Cloud Scanners
Cloud scanners connect to cloud provider APIs to discover certificates, keys, and credentials managed by cloud services.
AWS Cloud Scanner
Section titled “AWS Cloud Scanner”Type: cloud-aws
Category: Cloud
Access Mode: API
Produces: certificate, public-key, symmetric-key
Connects to AWS APIs to discover certificates in ACM, keys in KMS, and credentials in IAM.
What It Discovers
Section titled “What It Discovers”| Service | Assets Found |
|---|---|
| ACM | Certificates (public and private), including chain, expiry, and renewal status |
| KMS | Symmetric and asymmetric KMS keys with key policies and rotation status |
| IAM | Access keys, signing certificates associated with IAM users |
Configuration
Section titled “Configuration”region: us-east-1services: - acm - kms - iamaccessKeyId: AKIAIOSFODNN7EXAMPLEsecretAccessKey: wJalrXUtnFEMI/K7MDENG/bPxRfiCYEXAMPLEKEYConfig Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
region | string | Yes | — | AWS region (e.g., us-east-1, eu-west-1) |
services | string list | Yes | — | Services to scan: acm, kms, iam |
accessKeyId | string | No | — | AWS access key ID |
secretAccessKey | string | No | — | AWS secret access key |
If accessKeyId and secretAccessKey are omitted, the scanner uses the default AWS credential chain (environment variables, instance profile, shared config file).
Multi-Region Scanning
Section titled “Multi-Region Scanning”Create multiple scanner configs to scan across regions:
# Config 1region: us-east-1services: [acm, kms]
# Config 2region: eu-west-1services: [acm, kms]Azure Key Vault Scanner
Section titled “Azure Key Vault Scanner”Type: cloud-azure
Category: Cloud
Access Mode: API
Produces: certificate, public-key, symmetric-key
Connects to Azure Key Vault to discover certificates and keys stored in vaults.
What It Discovers
Section titled “What It Discovers”- Certificates stored in Key Vault (X.509 details, expiry, issuer)
- Cryptographic keys (RSA, EC) with key properties and operations
- Key versions and rotation status
Configuration
Section titled “Configuration”vaultUrl: https://my-vault.vault.azure.nettenantId: 72f988bf-86f1-41af-91ab-2d7cd011db47clientId: app-client-idclientSecret: app-client-secretcertificates: truekeys: trueConfig Fields
Section titled “Config Fields”| Field | Type | Required | Default | Description |
|---|---|---|---|---|
vaultUrl | string | Yes | — | Azure Key Vault URL |
tenantId | string | No | — | Azure AD tenant ID |
clientId | string | No | — | Service principal client ID |
clientSecret | string | No | — | Service principal secret |
certificates | boolean | No | true | Scan certificates in vault |
keys | boolean | No | true | Scan keys in vault |
If tenantId, clientId, and clientSecret are omitted, the scanner uses Azure’s DefaultAzureCredential (managed identity, environment variables, etc.).
Multi-Vault Scanning
Section titled “Multi-Vault Scanning”Create multiple configs for different vaults:
# Config 1vaultUrl: https://prod-vault.vault.azure.net
# Config 2vaultUrl: https://dev-vault.vault.azure.net- Least privilege — Create a dedicated IAM role or service principal with read-only access to the crypto services
- Credential management — Prefer instance profiles / managed identities over explicit credentials in config
- Scan frequency —
dailyis usually sufficient for cloud services since key rotation is typically planned
Related
Section titled “Related”- Network Scanners — Scan cloud-hosted TLS endpoints
- Filesystem Scanners — Scan EC2/VM filesystems