aws AWS What's New ·

Amazon Inspector improves agent-based EC2 scanning

securityawsgaengineerretailaws-ec2aws-iam
feature

Amazon Inspector has launched the Inspector VM Scanner for agent-based EC2 instances, expanding vulnerability detection for applications like WordPress and Python packages. This new scanner also reduces CPU utilization during scans, minimizing impact on production workloads. Security teams benefit from this enhanced, more efficient scanning which brings agent-based coverage to parity with agentless methods. The update is available in all Inspector regions at no additional cost.

  • Expanded vulnerability detection coverage on EC2 instances
  • Reduced CPU utilization during vulnerability scans
  • Parity between agent-based and agentless scanning
  • New scanner replaces previous engine with modern architecture
  • No additional IAM roles or SSM Agent changes required
Enhancements (3)
  • Expanded vulnerability detection coverage on EC2 instances

    Amazon Inspector now includes the Inspector VM Scanner, enhancing agent-based EC2 scanning to detect vulnerabilities in a broader range of software and applications. This includes previously unsupported items like WordPress, Apache HTTP Server, Python packages, and Ruby gems.

  • Reduced CPU utilization during vulnerability scans

    The new Inspector VM Scanner is optimized for performance, leading to reduced CPU utilization on EC2 instances during vulnerability scans. This minimizes the impact on production workloads.

  • Parity between agent-based and agentless scanning

    The expanded ecosystem detection provided by the Inspector VM Scanner brings agent-based scanning to parity with agentless scanning coverage. This ensures consistent vulnerability findings regardless of the scanning method used.

Notes (3)
  • New scanner replaces previous engine with modern architecture

    The Inspector VM Scanner replaces the previous scanning engine for agent-based EC2 with a modern architecture. Customers can opt in via the Amazon Inspector console or API.

  • No additional IAM roles or SSM Agent changes required

    Existing SSM Agent configurations continue to work with no changes needed, and no additional IAM instance profile roles are required on EC2 instances for the Inspector VM Scanner.

  • Availability and pricing of Inspector VM Scanner

    The Inspector VM Scanner for agent-based EC2 scanning is available in all AWS Regions where Amazon Inspector is available at no additional cost, with existing pricing applying. Delegated administrator accounts can enable it across their organization, while standalone accounts can enable it individually.

Read the original announcement →

https://aws.amazon.com/about-aws/whats-new/2026/05/amazon-inspector-ec2-agent-scanning-improvements

Related releases