.png)

What is AWS Inspector?
AWS Inspector is a fully managed, automated security assessment service that enables you to improve the security and compliance of your applications deployed on Amazon Elastic Compute Cloud (Amazon EC2) instances. It analyzes your EC2 instances and identifies potential security vulnerabilities, deviations from best practices, and exposure to common attack vectors. With AWS Inspector, you gain valuable insights to help you mitigate risks and build more secure applications.
Vulnerability Scanning
Vulnerability scanning is the process of identifying and analyzing potential security vulnerabilities in your infrastructure. AWS Inspector performs this task by running assessments against your EC2 instances, comparing them to an extensive library of known vulnerabilities, and generating detailed findings.
AWS Inspector's vulnerability scanning capabilities include:
Image Scanning
In addition to vulnerability scanning, AWS Inspector also offers image scanning capabilities. This feature allows you to scan your Amazon Machine Images (AMIs) and Amazon Elastic Container Registry (ECR) images for known vulnerabilities, providing an additional layer of security for your instances.
Key features of image scanning include:
ECR Scanning
Amazon Elastic Container Registry (ECR) is a fully-managed container registry that makes it easy to store, manage, and deploy container images. AWS Inspector integrates with ECR to scan your container images for vulnerabilities, allowing you to ensure the security of your containerized applications.
ECR scanning capabilities include:
To enable AWS Inspector and start using it for vulnerability assessments, follow these steps:
Sign in to the AWS Management Console using your AWS account credentials. If you don't have an account yet, create one and complete the sign-up process.
Navigate to the AWS Inspector console by searching for "Inspector" in the "Services" search bar or by visiting the following URL: https://console.aws.amazon.com/inspector/
For more in-depth assessments and better visibility into your instances, you can install the AWS Inspector Agent on your Amazon EC2 instances. The agent helps gather more information about the instances and provides better results in the assessment reports. Detailed instructions for installing the agent can be found in the official AWS documentation: https://docs.aws.amazon.com/inspector/latest/userguide/inspector_agents.html
AWS Inspector requires an IAM role with the necessary permissions to access your resources and perform security assessments. To create the role:
In the AWS Inspector console, click "Get Started" or "Create an assessment target" to define which instances should be assessed. Provide a name for the assessment target and select the instances you want to include in the assessment. You can select instances based on tags or manually pick them from the list.
An assessment template defines the rules packages and assessment duration. To create an assessment template:
To start the assessment, go to the "Assessment templates" tab in the AWS Inspector console, select the template you created in step 6, and click "Run." AWS Inspector will begin assessing your instances based on the rules packages and settings you defined.
The "side scanning" feature is a significant enhancement to AWS Inspector. It represents a new methodology in vulnerability scanning that offers several benefits:
Stream is the AI-native platform built to fight AI-enabled attacks. It autonomously prevents, detects, hunts, and remediates exposures and threats across production at machine speed - driving risk toward zero. It replaces the fragmented stack of scanners, runtime agents, exposure tools and playbooks with one live model of production.Defending Production needs a new approach: Stream is the only Autonomous Production Defense Platform that works across your entire production estate. It runs on a patented CloudTwin®, a high-fidelity security data harmonization layer that models Cloud, SaaS, identity, runtime, AI, network, perimeter, on-prem, security controls, and the behavior running on top of them into one live model of production: real-time, fully correlated, continuously updating. Not a snapshot. And it does not stop at boundaries - the boundaries that fragment every other tool are the same boundaries an attacker moves across. Inside CloudTwin they are one system.