AWS COST SCANNER

Find wasted spend in your AWS account.

Three ways to connect. All read-only. Nothing stored. Choose the one that fits your security posture.

Recommended for production. You create an IAM role in your account that trusts ours. We call sts:AssumeRole and get temporary credentials that expire in 15–60 minutes. Your secret keys never leave your account.

Step 1. In IAM → Policies → Create policy, paste this custom policy named ping192-readonly:

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Action": [
      "ec2:Describe*","rds:Describe*","s3:ListAllMyBuckets","s3:GetBucketLocation",
      "s3:GetBucketLifecycleConfiguration","lambda:ListFunctions","logs:DescribeLogGroups",
      "elasticloadbalancing:Describe*","elasticache:Describe*","redshift:Describe*",
      "dynamodb:ListTables","dynamodb:DescribeTable","eks:ListClusters","eks:DescribeCluster",
      "ecs:ListClusters","ecs:ListServices","ecs:DescribeServices","kinesis:ListStreams",
      "kinesis:DescribeStreamSummary","secretsmanager:ListSecrets","codebuild:ListProjects",
      "efs:DescribeFileSystems","states:ListStateMachines","es:ListDomainNames","es:DescribeDomains",
      "cloudwatch:GetMetricStatistics"
    ],
    "Resource": "*"
  }]
}

Step 2. IAM → Roles → Create role → Custom trust policy:

{
  "Version": "2012-10-17",
  "Statement": [{
    "Effect": "Allow",
    "Principal": { "AWS": "arn:aws:iam::YOUR_ACCOUNT:root" },
    "Action": "sts:AssumeRole",
    "Condition": { "StringEquals": { "sts:ExternalId": "ping192-xyz123" } }
  }]
}

Step 3. Name the role ping192-readonly, attach the policy above, copy the Role ARN. Then paste your own AWS credentials below (needed to call sts:AssumeRole):

Used only to call sts:AssumeRole, discarded after use. If you don't want to share even these, use the CUR upload path instead.

⚠ Use read-only IAM credentials — never your root account. Consider generating temporary session credentials with aws sts get-session-token instead of long-lived access keys.
  1. Open AWS Console → IAM → Users → Create user
  2. Name it ping192-readonly, do NOT enable console access
  3. Attach policy: ReadOnlyAccess (AWS managed)
  4. Create the user, open it, Security credentials → Create access key
  5. Choose "Other" as use case, copy both values, paste above
  6. After your scan, delete the access key in IAM

Even safer: after creating the key, run this in your terminal and paste the temporary values instead:

aws sts get-session-token --duration-seconds 3600

Paste the resulting AccessKeyId, SecretAccessKey, and SessionToken into the fields above. They expire in 1 hour.

Maximum safety — zero credentials. Upload a CSV of your AWS costs. We parse it locally and return findings. No keys, no API calls, no access to your account. Works with Cost Explorer exports and Cost & Usage Reports (CUR).
📄
Drop your CSV here, or tap to browse
Max 50 MB · CSV format · parsed locally, deleted immediately

Option 1 — Cost Explorer (fastest):

  1. AWS Console → Cost Explorer
  2. Date range → last 3 months
  3. Group by → Service (or Usage Type for deeper detail)
  4. Download CSV
  5. Upload the file above

Option 2 — Cost & Usage Report (deepest analysis):

  1. Billing → Cost & Usage Reports
  2. Create report → check "Include resource IDs"
  3. Time granularity → Monthly, format → CSV
  4. Wait for first delivery to S3 (up to 24 hours)
  5. Download the CSV from S3 and upload above
Account
—
Monthly waste
$0
Annual
$0
← Back to ping192.sbs