateFunctionCode permissions | terraform/aws/user_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode |
IAM role can escalate privileges through lambda:UpdateFunctionCode |
terraform/aws/role_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode |
| AWS Batch job definition enables privileged containers | terraform/aws/batch_job_definition_with_privileged_container_properties |
| Review EKS encryption key settings | terraform/aws/eks_cluster_encryption_disabled |
| IAM policy attached directly to a user | terraform/aws/iam_policies_attached_to_user |
| CloudWatch alarm missing for KMS key changes | terraform/aws/cloudwatch_disabling_or_scheduled_deletion_of_customer_created_cmk_alarm_missing |
| Review S3 public ACL suppression | terraform/aws/s3_bucket_without_ignore_public_acl |
| S3 bucket combines a public ACL with Block Public Access | terraform/aws/s3_bucket_public_acl_overridden_by_public_access_block |
| Review S3 public ACL blocking | terraform/aws/s3_bucket_allows_public_acl |
| Review S3 public bucket policy blocking | terraform/aws/s3_bucket_with_public_policy |
| RDS configuration uses a /0 subnet CIDR | terraform/aws/rds_associated_with_public_subnet |
| Legacy DB security group allows all source addresses | terraform/aws/db_security_group_has_public_interface |
| DMS replication instance enables public access | terraform/aws/amazon_dms_replication_instance_is_publicly_accessible |
| SQS queue policy public principals need review | terraform/aws/sqs_policy_with_public_access |
| Publicly accessible AWS MQ broker | terraform/aws/mq_broker_is_publicly_accessible |
| Publicly accessible AWS MSK broker | terraform/aws/msk_broker_is_publicly_accessible |
| Publicly accessible AWS Neptune cluster instance | terraform/aws/neptune_cluster_instance_is_publicly_accessible |
| ECR repository policy uses wildcard principals | terraform/aws/ecr_repository_is_publicly_accessible |
| SNS topic policy uses a wildcard principal | terraform/aws/sns_topic_is_publicly_accessible |
| CloudTrail log bucket public access needs review | terraform/aws/cloudtrail_log_files_s3_bucket_is_publicly_accessible |
| RDS public-access configuration needs review | terraform/aws/rds_db_instance_publicly_accessible |
| Review public IP assignment for EC2 instances | terraform/aws/ec2_instance_has_public_ip |
| ECS service assigned public IP addresses | terraform/aws/ecs_services_assigned_with_public_ip_address |
| VPC subnet automatically assigns public IP addresses | terraform/aws/vpc_subnet_assigns_public_ip |
| Legacy DB security-group source range needs review | terraform/aws/db_security_group_open_to_large_scope |
| IAM role trust policy needs review | terraform/aws/iam_role_with_full_privileges |
| KMS key access policy needs review | terraform/aws/kms_key_with_full_permissions |
| Secrets Manager secret access policy needs review | terraform/aws/secrets_manager_with_vulnerable_policy |
| AWS ECS service role permissions need review | terraform/aws/ecs_service_admin_role_is_present |
| Review the ECS task network mode | terraform/aws/ecs_task_definition_network_mode_not_recommended |
| AWS Lambda function with an overly privileged execution role | terraform/aws/lambda_function_with_privileged_role |
| EBS encryption by default disabled in an account and Region | terraform/aws/ebs_default_encryption_disabled |
| Review AWS default VPC configuration | terraform/aws/default_vpc_exists |
| Review default security group use on EC2 instances | terraform/aws/ec2_instance_using_default_security_group |
| Missing alarm for network gateway changes | terraform/aws/cloudwatch_network_gateways_changes_alarm_missing |
| Elasticsearch domain without node-to-node encryption | terraform/aws/elasticsearch_domain_not_encrypted_node_to_node |
| ElastiCache nodes not distributed across Availability Zones | terraform/aws/elasticache_nodes_not_created_across_multi_az |
