168 checks across every corner of the account
An agentless scan reads each connected AWS account through a read-only role and runs 168 checks — a 150-check baseline, a 12-check Foundational Security Best Practices gap pack, and a 6-check resource-hygiene pack (unattached security groups, idle Elastic IPs, orphaned volumes and interfaces, unused IAM roles, idle load balancers) — flagging public exposure, weak or over-privileged IAM, and misconfiguration.
IAM & identity
Root-account MFA and access keys, console users without MFA, unrotated and unused keys, AdministratorAccess attached straight to users, wildcard and privilege-escalation policies, cross-account trust missing an external ID, and IAM Access Analyzer coverage.
S3 & storage
Publicly accessible buckets, Block Public Access gaps, missing server-side encryption, versioning, access logging and lifecycle rules — plus object-lock, MFA-delete and replication posture for compliance-critical data.
EC2 & compute
Security groups open to 0.0.0.0/0 on sensitive ports, unencrypted volumes and snapshots, and the RDS, Lambda, ECS and EKS workloads running alongside — from public function URLs to privileged containers.
CloudTrail & KMS
Multi-region trail coverage, log-file validation, GuardDuty and AWS Config enablement, and KMS key management — so nothing meaningful happens in the account without an encrypted, auditable record.
VPC & network
Default security groups and network ACLs left wide open, missing VPC flow logs, and internet-facing exposure — the network paths an intruder would actually move through.
FSBP gap pack
A 12-check pack that closes the highest-impact holes in AWS Foundational Security Best Practices — Security Hub and Access Analyzer enablement, AWS Backup vault locks, SSM Patch Manager, WAF web ACLs, DynamoDB, Macie and Inspector.
Network & data-flow diagram
Every VPC, subnet, gateway, firewall and data store, auto-drawn into the network and data-flow diagram PCI DSS 1.2.3 / 1.2.4 (and CMMC, ISO 27001, SOC 2, HIPAA) require — generated from the live scan and exportable as SVG for auditors.