Skip to main content
compliance · aws

AWS accounts where Amazon Inspector vulnerability scanning is off

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

Amazon Inspector scans EC2 instances, ECR container images and Lambda functions for known vulnerabilities, and ZopNight flags an account and Region whose overall Inspector status, as returned by `BatchGetAccountStatus`, is anything other than `ENABLED`. Partial coverage, such as ECR scanning on but EC2 off, counts as enabled and is not flagged. The finding carries a $0 saving.

Signal and threshold

How ZopNight evaluates AWS accounts where Amazon Inspector vulnerability scanning is off.
Field Value
Rule IDsRC-1101
Categorycompliance
Severityhigh
Metricnone — pure configuration read
Thresholdaccount status not enabled
SourceZopNight
Permissions usedinspector2:BatchGetAccountStatus

What Amazon Inspector would be catching

Amazon Inspector discovers and scans EC2 instances, container images in Amazon ECR and Lambda functions, and raises a finding when it detects a software vulnerability or unintended network exposure. It is the managed answer to “which of my workloads are running a package with a published CVE?”

With Inspector off, that question has no automatic answer. Patching depends on someone noticing an advisory and mapping it to the right AMIs, images and function packages by hand, which rarely happens for workloads nobody is actively developing.

Reading Inspector account status yourself

The account status call reports both an overall state and one state per resource type:

Terminal window
aws inspector2 batch-get-account-status \
--query 'accounts[].[accountId,state.status]' --output table
aws inspector2 batch-get-account-status \
--query 'accounts[].resourceState'

Overall and per-type status values include ENABLED, DISABLED, SUSPENDED and the transitional ENABLING and DISABLING. Run it in each Region you use.

The account-level signal this rule reads

ZopNight records the overall Inspector state for the account in each Region it scans and raises a finding when that state is anything other than ENABLED, which includes DISABLED, SUSPENDED and the transitional states. It fires on the recorded flag alone; nothing about tags or naming affects it.

Coverage gaps this check cannot see

The rule reads only the overall status. An account can have Inspector running for ECR images while EC2 or Lambda scanning is turned off, and AWS reports that account as enabled overall, so ZopNight does not raise a finding. Use the resourceState query above to find those partial setups.

When the status cannot be read at all, for instance because the scanning role lacks Inspector permissions, no finding is produced rather than a guess.

What turning Inspector on costs

This is a security finding with no saving attached. Inspector charges per scanned resource, and all accounts new to Inspector get a 15-day free trial during which eligible EC2 instances, Lambda functions and ECR images are scanned at no cost. Use that window to see what the steady-state bill will be.

Switching scanning on for every resource type

  1. Enable Inspector with the scan types you need:
Terminal window
aws inspector2 enable --resource-types EC2 ECR LAMBDA LAMBDA_CODE
  1. Repeat per Region, or enable it across the organization from a delegated administrator account.
  2. Confirm with the resourceState query that each type reports ENABLED.
  3. Triage the initial findings by severity, then send new ones to your ticketing or chat tool through EventBridge.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·