AWS

Amazon AWS security scanning

Scan 78 AWS services for public exposure, weak IAM, unencrypted storage and missing audit trails.

How you connect

Connect with an IAM access key or, preferably, a cross-account role with an external ID. A1 Cloud Guard needs read-only permissions.

What A1 Cloud Guard looks for

  • S3 buckets readable by anyone on the internet
  • Security groups allowing 0.0.0.0/0 on SSH or RDS ports
  • IAM users with long-lived access keys and no MFA
  • RDS instances and EBS volumes without encryption at rest
  • CloudTrail disabled, or not writing to a protected bucket

78 services covered

Choose any combination per scan — you are never forced to scan the whole estate.

  • EC2 Instances
  • EBS Volumes
  • Auto Scaling Groups
  • Load Balancers
  • Lambda Functions
  • Elastic IP Addresses
  • Elastic Beanstalk
  • EKS Clusters
  • ECS
  • ECR
  • S3 Buckets
  • EFS
  • FSx
  • RDS Databases
  • DynamoDB
  • ElastiCache
  • DocumentDB
  • Neptune
  • Redshift
  • VPC
  • Security Groups
  • CloudFront
  • Route 53
  • WAF
  • API Gateway
  • IAM Users
  • IAM Policies
  • KMS Keys
  • Secrets Manager
  • ACM Certificates
  • Systems Manager
  • CloudTrail
  • CloudWatch
  • CloudWatch Alarms
  • GuardDuty
  • Inspector
  • SNS
  • SQS
  • MSK (Kafka)
  • Amazon MQ
  • Athena
  • Glue
  • EMR
  • OpenSearch
  • DMS
  • SageMaker
  • CodeDeploy
  • CloudFormation
  • Step Functions
  • EventBridge
  • AppSync
  • Transfer Family
  • AWS Config
  • Security Hub
  • Organizations
  • AWS Backup
  • Cognito
  • CodeBuild
  • Kinesis Data Streams
  • Data Firehose
  • Network Firewall
  • MemoryDB
  • Route 53 Resolver
  • IAM Identity Center
  • ACM Private CA
  • Directory Service
  • SES
  • Bedrock
  • WorkSpaces
  • Shield Advanced
  • Global Accelerator
  • AWS Batch
  • App Runner
  • Amplify
  • MWAA
  • Redshift Serverless
  • OpenSearch Serverless
  • Lake Formation

Scan your AWS estate

Connect a read-only credential and see the full report on the free plan.