Cloud cost audits turn up the same findings in a fairly predictable order. Here is that order, ranked by how much is typically recovered.
Idle non-production environments come first, almost every time. Staging running around the clock at production size is the single most common line item, and moving it to a schedule recovers more than any reserved-instance strategy.
Second: over-provisioned compute — instances sized for a load test that ran once and was never revisited. Third: unattached storage and orphaned snapshots, which accumulate quietly and rarely appear on anyone's dashboard.
Then inter-zone data transfer, forgotten managed services, and finally commitment coverage — which is where most teams start, and where the least money usually is.
None of this needs a tool you do not already have. It needs someone whose job it is to look.