Skip to main content

Posture Monitoring Check Actions

Action NameCheck NamePermissionsDeprecated
Set AMI to PrivateAMI Is PublicNoneNo
Revoke Access to Untrusted AccountsAMI Is Shared ExternallyNoneNo
Enable EBS Encryption By DefaultEBS Default Encryption Disabledec2:EnableEbsEncryptionByDefaultNo
Remove Failed Security GroupsEC2 Instance Exposes an Administrative Port to InternetNoneNo
Revoke Security Group RulesEC2 Security Group References ItselfNoneNo
Release IP AddressElastic IP Is Not In UseNoneNo
Disable IAM Access KeysIAM Access Key Should Be RotatedNoneNo
Enforce Password Policy ComplianceIAM Account Does Not Have A Secure Password PolicyNoneNo
Enable Password Reuse PreventionIAM Password Policy Does Not Prevent ReuseNoneNo
Enable Minimum Password Length of 14IAM Password Policy Does Not Require Minimum Length of 14 or GreaterNoneNo
Disable IAM UserIAM User Has Access Key Without MFA Enforcediam:DeleteLoginProfile,iam:UpdateAccessKeyNo
Disable IAM UserIAM User Has Access Key(s) That Are Publicly Available Onlineiam:DeleteLoginProfile,iam:UpdateAccessKeyNo
Disable IAM UserIAM User Has Administrator Access With MFA Disablediam:DeleteLoginProfile,iam:UpdateAccessKeyNo
Disable IAM UserIAM User Has Risky Permissionsiam:DeleteLoginProfile,iam:UpdateAccessKeyNo
Disable IAM UserNew IAM User Has Access Keysiam:DeleteLoginProfile,iam:UpdateAccessKeyNo
Remove Failed Security GroupsSensitive Ports are Exposed To InternetNoneNo
Remove Failed Security GroupsSensitive Ports On Windows System Exposed To InternetNoneNo
Disable IAM UserUnused IAM User Credentialsiam:DeleteLoginProfile,iam:UpdateAccessKeyNo
Quarantine IAM UserUnused IAM User CredentialsNoneNo
Disable IAM UserUser MFA not Enforced and Missing MFA Deviceiam:DeleteLoginProfile,iam:UpdateAccessKeyNo