Reports for Every Cloud

Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.

58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results
ASecureCloud report preview
AWS logo

Detection & Response Best Practices

49 controls
22 services covered

Checks threat detection and response — GuardDuty, Security Hub, Inspector, and Macie enablement and delegated administration, AWS Config, finding aggregation, and real-time alerting through CloudWatch event rules, metric filters, and alarm actions.

What we check

CloudWatch Metric Filter Alarms7
  • Ensure a log metric filter and alarm exist for usage of root account
  • Ensure a log metric filter and alarm exist for Management Console sign-in without MFA
  • Ensure a log metric filter and alarm exist for IAM policy changes
  • Ensure a log metric filter and alarm exist for unauthorized API calls
  • Ensure a log metric filter and alarm exist for AWS Management Console authentication failures
  • Ensure a log metric filter and alarm exist for CloudTrail configuration changes
  • Ensure a log metric filter and alarm exist for AWS Config configuration changes
EventBridge Finding Alert Rules6
  • Real-Time Alerts Configured for GuardDuty Findings
  • Real-Time Alerts Configured for Inspector Findings
  • Real-Time Alerts Configured for Macie Findings
  • Real-Time Alerts Configured for AWS Security Hub Findings
  • Real-Time Alerts Configured for Config Compliance Events
  • Real-Time Alerts Configured for IAM Access Analyzer Findings
Security Hub Organization Settings5
  • Security Hub Findings Aggregated to Dedicated Security Account
  • Security Hub Finding Cross-Region Aggregation is Configured
  • Security Hub Auto-Enroll Accounts in the Organization
  • Security Hub Auto-Enable New Controls Configured
  • Security Hub Management is Delegated in the Organization
Inspector Lambda Scanning4
  • Amazon Inspector Lambda Standard Scanning is Enabled
  • Inspector Lambda Code Scanning Enabled
  • Lambda Functions Covered by Inspector Vulnerability Scanning
  • No active Inspector Findings for Lambda Functions
GuardDuty Organization Settings3
  • GuardDuty Security Findings are Aggregated to a Dedicated Account
  • GuardDuty Auto-Enroll Accounts in the Organization
  • GuardDuty Management is Delegated in the Organization
Inspector EC2 Scanning3
  • Inspector Scanning Enabled for EC2
  • EC2 Instances Covered by Inspector Vulnerability Scanning
  • No Active Inspector Findings for EC2 Instances
Inspector ECR Scanning3
  • Inspector Scanning Enabled for ECR
  • ECR Repositories Covered by Inspector Vulnerability Scanning
  • No active Inspector Findings for ECR Repositories
GuardDuty S3 Protection2
  • GuardDuty S3 Protection Enabled
  • GuardDuty S3 Protection Auto-Enroll Accounts in the Organization
Security Hub Settings2
  • AWS Security Hub is Enabled
  • AWS Security Best Practices Monitoring Enabled
Macie Organization Settings2
  • Macie Auto-Enroll Accounts in the Organization
  • Macie Findings are Aggregated to a Dedicated Account
GuardDuty Settings1
  • Amazon GuardDuty is Enabled
GuardDuty Findings1
  • No Active GuardDuty Findings
GuardDuty EC2 Malware Protection1
  • GuardDuty EC2 Malware Protection Enabled
GuardDuty Runtime Protection1
  • GuardDuty Runtime Protection Enabled
GuardDuty Lambda Protection1
  • GuardDuty Lambda Protection Enabled
GuardDuty RDS Protection1
  • GuardDuty RDS Login Events Protection Enabled
Security Hub Findings1
  • No Active Security Hub Findings
Macie Settings1
  • Amazon Macie Enabled
Macie Findings1
  • Amazon Macie Active Findings
CloudWatch Alarms1
  • CloudWatch Alarm Action is Configured
AWS Config Settings1
  • AWS Config should be enabled and use the service-linked role for resource recording
Config Recorders1
  • Config configuration recorder should not fail to deliver logs

Run these reports on your own cloud

Connect an account and get your first set of reports in minutes — free to start, no credit card required.