| aws:accessanalyzer:analyzer | access-analyzer:GetAnalyzer, access-analyzer:ListAnalyzers |
| aws:account:account | organizations:DescribeOrganization, account:GetAlternateContact, account:GetContactInformation, account:GetPrimaryEmail, organizations:ListAccounts |
| aws:acm:acm | acm:DescribeCertificate, acm:ListCertificates |
| aws:apigateway:api | apigateway:GET |
| aws:apigateway:integration | apigateway:GetMethod, apigateway:GetResources, apigateway:GET |
| aws:apigateway:stage | apigateway:GET, apigateway:GET |
| aws:apigatewayv2:api | apigateway:GetApis, apigateway:GetRoutes |
| aws:apigatewayv2:route | apigateway:GetApis, apigateway:GetRoutes |
| aws:apigatewayv2:stage | apigateway:GetApis, apigateway:GetStages |
| aws:applicationautoscaling:scalingactivity | applicationautoscaling:DescribeScalingActivities |
| aws:appsync:graphqlapi | appsync:GetGraphqlApi, appsync:ListGraphqlApis |
| aws:athena:workgroup | athena:GetWorkGroup, athena:ListWorkGroups |
| aws:autoscaling:group | autoscaling:DescribeAutoScalingGroups |
| aws:autoscaling:launchconfiguration | autoscaling:DescribeLaunchConfigurations |
| aws:backup:plan | backup:ListBackupPlans |
| aws:backup:recoverypoint | backup:ListBackupVaults, backup:ListRecoveryPointsByBackupVault |
| aws:cloudformation:stack | cloudformation:DescribeStacks, cloudformation:ListStacks |
| aws:cloudfront:distribution | cloudfront:GetDistribution, cloudfront:ListDistributions |
| aws:cloudtrail:trail | cloudtrail:DescribeTrails, cloudtrail:GetEventSelectors, cloudtrail:GetTrailStatus |
| aws:cloudwatchlogs:metricfilter | logs:DescribeMetricFilters |
| aws:codebuild:project | codebuild:BatchGetProjects, codebuild:ListProjects |
| aws:cognitoidentity:identitypool | cognito-identity:DescribeIdentityPool, cognito-identity:GetIdentityPoolRoles, cognito-identity:ListIdentityPools |
| aws:cognitoidentityprovider:userpool | cognito-idp:DescribeUserPool, cognito-idp:ListIdentityProviders, cognito-idp:ListUserPools |
| aws:configservice:recorder | config:DescribeConfigurationRecorders |
| aws:configservice:recorderstatus | config:DescribeConfigurationRecorderStatus |
| aws:dms:endpoint | dms:DescribeEndpoints |
| aws:dms:replicationinstance | dms:DescribeReplicationInstances |
| aws:dms:replicationtask | dms:DescribeReplicationTasks |
| aws:dax:cluster | dax:DescribeClusters |
| aws:docdb:cluster | rds:DescribeDBClusters |
| aws:dynamodb:table | dynamodb:DescribeContinuousBackups, dynamodb:DescribeTable, dynamodb:DescribeTimeToLive, dynamodb:ListTables |
| aws:ec2:ebs-encryption-by-default | ec2:GetEbsEncryptionByDefault |
| aws:ec2:snapshot | ec2:DescribeSnapshotAttribute, ec2:DescribeSnapshots |
| aws:ec2:volume | ec2:DescribeVolumes |
| aws:ec2:image | ec2:DescribeImageAttribute, ec2:DescribeImages |
| aws:ec2:vpnconnection | ec2:DescribeVpnConnections |
| aws:ec2:instance | ec2:DescribeInstances |
| aws:ec2:launchtemplateversion | ec2:DescribeLaunchTemplateVersions, ec2:DescribeLaunchTemplates |
| aws:ec2:networkacl | ec2:DescribeNetworkAcls |
| aws:ec2:networkinterface | ec2:DescribeNetworkInterfaces |
| aws:ec2:publicimage | ec2:DescribeImages |
| aws:ec2:region | ec2:DescribeRegions |
| aws:ec2:securitygroup | ec2:DescribeSecurityGroups |
| aws:ec2:vpcendpoint | ec2:DescribeVpcEndpoints |
| aws:ec2:vpc | ec2:DescribeVpcs |
| aws:ec2:vpcflowlog | ec2:DescribeFlowLogs |
| aws:ec2:elasticip | ec2:DescribeAddresses |
| aws:ec2:vpcinternetgateway | ec2:DescribeInternetGateways |
| aws:ec2:vpcnatgateway | ec2:DescribeNatGateways |
| aws:ec2:routetable | ec2:DescribeRouteTables |
