CNS Policies
Azure Knowledge Base
AWS Knowledge Base
Amazon EKS
Amazon RDS
Amazon Kinesis
AWS Organizations
Amazon SQS (Simple Queue Service)
AWS Cloudtrail
AWS Certificate Manager
AWS IAM
AWS Workspaces
Amazon S3
AWS Systems Manager (AWS SSM)
Amazon EC2
Amazon Redshift
Amazon EMR
Amazon CloudFront
Amazon DynamoDB
Amazon Managed Workflows for Apache Airflow (MWAA)
Amazon Route 53
AWS Key Management Service (KMS)
Amazon CloudWatch
Amazon ElasticSearch
AWS Database Migration Service
AWS Config
AWS X-Ray
Amazon API Gateway
Amazon Athena
Amazon SageMaker
AWS Elastic Load Balancing (ELB)
AWS Lambda
AWS Auto Scaling
Amazon GuardDuty
Amazon Elastic File System (Amazon EFS)
Amazon Elastic Container Registry (Amazon ECR)
AWS Glue
Amazon Simple Notification Service (SNS)
AWS Elastic Beanstalk
AWS CodeBuild
AWS Secrets Manager
AWS Transfer Family
Amazon Access Analyzer
Azure Knowledge Base
Container Registries
Azure Virtual Machines
Network Security Group
PostgreSQL
Azure Monitor
Azure Security Center
SQL Databases
SQL Servers
Storage Accounts
Azure Key Vaults
Load Balancers
App Services
Azure Active Directory
Activity Log
Azure Policy
Kubernetes Services
Azure Resources
Azure Cosmos DB
CDN Profiles
MySQL Servers
Azure Virtual Network
Azure Network Watcher
Azure Cache for Redis
GCP Knowledge Base
Google Cloud VPC
Google Cloud IAM
Google Cloud Load Balancing
Google Cloud Logging
Google Cloud Kubernetes Engine
Google Cloud Pub/Sub
Google Compute Engine
Google Cloud Key Management Service (KMS)
Google Cloud DNS
Google Cloud Storage
Google Cloud Dataproc
Google Cloud SQL
Google Cloud Spanner
Google Cloud Deployment Manager
Google Cloud BigQuery
Google Cloud Dataflow
DigitalOcean Knowledge Base
DigitalOcean Firewall
DigitalOcean Database
DigitalOcean Load Balancers
DigitalOcean Droplets
Back to home
CNS Policies
Azure Knowledge Base
AWS Knowledge Base
Amazon EKS
Amazon RDS
Amazon Kinesis
AWS Organizations
Amazon SQS (Simple Queue Service)
AWS Cloudtrail
AWS Certificate Manager
AWS IAM
AWS Workspaces
Amazon S3
AWS Systems Manager (AWS SSM)
Amazon EC2
Amazon Redshift
Amazon EMR
Amazon CloudFront
Amazon DynamoDB
Amazon Managed Workflows for Apache Airflow (MWAA)
Amazon Route 53
AWS Key Management Service (KMS)
Amazon CloudWatch
Amazon ElasticSearch
AWS Database Migration Service
AWS Config
AWS X-Ray
Amazon API Gateway
Amazon Athena
Amazon SageMaker
AWS Elastic Load Balancing (ELB)
AWS Lambda
AWS Auto Scaling
Amazon GuardDuty
Amazon Elastic File System (Amazon EFS)
Amazon Elastic Container Registry (Amazon ECR)
AWS Glue
Amazon Simple Notification Service (SNS)
AWS Elastic Beanstalk
AWS CodeBuild
AWS Secrets Manager
AWS Transfer Family
Amazon Access Analyzer
Azure Knowledge Base
Container Registries
Azure Virtual Machines
Network Security Group
PostgreSQL
Azure Monitor
Azure Security Center
SQL Databases
SQL Servers
Storage Accounts
Azure Key Vaults
Load Balancers
App Services
Azure Active Directory
Activity Log
Azure Policy
Kubernetes Services
Azure Resources
Azure Cosmos DB
CDN Profiles
MySQL Servers
Azure Virtual Network
Azure Network Watcher
Azure Cache for Redis
GCP Knowledge Base
Google Cloud VPC
Google Cloud IAM
Google Cloud Load Balancing
Google Cloud Logging
Google Cloud Kubernetes Engine
Google Cloud Pub/Sub
Google Compute Engine
Google Cloud Key Management Service (KMS)
Google Cloud DNS
Google Cloud Storage
Google Cloud Dataproc
Google Cloud SQL
Google Cloud Spanner
Google Cloud Deployment Manager
Google Cloud BigQuery
Google Cloud Dataflow
DigitalOcean Knowledge Base
DigitalOcean Firewall
DigitalOcean Database
DigitalOcean Load Balancers
DigitalOcean Droplets
Azure Knowledge Base
Security checks and vulnerability fixes for Azure.
