AWS

Security and configuration guidance for AWS resources managed with Terraform.

Documentation

Article Path
Review usage plan associations for deployed API Gateway stages terraform/aws/api_gateway_deployment_without_api_gateway_usage_plan_associated
Review API Gateway stage usage plan associations terraform/aws/api_gateway_stage_without_api_gateway_usage_plan_associated
API Gateway X-Ray tracing disabled terraform/aws/api_gateway_xray_disabled
Review API Gateway response compression terraform/aws/api_gateway_with_invalid_compression
Review the scope of API Gateway permission to invoke Lambda terraform/aws/public_lambda_via_api_gateway
Review API Gateway API key usage management terraform/aws/api_gateway_method_does_not_contains_an_api_key
Review the Regions included in AWS Config aggregation terraform/aws/config_configuration_aggregator_to_all_regions_disabled
CloudWatch alarm missing for AWS Config changes terraform/aws/cloudwatch_aws_config_configuration_changes_alarm_missing
CloudWatch alarm missing for console sign-in failures terraform/aws/cloudwatch_management_console_auth_failed_alarm_missing
Missing alarm for AWS Organizations changes terraform/aws/cloudwatch_aws_organizations_changes_missing_alarm
Review the need for AWS Shield Advanced terraform/aws/shield_advanced_not_in_use
SNS topic encrypted with an AWS managed key terraform/aws/sns_topic_encrypted_with_aws_managed_key
Secrets Manager secret encrypted with an AWS managed key terraform/aws/secretsmanager_secret_encrypted_with_aws_managed_key
Review API Gateway REST API authentication terraform/aws/api_gateway_without_configured_authorizer
Auto Scaling group tags are missing terraform/aws/autoscaling_groups_supply_tags
Review Base64-encoded private keys in launch configuration user data terraform/aws/user_data_contains_encoded_private_key
Review CloudFront content delivery configuration terraform/aws/cdn_configuration_is_missing
Review CloudFormation stack notifications terraform/aws/stack_notifications_disabled
CloudFormation stack policy missing terraform/aws/no_stack_policy
CloudFormation stack template is missing terraform/aws/stack_without_template
Review the CloudFront TLS security policy terraform/aws/secure_ciphers_disabled
CloudTrail log-file delivery notifications are not configured terraform/aws/cloudtrail_sns_topic_name_undefined
Review KMS key settings for CloudTrail logs terraform/aws/cloudtrail_log_files_not_encrypted_with_kms
CloudTrail log integrity digests are disabled terraform/aws/cloudtrail_log_file_validation_disabled
Review CloudTrail regional and global-event coverage terraform/aws/cloudtrail_multi_region_disabled
CloudWatch alarm missing for CloudTrail changes terraform/aws/cloudwatch_cloudtrail_configuration_changes_alarm_missing
CloudTrail is not integrated with CloudWatch Logs terraform/aws/cloudtrail_not_integrated_with_cloudwatch
CloudWatch Logs destination policy grants excessive access terraform/aws/cloudwatch_logs_destination_with_vulnerable_policy
API Gateway detailed method metrics are disabled terraform/aws/cloudwatch_metrics_disabled
Route 53 public DNS query logging is not configured terraform/aws/cloudwatch_logging_disabled
Review CloudWatch log retention terraform/aws/cloudwatch_without_retention_period_specified
Review API Gateway CloudWatch log delivery terraform/aws/api_gateway_with_cloudwatch_logging_disabled
CodeBuild project using an AWS managed key terraform/aws/codebuild_project_encrypted_with_aws_managed_key
Review Cognito User Pool MFA coverage terraform/aws/cognito_userpool_without_mfa
Review DocumentDB encryption key management terraform/aws/docdb_cluster_encrypted_with_aws_managed_key
Review DynamoDB gateway endpoint routing associations terraform/aws/dynamodb_vpc_endpoint_without_route_table_association
DynamoDB point-in-time recovery is disabled terraform/aws/dynamodb_table_point_in_time_recovery_disabled
Review EC2 EBS optimization settings terraform/aws/ec2_not_ebs_optimized
Review AWS credentials in EC2 user data terraform/aws/hardcoded_aws_access_key
Review IMDSv1 access to EC2 metadata terraform/aws/instance_uses_metadata_service_IMDSv1
Review EC2 subnet and security-group selection terraform/aws/instance_with_no_vpc
Review an EC2 instance’s use of the default VPC terraform/aws/ec2_instance_using_default_vpc
AWS access keys deployed directly to an EC2 instance terraform/aws/ec2_instance_using_api_keys
Review ECR repository encryption key management terraform/aws/ecr_repository_not_encrypted
Review ECR repository access policies terraform/aws/ecr_repository_without_policy
Review ECR image vulnerability scanning terraform/aws/unscanned_ecr_image
Review ECS Container Insights settings terraform/aws/ecs_cluster_container_insights_disabled
Review the required ECS service task count terraform/aws/ecs_service_without_running_tasks
Review the EFS customer managed KMS key terraform/aws/efs_without_kms
EKS control plane log types missing terraform/aws/missing_cluster_log_types
Review EMR cluster subnet selection terraform/aws/emr_without_vpc
Configuration without an ENCRYPTED_VOLUMES AWS Config rule terraform/aws/config_rule_for_encrypted_volumes_is_disabled
Review the ElastiCache engine choice terraform/aws/redis_disabled
Review ElastiCache subnet group selection terraform/aws/elasticache_without_vpc
Review ElastiCache default ports and access controls terraform/aws/elasticache_using_default_port
Review Elasticsearch slow-log settings terraform/aws/elasticsearch_without_slow_logs
Cross-account IAM role trust conditions need review terraform/aws/cross_account_iam_assume_role_policy_without_external_id_or_mfa
GuardDuty detector is disabled terraform/aws/guardduty_detector_disabled
Review HTTPS enforcement for the S3 bucket terraform/aws/s3_bucket_policy_accepts_http_requests
HTTP port 80 is open to the internet terraform/aws/http_port_open
Elasticsearch domain does not enforce HTTPS terraform/aws/elasticsearch_with_https_disabled
AWS ALB listener using HTTP terraform/aws/alb_listening_on_http
CloudFront viewer policy allows HTTP terraform/aws/cloudfront_viewer_protocol_policy_allows_http
Review IAM Access Analyzer configuration terraform/aws/iam_access_analyzer_not_enabled
Neptune cluster has IAM database authentication disabled terraform/aws/neptune_cluster_with_iam_database_authentication_disabled
Review IAM password expiration policy terraform/aws/misconfigured_password_policy_expiration
Review IAM password reuse prevention terraform/aws/password_without_reuse_prevention
Review IAM password minimum length terraform/aws/iam_password_without_minimum_length
Review MFA requirements in IAM user policies terraform/aws/iam_user_policy_without_mfa
Review IAM access controls for an Elasticsearch domain terraform/aws/elasticsearch_without_iam_authentication
Missing alarm for IAM policy changes terraform/aws/cloudwatch_iam_policy_changes_alarm_missing
Review customer managed KMS key rotation terraform/aws/cmk_rotation_disabled
AWS Kinesis stream without KMS encryption terraform/aws/kinesis_not_encrypted_with_kms
Review the encryption key for a CloudWatch log group terraform/aws/cloudwatch_log_group_not_encrypted
Review the KMS key deletion waiting period terraform/aws/kms_key_with_no_deletion_window
DocumentDB encryption key settings need review terraform/aws/docdb_cluster_without_kms
Review Elasticsearch encryption key settings terraform/aws/elasticsearch_encryption_with_kms_is_disabled
Review SageMaker notebook encryption keys terraform/aws/sagemaker_notebook_instance_without_kms
Review encryption key settings for a Secrets Manager secret terraform/aws/secretsmanager_secret_without_kms
Review retention of failed Lambda asynchronous events terraform/aws/lambda_function_without_dead_letter_queue
Review IAM resource scope for Lambda InvokeFunction terraform/aws/lambda_iam_invokefunction_misconfigured
Review the action in Lambda permission terraform/aws/lambda_permission_misconfigured
Review Lambda X-Ray tracing configuration terraform/aws/lambda_functions_without_x-ray_tracing
Review AWS credentials in Lambda environment variables terraform/aws/hardcoded_aws_access_key_in_lambda
Review MFA requirements for IAM user access terraform/aws/authentication_without_mfa
Missing alarm for console sign-ins without MFA terraform/aws/cloudwatch_management_console_sign_in_without_mfa_alarm_missing
Review MQ broker logging terraform/aws/mq_broker_logging_disabled
Review MSK broker logging terraform/aws/msk_cluster_logging_disabled
CloudWatch alarm missing for network ACL changes terraform/aws/cloudwatch_changes_to_nacl_alarm_missing
Review Neptune audit log exports terraform/aws/neptune_logging_disabled
Review Network Firewall use in the VPC terraform/aws/vpc_without_network_firewall
Review API Gateway endpoint exposure terraform/aws/api_gateway_endpoint_config_is_not_private
Review query logging settings for RDS for PostgreSQL terraform/aws/postgres_rds_logging_disabled
Resource-based policy has no Principal terraform/aws/policy_without_principal
AWS Network ACL allows RDP from all addresses terraform/aws/network_acl_with_unrestricted_access_to_rdp
AWS security group allows RDP from all addresses terraform/aws/remote_desktop_port_open_to_internet
Review RDS default ports and access controls terraform/aws/rds_using_default_port
Review RDS CloudWatch log exports terraform/aws/rds_without_logging
RDS instance automated backups disabled terraform/aws/rds_with_backup_disabled
IAM database authentication is not enabled for an RDS instance terraform/aws/iam_database_auth_not_enabled
RDS automatic minor upgrades are disabled terraform/aws/automatic_minor_upgrades_disabled
Review RDS cluster backup retention terraform/aws/rds_cluster_with_backup_disabled
Review RDS snapshot tag copying terraform/aws/tags_not_copied_to_rds_cluster_snapshot
IAM database authentication is not enabled for an RDS cluster terraform/aws/iam_db_cluster_auth_not_enabled
TLS certificate has a short RSA key terraform/aws/certificate_rsa_key_bytes_lower_than_256
Review Redshift default ports and access controls terraform/aws/redshift_using_default_port
Review Redshift cluster network selection terraform/aws/redshift_cluster_without_vpc
Review Redshift audit logging terraform/aws/redshift_cluster_logging_disabled
Review S3 object-level CloudTrail data event coverage terraform/aws/s3_bucket_object_level_cloudtrail_logging_disabled
Review S3 bucket MFA Delete use terraform/aws/s3_bucket_without_enabled_mfa_delete
Review S3 server access logging terraform/aws/s3_bucket_logging_disabled
Review S3 bucket event notifications terraform/aws/s3_bucket_notifications_disabled
CloudWatch alarm missing for S3 bucket policy changes terraform/aws/cloudwatch_s3_policy_change_alarm_missing
SQL Analysis Services port 2383 allows unrestricted access terraform/aws/sql_analysis_services_port_2383_is_publicly_accessible
Review DNS settings for the SQS VPC endpoint terraform/aws/sqs_vpc_endpoint_without_dns_resolution
Review SQS queue-level encryption terraform/aws/sqs_with_sse_disabled
Network ACL allows SSH from a broad address range terraform/aws/network_acl_with_unrestricted_access_to_ssh
Security group allows SSH from the entire internet terraform/aws/security_group_with_unrestricted_access_to_ssh
Review API Gateway backend client certificate settings terraform/aws/api_gateway_without_ssl_certificate
Review additional KMS encryption for SSM sessions terraform/aws/ssm_session_transit_encryption_disabled
Review IAM Identity Center permission-set session duration terraform/aws/sso_permission_with_inadequate_user_session_duration
Security group rule descriptions are missing terraform/aws/security_group_rules_without_description
Review security group descriptions terraform/aws/security_group_without_description
AWS Organizations configuration cannot use Service Control Policies terraform/aws/service_control_policies_disabled
Review StackSet stack retention terraform/aws/stack_retention_disabled
AWS Identity Center users created directly with Terraform terraform/aws/sso_policy_with_full_priveleges_copy
Review VPC Flow Logs coverage terraform/aws/vpc_flowlogs_disabled
CloudWatch alarm missing for VPC changes terraform/aws/cloudwatch_vpc_changes_alarm_missing
Review AWS WAF protection for API Gateway terraform/aws/api_gateway_without_waf
Review the CloudFront WAF association terraform/aws/cloudfront_without_waf
AWS ALB not associated with WAF terraform/aws/alb_is_not_integrated_with_waf
S3 bucket ACL specifies WRITE_ACP permission terraform/aws/s3_bucket_acl_grants_write_acp_permission
SNS topic policy combines Effect: Allow and NotAction terraform/aws/sns_topic_publicity_has_allow_and_not_action_simultaneously
IAM group has excessive CloudFormation and PassRole permissions terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack
IAM user has excessive CloudFormation creation and PassRole permissions terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack
IAM role can escalate privileges through cloudformation:CreateStack and iam:PassRole terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_cloudformation_CreateStack
IAM group has excessive EC2 launch and PassRole permissions terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances
IAM user has excessive EC2 launch and PassRole permissions terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances
IAM role can escalate privileges through ec2:RunInstances and iam:PassRole terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_ec2_RunInstances
IAM group has excessive Glue creation and PassRole permissions terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint
IAM user has excessive Glue creation and PassRole permissions terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint
IAM role can escalate privileges through glue:CreateDevEndpoint and iam:PassRole terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_glue_CreateDevEndpoint
IAM group has excessive glue:UpdateDevEndpoint permissions terraform/aws/group_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint
IAM user has excessive glue:UpdateDevEndpoint permissions terraform/aws/user_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint
IAM role can escalate privileges through glue:UpdateDevEndpoint terraform/aws/role_with_privilege_escalation_by_actions_glue_UpdateDevEndpoint
IAM group permissions for iam:AddUserToGroup need review terraform/aws/group_with_privilege_escalation_by_actions_iam_AddUserToGroup
IAM user permissions for iam:AddUserToGroup need review terraform/aws/user_with_privilege_escalation_by_actions_iam_AddUserToGroup
IAM role permissions for iam:AddUserToGroup need review terraform/aws/role_with_privilege_escalation_by_actions_iam_AddUserToGroup
IAM group permissions for iam:AttachGroupPolicy need review terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachGroupPolicy
IAM user permissions for iam:AttachGroupPolicy need review terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachGroupPolicy
IAM role permissions for iam:AttachGroupPolicy need review terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachGroupPolicy
IAM group permissions for iam:AttachRolePolicy need review terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachRolePolicy
IAM user permissions for iam:AttachRolePolicy need review terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachRolePolicy
IAM role permissions for iam:AttachRolePolicy need review terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachRolePolicy
IAM group permissions for iam:AttachUserPolicy need review terraform/aws/group_with_privilege_escalation_by_actions_iam_AttachUserPolicy
IAM user permissions for iam:AttachUserPolicy need review terraform/aws/user_with_privilege_escalation_by_actions_iam_AttachUserPolicy
IAM role permissions for iam:AttachUserPolicy need review terraform/aws/role_with_privilege_escalation_by_actions_iam_AttachUserPolicy
IAM group has excessive iam:CreateAccessKey permissions terraform/aws/group_with_privilege_escalation_by_actions_iam_CreateAccessKey
IAM user has excessive iam:CreateAccessKey permissions terraform/aws/user_with_privilege_escalation_by_actions_iam_CreateAccessKey
IAM role can escalate privileges through iam:CreateAccessKey terraform/aws/role_with_privilege_escalation_by_actions_iam_CreateAccessKey
IAM group has excessive iam:CreateLoginProfile permissions terraform/aws/group_with_privilege_escalation_by_actions_iam_CreateLoginProfile
IAM user has excessive iam:CreateLoginProfile permissions terraform/aws/user_with_privilege_escalation_by_actions_iam_CreateLoginProfile
IAM role can escalate privileges through iam:CreateLoginProfile terraform/aws/role_with_privilege_escalation_by_actions_iam_CreateLoginProfile
IAM group permissions for iam:CreatePolicyVersion need review terraform/aws/group_with_privilege_escalation_by_actions_iam_CreatePolicyVersion
IAM user permissions for iam:CreatePolicyVersion need review terraform/aws/user_with_privilege_escalation_by_actions_iam_CreatePolicyVersion
IAM role permissions for iam:CreatePolicyVersion need review terraform/aws/role_with_privilege_escalation_by_actions_iam_CreatePolicyVersion
IAM group permissions for iam:PutGroupPolicy need review terraform/aws/group_with_privilege_escalation_by_actions_iam_PutGroupPolicy
IAM user permissions for iam:PutGroupPolicy need review terraform/aws/user_with_privilege_escalation_by_actions_iam_PutGroupPolicy
IAM role permissions for iam:PutGroupPolicy need review terraform/aws/role_with_privilege_escalation_by_actions_iam_PutGroupPolicy
IAM group permissions for iam:PutRolePolicy need review terraform/aws/group_with_privilege_escalation_by_actions_iam_PutRolePolicy
IAM user permissions for iam:PutRolePolicy need review terraform/aws/user_with_privilege_escalation_by_actions_iam_PutRolePolicy
IAM role permissions for iam:PutRolePolicy need review terraform/aws/role_with_privilege_escalation_by_actions_iam_PutRolePolicy
IAM group permissions for iam:PutUserPolicy need review terraform/aws/group_with_privilege_escalation_by_actions_iam_PutUserPolicy
IAM user permissions for iam:PutUserPolicy need review terraform/aws/user_with_privilege_escalation_by_actions_iam_PutUserPolicy
IAM role permissions for iam:PutUserPolicy need review terraform/aws/role_with_privilege_escalation_by_actions_iam_PutUserPolicy
IAM group permissions for iam:SetDefaultPolicyVersion need review terraform/aws/group_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion
IAM user permissions for iam:SetDefaultPolicyVersion need review terraform/aws/user_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion
IAM role permissions for iam:SetDefaultPolicyVersion need review terraform/aws/role_with_privilege_escalation_by_actions_iam_SetDefaultPolicyVersion
IAM group has excessive trust-policy update and role-assumption permissions terraform/aws/group_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole
IAM user has excessive trust-policy update and role-assumption permissions terraform/aws/user_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole
IAM role can escalate privileges through iam:UpdateAssumeRolePolicy and sts:AssumeRole terraform/aws/role_with_privilege_escalation_by_actions_iam_UpdateAssumeRolePolicy_and_sts_AssumeRole
IAM group has excessive iam:UpdateLoginProfile permissions terraform/aws/group_with_privilege_escalation_by_actions_iam_UpdateLoginProfile
IAM user has excessive iam:UpdateLoginProfile permissions terraform/aws/user_with_privilege_escalation_by_actions_iam_UpdateLoginProfile
IAM role can escalate privileges through iam:UpdateLoginProfile terraform/aws/role_with_privilege_escalation_by_actions_iam_UpdateLoginProfile
IAM group has excessive Lambda creation, invocation and PassRole permissions terraform/aws/group_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_and_lambda_InvokeFunction
IAM user has excessive Lambda creation, invocation and PassRole permissions terraform/aws/user_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_and_lambda_InvokeFunction
IAM role can escalate privileges through lambda:CreateFunction, lambda:InvokeFunction and iam:PassRole terraform/aws/role_with_privilege_escalation_by_actions_iam_PassRole_and_lambda_CreateFunction_lambda_InvokeFunction
IAM group has excessive lambda:UpdateFunctionCode permissions terraform/aws/group_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode
IAM user has excessive lambda:UpdateFunctionCode permissions terraform/aws/user_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode
IAM role can escalate privileges through lambda:UpdateFunctionCode terraform/aws/role_with_privilege_escalation_by_actions_lambda_UpdateFunctionCode
AWS Batch job definition enables privileged containers terraform/aws/batch_job_definition_with_privileged_container_properties
Review EKS encryption key settings terraform/aws/eks_cluster_encryption_disabled
IAM policy attached directly to a user terraform/aws/iam_policies_attached_to_user
CloudWatch alarm missing for KMS key changes terraform/aws/cloudwatch_disabling_or_scheduled_deletion_of_customer_created_cmk_alarm_missing
Review S3 public ACL suppression terraform/aws/s3_bucket_without_ignore_public_acl
S3 bucket combines a public ACL with Block Public Access terraform/aws/s3_bucket_public_acl_overridden_by_public_access_block
Review S3 public ACL blocking terraform/aws/s3_bucket_allows_public_acl
Review S3 public bucket policy blocking terraform/aws/s3_bucket_with_public_policy
RDS configuration uses a /0 subnet CIDR terraform/aws/rds_associated_with_public_subnet
Legacy DB security group allows all source addresses terraform/aws/db_security_group_has_public_interface
DMS replication instance enables public access terraform/aws/amazon_dms_replication_instance_is_publicly_accessible
SQS queue policy public principals need review terraform/aws/sqs_policy_with_public_access
Publicly accessible AWS MQ broker terraform/aws/mq_broker_is_publicly_accessible
Publicly accessible AWS MSK broker terraform/aws/msk_broker_is_publicly_accessible
Publicly accessible AWS Neptune cluster instance terraform/aws/neptune_cluster_instance_is_publicly_accessible
ECR repository policy uses wildcard principals terraform/aws/ecr_repository_is_publicly_accessible
SNS topic policy uses a wildcard principal terraform/aws/sns_topic_is_publicly_accessible
CloudTrail log bucket public access needs review terraform/aws/cloudtrail_log_files_s3_bucket_is_publicly_accessible
RDS public-access configuration needs review terraform/aws/rds_db_instance_publicly_accessible
Review public IP assignment for EC2 instances terraform/aws/ec2_instance_has_public_ip
ECS service assigned public IP addresses terraform/aws/ecs_services_assigned_with_public_ip_address
VPC subnet automatically assigns public IP addresses terraform/aws/vpc_subnet_assigns_public_ip
Legacy DB security-group source range needs review terraform/aws/db_security_group_open_to_large_scope
IAM role trust policy needs review terraform/aws/iam_role_with_full_privileges
KMS key access policy needs review terraform/aws/kms_key_with_full_permissions
Secrets Manager secret access policy needs review terraform/aws/secrets_manager_with_vulnerable_policy
AWS ECS service role permissions need review terraform/aws/ecs_service_admin_role_is_present
Review the ECS task network mode terraform/aws/ecs_task_definition_network_mode_not_recommended
AWS Lambda function with an overly privileged execution role terraform/aws/lambda_function_with_privileged_role
EBS encryption by default disabled in an account and Region terraform/aws/ebs_default_encryption_disabled
Review AWS default VPC configuration terraform/aws/default_vpc_exists
Review default security group use on EC2 instances terraform/aws/ec2_instance_using_default_security_group
Missing alarm for network gateway changes terraform/aws/cloudwatch_network_gateways_changes_alarm_missing
Elasticsearch domain without node-to-node encryption terraform/aws/elasticsearch_domain_not_encrypted_node_to_node
ElastiCache nodes not distributed across Availability Zones terraform/aws/elasticache_nodes_not_created_across_multi_az
IAM policy can be abused for data exfiltration terraform/aws/iam_policy_allows_for_data_exfiltration
Missing alarm for route table changes terraform/aws/cloudwatch_route_table_changes_alarm_missing
Empty values in an AWS Route 53 record terraform/aws/route53_record_undefined
Review CloudFront request logging terraform/aws/cloudfront_logging_disabled
AWS CloudTrail logging disabled terraform/aws/cloudtrail_logging_disabled
Review DocumentDB log exports terraform/aws/docdb_logging_disabled
Review access logging for the CloudTrail log bucket terraform/aws/cloudtrail_log_files_s3_bucket_with_logging_disabled
EKS cluster logging disabled terraform/aws/eks_cluster_log_disabled
Review Elasticsearch log publishing terraform/aws/elasticsearch_logs_disabled
CloudWatch alarm missing for root user activity terraform/aws/cloudwatch_root_account_use_alarm_missing
Review access keys for an IAM user named root terraform/aws/iam_access_key_is_exposed
Expired TLS certificate terraform/aws/certificate_has_expired
IAM service-role trust principals need review terraform/aws/iam_policy_grants_assumerole_permission_across_all_services
S3 bucket policy uses wildcard actions and principals terraform/aws/s3_bucket_with_all_permissions
iam:PassRole allows every role terraform/aws/iam_role_policy_passrole_allows_all
S3 bucket ACL grants read access to any authenticated AWS account terraform/aws/s3_bucket_acl_allows_read_to_any_authenticated_user
SQS queue policy grants broad actions terraform/aws/sqs_policy_allows_all_actions
IAM role account-wide trust needs review terraform/aws/iam_role_allows_all_principals_to_assume
S3 bucket policy combines wildcard principals with delete actions terraform/aws/s3_bucket_allows_delete_action_from_all_principals
S3 bucket policy combines wildcard principals with put actions terraform/aws/s3_bucket_allows_put_action_from_all_principals
S3 bucket policy uses wildcard principals terraform/aws/s3_bucket_access_to_any_principal
S3 bucket policy grants Get permissions to all principals terraform/aws/s3_bucket_allows_get_action_from_all_principals
S3 bucket policy grants listing permissions to all principals terraform/aws/s3_bucket_allows_list_action_from_all_principals
Default security-group traffic permissions need review terraform/aws/vpc_default_security_group_accepts_all_traffic
AWS default security group allows traffic with all addresses terraform/aws/default_security_groups_with_unrestricted_traffic
Review unused security groups terraform/aws/security_groups_not_used
Review private-network access to sensitive service ports terraform/aws/sensitive_port_is_exposed_to_wide_private_network
AWS security group allows management or internal-service ports from all addresses terraform/aws/sensitive_port_is_exposed_to_entire_network
ElastiCache Redis automatic backups disabled terraform/aws/elasticache_redis_cluster_without_backup
Review S3 versioning settings terraform/aws/s3_bucket_without_versioning
CloudWatch alarm missing for security group changes terraform/aws/cloudwatch_security_group_changes_alarm_missing
Review the AWS ElastiCache Redis OSS engine version terraform/aws/redis_not_compliant
Review the API Gateway custom domain TLS policy terraform/aws/api_gateway_without_security_policy
WorkSpace without volume encryption terraform/aws/workspaces_workspace_volume_not_encrypted
Review IAM user initial password settings terraform/aws/no_password_policy_enabled
AWS snapshot created from an unencrypted EBS volume terraform/aws/ebs_volume_snapshot_not_encrypted
Review RDS cluster snapshot encryption terraform/aws/rds_database_cluster_not_encrypted
CloudWatch monitoring for unauthorized API calls needs review terraform/aws/cloudwatch_unauthorized_access_defined_alarm_missing
IAM group has no users terraform/aws/iam_group_without_users
Review IAM users’ password-change permissions terraform/aws/aws_password_policy_with_unchangeable_passwords
Review use of a disabled customer managed KMS key terraform/aws/cmk_is_unusable
AWS ALB deletion protection disabled terraform/aws/alb_deletion_protection_disabled
EC2 detailed monitoring disabled terraform/aws/ec2_instance_monitoring_disabled
DynamoDB table encryption key settings need review terraform/aws/dynamodb_table_not_encrypted
Review S3 object server-side encryption settings terraform/aws/s3_bucket_object_not_encrypted
Amazon Data Firehose encryption settings need review terraform/aws/kinesis_sse_not_configured
Review S3 CORS settings terraform/aws/s3_bucket_with_unsecured_cors_rule
Review SSL/TLS protocols in ELB policies terraform/aws/elb_using_insecure_protocols
AWS security-group port exposure needs review terraform/aws/unknown_port_exposed_to_internet
Review MSK cluster encryption settings terraform/aws/msk_cluster_encryption_disabled
Athena database query-result encryption settings need review terraform/aws/athena_database_not_encrypted
Review SageMaker endpoint storage encryption keys terraform/aws/sagemaker_endpoint_configuration_encryption_disabled
Amazon MQ broker encryption key settings need review terraform/aws/amazon_mq_broker_encryption_disabled
Review Glue Data Catalog and connection password encryption terraform/aws/glue_data_catalog_encryption_disabled
Review Glue Security Configuration encryption settings terraform/aws/glue_security_configuration_encryption_disabled
SNS topic without message encryption terraform/aws/sns_topic_not_encrypted
API Gateway cache without encryption terraform/aws/api_gateway_method_settings_cache_not_encrypted
Unencrypted AWS AMI terraform/aws/ami_not_encrypted
AWS EBS volume without encryption terraform/aws/ebs_volume_encryption_disabled
AWS EFS file system without encryption terraform/aws/efs_not_encrypted
AWS block-device mappings without encryption terraform/aws/block_device_is_not_encrypted
AWS Classic ELB cipher policies need review terraform/aws/elb_using_weak_ciphers
Review AWS AMI account sharing terraform/aws/ami_shared_with_multiple_accounts