| aws:ec2:client-vpn-endpoint | ec2:DescribeClientVpnEndpoints |
| aws:ecr:repository | ecr:DescribeRepositories, ecr:GetLifecyclePolicy, ecr:GetRepositoryPolicy |
| aws:ecrpublic:repository | ecr-public:DescribeImages, ecr-public:DescribeRepositories, ecr-public:GetRepositoryPolicy |
| aws:ecs:cluster | ecs:DescribeClusters, ecs:ListClusters |
| aws:ecs:service | ecs:DescribeServices, ecs:ListClusters, ecs:ListServices |
| aws:ecs:task | ecs:DescribeServices, ecs:DescribeTasks, ecs:ListClusters, ecs:ListServices, ecs:ListTasks |
| aws:ecs:task-definition | ecs:DescribeServices, ecs:DescribeTaskDefinition, ecs:DescribeTasks, ecs:ListClusters, ecs:ListServices, ecs:ListTasks |
| aws:efs:accesspoint | elasticfilesystem:DescribeAccessPoints |
| aws:efs:filesystem | elasticfilesystem:DescribeFileSystems, elasticfilesystem:DescribeLifecycleConfiguration |
| aws:eks:cluster | eks:DescribeCluster, eks:ListClusters |
| aws:eks:nodegroup | eks:DescribeCluster, eks:DescribeNodeGroup, eks:ListClusters, eks:ListNodeGroups |
| aws:elasticache:replicationgroup | elasticache:DescribeReplicationGroups |
| aws:elasticache:cluster | elasticache:DescribeCacheClusters |
| aws:elasticbeanstalk:environment | elasticbeanstalk:DescribeConfigurationSettings, elasticbeanstalk:DescribeEnvironments |
| aws:elasticloadbalancing:loadbalancer | elasticloadbalancing:DescribeInstanceHealth, elasticloadbalancing:DescribeLoadBalancerAttributes, elasticloadbalancing:DescribeLoadBalancerPolicies, elasticloadbalancing:DescribeLoadBalancers |
| aws:elasticloadbalancingv2:loadbalancer | elasticloadbalancing:DescribeListeners, elasticloadbalancing:DescribeLoadBalancerAttributes, elasticloadbalancing:DescribeLoadBalancers |
| aws:elasticloadbalancingv2:targetgroup | elasticloadbalancing:DescribeTargetGroups, elasticloadbalancing:DescribeTargetHealth |
| aws:elasticsearchservice:domain | es:DescribeElasticsearchDomains, es:ListDomainNames |
| aws:emr:cluster | elasticmapreduce:DescribeCluster, elasticmapreduce:GetAutoTerminationPolicy, elasticmapreduce:GetManagedScalingPolicy, elasticmapreduce:ListClusters |
| aws:eventbridge:eventbus | events:ListEventBuses, events:ListRules |
| aws:iam:account | organizations:DescribeOrganization, iam:GetAccountPasswordPolicy, iam:GetAccountSummary |
| aws:iam:instanceprofile | iam:GetInstanceProfile, iam:ListInstanceProfiles |
| aws:iam:server-certificate | iam:ListServerCertificates |
| aws:iam:group | iam:GetGroup, iam:ListAttachedGroupPolicies, iam:ListGroups |
| aws:iam:groupinlinepolicy | iam:GetGroupPolicy, iam:ListGroupPolicies, iam:ListGroups |
| aws:iam:policy | iam:GetPolicy, iam:GetPolicyVersion, iam:ListPolicies |
| aws:iam:role | iam:GetAccountAuthorizationDetails, iam:GetRole, iam:ListAttachedRolePolicies |
| aws:iam:roleinlinepolicy | iam:GetAccountAuthorizationDetails, iam:GetRole, iam:GetRolePolicy, iam:ListRolePolicies |
| aws:iam:accesskeymetadata | iam:GetUser, iam:ListAccessKeys, iam:ListUsers, iam:ListVirtualMFADevices |
| aws:iam:user | iam:GetLoginProfile, iam:GetUser, iam:ListAttachedUserPolicies, iam:ListGroupsForUser, iam:ListMFADevices, iam:ListSSHPublicKeys, iam:ListUsers, iam:ListVirtualMFADevices |
| aws:iam:userinlinepolicy | iam:GetUser, iam:GetUserPolicy, iam:ListUserPolicies, iam:ListUsers, iam:ListVirtualMFADevices |
| aws:iam:virtualmfadevice | iam:ListUsers, iam:ListVirtualMFADevices |
| aws:kinesis:stream | kinesis:DescribeStreamSummary, kinesis:ListStreams |
| aws:kms:alias | kms:GetKeyPolicy, kms:ListAliases |