| IAM policy can be abused for data exfiltration | terraform/aws/iam_policy_allows_for_data_exfiltration |
| Missing alarm for route table changes | terraform/aws/cloudwatch_route_table_changes_alarm_missing |
| Empty values in an AWS Route 53 record | terraform/aws/route53_record_undefined |
| Review CloudFront request logging | terraform/aws/cloudfront_logging_disabled |
| AWS CloudTrail logging disabled | terraform/aws/cloudtrail_logging_disabled |
| Review DocumentDB log exports | terraform/aws/docdb_logging_disabled |
| Review access logging for the CloudTrail log bucket | terraform/aws/cloudtrail_log_files_s3_bucket_with_logging_disabled |
| EKS cluster logging disabled | terraform/aws/eks_cluster_log_disabled |
| Review Elasticsearch log publishing | terraform/aws/elasticsearch_logs_disabled |
| CloudWatch alarm missing for root user activity | terraform/aws/cloudwatch_root_account_use_alarm_missing |
| Review access keys for an IAM user named root | terraform/aws/iam_access_key_is_exposed |
| Expired TLS certificate | terraform/aws/certificate_has_expired |
| IAM service-role trust principals need review | terraform/aws/iam_policy_grants_assumerole_permission_across_all_services |
| S3 bucket policy uses wildcard actions and principals | terraform/aws/s3_bucket_with_all_permissions |
| iam:PassRole allows every role | terraform/aws/iam_role_policy_passrole_allows_all |
| S3 bucket ACL grants read access to any authenticated AWS account | terraform/aws/s3_bucket_acl_allows_read_to_any_authenticated_user |
| SQS queue policy grants broad actions | terraform/aws/sqs_policy_allows_all_actions |
| IAM role account-wide trust needs review | terraform/aws/iam_role_allows_all_principals_to_assume |
| S3 bucket policy combines wildcard principals with delete actions | terraform/aws/s3_bucket_allows_delete_action_from_all_principals |
| S3 bucket policy combines wildcard principals with put actions | terraform/aws/s3_bucket_allows_put_action_from_all_principals |
| S3 bucket policy uses wildcard principals | terraform/aws/s3_bucket_access_to_any_principal |
| S3 bucket policy grants Get permissions to all principals | terraform/aws/s3_bucket_allows_get_action_from_all_principals |
| S3 bucket policy grants listing permissions to all principals | terraform/aws/s3_bucket_allows_list_action_from_all_principals |
| Default security-group traffic permissions need review | terraform/aws/vpc_default_security_group_accepts_all_traffic |
| AWS default security group allows traffic with all addresses | terraform/aws/default_security_groups_with_unrestricted_traffic |
| Review unused security groups | terraform/aws/security_groups_not_used |
| Review private-network access to sensitive service ports | terraform/aws/sensitive_port_is_exposed_to_wide_private_network |
| AWS security group allows management or internal-service ports from all addresses | terraform/aws/sensitive_port_is_exposed_to_entire_network |
| ElastiCache Redis automatic backups disabled | terraform/aws/elasticache_redis_cluster_without_backup |
| Review S3 versioning settings | terraform/aws/s3_bucket_without_versioning |
| CloudWatch alarm missing for security group changes | terraform/aws/cloudwatch_security_group_changes_alarm_missing |
| Review the AWS ElastiCache Redis OSS engine version | terraform/aws/redis_not_compliant |
| Review the API Gateway custom domain TLS policy | terraform/aws/api_gateway_without_security_policy |
| WorkSpace without volume encryption | terraform/aws/workspaces_workspace_volume_not_encrypted |
| Review IAM user initial password settings | terraform/aws/no_password_policy_enabled |
| AWS snapshot created from an unencrypted EBS volume | terraform/aws/ebs_volume_snapshot_not_encrypted |
| Review RDS cluster snapshot encryption | terraform/aws/rds_database_cluster_not_encrypted |
