Description
The internet-facing asset {AwsEc2Instance} ({AwsEc2Instance.InstanceId}) was found to have full access to your EC2 resources. Instance Profiles with the AmazonEC2FullAccess policy attached grant unrestricted access (Action: 'ec2:*') to EC2 resources on the account (Resource: '*'). In the event that the asset is compromised, this will grant the attacker full access to your EC2 resources, any data stored on them, and possible lateral movement which may lead to full account compromise.