Mondoo Docs

AWS Resources

MQL resources for AWS - query and validate your AWS infrastructure with cnquery and cnspec.

AWS Resources

207 resources

aws

AWS resource

47 fields
aws.account

AWS Account

10 fields
aws.account.alternateContact

AWS Account alternate contact

7 fields
aws.acm

AWS Certificate Manager resource (for assessing the configuration of AWS Certificate Manager)

2 fields
aws.acm.certificate

AWS Certificate Manager Certificate resource (provides an object representing an individual ACM certificate)

15 fields
aws.apigateway

Amazon API Gateway

3 fields
aws.apigateway.restapi

Amazon API Gateway REST API

8 fields
aws.apigateway.stage

Amazon API Gateway REST API stages

6 fields
aws.applicationAutoscaling

AWS Application Auto Scaling

3 fields
aws.applicationAutoscaling.target

AWS Application Auto Scaling target

7 fields
aws.autoscaling

AWS Auto Scaling

2 fields
aws.autoscaling.group

AWS Auto Scaling group

18 fields
aws.backup

AWS Backup

3 fields
aws.backup.vault

AWS Backup vault

10 fields
aws.backup.vaultRecoveryPoint

AWS Backup vault recovery point

10 fields
aws.cloudfront

Amazon CloudFront

4 fields
aws.cloudfront.distribution

Amazon CloudFront distribution

12 fields
aws.cloudfront.distribution.origin

Amazon CloudFront distribution origin

6 fields
aws.cloudfront.function

Amazon CloudFront function

9 fields
aws.cloudtrail

AWS CloudTrail

2 fields
aws.cloudtrail.trail

AWS CloudTrail trail

15 fields
aws.cloudwatch

Amazon CloudWatch

8 fields
aws.cloudwatch.loggroup

Amazon CloudWatch log group

8 fields
aws.cloudwatch.loggroup.metricsfilter

Amazon CloudWatch log group metrics filter

4 fields
aws.cloudwatch.metric

Amazon CloudWatch metric

7 fields
aws.cloudwatch.metric.datapoint

Amazon CloudWatch metric datapoint

7 fields
aws.cloudwatch.metricdimension

Amazon CloudWatch metric dimension

2 fields
aws.cloudwatch.metricsalarm

Amazon CloudWatch metrics alarm

10 fields
aws.cloudwatch.metricstatistics

Amazon CloudWatch metric statistics

5 fields
aws.codebuild

AWS CodeBuild for building and testing code

2 fields
aws.codebuild.project

AWS CodeBuild project

7 fields
aws.codedeploy

AWS CodeDeploy

4 fields
aws.codedeploy.application

AWS CodeDeploy Application

10 fields
aws.codedeploy.deployment

AWS CodeDeploy Deployment

18 fields
aws.codedeploy.deploymentGroup

AWS CodeDeploy Deployment Group

18 fields
aws.config

AWS Config

6 fields
aws.config.deliverychannel

AWS Config delivery channel

5 fields
aws.config.recorder

AWS Config recorder

8 fields
aws.config.rule

AWS Config rule

7 fields
aws.dms

AWS Database Migration Service (DMS)

1 field
aws.dynamodb

Amazon DynamoDB

9 fields
aws.dynamodb.export

Amazon DynamoDB Export

12 fields
aws.dynamodb.globaltable

Amazon DynamoDB global table

3 fields
aws.dynamodb.limit

Amazon DynamoDB limits

6 fields
aws.dynamodb.table

Amazon DynamoDB table

17 fields
aws.ec2

Amazon EC2

22 fields
aws.ec2.eip

Amazon Elastic IP (EIP)

9 fields
aws.ec2.image

Amazon EC2 image (AMI)

