scan_group
Run predefined security scanner groups for compliance or defense scenarios across AWS accounts. Supports read-only multi-account scanning.
Instructions
Run a predefined group of security scanners for a specific scenario (e.g., MLPS compliance, network defense). Read-only. Supports multi-account org scanning.
Input Schema
| Name | Required | Description | Default |
|---|---|---|---|
| group | Yes | Scan group ID: mlps3_precheck, hw_defense, exposure, data_encryption, least_privilege, log_integrity, disaster_recovery, idle_resources, tag_compliance, new_account_baseline, aggregation | |
| region | No | AWS region to scan (default: server region) | |
| org_mode | No | Enable multi-account scanning via AWS Organizations | |
| role_name | No | IAM role name to assume in child accounts (default: AWSSecurityMCPAudit) | |
| account_ids | No | Specific account IDs to scan (default: all org accounts) | |
| lang | No | Report language (default: zh) |