Commit f398469aab
Verified · cmc
Layout: unified · split
README.md added +249
| @@ -0,0 +1,249 @@ | ||
| 1 | # Overview | |
| 2 | ||
| 3 | This project is a Python-based tool that sends a daily plaintext email | |
| 4 | summarizing key AWS environment metrics and alerts. It is modular, | |
| 5 | configurable, and intended for solo or small-team AWS accounts that want | |
| 6 | automated visibility into infrastructure health, security, and cost. | |
| 7 | ||
| 8 | # Features | |
| 9 | ||
| 10 | - ✅ Daily billing breakdown (Cost Explorer) | |
| 11 | - ✅ New Security Hub findings | |
| 12 | - ✅ Route 53 health check status | |
| 13 | - ✅ CloudWatch alarms triggered in the last 24 hours | |
| 14 | - ✅ S3 bucket access/encryption audit | |
| 15 | - ✅ Expiring ACM certificates (next 30 days) | |
| 16 | - ✅ AWS Config non-compliant resources | |
| 17 | - ✅ CloudFront distribution changes (last 48h) | |
| 18 | - ✅ WAF blocked request summary (regional) | |
| 19 | ||
| 20 | The program is configured to be modular and accept new sections to the | |
| 21 | report as needed. To create a new section, simply create the | |
| 22 | `new_section.py` script inside the `sections/` directory and update the | |
| 23 | `sections` variable inside the `config.toml` file. | |
| 24 | ||
| 25 | # Directory Structure | |
| 26 | ||
| 27 | . | |
| 28 | ├── README.org ; This file | |
| 29 | ├── config.toml ; Configuration (AWS profile, region, etc.) | |
| 30 | ├── email_formatter.py ; Utility to format email body | |
| 31 | ├── main.py ; Main entry point for report generation | |
| 32 | ├── pyproject.toml ; Project metadata and dependencies | |
| 33 | ├── utils.py ; Shared utility functions | |
| 34 | ├── sections/ ; Modular report generators | |
| 35 | │ ├── acm.py ; ACM expiring certs | |
| 36 | │ ├── cloudfront.py ; CloudFront changes | |
| 37 | │ ├── cloudwatch.py ; Alarms | |
| 38 | │ ├── config.py ; Config compliance | |
| 39 | │ ├── costexplorer.py ; Billing | |
| 40 | │ ├── route53.py ; Health checks | |
| 41 | │ ├── s3.py ; Bucket audit | |
| 42 | │ └── securityhub.py ; Findings | |
| 43 | ||
| 44 | # Usage | |
| 45 | ||
| 46 | ## 1. Configure | |
| 47 | ||
| 48 | Edit `config.toml` to configure your AWS, email, and report options: | |
| 49 | ||
| 50 | ``` toml | |
| 51 | [aws] | |
| 52 | profile = "default" | |
| 53 | region = "us-east-1" | |
| 54 | ||
| 55 | [email] | |
| 56 | from = "you@example.com" | |
| 57 | to = ["you@example.com"] | |
| 58 | subject = "Daily AWS Report" | |
| 59 | ||
| 60 | [recipients] | |
| 61 | emails = [ | |
| 62 | "you@example.com" | |
| 63 | ] | |
| 64 | ||
| 65 | [report] | |
| 66 | sections = [ | |
| 67 | "acm" | |
| 68 | ] | |
| 69 | ``` | |
| 70 | ||
| 71 | If you do not already have an AWS profile (e.g., `default`), then you | |
| 72 | will need to install the AWS CLI and configure a profile first: | |
| 73 | ||
| 74 | ``` bash | |
| 75 | aws configure --profile default | |
| 76 | ``` | |
| 77 | ||
| 78 | ## 2. Run | |
| 79 | ||
| 80 | Use Python to run the report and send the email: | |
| 81 | ||
| 82 | ``` bash | |
| 83 | python main.py | |
| 84 | ``` | |
| 85 | ||
| 86 | Or, if you're using [uv](https://github.com/astral-sh/uv) (which will | |
| 87 | auto-install dependencies and create a virtual environment): | |
| 88 | ||
| 89 | ``` bash | |
| 90 | uv run main.py | |
| 91 | ``` | |
| 92 | ||
| 93 | Emails are plaintext with ASCII-formatted tables (via `tabulate`). | |
| 94 | ||
| 95 | <figure> | |
| 96 | <img src="./screenshots/uv.png" /> | |
| 97 | <figcaption>UV Run</figcaption> | |
