Cloud Posture and Runtime Security data sources

These data sources are included with Cloud Posture Security, Cloud Runtime Security, or Cortex XSIAM Premium license.

Cloud Posture Management and Cloud Runtime Security have their own data sources that you can use to gain complete visibility and real-time control over security risks to your cloud data. These sources utilize cloud-native APIs to discover, contextualize, monitor, and protect assets across multi-cloud environments, as well as specialized services like Snowflake and Microsoft 365.

Relevant Cloud Posture and Runtime data source types:

  • Container Registry connectors: A Runtime data source category that integrates with supported container registries like Amazon ECR, Docker Hub, and JFrog to automatically scan container images for vulnerabilities and other security risks.
  • Posture management connectors: Provides specialized onboarding to identify misconfigurations in SaaS and data platforms like Snowflake and Microsoft 365 (Posture).
  • Discovery engine: Performs regular scans and uses Event Assisted Ingestion (EAI) to track near-real-time changes to cloud assets and VMs.
  • Serverless function security: Provides agentless scanning for vulnerabilities in serverless code and pipelines for AWS Lambda, GCP, and Azure functions.
  • Cloud data security (DSPM): Discovers and classifies sensitive data across managed storage, such as S3 and Cloud SQL, and self-managed databases.

The following Cloud Posture and Runtime Security data sources and connectors are supported: