Back to integrations
    Cloud Security

    AWS Inspector integration

    Check whether the vulnerabilities AWS Inspector finds in your ECR container images are exploitable.

    Integration details

    Primary category

    Cloud Security

    Sync direction

    AWS Inspector → Konvu

    Konvu reads active AWS Inspector findings and ECR scan results once a day through a read-only IAM role. Verdicts go out through Slack and the Konvu API.

    Status

    Available

    Which AWS Inspector image findings can be exploited?

    AWS Inspector scans the images in your ECR repositories and reports every vulnerable package it finds. Konvu reads those findings through a read-only IAM role, checks whether each vulnerability can be exploited in the image, and returns a verdict with evidence. Verdicts reach your team through Slack and the Konvu API.

    AWS Inspector findings Konvu analyzes

    Container

    AWS Inspector enhanced scanning

    Active findings for container images in Amazon ECR.

    Container

    ECR basic scanning

    Scan findings from ECR repositories that use basic scanning.

    Not imported today

    • Images in registries outside ECR, such as Docker Hub, GCR, or Harbor

    Access and setup

    Konvu assumes an IAM role in your account with an external ID. Konvu generates the trust and permissions policy as JSON or Terraform, you create the role, and you paste its ARN. One connection covers one account and region, and Inspector must be enabled in that region for its findings to import.

    To read findings

    • ecr:GetAuthorizationToken
    • ecr:BatchCheckLayerAvailability
    • ecr:BatchGetImage
    • ecr:DescribeImages
    • ecr:DescribeImageScanFindings
    • ecr:DescribeRepositories
    • ecr:GetDownloadUrlForLayer
    • ecr:ListImages
    • inspector2:ListFindings, for Inspector findings
    • inspector2:ListCoverage, for Inspector findings
    • inspector2:BatchGetFindingDetails, for Inspector findings

    To write back

    No write access is needed.

    How Konvu investigates AWS Inspector findings

    What Konvu receives

    The finding: the ECR image, the vulnerable package and version, and the CVE.

    What Konvu checks

    • Whether the vulnerable package or library is used by the software that runs in the image.
    • The conditions the CVE needs, such as a proxy setting, a running service, or a specific configuration.
    • Whether input an attacker controls can reach the vulnerable code.

    What decides the verdict

    Konvu returns exploitable or false positive, with the reasoning behind it: what runs in the image, the conditions it tested, and what settled the call. When the evidence does not settle it, the finding is left without a verdict rather than guessed.

    Illustrative example

    A curl finding from AWS Inspector

    A made-up service, written to show how an investigation reads. Not a customer result.

    1. 1

      Scanner finding

      AWS Inspector reports CVE-2023-38545, a heap overflow in curl and libcurl before 8.4.0, in the ECR image of an internal Go service. The flaw is in SOCKS5 proxy handling.

    2. 2

      Application context

      The service is a statically linked Go binary. The only use of curl in the image is the health check, which calls http://localhost:8080/health.

    3. 3

      Investigation

      Konvu confirms the Go binary does not link libcurl. It then checks every curl call in the image definition: the health check uses no proxy, and no proxy environment variables are set, so the SOCKS5 code path never runs.

    4. 4

      Verdict

      False positive. curl is present, but nothing uses it through a SOCKS5 proxy.

    5. 5

      Evidence

      The libraries the binary links, the health check command, and the proxy settings Konvu checked.

    6. 6

      Where it ends up

      The verdict and evidence stay on the finding in Konvu. AWS is not changed, so if the team wants a suppression rule in Inspector, they create it there.

    Writeback and controls

    Where results go

    • Exploitable findings can be posted to Slack, so the team hears about them without opening Konvu.
    • Every verdict and its evidence can be pulled into your own tools through the Konvu API or CLI.

    Who triggers it

    Konvu imports findings on its daily schedule. What to do with a verdict is up to your team.

    What stays with your team

    • Suppression rules in AWS Inspector.
    • Rebuilding and pushing a patched image. Konvu does not open fix pull requests for container findings.