Aws shield advanced is a good choice for x security.
Aws security scanning tools.
Intelligent discovery helps you manage your aws security with ease.
The scan results show the users with excessive risky or sensitive permissions.
You need a security monitoring solution that automates aws vulnerability scanning and threat detection.
Usm anywhere provides a unified security platform for your aws environment that simplifies threat detection by automatically performing vulnerability scanning on assets within your aws environment.
Awstealth is a security that tool teams use to discover the most privileged entities in the aws cloud environment.
Also if there are any zero day vulnerabilities reported these security testing tools can be used to scan amazon ec2 instances across an aws environments and provide immediate results with a list of the vulnerabilities that require patching.
Top 15 paid and free vulnerability scanner tools 2020 update dnsstuff.
Aws security vulnerability scanning remediation.