Skip to main content

Cloudaware Vulnerability Scanning (VSaaS)

Cloudaware Vulnerability Scanning is a managed vulnerability scanning service that consolidates cloud‑native signals (e.g., AWS Inspector), agent/host scans, IP/URL scans, and container image scans into Cloudaware CMDB for unified risk reporting, routing, and remediation.

Supported Scan Types

Cloudaware VSaaS supports multiple scan types and vendor backends, with results normalized to CMDB:

  • Agent‑based vulnerability scans (default)
    • Standard
    • PCI DSS (Windows, Red Hat only)
  • IP‑based network scans (optional)
    • Standard (unauthenticated)
    • Credentialed
    • PCI DSS (Windows, Red Hat only)
  • URL scanning
    • OWASP Top 10 coverage for web endpoints
  • Container image scanning
  • Compliance benchmarks
    • CIS Level 1/2, DISA
  • Other
    • Patch audit, malware detection, host discovery, vulnerability‑specific checks, content analysis (e.g., PII/PHI)

Scan Coverage and Cadence

  • Frequency: all assets assessed at least every 7 days; results roll into CMDB KPIs (coverage, age, severities)
  • On‑demand scans: can be enabled via a Scan Request action for ad‑hoc assessments
  • Health & self‑healing: if a scanning agent is uninstalled or impaired, Breeze can repair or reinstall as needed

Findings and coverage are mapped to CMDB objects and asset records for reporting and automation.

  • Asset fields: Last Scan Date, counts of Critical/High/Medium/Low vulnerabilities per CI
  • Vulnerability objects: Cloudaware Vulnerability Scan, Cloudaware Vulnerability Scan CVE, Docker Runtime Vulnerability, and related objects
  • Cloud‑native signals: AWS Inspector EC2 vulnerability data is ingested and visible on EC2 CIs
  • Tenable Security Center: vulnerabilities map to AWS/Azure network interfaces and Physical Servers for focused remediation

See also: Findings & Data Model.

Requirements

Before configuring scans, make sure the following requirements are met:

  • Agent-based scans: Install Breeze Agent on Windows and Linux endpoints. Breeze enables accurate inventory and supports agent lifecycle management and repair.
  • IP and URL scans: Mark eligible IPs and URLs for scanning in the CMDB, and ensure they are reachable by the scanner.
  • Permissions and network access: Allow outbound connections required by the scanner engines. For private endpoints, use TunHub where applicable.
  • Integrations (optional): Connect third-party scanners to enrich coverage, such as Qualys, Rapid7 InsightVM, and Tenable Security Center.

High-level Setup Flow

  1. Scope and prerequisites.
    • Confirm target assets and networks, scanning windows, and any PCI requirements
    • Ensure Breeze Agent coverage for host‑based scanning
  2. Enable sources.
  3. Configure Cloudaware VSaaS.
    • Define scan types (agent/IP/URL/container) and desired cadences
    • For IP/URL scans, tag/mark targets in CMDB; confirm credentials for credentialed scans
    • Request on‑demand scanning capability if needed (Scan Request button)
  4. Verify ingestion.

Operations

  • Ticketing and incident routing: integrate ITSM/collaboration tools (ServiceNow, Jira, PagerDuty, etc.) and use stateful ticketing to auto‑update when findings are remediated.
  • Prioritization: combine CVSS, exploitability, and business impact from CMDB (ownership, criticality) to focus work. For more details, see Prioritization.
  • Remediation: coordinate with Patch Management and change processes.
  • vCenter at scale: Breeze Agent supports mapping vCenter VMs to agent IDs via BIOS UUID for large‑scale scans.

Notes

  • Cloudaware can assist with obtaining required scanning permissions from cloud and network providers
  • Pricing and licensing vary by scope and vendor backends. Contact Cloudaware Support for details