Skip to main content
compliance · aws

Running EC2 instances that still accept IMDSv1 metadata requests

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags a running EC2 instance whose metadata option `HttpTokens` is `optional` rather than `required`, meaning the instance still answers token-less IMDSv1 requests. IMDSv2 requires a session token obtained with a PUT request, which blocks a class of server-side request forgery attacks that steal instance role credentials. High severity, no saving.

Signal and threshold

How ZopNight evaluates Running EC2 instances that still accept IMDSv1 metadata requests.
Field Value
Rule IDsRC-152
Categorycompliance
Severityhigh
Metricnone — pure configuration read
ThresholdHttpTokens = optional
SourceZopNight
Permissions usedec2:DescribeInstances · cloudwatch:GetMetricStatistics

What IMDSv1 leaves open

The instance metadata service hands out, among other things, temporary credentials for the instance’s IAM role. The IMDS guide describes two modes: IMDSv1, a plain request and response, and IMDSv2, a session-oriented method where the caller first obtains a token with a PUT request. By default an instance accepts both. AWS positions IMDSv2 as defence in depth against open firewalls, reverse proxies and SSRF vulnerabilities, where an attacker tricks an application into fetching a URL on their behalf. A simple GET is easy to smuggle through such a bug; the token handshake is not.

Finding instances that do not require tokens

Terminal window
aws ec2 describe-instances \
--filters Name=instance-state-name,Values=running Name=metadata-options.http-tokens,Values=optional \
--query 'Reservations[].Instances[].[InstanceId,InstanceType]' --output table

Before enforcing, check whether anything on the instance still uses IMDSv1. The MetadataNoToken CloudWatch metric counts those calls, and AWS says an instance is ready once it records zero:

Terminal window
aws cloudwatch get-metric-statistics --namespace AWS/EC2 --metric-name MetadataNoToken \
--dimensions Name=InstanceId,Value=i-0123456789abcdef0 \
--start-time 2026-09-11T00:00:00Z --end-time 2026-09-25T00:00:00Z \
--period 86400 --statistics Sum

The condition checked

The instance must be running, and ZopNight must have read its metadata options and found that IMDSv2 is not required. That is the whole test: no threshold, no window.

Instances ZopNight does not flag

Stopped instances are skipped. If AWS did not return metadata options for an instance, ZopNight has nothing to judge and stays silent. A tag claiming IMDSv2 is enforced has no effect; only the setting AWS reports counts.

Risk exposure, no dollar figure

The finding reports $0. The cost of leaving it is the blast radius of the instance role: any credential stolen through the metadata service carries every permission that role has.

Enforcing IMDSv2

  1. Confirm MetadataNoToken is zero, or update scripts and SDKs that still make IMDSv1 calls.
  2. Require tokens. AWS notes that setting --http-tokens also needs --http-endpoint enabled: aws ec2 modify-instance-metadata-options --instance-id i-0123456789abcdef0 --http-tokens required --http-endpoint enabled.
  3. Test the application; any remaining IMDSv1 call now fails.
  4. Set IMDSv2 as required in launch templates and AMI defaults so new instances start compliant.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·