10 fields
aws.ec2.instance

Amazon EC2 instance

38 fields
aws.ec2.instance.device

Amazon EC2 instance block device

4 fields
aws.ec2.internetgateway

Amazon EC2 internet gateway

3 fields
aws.ec2.keypair

Amazon EC2 key pair

7 fields
aws.ec2.networkacl

Amazon EC2 network ACL

9 fields
aws.ec2.networkacl.association
3 fields
aws.ec2.networkacl.entry

Amazon EC2 network ACL entry

8 fields
aws.ec2.networkacl.entry.portrange

Amazon EC2 network ACL entry port range

3 fields
aws.ec2.networkinterface

AWS EC2 network interface

14 fields
aws.ec2.securitygroup

Amazon EC2 security group

11 fields
aws.ec2.securitygroup.ippermission

Amazon EC2 security group IP permission

8 fields
aws.ec2.snapshot

Amazon EC2 (EBS) snapshot

13 fields
aws.ec2.vgwtelemetry

Amazon EC2 VPN tunnel telemetry

3 fields
aws.ec2.volume

Amazon EC2 (EBS) volume

14 fields
aws.ec2.vpnconnection

Amazon EC2 VPN connection

2 fields
aws.ecr

AWS Elastic Container Registry (ECR)

5 fields
aws.ecr.image

AWS Elastic Container Registry image

11 fields
aws.ecr.repository

AWS Elastic Container Registry repository

8 fields
aws.ecs

Amazon Elastic Container Service (ECS)

7 fields
aws.ecs.cluster

Amazon ECS cluster

12 fields
aws.ecs.container

Amazon ECS container

19 fields
aws.ecs.instance

AWS ECS container instance

6 fields
aws.ecs.task

Amazon ECS task

8 fields
aws.efs

AWS Elastic File System (EFS) service

2 fields
aws.efs.filesystem

AWS Elastic File System (EFS) file system

10 fields
aws.eks

Amazon Elastic Kubernetes Service (EKS)

4 fields
aws.eks.addon

Amazon EKS add-on

10 fields
aws.eks.cluster

Amazon EKS cluster

19 fields
aws.eks.nodegroup

Amazon EKS managed node group

15 fields
aws.elasticache

Amazon ElastiCache

4 fields
aws.elasticache.cluster

Amazon ElastiCache cluster

28 fields
aws.elasticache.serverlessCache

Amazon ElastiCache serverless cache

13 fields
aws.elb

AWS Elastic Load Balancing

4 fields
aws.elb.loadbalancer

AWS Elastic Load Balancing load balancer

16 fields
aws.elb.targetgroup

AWS Elastic Load Balancer (ELB) Target Group

17 fields
aws.emr

Amazon EMR

2 fields
aws.emr.cluster

Amazon EMR cluster

8 fields
aws.es

AWS Elasticsearch service

2 fields
aws.es.domain

Amazon Elasticsearch service domain

10 fields
aws.guardduty

Amazon GuardDuty for threat detection

4 fields
aws.guardduty.detector

Amazon GuardDuty detector

7 fields
aws.guardduty.finding

AWS Guard Duty finding

10 fields
aws.iam

AWS service to create and manage permissions for users and groups

26 fields
aws.iam.accessanalyzer
2 fields
aws.iam.accessAnalyzer

AWS IAM Access Analyzer resource (for assessing the configuration of AWS IAM Access Analyzer)

3 fields
aws.iam.accessanalyzer.analyzer

AWS IAM Access Analyzer resource (provides an object representing an individual AWS IAM Access Analyzer configuration)

9 fields
aws.iam.accessanalyzer.analyzer

AWS IAM Access Analyzer resource (provides an object representing an individual AWS IAM Access Analyzer configuration)

9 fields
aws.iam.accessanalyzer.finding

AWS IAM Access Analyzer finding

12 fields
aws.iam.group

AWS IAM group

5 fields
aws.iam.instanceProfile

AWS IAM instance profile

6 fields
aws.iam.loginProfile

AWS IAM login profile for a user

1 field
aws.iam.oidcProvider

AWS IAM OpenID Connect (OIDC) identity provider

6 fields
aws.iam.policy

AWS IAM policy

14 fields
aws.iam.policyversion

AWS IAM policy version

5 fields
aws.iam.role

AWS IAM role

7 fields
aws.iam.samlProvider

AWS IAM SAML 2.0 identity provider

6 fields
aws.iam.user

AWS IAM user

11 fields
aws.iam.usercredentialreportentry

Entry in AWS IAM credential report

23 fields
aws.iam.virtualmfadevice

AWS IAM virtual MFA device

3 fields
aws.inspector

Amazon Inspector

2 fields
aws.inspector.coverage

Amazon Inspector environment coverage

15 fields
aws.inspector.coverage.image

Amazon Inspector container image coverage group

3 fields
aws.inspector.coverage.instance

Amazon Inspector instance coverage group

4 fields
aws.inspector.coverage.repository

Amazon Inspector container registry coverage group

3 fields
aws.kms

AWS Key Management Service (KMS)

