Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Logging & Audit
65 controls
41 services covered
Confirms access, audit, object-level, and activity logging is enabled across the account — CloudTrail, VPC flow logs, load balancers, CloudFront, API Gateway, Route 53, RDS, DynamoDB, OpenSearch, MSK, EKS, Lambda, Step Functions, Bedrock, Connect, and many more services.
What we check
RDS Event Subscriptions5
- RDS Event Subscriptions: DB Parameter Group Changes
- RDS Event Subscription for DB Security Group Changes
- RDS Event Subscriptions: Cluster or Instance Failure Event Monitoring is Enabled
- RDS Event Subscriptions: Instance Availability Event Monitoring is Enabled
- RDS Event Subscriptions: Instance Low Storage Event Monitoring is Enabled
RDS DB Instances4
- RDS Logging
- RDS for PostgreSQL DB instances should publish logs to CloudWatch Logs
- RDS for SQL Server DB instances should publish logs to CloudWatch Logs
- RDS for MariaDB DB instances should publish logs to CloudWatch Logs
API Gateway Stages4
- API Stage Access Logging
- API (v2) Stage Access Logging
- API Stage Execution Logging
- X-Ray Tracing Enabled
CloudTrail Trails4
- Ensure CloudTrail is Enabled for this Region
- CloudTrail Global Services Enabled
- CloudTrail Trail Insights is Enabled
- Ensure that a Multi-Region CloudTrail Trail is Configured
S3 Access and Data Event Logging3
- S3 Server Access Logs
- S3 Object-Level Read Events Logging (CloudTrail)
- S3 Object-Level Write Events Logging (CloudTrail)
OpenSearch Domains3
- OpenSearch Audit Logging
- Amazon Elasticsearch Domain Application/Performance Logging Enabled
- OpenSearch domain error logging to CloudWatch Logs should be enabled
CloudTrail Log Delivery and Integrity3
- Ensure that CloudTrail Logs are forwarded to CloudWatch
- Ensure that CloudTrail logs are encrypted using KMS
- Ensure that CloudTrail Log File Validation is Enabled
CloudFront Logging2
- CloudFront Access Logs
- CloudFront Real-Time Logging
WAF Logging2
- WAF WebACL Logging
- WAFv2 Rule Group Logging Enabled
CloudTrail S3 Log Buckets2
- S3 Bucket for CloudTrail has Access Logging Enabled
- External S3 Bucket for CloudTrail Logs
Site-to-Site VPN Connections2
- EC2 Client VPN Endpoint Client Connection Logging Enabled
- EC2 VPN connections should have logging enabled
DMS Replication Tasks2
- DMS replication tasks for the target database should have logging enabled
- DMS replication tasks for the source database should have logging enabled
VPC Flow Logs1
- VPC Flow Logs
VPC Route Tables1
- VPC DNS Logging (Route53)
Classic Load Balancers1
- ELB Access Logs
RDS DB Clusters1
- Aurora MySQL DB clusters should publish audit logs to CloudWatch Logs
EKS Control Plane1
- EKS Control Plane Logging
ACM Certificates1
- Certificate Transparency Logging
Route 53 Hosted Zones1
- Route 53 Public Hosted Zone Query Logging
DocumentDB Clusters1
- DocumentDB Audit Logging
Neptune Clusters1
- Neptune Audit Logging
MSK Clusters1
- MSK Broker Logging
MSK Connect Connectors1
- MSK connectors should have logging enabled
AppSync Logging1
- AWS AppSync API Logging Configuration Check
Athena Workgroups1
- Athena WorkGroup CloudWatch Usage Metrics Logging Check
Bedrock Model Invocation Logging1
- Amazon Bedrock Model Invocation Logging Enabled
Bedrock Knowledge Bases1
- Bedrock Knowledge Bases Ingestion Logging Enabled
DataSync Tasks1
- DataSync Task Logging Configuration Check
Directory Service Logs1
- Directory Service Domain Controller Has Security Event Logging Enabled
DynamoDB Tables1
- DynamoDB Operations Logging with CloudTrail is Enabled
Elastic Beanstalk Environments1
- Elastic Beanstalk Streaming Logs to CloudWatch Enabled
FSx File Systems1
- FSx Windows File Access Audit Enabled
Glue Jobs1
- AWS Glue Job Logging Enabled Check
Lambda Logging1
- Lambda function Logging is enabled
Amazon MQ Brokers1
- MQ CloudWatch Audit Logging Enabled
Network Firewall Firewalls1
- Network Firewall Logging Enabled Check
Step Functions State Machines1
- AWS Step Functions State Machine Logging Enabled Check
Amazon Connect Instances1
- Connect Customer instances should have CloudWatch logging enabled
Redshift Serverless Namespaces1
- Redshift Serverless namespaces should export logs to CloudWatch Logs
Systems Manager Automation1
- SSM Automation should have CloudWatch logging enabled
Transfer Family Connectors1
- Transfer Family connectors should have logging enabled
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
