- 
acm:DescribeCertificate
 
- 
acm:ListCertificates
 
- 
acm:ListTagsForCertificate
 
- 
apigateway:GET
 
- 
autoscaling:DescribeAccountLimits
 
- 
autoscaling:DescribeAutoScalingGroups
 
- 
autoscaling:DescribeAutoScalingInstances
 
- 
autoscaling:DescribeLaunchConfigurations
 
- 
autoscaling:DescribeLoadBalancerTargetGroups
 
- 
autoscaling:DescribeLoadBalancers
 
- 
autoscaling:DescribeNotificationConfigurations
 
- 
autoscaling:DescribeTags
 
- 
cloudformation:DescribeAccountLimits
 
- 
cloudformation:DescribeStackDriftDetectionStatus
 
- 
cloudformation:DescribeStacks
 
- 
cloudformation:DetectStackDrift
 
- 
cloudformation:GetStackPolicy
 
- 
cloudformation:ListStacks
 
- 
cloudfront:GetDistribution
 
- 
cloudfront:ListTagsForResource
 
- 
cloudfront:ListDistributions
 
- 
cloudtrail:DescribeTrails
 
- 
cloudtrail:GetTrailStatus
 
- 
cloudtrail:GetEventSelectors
 
- 
cloudtrail:ListTags
 
- 
cloudwatch:DescribeAlarms
 
- 
cloudwatch:DescribeAlarmsForMetric
 
- 
cloudwatch:GetMetricStatistics
 
- 
cloudwatch:GetMetricData
 
- 
cloudwatch:ListMetrics
 
- 
config:DescribeComplianceByConfigRule
 
- 
config:DescribeConfigRules
 
- 
config:DescribeConfigurationRecorderStatus
 
- 
config:DescribeConfigurationRecorders
 
- 
config:DescribeDeliveryChannelStatus
 
- 
config:DescribeDeliveryChannels
 
- 
config:GetComplianceDetailsByConfigRule
 
- 
config:GetResourceConfigHistory
 
- 
config:ListTagsForResource
 
- 
dynamodb:DescribeContinuousBackups
 
- 
dynamodb:DescribeLimits
 
- 
dynamodb:DescribeTable
 
- 
dynamodb:ListBackups
 
- 
dynamodb:ListTables
 
- 
dynamodb:ListTagsOfResource
 
- 
ec2:DescribeAccountAttributes
 
- 
ec2:DescribeAddresses
 
- 
ec2:DescribeEgressOnlyInternetGateways
 
- 
ec2:DescribeFlowLogs
 
- 
ec2:DescribeImages
 
- 
ec2:DescribeInstanceAttribute
 
- 
ec2:DescribeInstanceStatus
 
- 
ec2:DescribeInstances
 
- 
ec2:DescribeInternetGateways
 
- 
ec2:DescribeKeyPairs
 
- 
ec2:DescribeNatGateways
 
- 
ec2:DescribeNetworkAcls
 
- 
ec2:DescribeNetworkInterfaces
 
- 
ec2:DescribeReservedInstances
 
- 
ec2:DescribeRouteTables
 
- 
ec2:DescribeSecurityGroupReferences
 
- 
ec2:DescribeSecurityGroups
 
- 
ec2:DescribeSnapshots
 
- 
ec2:DescribeSnapshotAttribute
 
- 
ec2:DescribeSubnets
 
- 
ec2:DescribeTags
 
- 
ec2:DescribeTransitGatewayPeeringAttachments
 
- 
ec2:SearchTransitGatewayRoutes
 
- 
ec2:DescribeTransitGatewayRouteTables
 
- 
ec2:DescribeTransitGateways
 
- 
ec2:DescribeTransitGatewayAttachments
 
- 
ec2:DescribeVolumes
 
- 
ec2:DescribeVpcAttribute
 
- 
ec2:DescribeVpcEndpoints
 
- 
ec2:DescribeVpcEndpointConnections
 
- 
ec2:DescribeVpcEndpointServices
 
- 
ec2:DescribeVpcPeeringConnections
 
- 
ec2:DescribeVpcs
 
- 
ec2:DescribeVpnConnections
 
- 
