Container Registries

License type: This feature is included with a Cortex XSIAM Premium license. It is also included with any other Cortex XSIAM product that has the Cloud Posture Security or the Cloud Runtime Security add-on.

Overview

Container Registries

Container Registries are a category of Runtime Security data sources (also known as connectors) in Cortex XSIAM that enable integration with container image repositories across cloud and third-party environments. These data sources provide visibility into container images stored in registries and allow Runtime Security to assess the security posture of containerized applications.

Container Registry data sources support both managed cloud registries and third-party registry integrations, allowing you to monitor container images across various environments.

Container Registry Scanning

Container Registry Scanning is a Runtime Security capability enabled through Container Registry connectors. It automatically scans container images stored in connected registries to identify security risks, including:

  • Vulnerabilities in operating system packages and application dependencies
  • Malware within container images
  • Exposed secrets such as credentials, tokens, and certificates
  • Security policy violations and deviations from security best practices

After a registry is onboarded, scanning runs automatically at regular intervals, eliminating the need for manual image assessment and providing continuous visibility into container security risks.

Supported container registry integrations

After you onboard your container registries, Runtime Security ensures that all containers and images are scanned at regular intervals and that you are notified about any deviation from your security policies and best practices.