📝 AWS CloudTrail Log File Validation is not enabled 🟢 | 1 | 🟢 x6 |
📝 AWS CloudTrail S3 Bucket Access Logging is not enabled. 🟢 | 1 | 🟢 x6 |
📝 AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports 🟢 | 1 | 🟢 x6 |
📝 AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports 🟢 | 1 | 🟢 x6 |
📝 AWS EC2 Security Group allows unrestricted traffic to MongoDB 🟢 | 1 | 🟢 x6 |
📝 AWS EC2 Security Group allows unrestricted traffic to Oracle DBMS 🟢 | 1 | 🟢 x6 |
📝 AWS IAM User has inline or directly attached policies 🟢 | 1 | 🟠 x1, 🟢 x5 |
📝 AWS S3 Bucket is not configured to block public access 🟢 | 1 | 🟢 x6 |
📝 AWS S3 Bucket Policy is not set to deny HTTP requests 🟢 | 1 | 🟢 x6 |
📝 AWS S3 Bucket Server Access Logging is not enabled 🟢 | 1 | 🟢 x6 |
📝 AWS VPC Flow Logs are not enabled 🟢 | 1 | 🟠 x1, 🟢 x5 |
📝 Azure Diagnostic Setting for Azure Key Vault is not enabled 🟢 | | 🟢 x3 |
📝 Azure PostgreSQL Flexible Server connection_throttle.enable Parameter is not set to ON 🟢 | 1 | 🟢 x6 |
📝 Azure PostgreSQL Flexible Server log_checkpoints Parameter is not set to ON 🟢 | 1 | 🟢 x6 |
📝 Azure PostgreSQL Flexible Server log_retention_days Parameter is less than 4 days 🟢 | 1 | 🟢 x6 |
📝 Azure PostgreSQL Single Server log_connections Parameter is not set to ON 🟢 | 1 | 🟢 x6 |
📝 Azure PostgreSQL Single Server log_disconnections Parameter is not set to ON 🟢 | 1 | 🟢 x6 |
📝 Azure SQL Server Auditing is not enabled 🟢 | 1 | 🟢 x6 |
📝 Azure SQL Server Auditing Retention is less than 90 days 🟢 | 1 | 🟢 x6 |
📝 Azure Storage Blob Logging is not enabled for Read, Write, and Delete requests 🟢 | 1 | 🟢 x6 |
📝 Azure Storage Queue Logging is not enabled for Read, Write, and Delete requests 🟢 | 1 | 🟢 x6 |
📝 Azure Subscription Activity Log Alert for Create or Update Network Security Group does not exist 🟢 | 1 | 🟢 x6 |
📝 Azure Subscription Activity Log Alert for Create or Update Security Solution does not exist 🟢 | 1 | 🟢 x6 |
📝 Azure Subscription Activity Log Alert for Create Policy Assignment does not exist 🟢 | 1 | 🟢 x6 |
📝 Azure Subscription Activity Log Alert for Delete Network Security Group does not exist 🟢 | 1 | 🟢 x6 |
📝 Azure Subscription Activity Log Alert for Delete Policy Assignment does not exist 🟢 | 1 | 🟢 x6 |
📝 Azure Subscription Activity Log Alert for Delete Security Solution does not exist 🟢 | 1 | 🟢 x6 |
📝 Google BigQuery Dataset is anonymously or publicly accessible 🟢 | 1 | 🟢 x6 |
📝 Google Cloud Audit Logging is not configured properly 🟢 | 1 | 🟢 x6 |
📝 Google Cloud PostgreSQL Instance Log_error_verbosity Database Flag is not set to DEFAULT or stricter 🟢 | 1 | 🟢 x6 |
📝 Google Cloud PostgreSQL Instance Log_connections Database Flag is not set to On 🟢 | 1 | 🟢 x6 |
📝 Google Cloud PostgreSQL Instance Log_disconnections Database Flag is not set to On 🟢 | 1 | 🟢 x6 |
📝 Google Cloud PostgreSQL Instance Log_min_error_statement Database Flag is not set to Error or stricter 🟢 | 1 | 🟢 x6 |
📝 Google Cloud PostgreSQL Instance Log_min_messages Database Flag is not set at minimum to Warning 🟢 | 1 | 🟢 x6 |
📝 Google Cloud PostgreSQL Instance Log_statement Database Flag is not set appropriately 🟢 | 1 | 🟢 x6 |
📝 Google Cloud SQL Instance External Authorized Networks do not whitelist all public IP addresses 🟢 | 1 | 🟢 x6 |
📝 Google GCE Instance has a public IP address 🟢 | 1 | 🟢 x6 |
📝 Google GCE Network has Firewall Rules which allow unrestricted SSH access from the Internet 🟢 | 1 | 🟢 x6 |
📝 Google GCE Subnetwork Flow Logs are not enabled 🟢 | 1 | 🟢 x6 |
📝 Google HTTPS or SSL Proxy Load Balancer permits SSL policies with weak cipher suites 🟢 | | 🟢 x3 |
📝 Google Storage Bucket is anonymously or publicly accessible 🟢 | 1 | 🟢 x6 |