Usecase Universe

A collective of use cases for DevOps teams

Browse a variety of 200+ predefined templates to automate all your AWS actions

Create Template
Solutions
All Categories

Security

24 Times Used
22 MAY 2019
IAM user has console login allowed without MFA
IAM
Security
Security

Sends report of IAM users that has control access but MFA is not enabled

CMK Key Rotation Enabled
Security
Security
Key Management Service

Check if the existing Customer Managed Keys (CMKs) have key rotation enabled

SQS Exposed Queues
Security
Simple Queue Service
Security

This workflow sends a report for SQS queues which are publicly accessible. Allowing anonymous users to have access to your SQS queues can lead to unauthorized actions such as intercepting, deleting and sending queue messages.

EC2 Desired Instance Type
Security
EC2
Security

EC2 instances provisioned in your AWS account have the desired instance type(s) established by your organization based on the workload deployed.

EC2 Default Security Groups In Use
Security
EC2
Security

To determine if you have any provisioned EC2 instances associated with default security groups.

Unrestricted DB Security Group
Security
RDS
Security

To determine if your existing RDS DB security groups allow unrestricted access, AWS RDS DB security groups do not allow access from 0.0.0.0/0 in order to reduce the risk of unauthorized access.

Unrestricted Oracle Access
EC2
Security

It is AWS best practice to remove entries in security group which allows Oracle DB access from public IP to reduce possibility of breach. Allowing unrestricted Oracle access can increase threats like hacking, denial-of-service (DoS) attacks and loss of data.

Unrestricted MySQL Access
EC2
Security

It is AWS best practice to remove entries in security group which allows MySQL access from public IP to reduce possibility of breach. Allowing unrestricted MySQL access can increase threats like hacking, denial-of-service (DoS) attacks and loss of data.

AWS Config Configuration Changes
Security
Config
Security

Send report of all the AWS config changes in your AWS account i.e. if any operations like start/stop/put configuration recorder is performed in your AWS account then this workflow will generate a report of it and send it to your email.

Unrestricted DNS Access
EC2
Security
Security

It is AWS best practice to remove entries in security group which allows DNS access from public IP to reduce possibility of breach. Allowing unrestricted DNS access can increase threats such as Denial of Service (DoS) attacks or Distributed Denial of Service (DDoS) attacks.

ElastiCache Redis Multi-AZ
ElastiCache
Security
Security

Ensure that your ElastiCache Redis Cache clusters are using a Multi-AZ deployment configuration to enhance High Availability (HA). To determine if your ElastiCache Redis Cache clusters are using a Multi-AZ configuration.

Elasticsearch Cross Account Access
Security
Security
Elasticsearch Service

Sends a report of AWS ElasticSearch domains which allows access to unauthorized cross users. Allowing untrustworthy cross account access to your AWS ES clusters can lead to unauthorized actions such as uploading, downloading and deleting documents without permission.

Unrestricted Default Security Groups - VPC
Security
VPC
Security

Sends a report of VPC's default Security Groups which are allowing inbound traffic from all the ports.

Unrestricted HTTP Access
EC2
Security
Security

It is AWS best practice to get aware of security groups which allows HTTP access from public IP to reduce possibility of breach. Allowing unrestricted HTTP access can increase threats like hacking, denial-of-service (DoS) attacks and loss of data.

Enable deletion protection for RDS Aurora DB clusters
RDS
Security

This workflow enables the deletion protection feature for Aurora DB clusters. Deletion protection prevents any existing or new Aurora database cluster, regardless of its type - provisioned or serverless, from being terminated by a root or IAM user using the AWS Management Console, AWS CLI or AWS API calls, unless the feature is explicitly disabled