Cloud Control resource request by token
Gets the progress event for one Cloud Control resource request by its request token; poll it until the operation completes.
Gets the progress event for one Cloud Control resource request by its request token; poll it until the operation completes.
Lists recent Cloud Control resource requests in a region filtered by operation and status; the follow-up surface for asynchronous AWS mutations.
Reports instance state and health checks for a region, and covers the stop and start lifecycle operations that change it.
Looks up vCPU, memory, architecture and capability details for named EC2 instance types; the architecture check before launching an instance.
Lists EC2 instances in one region with type, state, addressing and network placement.
Lists the AWS regions enabled for the account with endpoint, country and opt-in status; the valid fan-out list for region-swept queries.
Resolves identifiers for ID-centric AWS resource types by querying the tagging API with a resource type and tag filter; returns ARNs, extracted ids and tags.
Lists a user's access keys with their age in days; keys older than the rotation window are the finding.
Assesses the IAM account password policy against CIS AWS Foundations Benchmark password controls, returning raw values and per-control PASS/FAIL verdicts.
Inventories the SAML and OIDC identity providers registered in the account; the trusted federation surface behind assumable roles.
Lists IAM roles whose trust policy admits principals from other AWS accounts, flagging external id and federation use; the cross-account exposure surface.
Enumerates IAM users in the account; IAM is global and always served from us-east-1, so the query takes no parameters.
Lists IAM users alongside whether they have a virtual MFA device registered; console-capable users without MFA are the finding.
Summarises a region's Lambda functions by runtime and architecture with counts and memory totals; the runtime modernisation and Graviton migration view.
Lists Lambda functions in one region with runtime, architecture, memory, timeout and execution role in a single call.
Reads a Lambda function's resource policy and flags statements granting invoke rights to a wildcard principal; the public-invoke exposure check.
Launches an EC2 instance through Cloud Control, returning a progress event to poll; user data must be base64 encoded.
Reports the four block-public-access settings plus object ownership for a bucket; any flag returning 0 leaves a public exposure path open.
Full security configuration for one bucket: public access block, encryption, versioning, ownership controls and logging.
Enumerates every S3 bucket in the account with its ARN, home region and creation date in one account-global call.
Updates RetentionInDays on a CloudWatch log group via an asynchronous Cloud Control update.