AWS
Infrastructure
Made Clear

Visualize your network. Analyze traffic. Cut waste.
All in one place. Completely free.

No credit card
No time limit
All features included

Network Topology

See your entire AWS network architecture. VPCs, subnets, gateways, and connections—visualized.

Loading diagram...

VPC Groups

See subnets, route tables, and network ACLs organized by VPC

Gateway Connections

NAT gateways, internet gateways, and transit gateway attachments

VPC Peering

Visualize peering connections between VPCs

Cost Optimization

Find idle resources. Right-size instances. Cut waste with automated checks.

Total Potential Savings
$440/mo

$5,280/year potential savings

High Priority
1

Critical issues requiring attention

Quick Wins
2

Fixable in under 5 minutes

Daily Cost Waste (Last 7 Days)

~$18/day in preventable cloud costs

Automated daily scans detect new issues immediately

Example Cost Findings

HIGHus-east-1
10 min

High S3 data transfer - VPC endpoint recommended

application-data-bucket

2.4 TB/month cross-region data transfer from us-east-1

đź’ˇ

Deploy VPC endpoint for S3 to eliminate data transfer charges. Current transfer rate: 2.4 TB/mo Ă— $0.09/GB = $216/mo. VPC endpoints are free and eliminate this cost entirely.

$216/mo
potential
MEDIUMus-east-1
1 min

Log group with excessive retention (never expires)

/aws/lambda/data-processor-prod

420 GB of CloudWatch Logs with infinite retention

đź’ˇ

Set retention to 30 days for application logs. Long-term log storage should use S3 ($0.023/GB) instead of CloudWatch ($0.50/GB). Consider exporting to S3 and deleting old logs.

$210/mo
potential
LOWeu-west-1
3 min

Old unused AMI with snapshots

ami-0abc123def456 (api-server-v1.2.3-deprecated)

AMI from 2022 with 4 associated snapshots (280 GB)

đź’ˇ

Deregister AMI ami-0abc123def456 and delete associated snapshots. This AMI hasn't been used to launch instances in 18 months. Always keep the last 3 production AMIs.

$14/mo
potential

Security & Compliance

Continuous compliance monitoring across multiple frameworks. Identify security risks and misconfigurations before they become problems.

CIS AWS 2.0
Compliance86%
142 passed
23 failed
PCI DSS 4.0
Compliance89%
98 passed
12 failed
HIPAA
Compliance90%
76 passed
8 failed
SOC 2
Compliance90%
52 passed
6 failed
Critical Issues
1

Immediate action required

High Priority
1

Address within 7 days

Compliance Rate
87%

368 controls passing

Example Security Findings

CRITICALS3Production

S3 bucket publicly accessible

prod-customer-data

Bucket allows public read access - potential data exposure

Frameworks:CIS AWS 2.0PCI DSS 4.0SOC 2
Category:Data Protection
HIGHEC2Production

Security group allows 0.0.0.0/0 on port 22

sg-0abc123def456 (web-servers)

SSH access open to entire internet

Frameworks:CIS AWS 2.0HIPAA
Category:Network Security
MEDIUMIAMProduction

IAM password policy - minimum length not set

AWS Account Password Policy

Password policy doesn't enforce minimum length requirement

Frameworks:CIS AWS 2.0PCI DSS 4.0
Category:Identity & Access

Multiple Frameworks

Monitor compliance across CIS AWS, PCI DSS, HIPAA, SOC 2, and more. All in one dashboard.

Continuous Monitoring

Automated daily scans detect new security issues immediately. Get notified of critical findings via Slack or email.

Audit-Ready Reports

Generate compliance reports for auditors. Export findings with evidence and remediation steps.

Tag Compliance

Enforce tagging standards across all resources. Define policies, catch violations, and maintain governance at scale.

Policies Active
3

Enforcing 12 required tags

Resources Checked
91

73% compliance rate

Violations Found
24

8 high, 12 medium, 4 low

Active Policy: Production Tagging Standard

Required tags and validation rules for all production resources

EnvironmentRequired · prod/staging/dev
OwnerRequired · valid email
CostCenterRequired · CC-XXXX
ProjectRequired

Example Violations

HIGHEC2 InstanceProduction

Missing "Environment" tag

i-0abc123def456 (api-server-prod)
us-east-1

Add tag Environment with value 'prod'. This tag is required by the Production Tagging Standard policy for cost allocation.

MEDIUMRDS ClusterProduction

Invalid "Owner" value: "john"

rds-analytics-cluster
us-east-1

Update Owner tag to a valid email format (e.g., john@company.com). Current value 'john' doesn't match the required email pattern.

HIGHSecurity GroupDevelopment

Missing "CostCenter" and "Project" tags

sg-0def789abc123 (default-sg)
us-west-2

Add CostCenter tag (format: CC-XXXX) and Project tag. Both are required by organizational tagging policy.

Custom Policies

Define required tags, allowed values, and validation rules. Enforce different standards per account or environment.

Continuous Scanning

Automatically audit all resources against your policies. New resources are checked as soon as they're discovered.

Governance at Scale

Track compliance across all accounts. Generate reports, monitor trends, and hold teams accountable for tagging standards.

Service Quotas

Monitor AWS service limits across all accounts. Get alerts before you hit quotas and prevent outages.

Quotas Monitored
152

Across 4 accounts, 6 regions

At-Risk Alerts
10

3 critical, 7 warning

Accounts Covered
4

All accounts healthy visibility

Quota Usage Overview

Services approaching their limits

EC2 Instances95%
VPCs per Region80%
Lambda Concurrent75%
EBS Volume Storage (TiB)84%
S3 Buckets52%
Alerts trigger at 80% (warning) and 90% (critical)

Example Quota Alerts

CRITICALEC2us-east-1

Running On-Demand Standard Instances

Production Account
Usage: 95 / 10095%

Request a limit increase immediately. Current usage is at 95% — auto-scaling events or new deployments will fail.

CRITICALVPCus-east-1

VPCs per Region

Production Account
Usage: 4 / 580%

Only 1 VPC remaining. New environment or service deployments will be blocked. Request increase to 10.

WARNINGLambdaus-east-1

Concurrent Executions

Development Account
Usage: 750 / 100075%

Usage trending upward. At current growth rate, you'll hit the limit in ~2 weeks. Request increase proactively.

Multi-Account Monitoring

Track quotas across all AWS accounts and regions. One dashboard for your entire organization's service limits.

Proactive Alerts

Get notified before you hit limits. Configurable warning and critical thresholds with Slack and email notifications.

Usage Trends

Track quota usage over time. Predict when you'll hit limits and plan capacity increases ahead of demand.

Traffic Analysis

See traffic flows between resources. Track data transfer. Identify bottlenecks and find cost savings.

ALB
us-east-1a
18.7 GB
API Server
us-east-1a
Active
API Server
us-east-1a
43.2 GB
PostgreSQL
us-east-1a
Active
API Server
us-east-1a
8.4 GB
Redis
us-east-1c
$84/mo
Cost Optimization: Move Redis to us-east-1a to eliminate inter-AZ transfer costs
Unknown IP
unknown
2.1 GB
PostgreSQL
us-east-1a
Blocked
Security: Blocked by security group
Powered by VPC Flow Logs • Last 24 hours

Infrastructure Visualization

Click on any resource to see details, connections, and cost optimization recommendations

Loading diagram...
520 GB
Total Egress
200 GB
Total Ingress
$84/mo
Potential Savings
342
Blocked Connections

Query Builder

Query your flow logs with a powerful visual interface. No SQL required. Filter, aggregate, and export results in seconds.

Flow Log Query Builder
Last 24h
action = REJECT
Last 24 hours
dstport = 22
Query completed in 1.2s
srcaddrdstaddrsrcportdstportbytesaction
10.0.2.4510.0.3.1254321543243,200,000ACCEPT
10.0.1.4510.0.2.45443808018,700,000ACCEPT
203.0.113.4210.0.1.4512345221,200REJECT
Showing 3 of 342 results • Powered by AWS Athena

Visual Filters

Build complex queries visually. Filter by IP, port, protocol, action, and time range without writing SQL.

Fast Results

Queries run on AWS Athena for blazing fast results. Search through billions of flow log records in seconds.

Export & Share

Export results to CSV for further analysis. Save queries to reuse later or share with your team.

Completely Free

Every feature. No credit card. No time limit.

100% Free

Every feature. No credit card required. No time limits. No hidden charges. CloudWrangler is completely free to use.

Built by AWS Experts

Created by engineers who've built their careers on AWS. We know the pain points because we've lived them. Real-world experience meets practical solutions.

Your Data Stays Yours

We never sell, share, or monetize your infrastructure data. Read-only access means we only analyze metadata—never your application data. Your privacy is sacred.

Support Us (Optional)

Love what we're building? Buy us a coffee or become a sponsor. Your support helps us keep improving CloudWrangler for everyone.

Support development (completely optional)

Get Started

Ready to Cut Cloud Waste?

Connect your AWS account and start discovering cost savings, visualizing network topology, and analyzing traffic—all in under 5 minutes. Free. No credit card required.

Get Started