AWS Resources Collected

The following resources are actively monitored in the Secberus platform. If you need coverage for additional resources, please reach out to [email protected].

AWS Resources

Access Analyzer

Archive Rules
Analyzer Findings
Analyzers

Account

Alternate Contacts
Contacts

ACM

Certificates

AMP

Rule Groups Namespaces
Workspaces

Amplify

Apps

API Gateway

API Keys
Client Certificates
Domain Name Base Path Mappings
Domain Names
Rest API Authorizers
Rest API Deployments
Rest API Documentation Parts
Rest API Documentation Versions
Rest API Gateway Responses
Rest API Models
Rest API Request Validators
Rest API Resource Method Integrations
Rest API Resource Methods
Rest API Resources
Rest API Stages
Rest APIs
Usage Plan Keys
Usage Plans
VPC Links

API Gateway v2

API Authorizers
API Deployments
API Integration Responses
API Integrations
API Models
API Route Responses
API Routes
API Stages
APIs
Domain Name Rest API Mappings
Domain Names
VPC Links

Application Autoscaling

Policies
Scalable Targets
Scaling Activities
Scheduled Actions

App Runner

Auto Scaling Configurations
Connections
Custom Domains
Observability Configurations
Operations
Services
VPC Connectors
VPC Ingress Connections

AppStream

App Blocks
Application Fleet Associations
Applications
Directory Configs
Fleets
Image Builders
Images
Stack Entitlements
Stack User Associations
Stacks
Usage Report Subscriptions
Users

AppSync

GraphQL APIs

Athena

Data Catalog Database Tables
Data Catalog Databases
Data Catalogs
Work Group Named Queries
Work Group Prepared Statements
Work Group Query Executions
Work Groups

Autoscaling

Group Lifecycle Hooks
Group Scaling Policies
Groups
Launch Configurations
Plan Resources
Plans
Scheduled Actions

Availability Zones

Backup

Global Settings
Plan Selections
Plans
Region Settings
Vault Recovery Points
Vaults

Batch

Job Definitions
Job Queues
Jobs

Cloudformation

Stack Resources
Stack Set Operation Results
Stack Set Operations
Stack Sets
Stacks

Cloudfront

Cache Policies
Distributions
Functions
Origin Access Identities
Origin Request Policies
Response Headers Policies

Cloud HSM v2

Backups
Clusters

CloudTrail

Channels
Imports
Trail Event Selectors
Trails

Cloudwatch

Alarms

CloudWatch Logs

Log Group Data Protection Policies
Log Group Subscription Filters
Log Groups
Metric Filters
Resource Policies

Codebuild

Projects

CodePipeline

Pipelines
Webhooks

Cognito

Identity Pools
User Pool Identity Providers
User Pools

Compute Optimizer

Autoscaling Group Recommendations
Ebs Volume Recommendations
Ec2 Instance Recommendations
Ecs Service Recommendations
Enrollment Statuses
Lambda Function Recommendations

Config

Config Rule Compliance Details
Config Rule Compliances
Config Rules
Configuration Aggregators
Configuration Recorders
Conformance Pack Rule Compliances
Conformance Packs
Delivery Channel Statuses
Delivery Channels
Remediation Configurations
Retention Configurations

DAX

Clusters

DB Proxies

Direct Connect

Connections
Gateway Associations
Gateway Attachments
Gateways
Lags
Locations
Virtual Gateways
Virtual Interfaces

DMS

Replication Instances

DocumentDB

Certificates
Cluster Snapshots
Clusters
Event Categories
Event Subscriptions
Events
Global Clusters
Instances
Pending Maintenance Actions
Subnet Groups

DynamoDB

Backups
Exports
Global Tables
Table Continuous Backups
Table Replica Auto Scalings
Tables

