Amazon Inspector — Automated security assessment service that scans applications for vulnerabilities.
Overview
Amazon Inspector automatically discovers software vulnerabilities in your EC2 instances, ECR container images, and Lambda functions.
Key Insight: Inspector is like an automated security auditor — it continuously scans your compute resources for known vulnerabilities (CVEs) and security best practice violations.
Core Inspector Concepts
| Concept | Description | Key Point |
|---|---|---|
| Assessment Target | What to scan (EC2 instances, ECR images, Lambda) | Define scope |
| Vulnerability | Known security issue (CVE) | Severity levels |
| Finding | Detected vulnerability | Contains details, severity, fix info |
| Scan | Inspection process | Can be continuous or one-time |
| Network Reachability | Identifies exposed network paths | Shows attack surface |
How Inspector Works
flowchart TD subgraph Inputs["Resources to Scan"] EC2["EC2 Instances"] ECR["ECR Images"] LAMBDA["Lambda Functions"] end DISC["Discovery and Scan Setup<br/>Agent-based or agentless"] CVE["CVE and Package Analysis"] NET["Network Reachability Analysis"] FIND["Generate Findings<br/>Severity + remediation guidance"] EC2 --> DISC ECR --> DISC LAMBDA --> DISC DISC --> CVE --> NET --> FIND FIND --> HUB["Security Hub<br/>(centralized findings)"] FIND --> PATCH["Patch and remediation workflow"] FIND --> CONSOLE["Inspector Console"]
Inspector Scanning Types
EC2 Instance Scanning
| Mode | Description |
|---|---|
| Agent-based | Installs SSM Agent on instances for deep scanning |
| Network Reachability | Identifies exposed network paths (no agent) |
ECR Container Scanning
| Trigger | Description |
|---|---|
| Push | Automatic scan on image push |
| On-Demand | Manual scan of specific image |
| Continuous | Rescans when new vulnerabilities discovered |
Lambda Function Scanning
Scans Lambda function code and dependencies for vulnerabilities.
Vulnerability Severity Levels
| Severity | Description | Action |
|---|---|---|
| Critical | Exploitable, remote code execution | Fix immediately |
| High | High risk, exploit available | Fix soon |
| Medium | Moderate risk | Plan fix |
| Low | Minor risk | Monitor |
| Informational | No risk, for awareness | Optional |
Key Features
| Feature | Description |
|---|---|
| Auto-Discovery | Automatically finds EC2 instances in account |
| Network Reachability | Maps potential attack paths |
| Continuous Scanning | Rescans when new CVEs published |
| Integration with Security Hub | Centralized findings management |
| ECR Integration | Scans container images automatically |
| Lambda Scanning | Scans serverless functions |
Use Cases
| Use Case | Description |
|---|---|
| Vulnerability Management | Find and fix CVEs before they’re exploited |
| Container Security | Scan ECR images before deployment |
| Compliance | Meet security standards (PCI DSS, CIS) |
| CI/CD Integration | Scan before promoting to production |
| Serverless Security | Scan Lambda functions |
Pricing
| Component | Price | Free Trial |
|---|---|---|
| EC2 Scanning | Per instance per month | 15-day free trial |
| ECR Scanning | Per GB scanned | 15-day free trial |
| Lambda Scanning | Per function | 15-day free trial |
⚠️ Important Note: Amazon Inspector Classic is being deprecated on May 20, 2026. Migrate to the new Inspector before this date.
⚠️ Pricing Disclaimer: AWS pricing is subject to change. Always verify current pricing at the official Inspector pricing page.
Inspector vs Other Security Tools
| Tool | Focus | Complementarity |
|---|---|---|
| Inspector | Vulnerability scanning | Finds CVEs in compute resources |
| GuardDuty | Threat detection | Detects active attacks/anomalies |
| Security Hub | Centralized findings | Aggregates Inspector + other findings |
| Config | Configuration compliance | Ensures resources meet standards |
TL;DR
- Amazon Inspector = Automated vulnerability scanning for compute resources
- Scans = EC2 instances, ECR container images, Lambda functions
- Finds = Known vulnerabilities (CVEs), network exposure
- Severity = Critical, High, Medium, Low, Informational
- Pricing = Per resource type; 15-day free trial
- Important = Inspector Classic ends May 20, 2026 — migrate to new Inspector
- Use Cases = Vulnerability management, container security, compliance
- Integrates with = Security Hub (centralized findings)
Resources
Amazon Inspector Documentation Complete Inspector user guide.
Inspector Pricing Detailed pricing breakdown.
Inspector Classic Migration Guide to migrate from Inspector Classic.