ec2:DescribeVpnGateways
 
- 
ec2:GetEbsEncryptionByDefault
 
- 
elasticfilesystem:DescribeFileSystems
 
- 
elasticfilesystem:DescribeTags
 
- 
elasticmapreduce:DescribeCluster
 
- 
elasticmapreduce:ListClusters
 
- 
elasticmapreduce:ListInstances
 
- 
elasticmapreduce:GetBlockPublicAccessConfiguration
 
- 
es:DescribeElasticsearchDomain
 
- 
es:DescribeElasticsearchDomainConfig
 
- 
es:DescribeElasticsearchDomains
 
- 
es:DescribeElasticsearchInstanceTypeLimits
 
- 
es:DescribeReservedElasticsearchInstanceOfferings
 
- 
es:DescribeReservedElasticsearchInstances
 
- 
es:ListDomainNames
 
- 
es:ListElasticsearchInstanceTypes
 
- 
es:ListElasticsearchVersions
 
- 
es:ListTags
 
- 
elasticache:DescribeCacheClusters
 
- 
elasticache:DescribeReplicationGroups
 
- 
elasticache:DescribeReservedCacheNodes
 
- 
elasticache:ListTagsForResource
 
- 
elasticloadbalancing:DescribeListeners
 
- 
elasticloadbalancing:DescribeLoadBalancerAttributes
 
- 
elasticloadbalancing:DescribeLoadBalancerPolicies
 
- 
elasticloadbalancing:DescribeLoadBalancers
 
- 
elasticloadbalancing:DescribeTags
 
- 
elasticloadbalancing:DescribeTargetGroups
 
- 
elasticloadbalancing:DescribeTargetHealth
 
- 
iam:GenerateCredentialReport
 
- 
elasticloadbalancing:DescribeRules
 
- 
iam:GetAccessKeyLastUsed
 
- 
iam:GetAccountPasswordPolicy
 
- 
iam:GetAccountSummary
 
- 
iam:GetCredentialReport
 
- 
iam:GetGroup
 
- 
iam:GetGroupPolicy
 
- 
iam:GetLoginProfile
 
- 
iam:GetOpenIDConnectProvider
 
- 
iam:GetPolicy
 
- 
iam:GetPolicyVersion
 
- 
iam:GetRole
 
- 
iam:GetRolePolicy
 
- 
iam:GetSAMLProvider
 
- 
iam:GetServerCertificate
 
- 
iam:GetUser
 
- 
iam:GetUserPolicy
 
- 
iam:ListAccessKeys
 
- 
iam:ListAccountAliases
 
- 
iam:ListAttachedGroupPolicies
 
- 
iam:ListAttachedRolePolicies
 
- 
iam:ListAttachedUserPolicies
 
- 
iam:ListEntitiesForPolicy
 
- 
iam:ListGroupPolicies
 
- 
iam:ListGroups
 
- 
iam:ListInstanceProfiles
 
- 
iam:ListInstanceProfilesForRole
 
- 
iam:ListMFADevices
 
- 
iam:ListOpenIDConnectProviders
 
- 
iam:ListPolicies
 
- 
iam:ListPolicyTags
 
- 
iam:ListPolicyVersions
 
- 
iam:ListRolePolicies
 
- 
iam:ListRoleTags
 
- 
iam:ListRoles
 
- 
iam:ListSAMLProviders
 
- 
iam:ListSSHPublicKeys
 
- 
iam:ListServerCertificates
 
- 
iam:ListUserPolicies
 
- 
iam:ListUserTags
 
- 
iam:ListUsers
 
- 
iam:ListVirtualMFADevices
 
- 
kms:DescribeKey
 
- 
kms:GetKeyPolicy
 
- 
kms:GetKeyRotationStatus
 
- 
kms:ListAliases
 
- 
kms:ListGrants
 
- 
kms:ListKeyPolicies
 
- 
kms:ListKeys
 
- 
kms:ListResourceTags
 
- 
lambda:GetAccountSettings
 
- 
lambda:GetFunction
 
- 
lambda:GetFunctionConfiguration
 
- 
lambda:GetPolicy
 
- 
lambda:ListEventSourceMappings
 
- 
lambda:ListFunctions
 
- 
lambda:ListTags
 