DynamoDB Streams

Steams

EC2

Account Attributes
Byoip Cidrs
Capacity Reservations
Customer Gateways
DHCP Options
EBS Snapshot Attributes
EBS Snapshots
EBS Volume Statuses
EBS Volumes
Egress Only Internet Gateways
Elastic IPs
Flow Logs
Hosts
Image Last Launched Times
Image Launch Permissions
Images
Instance Connect Endpoints
Instance Statuses
Instances
Internet Gateways
Key Pairs
Launch Template Versions
Launch Templates
Managed Prefix Lists
NAT Gateways
Network ACLs
Network Interfaces
Regional Configs
Reserved Instances
Route Tables
Security Groups
Spot Fleet Instances
Spot Fleet Requests
Spot Instance Requests
Subnets
Transit Gateway Attachments
Transit Gateway Multicast Domains
Transit Gateway Peering Attachments
Transit Gateway Route Tables
Transit Gateway VPC Attachments
Transit Gateways
VPC Endpoint Connections
VPC Endpoint Service Configurations
VPC Endpoints
VPC Peering Connections
VPCs
VPN Connections
VPN Gateways

ECR

Pull Through Cache Rules
Registries
Registry Policies
Repositories
Repository Image Scan Findings
Repository Images
Repository Lifecycle Policies

ECR Public

Repositories
Repository Images

ECS

Cluster Container Instances
Cluster Services
Cluster Task Sets
Cluster Tasks
Clusters
Task Definitions

EFS

Access Points
Filesystems

EKS

Cluster Addons
Cluster Node Groups
Cluster OIDC Identity Provider Configs
Clusters
Fargate Profiles

ElastiCache

Clusters
Events
Global Replication Groups
Replication Groups
Reserved Cache Nodes
Snapshots
Subnet Groups
Update Actions
User Groups
Users

Elastic Beanstalk

Application Versions
Applications
Configuration Options
Configuration Settings
Environments

Elasticsearch

Domains
Packages
Versions
VPC Endpoints

Elastic Transcoder

Pipeline Jobs
Pipelines
Presets

ELB v1

Load Balancer Policies
Load Balancers

ELB v2

Listener Certificates
Listener Rules
Listeners
Load Balancer Attributes
Load Balancer Web ACLs
Load Balancers
Target Group Target Health Descriptions
Target Groups

EMR

Block Public Access Configs
Cluster Instance Fleets
Cluster Instance Groups
Cluster Instances
Clusters
Notebook Executions
Release Labels
Security Configurations
Steps
Studio Session Mappings
Studios
Supported Instance Types

EventBridge

API Destinations
Archives
Connections
Endpoints
Event Bus Rules
Event Bus Targets
Event Buses
Event Sources
Replays

Firehose

Delivery Streams

Fraud Detector

Batch Imports
Batch Predictions
Detectors
Entity Types
Event Types
External Models
Labels
Model Versions
Models
Outcomes
Rules
Variables

FSx

Backups
Data Repository Associations
Data Repository Tasks
File Caches
File Systems
Snapshots
Storage Virtual Machines
Volumes

Glacier

Data Retrieval Policies
Vault Access Policies
Vault Lock Policies
Vault Notifications
Vaults

Glue

Classifiers
Connections
Crawlers
Database Table Indexes
Database Tables
Databases
Datacatalog Encryption Settings
Dev Endpoints
Job Runs
Jobs
Ml Transform Task Runs
Ml Transforms
Registries
Registry Schema Versions
Registry Schemas
Security Configurations
Triggers
Workflows

Guardduty

Detector Filters
Detector Intel Sets
Detector Ip Sets
Detector Members
Detector Publishing Destinations
Detectors

IAM

Accounts
Credential Reports
Group Attached Policies
Group Policies
Groups
Instance Profiles
OpenID Connect Identity Providers
Password Policies
Policies
Role Attached Policies
Role Policies
Roles
SAML Identity Providers
Server Certificates
Signing Certificates
Ssh Public Keys
User Access Keys
User Attached Policies
User Groups
User Policies
Users
Virtual MFA Devices

Identity Store

Group Memberships
Groups
Users

Inspector

Findings

Inspector2

Findings

IOT

Billing Groups
CA Certificates
Certificates
Jobs
Policies
Security Profiles
Streams
Thing Groups
Thing Types
Things
Topic Rules

Kafka

Cluster Operations
Clusters
Configurations
Nodes

Kinesis

Streams

KMS

Aliases
Key Grants
Key Policies
Keys

Lambda

Function Aliases
Function Concurrency Configs
Function Event Invoke Configs
Function Event Source Mappings
Function Url Configs
Function Versions
Functions
Layer Version Policies
Layer Versions
Layers
Runtimes

Lightsail

Alarms
Bucket Access Keys
Buckets
Certificates
Container Service Deployments
Container Service Images
Container Services
Database Events
Database Log Events
Database Parameters
Database Snapshots
Databases
Disk Snapshots
Disks
Distributions
Instance Port States
Instance Snapshots
Instances
Load Balancer TLS Certificates
Load Balancers
Static IPs

MQ

Broker Configuration Revisions
Broker Configurations
Broker Users
Brokers

MWAA

Environments

Neptune

Cluster Snapshots
Clusters
Event Subscriptions
Global Clusters
Instances
Subnet Groups

Organizations

Account Parents
Accounts
Delegated Administrators
Delegated Services
Organizational Unit Parents
Organizational Units
Organizations
Policies
Resource Policies
Roots

QLDB

Ledger Journal Kinesis Streams
Ledger Journal S3 Exports
Ledgers

QuickSight

Analyses
Dashboards
Data Sets
Data Sources
Folders
Group Members
Groups
Ingestions
Templates
Users

RAM

Principals
Resource Share Associations
Resource Share Invitations
Resource Share Permissions
Resource Shares
Resource Types
Resources

RDS

Certificates
Cluster Backtracks
Cluster Snapshots
Clusters
Db Security Groups
Db Snapshots
Event Subscriptions
Events
Instances
Option Groups
Reserved Instances
Subnet Groups

Redshift

Cluster Parameter Groups
Cluster Parameters
Clusters
Data Shares
Endpoint Access
Endpoint Accesses
Endpoint Authorization
Endpoint Authorizations
Event Subscriptions
Events
Snapshots
Subnet Groups

Regions

Resilience Hub

Alarm Recommendations
App Assessments
App Component Compliances
App Version Resource Mappings
App Version Resources
App Versions
Apps
Component Recommendations
Recommendation Templates
Resiliency Policies
Sop Recommendations
Suggested Resiliency Policies
Test Recommendations

Resource Groups

Resource Groups

Route53

Delegation Sets
Domains
Health Checks
Hosted Zone Query Logging Configs
Hosted Zone Resource Record Sets
Hosted Zone Traffic Policy Instances
Hosted Zones
Operations
Traffic Policies
Traffic Policy Versions

S3

Access Points
Accounts
Bucket Cors Rules
Bucket Encryption Rules
Bucket Grants
Bucket Lifecycles
Bucket Notification Configurations
Bucket Object Lock Configurations
Bucket Websites
Buckets
Multi Region Access Points

SageMaker

Apps
Endpoint Configurations
Models
Notebook Instances
Training Jobs

Savings Plans

Plans

Scheduler

Schedule Groups
Schedules

Secrets Manager

Secret Versions
Secrets

Security Hub

Findings

Service Catalog

Portfolios
Products
Provisioned Products

SES

Active Receipt Rule Sets
Configuration Set Event Destinations
Configuration Sets
Contact Lists
Custom Verification Email Templates
Identities
Templates

Shield

Attacks
Protection Groups
Protections
Subscriptions

SNS

Subscriptions
Topics

SQS

Queues

SSM

Associations
Compliance Summary Items
Document Versions
Documents
Instance Compliance Items
Instance Patches
Instances
Inventories
Inventory Schemas
Parameters
Patch Baselines
Sessions

SSO Admin

Account Assignments
Instances
Permission Sets

Step Functions

Activities
Executions
Map Run Executions
Map Runs
State Machines

Support

Case Communications
Cases
Services
Severity Levels
Trusted Advisor Check Results
Trusted Advisor Check Summaries
Trusted Advisor Checks

Timestream

Databases
Tables

Transfer

Servers

WAF

Rule Groups
Rules
Subscribed Rule Groups
Web ACLs

WAF Regional

Rate Based Rules
Rule Groups
Rules
Web ACLs

WAF v2

Ipsets
Managed Rule Groups
Regex Pattern Sets
Rule Groups
Web ACLs

Workspaces

Directories
Workspaces

X-Ray

Encryption Configs
Groups
Resource Policies
Sampling Rules