Status: CloudBurn Platform has not launched publicly yet. This page describes how it works. Join the waitlist for a 30% founding-member discount: only waitlist members get it, and they keep the lower price for as long as they keep their plan.
Unused Resources finds paid resources you can remove, stop, pause, or release because they no longer provide value: unattached EBS volumes, idle NAT gateways and load balancers, stopped instances that still pay for storage, and snapshots past their retention. It is one of four areas of a Cost Optimization scan, and the same scan refreshes all four. Open Unused Resources under Cost optimization, choose an AWS account, and run a scan or review its latest snapshot; Run a scan covers plans, readiness, and snapshot history.
What it checks
Unused Resources runs 31 checks. Inventory checks cover the connection's configured Region; the account-wide ones read CloudFront, Route 53, and Cost Optimization Hub.
| Check | Rule | Evidence scope |
|---|---|---|
| CloudFront Distribution Unused | CLDBRN-AWS-CLOUDFRONT-2 | Account-wide |
| CloudTrail Redundant Global Trails | CLDBRN-AWS-CLOUDTRAIL-1 | Configured Region |
| CloudTrail Redundant Regional Trails | CLDBRN-AWS-CLOUDTRAIL-2 | Configured Region |
| CloudWatch Log Group Inactive | CLDBRN-AWS-CLOUDWATCH-2 | Configured Region |
| AWS-Classified Idle Capacity | CLDBRN-AWS-COSTOPTIMIZATIONHUB-3 | Account-wide |
| DynamoDB Table Inactive | CLDBRN-AWS-DYNAMODB-1 | Configured Region |
| DynamoDB Table Unused | CLDBRN-AWS-DYNAMODB-3 | Configured Region |
| EBS Volume Unattached | CLDBRN-AWS-EBS-2 | Configured Region |
| EBS Volume Attached To Stopped Instances | CLDBRN-AWS-EBS-3 | Configured Region |
| EBS Snapshot Max Age Exceeded | CLDBRN-AWS-EBS-7 | Configured Region |
| Elastic IP Address Unassociated | CLDBRN-AWS-EC2-3 | Configured Region |
| VPC Interface Endpoint Inactive | CLDBRN-AWS-EC2-4 | Configured Region |
| NAT Gateway Idle | CLDBRN-AWS-EC2-11 | Configured Region |
| EC2 Instance Stopped | CLDBRN-AWS-EC2-13 | Configured Region |
| Transit Gateway VPC Attachment Idle | CLDBRN-AWS-EC2-14 | Configured Region |
| ElastiCache Cluster Idle | CLDBRN-AWS-ELASTICACHE-2 | Configured Region |
| Application Load Balancer Without Targets | CLDBRN-AWS-ELB-1 | Configured Region |
| Classic Load Balancer Without Instances | CLDBRN-AWS-ELB-2 | Configured Region |
| Gateway Load Balancer Without Targets | CLDBRN-AWS-ELB-3 | Configured Region |
| Network Load Balancer Without Targets | CLDBRN-AWS-ELB-4 | Configured Region |
| Load Balancer Idle | CLDBRN-AWS-ELB-5 | Configured Region |
| EMR Cluster Idle | CLDBRN-AWS-EMR-2 | Configured Region |
| KMS Key Without Recent Recorded Usage | CLDBRN-AWS-KMS-2 | Configured Region |
| RDS DB Instance Idle | CLDBRN-AWS-RDS-2 | Configured Region |
| RDS Snapshot Without Source DB Instance | CLDBRN-AWS-RDS-7 | Configured Region |
| RDS DB Instance Stopped | CLDBRN-AWS-RDS-9 | Configured Region |
| RDS Manual Snapshot Max Age Exceeded | CLDBRN-AWS-RDS-10 | Configured Region |
| Route 53 Health Check Unused | CLDBRN-AWS-ROUTE53-2 | Account-wide |
| SageMaker Notebook Instance Running | CLDBRN-AWS-SAGEMAKER-1 | Configured Region |
| SageMaker Endpoint Idle | CLDBRN-AWS-SAGEMAKER-2 | Configured Region |
| Secrets Manager Secret Unused | CLDBRN-AWS-SECRETSMANAGER-1 | Configured Region |
AWS-Classified Idle Capacity reads Cost Optimization Hub, which needs AWS Compute Optimizer for its idle recommendations. When either is not set up, that check reports missing evidence and the other 30 run as usual. See data sources.
Review the findings
The summary shows Findings, Checks, and the Snapshot outcome. Each finding row shows the resource, its Region, its severity, and an action to open it. Open a finding for its Financial evidence: the current cost of the resource and what removing it would save, when that evidence exists.
A finding's guidance is labelled Read-only: Removal guidance. Ten checks include an example AWS CLI command: unattached EBS volumes and old EBS snapshots, unassociated Elastic IPs, inactive VPC interface endpoints, idle NAT gateways, stopped EC2 instances, orphaned and old RDS snapshots, inactive CloudWatch log groups, and unused Secrets Manager secrets. Other findings ask you to review the evidence with the account owner. CloudBurn never runs these commands; check the resource's dependencies before you remove it.
Exports add a Recommended action column. See Export findings.
Run it yourself
Every check above is an open-source rule that runs in discovery mode, so you can run it against your own account with cloudburn discover. Platform runs the same rules through the role you deployed and keeps snapshot history for your workspace.
What's next
| Read this | To learn |
|---|---|
| Resource Efficiency | Improve the resources you keep |
| Cost Optimization | Compare areas on the Overview and read snapshot outcomes |
| Rules documentation | How each check decides and how to fix it |