Skip to main content
emnode
Compliance High severity

AWS Security Hub · EC2

EC2.2: Default security groups still allow traffic

Written and reviewed by Emnode · Last reviewed

What does AWS Security Hub EC2.2 check?

EC2.2 fails when a VPC's default security group has any inbound or outbound rules. AWS best practice is that the default SG should permit no traffic at all.

Why does EC2.2 matter?

Every ENI that is launched without an explicit security group lands in the default one. If that group has open rules, resources silently inherit network access nobody intended: a classic way for a forgotten instance to end up reachable. Emptying the default SG makes "no explicit SG" fail safe instead of fail open.

How do I fix EC2.2?

  1. For each VPC, remove all inbound and outbound rules from the default security group.
  2. Create purpose-built security groups and attach them explicitly to every resource.
  3. Add an SCP or Config rule so the default SG stays empty going forward.

Remediation script · bash

# Revoke an over-open admin rule, covering both IPv4 and IPv6 in one call.
aws ec2 revoke-security-group-ingress --group-id sg-0a1b2c3d \
  --ip-permissions 'IpProtocol=tcp,FromPort=22,ToPort=22,IpRanges=[{CidrIp=0.0.0.0/0}],Ipv6Ranges=[{CidrIpv6=::/0}]'

# Where access is genuinely needed, re-add it scoped to a source security group, not a CIDR.
aws ec2 authorize-security-group-ingress --group-id sg-0a1b2c3d \
  --ip-permissions 'IpProtocol=tcp,FromPort=6379,ToPort=6379,UserIdGroupPairs=[{GroupId=sg-0app1234,Description=app-tier}]'

# Strip a default security group to empty by feeding its current rules back into revoke.
INGRESS=$(aws ec2 describe-security-groups --group-ids sg-0default01 \
  --query 'SecurityGroups[0].IpPermissions')
[ "$INGRESS" != "[]" ] && aws ec2 revoke-security-group-ingress \
  --group-id sg-0default01 --ip-permissions "$INGRESS"

Full walkthrough (console steps, edge cases and verification) in the lesson Harden security groups and restrict ingress.

Is EC2.2 a false positive?

The default SG includes an implicit allow-all egress rule when created; EC2.2 wants that removed too. Deleting only inbound rules will leave the control FAILED.

Part of the learning path Lock down access
  • EC2.1 An EBS snapshot is publicly restorable by any account
  • EC2.3 Attached EBS volumes are not encrypted at rest
  • EC2.4 Long-stopped instances are abandoned attack surface
  • EC2.6 No VPC flow logs, so there is no network audit trail
  • EC2.7 New EBS volumes are not encrypted by default
  • EC2.8 IMDSv1 lets an SSRF steal instance credentials
  • EC2.9 Instances are directly reachable on public IPv4
  • EC2.10 EC2 API traffic leaves the VPC over the internet
  • EC2.13 SSH (port 22) is open to the entire internet
  • EC2.14 RDP (port 3389) is open to the entire internet
  • EC2.15 Subnets auto-assign public IPs to new instances
  • EC2.17 Instances with multiple ENIs can bridge network boundaries