CNS Policies
Azure Knowledge Base
AWS Knowledge Base
Amazon EKS
Amazon RDS
Amazon Kinesis
AWS Organizations
Amazon SQS (Simple Queue Service)
AWS Cloudtrail
AWS Certificate Manager
AWS IAM
AWS Workspaces
Amazon S3
AWS Systems Manager (AWS SSM)
Amazon EC2
Amazon Redshift
Amazon EMR
Amazon CloudFront
Amazon DynamoDB
Amazon Managed Workflows for Apache Airflow (MWAA)
Amazon Route 53
AWS Key Management Service (KMS)
Amazon CloudWatch
Amazon ElasticSearch
AWS Database Migration Service
AWS Config
AWS X-Ray
Amazon API Gateway
Amazon Athena
Amazon SageMaker
AWS Elastic Load Balancing (ELB)
AWS Lambda
AWS Auto Scaling
Amazon GuardDuty
Amazon Elastic File System (Amazon EFS)
Amazon Elastic Container Registry (Amazon ECR)
AWS Glue
Amazon Simple Notification Service (SNS)
AWS Elastic Beanstalk
AWS CodeBuild
AWS Secrets Manager
AWS Transfer Family
Amazon Access Analyzer
Azure Knowledge Base
Container Registries
Azure Virtual Machines
Network Security Group
PostgreSQL
Azure Monitor
Azure Security Center
SQL Databases
SQL Servers
Storage Accounts
Azure Key Vaults
Load Balancers
App Services
Azure Active Directory
Activity Log
Azure Policy
Kubernetes Services
Azure Resources
Azure Cosmos DB
CDN Profiles
MySQL Servers
Azure Virtual Network
Azure Network Watcher
Azure Cache for Redis
GCP Knowledge Base
Google Cloud VPC
Google Cloud IAM
Google Cloud Load Balancing
Google Cloud Logging
Google Cloud Kubernetes Engine
Google Cloud Pub/Sub
Google Compute Engine
Google Cloud Key Management Service (KMS)
Google Cloud DNS
Google Cloud Storage
Google Cloud Dataproc
Google Cloud SQL
Google Cloud Spanner
Google Cloud Deployment Manager
Google Cloud BigQuery
Google Cloud Dataflow
DigitalOcean Knowledge Base
DigitalOcean Firewall
DigitalOcean Database
DigitalOcean Load Balancers
DigitalOcean Droplets
Back to home
CNS Policies
Azure Knowledge Base
AWS Knowledge Base
Amazon EKS
Amazon RDS
Amazon Kinesis
AWS Organizations
Amazon SQS (Simple Queue Service)
AWS Cloudtrail
AWS Certificate Manager
AWS IAM
AWS Workspaces
Amazon S3
AWS Systems Manager (AWS SSM)
Amazon EC2
Amazon Redshift
Amazon EMR
Amazon CloudFront
Amazon DynamoDB
Amazon Managed Workflows for Apache Airflow (MWAA)
Amazon Route 53
AWS Key Management Service (KMS)
Amazon CloudWatch
Amazon ElasticSearch
AWS Database Migration Service
AWS Config
AWS X-Ray
Amazon API Gateway
Amazon Athena
Amazon SageMaker
AWS Elastic Load Balancing (ELB)
AWS Lambda
AWS Auto Scaling
Amazon GuardDuty
Amazon Elastic File System (Amazon EFS)
Amazon Elastic Container Registry (Amazon ECR)
AWS Glue
Amazon Simple Notification Service (SNS)
AWS Elastic Beanstalk
AWS CodeBuild
AWS Secrets Manager
AWS Transfer Family
Amazon Access Analyzer
Azure Knowledge Base
Container Registries
Azure Virtual Machines
Network Security Group
PostgreSQL
Azure Monitor
Azure Security Center
SQL Databases
SQL Servers
Storage Accounts
Azure Key Vaults
Load Balancers
App Services
Azure Active Directory
Activity Log
Azure Policy
Kubernetes Services
Azure Resources
Azure Cosmos DB
CDN Profiles
MySQL Servers
Azure Virtual Network
Azure Network Watcher
Azure Cache for Redis
GCP Knowledge Base
Google Cloud VPC
Google Cloud IAM
Google Cloud Load Balancing
Google Cloud Logging
Google Cloud Kubernetes Engine
Google Cloud Pub/Sub
Google Compute Engine
Google Cloud Key Management Service (KMS)
Google Cloud DNS
Google Cloud Storage
Google Cloud Dataproc
Google Cloud SQL
Google Cloud Spanner
Google Cloud Deployment Manager
Google Cloud BigQuery
Google Cloud Dataflow
DigitalOcean Knowledge Base
DigitalOcean Firewall
DigitalOcean Database
DigitalOcean Load Balancers
DigitalOcean Droplets
Azure Knowledge Base
Security checks and vulnerability fixes for Azure.
