I've had AWS support tell me exactly what processes are running on my instance. They do seem to have some visibility beyond metadata.

I'm an Amazon employee here - but my words don't represent the company.

Internally we also talk to AWS support. They absolutely don't have much visibility into our accounts at all - much to my frustrations. They only see metadata - even for internal accounts.

The only teams that have some access to such information is security team, or when you Grant access explicitly to the other person via standard AWS auth mechanism (IAM)

Seems vanishingly unlikely, unless you're using a service (SSM Inventory or similar) that would reflect what you have running/installed.

I'm at AWS and we have basically zero insight into these things.

