Dasnuve · Cloud Discovery · Fast Track

Scrivas — AWS Discovery Findings

Resource footprint · security posture · cost — phases 2–5, read-only
org o-qfj0pvhhv7
2 accounts · us-east-2 primary
2026-08-19
$858/mo
Current run-rate (Jul)
up ~4× from $223 in January
4
GuardDuty high/critical findings
severity 8–9, both regions, open
13
Security groups open to 0.0.0.0/0
management account, us-east-2
5
Access keys > 90 days old
incl. admin keys at 322 & 319 days
05

Cost baseline

Cost Explorer · unblended · payer account
$223
Jan
$131
Feb
$522
Mar
$732
Apr
$746
May
$821
Jun
$858
Jul
Monthly spend, 2026+284% Jan→Jul · 7-mo total ≈ $4,033
Top services · 6-month spend
EC2 – Compute$2,722
EC2 – Other$375
AWS WAF$364
Security Hub$153
VPC$117
Config$84
GuardDuty$56
EKS$47

EC2 compute is 67% of spend — the primary optimization lever (rightsizing, Savings Plans, Graviton/spot). Security tooling (WAF, Security Hub, Config, GuardDuty) adds ~$110/mo.

03

Resource footprint

active regions only · us-east-2 primary
7EC2 instances
9EBS volumes (2 unattached)
7Elastic IPs
9S3 buckets
2Regions in use
15Idle regions

Scrivas Admin management + workloads

716468089330 · us-east-2
  • 7 EC2 · 9 EBS (2 unattached) · 7 EIPs · 9 S3 buckets
  • EKS IAM roles present (staging/gpu/infra/apps) — no live clusters returned; likely torn down, roles orphaned
  • RDS monitoring role present; VPC flow logs enabled
  • Anti-pattern: production workloads run in the org management account

Lazka bare & unmonitored

547868853286 · us-east-1
  • 0 EC2 · 0 S3 · 0 IAM users — effectively empty
  • Only default service-linked roles + OrganizationAccountAccessRole
  • Security Hub not enabled; no GuardDuty detector
  • Covered by the org CloudTrail, but otherwise dark
04

Security posture & IAM

prioritized risk register
SeverityFindingEvidenceWhy it matters
High Open GuardDuty high/critical findings sev 8–9 in us-east-1 & us-east-2 Active threat signals unremediated; no delegated security owner to triage
High 13 security groups open to the internet 0.0.0.0/0 ingress, us-east-2 Direct attack surface on the workload account — needs port-level review
High Stale admin access keys admin keys 322 & 319 days; +3 others >90d Long-lived static credentials for privileged users — top breach vector
Medium Console users without MFA 2 of 10 IAM users Account-takeover risk; fails CIS AWS baseline
Medium Member account unmonitored Lazka: no GuardDuty / Security Hub Detection blind spot; org security services not delivered to members
Good Org CloudTrail configured well multi-region + org trail + log-file validation Solid audit foundation to build on
Good No public S3 buckets or public RDS 0 of 9 buckets public; 0 public DBs Data-exposure basics are in order
CIS

Compliance benchmark

Prowler 5.39 · 632 checks · 1,230 findings · mgmt account
70%Checks passing (861)
2Critical failures
111High failures
189Medium failures
Pass rate by framework
SOC 281%
ISO 27001:202277%
CIS 3.074%
NIST CSF 2.071%
PCI DSS 4.057%

SOC 2 at 81% aligns with their Secureframe program — a focused push closes the gap. PCI is lowest (not in scope unless they process cards).

Critical & notable high failures
CRITRoot account has no hardware MFA
CRITAWS-managed policy grants *:* admin
HIGHNo delegated admin: Config / GuardDuty / Security Hub
HIGHIMDSv2 not enforced at account level
HIGHIAM users rely on long-lived credentials
HIGHSecrets Manager rotation disabled (19 secrets)
HIGHKMS key auto-rotation off · SCP region restriction absent

Full evidence: findings/prowler/*.html · *.ocsf.json · compliance/

Proposal levers

where we create value · ordered by priority
WorkstreamDriver from discoveryOutcome
Landing zone & account separationWorkloads in mgmt acct; flat org, no OUs; empty Lazka; SCP region-deny absentDedicated workload account; OUs + SCP guardrails (region deny, root protection)
Delegated security accountZero delegated admins — GuardDuty, Security Hub and Config all flagged high; 4 open GD high/critical findings; Lazka darkCentral security account admins all three org-wide; findings get a named owner and triage SLA
Backup & resilience0 of 9 EBS volumes have snapshots or a backup plan (18 high/medium failures)AWS Backup plans, tested restores, RPO/RTO defined — today a volume loss is unrecoverable
Identity hardeningAdmin keys 322 & 319 days; 5 keys >90d; 6 users on static creds; 9 users + root without hardware MFA; AdministratorAccess attached (*:*)IAM Identity Center + short-lived roles; retire static keys, scope admin, hardware MFA on root
Exposure reduction13 internet-open SGs; 3 permissive NACLs; 7 public-IP instances; 6 internet-facing instances carrying instance profiles; IMDSv2 not enforced account-wideLeast-privilege ingress, IMDSv2 enforced, ALB/WAF fronting — closes the credential-theft path
Secrets & key management19 secrets with no rotation and no restrictive resource policy; 2 KMS keys without auto-rotation; 19 log groups unencrypted; secrets detected in 7 log groupsRotation on every secret, KMS/CMK coverage for logs and SNS, resource policies scoped to consumers
Cost optimization$858/mo, +284% Jan→Jul; EC2 = 67% of spend; 2 unattached EBS + 7 EIPs; orphaned EKS roles from a torn-down clusterRightsizing + Savings Plans + Graviton/spot + cleanup → recurring savings and a growth-safe baseline
Compliance accelerationProwler: 363 failures (2 critical, 111 high); SOC 2 81%, ISO 27001 77%, CIS 3.0 74%; Secureframe + Intruder already engagedClose the SOC 2 gap on evidence they already collect; Security Hub as the standing control monitor

The first three are the fastest to land and the hardest to defend leaving open — no delegated security owner, no backups, and workloads in the management account are each a single-event risk. Cost optimization is the lever that funds the rest.