Trustedadvisor
Basics
- Account level product. Does not need any agents to be installed
- Provides checks for Cost Optimization, Performance, Security, Fault Tolerance & Service Limits
- 7 core checks are provided with basic and developer support plans. Additional checks require Business or Enterprise support plan
- 7 Core Free checks are
- S3 Bucket Permissions (not objects just buckets)
- Security Groups - Specific ports unrestricted
- IAM Use
- MFA on Root Account
- EBS Public Snapshots
- RDS Public Snapshots
- 50 service limit checks
- Business & Enterprise plans provide 115 additional checks
- Additionally one gets access to AWS Support APIs. With this one can programmatically trigger checks individually. Also one gets CloudWatch integration