Features Pricing Catalog Docs Demos About Sign in Start free

Pane catalog

Cloud
Tier
Category
Kind
AWS explorer

Access Analyzer

IAM Access Analyzer findings — resources accessible from outside the account's trust boundary.

AWS Service

Access analyzers

Every IAM Access Analyzer with type, status and current finding count.

AWS Service

ACM certificates

Every ACM certificate with domain, status, validation method and expiry date.

Azure builder

Activity Timeline (24h)

Activity timeline from the Azure Activity Log — who changed what, when, filterable by service.

GCP builder

Activity Timeline (24h)

Activity timeline from Cloud Audit Logs — who changed what, when, filterable by service.

Azure Service

AKS clusters

Every AKS cluster with Kubernetes version, node pool count, FQDN and power state.

AWS explorer

Alarm Coverage Gap

Resources that should have CloudWatch alarms but don't — find the gaps before they bite.

AWS explorer

Ami Inventory

Every AMI in the account with creation date, in-use count and stale candidates ready to deregister.

AWS Service

AMIs

Every AMI in the account with creation date, virtualisation type and public-share state.

AWS Service

API Gateway (HTTP)

Every HTTP API in API Gateway with protocol, endpoint type and route count.

AWS Service

API Gateway (REST)

Every REST API in API Gateway with endpoint type, stage count and last-updated date.

AWS explorer

App Health

Account-wide operational health scorecard — 15 rules across monitoring, backup, capacity and runtime.

Azure Service

App Services

Every Azure App Service with kind, SKU, state, runtime stack and default host name.

GCP Service

Artifact Registry

Every Artifact Registry repository with format, location and last-updated time.

AWS explorer

Asg Activity

Every Auto Scaling group with capacity, scaling rules and a 24-hour activity timeline.

AWS Service

Auto Scaling groups

Every Auto Scaling group with capacity (min / desired / max), instance type and AZs.

AWS explorer

AWS Backup

AWS Backup plans and recent job results — what's protected, when it ran and any failures.

AWS Service

AWS Config rules

Every AWS Config rule with compliance counts, source (managed / custom) and trigger type.

AWS explorer

AWS Health

AWS Health events: service incidents, scheduled maintenance, security advisories and notifications.

AWS Service

Backup jobs

Recent AWS Backup jobs with status, resource, backup plan and completion time.

AWS Service

Backup vaults

Every AWS Backup vault with recovery-point count, encryption and access policy.

GCP Service

BigQuery datasets

Every BigQuery dataset with location, default table expiration and access controls.

GCP Service

Bigtable instances

Every Bigtable instance with cluster count, storage type and serve nodes.

Azure team

Change Feed (24h)

24-hour stream of changes from the Activity Log, mixed across services into one timeline.

GCP team

Change Feed (24h)

24-hour stream of changes from Cloud Audit Logs, mixed across services into one timeline.

GCP Service

Cloud DNS zones

Every Cloud DNS zone with visibility (public / private), DNS name and record count.

GCP Service

Cloud Functions

Every Cloud Function (Gen 1 + Gen 2) with runtime, trigger type, region and status.

GCP Service

Cloud NAT

Every Cloud NAT gateway with router, region, NAT IP allocation and minimum ports per VM.

GCP Service

Cloud Run services

Every Cloud Run service with traffic split, latest revision, region and ingress setting.

GCP Service

Cloud Scheduler jobs

Every Cloud Scheduler job with schedule, target type, last attempt and current state.

GCP Service

Cloud Spanner

Every Cloud Spanner instance with configuration, processing units and node count.

GCP Service

Cloud SQL

Every Cloud SQL instance with engine, version, tier, HA mode and backup setting.

GCP Service

Cloud Storage buckets

Every Cloud Storage bucket with location, storage class, encryption and uniform-IAM state.

GCP Service

Cloud Tasks queues

Every Cloud Tasks queue with state, rate limits, retry config and stackdriver logging setting.