| CloudWatch monitoring for unauthorized API calls needs review | terraform/aws/cloudwatch_unauthorized_access_defined_alarm_missing |
| IAM group has no users | terraform/aws/iam_group_without_users |
| Review IAM users’ password-change permissions | terraform/aws/aws_password_policy_with_unchangeable_passwords |
| Review use of a disabled customer managed KMS key | terraform/aws/cmk_is_unusable |
| AWS ALB deletion protection disabled | terraform/aws/alb_deletion_protection_disabled |
| EC2 detailed monitoring disabled | terraform/aws/ec2_instance_monitoring_disabled |
| DynamoDB table encryption key settings need review | terraform/aws/dynamodb_table_not_encrypted |
| Review S3 object server-side encryption settings | terraform/aws/s3_bucket_object_not_encrypted |
| Amazon Data Firehose encryption settings need review | terraform/aws/kinesis_sse_not_configured |
| Review S3 CORS settings | terraform/aws/s3_bucket_with_unsecured_cors_rule |
| Review SSL/TLS protocols in ELB policies | terraform/aws/elb_using_insecure_protocols |
| AWS security-group port exposure needs review | terraform/aws/unknown_port_exposed_to_internet |
| Review MSK cluster encryption settings | terraform/aws/msk_cluster_encryption_disabled |
| Athena database query-result encryption settings need review | terraform/aws/athena_database_not_encrypted |
| Review SageMaker endpoint storage encryption keys | terraform/aws/sagemaker_endpoint_configuration_encryption_disabled |
| Amazon MQ broker encryption key settings need review | terraform/aws/amazon_mq_broker_encryption_disabled |
| Review Glue Data Catalog and connection password encryption | terraform/aws/glue_data_catalog_encryption_disabled |
| Review Glue Security Configuration encryption settings | terraform/aws/glue_security_configuration_encryption_disabled |
| SNS topic without message encryption | terraform/aws/sns_topic_not_encrypted |
| API Gateway cache without encryption | terraform/aws/api_gateway_method_settings_cache_not_encrypted |
| Unencrypted AWS AMI | terraform/aws/ami_not_encrypted |
| AWS EBS volume without encryption | terraform/aws/ebs_volume_encryption_disabled |
| AWS EFS file system without encryption | terraform/aws/efs_not_encrypted |
| AWS block-device mappings without encryption | terraform/aws/block_device_is_not_encrypted |
| AWS Classic ELB cipher policies need review | terraform/aws/elb_using_weak_ciphers |
| Review AWS AMI account sharing | terraform/aws/ami_shared_with_multiple_accounts |
| Review Elastic IP usage and association | terraform/aws/aws_eip_not_attached_to_any_instance |
| Review the Auto Scaling group load-balancer association | terraform/aws/auto_scaling_group_with_no_associated_elb |
| RDS instance uses an outdated CA certificate | terraform/aws/ca_certificate_identifier_is_outdated |
| Lambda function policy grants broad actions | terraform/aws/lambda_with_vulnerable_policy |
| Lambda invocation permission uses a wildcard principal | terraform/aws/lambda_permission_principal_is_wildcard |
| API Gateway REST API policy grants excessive access | terraform/aws/rest_api_with_vulnerable_policy |
| AWS Redshift cluster public-access settings need review | terraform/aws/redshift_publicly_accessible |
| AWS SQS queue policy access needs review | terraform/aws/sqs_queue_exposed |
| Operational tags are missing | terraform/aws/resource_not_using_tags |
| Review API Gateway method authentication | terraform/aws/api_gateway_with_open_access |
| Review source ranges for sensitive service ports | terraform/aws/sensitive_port_is_exposed_to_small_public_network |
| AWS ALB does not drop invalid headers | terraform/aws/alb_not_dropping_invalid_headers |
| Review Redshift encryption at rest | terraform/aws/redshift_not_encrypted |
| Amazon Aurora storage encryption settings need review | terraform/aws/aurora_with_disabled_at_rest_encryption |
| AWS DAX cluster without encryption at rest | terraform/aws/dax_cluster_not_encrypted |
| Amazon DocumentDB cluster without storage encryption | terraform/aws/docdb_cluster_not_encrypted |
| AWS ElastiCache replication group without encryption at rest | terraform/aws/elasticache_replication_group_not_encrypted_at_rest |
| AWS Elasticsearch domain without encryption at rest | terraform/aws/elasticsearch_not_encrypted_at_rest |
| AWS Neptune cluster without encryption at rest | terraform/aws/neptune_database_cluster_encryption_disabled |
| AWS DB instance without storage encryption | terraform/aws/db_instance_storage_not_encrypted |
| Review RDS cluster storage encryption | terraform/aws/rds_storage_not_encrypted |
| EFS volume with transit encryption disabled | terraform/aws/efs_volume_with_disabled_transit_encryption |
| ElastiCache replication group with transit encryption disabled | terraform/aws/elasticache_replication_group_not_encrypted_at_transit |
| Review destination ranges for VPC peering routes | terraform/aws/vpc_peering_route_table_with_unrestricted_cidr |
| IAM policy administrative permissions need review | terraform/aws/iam_policies_with_full_privileges |
| Identity Center permission set grants excessive access | terraform/aws/sso_policy_with_full_priveleges |
| IAM policy grants excessive permissions | terraform/aws/iam_policy_grants_full_permissions |
| S3 bucket configuration uses a public canned ACL | terraform/aws/s3_bucket_acl_allows_read_or_write_to_all_users |
| EC2-Classic DB security group allows all IPv4 addresses | terraform/aws/db_security_group_with_public_scope |
| EKS public access CIDRs allow the entire internet | terraform/aws/eks_cluster_has_public_access_cidrs |
| AWS security group allows ingress from all source addresses | terraform/aws/unrestricted_security_group_ingress |
| SES identity-policy access needs review | terraform/aws/ses_policy_with_allowed_iam_actions |
| Review access logging on an API Gateway deployment stage | terraform/aws/api_gateway_deployment_without_access_log_setting |
| Review API Gateway stage logging | terraform/aws/api_gateway_access_logging_disabled |
| Classic ELB access logging disabled | terraform/aws/elb_access_logging_disabled |
| Review ELBv2 load-balancer access logging | terraform/aws/elb_v2_lb_access_log_disabled |
| EKS node remote access has no source security groups | terraform/aws/eks_node_group_remote_access_disabled |
| Review public exposure of an AWS S3 static website | terraform/aws/s3_static_website_host_enabled |
| CloudFront security policy allows older TLS versions | terraform/aws/cloudfront_without_minimum_protocol_tls_1.2 |
| Review certificates for CloudFront custom domains | terraform/aws/vulnerable_default_ssl_certificate |
| EFS file system policy access needs review | terraform/aws/efs_with_vulnerable_policy |
| AWS Glue Data Catalog policy permissions need review | terraform/aws/glue_with_vulnerable_policy |
| Elasticsearch domain policy access needs review | terraform/aws/elasticsearch_domain_with_vulnerable_policy |
| IAM user has console access | terraform/aws/iam_user_with_access_to_console |
| Athena workgroup result encryption settings need review | terraform/aws/athena_workgroup_not_encrypted |
| Mutable image tags in an AWS ECR repository | terraform/aws/ecr_image_tag_not_immutable |
| Public and private EC2 instances share an IAM role | terraform/aws/public_and_private_ec2_share_role |
| Review restrictions on public S3 buckets | terraform/aws/s3_bucket_without_restriction_of_public_bucket |
| Public access enabled for an EKS cluster | terraform/aws/eks_cluster_has_public_access |
| Review the number of access keys for an IAM user | terraform/aws/iam_user_too_many_access_keys |
| Review active access keys for an IAM user | terraform/aws/root_account_has_active_access_keys |
| AWS Global Accelerator flow logs disabled | terraform/aws/global_accelerator_flow_logs_disabled |