diff --git a/content/en/security/cloud_security_management/setup/agentless_scanning/compatibility.md b/content/en/security/cloud_security_management/setup/agentless_scanning/compatibility.md index 7fff9d92393..7f2e8bf2656 100644 --- a/content/en/security/cloud_security_management/setup/agentless_scanning/compatibility.md +++ b/content/en/security/cloud_security_management/setup/agentless_scanning/compatibility.md @@ -10,19 +10,19 @@ Agentless Scanning is supported on AWS, Azure, and GCP. The following table provides a summary of Agentless Scanning technologies in relation to their corresponding components for each supported cloud provider: -| Component | AWS | Azure | GCP | -|-------------------------------------------------|----------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| -| Operating System | Linux; Windows Server 2016 or later; Windows 10 or later | Linux; Windows Server 2016 or later; Windows 10 or later | Linux; Windows Server 2016 or later; Windows 10 or later | -| Host File System | Btrfs, Ext2, Ext3, Ext4, xfs, NTFS | Btrfs, Ext2, Ext3, Ext4, xfs, NTFS | Btrfs, Ext2, Ext3, Ext4, xfs, NTFS | -| Package Manager | Deb (debian, ubuntu)
RPM (amazon-linux, fedora, redhat, centos)
APK (alpine) | Deb (debian, ubuntu)
RPM (fedora, redhat, centos)
APK (alpine) | Deb (debian, ubuntu)
RPM (fedora, redhat, centos)
APK (alpine) | -| Encryption | AWS
Unencrypted
Encrypted - Platform Managed Key (PMK) and Customer Managed Key (CMK) | Encrypted - Platform Managed Key (PMK): Azure Disk Storage Server-Side Encryption, Encryption at host
**Note**: Encrypted - Customer Managed Key (CMK) is **not** supported | Encrypted - Platform Managed Key (PMK): Persistent Disk Encryption, Confidential VM
**Note**: Encrypted - Customer Managed Encryption Key (CMEK) and Customer-Supplied Encryption Keys (CSEK) are **not** supported | -| Container runtime | Docker, containerd
**Note**: CRI-O is **not** supported | Docker, containerd
**Note**: CRI-O is **not** supported | Docker, containerd
**Note**: CRI-O is **not** supported | -| Serverless | AWS Lambda
AWS Fargate for ECS | Azure Container Apps and Azure Container Instances
**Note**: Requires the latest agentless scanner. See [Update Agentless Scanning][17]. | Cloud Run (container deployment only — not from GitHub repos or inline editors) | +| Component | AWS | Azure | GCP | +|-------------------------------------------------|-------------------------------------------------------------------------------------------------------------------------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| +| Operating System | Linux; Windows Server 2016 or later; Windows 10 or later | Linux; Windows Server 2016 or later; Windows 10 or later | Linux; Windows Server 2016 or later; Windows 10 or later | +| Host File System | Btrfs, Ext2, Ext3, Ext4, xfs, NTFS | Btrfs, Ext2, Ext3, Ext4, xfs, NTFS | Btrfs, Ext2, Ext3, Ext4, xfs, NTFS | +| Package Manager | Deb (debian, ubuntu)
RPM (amazon-linux, fedora, redhat, centos)
APK (alpine) | Deb (debian, ubuntu)
RPM (fedora, redhat, centos)
APK (alpine) | Deb (debian, ubuntu)
RPM (fedora, redhat, centos)
APK (alpine) | +| Encryption | AWS
Unencrypted
Encrypted - Platform Managed Key (PMK) and Customer Managed Key (CMK) | Encrypted - Platform Managed Key (PMK): Azure Disk Storage Server-Side Encryption, Encryption at host
**Note**: Encrypted - Customer Managed Key (CMK) is **not** supported | Encrypted - Platform Managed Key (PMK): Persistent Disk Encryption, Confidential VM
**Note**: Encrypted - Customer Managed Encryption Key (CMEK) and Customer-Supplied Encryption Keys (CSEK) are **not** supported | +| Container runtime | Docker, containerd
**Note**: CRI-O is **not** supported | Docker, containerd
**Note**: CRI-O is **not** supported | Docker, containerd
**Note**: CRI-O is **not** supported | +| Serverless | AWS Lambda
AWS Fargate for ECS | Azure Container Apps and Azure Container Instances