AWS explorer

CloudFormation Drift

CloudFormation stacks ranked by drift state, with per-resource property diffs for drifted stacks.

AWS Service

CloudFormation stacks

Every CloudFormation stack with status, drift state, last-updated time and template source.

AWS explorer

CloudFront

Every CloudFront distribution with hit ratio, requests per hour, error rate and origin latency.

AWS Service

CloudFront

Every CloudFront distribution with status, default cache behaviour and aliases.

AWS explorer

CloudFront Free Tier

CloudFront Free Tier consumption (1 TB / 10M requests) with burn rate and projected overage.

AWS builder

CloudTrail Events

CloudTrail audit trail of every API call that changed the account — filter, search and drill in.

AWS team

CloudTrail Search

Filtered search across CloudTrail events: event name, principal, resource and category.

AWS Service

CloudTrail trails

Every CloudTrail trail with multi-region flag, logging status and data-events config.

AWS Service

CloudWatch alarms

Every CloudWatch alarm with state (OK / ALARM / INSUFFICIENT_DATA), threshold and metric.

AWS Service

CloudWatch log groups

Every CloudWatch Log Group with retention setting, stored bytes and last-event time.

AWS explorer

CloudWatch Logs Storage

Every CloudWatch Log Group with volume, retention, last event and monthly storage cost.

AWS Service

CodeBuild projects

Every CodeBuild project with environment, source provider and last-build outcome.

AWS Service

CodePipeline pipelines

Every CodePipeline with stage count, version, last-execution status and update date.

GCP Service

Compute Engine VMs

Every Compute Engine VM with machine type, status, zone, network and service account.

AWS builder

Compute Optimizer

AWS Compute Optimizer findings across EC2, EBS, Lambda, ECS and Auto Scaling in one filterable list.

Azure builder

Compute Right-Sizing

Virtual Machines Azure Advisor thinks are over-provisioned, with projected monthly savings.

GCP builder

Compute Right-Sizing

Compute Engine and Cloud SQL instances GCP Recommender thinks are over-provisioned.

AWS explorer

Config Compliance

AWS Config rules with compliance counts per pack (CIS, PCI, OPS) and non-compliant resources.

Azure Service

Container Registries

Every Azure Container Registry with SKU, admin-user setting and login server.

Azure Service

Cosmos DB accounts

Every Cosmos DB account with API kind, multi-region writes and default consistency.

GCP builder

Cost by Label

GCP spend grouped by a label (environment, team, application) — what each slice costs.

AWS builder

Cost by Tag

AWS spend grouped by a tag (Environment, Team, Application) — what each slice of the account costs.

Azure builder

Cost by Tag

Azure spend grouped by a tag (Environment, Team, CostCenter) — what each slice costs.

AWS builder

Cost Forecast

30 days of daily AWS cost plus a 30-day forecast, with cost anomalies and remediation hints.

Azure builder

Cost Forecast (next 30 days)

30 days of daily Azure cost plus a 30-day forecast — track end-of-month spend before the bill.

GCP builder

Cost Forecast (next 30 days)

30 days of daily GCP cost plus a 30-day forecast — track end-of-month spend before the bill.

AWS builder

Cost Summary

Month-to-date AWS spend by service, region and account, with the top movers since last month.

Azure builder

Cost Summary

Month-to-date Azure spend by service, region and subscription, with top movers since last month.

GCP builder

Cost Summary

Month-to-date GCP spend by service, region and project, with top movers since last month.

AWS explorer

Cw Alarms

Every CloudWatch alarm with state, threshold, the metric driving it and a recent sparkline.

AWS builder

Daily Briefing

Newspaper-style 24h summary: alarms, security findings, free-tier hot spots and cost opportunities.

Azure builder

Daily Briefing ·

Newspaper-style 24h summary across alerts, security findings, activity and cost — Azure-wide.

GCP builder

Daily Briefing ·

Newspaper-style 24h summary across alerts, security findings, activity and cost — GCP-wide.

