id: iam-root-mfa info: name: MFA not enabled on AWS Root Account author: princechaddha severity: high description: | Checks if Multi-Factor Authentication (MFA) is enabled for the AWS root account reference: - https://docs.aws.amazon.com/cli/latest/reference/iam/get-account-summary.html tags: cloud,devops,aws,amazon,iam,aws-cloud-config self-contained: true code: - engine: - sh - bash source: | aws iam get-account-summary | jq -r '.SummaryMap.AccountMFAEnabled' matchers: - type: word words: - "0" extractors: - type: dsl dsl: - '"MFA is not enabled on your AWS Root account"' # digest: 4b0a00483046022100add350e50addd6d7c475c7ab805a9869384178065cc1aef7e96777448765fa2e022100cd5ae007e6406f2f721bc5d308de70f92456f2d0280b778690b85a80cd2fdb23:922c64590222798bb761d5b6d8e72950