Running EC2 instances that still accept IMDSv1 metadata requests
What does ZopNight detect here?
ZopNight flags a running EC2 instance whose metadata option `HttpTokens` is `optional` rather than `required`, meaning the instance still answers token-less IMDSv1 requests. IMDSv2 requires a session token obtained with a PUT request, which blocks a class of server-side request forgery attacks that steal instance role credentials. High severity, no saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-152 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | HttpTokens = optional |
| Source | ZopNight |
| Permissions used | ec2:DescribeInstances · cloudwatch:GetMetricStatistics |
Where it applies
What IMDSv1 leaves open
The instance metadata service hands out, among other things, temporary credentials for the instance’s IAM role. The IMDS guide describes two modes: IMDSv1, a plain request and response, and IMDSv2, a session-oriented method where the caller first obtains a token with a PUT request. By default an instance accepts both. AWS positions IMDSv2 as defence in depth against open firewalls, reverse proxies and SSRF vulnerabilities, where an attacker tricks an application into fetching a URL on their behalf. A simple GET is easy to smuggle through such a bug; the token handshake is not.
Finding instances that do not require tokens
aws ec2 describe-instances \ --filters Name=instance-state-name,Values=running Name=metadata-options.http-tokens,Values=optional \ --query 'Reservations[].Instances[].[InstanceId,InstanceType]' --output tableBefore enforcing, check whether anything on the instance still uses IMDSv1. The MetadataNoToken
CloudWatch metric counts those calls, and AWS says an instance is ready once it records zero:
aws cloudwatch get-metric-statistics --namespace AWS/EC2 --metric-name MetadataNoToken \ --dimensions Name=InstanceId,Value=i-0123456789abcdef0 \ --start-time 2026-09-11T00:00:00Z --end-time 2026-09-25T00:00:00Z \ --period 86400 --statistics SumThe condition checked
The instance must be running, and ZopNight must have read its metadata options and found that IMDSv2 is not required. That is the whole test: no threshold, no window.
Instances ZopNight does not flag
Stopped instances are skipped. If AWS did not return metadata options for an instance, ZopNight has nothing to judge and stays silent. A tag claiming IMDSv2 is enforced has no effect; only the setting AWS reports counts.
Risk exposure, no dollar figure
The finding reports $0. The cost of leaving it is the blast radius of the instance role: any credential stolen through the metadata service carries every permission that role has.
Enforcing IMDSv2
- Confirm
MetadataNoTokenis zero, or update scripts and SDKs that still make IMDSv1 calls. - Require tokens. AWS notes that setting
--http-tokensalso needs--http-endpoint enabled:aws ec2 modify-instance-metadata-options --instance-id i-0123456789abcdef0 --http-tokens required --http-endpoint enabled. - Test the application; any remaining IMDSv1 call now fails.
- Set IMDSv2 as required in launch templates and AMI defaults so new instances start compliant.