AWS explorer

Data Transfer Hotspots

Where AWS data-transfer cost is coming from — NAT, cross-region, cross-AZ, CloudFront, ranked.

Azure explorer

Database Inventory

Every Azure SQL, Cosmos DB, PostgreSQL and MySQL database with version, HA and backups.

GCP explorer

Database Inventory

Every Cloud SQL, AlloyDB, Firestore and Bigtable database with version, HA mode and backups.

Azure Service

DNS zones

Every Azure DNS zone with public / private flag, record count and resource group.

AWS explorer

DynamoDB

Every DynamoDB table with capacity, throttles, item count, size and feature flags (PITR, TTL).

AWS Service

DynamoDB tables

Every DynamoDB table with billing mode, capacity, item count and size.

AWS explorer

Ebs Snapshots

Every EBS snapshot with size, age and whether its source volume still exists — orphans first.

AWS Service

EBS snapshots

Every EBS snapshot with size, age, source volume and encryption state.

AWS Service

EBS volumes

Every EBS volume with size, IOPS, encryption and the instance it's attached to.

AWS Service

EC2 instances

Every EC2 instance with type, state, IPs, AZ and the AMI it launched from.

AWS Service

ECR repositories

Every ECR repository with image count, last-pushed date and tag-immutability setting.

AWS Service

ECS clusters

Every ECS cluster with active services, running tasks and capacity providers.

AWS explorer

Ecs Services

Every ECS service across every cluster, with deploy state, task counts and recent events.

AWS Service

EFS file systems

Every EFS file system with size, throughput mode, lifecycle policy and mount targets.

AWS explorer

Eip Eni

Every Elastic IP and ENI with attachment state — unattached EIPs (avoidable hourly cost) first.

AWS Service

EKS clusters

Every EKS cluster with Kubernetes version, endpoint access and node groups.

AWS explorer

Eks Overview

Every EKS cluster with Kubernetes version, node groups, add-ons and upcoming upgrade windows.

AWS Service

Elastic IPs

Every Elastic IP with attached resource — unattached EIPs (avoidable hourly cost) first.

AWS Service

ElastiCache clusters

Every ElastiCache cluster node with engine, node type, status and cache version.

AWS Service

ElastiCache replication groups

Every ElastiCache replication group with engine, primary / replicas and shard count.

AWS Service

EMR clusters

Every EMR cluster with state, instance fleet, release label and runtime.

AWS explorer

Engine Eol

RDS, Aurora, ElastiCache and EKS engines reaching End-of-Life within the next year.

AWS builder

Event Correlation

Alarms, deploys, security findings and CloudTrail events on one timeline for incident reviews.

Azure Service

Event Hubs

Every Event Hub namespace with SKU, throughput units and configured event hubs.

AWS Service

EventBridge rules

Every EventBridge rule with schedule / event pattern, bus and target count.

AWS explorer

Extended Support Cost

RDS, Aurora and EKS engines on AWS Extended Support, the monthly surcharge and upgrade target.

GCP Service

Filestore instances

Every Filestore instance with tier, capacity, network and current state.

GCP Service

Firestore databases

Every Firestore database with type (Native / Datastore mode), location and concurrency mode.

GCP Service

Firewall rules

Every firewall rule with direction, action, protocol / ports and source / target tags.

AWS builder

Free Tier Monitor

AWS Free Tier usage against allowances — which services are nearing their limits this month.

AWS Service

Free Tier usage

AWS Free Tier usage with service, allowance, actual usage and projected month-end consumption.

Azure explorer

Function Radar

Every Azure Function App with invocations, error rate, duration and last-deploy timestamp.

GCP explorer

Function Radar

Every Cloud Function with invocations, error rate, duration and last-deploy timestamp.

Azure Service

Functions

Every Azure Function App with hosting plan, runtime, OS and last-modified date.

GCP Service

GKE clusters

Every GKE cluster with Kubernetes version, node-pool count, location and endpoint.

