Checks Performed
- Access Logging Should Be Enabled For Elastic Beanstalk Load Balancer
- Alert Notifications Should Be Enabled For Elastic Beanstalk Events
- AMI Age Should Not Exceed the Configured Age
- Autoscaling Groups Health Checks Should Be Checked
- Autoscaling Hop Limit Should Be Checked
- AWS Client VPN Authorization Rules Should Be Enabled Authorizing All Clients
- AWS EC2 Hibernation Should Be Enabled
- Backup Manual Deletion Should Be Disabled
- Backup Plan Should Have Retention Period.
- Blacklisted AMIs Should Not Be Used
- Default Security Group Should Not Allow Unrestricted Public Traffic
- Default VPC Should Not Be In Use
- Detailed Monitoring for EC2 Instances Should Be Enabled
- DNS Resolution To Private IP Should Be Enabled
- EBS Volumes Should Be Encrypted
- EC2 AMIs Should Be Encrypted
- EC2 AMIs Should Not Be Public
- EC2 Classic Should Not Be Used
- EC2 Hop Limit Check.
- EC2 IAM Roles Should Be Used
- EC2 Instance Count Should Not Exceed the Limit
- EC2 Instance Should Be of Desired Type
- EC2 Instance Should Not Be In Public Subnet
- EC2 Instance Snapshots Should Not Be Public
- EC2 Instance Tenancy
- EC2 Instances Should Be Managed By SSM
- EC2 Instances Should Have Backup Plan Protection
- EC2 Instances Should Not Be Idle
- EC2 Instances Should Not Be Overutilized
- EC2 Instances Should Not Be Underutilized
- EC2 Instances Should Not Have Blacklisted Instance Types
- EC2 Instances Should Not Have Multiple Security Groups
- EC2 Instances Should Not Reach vCPU Limit
- EC2 Instances Should Use Latest Generation
- EC2 Reserved Instances Recent Purchases Should Be Reviewed
- EC2 Reserved Instances Should Not Have Payment Failed
- EC2 Reserved Instances Should Not Have Payment Pending
- EC2 Systems Manager Are Configured To Collect Blacklisted Inventory.
- EC2-Classic Elastic IP Address Limit Should Not Be Reached
- EC2-VPC Elastic IP Address Limit Should Not Be Reached
- Elastic Compute Cloud Should Have Recovery Point
- Elastic Compute Cloud Should Have Recovery Point
- Elastic File System Should Be In Backup Plan
- Elastic File System Should Have Backup Plan
- Elastic File System Should Have Recovery Point
- Elastic File System Should Have Recovery Point Within Specified Duration
- Enable Default Encryption For EBS Volumes
- Enhanced Health Reporting Should Be Enabled For Elastic Beanstalk Environments
- FSx Should Have Backup Plan
- FSx Should Have Recovery Point
- FSx Should Have Recovery Point Within Specified Duration
- HTTPS Should Be Enforced On Elastic Beanstalk Load Balancers
- IMDSv2 Should Be Enabled For EC2 Instances
- Instance Should Be Launched In Auto Scaling Group
- Internet Gateways Should Be Attached To Authorized Virtual Private Clouds
- Long Running Instances Should Be Re-launched
- Managed Platform Updates Should Be Enabled For Elastic Beanstalk Environment
- Multiple ENIs Should Not Be Attached To EC2 Instances
- Network Firewall Deletion Protection Should Be Enabled
- Network Firewall Logging Should Be Enabled
- Network Firewall Policy Default Action Should Be Set For Fragmented Packets
- Network Firewall Policy Default Action Should Be Set For Full Packets
- Network Firewall Rule Groups Should Be Stateless Or Stateful
- Network Firewalls Deployed Across Multiple Availability Zones
- Non-Empty Stateless Network Firewall Rule Groups Should Not Be Present
- None Specified Applications Should Be Installed On Instance.
- Patch Installation Should Be Done On Systems Manager
- Persistent Logs Should Be Enabled For Elastic Beanstalk Environments
- Recovery Point Retention Should Be Reviewed
- Reserved Instance Lease Expiration In The Next 30 Days
- Reserved Instance Lease Expiration In The Next 7 Days
- Reserved Instances Should Not Be Unused
- Restrict data-tier subnet connectivity to VPC NAT Gateway
- Scheduled Events for EC2 Instances
- Security Group Name Prefixed With launch-wizard Should Not Be Used
- Security Group Port Range Should Be Limited
- Security Group Rules Counts
- Security Group Should Not Exceed Certain Limit
- Security Groups Should Be Attached To Elastic Network Interfaces
- Security Groups Should Have Descriptions
- Security Groups Should Not Allow Inbound Traffic From RFC 1918
- Specified Applications Should Be Installed On Instance
- SSM Document Should Not Be Public
- SSM Parameters Should Be Encrypted
- SSM Session Length Should Be Minimum
- Status OF Managed Instance Compliance Should Be Checked
- Storage Gateway Recovery Point Should Be Created
- Storage Gateway Recovery Point Should Be Created Within Specified Duration
- Storage Gateway Volumes Should Have Backup Plan
- Termination Protection Should Be Enabled
- Unassociated Elastic IP Addresses Should Be Removed
- Unrestricted CIFS Access Should Not Be Allowed
- Unrestricted DNS Access Should Not Be Allowed
- Unrestricted Elasticsearch Access Should Not Be Allowed
- Unrestricted FTP Access Should Not Be Allowed
- Unrestricted HTTP Access Should Not Be Allowed
- Unrestricted HTTPS Access Should Not Be Allowed
- Unrestricted ICMP Access Should Not Be Allowed
- Unrestricted Inbound Access On Non-HTTP Ports
- Unrestricted MongoDB Access Should Not Be Allowed
- Unrestricted MsSQL Access Should Not Be Allowed
- Unrestricted MySQL Access Should Not Be Allowed
- Unrestricted Netbios Access Should Not Be Allowed
- Unrestricted Oracle Access Should Not Be Allowed
- Unrestricted Outbound Access Should Not Be Allowed
- Unrestricted PostgreSQL Access Should Not Be Allowed
- Unrestricted RDP Access Should Not Be Allowed
- Unrestricted RPC Access Should Not Be Allowed
- Unrestricted SMTP Access Should Not Be Allowed
- Unrestricted SSH Access Should Not Be Allowed
- Unrestricted Telnet Access Should Not Be Allowed
- Unused AMIs Should Be Removed
- Unused AWS EC2 Key Pairs Should Be Removed
- Unused Elastic Network Interfaces Should Be Removed
- Virtualization Type Of EC2 Instance Is Paravirtual.
- VPC Flow Logs Should Be Enabled
- VPN Tunnel Should Be Up
- X-Ray Tracing Should Enabled For Elastic Beanstalk Environments

