This is a real evidence pack, produced by a real scan of a real AWS account, published so you can see the shape of the output rather than a description of it. The account number, organisation identifiers and IAM principal identifiers have been replaced with synthetic values of the same form.
The hashes below are from the unredacted original and therefore do not verify against this altered copy. They are left in place because they are genuine output and show the real structure — but a redacted document cannot honestly claim its own chain verifies, and this one does not claim it. The original verifies; this copy is an illustration of it.
Period: 2026-08-25 00:00:00 UTC to 2026-08-27 00:00:00 UTC (inclusive of the start, exclusive of the end)
Framework: soc2
Connections in scope: 01JEXAMPCNN000000000000000
Every scan segment recorded in this period completed.
| Control | In-scope resource types | Status |
|---|---|---|
| configuration_changes_are_detected | config.recorder | Violation(s) observed during this period. |
| console_users_have_mfa | iam.user | Continuously compliant. |
| database_storage_encrypted_at_rest | rds.instance | Continuously compliant. |
| deployed_artifacts_are_immutable | ecr.repository, ecs.task_definition | Continuously compliant. |
| detected_anomalies_reach_an_owner | cloudwatch.alarm | Continuously compliant. |
| iam_no_unrestricted_administrative_access | iam.group, iam.policy, iam.role, iam.user | Violation(s) observed during this period. |
| object_storage_encrypted_at_rest | s3.bucket | Continuously compliant. |
| s3_bucket_not_publicly_accessible | s3.bucket | Continuously compliant. |
| tls_listeners_reject_obsolete_protocols | elasticloadbalancing.listener | Continuously compliant. |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0009XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Resource type: iam.user Kind: control_failure Field: attached_policy_arns Control: iam_no_unrestricted_administrative_access
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.user:AIDAEXAMPLE0000XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:14:57 UTC | finding_created |
Resource type: iam.access_key Kind: contract_violation Field: last_used_date Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.access_key:AKIAEXAMPLE0001XXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:18 UTC | finding_created |
Resource type: config.recorder Kind: control_failure Field: recording Control: configuration_changes_are_detected
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012/us-east-1:config.recorder:us-east-1
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:16:14 UTC | finding_created |
Resource type: ec2.security_group Kind: contract_violation Field: egress_rules Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012/us-east-1:ec2.security_group:sg-0e5a1c7b39f4d2a86
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:21 UTC | finding_created |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0003XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0006XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0008XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0010XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0004XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0005XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0012XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Resource type: ec2.security_group Kind: contract_violation Field: ingress_rules Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012/us-east-1:ec2.security_group:sg-0e5a1c7b39f4d2a86
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:21 UTC | finding_created |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0002XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0007XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Resource type: iam.user Kind: contract_violation Field: mfa_devices_active Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.user:AIDAEXAMPLE0000XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:14:57 UTC | finding_created |
Resource type: iam.role Kind: contract_violation Field: max_session_duration Control: unmapped
ARI: ari:01JEXAMP0RG000000000000000:aws:123456789012:iam.role:AROAEXAMPLE0011XXXXXX
| Timestamp | Event | Detail |
|---|---|---|
| 2026-08-25 19:15:13 UTC | finding_created |
Shipped verbatim so the derivations above can be re-run independently. Not filtered to this pack's framework — this is the whole table Assemble was given.
| ID | Description | Citations |
|---|---|---|
| object_storage_encrypted_at_rest | Data stored in an object storage service is encrypted at rest, using either a provider-managed or customer-managed encryption key. | soc2 CC6.6 (pending-review) |
| database_storage_encrypted_at_rest | Data stored in a managed database instance is encrypted at rest, using either a provider-managed or customer-managed encryption key. | soc2 CC6.6 (pending-review) |
| s3_bucket_not_publicly_accessible | An S3 bucket's own policy does not grant access to everyone on the internet. A statement whose effect would otherwise be a public grant, but carries a Condition or a NotPrincipal, is not evaluated -- AXON does not interpret condition keys or NotPrincipal semantics and reports those as indeterminate rather than guessing. This control does not see the account-level S3 Block Public Access setting (a separate resource, s3.account_public_access_block) or object ACLs -- neither is joined here. | soc2 CC6.1 (pending-review) |
| console_users_have_mfa | Every IAM user who can sign in to the AWS Management Console (has a login profile) has at least one active MFA device. A programmatic-only user with no console password is not evaluated by this control -- it has no business carrying an MFA device. This control does not see the AWS account root user (not an IAM user, not ingested), the account password policy, or access key rotation -- none are joined here. | soc2 CC6.2 (pending-review) |