2 fields
aws.kms.key

AWS Key Management Service (KMS) key

7 fields
aws.lambda

AWS Lambda

2 fields
aws.lambda.function

AWS Lambda function

9 fields
aws.macie

Amazon Macie

8 fields
aws.macie.classificationJob

Amazon Macie classification job

13 fields
aws.macie.customDataIdentifier

Amazon Macie custom data identifier

8 fields
aws.macie.finding

Amazon Macie finding

15 fields
aws.macie.session

Amazon Macie session

8 fields
aws.neptune

Amazon Neptune

4 fields
aws.neptune.cluster

Amazon Neptune cluster

30 fields
aws.neptune.instance

Amazon Neptune instance

30 fields
aws.organization

AWS Organization resource

6 fields
aws.rds

Amazon Relational Database Service (RDS)

12 fields
aws.rds.backupsetting

Amazon RDS Backup Setting

10 fields
aws.rds.clusterParameterGroup

Amazon RDS cluster parameter groups

6 fields
aws.rds.dbcluster

Amazon RDS database cluster

43 fields
aws.rds.dbinstance

Amazon RDS database instance

44 fields
aws.rds.parameterGroup

Amazon RDS parameter groups

7 fields
aws.rds.parameterGroup.parameter
11 fields
aws.rds.pendingMaintenanceAction

Amazon RDS pending maintenance action

7 fields
aws.rds.snapshot

Amazon RDS snapshot

14 fields
aws.redshift

Amazon Redshift

2 fields
aws.redshift.cluster

Amazon Redshift cluster

25 fields
aws.s3

Amazon S3 cloud object storage

2 fields
aws.s3.bucket

Amazon S3 bucket

21 fields
aws.s3.bucket.corsrule

Amazon S3 bucket CORS rule

6 fields
aws.s3.bucket.grant

Amazon S3 bucket grant

4 fields
aws.s3.bucket.policy

Amazon S3 bucket policy

6 fields
aws.s3control

Amazon S3 bucket control

1 field
aws.sagemaker

AWS SageMaker

5 fields
aws.sagemaker.endpoint

AWS SageMaker endpoint

5 fields
aws.sagemaker.notebookinstance

AWS SageMaker notebook instance

5 fields
aws.sagemaker.notebookinstancedetails

AWS SageMaker notebook instance details

3 fields
aws.secretsmanager

AWS Secrets Manager

2 fields
aws.secretsmanager.secret

AWS Secrets Manager secret

10 fields
aws.securityhub

AWS Security Hub

2 fields
aws.securityhub.hub

AWS Security Hub hub

2 fields
aws.sns

AWS Simple Notification Service (SNS)

3 fields
aws.sns.subscription

AWS Simple Notification Service (SNS) subscription

2 fields
aws.sns.topic

AWS Simple Notification Service (SNS) topic

5 fields
aws.sqs

Amazon Simple Queue Service (SQS)

2 fields
aws.sqs.queue

Amazon Simple Queue Service (SQS) Queue

15 fields
aws.ssm

Amazon Systems Manager

4 fields
aws.ssm.instance

Amazon SSM instance

9 fields
aws.ssm.parameter

Amazon SSM parameter

11 fields
aws.timestream
1 field
aws.timestream.liveanalytics

Amazon Timestream for LiveAnalytics

4 fields
aws.timestream.liveanalytics.database

Amazon Timestream for LiveAnalytics database

7 fields
aws.timestream.liveanalytics.table

Amazon Timestream for LiveAnalytics table

8 fields
aws.vpc

Amazon Virtual Private Cloud (VPC)

