All technological notes.
AWS ConfigAWS Config
S3 (analyzed by Athena)

CloudTrail API calls of a resource over time
Types:
Rules can be evaluated / triggered:
AWS Config Rules does not prevent actions from happening (no deny)(just overview of configurateion)
IAM denyPricing:
Sample:
EventBridge to trigger notifications when AWS resources are noncomplian
SNS (all events – use SNS Filtering or filter at client-side)
SSM Automation DocumentsAWS-Managed Automation Documents or create custom Automation DocumentsAutomation Documents that invokes Lambda functionRemediation Retries if the resource is still non-compliant after auto-remediation
