AWS Inspector integration
Check whether the vulnerabilities AWS Inspector finds in your ECR container images are exploitable.
Integration details
Primary category
Cloud Security
Sync direction
AWS Inspector → Konvu
Konvu reads active AWS Inspector findings and ECR scan results once a day through a read-only IAM role. Verdicts go out through Slack and the Konvu API.
Status
Available
Which AWS Inspector image findings can be exploited?
AWS Inspector scans the images in your ECR repositories and reports every vulnerable package it finds. Konvu reads those findings through a read-only IAM role, checks whether each vulnerability can be exploited in the image, and returns a verdict with evidence. Verdicts reach your team through Slack and the Konvu API.
AWS Inspector findings Konvu analyzes
Container
AWS Inspector enhanced scanning
Active findings for container images in Amazon ECR.
Container
ECR basic scanning
Scan findings from ECR repositories that use basic scanning.
Not imported today
- Images in registries outside ECR, such as Docker Hub, GCR, or Harbor
Access and setup
Konvu assumes an IAM role in your account with an external ID. Konvu generates the trust and permissions policy as JSON or Terraform, you create the role, and you paste its ARN. One connection covers one account and region, and Inspector must be enabled in that region for its findings to import.
To read findings
ecr:GetAuthorizationTokenecr:BatchCheckLayerAvailabilityecr:BatchGetImageecr:DescribeImagesecr:DescribeImageScanFindingsecr:DescribeRepositoriesecr:GetDownloadUrlForLayerecr:ListImagesinspector2:ListFindings, for Inspector findingsinspector2:ListCoverage, for Inspector findingsinspector2:BatchGetFindingDetails, for Inspector findings
To write back
No write access is needed.
How Konvu investigates AWS Inspector findings
What Konvu receives
The finding: the ECR image, the vulnerable package and version, and the CVE.
What Konvu checks
- Whether the vulnerable package or library is used by the software that runs in the image.
- The conditions the CVE needs, such as a proxy setting, a running service, or a specific configuration.
- Whether input an attacker controls can reach the vulnerable code.
What decides the verdict
Konvu returns exploitable or false positive, with the reasoning behind it: what runs in the image, the conditions it tested, and what settled the call. When the evidence does not settle it, the finding is left without a verdict rather than guessed.
Illustrative example
A curl finding from AWS Inspector
A made-up service, written to show how an investigation reads. Not a customer result.
- 1
Scanner finding
AWS Inspector reports CVE-2023-38545, a heap overflow in curl and libcurl before 8.4.0, in the ECR image of an internal Go service. The flaw is in SOCKS5 proxy handling.
- 2
Application context
The service is a statically linked Go binary. The only use of curl in the image is the health check, which calls http://localhost:8080/health.
- 3
Investigation
Konvu confirms the Go binary does not link libcurl. It then checks every curl call in the image definition: the health check uses no proxy, and no proxy environment variables are set, so the SOCKS5 code path never runs.
- 4
Verdict
False positive. curl is present, but nothing uses it through a SOCKS5 proxy.
- 5
Evidence
The libraries the binary links, the health check command, and the proxy settings Konvu checked.
- 6
Where it ends up
The verdict and evidence stay on the finding in Konvu. AWS is not changed, so if the team wants a suppression rule in Inspector, they create it there.
Writeback and controls
Where results go
- Exploitable findings can be posted to Slack, so the team hears about them without opening Konvu.
- Every verdict and its evidence can be pulled into your own tools through the Konvu API or CLI.
Who triggers it
Konvu imports findings on its daily schedule. What to do with a verdict is up to your team.
What stays with your team
- Suppression rules in AWS Inspector.
- Rebuilding and pushing a patched image. Konvu does not open fix pull requests for container findings.
The technical detail
More integrations
View allAWS Security Hub
Get exploitability verdicts for the AWS Inspector container findings in Security Hub, read directly from Inspector.
- Cloud Security
Wiz
Get an exploitability verdict for Wiz container image vulnerabilities, and optionally add it to the finding in Wiz as a note.
- Cloud Security
Check Point CloudGuard
Filter CloudGuard posture findings to focus on exploitable security gaps.
- Cloud Security
Datadog Cloud Security
Prioritize Datadog CSM findings with environment-specific exploitability analysis.
- Cloud Security
Google Cloud Security Command Center
Triage SCC findings with exploit data across GCP assets and vulnerabilities.
- Cloud Security
Lacework
Focus Lacework anomaly alerts on hosts with exploitable vulnerabilities.
- Cloud Security