24 fields
aws.vpc.endpoint

Amazon Virtual Private Cloud (VPC) endpoint

10 fields
aws.vpc.flowlog

Amazon Virtual Private Cloud (VPC) flow log

11 fields
aws.vpc.natgateway

Amazon VPC NAT Gateway

8 fields
aws.vpc.natgateway.address

Amazon VPC NAT gateway address

5 fields
aws.vpc.peeringConnection

Amazon VPC Peering Connection

7 fields
aws.vpc.peeringConnection.peeringVpc

Amazon VPC Peering Connection Peering VPC

7 fields
aws.vpc.routetable

Amazon Virtual Private Cloud (VPC) route table

5 fields
aws.vpc.routetable.association

Amazon Virtual Private Cloud (VPC) route table association

6 fields
aws.vpc.serviceEndpoint

Amazon VPC Service Endpoint

13 fields
aws.vpc.subnet

Amazon Virtual Private Cloud (VPC) subnet

11 fields
aws.waf

Amazon WAF v2

8 fields
aws.waf.acl

Amazon WAF v2 ACL

7 fields
aws.waf.ipset

Amazon WAF IP set (defining IP Ranges)

7 fields
aws.waf.rule

Amazon WAF rule

7 fields
aws.waf.rule.action

Action that happens if a rule statement matches

3 fields
aws.waf.rule.fieldtomatch

Field to match

20 fields
aws.waf.rule.fieldtomatch.body

Body of the field to match

3 fields
aws.waf.rule.fieldtomatch.cookie

Cookie of the field to match

3 fields
aws.waf.rule.fieldtomatch.headerorder

Order of headers of the field to match

3 fields
aws.waf.rule.fieldtomatch.headers

Headers

6 fields
aws.waf.rule.fieldtomatch.headers.matchpattern

Pattern to match

5 fields
aws.waf.rule.fieldtomatch.ja3fingerprint

JA3 fingerprint

3 fields
aws.waf.rule.fieldtomatch.jsonbody

Request body as JSON

7 fields
aws.waf.rule.fieldtomatch.jsonbody.matchpattern

Pattern to match

4 fields
aws.waf.rule.fieldtomatch.singleheader

Single header of the field to match

3 fields
aws.waf.rule.fieldtomatch.singlequeryargument

Single query argument

3 fields
aws.waf.rule.statement
33 fields
aws.waf.rule.statement.andstatement

Rule statement that matches if all of the rule statements inside it match

3 fields
aws.waf.rule.statement.bytematchstatement

Rule statement that matches a specified sequence of bytes

4 fields
aws.waf.rule.statement.geomatchstatement

Rule statement that checks for requests from certain countries

3 fields
aws.waf.rule.statement.ipsetreferencestatement

Rule statement that checks for requests from IP addresses defined in an IPSet

5 fields
aws.waf.rule.statement.ipsetreferencestatement.ipsetforwardedipconfig
5 fields
aws.waf.rule.statement.labelmatchstatement
4 fields
aws.waf.rule.statement.managedrulegroupstatement

Rule statement that is managed by AWS

4 fields
aws.waf.rule.statement.notstatement

Rule statement that negates another rule statement

3 fields
aws.waf.rule.statement.orstatement

Rule statement that matches if one of the rule statements inside it matches

3 fields
aws.waf.rule.statement.ratebasedstatement

Rule statement that matches at a certain rate of requests (rate limiting)

0 fields
aws.waf.rule.statement.regexmatchstatement

Rule statement that matches a specified regex pattern

4 fields
aws.waf.rule.statement.regexpatternsetreferencestatement

Rule statement that checks for a regex pattern defined in a regex pattern set

4 fields
aws.waf.rule.statement.rulegroupreferencestatement

Rule statement that refers to a group of rules

4 fields
aws.waf.rule.statement.sizeconstraintstatement

Rule statement that checks the size of the specified field

5 fields
aws.waf.rule.statement.sqlimatchstatement

Statement that matches SQLI attacks

4 fields
aws.waf.rule.statement.xssmatchstatement

Statement that matches XSS attacks

3 fields
aws.waf.rulegroup

Amazon WAF v2 RuleGroup

6 fields

On this page