| iam_no_unrestricted_administrative_access | No IAM identity (user, role, group or customer-managed policy) is granted unrestricted administrative access -- an Allow statement whose Action and Resource are both the literal wildcard "*", found in a stored policy document or an inline policy, or the AWS-managed AdministratorAccess policy attached by reference. This is NOT a least-privilege analysis: a narrower-but-still-broad grant (s3:* scoped to one bucket, a role that happens to be justified) is out of scope and never flagged. AWS service-linked roles (path beginning /aws-service-role/) pass unconditionally -- the customer did not create them and cannot modify them. This control does not see AWS-managed policy documents other than AdministratorAccess by exact ARN (their content is never stored), non-default policy versions, permission boundaries, SCPs, or group-inherited permissions on the member user. | soc2 CC6.3 (pending-review) |
| tls_listeners_reject_obsolete_protocols | No load-balancer listener negotiates TLS 1.0 or TLS 1.1 -- an HTTPS or TLS listener's own resolved SSL policy protocol list must never contain TLSv1 or TLSv1.1. A listener whose protocol is not HTTPS or TLS (HTTP, TCP, UDP, TCP_UDP, GENEVE) has no TLS policy at all and is out of scope, never flagged. A listener whose policy name this codebase does not recognise is indeterminate, never a pass -- an unfamiliar name is not evidence of a modern policy. This control does not see certificate expiry (needs a clock, which internal/controls may never read), cipher suites (the protocol list says nothing about which ciphers a policy permits), whether the load balancer is internet-facing (an internal listener permitting TLS 1.0 still fails), or CloudFront/API Gateway/any other TLS terminator (a different resource type with its own field, not joined here). | soc2 CC6.7 (pending-review) |
| configuration_changes_are_detected | AWS Config is actively recording configuration changes in every scanned region -- a configuration recorder exists and its own recording status is true. This control does NOT see CloudTrail, which records WHO made a change (AXON has no CloudTrail adapter at all -- Config only records WHAT changed); whether anyone reads or acts on the detections it records (a separate control); Config rules (config.rule is a different question -- a recorder with zero rules still records changes); delivery-channel health beyond the recorder's own last-delivery status; a narrow-scope recorder that records only an explicitly-listed subset of resource types (a real customer configuration whose serialised shape is not independently measured); or any region AXON does not scan at all. | soc2 CC7.1 (pending-review) |
| detected_anomalies_reach_an_owner | A CloudWatch alarm that transitions to ALARM can actually notify someone: its own actions are enabled, and at least one action (an SNS topic, an Auto Scaling policy, or another target) is configured to fire. This control evaluates every metric alarm the account has; it does NOT judge whether the account has adequate monitoring coverage for the resources it runs, and an account with zero alarms produces zero findings from this control. This control does NOT see whether an SNS topic named in alarm_actions has any subscribers -- a different resource AXON does not ingest, and an alarm firing into an empty topic passes this control; whether the alarm's own threshold is sensible (not judgeable from configuration alone); whether a human actually reads a delivered notification; composite alarms (a structurally different SDK type, not ingested under this resource type); or other detection sources such as CloudTrail, GuardDuty or Security Hub, none of which AXON ingests. | soc2 CC7.2 (pending-review) |
| deployed_artifacts_are_immutable | What runs in production cannot change identity without a new, recorded version. This control does NOT see who approved a change -- that needs CloudTrail plus a ticketing system, neither of which AXON ingests -- nor whether a git repository, a pull-request review, or any approval process exists at all; it also does not see Lambda functions, EC2 AMIs, or any other deployable artifact besides these two AWS resource types; whether the digest a task definition pins actually points at a GOOD image (immutable and vulnerable is still immutable); ecr.repository's own registry-level scanning configuration, which is a different API and is not ingested; or repositories in another account that a task definition's image string names -- that string is not resolved against AXON's own observed resources. Within that scope: an ECR repository whose image tags are not exactly IMMUTABLE fails, because anyone with push rights can later make an already-approved tag resolve to different code; an ECS task definition whose container pins a mutable tag rather than a content digest fails for the identical reason, regardless of how the tag is spelled -- a semver-looking tag is exactly as overwritable as "latest". | soc2 CC8.1 (pending-review) |
| Resource type | Finding kind | Field | Control |
|---|---|---|---|
| s3.bucket | contract_violation | encryption | object_storage_encrypted_at_rest |
| s3.bucket | control_failure | encryption | object_storage_encrypted_at_rest |
| rds.instance | contract_violation | storage_encrypted | database_storage_encrypted_at_rest |
| rds.instance | control_failure | storage_encrypted | database_storage_encrypted_at_rest |
| s3.bucket | control_failure | policy | s3_bucket_not_publicly_accessible |
| iam.user | control_failure | mfa_devices_active | console_users_have_mfa |
| iam.policy | control_failure | document | iam_no_unrestricted_administrative_access |
| iam.user | control_failure | attached_policy_arns | iam_no_unrestricted_administrative_access |
| iam.user | control_failure | inline_policies | iam_no_unrestricted_administrative_access |
| iam.role | control_failure | attached_policy_arns | iam_no_unrestricted_administrative_access |
| iam.role | control_failure | inline_policies | iam_no_unrestricted_administrative_access |
| iam.group | control_failure | attached_policy_arns | iam_no_unrestricted_administrative_access |
| iam.group | control_failure | inline_policies | iam_no_unrestricted_administrative_access |
| elasticloadbalancing.listener | control_failure | ssl_policy_protocols | tls_listeners_reject_obsolete_protocols |
| config.recorder | control_failure | recording | configuration_changes_are_detected |
| cloudwatch.alarm | control_failure | actions_enabled | detected_anomalies_reach_an_owner |
| cloudwatch.alarm | control_failure | alarm_actions | detected_anomalies_reach_an_owner |
| ecr.repository | control_failure | image_tag_mutability | deployed_artifacts_are_immutable |
| ecs.task_definition | control_failure | containers | deployed_artifacts_are_immutable |