Agent/Host-Based Scanners
Cloudaware can use both Cloudaware‑managed and third‑party scanners to assess OS‑level vulnerabilities on servers and endpoints. Findings are ingested into Cloudaware Vulnerability Scan objects and linked back to the corresponding CIs in CMDB.
Cloudaware‑Managed Scanning (VSaaS)
Cloudaware Vulnerability Scanning (VSaaS) provides:
- Agent‑based scans for Windows and Linux.
- Network scans for IP ranges (credentialed and non‑credentialed).
Cloudaware VSaaS relies on:
- Breeze Agent for inventory and, where applicable, scanner agent lifecycle management.
- CMDB flags that mark which hosts/IPs are in scope for scanning.
See Cloudaware Vulnerability Scanning for details.
Third‑Party Host Scanners
Cloudaware can also ingest findings from external platforms, for example:
- Qualys (Cloud Agent and network scans).
- Rapid7 InsightVM.
- Tenable (Nessus, Tenable.io, Tenable.sc).
- CrowdStrike, endpoint security tools, and other host‑centric sources.
- Orca Security.
Each integration:
- Maps scanner‑specific host identifiers (agent IDs, host IDs, IPs) to CMDB CIs.
- Normalizes severities, CVEs, and metadata into the Cloudaware Vulnerability Scan schema.
- Uses record types to distinguish the source; see Cloudaware Vulnerability Scan Record Types.
Host Identity and Ownership
Accurate mapping depends on:
- Stable identifiers such as instance IDs, BIOS UUIDs, or cloud provider resource IDs.
- Breeze Agent data (hostnames, IPs, OS details) to reconcile scanner assets with CMDB CIs.
- Ownership fields on CIs (application, OU, environment) so vulnerabilities inherit the right owner.
Best practices:
- Standardize host naming across environments.
- Ensure Breeze Agent is widely deployed on in‑scope hosts.
- Periodically review “unmatched” scanner assets and reconcile them with CMDB.
For containerized workloads and Kubernetes clusters, see Containers & Kubernetes.