Amazon Inspector

Amazon Inspector

Last updated on November 30, 2025

Amazon Inspector Cheat Sheet

  • Amazon Inspector is an automated vulnerability management service that continually scans AWS workloads for software vulnerabilities and unintended network exposure.

    • Legacy Note: This service replaces “Amazon Inspector Classic.” Inspector Classic required manual scheduling and custom agents; the new Inspector is continuous, automated, and integrated with AWS Organizations.

  • Tutorials dojo strip
  • Key Capabilities

    • Continuous Scanning: Automatically detects new resources and scans them immediately. It re-scans resources whenever changes occur (e.g., new software installed, new CVE released).

    • Multi-Resource Coverage: Scans Amazon EC2 instances, Amazon ECR container images, AWS Lambda functions, and Developer Code (CI/CD).

    • Centralized Management: Integrated with AWS Organizations, allowing a delegated administrator to manage findings for all member accounts.

    • Inspector automatically chooses the best available scan mode (agent or agentless).

Features

  • Inspector provides an engine that analyzes system and resource configuration and monitors activity to determine what an assessment target looks like, how it behaves, and its dependent components. The combination of this telemetry provides a complete picture of the assessment target and its potential security or compliance issues.
  • Inspector incorporates a built-in library of rules and reports. These include checks against best practices, common compliance standards and vulnerabilities.
  • Automate security vulnerability assessments throughout your development and deployment pipeline or against static production systems.
  • Inspector is an API-driven service that uses an optional agent, making it easy to deploy, manage, and automate.

Amazon Inspector

Concepts

  • Findings: Potential security issues detected during scans (exploitable vulnerabilities, network exposure, package risks, code issues).
  • Severity Levels:
    • Critical / High / Medium / Low — indicate risk impact on confidentiality, integrity, or availability.

    • Informational — highlights non-critical configuration details.

  • Network Exposure Analysis: Inspector determines whether EC2 instance ports are reachable from external sources (e.g., internet gateway, VPC peering, VPN). It highlights overly permissive security groups, ACLs, and other misconfigurations.
  • Resource Inventory: Inspector collects metadata such as installed packages, versions, Lambda layers, container base images, and software dependencies.

Scanning Engines

  • EC2 Scanning:

    • Agent-Based (SSM): Uses the AWS Systems Manager (SSM) Agent to inspect the software inventory of instances. No separate “Inspector Agent” is required.

    • Agentless (Hybrid): Scans EC2 instances without an agent by taking a snapshot of the EBS volume and analyzing it. Useful for unmanaged or “hardened” instances where agents cannot be installed.

  • ECR Scanning:

    • On-Push: Scans container images automatically when they are pushed to the registry.

    • Continuous: Continuously re-scans images when new vulnerabilities (CVEs) are added to the database.

  • Lambda Scanning:

    • Standard Scanning: Scans application dependencies (e.g., Python pip packages, Node.js npm modules) within the Lambda function and layers.

    • Code Scanning: Scans your custom application code for security vulnerabilities (e.g., injection flaws, data leaks, hardcoded secrets).

  • CIS Benchmarks:

    • Runs on-demand or scheduled assessments against Center for Internet Security (CIS) configuration benchmarks for operating systems (e.g., “CIS Amazon Linux 2 Benchmark Level 1”).

Assessment Reports

  • Inspector findings can be exported or viewed in the AWS Console or Security Hub.
  • Findings report includes:
    • Executive summary

    • Affected resources (EC2, Lambda, ECR, etc.)

    • Vulnerability details and CVE references

    • Recommended remediation steps

    • Package or code component involved

  • You can generate detailed exportable reports for audits or compliance reviews.

Amazon Inspector Pricing

  • Pricing depends on the resource type scanned.
Resource Type Feature Estimated Cost (US East 1)
EC2 Instances Agent-Based (SSM) ~$1.25 per instance/month
  Agentless ~$1.75 per instance/month
ECR Containers Initial Image Scan $0.09 per image pushed
  Continuous Rescan $0.01 per rescan
AWS Lambda Standard Scanning $0.30 per function/month
  Code Scanning +$0.60 per function/month (Total: $0.90)
Code Security CI/CD / Repository $0.15 per scan

Note: If you are studying for the AWS Certified Security Specialty exam, we highly recommend that you take our AWS Certified Security – Specialty Practice Exams and read our Security Specialty exam study guide.

AWS Certified Security - Specialty Exam Study Path

Amazon Inspector Cheat Sheet References:
https://docs.aws.amazon.com/inspector/latest/userguide
https://aws.amazon.com/inspector/pricing/
https://aws.amazon.com/inspector/faqs/

Tutorials Dojo portal

Learn AWS with our PlayCloud Hands-On Labs

🧑‍💻 50% OFF – CodeQuest Coding Labs

$2.99 AWS and Azure Exam Study Guide eBooks

tutorials dojo study guide eBook

New AWS Generative AI Developer Professional Course AIP-C01

AIP-C01 Exam Guide AIP-C01 examtopics AWS Certified Generative AI Developer Professional Exam Domains AIP-C01

Learn GCP By Doing! Try Our GCP PlayCloud

Learn Azure with our Azure PlayCloud

FREE AI and AWS Digital Courses

FREE AWS, Azure, GCP Practice Test Samplers

Subscribe to our YouTube Channel

Tutorials Dojo YouTube Channel

Follow Us On Linkedin

Written by: Jon Bonso

Jon Bonso is the co-founder of Tutorials Dojo, an EdTech startup and an AWS Digital Training Partner that provides high-quality educational materials in the cloud computing space. He graduated from Mapúa Institute of Technology in 2007 with a bachelor's degree in Information Technology. Jon holds 10 AWS Certifications and is also an active AWS Community Builder since 2020.

AWS, Azure, and GCP Certifications are consistently among the top-paying IT certifications in the world, considering that most companies have now shifted to the cloud. Earn over $150,000 per year with an AWS, Azure, or GCP certification!

Follow us on LinkedIn, YouTube, Facebook, or join our Slack study group. More importantly, answer as many practice exams as you can to help increase your chances of passing your certification exams on your first try!

View Our AWS, Azure, and GCP Exam Reviewers Check out our FREE courses

Our Community

~98%
passing rate
Around 95-98% of our students pass the AWS Certification exams after training with our courses.
200k+
students
Over 200k enrollees choose Tutorials Dojo in preparing for their AWS Certification exams.
~4.8
ratings
Our courses are highly rated by our enrollees from all over the world.

What our students say about us?