- 
lambda:ListLayers
 
- 
logs:DescribeLogGroups
 
- 
logs:DescribeMetricFilters
 
- 
rds:DescribeAccountAttributes
 
- 
rds:DescribeDBClusters
 
- 
rds:DescribeDBClusterParameters
 
- 
rds:DescribeDBClusterParameterGroups
 
- 
rds:DescribeDBInstances
 
- 
rds:DescribeDBSecurityGroups
 
- 
rds:DescribeDBSnapshotAttributes
 
- 
rds:DescribeDBSnapshots
 
- 
rds:DescribeDBParameters
 
- 
rds:DescribeEvents
 
- 
rds:DescribeEventSubscriptions
 
- 
rds:DescribeReservedDBInstances
 
- 
rds:ListTagsForResource
 
- 
redshift:DescribeClusterParameterGroups
 
- 
redshift:DescribeClusterParameters
 
- 
redshift:DescribeClusters
 
- 
redshift:DescribeLoggingStatus
 
- 
redshift:DescribeReservedNodes
 
- 
redshift:DescribeTags
 
- 
route53:GetDNSSEC
 
- 
route53:GetGeoLocation
 
- 
route53:ListHostedZones
 
- 
route53:ListResourceRecordSets
 
- 
route53:ListTagsForResource
 
- 
route53domains:ListDomains
 
- 
route53domains:ListTagsForDomain
 
- 
ses:GetIdentityDkimAttributes
 
- 
ses:GetIdentityPolicies
 
- 
ses:GetIdentityVerificationAttributes
 
- 
ses:ListIdentities
 
- 
ses:ListIdentityPolicies
 
- 
sns:GetTopicAttributes
 
- 
sns:ListTopics
 
- 
sns:ListSubscriptionsByTopic
 
- 
sns:ListTagsForResource
 
- 
sqs:GetQueueAttributes
 
- 
sqs:ListQueues
 
- 
sqs:ListQueueTags
 
- 
tag:GetResources
 
- 
tag:GetTagKeys
 
- 
tag:GetTagValues
 
- 
access-analyzer:ListAnalyzers
 
- 
access-analyzer:ListFindings
 
- 
application-autoscaling:DescribeScalableTargets
 
- 
application-autoscaling:DescribeScalingActivities
 
- 
application-autoscaling:DescribeScalingPolicies
 
- 
application-autoscaling:DescribeScheduledActions
 
- 
athena:GetQueryExecution
 
- 
athena:ListQueryExecutions
 
- 
athena:ListTagsForResource
 
- 
backup:DescribeBackupVault
 
- 
backup:ListBackupVaults
 
- 
backup:ListRecoveryPointsByResource
 
- 
backup:GetBackupVaultAccessPolicy
 
- 
ce:GetAnomalies
 
- 
ce:GetAnomalyMonitors
 
- 
dax:DescribeClusters
 
- 
dax:ListTags
 
- 
dms:DescribeReplicationInstances
 
- 
dms:ListTagsForResource
 
- 
ds:DescribeDirectories
 
- 
ds:ListTagsForResource
 
- 
elasticbeanstalk:DescribeConfigurationSettings
 
- 
elasticbeanstalk:DescribeEnvironments
 
- 
ecr:DescribeRepositories
 
- 
ecr:GetRepositoryPolicy
 
- 
ecr:GetLifecyclePolicy
 
- 
ecr:DescribeImages
 
- 
eks:DescribeCluster
 
- 
eks:ListClusters
 
- 
events:DescribeEventBus
 
- 
events:ListRules
 
- 
events:DescribeRule
 
- 
firehose:DescribeDeliveryStream
 
- 
firehose:ListDeliveryStreams
 
- 
kafka:DescribeCluster
 
- 
kafka:ListClusters
 
- 
kafka:ListNodes
 
- 
mq:DescribeBroker
 
- 
mq:ListBrokers
 
- 
glue:GetDataCatalogEncryptionSettings
 
- 
glue:GetSecurityConfiguration
 
- 
glue:GetSecurityConfigurations
 
- 
