🧹 AWS Cleanup — auditor

A read-only sweeper (Node, ~$2/mo, deployed as Infrastructure-as-Code) that inventories an AWS account, prices idle waste, and flags live security exposure — then cross-checks its findings against AWS Security Hub.

Demo view — every value on this page is synthetic. Account IDs, IP addresses, resource IDs and dollar figures are fabricated for illustration. The real tool runs against a live account; no customer data is shown here.
3
Critical exposures
11
High findings
~$67k
Idle cost / yr (illustrative)
142
Resources scanned

🛡 Security posture

MySQL (3306) open to the internetCRITICAL
sg-•••••••• · 0.0.0.0/0 → :3306 · eni attached
RDS instance publicly accessibleCRITICAL
db-•••••• · public endpoint · in a public subnet
RDP (3389) open to the worldCRITICAL
sg-•••••••• · 0.0.0.0/0 → :3389
SSH (22) open to 0.0.0.0/0HIGH
sg-•••••••• · attached to 4 instances
IAM user without MFAHIGH
user •••••• · console access · active keys
Access key not rotated > 365 daysHIGH
AKIA•••••••• · last rotated 500+ days ago
S3 account-level block-public-access offMEDIUM
account •••••••••••• · 2 of 4 settings disabled
GuardDuty not enabled in regionMEDIUM
us-east-1 · no threat detection

💰 Cost savings

Orphaned EBS snapshots~$1,900/mo
312 snapshots · source volumes deleted
Idle / oversized instances~$1,400/mo
i-•••••• · <3% CPU · m6i.2xlarge
Unattached EBS volumes~$620/mo
27 volumes · not attached to any instance
Idle NAT gateways~$390/mo
nat-•••••• · ~0 bytes processed
Stopped instances (billed EBS)~$280/mo
9 instances stopped > 90 days · disks still billed
Idle Elastic IPs~$110/mo
31 EIPs allocated · not associated
Idle load balancers~$85/mo
3 ALBs · no healthy targets
Idle RDS instances~$70/mo
db-•••••• · ~0 connections / 30 days

🔎 Cross-checked against AWS Security Hub

3
Critical
11
High
24
Medium
68%
FSBP score