| aws:kms:key | kms:DescribeKey, kms:GetKeyRotationStatus, kms:ListKeys |
| aws:lambda:eventsourcemapping | lambda:ListEventSourceMappings, lambda:ListFunctions |
| aws:lambda:function | lambda:GetFunction, lambda:GetPolicy, lambda:ListFunctionUrlConfigs, lambda:ListFunctions, lambda:ListProvisionedConcurrencyConfigs |
| aws:lightsail:instance | lightsail:GetInstancePortStates, lightsail:GetInstances |
| aws:cloudwatch:metricalarm | cloudwatch:DescribeAlarms |
| aws:cloudwatchlogs:metricfilter | logs:DescribeMetricFilters |
| aws:neptune:cluster | rds:DescribeDBClusters |
| aws:neptune:cluster-snapshot | rds:DescribeDBClusterSnapshotAttributes, rds:DescribeDBClusterSnapshots |
| aws:neptune:dbinstance | rds:DescribeDBInstances |
| aws:network-firewall:firewall | network-firewall:DescribeFirewall, network-firewall:DescribeFirewallPolicy, network-firewall:DescribeLoggingConfiguration, network-firewall:ListFirewalls |
| aws:opensearch:domain | es:DescribeDomain, es:ListDomainNames |
| aws:rds:cluster | rds:DescribeDBClusters |
| aws:rds:cluster-snapshot | rds:DescribeDBClusterSnapshotAttributes, rds:DescribeDBClusterSnapshots |
| aws:rds:eventsubscription | rds:DescribeEventSubscriptions |
| aws:rds:instance | rds:DescribeDBInstances |
| aws:rds:snapshot | rds:DescribeDBSnapshotAttributes, rds:DescribeDBSnapshots |
| aws:redshift:cluster | redshift:DescribeClusterParameters, redshift:DescribeClusters, redshift:DescribeEndpointAccess, redshift:DescribeLoggingStatus |
| aws:route53:hostedzone | route53:GetDNSSEC, route53:GetHostedZone, route53:ListHostedZones |
| aws:route53:resourcerecordset | route53:ListHostedZones, route53:ListResourceRecordSets |
| aws:route53domains:domain | route53domains:ListDomains |
| aws:s3:bucket | s3:GetBucketAcl, s3:GetEncryptionConfiguration, s3:GetLifecycleConfiguration, s3:GetBucketLogging, s3:GetBucketMetadataConfiguration, s3:GetBucketNotification, s3:GetBucketOwnershipControls, s3:GetBucketPolicy, s3:GetBucketPolicyStatus, s3:GetReplicationConfiguration, s3:GetBucketVersioning, s3:GetBucketWebsite, s3:GetBucketPublicAccessBlock, s3:GetInventoryConfiguration, s3:ListAllMyBuckets |
| aws:s3control:accountpublicaccessblock | s3:GetBucketPublicAccessBlock |
| aws:sagemaker:notebookinstance | sagemaker:DescribeNotebookInstance, sagemaker:ListNotebookInstances |
| aws:secretsmanager:secret | secretsmanager:DescribeSecret, secretsmanager:GetResourcePolicy, secretsmanager:ListSecrets |
| aws:securityhub:hub | securityhub:DescribeHub |
| aws:sfn:statemachine | states:DescribeStateMachine, states:ListStateMachines |
| aws:sns:topic | sns:GetTopicAttributes, sns:ListTopics |
| aws:sqs:queue | sqs:GetQueueAttributes, sqs:GetQueueUrl, sqs:ListQueues |
| aws:ssm:instance | ssm:DescribeInstanceInformation, ssm:ListComplianceItems |
| aws:ec2:subnet | ec2:DescribeSubnets |
| aws:ec2:transitgateway | ec2:DescribeTransitGateways |
| aws:wafv2:acl | wafv2:GetLoggingConfiguration, wafv2:GetWebACL, wafv2:ListWebACLs |
| aws:wafv2:ipset | wafv2:GetIPSet, wafv2:ListIPSets |
| aws:wafv2:regexpatternset | wafv2:GetRegexPatternSet, wafv2:ListRegexPatternSets |
| aws:wafv2:rulegroup | wafv2:GetRuleGroup, wafv2:ListRuleGroups |
| aws:wafv2:acl | wafv2:GetLoggingConfiguration, wafv2:GetWebACL, wafv2:ListResourcesForWebACL, wafv2:ListWebACLs |
| aws:wafv2:ipset | wafv2:GetIPSet, wafv2:ListIPSets |
| aws:wafv2:regexpatternset | wafv2:GetRegexPatternSet, wafv2:ListRegexPatternSets |
| aws:wafv2:rulegroup | wafv2:GetRuleGroup, wafv2:ListRuleGroups |
| aws:iam:credentialreport | iam:GenerateCredentialReport, iam:GetCredentialReport |