Amazon Inspector features
Overview
Amazon Inspector is a vulnerability management service that continually scans AWS workloads and code repositories for software vulnerabilities and unintended network exposure. It’s available both as a standalone service and as a core capability within AWS Security Hub (Preview). Amazon Inspector provides essential vulnerability and exposure signals to prioritize your critical security issues and help you respond at scale. When using the enhanced Security Hub, Amazon Inspector findings are automatically correlated and enriched with critical context, allowing you to surface critical risks that may only become apparent when analyzed across the entire environment.
With a few steps in the AWS Management Console, you can use Amazon Inspector across all accounts in your organization. Once started, it automatically discovers Amazon Elastic Compute Cloud (EC2) instances, container images residing in Amazon Elastic Container Registry (ECR) and within continuous integration and continuous delivery (CI/CD) tools, code repositories, and AWS Lambda functions, at scale, and immediately starts assessing them for known vulnerabilities.
Amazon Inspector calculates a highly contextualized risk score for each finding by correlating common vulnerabilities and exposures (CVE) information with factors such as network access and exploitability. This score is used to prioritize the most critical vulnerabilities to improve remediation response efficiency. All findings are aggregated in the Amazon Inspector console and pushed to AWS Security Hub and Amazon EventBridge to automate workflows. Vulnerabilities found in container images are also sent to Amazon ECR for resource owners to view and remediate. Amazon Inspector empowers security teams and developers of any size to achieve comprehensive infrastructure workload security and compliance across their AWS environments.