Skip to content
Notifications
Clear all

Am I the only one who thinks the vulnerability management is weak?

2 Posts
2 Users
0 Reactions
16 Views
(@harryj)
Reputable Member
Joined: 3 months ago
Posts: 381
Topic starter   [#19164]

Just set up CloudGuard Posture Management across our AWS accounts. The compliance and asset visibility are solid, but the vulnerability scanning for workloads feels like an afterthought compared to dedicated tools.

* It only scans **every 12 hours** by default? That's a lifetime in a fast-moving dev environment.
* Findings are too high-level. "Instance has a vulnerability" – okay, but on *which* package? In the OS or a container layer? I'm digging through CLI logs to get details.
* The ticketing integration (we use Jira) is clunky. Can't auto-create tickets for new critical CVEs without a ton of custom scripting.

Am I missing a configuration trick, or is this a known gap? For the price, I expected this piece to be stronger.

~hj


Automate the boring stuff.


   
Quote
(@emilyr)
Reputable Member
Joined: 3 months ago
Posts: 295
 

You're absolutely right about the scan frequency being insufficient for dynamic environments. The 12-hour default is a policy scan tied to the posture management engine, not a runtime scanner. It's checking your cloud config snapshot, not live packages. For workload-specific scanning, you'd need to integrate their CloudGuard Workload Protection agent, which offers continuous scanning on the host. That division of product lines is where the gap you're noticing originates.

Regarding the high-level findings, this is a common frustration. The posture management console aggregates data at the resource level (e.g., EC2 instance) for its primary compliance focus. The package details are usually in the raw scan data, accessible via their API. You can pull them with a query like this:

```
GET /api/v1/container-security/api/v1/images/{imageId}/vulnerabilities
```

But you're correct that this requires extra steps outside the main dashboard, which defeats the purpose of an integrated view. It's a known trade-off with their platform approach.

For Jira automation, the out-of-box integration is indeed limited to posture findings. Automated ticketing for new CVEs typically requires setting up an external orchestrator (like a small Lambda function) to poll their vulnerability feeds and use Jira's API. It adds operational overhead they should solve.



   
ReplyQuote