**Note**: Requires the latest agentless scanner. See [Update Agentless Scanning][17]. | Cloud Run (container deployment only — not from GitHub repos or inline editors) | | Kubernetes | EKS on EC2 nodes
EKS on Fargate
**Note**: EKS on Fargate requires the [Datadog Cluster Agent][18] to be installed | AKS on virtual machines and Virtual Machine Scale Sets (VMSS)
**Note**: AKS on ACI is **not** supported | GKE Standard only
**Note**: GKE Autopilot and image streaming are **not** supported | -| Application languages (in hosts and containers) | Java, .Net, Python, Node.js, Go, Ruby, Rust, PHP, Swift, Dart, Elixir, Conan, Conda | Java, .Net, Python, Node.js, Go, Ruby, Rust, PHP, Swift, Dart, Elixir, Conan, Conda | Java, .Net, Python, Node.js, Go, Ruby, Rust, PHP, Swift, Dart, Elixir, Conan, Conda | -| Container Registries | Amazon ECR (public and private): Scans running container images and the last 1,000 pushed images at rest | ACR: Scans running container images only
**Note:** To request at-rest registry scanning or to increase the number of at-rest images to scan, contact [Datadog Support][16] | Google Artifact Registry (Preview): Scans images from running workloads only
**Note:** Google Artifact Registry at rest scanning support is in Preview. To request access, contact [Datadog Support][16] | -| Host Images | AMI | Not supported | Not supported | -| Sensitive Data (SDS) | S3 | Not supported | Not supported | +| Application languages (in hosts and containers) | Java, .Net, Python, Node.js, Go, Ruby, Rust, PHP, Swift, Dart, Elixir, Conan, Conda | Java, .Net, Python, Node.js, Go, Ruby, Rust, PHP, Swift, Dart, Elixir, Conan, Conda | Java, .Net, Python, Node.js, Go, Ruby, Rust, PHP, Swift, Dart, Elixir, Conan, Conda | +| Container Registries | Amazon ECR (public and private): Scans running container images and the last 1,000 pushed images at rest | ACR: Scans running container images only
**Note:** To request at-rest registry scanning or to increase the number of at-rest images to scan, contact [Datadog Support][16] | Google Artifact Registry ([Preview][19]): Scans images from running workloads only | +| Host Images | AMI | Not supported | Not supported | +| Sensitive Data (SDS) | S3 | Not supported | Not supported | **Note**: AMIs must be stored in an account that uses Datadog's AWS integration. Otherwise, Datadog can't read the AMI's underlying Amazon Elastic Block Store (EBS) snapshot, so it can't scan or report on the AMI. @@ -66,11 +66,11 @@ The following application languages and libraries are supported for vulnerabilit The following container image registries are supported for container image scans: -| Registry | Support level | Notes | -|---------------------------------|---------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| -| Amazon ECR (public and private) | GA | Scans running container images **and** the last 1,000 pushed images at rest (by date). This is the only registry with at-rest scanning support
**Note:** To increase the number of at-rest images to scan, contact [Datadog Support][16] | -| Google Artifact Registry (GAR) | Preview | Scans images tied to running workloads (Cloud Run, GKE) only
**Note**: Google Artifact Registry at-rest scanning support is in Preview. To request access, contact [Datadog Support][16] | -| Azure Container Registry (ACR) | GA | Scans running container images from Azure Container Apps and Azure Container Instances only
**Note**: To request at-rest registry scanning, contact [Datadog Support][16] | +| Registry | Support level | Notes | +|---------------------------------|---------------|-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------| +| Amazon ECR (public and private) | GA | Scans running container images **and** the last 1,000 pushed images at rest (by date). This is the only registry with at-rest scanning support
**Note:** To increase the number of at-rest images to scan, contact [Datadog Support][16] | +| Google Artifact Registry (GAR) | Preview | Scans images tied to running workloads (Cloud Run, GKE) only
**Note**: Google Artifact Registry at-rest scanning support is in [Preview][19] | +| Azure Container Registry (ACR) | GA | Scans running container images from Azure Container Apps and Azure Container Instances only
**Note**: To request at-rest registry scanning, contact [Datadog Support][16] | **Note**: Container image scanning from registry is only supported if you have installed Agentless with: - CloudFormation Integrations >= v2.0.8 @@ -103,3 +103,4 @@ The following container runtimes are supported: [16]: /help [17]: /security/cloud_security_management/setup/agentless_scanning/update [18]: /containers/cluster_agent/setup/ +[19]: https://www.datadoghq.com/product-preview/google-artifact-registry-at-rest-scanning/ diff --git a/content/en/security/cloud_security_management/vulnerabilities/_index.md b/content/en/security/cloud_security_management/vulnerabilities/_index.md index f58e362b4e9..0a2cb73c516 100644 --- a/content/en/security/cloud_security_management/vulnerabilities/_index.md +++ b/content/en/security/cloud_security_management/vulnerabilities/_index.md @@ -81,14 +81,14 @@ Use these tables to decide which solution to start with: | Vulnerability prioritization | Yes | Yes, with runtime context | | Vulnerability scanning frequency | 12 hours | Real-time | -| Vulnerability detection scope | Agentless | Unified Datadog Agent | -|-------------------------------|-----------------------------------------------------------------------------------|--------------------------------| -| Host and host image | OS packages and app packages, mapped to image | OS packages | -| Container image | OS packages and app packages, mapped to image | OS packages | -| Cloud provider | AWS, Azure, GCP | AWS, Azure, GCP, on-prem, etc. | -| Operating system | Linux, Windows | Linux, Windows | -| Serverless | AWS Lambda, Amazon ECS Fargate, Azure Container Apps, Azure Container Instances, GCP Cloud Run (container deployment only) | Not applicable | -| Container registries | Amazon ECR (running + at-rest), Google Artifact Registry (running workloads only), Azure Container Registry (running container images only) | Not applicable | +| Vulnerability detection scope | Agentless | Unified Datadog Agent | +|-------------------------------|--------------------------------------------------------------------------------------------------------------------------------------------------------------|--------------------------------| +| Host and host image | OS packages and app packages, mapped to image | OS packages | +| Container image | OS packages and app packages, mapped to image | OS packages | +| Cloud provider | AWS, Azure, GCP | AWS, Azure, GCP, on-prem, etc. | +| Operating system | Linux, Windows | Linux, Windows | +| Serverless | AWS Lambda, Amazon ECS Fargate, Azure Container Apps, Azure Container Instances, GCP Cloud Run (container deployment only) | Not applicable | +| Container registries | Amazon ECR (running + at-rest), Google Artifact Registry (running workloads only; in [Preview][8]), Azure Container Registry (running container images only) | Not applicable | For more information on compatibility, see [Cloud Security Vulnerabilities Hosts and Containers Compatibility][13]. If you need any assistance, see the [troubleshooting guide][14], or reach out to support@datadoghq.com. @@ -143,6 +143,7 @@ Quickly assess the impact of a critical emerging vulnerability by searching for [5]: /security/code_security/software_composition_analysis/ [6]: https://www.datadoghq.com/product/infrastructure-monitoring/ [7]: https://app.datadoghq.com/container-images +[8]: https://www.datadoghq.com/product-preview/google-artifact-registry-at-rest-scanning/ [9]: https://www.cisa.gov/known-exploited-vulnerabilities-catalog [10]: /security/code_security/iast/ [11]: /security/cloud_security_management/setup/agentless_scanning/