📝 AWS Backup Vault contains unencrypted Recovery Points 🟢 | 1 | 🟢 x6 |
📝 AWS CodeBuild Project Bitbucket Source Location URL contains credentials 🟢 | 1 | 🟢 x6 |
📝 AWS DynamoDB Table Point In Time Recovery is not enabled 🟢 | 1 | 🟢 x6 |
📝 AWS EC2 Security Group allows public IPv4 (0.0.0.0/0) access to admin ports 🟢 | 1 | 🟢 x6 |
📝 AWS EC2 Security Group allows public IPv6 (::/0) access to admin ports 🟢 | 1 | 🟢 x6 |
📝 AWS S3 Bucket MFA Delete is not enabled 🟠🟢 | 1 | 🟠 x1, 🟢 x6 |
📝 Google API Key is not restricted for unused APIs 🟢 | 1 | 🟢 x6 |
📝 Google API Key is not rotated every 90 days 🟢 | 1 | 🟢 x6 |
📝 Google BigQuery Dataset is anonymously or publicly accessible 🟢 | 1 | 🟢 x6 |
📝 Google Cloud Asset Inventory API is not enabled 🟢 | 1 | 🟢 x6 |
📝 Google Cloud DNS Managed Zone DNSSEC is not enabled 🟢 | 1 | 🟢 x6 |
📝 Google Cloud DNS Managed Zone DNSSEC Key-Signing Algorithm is RSASHA1 🟢 | 1 | 🟢 x6 |
📝 Google Cloud DNS Managed Zone DNSSEC Zone-Signing Algorithm is RSASHA1 🟢 | 1 | 🟢 x6 |
📝 Google Cloud MySQL Instance allows anyone to connect with administrative privileges 🟢 | | 🟢 x3 |
📝 Google Cloud SQL Server Instance 3625 (trace flag) Database Flag is not set to on 🟢 | 1 | 🟢 x6 |
📝 Google Cloud SQL Server Instance user connections Database Flag is set to a limiting (other than 0) value 🟢 | 1 | 🟢 x6 |
📝 Google Cloud SQL Server Instance user options Database Flag is configured 🟢 | 1 | 🟢 x6 |
📝 Google Project has a default network 🟢 | 1 | 🟢 x6 |
📝 Google Project has a legacy network 🟢 | 1 | 🟢 x6 |
📝 Google Project has API Keys 🟢 | 1 | 🟠 x1, 🟢 x5 |
📝 Google Storage Bucket is anonymously or publicly accessible 🟢 | 1 | 🟢 x6 |