Cloud-Native Sources
Cloud providers ship their own vulnerability and security services (e.g., AWS Inspector, Azure Defender for Cloud, GCP Security Command Center). Cloudaware ingests these findings and maps them to CMDB assets for unified reporting and routing.
Supported Patterns
Typical cloud‑native integrations include:
- AWS
- Amazon Inspector for EC2 and container images.
- ECR image scanning.
- Security Hub or other aggregated findings where applicable.
- Microsoft Azure
- Defender for Cloud (VMs, containers, App Services, SQL, etc.).
- Container Registry image scanning.
- Google Cloud
- Security Command Center (SCC) and container/image findings.
Cloudaware normalizes these findings into Cloudaware Vulnerability Scan records and links them to:
- EC2/Azure VM/GCE Instance CIs.
- Container/Image CIs.
- Cloud account/subscription CIs.
Configuration Steps
- Connect cloud accounts.
- Onboard AWS, Azure, and Google accounts into Cloudaware CMDB.
- Verify that inventory and configuration data are flowing correctly.
- Enable provider scanners.
- Turn on AWS Inspector, Azure Defender for Cloud, or GCP SCC in the relevant accounts.
- Configure required roles and permissions for Cloudaware to read findings.
- Review mappings.
- Confirm that instance IDs, resource IDs, and image digests match CMDB records.
- Use Cloudaware mapping rules to align findings with applications, OUs, and environments.
Usage and Best Practices
- Treat cloud‑native scanners as a baseline for coverage; complement with agent‑based or VSaaS scans where you need deeper OS‑level checks.
- Use Cloudaware dashboards to compare coverage between cloud‑native and other sources.
- Combine provider severities with business impact and exploitability via your risk model. See Risk Models.
For host and container‑centric scanning approaches, see: