{
  "generatedAt": "2026-07-31T07:58:41.650Z",
  "region": "us-east-1",
  "cloudtrail": {
    "name": "sec-trail",
    "logging": true,
    "multiRegion": true,
    "logFileValidation": true,
    "kmsEncrypted": true,
    "latestDeliveryAt": "2026-07-31T07:57:34.373Z"
  },
  "kms": {
    "alias": "alias/sec-trail",
    "keyState": "Enabled",
    "customerManaged": true,
    "rotationEnabled": true
  },
  "guardduty": {
    "detectorId": "f2414166a3134f3995c7759898752148",
    "total": 409,
    "bySeverity": {
      "HIGH": 173,
      "MEDIUM": 170,
      "LOW": 66
    },
    "sampleFindings": true,
    "fieldGuide": [
      {
        "type": "Trojan:Runtime/DropPoint!DNS",
        "count": 5,
        "threatPurpose": "Trojan",
        "resource": "Runtime",
        "family": "DropPoint",
        "severity": "MEDIUM",
        "plain": "A resource is behaving as though it carries malware."
      },
      {
        "type": "Trojan:Runtime/DropPoint",
        "count": 5,
        "threatPurpose": "Trojan",
        "resource": "Runtime",
        "family": "DropPoint",
        "severity": "MEDIUM",
        "plain": "A resource is behaving as though it carries malware."
      },
      {
        "type": "Trojan:Runtime/DriveBySourceTraffic!DNS",
        "count": 5,
        "threatPurpose": "Trojan",
        "resource": "Runtime",
        "family": "DriveBySourceTraffic",
        "severity": "HIGH",
        "plain": "A resource is behaving as though it carries malware."
      },
      {
        "type": "PrivilegeEscalation:Runtime/UserfaultfdUsage",
        "count": 5,
        "threatPurpose": "PrivilegeEscalation",
        "resource": "Runtime",
        "family": "UserfaultfdUsage",
        "severity": "MEDIUM",
        "plain": "Someone is trying to gain more permission than they were given."
      },
      {
        "type": "PrivilegeEscalation:Runtime/ElevationToRoot",
        "count": 5,
        "threatPurpose": "PrivilegeEscalation",
        "resource": "Runtime",
        "family": "ElevationToRoot",
        "severity": "LOW",
        "plain": "Someone is trying to gain more permission than they were given."
      },
      {
        "type": "PrivilegeEscalation:Runtime/ContainerMountsHostDirectory",
        "count": 5,
        "threatPurpose": "PrivilegeEscalation",
        "resource": "Runtime",
        "family": "ContainerMountsHostDirectory",
        "severity": "MEDIUM",
        "plain": "Someone is trying to gain more permission than they were given."
      },
      {
        "type": "PrivilegeEscalation:Runtime/CGroupsReleaseAgentModified",
        "count": 5,
        "threatPurpose": "PrivilegeEscalation",
        "resource": "Runtime",
        "family": "CGroupsReleaseAgentModified",
        "severity": "HIGH",
        "plain": "Someone is trying to gain more permission than they were given."
      },
      {
        "type": "Persistence:Runtime/SuspiciousCommand",
        "count": 5,
        "threatPurpose": "Persistence",
        "resource": "Runtime",
        "family": "SuspiciousCommand",
        "severity": "LOW",
        "plain": "Someone is trying to keep access they should not have."
      },
      {
        "type": "Impact:Runtime/SuspiciousDomainRequest.Reputation",
        "count": 5,
        "threatPurpose": "Impact",
        "resource": "Runtime",
        "family": "SuspiciousDomainRequest",
        "severity": "LOW",
        "plain": "A resource is being used to cause harm, such as a denial-of-service."
      },
      {
        "type": "Execution:Runtime/SuspiciousShellCreated",
        "count": 5,
        "threatPurpose": "Execution",
        "resource": "Runtime",
        "family": "SuspiciousShellCreated",
        "severity": "LOW",
        "plain": "A behavior the watch is trained to flag."
      },
      {
        "type": "Execution:Runtime/NewBinaryExecuted",
        "count": 5,
        "threatPurpose": "Execution",
        "resource": "Runtime",
        "family": "NewBinaryExecuted",
        "severity": "MEDIUM",
        "plain": "A behavior the watch is trained to flag."
      },
      {
        "type": "Discovery:Runtime/SuspiciousCommand",
        "count": 5,
        "threatPurpose": "Discovery",
        "resource": "Runtime",
        "family": "SuspiciousCommand",
        "severity": "LOW",
        "plain": "Someone is mapping the account to see what is worth taking."
      }
    ],
    "fieldGuideSampled": 200,
    "distinctTypes": 115
  },
  "securityHub": {
    "standards": [
      {
        "arn": "arn:aws:securityhub:us-east-1::standards/aws-foundational-security-best-practices/v/1.0.0",
        "status": "PENDING"
      }
    ],
    "compliance": {
      "PASSED": 630,
      "FAILED": 178,
      "WARNING": 0,
      "NOT_AVAILABLE": 0
    },
    "failedSeverity": {
      "CRITICAL": 1,
      "HIGH": 8,
      "MEDIUM": 142,
      "LOW": 27,
      "INFORMATIONAL": 0
    },
    "topFailedControls": [
      {
        "id": "S3.5",
        "title": "S3 general purpose buckets should require requests to use SSL",
        "count": 18
      },
      {
        "id": "S3.9",
        "title": "S3 general purpose buckets should have server access logging enabled",
        "count": 18
      },
      {
        "id": "APIGateway.8",
        "title": "API Gateway routes should specify an authorization type",
        "count": 17
      },
      {
        "id": "S3.13",
        "title": "S3 general purpose buckets should have Lifecycle configurations",
        "count": 14
      },
      {
        "id": "CloudFront.6",
        "title": "CloudFront distributions should have WAF enabled",
        "count": 10
      },
      {
        "id": "CloudFront.17",
        "title": "CloudFront distributions should use trusted key groups for signed URLs and cookies",
        "count": 10
      },
      {
        "id": "CloudFront.5",
        "title": "CloudFront distributions should have logging enabled",
        "count": 10
      },
      {
        "id": "CloudFront.4",
        "title": "CloudFront distributions should have origin failover configured",
        "count": 10
      }
    ],
    "truncated": false
  },
  "config": {
    "recorderOn": true,
    "conformancePack": "sec-nist-800-53-rev5",
    "framework": "NIST 800-53 rev 5 (AWS operational best practices pack)",
    "rules": {
      "COMPLIANT": 32,
      "NON_COMPLIANT": 27,
      "INSUFFICIENT_DATA": 71
    },
    "totalRules": 130,
    "noncompliantRules": [
      "account-part-of-organizations",
      "api-gw-associated-with-waf",
      "api-gw-cache-enabled-and-encrypted",
      "api-gw-execution-logging-enabled",
      "cloud-trail-cloud-watch-logs-enabled",
      "cloudtrail-s3-dataevents-enabled",
      "cloudwatch-alarm-action-check",
      "dynamodb-in-backup-plan",
      "dynamodb-table-encrypted-kms",
      "ec2-ebs-encryption-by-default",
      "iam-inline-policy-blocked-kms-actions",
      "iam-no-inline-policy-check",
      "iam-password-policy",
      "iam-user-group-membership-check",
      "lambda-dlq-check",
      "no-unrestricted-route-to-igw",
      "s3-bucket-logging-enabled",
      "s3-bucket-replication-enabled",
      "s3-bucket-ssl-requests-only",
      "s3-bucket-versioning-enabled",
      "s3-default-encryption-kms",
      "s3-event-notifications-enabled",
      "s3-version-lifecycle-policy-check",
      "sns-encrypted-kms",
      "subnet-auto-assign-public-ip-disabled",
      "vpc-default-security-group-closed",
      "vpc-flow-logs-enabled"
    ]
  },
  "boundary": {
    "role": "sec-boundary-demo",
    "boundaryPolicy": "arn:aws:iam::926634327975:policy/sec-permission-boundary",
    "simulations": [
      {
        "action": "s3:GetObject",
        "decision": "allowed",
        "allowedByBoundary": true,
        "grantedByPolicy": true
      },
      {
        "action": "s3:PutObject",
        "decision": "implicitDeny",
        "allowedByBoundary": false,
        "grantedByPolicy": true
      },
      {
        "action": "iam:CreateUser",
        "decision": "implicitDeny",
        "allowedByBoundary": false,
        "grantedByPolicy": false
      }
    ]
  }
}