glue:GetDatabases
 
- 
guardduty:GetDetector
 
- 
guardduty:GetFindings
 
- 
guardduty:ListDetectors
 
- 
guardduty:ListFindings
 
- 
health:DescribeAffectedEntities
 
- 
health:DescribeEventDetails
 
- 
health:DescribeEvents
 
- 
inspector:DescribeFindings
 
- 
inspector:DescribeAssessmentRuns
 
- 
inspector:DescribeAssessmentTemplates
 
- 
inspector:DescribeExclusions
 
- 
inspector:ListFindings
 
- 
inspector:ListAssessmentRuns
 
- 
inspector:ListAssessmentTemplates
 
- 
inspector:ListExclusions
 
- 
kinesis:DescribeStream
 
- 
kinesis:ListStreams
 
- 
kinesis:ListTagsForStream
 
- 
organizations:DescribeAccount
 
- 
organizations:DescribeCreateAccountStatus
 
- 
organizations:DescribeHandshake
 
- 
organizations:DescribeOrganization
 
- 
organizations:DescribeOrganizationalUnit
 
- 
organizations:DescribePolicy
 
- 
organizations:ListAWSServiceAccessForOrganization
 
- 
organizations:ListAccounts
 
- 
organizations:ListAccountsForParent
 
- 
organizations:ListChildren
 
- 
organizations:ListCreateAccountStatus
 
- 
organizations:ListHandshakesForAccount
 
- 
organizations:ListHandshakesForOrganization
 
- 
organizations:ListOrganizationalUnitsForParent
 
- 
organizations:ListParents
 
- 
organizations:ListPolicies
 
- 
organizations:ListPoliciesForTarget
 
- 
organizations:ListRoots
 
- 
organizations:ListTargetsForPolicy
 
- 
route53domains:GetDomainDetail
 
- 
s3:GetAccelerateConfiguration
 
- 
s3:GetAccountPublicAccessBlock
 
- 
s3:GetBucketAcl
 
- 
s3:GetBucketLocation
 
- 
s3:GetBucketLogging
 
- 
s3:GetBucketObjectLockConfiguration
 
- 
s3:GetBucketPolicy
 
- 
s3:GetBucketPolicyStatus
 
- 
s3:GetBucketPublicAccessBlock
 
- 
s3:GetBucketTagging
 
- 
s3:GetBucketVersioning
 
- 
s3:GetBucketWebsite
 
- 
s3:GetEncryptionConfiguration
 
- 
s3:GetLifecycleConfiguration
 
- 
s3:ListBucket
 
- 
3:ListAllMyBuckets
 
- 
securityhub:GetEnabledStandards
 
- 
securityhub:GetFindings
 
- 
securityhub:GetInsightResults
 
- 
securityhub:GetInsights
 
- 
securityhub:GetMasterAccount
 
- 
securityhub:GetMembers
 
- 
securityhub:ListEnabledProductsForImport
 
- 
securityhub:ListInvitations
 
- 
securityhub:ListMembers
 
- 
servicequotas:ListServiceQuotas
 
- 
sagemaker:DescribeNotebookInstance
 
- 
sagemaker:ListNotebookInstances
 
- 
sagemaker:ListTags
 
- 
sagemaker:DescribeDomain
 
- 
sagemaker:ListDomains
 
- 
sagemaker:ListModels
 
- 
sagemaker:DescribeModel
 
- 
sagemaker:ListEndpoints
 
- 
sagemaker:DescribeEndpoint
 
- 
sagemaker:ListImages
 
- 
sagemaker:ListClusters
 
- 
sagemaker:DescribeCluster
 
- 
sagemaker:ListClusterNodes
 
- 
sagemaker:DescribeClusterNode
 
- 
sagemaker:DescribeImageVersion
 
- 
secretsmanager:DescribeSecret
 
- 
secretsmanager:ListSecrets
 
- 