| 98 | </figure> | |
| 99 | ||
| 100 | # Installation | |
| 101 | ||
| 102 | ## Dependencies | |
| 103 | ||
| 104 | Python 3.11+ is recommended. Install dependencies using: | |
| 105 | ||
| 106 | ``` bash | |
| 107 | pip install -r requirements.txt | |
| 108 | # or if you're using uv: | |
| 109 | uv sync | |
| 110 | ``` | |
| 111 | ||
| 112 | You may need to install: | |
| 113 | ||
| 114 | - `boto3` | |
| 115 | - `tabulate` | |
| 116 | ||
| 117 | ## AWS Permissions | |
| 118 | ||
| 119 | Ensure your IAM user or role has read access to: | |
| 120 | ||
| 121 | - Cost Explorer | |
| 122 | - Security Hub | |
| 123 | - S3, CloudFront, CloudWatch | |
| 124 | - Route 53, ACM, Config, WAF | |
| 125 | - SES (if sending emails from within AWS) | |
| 126 | ||
| 127 | # Customizing Sections | |
| 128 | ||
| 129 | Each section is defined in a file under `sections/` and implements a: | |
| 130 | ||
| 131 | ``` python | |
| 132 | def get_section(config) -> str: | |
| 133 | ... | |
| 134 | ``` | |
| 135 | ||
| 136 | You can add, remove, or modify these sections in `config.toml`. | |
| 137 | ||
| 138 | # Example Output | |
| 139 | ||
| 140 | Here's an example of the output in plain text format. | |
| 141 | ||
| 142 | Expiring TLS Certificates: | |
| 143 | No certs expiring in the next 30 days. | |
| 144 | ||
| 145 | CloudFront Changes: | |
| 146 | No distributions changed in the last 48h. | |
| 147 | ||
| 148 | CloudWatch Alarms: | |
| 149 | No alarms triggered in the last 24h. | |
| 150 | ||
| 151 | AWS Config Non-Compliant Resources: | |
| 152 | [https://eu-west-1.console.aws.amazon.com/config/home#/resources?complianceType=NON_COMPLIANT] | |
| 153 | ┌───────────────────────────────────────┬────────────────────────┐ | |
| 154 | │ Resource Type │ Resource ID │ | |
| 155 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 156 | │ AWS::::Account │ <account-id> │ | |
| 157 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 158 | │ AWS::EC2::VPC │ vpc-<id> │ | |
| 159 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 160 | │ AWS::EC2::Subnet │ subnet-<id> │ | |
| 161 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 162 | │ AWS::EC2::Subnet │ subnet-<id> │ | |
| 163 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 164 | │ AWS::EC2::Subnet │ subnet-<id> │ | |
| 165 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 166 | │ AWS::EC2::VPCBlockPublicAccessOptions │ <account-id> │ | |
| 167 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 168 | │ AWS::EC2::SecurityGroup │ sg-<id> │ | |
| 169 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 170 | │ AWS::S3::Bucket │ example-cf-logs │ | |
| 171 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 172 | │ AWS::S3::Bucket │ img.example.com │ | |
| 173 | └───────────────────────────────────────┴────────────────────────┘ | |
| 174 | ||
| 175 | AWS Billing Report for 2025-06-18 | |
| 176 | [https://eu-west-1.console.aws.amazon.com/costmanagement/] | |
| 177 | ┌────────────────────────────────────┬────────┐ | |
| 178 | │ Service │ Cost │ | |
| 179 | ├────────────────────────────────────┼────────┤ | |
| 180 | │ AWS CloudShell │ $0.00 │ | |
| 181 | │ AWS Config │ $0.17 │ | |
| 182 | │ AWS Glue │ $0.00 │ | |
| 183 | │ AWS HealthImaging │ $0.00 │ | |
| 184 | │ AWS Key Management Service │ $0.00 │ | |
| 185 | │ AWS Migration Hub Refactor Spaces │ $0.00 │ | |
| 186 | │ AWS Secrets Manager │ $0.00 │ | |
| 187 | │ AWS Security Hub │ $0.00 │ | |
| 188 | │ AWS Service Catalog │ $0.00 │ | |
| 189 | │ AWS WAF │ $0.29 │ | |
| 190 | │ Amazon CloudFront │ $0.00 │ | |
| 191 | │ Amazon GuardDuty │ $0.00 │ | |
| 192 | │ Amazon Location Service │ $0.00 │ | |
| 193 | │ Amazon Route 53 │ $0.01 │ | |
| 194 | │ Amazon Simple Notification Service │ $0.00 │ | |
| 195 | │ Amazon Simple Queue Service │ $0.00 │ | |
| 196 | │ Amazon Simple Storage Service │ $0.00 │ | |
| 197 | │ AmazonCloudWatch │ $0.00 │ | |
| 198 | │ CloudWatch Events │ $0.00 │ | |
| 199 | ├────────────────────────────────────┼────────┤ | |
| 200 | │ TOTAL │ $0.47 │ | |
| 201 | └────────────────────────────────────┴────────┘ | |
| 202 | ||
| 203 | Note: Costs are estimated and may change. | |
| 204 | ||
| 205 | Route 53 Health Checks: | |
| 206 | [https://eu-west-1.console.aws.amazon.com/route53/v2/healthchecks/home] | |
| 207 | ┌────────────────────┬──────────┐ | |
| 208 | │ Domain │ Status │ | |
| 209 | ├────────────────────┼──────────┤ | |
| 210 | │ img.example.com │ HEALTHY │ | |
| 211 | └────────────────────┴──────────┘ | |
| 212 | ||
| 213 | S3 Bucket Access Summary: | |
| 214 | [https://eu-west-1.console.aws.amazon.com/s3/home] | |
| 215 | ┌──────────────────────────────────────────────┬────────┬────────────┐ | |
| 216 | │ Bucket │ Public │ Encrypted │ | |
| 217 | ├──────────────────────────────────────────────┼────────┼────────────┤ | |
| 218 | │ aws-cloudtrail-logs-<account-id>-<suffix> │ No │ Yes │ | |
| 219 | │ example-cf-logs │ No │ Yes │ | |
| 220 | │ img.example.com │ No │ Yes │ | |
| 221 | └──────────────────────────────────────────────┴────────┴────────────┘ | |
| 222 | ||
| 223 | AWS Security Hub Findings (Last 24h): 18 new finding(s) | |
| 224 | [https://eu-west-1.console.aws.amazon.com/securityhub/home?region=eu-west-1#/findings] | |
| 225 | ┌───────────────┬────────────────────────────────────────────────────┬──────────────┬────────────────────────────────┐ | |
| 226 | │ Severity │ Title │ Product │ Resource │ | |
| 227 | ├───────────────┼────────────────────────────────────────────────────┼──────────────┼────────────────────────────────┤ | |
| 228 | │ INFORMATIONAL │ S3 buckets should have server access logging │ Security Hub │ arn:aws:s3:::img.example.com │ | |
| 229 | │ INFORMATIONAL │ S3 buckets should require requests to use HTTPS │ Security Hub │ arn:aws:s3:::img.example.com │ | |
| 230 | │ INFORMATIONAL │ S3 buckets should have lifecycle configuration │ Security Hub │ arn:aws:s3:::img.example.com │ | |
| 231 | │ INFORMATIONAL │ S3 buckets should block public access │ Security Hub │ arn:aws:s3:::example-cf-logs │ | |
| 232 | │ INFORMATIONAL │ ACLs should not be used to manage user access │ Security Hub │ arn:aws:s3:::img.example.com │ | |
| 233 | │ INFORMATIONAL │ EC2 subnets shouldn't auto-assign public IPs │ Security Hub │ arn:aws:ec2:eu-west-1:<acct> │ | |
| 234 | │ INFORMATIONAL │ VPC block public access should be enabled │ Security Hub │ arn:aws:ec2:eu-west-1:<acct> │ | |
| 235 | │ INFORMATIONAL │ S3 bucket policies should restrict public access │ Security Hub │ arn:aws:s3:::img.example.com │ | |
| 236 | │ INFORMATIONAL │ Unused network ACLs should be removed │ Security Hub │ arn:aws:ec2:eu-west-1:<acct> │ | |
| 237 | │ INFORMATIONAL │ RSA certs should use 2048-bit+ key lengths │ Security Hub │ arn:aws:acm:eu-west-1:<acct> │ | |
| 238 | │ INFORMATIONAL │ Athena workgroups should enable logging │ Security Hub │ arn:aws:athena:eu-west-1:<acct>│ | |
| 239 | └───────────────┴────────────────────────────────────────────────────┴──────────────┴────────────────────────────────┘ | |
| 240 | ||
| 241 | # License | |
| 242 | ||
| 243 | Refer to the LICENSE file for information on the GPL v3 license. | |
| 244 | ||
| 245 | # Future Improvements | |
| 246 | ||
| 247 | - [ ] Email attachment support (e.g., CSV or HTML export) | |
| 248 | - [ ] Slack or Teams notification integration | |
| 249 | - [ ] Cloud deployment (Lambda, Step Functions) | |
aws-summary/README.md added +238
| @@ -0,0 +1,238 @@ | ||
| 1 | # Overview | |
| 2 | ||
| 3 | This project is a Python-based tool that sends a daily plaintext email | |
| 4 | summarizing key AWS environment metrics and alerts. It is modular, | |
| 5 | configurable, and intended for solo or small-team AWS accounts that want | |
| 6 | automated visibility into infrastructure health, security, and cost. | |
| 7 | ||
| 8 | # Features | |
| 9 | ||
| 10 | - ✅ Daily billing breakdown (Cost Explorer) | |
| 11 | - ✅ New Security Hub findings | |
| 12 | - ✅ Route 53 health check status | |
| 13 | - ✅ CloudWatch alarms triggered in the last 24 hours | |
| 14 | - ✅ S3 bucket access/encryption audit | |
| 15 | - ✅ Expiring ACM certificates (next 30 days) | |
| 16 | - ✅ AWS Config non-compliant resources | |
| 17 | - ✅ CloudFront distribution changes (last 48h) | |
| 18 | - ✅ WAF blocked request summary (regional) | |
| 19 | ||
| 20 | The program is configured to be modular and accept new sections to the | |
| 21 | report as needed. To create a new section, simply create the | |
| 22 | `new_section.py` script inside the `sections/` directory and update the | |
| 23 | `sections` variable inside the `config.toml` file. | |
| 24 | ||
| 25 | # Directory Structure | |
| 26 | ||
| 27 | . | |
| 28 | ├── README.org ; This file | |
| 29 | ├── config.toml ; Configuration (AWS profile, region, etc.) | |
| 30 | ├── email_formatter.py ; Utility to format email body | |
| 31 | ├── main.py ; Main entry point for report generation | |
| 32 | ├── pyproject.toml ; Project metadata and dependencies | |
| 33 | ├── utils.py ; Shared utility functions | |
| 34 | ├── sections/ ; Modular report generators | |
| 35 | ├── acm.py ; ACM expiring certs | |
| 36 | ├── cloudfront.py ; CloudFront changes | |
| 37 | ├── cloudwatch.py ; Alarms | |
| 38 | ├── config.py ; Config compliance | |
| 39 | ├── costexplorer.py ; Billing | |
| 40 | ├── route53.py ; Health checks | |
| 41 | ├── s3.py ; Bucket audit | |
| 42 | └── securityhub.py ; Findings | |
| 43 | ||
| 44 | # Usage | |
| 45 | ||
| 46 | ## 1. Configure | |
| 47 | ||
| 48 | Edit `config.toml` to configure your AWS, email, and report options: | |
| 49 | ||
| 50 | ``` toml | |
| 51 | [aws] | |
| 52 | profile = "default" | |
| 53 | region = "us-east-1" | |
| 54 | ||
| 55 | [email] | |
| 56 | from = "you@example.com" | |
| 57 | to = ["you@example.com"] | |
| 58 | subject = "Daily AWS Report" | |
| 59 | ||
| 60 | [recipients] | |
| 61 | emails = [ | |
| 62 | "you@example.com" | |
| 63 | ] | |
| 64 | ||
| 65 | [report] | |
| 66 | sections = [ | |
| 67 | "acm" | |
| 68 | ] | |
| 69 | ``` | |
| 70 | ||
| 71 | ## 2. Run | |
| 72 | ||
| 73 | Use Python to run the report and send the email: | |
| 74 | ||
| 75 | ``` bash | |
| 76 | python main.py | |
| 77 | ``` | |
| 78 | ||
| 79 | Or, if you're using [uv](https://github.com/astral-sh/uv) (which will | |
| 80 | auto-install dependencies and create a virtual environment): | |
| 81 | ||
| 82 | ``` bash | |
| 83 | uv main.py | |
| 84 | ``` | |
| 85 | ||
| 86 | Emails are plaintext with ASCII-formatted tables (via `tabulate`). | |
| 87 | ||
| 88 | # Installation | |
| 89 | ||
| 90 | ## Dependencies | |
| 91 | ||
| 92 | Python 3.11+ is recommended. Install dependencies using: | |
| 93 | ||
| 94 | ``` bash | |
| 95 | pip install -r requirements.txt | |