Virtual Network Alerts Monitor
Container Registries
Azure Container Registries With Admin User
Azure Virtual Machines
Premium SSD Disk Enabled
Old VM Disk Snapshots
Low VM Instant Restore Backup Retention Limit
Scale Sets Autoscale Notifications Disabled
No Recovery Services Vault
Premium Data SSD Disk Enabled
Automatic OS Upgrades Disabled
VM Undesired SKU Size
Accelerated Networking Disabled
Unattached Disk Volumes
Guest Level Diagnostics Disabled
Scale Sets Health Monitoring Disabled
VM Availability Set Disabled
VM Active Directory (AD) Authentication Disabled
Virtual Machine Performance Diagnostics Disabled
VM OS Disk Encryption Disabled
VM Auto Update Disabled
VM Backups Disabled
VM Data Disk Encryption Disabled
VM Unapproved Extensions
Disk Volumes BYOK Encryption Disabled
Empty Scale Sets
VM Boot Diagnostic Disabled
Automatic Instance Repairs Disabled
VM Daily Backup Low Retention Period
See more
Network Security Group
Open VNC Server
Open RPC
Open PostgreSQL
Open RDP
Open All Ports
Open SSH
Open Oracle Auto Data Warehouse
No Network Watcher
Open Hadoop HDFS NameNode WebUI
Open Docker
Open MySQL
Open VNC Client
Open Telnet
Open SQLServer
Open FTP
Open NetBIOS
Open Salt
Open Hadoop HDFS NameNode Metadata Service
Open SMBoTCP
Open DNS
Open SMTP
Open Oracle
Open CIFS
Network Watcher Disabled
Excessive Security Groups
Open Kibana
Restricted Ports Open To Public
Default Security Group Rules
See more
PostgreSQL
Enforce PostgreSQL SSL Connection Disabled
Log Checkpoints Disabled
Log Duration Disabled
Geo-Redundant Backups Disabled
Low Log Retention Period
Log Disconnections Disabled
Connection Throttling Disabled
Azure Active Directory Admin Disabled
Storage Auto-Growth Disabled
Log Connections Disabled
See more
Azure Monitor
NSG Log Analytics Disabled
CDN Profile Log Analytics Disabled
Load Balancer No Diagnostic Settings
Azure Monitor Logs Disabled
Load Balancer Log Analytics Disabled
CDN No Diagnostic Settings
Log Profile Low Retention Time
Log Profile Archive Data For Critical Activities
NSG No Diagnostic Settings
Log Profile No Retention Policy
No Log Profile
Azure Monitor Storage Account Not configured
Key Vault No Diagnostic Settings
Azure Monitor No Diagnostic Settings
Key Vault Log Analytics Disabled
See more
Azure Security Center
Security Contacts Phone Disabled
High Severity Alerts Disabled
No Security Contact
Auto-Provisioning Disabled
Admin Security Alerts Disabled
Security Contacts Email Disabled
See more
SQL Databases
DB Not Restorable
Low Point in Time Restore Backup Retention
SQL DB Multiple AZ Missing
Database Auditing Disabled
SQL Servers
SQL Server Public Access
Azure Active Directory Admin Disabled
SQL Server Automatic Tuning Disabled
Audit Retention Policy Limit
SQL Server Allow Insecure TLS Version
Auto-Failover Groups Disabled
Audit Action Groups Disabled
Server Auditing Disabled
SQL Server Minimum TLS Version
TDE Protector Encryption Disabled
SQL Server Private Endpoints Not Configured
See more
Storage Accounts
Insecure Network Access Default Action
Queue Service All Access ACL
Storage Account Encryption Disabled
Storage Accounts Without HTTPS-Only
Trusted MS Access Disabled
Log Container Public Access
Log Storage Encryption Disabled
Blob Container Public Access
Blob Service Encryption Disabled
Blob Service Not Immutable
Blobs Soft Deletion Disabled
See more
Azure Key Vaults
Key Vault Recovery Disabled
Key Expiration Disabled
Secret Expiration Disabled
Load Balancers
Public Load Balancers
Load Balancers HTTPS Only Not Configured
Load Balancers Without Instances
Insecure Ports Open For Load Balancer
App Services
Web Apps Remote Debugging Enabled
Authentication Disabled
Web Apps Always On Disabled
Outdated Python Version
Outdate PHP Version
HTTPS Only Disabled
Outdated Java Version
Identity Disabled
Insecure TLS Version Supported
HTTP 2.0 Disabled
.NET Framework Version Not Latest
See more
Azure Active Directory
Custom Owner Roles
Activity Log
Security Solutions Logging
Policy Assignment Alerts Enabled
Network Security Group Rule Logging Disabled
Security Policy Alerts Disabled
Network Security Groups Logging Disabled
See more
Azure Policy
Missing Allowed Locations Policy
Resource Location Matches Resource Groups
No Policy Assignment
Kubernetes Services
Outdated Kubernetes Version
Kubernetes RBAC Disabled
Kubernetes Different Node Pool Version
Azure Resources
Management Lock Disabled
Resources Usage Limit Exceed
Azure Cosmos DB
CosmosDB Public Access Enabled
Advanced Threat Protection Disabled
CDN Profiles
CDN Profile Endpoint Logging Disabled
CDN Profile HTTP Enabled
MySQL Servers
MySQL SSL Connection Enforcement Disabled
Azure Virtual Network
Single Subnet
Unknown Virtual Network Peering
DDoS Standard Protection Disabled
Network Gateways In Use
Established Network Gateways Connections
Managed NAT Gateway Disabled
See more
Azure Network Watcher
NSG Flow Logs Retention Period
Azure Cache for Redis
Insecure TLS Version Supported
SSL Access Only Disabled