Review Elastic IP usage and association terraform/aws/aws_eip_not_attached_to_any_instance
Review the Auto Scaling group load-balancer association terraform/aws/auto_scaling_group_with_no_associated_elb
RDS instance uses an outdated CA certificate terraform/aws/ca_certificate_identifier_is_outdated
Lambda function policy grants broad actions terraform/aws/lambda_with_vulnerable_policy
Lambda invocation permission uses a wildcard principal terraform/aws/lambda_permission_principal_is_wildcard
API Gateway REST API policy grants excessive access terraform/aws/rest_api_with_vulnerable_policy
AWS Redshift cluster public-access settings need review terraform/aws/redshift_publicly_accessible
AWS SQS queue policy access needs review terraform/aws/sqs_queue_exposed
Operational tags are missing terraform/aws/resource_not_using_tags
Review API Gateway method authentication terraform/aws/api_gateway_with_open_access
Review source ranges for sensitive service ports terraform/aws/sensitive_port_is_exposed_to_small_public_network
AWS ALB does not drop invalid headers terraform/aws/alb_not_dropping_invalid_headers
Review Redshift encryption at rest terraform/aws/redshift_not_encrypted
Amazon Aurora storage encryption settings need review terraform/aws/aurora_with_disabled_at_rest_encryption
AWS DAX cluster without encryption at rest terraform/aws/dax_cluster_not_encrypted
Amazon DocumentDB cluster without storage encryption terraform/aws/docdb_cluster_not_encrypted
AWS ElastiCache replication group without encryption at rest terraform/aws/elasticache_replication_group_not_encrypted_at_rest
AWS Elasticsearch domain without encryption at rest terraform/aws/elasticsearch_not_encrypted_at_rest
AWS Neptune cluster without encryption at rest terraform/aws/neptune_database_cluster_encryption_disabled
AWS DB instance without storage encryption terraform/aws/db_instance_storage_not_encrypted
Review RDS cluster storage encryption terraform/aws/rds_storage_not_encrypted
EFS volume with transit encryption disabled terraform/aws/efs_volume_with_disabled_transit_encryption
ElastiCache replication group with transit encryption disabled terraform/aws/elasticache_replication_group_not_encrypted_at_transit
Review destination ranges for VPC peering routes terraform/aws/vpc_peering_route_table_with_unrestricted_cidr
IAM policy administrative permissions need review terraform/aws/iam_policies_with_full_privileges
Identity Center permission set grants excessive access terraform/aws/sso_policy_with_full_priveleges
IAM policy grants excessive permissions terraform/aws/iam_policy_grants_full_permissions
S3 bucket configuration uses a public canned ACL terraform/aws/s3_bucket_acl_allows_read_or_write_to_all_users
EC2-Classic DB security group allows all IPv4 addresses terraform/aws/db_security_group_with_public_scope
EKS public access CIDRs allow the entire internet terraform/aws/eks_cluster_has_public_access_cidrs
AWS security group allows ingress from all source addresses terraform/aws/unrestricted_security_group_ingress
SES identity-policy access needs review terraform/aws/ses_policy_with_allowed_iam_actions
Review access logging on an API Gateway deployment stage terraform/aws/api_gateway_deployment_without_access_log_setting
Review API Gateway stage logging terraform/aws/api_gateway_access_logging_disabled
Classic ELB access logging disabled terraform/aws/elb_access_logging_disabled
Review ELBv2 load-balancer access logging terraform/aws/elb_v2_lb_access_log_disabled
EKS node remote access has no source security groups terraform/aws/eks_node_group_remote_access_disabled
Review public exposure of an AWS S3 static website terraform/aws/s3_static_website_host_enabled
CloudFront security policy allows older TLS versions terraform/aws/cloudfront_without_minimum_protocol_tls_1.2
Review certificates for CloudFront custom domains terraform/aws/vulnerable_default_ssl_certificate
EFS file system policy access needs review terraform/aws/efs_with_vulnerable_policy
AWS Glue Data Catalog policy permissions need review terraform/aws/glue_with_vulnerable_policy
Elasticsearch domain policy access needs review terraform/aws/elasticsearch_domain_with_vulnerable_policy
IAM user has console access terraform/aws/iam_user_with_access_to_console
Athena workgroup result encryption settings need review terraform/aws/athena_workgroup_not_encrypted
Mutable image tags in an AWS ECR repository terraform/aws/ecr_image_tag_not_immutable
Public and private EC2 instances share an IAM role terraform/aws/public_and_private_ec2_share_role
Review restrictions on public S3 buckets terraform/aws/s3_bucket_without_restriction_of_public_bucket
Public access enabled for an EKS cluster terraform/aws/eks_cluster_has_public_access
Review the number of access keys for an IAM user terraform/aws/iam_user_too_many_access_keys
Review active access keys for an IAM user terraform/aws/root_account_has_active_access_keys
AWS Global Accelerator flow logs disabled terraform/aws/global_accelerator_flow_logs_disabled