| 96 | # or if you're using uv: | |
| 97 | uv sync | |
| 98 | ``` | |
| 99 | ||
| 100 | You may need to install: | |
| 101 | ||
| 102 | - `boto3` | |
| 103 | - `tabulate` | |
| 104 | ||
| 105 | ## AWS Permissions | |
| 106 | ||
| 107 | Ensure your IAM user or role has read access to: | |
| 108 | ||
| 109 | - Cost Explorer | |
| 110 | - Security Hub | |
| 111 | - S3, CloudFront, CloudWatch | |
| 112 | - Route 53, ACM, Config, WAF | |
| 113 | - SES (if sending emails from within AWS) | |
| 114 | ||
| 115 | # Customizing Sections | |
| 116 | ||
| 117 | Each section is defined in a file under `sections/` and implements a: | |
| 118 | ||
| 119 | ``` python | |
| 120 | def get_section(config) -> str: | |
| 121 | ... | |
| 122 | ``` | |
| 123 | ||
| 124 | You can add, remove, or modify these sections and control their order in | |
| 125 | `main.py`. | |
| 126 | ||
| 127 | # Example Output | |
| 128 | ||
| 129 | Here is an example of the output produced by the program. | |
| 130 | ||
| 131 | Expiring TLS Certificates: | |
| 132 | No certs expiring in the next 30 days. | |
| 133 | ||
| 134 | CloudFront Changes: | |
| 135 | No distributions changed in the last 48h. | |
| 136 | ||
| 137 | CloudWatch Alarms: | |
| 138 | No alarms triggered in the last 24h. | |
| 139 | ||
| 140 | AWS Config Non-Compliant Resources: | |
| 141 | [https://eu-west-1.console.aws.amazon.com/config/home#/resources?complianceType=NON_COMPLIANT] | |
| 142 | ┌───────────────────────────────────────┬────────────────────────┐ | |
| 143 | │ Resource Type │ Resource ID │ | |
| 144 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 145 | │ AWS::::Account │ <account-id> │ | |
| 146 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 147 | │ AWS::EC2::VPC │ vpc-<id> │ | |
| 148 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 149 | │ AWS::EC2::Subnet │ subnet-<id> │ | |
| 150 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 151 | │ AWS::EC2::Subnet │ subnet-<id> │ | |
| 152 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 153 | │ AWS::EC2::Subnet │ subnet-<id> │ | |
| 154 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 155 | │ AWS::EC2::VPCBlockPublicAccessOptions │ <account-id> │ | |
| 156 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 157 | │ AWS::EC2::SecurityGroup │ sg-<id> │ | |
| 158 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 159 | │ AWS::S3::Bucket │ example-cf-logs │ | |
| 160 | ├───────────────────────────────────────┼────────────────────────┤ | |
| 161 | │ AWS::S3::Bucket │ img.example.com │ | |
| 162 | └───────────────────────────────────────┴────────────────────────┘ | |
| 163 | ||
| 164 | AWS Billing Report for 2025-06-18 | |
| 165 | [https://eu-west-1.console.aws.amazon.com/costmanagement/] | |
| 166 | ┌────────────────────────────────────┬────────┐ | |
| 167 | │ Service │ Cost │ | |
| 168 | ├────────────────────────────────────┼────────┤ | |
| 169 | │ AWS CloudShell │ $0.00 │ | |
| 170 | │ AWS Config │ $0.17 │ | |
| 171 | │ AWS Glue │ $0.00 │ | |
| 172 | │ AWS HealthImaging │ $0.00 │ | |
| 173 | │ AWS Key Management Service │ $0.00 │ | |
| 174 | │ AWS Migration Hub Refactor Spaces │ $0.00 │ | |
| 175 | │ AWS Secrets Manager │ $0.00 │ | |
| 176 | │ AWS Security Hub │ $0.00 │ | |
| 177 | │ AWS Service Catalog │ $0.00 │ | |
| 178 | │ AWS WAF │ $0.29 │ | |
| 179 | │ Amazon CloudFront │ $0.00 │ | |
| 180 | │ Amazon GuardDuty │ $0.00 │ | |
| 181 | │ Amazon Location Service │ $0.00 │ | |
| 182 | │ Amazon Route 53 │ $0.01 │ | |
| 183 | │ Amazon Simple Notification Service │ $0.00 │ | |
| 184 | │ Amazon Simple Queue Service │ $0.00 │ | |
| 185 | │ Amazon Simple Storage Service │ $0.00 │ | |
| 186 | │ AmazonCloudWatch │ $0.00 │ | |
| 187 | │ CloudWatch Events │ $0.00 │ | |
| 188 | ├────────────────────────────────────┼────────┤ | |
| 189 | │ TOTAL │ $0.47 │ | |
| 190 | └────────────────────────────────────┴────────┘ | |
| 191 | ||
| 192 | Note: Costs are estimated and may change. | |
| 193 | ||
| 194 | Route 53 Health Checks: | |
| 195 | [https://eu-west-1.console.aws.amazon.com/route53/v2/healthchecks/home] | |
| 196 | ┌────────────────────┬──────────┐ | |
| 197 | │ Domain │ Status │ | |
| 198 | ├────────────────────┼──────────┤ | |
| 199 | │ img.example.com │ HEALTHY │ | |
| 200 | └────────────────────┴──────────┘ | |
| 201 | ||
| 202 | S3 Bucket Access Summary: | |
| 203 | [https://eu-west-1.console.aws.amazon.com/s3/home] | |
| 204 | ┌──────────────────────────────────────────────┬────────┬────────────┐ | |
| 205 | │ Bucket │ Public │ Encrypted │ | |
| 206 | ├──────────────────────────────────────────────┼────────┼────────────┤ | |
| 207 | │ aws-cloudtrail-logs-<account-id>-<suffix> │ No │ Yes │ | |
| 208 | │ example-cf-logs │ No │ Yes │ | |
| 209 | │ img.example.com │ No │ Yes │ | |
| 210 | └──────────────────────────────────────────────┴────────┴────────────┘ | |
| 211 | ||
| 212 | AWS Security Hub Findings (Last 24h): 18 new finding(s) | |
| 213 | [https://eu-west-1.console.aws.amazon.com/securityhub/home?region=eu-west-1#/findings] | |
| 214 | ┌───────────────┬────────────────────────────────────────────────────┬──────────────┬────────────────────────────────┐ | |
| 215 | │ Severity │ Title │ Product │ Resource │ | |
| 216 | ├───────────────┼────────────────────────────────────────────────────┼──────────────┼────────────────────────────────┤ | |
| 217 | │ INFORMATIONAL │ S3 buckets should have server access logging │ Security Hub │ arn:aws:s3:::img.example.com │ | |
| 218 | │ INFORMATIONAL │ S3 buckets should require requests to use HTTPS │ Security Hub │ arn:aws:s3:::img.example.com │ | |
| 219 | │ INFORMATIONAL │ S3 buckets should have lifecycle configuration │ Security Hub │ arn:aws:s3:::img.example.com │ | |
| 220 | │ INFORMATIONAL │ S3 buckets should block public access │ Security Hub │ arn:aws:s3:::example-cf-logs │ | |
| 221 | │ INFORMATIONAL │ ACLs should not be used to manage user access │ Security Hub │ arn:aws:s3:::img.example.com │ | |
| 222 | │ INFORMATIONAL │ EC2 subnets shouldn't auto-assign public IPs │ Security Hub │ arn:aws:ec2:eu-west-1:<acct> │ | |
| 223 | │ INFORMATIONAL │ VPC block public access should be enabled │ Security Hub │ arn:aws:ec2:eu-west-1:<acct> │ | |
| 224 | │ INFORMATIONAL │ S3 bucket policies should restrict public access │ Security Hub │ arn:aws:s3:::img.example.com │ | |
| 225 | │ INFORMATIONAL │ Unused network ACLs should be removed │ Security Hub │ arn:aws:ec2:eu-west-1:<acct> │ | |
| 226 | │ INFORMATIONAL │ RSA certs should use 2048-bit+ key lengths │ Security Hub │ arn:aws:acm:eu-west-1:<acct> │ | |
| 227 | │ INFORMATIONAL │ Athena workgroups should enable logging │ Security Hub │ arn:aws:athena:eu-west-1:<acct>│ | |
| 228 | └───────────────┴────────────────────────────────────────────────────┴──────────────┴────────────────────────────────┘ | |
| 229 | ||
| 230 | # License | |
| 231 | ||
| 232 | Refer to the LICENSE file. | |
| 233 | ||
| 234 | # Future Improvements | |
| 235 | ||
| 236 | - [ ] Email attachment support (e.g., CSV or HTML export) | |
| 237 | - [ ] Slack or Teams notification integration | |
| 238 | - [ ] Cloud deployment (Lambda, Step Functions) | |