Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Detection & Response Best Practices
49 controls
22 services covered
Checks threat detection and response — GuardDuty, Security Hub, Inspector, and Macie enablement and delegated administration, AWS Config, finding aggregation, and real-time alerting through CloudWatch event rules, metric filters, and alarm actions.
What we check
CloudWatch Metric Filter Alarms7
- Ensure a log metric filter and alarm exist for usage of root account
- Ensure a log metric filter and alarm exist for Management Console sign-in without MFA
- Ensure a log metric filter and alarm exist for IAM policy changes
- Ensure a log metric filter and alarm exist for unauthorized API calls
- Ensure a log metric filter and alarm exist for AWS Management Console authentication failures
- Ensure a log metric filter and alarm exist for CloudTrail configuration changes
- Ensure a log metric filter and alarm exist for AWS Config configuration changes
EventBridge Finding Alert Rules6
- Real-Time Alerts Configured for GuardDuty Findings
- Real-Time Alerts Configured for Inspector Findings
- Real-Time Alerts Configured for Macie Findings
- Real-Time Alerts Configured for AWS Security Hub Findings
- Real-Time Alerts Configured for Config Compliance Events
- Real-Time Alerts Configured for IAM Access Analyzer Findings
Security Hub Organization Settings5
- Security Hub Findings Aggregated to Dedicated Security Account
- Security Hub Finding Cross-Region Aggregation is Configured
- Security Hub Auto-Enroll Accounts in the Organization
- Security Hub Auto-Enable New Controls Configured
- Security Hub Management is Delegated in the Organization
Inspector Lambda Scanning4
- Amazon Inspector Lambda Standard Scanning is Enabled
- Inspector Lambda Code Scanning Enabled
- Lambda Functions Covered by Inspector Vulnerability Scanning
- No active Inspector Findings for Lambda Functions
GuardDuty Organization Settings3
- GuardDuty Security Findings are Aggregated to a Dedicated Account
- GuardDuty Auto-Enroll Accounts in the Organization
- GuardDuty Management is Delegated in the Organization
Inspector EC2 Scanning3
- Inspector Scanning Enabled for EC2
- EC2 Instances Covered by Inspector Vulnerability Scanning
- No Active Inspector Findings for EC2 Instances
Inspector ECR Scanning3
- Inspector Scanning Enabled for ECR
- ECR Repositories Covered by Inspector Vulnerability Scanning
- No active Inspector Findings for ECR Repositories
GuardDuty S3 Protection2
- GuardDuty S3 Protection Enabled
- GuardDuty S3 Protection Auto-Enroll Accounts in the Organization
Security Hub Settings2
- AWS Security Hub is Enabled
- AWS Security Best Practices Monitoring Enabled
Macie Organization Settings2
- Macie Auto-Enroll Accounts in the Organization
- Macie Findings are Aggregated to a Dedicated Account
GuardDuty Settings1
- Amazon GuardDuty is Enabled
GuardDuty Findings1
- No Active GuardDuty Findings
GuardDuty EC2 Malware Protection1
- GuardDuty EC2 Malware Protection Enabled
GuardDuty Runtime Protection1
- GuardDuty Runtime Protection Enabled
GuardDuty Lambda Protection1
- GuardDuty Lambda Protection Enabled
GuardDuty RDS Protection1
- GuardDuty RDS Login Events Protection Enabled
Security Hub Findings1
- No Active Security Hub Findings
Macie Settings1
- Amazon Macie Enabled
Macie Findings1
- Amazon Macie Active Findings
CloudWatch Alarms1
- CloudWatch Alarm Action is Configured
AWS Config Settings1
- AWS Config should be enabled and use the service-linked role for resource recording
Config Recorders1
- Config configuration recorder should not fail to deliver logs
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
