Amazon Inspector is a fully managed service that allows you to secure your instances and the applications that run on top of them by performing vulnerability assessments via an agent.
The assessments that are run are based upon rules packages that contain hundreds of different known security weaknesses, threats, and vulnerabilities that could exist within your EC2 instance. These rules packages are pulled from five different sources:
- The Center for Internet Security (CIS) Benchmarks, which is a list of global standards and best practices
- A publicly known reference of well-documented security threats and flaws found within the common vulnerabilities and exposures list, also known as the CVE
- General security best practices known across the industry, which helps you find deviations within your infrastructure
- Runtime behavior analysis, which is used to assess and monitor security weaknesses as your EC2 instance is running through...