Agentless workload vulnerability scanning
Systems and methods for agentless workload vulnerability scanning include creating a snapshot of a workload in a cloud environment and analyzing workload data from the snapshot to identify one or more characteristics of the workload. The characteristics can be used to identify vulnerabilities present in the workload by correlation. These identified vulnerabilities can be persisted in a database and displayed to users for alerting and remediation.
1 . A method comprising steps of:
creating a snapshot of a workload in a cloud environment, wherein the snapshot includes data within a root disk of the workload, files making up the workload, and posture control data of the workload at a specific point in time;
analyzing workload data from the snapshot to identify one or more characteristics of the workload;
identifying vulnerabilities present in the workload by correlating the one or more characteristics of the workload; and
persisting the identified vulnerabilities in a database.
2 . The method of claim 1 , wherein the workload is a virtual machine instance, and wherein the steps are performed without an agent installed on the workload.
3 . The method of claim 2 , wherein the virtual machine instance is associated with one of a plurality of Cloud Service Providers (CSPs), and wherein the snapshot is performed by a snapshot manager executing outside of an environment of the CSP.
4 . The method of claim 1 , wherein the identified vulnerabilities are persisted in the database on a per-workload basis.
5 . The method of claim 1 , wherein prior to the creating, the steps include configuring one or more discovery modules.
6 . The method of claim 1 , wherein the one or more characteristics include any of an Operating System (OS) of the workload and packages present in the workload.
7 . The method of claim 1 , wherein the steps are performed in response to a user initiated trigger or based on an automated schedule.
8 . The method of claim 1 , wherein the steps further include providing a Graphical User Interface (GUI) for displaying the identified vulnerabilities.
9 . The method of claim 8 , wherein the GUI includes actionable steps describing how to remediate the identified vulnerabilities.
10 . The method of claim 8 , wherein the GUI includes a risk level associated with each identified vulnerability.
11 . A non-transitory computer-readable medium comprising instructions that, when executed, cause one or more processors to perform steps of:
creating a snapshot of a workload in a cloud environment, wherein the snapshot includes data within a root disk of the workload, files making up the workload, posture control data of the workload at a specific point in time;
analyzing workload data from the snapshot to identify one or more characteristics of the workload;
identifying vulnerabilities present in the workload by correlating the one or more characteristics of the workload; and
persisting the identified vulnerabilities in a database.
12 . The non-transitory computer-readable medium of claim 11 , wherein the workload is a virtual machine instance, and wherein the steps are performed without an agent installed on the workload.
13 . The non-transitory computer-readable medium of claim 12 , wherein the virtual machine instance is associated with one of a plurality of Cloud Service Providers (CSPs), and wherein the snapshot is performed by a snapshot manager executing outside of an environment of the CSP.
14 . The non-transitory computer-readable medium of claim 11 , wherein the identified vulnerabilities are persisted in the database on a per-workload basis.
15 . The non-transitory computer-readable medium of claim 11 , wherein prior to the creating, the steps include configuring one or more discovery modules.
16 . The non-transitory computer-readable medium of claim 11 , wherein the one or more characteristics include any of an Operating System (OS) of the workload and packages present in the workload.
17 . The non-transitory computer-readable medium of claim 11 , wherein the steps are performed in response to a user initiated trigger or based on an automated schedule.
18 . The non-transitory computer-readable medium of claim 11 , wherein the steps further include providing a Graphical User Interface (GUI) for displaying the identified vulnerabilities.
19 . The non-transitory computer-readable medium of claim 18 , wherein the GUI includes actionable steps describing how to remediate the identified vulnerabilities.
20 . The non-transitory computer-readable medium of claim 18 , wherein the GUI includes a risk level associated with each identified vulnerability.