Find the cracks in your AWS account.
Pillarscan scans an account and ranks every weak spot across security, reliability and cost, with the fix for each one.
No sign-in. The demo below runs on sample data.
Security58 / 100
Reliability50 / 100
Cost42 / 100
Live demo
Demo account. A fictional company's account. The findings come from running the real scanner against mocked AWS, so every check has something to show.
Posture score
54/ 100Needs attention
38 of 75 checks failed. 22 rules, 3 regions, scanned 9 Oct 2026, 22:20 UTC.
Failed checks by service
Security
58 / 100
15 failed, 19 passed
Reliability
50 / 100
10 failed, 9 passed
Cost
42 / 100
13 failed, 9 passed
- Passed
- Critical
- High
- Medium
- Low
- One block is one check on one resource. Select a block to open it.
Findings
| Critical | Account | Failed |
| High | Account | Failed |
| High | sg-bdfeba40391a25f39 | Failed |
| High | sg-ffed841d2830eec7a | Failed |
| High | legacy-admin | Failed |
| High | contractor-temp | Failed |
| High | analytics-dev | Failed |
| High | analytics-dev | Failed |
| High | northwind-marketing-site | Failed |
| High | northwind-customer-exports | Failed |
| Medium | autoScalingGroup:37f3e1ea-2ee5-4006-b8bf-ac3fc1e6b638:autoScalingGroupName/worker-asg | Failed |
| Medium | sessions | Failed |
| Medium | feature-flags | Failed |
| Medium | Account | Failed |
| Medium | Account | Failed |
| Medium | vol-e41417dd74dd62ca3 | Failed |
| Medium | vol-64c27b4455a3bad2e | Failed |
| Medium | vol-88b067376db51aa6d | Failed |
| Medium | app/api-v1-retired/1a1d4d17f0dc05d9 | Failed |
| Medium | Account | Failed |
| Medium | Account | Failed |
| Medium | deploy-bot | Failed |
| Medium | metrics-exporter | Failed |
| Medium | reporting-eu | Failed |
| Medium | analytics-dev | Failed |
| Low | vol-b804034d464d24583 | Failed |
| Low | vol-e41417dd74dd62ca3 | Failed |
| Low | vol-64c27b4455a3bad2e | Failed |
| Low | snap-03b94175e1283ba60 | Failed |
| Low | snap-d0c8c2f5058c0a17a | Failed |
| Low | eipalloc-790c11cdcda85b672 | Failed |
| Low | eipalloc-e72e567664d2da6d2 | Failed |
| Low | image-thumbnailer | Failed |
| Low | nightly-export | Failed |
| Low | /aws/lambda/image-thumbnailer | Failed |
| Low | /northwind/api/access | Failed |
| Low | northwind-marketing-site | Failed |
| Low | northwind-artifacts | Failed |
One command, under a minute.
There is no agent to install and nothing to set up inside the account being scanned.
It assumes a read-only role
The role carries two AWS managed policies, SecurityAudit and ViewOnlyAccess, and nothing else. The scanner can look at everything and change nothing.
It runs 22 checks in every region
Each check is one small Python file that looks for one common mistake. They run in parallel across every region enabled in the account.
It ranks what it found
Every finding names the exact resource, says why it matters and gives the fix. The worst ones come first.
$ python -m scanner --profile pillarscan --out findings.jsonRan 22 checks against account 000000000000 40 failed, 19 passed, 0 errored high: 3 medium: 35 low: 2Findings written to findings.json
22 checks across three pillars.
The pillars come from the AWS Well-Architected Framework. Each check looks for one specific, common mistake.
Security10 checks
- Root account without MFACritical
- CloudTrail not enabled in all regionsHigh
- Security group open to the internet on port 22 or 3389High
- IAM policy granting * on *High
- IAM user without MFAHigh
- Publicly accessible RDS instanceHigh
- S3 bucket without public access blockHigh
- EBS default encryption offMedium
- GuardDuty not enabledMedium
- Access key older than 90 daysMedium
Reliability6 checks
- RDS automated backups disabledHigh
- Auto scaling group in a single availability zoneMedium
- DynamoDB table without point-in-time recoveryMedium
- RDS instance without Multi-AZMedium
- Lambda function without a dead-letter queueLow
- S3 bucket without versioningLow
Cost6 checks
- Unattached EBS volumeMedium
- Load balancer with no targetsMedium
- gp2 volume that could be gp3Low
- EBS snapshot older than 90 daysLow
- Unassociated Elastic IPLow
- CloudWatch log group with no retention setLow
A portfolio project, built in the open.
Pillarscan is not a company or a product. It is one engineer's working answer to “show me you understand AWS”.
The scanner is Python with boto3, tested with pytest and moto. The infrastructure is Terraform. This site is Next.js and TypeScript.
Scanner · built
A command-line tool with 22 checks, each tested against mocked AWS.
Dashboard · built
This page: a posture score, the pillars and a findings table with fixes.
Scan history · planned
An API on Lambda and DynamoDB that stores each scan and shows the trend.
Connect your own account · planned
Sign in, deploy a one-click role template, and scan from the browser.