AWS builder

Global Resource Search

Free-text search across every discovered AWS resource — instances, buckets, functions, databases.

Azure builder

Global Resource Search

Free-text search across every discovered Azure resource — VMs, storage, functions, databases.

GCP builder

Global Resource Search

Free-text search across every discovered GCP resource — VMs, buckets, functions, databases.

AWS Service

Glue databases

Every Glue catalog database with table count, location URI and description.

AWS explorer

Guardduty

Active GuardDuty threats: crypto-mining, credential exfiltration, unusual API patterns and more.

AWS Service

GuardDuty detectors

Every GuardDuty detector with status, data sources, finding-publishing frequency.

AWS explorer

IAM Access Keys

IAM access keys with age, last-used date and service — stale and unused keys called out first.

AWS Service

IAM policies

Every IAM managed policy with attachment count, default version and document size.

AWS Service

IAM roles

Every IAM role with trust policy, attached policies, last-used date and creation.

GCP Service

IAM service accounts

Every GCP service account with email, disabled flag, owned keys and last-used dates.

AWS Service

IAM users

Every IAM user with creation date, MFA status, access-key count and attached policies.

AWS explorer

Idle Finder

Resources sitting idle and costing money — low-CPU instances, idle databases, unused volumes.

Azure explorer

Idle Resource Finder

Azure resources sitting idle and costing money — low-CPU VMs, idle SQL, unattached disks.

GCP explorer

Idle Resource Finder

GCP resources sitting idle and costing money — low-CPU VMs, idle SQL, unattached disks.

AWS Service

Internet gateways

Every Internet Gateway with attached VPC and current state.

AWS explorer

Key & Secret Rotation

KMS keys and Secrets Manager secrets with rotation state: off, overdue or actively rotating.

AWS Service

Key pairs

Every EC2 key pair with name, fingerprint, type and creation date.

Azure explorer

Key Vault Rotation Audit

Azure Key Vault keys with rotation policy, last-rotated date and overdue flag.

Azure Service

Key Vaults

Every Azure Key Vault with SKU, soft-delete setting, network ACLs and access model.

AWS Service

Kinesis streams

Every Kinesis stream with shard count, retention period and encryption state.

GCP Service

KMS keyrings

Every Cloud KMS key ring with location, key count and parent project.

AWS Service

KMS keys

Every KMS key with key type, manager (AWS / customer), rotation state and aliases.

GCP explorer

KMS Rotation Audit

Cloud KMS keys with rotation period, last-rotated date and overdue flag.

GCP explorer

Label Coverage

Which GCP resources carry the required labels and which don't, scored by service type.

AWS Service

Lambda functions

Every Lambda function with runtime, memory, last-modified and reserved concurrency.

AWS explorer

Lambda Radar

Every Lambda function with concurrency, error rate, throttles and a 24-hour invocation trend.

AWS explorer

Load Balancer Health

Every load balancer with target groups, healthy / unhealthy counts and recent state changes.

AWS Service

Load balancers

Every load balancer (ALB / NLB / GLB) with scheme, listeners and target groups.

Azure Service

Load balancers

Every Azure Load Balancer with SKU (Basic / Standard), tier and front-end IP configurations.

GCP Service

Load balancers

Every Cloud Load Balancer with scheme (external / internal), protocol and backend services.

Azure Service

Managed disks

Every Azure managed disk with size, SKU, encryption type and the VM it's attached to.

GCP Service

Managed instance groups

Every Managed Instance Group with target size, autoscaler and current versions.

GCP Service

Memorystore instances

Every Memorystore (Redis / Memcached) instance with tier, capacity, version and HA mode.

Azure Service

Monitor alerts

Every Azure Monitor alert rule with state, severity, scope and trigger condition.

GCP Service

Monitoring alerts

Every Cloud Monitoring alert policy with state, severity, conditions and notification channels.

AWS builder

Multi-Region Footprint

World map of which AWS regions this account uses, sized by resource count.

