Find the cracks in your AWS account.

Pillarscan scans an account and ranks every weak spot across security, reliability and cost, with the fix for each one.

No sign-in. The demo below runs on sample data.

Live demo

PillarscanLive demo

Demo account. A fictional company's account. The findings come from running the real scanner against mocked AWS, so every check has something to show.

Posture score

54/ 100Needs attention

38 of 75 checks failed. 22 rules, 3 regions, scanned 9 Oct 2026, 22:20 UTC.

Failed checks by service

Failed checks by service. EBS: 10. IAM: 5. EC2: 4. RDS: 4. S3: 4. DynamoDB: 2. GuardDuty: 2. Other services: 7.

Security

58 / 100

15 failed, 19 passed

Reliability

50 / 100

10 failed, 9 passed

Cost

42 / 100

13 failed, 9 passed

  • Passed
  • Critical
  • High
  • Medium
  • Low
  • One block is one check on one resource. Select a block to open it.

Findings

CriticalAccountFailed
HighAccountFailed
Highsg-bdfeba40391a25f39Failed
Highsg-ffed841d2830eec7aFailed
Highlegacy-adminFailed
Highcontractor-tempFailed
Highanalytics-devFailed
Highanalytics-devFailed
Highnorthwind-marketing-siteFailed
Highnorthwind-customer-exportsFailed
MediumautoScalingGroup:37f3e1ea-2ee5-4006-b8bf-ac3fc1e6b638:autoScalingGroupName/worker-asgFailed
MediumsessionsFailed
Mediumfeature-flagsFailed
MediumAccountFailed
MediumAccountFailed
Mediumvol-e41417dd74dd62ca3Failed
Mediumvol-64c27b4455a3bad2eFailed
Mediumvol-88b067376db51aa6dFailed
Mediumapp/api-v1-retired/1a1d4d17f0dc05d9Failed
MediumAccountFailed
MediumAccountFailed
Mediumdeploy-botFailed
Mediummetrics-exporterFailed
Mediumreporting-euFailed
Mediumanalytics-devFailed
Lowvol-b804034d464d24583Failed
Lowvol-e41417dd74dd62ca3Failed
Lowvol-64c27b4455a3bad2eFailed
Lowsnap-03b94175e1283ba60Failed
Lowsnap-d0c8c2f5058c0a17aFailed
Loweipalloc-790c11cdcda85b672Failed
Loweipalloc-e72e567664d2da6d2Failed
Lowimage-thumbnailerFailed
Lownightly-exportFailed
Low/aws/lambda/image-thumbnailerFailed
Low/northwind/api/accessFailed
Lownorthwind-marketing-siteFailed
Lownorthwind-artifactsFailed
Showing 38 of 75

One command, under a minute.

There is no agent to install and nothing to set up inside the account being scanned.

  1. It assumes a read-only role

    The role carries two AWS managed policies, SecurityAudit and ViewOnlyAccess, and nothing else. The scanner can look at everything and change nothing.

  2. It runs 22 checks in every region

    Each check is one small Python file that looks for one common mistake. They run in parallel across every region enabled in the account.

  3. It ranks what it found

    Every finding names the exact resource, says why it matters and gives the fix. The worst ones come first.

$ python -m scanner --profile pillarscan --out findings.jsonRan 22 checks against account 000000000000  40 failed, 19 passed, 0 errored  high: 3  medium: 35  low: 2Findings written to findings.json
Real output from a scan of this project's own AWS account: 17 regions in 52 seconds.

22 checks across three pillars.

The pillars come from the AWS Well-Architected Framework. Each check looks for one specific, common mistake.

Security10 checks

  • Root account without MFACritical
  • CloudTrail not enabled in all regionsHigh
  • Security group open to the internet on port 22 or 3389High
  • IAM policy granting * on *High
  • IAM user without MFAHigh
  • Publicly accessible RDS instanceHigh
  • S3 bucket without public access blockHigh
  • EBS default encryption offMedium
  • GuardDuty not enabledMedium
  • Access key older than 90 daysMedium

Reliability6 checks

  • RDS automated backups disabledHigh
  • Auto scaling group in a single availability zoneMedium
  • DynamoDB table without point-in-time recoveryMedium
  • RDS instance without Multi-AZMedium
  • Lambda function without a dead-letter queueLow
  • S3 bucket without versioningLow

Cost6 checks

  • Unattached EBS volumeMedium
  • Load balancer with no targetsMedium
  • gp2 volume that could be gp3Low
  • EBS snapshot older than 90 daysLow
  • Unassociated Elastic IPLow
  • CloudWatch log group with no retention setLow

A portfolio project, built in the open.

Pillarscan is not a company or a product. It is one engineer's working answer to “show me you understand AWS”.

The scanner is Python with boto3, tested with pytest and moto. The infrastructure is Terraform. This site is Next.js and TypeScript.

  • Scanner · built

    A command-line tool with 22 checks, each tested against mocked AWS.

  • Dashboard · built

    This page: a posture score, the pillars and a findings table with fixes.

  • Scan history · planned

    An API on Lambda and DynamoDB that stores each scan and shows the trend.

  • Connect your own account · planned

    Sign in, deploy a one-click role template, and scan from the browser.