Insecure service configuration - EC2
Description
Some EC2 instances have insecure configurations that an attacker can use to access or interrupt critical application processes
Impact
Compromise the security of one or several EC2 Instances
Recommendation
Perform a hardening process over all the EC2 instances, by following the recommended best practices
Threat
Internet attacker with access to the AWS console.
Expected Remediation Time
⏱️ 45 minutes.
Requirements
266 - Disable insecure functionalitiesRules
Aws Multiple Network InterfacesAws Unencrypted SnapshotsAws Terminate Shutdown BehaviorAws Modify Instance AttributeAws Unapproved AmisAws Associate Public IpAws Using Imds V1Aws Unused Key PairsAws Unencrypted AmisAws Instances Without Iam ProfileAws Publicly Shared AmisTerraform Associate Public Ip Address TrueTerraform Missing Iam Instance ProfileJson Yaml Misconfigured Public Ip AddressJson Yaml Missing Iam Instance ProfileFixes