Azure builder

Multi-Region Footprint

World map of which Azure regions this subscription uses, sized by resource count.

GCP builder

Multi-Region Footprint

World map of which GCP regions this project uses, sized by resource count.

AWS Service

NAT gateways

Every NAT Gateway with VPC, subnet, connectivity type and Elastic IP.

AWS explorer

Nat Traffic

Every NAT Gateway with bytes-out, connection count and a monthly cost breakdown.

AWS Service

Network ACLs

Every Network ACL with VPC, ingress / egress rules and associated subnets.

Azure explorer

Network Exposure

NSG rules allowing inbound from the internet — what's open, which ports and which targets.

GCP explorer

Network Exposure

GCP firewall rules allowing inbound from the internet — what's open and to which targets.

Azure Service

Network security groups

Every Network Security Group with inbound / outbound rule counts and associations.

GCP Service

Persistent disks

Every persistent disk with size, type, status and the instance it's attached to.

GCP Service

Pub/Sub subscriptions

Every Pub/Sub subscription with ack deadline, delivery type and dead-letter topic.

GCP Service

Pub/Sub topics

Every Pub/Sub topic with message retention, encryption and subscription count.

AWS explorer

Public Exposure Audit

Every publicly-reachable resource — buckets, databases, EC2, ALBs — split into critical vs expected.

Azure explorer

Public Exposure Audit

Every publicly-reachable Azure resource — storage, SQL, VMs, App Gateways — critical vs expected.

GCP explorer

Public Exposure Audit

Every publicly-reachable GCP resource — buckets, SQL, VMs, load balancers — critical vs expected.

Azure Service

Public IPs

Every Azure Public IP with SKU, allocation method, IP version and attached resource.

Azure explorer

Quota Radar

Azure subscription quotas with current usage vs limit — the ones most likely to bite at scale.

GCP explorer

Quota Radar

GCP quotas with current usage vs limit — the ones most likely to bite at scale.

AWS explorer

Rds Backups

Every RDS instance and Aurora cluster with retention, snapshot age, Multi-AZ and deletion protection.

AWS Service

RDS clusters

Every Aurora cluster with engine, version, writer / readers and storage.

AWS Service

RDS instances

Every RDS instance with engine, version, instance class, Multi-AZ and storage.

AWS builder

Reachability

VPC Reachability Analyzer paths — proof that one resource can or cannot reach another.

AWS Service

Redshift clusters

Every Redshift cluster with node type, count, version and encryption state.

AWS builder

RI & Savings Plans

Reserved Instances and Savings Plans coverage, utilisation and uncovered on-demand usage.

AWS builder

Right-Sizing

EC2, EBS, Lambda and ECS resources AWS thinks are over-provisioned, with projected monthly savings.

AWS explorer

Root Summary

Root credential summary: MFA, access keys, last-used, IAM user count and password policy.

AWS Service

Route 53 hosted zones

Every Route 53 hosted zone with public / private flag, record count and name servers.

AWS Service

Route tables

Every route table with VPC, route entries and associated subnets.

AWS explorer

Route53

Route 53 hosted zones, DNS records and health checks — DNS state for the account in one view.

AWS explorer

Runtime Eol

Lambda functions on deprecated runtimes, with AWS's block-create and disable dates.

AWS explorer

S3 Bucket Grid

Every S3 bucket with size, encryption, versioning, public-access-block and storage-class split.

AWS Service

S3 buckets

Every S3 bucket with region, size, versioning, encryption and public-access-block state.

AWS explorer

S3 Tree

Browseable folder-tree view of an S3 bucket with per-prefix size and object-count rollups.

GCP Service

Secret Manager

Every Secret Manager secret with replication policy, rotation period and last-rotated date.

AWS explorer

Secrets Browser

Every Secrets Manager secret with metadata, version count and last-changed date (no values).

AWS Service

Secrets Manager

Every Secrets Manager secret with last-rotated date, rotation enabled flag and KMS key.