Virtual Network Alerts Monitor
Container Registries
Azure Container Registries With Admin User
Azure Virtual Machines
VM Daily Backup Low Retention Period
Automatic Instance Repairs Disabled
VM Boot Diagnostic Disabled
Empty Scale Sets
Disk Volumes BYOK Encryption Disabled
VM Unapproved Extensions
VM Data Disk Encryption Disabled
VM Backups Disabled
VM Auto Update Disabled
VM OS Disk Encryption Disabled
Virtual Machine Performance Diagnostics Disabled
VM Active Directory (AD) Authentication Disabled
VM Availability Set Disabled
Scale Sets Health Monitoring Disabled
Guest Level Diagnostics Disabled
Unattached Disk Volumes
Accelerated Networking Disabled
VM Undesired SKU Size
Automatic OS Upgrades Disabled
Premium Data SSD Disk Enabled
No Recovery Services Vault
Scale Sets Autoscale Notifications Disabled
Low VM Instant Restore Backup Retention Limit
Old VM Disk Snapshots
Premium SSD Disk Enabled
See more
Network Security Group
Default Security Group Rules
Restricted Ports Open To Public
Open Kibana
Excessive Security Groups
Network Watcher Disabled
Open CIFS
Open Oracle
Open SMTP
Open DNS
Open SMBoTCP
Open Hadoop HDFS NameNode Metadata Service
Open Salt
Open NetBIOS
Open FTP
Open SQLServer
Open Telnet
Open VNC Client
Open MySQL
Open Docker
Open Hadoop HDFS NameNode WebUI
No Network Watcher
Open Oracle Auto Data Warehouse
Open SSH
Open All Ports
Open RDP
Open PostgreSQL
Open RPC
Open VNC Server
See more
PostgreSQL
Log Connections Disabled
Storage Auto-Growth Disabled
Azure Active Directory Admin Disabled
Connection Throttling Disabled
Log Disconnections Disabled
Low Log Retention Period
Geo-Redundant Backups Disabled
Log Duration Disabled
Log Checkpoints Disabled
Enforce PostgreSQL SSL Connection Disabled
See more
Azure Monitor
Key Vault Log Analytics Disabled
Azure Monitor No Diagnostic Settings
Key Vault No Diagnostic Settings
Azure Monitor Storage Account Not configured
No Log Profile
Log Profile No Retention Policy
NSG No Diagnostic Settings
Log Profile Archive Data For Critical Activities
Log Profile Low Retention Time
CDN No Diagnostic Settings
Load Balancer Log Analytics Disabled
Azure Monitor Logs Disabled
Load Balancer No Diagnostic Settings
CDN Profile Log Analytics Disabled
NSG Log Analytics Disabled
See more
Azure Security Center
Security Contacts Email Disabled
Admin Security Alerts Disabled
Auto-Provisioning Disabled
No Security Contact
High Severity Alerts Disabled
Security Contacts Phone Disabled
See more
SQL Databases
Database Auditing Disabled
SQL DB Multiple AZ Missing
Low Point in Time Restore Backup Retention
DB Not Restorable
SQL Servers
SQL Server Private Endpoints Not Configured
TDE Protector Encryption Disabled
SQL Server Minimum TLS Version
Server Auditing Disabled
Audit Action Groups Disabled
Auto-Failover Groups Disabled
SQL Server Allow Insecure TLS Version
Audit Retention Policy Limit
SQL Server Automatic Tuning Disabled
Azure Active Directory Admin Disabled
SQL Server Public Access
See more
Storage Accounts
Blobs Soft Deletion Disabled
Blob Service Not Immutable
Blob Service Encryption Disabled
Blob Container Public Access
Log Storage Encryption Disabled
Log Container Public Access
Trusted MS Access Disabled
Storage Accounts Without HTTPS-Only
Storage Account Encryption Disabled
Queue Service All Access ACL
Insecure Network Access Default Action
See more
Azure Key Vaults
Secret Expiration Disabled
Key Expiration Disabled
Key Vault Recovery Disabled
Load Balancers
Insecure Ports Open For Load Balancer
Load Balancers Without Instances
Load Balancers HTTPS Only Not Configured
Public Load Balancers
App Services
.NET Framework Version Not Latest
HTTP 2.0 Disabled
Insecure TLS Version Supported
Identity Disabled
Outdated Java Version
HTTPS Only Disabled
Outdate PHP Version
Outdated Python Version
Web Apps Always On Disabled
Authentication Disabled
Web Apps Remote Debugging Enabled
See more
Azure Active Directory
Custom Owner Roles
Activity Log
Network Security Groups Logging Disabled
Security Policy Alerts Disabled
Network Security Group Rule Logging Disabled
Policy Assignment Alerts Enabled
Security Solutions Logging
See more
Azure Policy
No Policy Assignment
Resource Location Matches Resource Groups
Missing Allowed Locations Policy
Kubernetes Services
Kubernetes Different Node Pool Version
Kubernetes RBAC Disabled
Outdated Kubernetes Version
Azure Resources
Resources Usage Limit Exceed
Management Lock Disabled
Azure Cosmos DB
Advanced Threat Protection Disabled
CosmosDB Public Access Enabled
CDN Profiles
CDN Profile HTTP Enabled
CDN Profile Endpoint Logging Disabled
MySQL Servers
MySQL SSL Connection Enforcement Disabled
Azure Virtual Network
Managed NAT Gateway Disabled
Established Network Gateways Connections
Network Gateways In Use
DDoS Standard Protection Disabled
Unknown Virtual Network Peering
Single Subnet
See more
Azure Network Watcher
NSG Flow Logs Retention Period
Azure Cache for Redis
SSL Access Only Disabled
Insecure TLS Version Supported