Last Updated: 2024-10-09
Purpose
This article describes how to set up a Cloud discovery scan.
Introduction
Cloud Discovery enables you to inventory cloud infrastructure—such as AWS instances—without relying on network-based scanning. Instead, it uses provided credentials to call cloud REST APIs and enumerate assets directly from the cloud provider’s system. This method avoids network impact, detects resources beyond perimeter reach, and ensures accurate discovery of dynamic environments.
A Cloud Discovery scan counts the instances in (AWS currently) cloud environments without using network traffic but with provided AWS credentials and querying the AWS REST APIs.
Setting up a Cloud Discovery Scan
Run the Cloud Discovery Scan
To configure a Cloud discovery scan:
-
Navigate to Configurations > Scan Configurations in the Main Menu.
-
Click on the
icon in the right bottom corner. -
Select Cloud discovery.
-
Select Credentials from the drop-down menu.
-
Select Regions.
-
Choose a scanner.
-
Click the blue ADD button to save the configuration.
-
Select the Scan configuration and click on the scan now
icon in the blue toolbar at the bottom right to run a Cloud discovery scan. -
View the scan status under Scans in the Main Menu.
-
View the discovered assets, Docker images under Assets > Assets as the list of assets with the filter 'source' set to Cloudsec and the type set to Docker Image.
Related Articles
- Docker Image Assessment
- How to Scan AWS ECR Images
- Generate Azure Credentials
- Container Inspection - Azure
- Import Cloud Image on AWS
- Google Cloud Platform Credentials
- Microsoft Azure Credentials
- Azure Cloud Discovery
- Docker Credentials
- Amazon
- Cloud Discovery
- Scan a Docker Image
- Configure Application Gateway for HIAB on Azure
- Amazon Web Services Credentials
- Change Hard Drive Size on HIAB in Amazon Web Services
- Change Instance Type on HIAB on Amazon Web Services
- Cloud Discovery on HIAB
- Generate AWS Credentials
- Extend HIAB Disk Space on Azure
- AWS Scanning with OUTSCAN
- Cloud Assessment
- Generate GCP Credentials
- Google Registries Scanning with Container Inspection
- Deploy HIAB on Amazon Web Services
- Cloudsec Scan Configuration
- Docker Image Discovery
- Importing Tags for AWS Discovery
- Deploy HIAB on Microsoft Azure
- Vulnerabilities