What we detect

StaleSweep detects unused and idle resources across compute, storage, networking, databases, serverless, security, and cost categories.

CategoryExamples
ComputeStopped or idle EC2 instances, zero-capacity Auto Scaling groups, idle ECS/EKS/EMR clusters, unused AMIs and key pairs
StorageUnattached EBS volumes, orphaned/redundant snapshots, empty S3 buckets, incomplete multipart uploads, unused EFS
NetworkingUnassociated Elastic IPs, idle NAT gateways, unused security groups/ENIs/route tables, empty VPCs, stale peering, unattached transit gateways, idle VPN and Client VPN, unused VPC endpoints, Global Accelerators with no endpoints
Databases & cachesStopped/idle RDS, idle read replicas, stale manual snapshots, idle DynamoDB tables, idle Redshift, idle ElastiCache clusters, orphaned cache snapshots
Serverless & appIdle Lambda functions, idle API Gateway APIs, unused EventBridge rules, idle SQS queues and SNS topics, unused ECR repositories, idle CloudFront distributions
Security & governanceUnused IAM roles/users/access keys/policies, roles with no permissions, expired or unused ACM certificates, WAF ACLs with no resources or no rules, disabled KMS keys, unused secrets
ObservabilityLog groups with no retention or no recent events, orphaned CloudWatch alarms

Detectors are deliberately conservative: grace periods for freshly created resources, exclusions for things referenced by Launch Templates or permissions boundaries, dead-letter-queue awareness, and per-type lookback windows all minimize false positives. The full, always-current list with per-rule descriptions lives on your Rules page, where every detector can also be toggled on or off for your workspace.