shield:DescribeSubscription
 
- 
ssm:DescribeParameters
 
- 
ssm:DescribeSessions
 
- 
ssm:DescribeInstanceInformation
 
- 
storagegateway:DescribeNFSFileShares
 
- 
storagegateway:DescribeSMBFileShares
 
- 
storagegateway:DescribeTapes
 
- 
storagegateway:ListFileShares
 
- 
storagegateway:ListTagsForResource
 
- 
storagegateway:ListTapes
 
- 
transfer:DescribeServer
 
- 
transfer:ListServers
 
- 
xray:GetEncryptionConfig
 
- 
waf:GetWebACL
 
- 
waf:ListWebACLs
 
- 
wafv2:GetWebACL
 
- 
wafv2:ListWebACLs
 
- 
workspaces:DescribeTags
 
- 
workspaces:DescribeWorkspaces
 
- 
workspaces:DescribeWorkspacesConnectionStatus
 
- 
support:DescribeSeverityLevels
 
- 
support:DescribeTrustedAdvisorChecks
 
- 
support:DescribeTrustedAdvisorCheckResult
 
- 
support:DescribeTrustedAdvisorCheckRefreshStatuses
 
- 
support:RefreshTrustedAdvisorCheck
 
- 
comprehend:ListKeyPhrasesDetectionJobs
 
- 
comprehend:ListSentimentDetectionJobs
 
- 
comprehend:ListTopicsDetectionJobs
 
- 
comprehend:ListEntitiesDetectionJobs
 
- 
comprehend:ListDocumentClassificationJobs
 
- 
comprehend:ListDominantLanguageDetectionJobs
 
- 
wellarchitected:ListWorkloads
 
- 
wellarchitected:GetWorkload
 
- 
ecs:DescribeTaskDefinition
 
- 
ecs:ListTaskDefinitions
 
- 
compute-optimizer:GetAutoScalingGroupRecommendations
 
- 
compute-optimizer:GetEC2InstanceRecommendations
 
- 
ecs:ListClusters
 
- 
ecs:ListServices
 
- 
ecs:DescribeServices
 
- 
ecs:ListContainerInstances
 
- 
ecs:DescribeContainerInstances
 
- 
config:SelectResourceConfig
 
- 
iam:GetAccountAuthorizationDetails
 
- 
lambda:ListFunctionUrlConfigs
 
- 
rds:DescribeDBParameterGroups
 
- 
firehose:ListTagsForDeliveryStream
 
- 
inspector:DescribeAssessmentTargets
 
- 
inspector:DescribeResourceGroups
 
- 
inspector:ListAssessmentTargets
 
- 
inspector:PreviewAgents
 
- 
macie2:GetClassificationExportConfiguration
 
- 
macie2:GetFindingStatistics
 
- 
macie2:ListClassificationJobs
 
- 
securityhub:DescribeHub
 
- 
ecs:DescribeClusters
 
- 
ecs:ListTagsForResource
 
- 
appflow:DescribeFlow
 
- 
appflow:ListFlows
 
- 
bedrock:ListAgents
 
- 
bedrock:GetAgent
 
- 
bedrock:ListGuardrails
 
- 
bedrock:GetGuardrail
 
- 
bedrock:ListCustomModels
 
- 
bedrock:GetCustomModel
 
- 
bedrock:ListFoundationModels
 
- 
bedrock:ListTagsForResource
 
- 
bedrock:ListDataSources
 
- 
bedrock:GetDataSource
 
- 
bedrock:ListKnowledgeBases
 
- 
bedrock:GetKnowledgeBase
 
- 
bedrock:ListAgentActionGroups
 
- 
bedrock:GetAgentActionGroup
 
- 
bedrock:ListAgentKnowledgeBases
 
- 
bedrock:GetAgentKnowledgeBase
 
- 
bedrock:ListImportedModels
 
- 
bedrock:GetImportedModel
 
- 
aoss:ListCollections
 
- 
aoss:ListTagsForResource
 
- 
elasticache:DescribeServerlessCaches
 
- 
inspector2:ListFindings