Views:

Scan your AWS cloud resources for vulnerabilities to help prioritize and remediate issues and proactively identify zero-day exploits.

Agentless Vulnerability & Threat Detection scans your supported AWS cloud resources to identify security vulnerabilities. Scans occur daily from the time you first enable the feature for your AWS account. Scan times are not configurable.

Procedure

  1. Go to Cloud SecurityCloud AccountsAWS and click Add Account.
  2. Choose CloudFormation as the deployment method and select Single AWS Account.
  3. Click Next.
  4. Specify the general information for the account and click Next. For more details, see Adding an AWS account using CloudFormation.
    The Features and Permissions screen appears.
  5. In Features and Permissions, enable Agentless Vulnerability & Threat Detection and select the deployment regions.
    Note
    Note
    Selected regions are the regions where Agentless Vulnerability & Threat Detection is deployed, not necessarily the region of your AWS account. You may select multiple deployment regions.
  6. Click Scanner Configuration and enable vulnerability scanning.
  7. Select the AWS resource types you wish to include in vulnerability scans. All supported resource types are selected by default.
  8. Click Save Changes and continue configuring the CloudFormation template.
  9. For AWS accounts that you have already connected in Cloud Accounts:
    1. Select the AWS account.
    2. Go to the Stack Update tab.
    3. In Features and Permissions, enable Agentless Vulnerability & Threat Detection and follow the configuration steps.