- Newest
- Most votes
- Most comments
If you're using New AWS Inspector, Unfortunately, it's not possible to prevent scan of some EC2 instances as of now.
Amazon Inspector automatically discovers all supported EC2 instances and then scan it automatically. Please refer to below for more details.
https://docs.aws.amazon.com/inspector/latest/user/enable-disable-scanning-ec2.html
Remove SSM agent from the instances where you dont want the scan to happen and or remove SSM permissions from the instance IAM role. Without SSM agent installed or IAM permissions inspector will not be able to access.
if the instance doesn't meet Inspector prerequisites then it won't be scanned. The prerequisites is mainly being a managed instance in Systems Manager.
To exclude an EC2 instance from scans, tag that instance with the following key:
InspectorEc2Exclusion
AWS documentation here
Relevant content
- asked 2 years ago
- asked 11 days ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated 2 years ago
- AWS OFFICIALUpdated a year ago