Reports for Every Cloud
Purpose-built reports that answer the questions cloud and security teams actually ask — across AWS, Azure, and Google Cloud.
58
Curated Reports
1705+
Controls Checked
3
Cloud Providers
5 min
To First Results

Activity Logs & Alerts
30 controls
11 services covered
Checks subscription activity log export, Monitor alert rules, Application Insights and Log Analytics ingestion controls, protected log-storage containers, and Defender for Cloud alert contact configuration.
What we check
Network Change Alerts6
- Create/Update NSG Log Alert Exists
- Delete NSG Log Alert Exists
- Create/Update NSG Rule Log Alert Exists
- Delete NSG Rule Log Alert Exists
- Activity Log Alert Rule Exists for Creating or Updating Public IP Addresses
- Activity Log Alert Rule Exists for Deleting Public IP Addresses
Subscription Activity Logs4
- Log Profile Enabled for All Subscriptions
- Diagnostic Settings Exists for Subscription
- Diagnostic Settings Capture Required Categories
- Log Profile Retention 365 Days
Security Solution and Policy Alerts4
- Create/Update Security Solution Log Alert Exists
- Delete Security Solution Log Alert Exists
- Create Policy Assignment Log Alert Exists
- Delete Policy Assignment Log Alert Exists
Log Storage Containers4
- Activity Log Storage Container Encrypted with BYOK
- Activity Log Storage Container Not Publicly Accessible
- Operational Log Storage Container Encrypted with BYOK
- Operational Log Storage Container Not Publicly Accessible
Security Alert Contacts3
- 'Additional email addresses' is Configured with a Security Contact Email
- 'All users with the following roles' is set to 'Owner'
- Alert Notifications are Enabled
Application Insights Components2
- Application Insights components should block log ingestion and querying from public networks
- Azure Monitor Logs for Application Insights should be linked to a Log Analytics workspace
Log Analytics Workspaces2
- Log Analytics workspaces should block log ingestion and querying from public networks
- Log Analytics Workspaces should block non-Azure Active Directory based ingestion
SQL Firewall Rule Alerts2
- Alert Rule Create/Update SQL Server Firewall Rule Exists
- Alert Rule Delete SQL Server Firewall Rule Exists
Administrative Operation Alerts1
- Log Alert for Administrative Operations
Network Flow Analytics1
- Network Watcher Flow Log Traffic Analytics Enabled
Security Monitoring Agents1
- 'Log Analytics agent/Azure Monitor agent' is Enabled
Run these reports on your own cloud
Connect an account and get your first set of reports in minutes — free to start, no credit card required.
