Account ****-****-7034·Last scan: 2 hours agoDeep ScanDemo
Type II
Rev 5
Security Rule
v4.0
Safeguards Rule
AWS Foundations
2022
Threat Model
Root account MFA not enabled
Security group sg-0a3f8e12 allows SSH from 0.0.0.0/0
Security group sg-0b7c4d99 allows all traffic from 0.0.0.0/0
No multi-region trail configured
User deploy-bot has access keys but no MFA
No password policy configured
Bucket app-logs-staging has no encryption
Trail prod-trail is not logging
RDS instance analytics-db is publicly accessible
User ci-pipeline has access keys but no MFA
Bucket temp-uploads missing public access block
VPC vpc-0f9a8b12 has no flow logs
User legacy-admin has access key older than 90 days
KMS key a1b2c3d4-... does not have rotation enabled
Trail prod-trail has no log file validation
Bucket cdn-assets missing public access block
Auditor questions analysis — see which can be auto-answered and which need documentation
Define which resources are in scope for compliance reporting
Deploy a read-only IAM role via CloudFormation. Get your first compliance report before your coffee gets cold.