AWS Service

Security groups

Every security group with VPC, ingress / egress rule counts and attached resources.

AWS Service

Security Hub findings

Active Security Hub findings with severity, standard, resource and workflow status.

AWS builder

Security Posture

A 0–100 score for the account's security configuration, broken down by rule category.

AWS builder

Security Recommendations

AWS Security Hub findings across CIS, PCI and AWS Foundational standards, with status and severity.

Azure builder

Security Recommendations

Microsoft Defender for Cloud findings: misconfigurations, vulnerabilities and threats.

GCP builder

Security Recommendations

Security Command Center findings: misconfigurations, vulnerabilities and threats across the project.

GCP explorer

Service Account Audit

Every GCP service account with its keys, roles and how recently each key was used.

Azure Service

Service Bus

Every Service Bus namespace with SKU, queue / topic count and managed identity.

Azure explorer

Service Principal Audit

Every Azure service principal with its credentials, role assignments and last-used dates.

AWS explorer

Service Quotas

AWS service quotas with current usage vs limit — the ones most likely to bite at scale.

AWS Service

Shield protections

Every AWS Shield protection with resource, protection group and current state.

AWS Service

SNS topics

Every SNS topic with subscription count, owner and encryption (KMS) status.

Azure Service

SQL databases

Every Azure SQL Database with edition, service tier, max-size and elastic-pool membership.

Azure Service

SQL servers

Every Azure SQL Server with version, public-network-access flag and admin login.

AWS Service

SQS queues

Every SQS queue with type (standard / FIFO), message count and visibility timeout.

AWS Service

SSM parameters

Every SSM Parameter Store entry with type (String / SecureString) and last-modified date.

AWS explorer

Step Functions

Every Step Functions state machine with success/failure rate, duration and 24-hour throughput.

AWS Service

Step Functions

Every Step Functions state machine with type (Standard / Express), status and role.

Azure Service

Storage accounts

Every Azure Storage account with kind, SKU, access tier, encryption and public-access state.

Azure explorer

Storage Inventory

Every Azure Storage account with size, access tier, encryption and public-access setting.

GCP explorer

Storage Inventory

Every Cloud Storage bucket with size, class, location, encryption and public-access setting.

AWS Service

Subnets

Every subnet with VPC, AZ, CIDR, available IPs and public-IP-on-launch flag.

Azure Service

Subnets

Every subnet with VNet, address prefix, NSG and the resources currently using it.

GCP Service

Subnets

Every subnet with region, primary CIDR, secondary ranges and private-Google-access flag.

Azure explorer

Tag Coverage

Which Azure resources carry the required tags and which don't, scored by service type.

AWS explorer

Tag Coverage Scorecard

Which AWS resources carry the required tags and which don't, scored by service type.

AWS Service

Transit gateways

Every Transit Gateway with state, owner, attachments and routing tables.

Azure Service

Virtual Machines

Every Azure Virtual Machine with size, OS, power state, region and resource group.

Azure Service

Virtual networks

Every Azure Virtual Network with address space, subnets and DNS server configuration.

AWS Service

VPC endpoints

Every VPC endpoint with service name, type (Gateway / Interface) and subnets.

GCP Service

VPC networks

Every VPC network with subnet mode (auto / custom), MTU and routing mode.

AWS Service

VPC peering

Every VPC peering connection with requester, accepter, region and current status.

AWS builder

Vpc Topology

Per-VPC topology: subnets, route tables, IGWs, NATs, peering and transit-gateway attachments.

AWS Service

VPCs

Every VPC with CIDR, default flag, DNS settings and tenancy.

AWS Service

WAF (CloudFront)

Every CloudFront-scoped WAFv2 ACL with rule count, default action and associated distributions.

AWS Service

WAF (regional)

Every regional WAFv2 ACL with rule count, default action and associated resources.

AWS builder

Xray Map

AWS X-Ray service map of how requests flow between services, with per-edge latency and errors.