Related pages340

Review usage plan associations for deployed API Gateway stages

Associate a deployed stage with a usage plan when per-key usage management is needed.

Review API Gateway stage usage plan associations

Associate stages with the correct plan when per-key usage controls are needed.

API Gateway X-Ray tracing disabled

Disabled X-Ray tracing on a REST API can make request-path and latency analysis harder.

Review API Gateway response compression

Choose response compression and its minimum size to suit the API payloads.

Review the scope of API Gateway permission to invoke Lambda

Limit API Gateway permission to invoke Lambda to the required stage, method, and path.

Review API Gateway API key usage management

Require API keys where per-key usage management is needed, and configure authentication separately.

Review the Regions included in AWS Config aggregation

Include the Regions that need a central AWS Config view.

CloudWatch alarm missing for AWS Config changes

Monitor AWS Config changes with a CloudWatch alarm.

CloudWatch alarm missing for console sign-in failures

Configure notifications for AWS console sign-in failures.

Missing alarm for AWS Organizations changes

Without a CloudWatch filter and alarm for AWS Organizations changes, changes to organizational permissions may go unnoticed for longer.

Review the need for AWS Shield Advanced

Evaluate additional protection against the service’s DDoS response needs.

SNS topic encrypted with an AWS managed key

Check whether the AWS managed SNS encryption key meets organizational key-control requirements.

Secrets Manager secret encrypted with an AWS managed key

Check whether the AWS managed Secrets Manager key meets your key-management requirements.

Review API Gateway REST API authentication

Attach suitable authentication to protected REST API methods and verify actual permission checks.

Auto Scaling group tags are missing

Specify the operational tags needed on the group and new instances.

Review Base64-encoded private keys in launch configuration user data

Base64 encoding does not keep a private key secret. Remove actual private keys from EC2 user data.

Review CloudFront content delivery configuration

Configure the CloudFront distribution and origin needed by the service.

Review CloudFormation stack notifications

Deliver CloudFormation stack events through the notification path needed for operations, and verify failure and rollback notifications.

CloudFormation stack policy missing

Use a stack policy to protect resources during stack updates.

CloudFormation stack template is missing

Provide a template body or URL for the stack to be created.

Review the CloudFront TLS security policy

Configure an appropriate minimum TLS version for CloudFront client connections.

CloudTrail log-file delivery notifications are not configured

Associate an SNS topic when log-file arrival notifications are needed.

Review KMS key settings for CloudTrail logs

Distinguish default CloudTrail storage encryption from separate KMS key controls.

CloudTrail log integrity digests are disabled

Generate digest files for verifying changes to CloudTrail logs.

Review CloudTrail regional and global-event coverage

Include the Regions and global service events required for auditing.

CloudWatch alarm missing for CloudTrail changes

Monitor CloudTrail configuration changes and logging stops.

CloudTrail is not integrated with CloudWatch Logs

Configure CloudTrail delivery to analyze audit logs in CloudWatch.

CloudWatch Logs destination policy grants excessive access

Allow only the senders and actions needed for log subscriptions.

API Gateway detailed method metrics are disabled

Enable detailed CloudWatch metrics for API methods that need them.

Route 53 public DNS query logging is not configured

Record DNS queries for public hosted zones that need detailed logs.

Review CloudWatch log retention

Set CloudWatch log retention to meet operational and regulatory needs, avoiding both lost evidence and unnecessary storage.

Review API Gateway CloudWatch log delivery

Check CloudWatch delivery and retention for the API Gateway log type you use.

CodeBuild project using an AWS managed key

Choose an AWS managed or customer-managed key according to the key-policy requirements for CodeBuild artifacts.

Review Cognito User Pool MFA coverage

Apply MFA to password-based sign-ins where required and verify the coverage of optional settings.

Review DocumentDB encryption key management

Choose a KMS key that meets your key-management requirements.

Review DynamoDB gateway endpoint routing associations

Associate the application subnet’s route table with the endpoint.

DynamoDB point-in-time recovery is disabled

Plan point-in-time recovery and a tested restore process for important tables.

Review EC2 EBS optimization settings

Check the instance type’s defaults alongside the workload’s EBS performance needs.

Review AWS credentials in EC2 user data

Remove long-term AWS credentials from EC2 user data and use temporary credentials from an instance role.

Review IMDSv1 access to EC2 metadata

Require IMDSv2 for needed metadata access and verify the effective configuration.

Review EC2 subnet and security-group selection

Configure EC2 network placement explicitly.

Review an EC2 instance’s use of the default VPC

Check that default VPC use fits the workload’s network design.

AWS access keys deployed directly to an EC2 instance

Use temporary IAM role credentials instead of placing long-lived keys on EC2.

Review ECR repository encryption key management

Configure ECR encryption for the required level of key control.

Review ECR repository access policies

Limit access to the principals and image operations that need it.

Review ECR image vulnerability scanning

Scan stored images and address the findings.

Review ECS Container Insights settings

Collect the operational information you need through ECS Container Insights.

Review the required ECS service task count

Check the desired task count and actual running state against the service’s operating needs.

Review the EFS customer managed KMS key

Choose the EFS encryption key to meet your organization’s key-management requirements.

EKS control plane log types missing

Configure the full set of EKS control plane log types.