Vulnerabilities
Cloud Vulnerability Management
CVE noise dies when you rank by blast radius, not by CVSS alone.
10ETLabs vulnerability views start from control-plane signals: ECR repositories without scan-on-push, and related posture. Package CVEs come from opt-in DeepScan, which scans VM disks agentlessly inside your own account (with EPSS and CISA KEV exploitability), or from the optional host sensor. What you get is prioritized gaps on the path to data.

Vulnerabilities
ECR scan-on-push gaps and DeepScan or host-sensor CVEs, ranked by blast radius.
See it work
Every cloud’s findings, one ranked queue
Findings from each provider share one shape, then 10ET Score orders them by exposure and blast radius.
Many clouds · one ranked queue
01Scan each cloud
Posture jobs list each connected provider’s control plane with its reader role or token — AWS deepest, then Azure, GCP, and Kubernetes.
Sample findings using real rule titles. Scores follow the 10ET Score formula.
What you get
Registry and image posture
ECR repositories with scan-on-push disabled are flagged. Image contents are not scanned agentlessly in this release.
Prioritized by 10ET Score
A registry gap on an internet-exposed cluster outranks a low finding on a private sandbox account.
Same ticket shape
Vuln rows are findings with remediation text. Analysts can resolve or suppress under RBAC.
Optional Prowler depth
If Prowler is on PATH and enabled, extra AWS checks merge into the same queue.
In this module
Step 1
Collect registry and compute metadata
Inventory already knows which images and clusters exist.
Step 2
Emit control-plane vuln findings
Rules fire when ECR scan-on-push is off; host-sensor CVEs merge into the same queue.
Step 3
Work the ranked list
Open Vulnerabilities. Filter by cloud unit. Escalate only what reaches sensitive assets.
In this release
- Control-plane vulnerability findings
- 10ET Score ranking
- Optional Prowler merge on AWS
On the roadmap
- ACR and Artifact Registry posture
- Container image contents
Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.
More of the platform
Other modules — not a reprint of this page.
AI security
AI workload security
Trace attack paths to models and agents on SageMaker, Bedrock, Azure AI Foundry and Vertex AI — exposed notebooks, public training data, model weights anyone can swap, retrieval sources fed from public buckets, and workload identities with admin rights.
Code security
Agentless code-to-cloud security
Check Terraform, CloudFormation, ARM, and Kubernetes YAML against built-in pattern rules — in the console or on every pull request — then see the same risk classes on live AWS, Azure, GCP, Kubernetes, and other VPS.
CSPM
Cloud Security Posture Management
Misconfiguration and identity-risk checks across AWS, Azure, GCP, Kubernetes, and other VPS — AWS-first, re-checked on every scan you run or schedule.
CWPP
Cloud Workload Protection
Inventory VMs, Lambda functions, and hosts from the control plane, and look inside VM disks with opt-in, agentless DeepScan.
CIEM
Cloud Identity & Access
AWS IAM, Azure Entra ID and GCP service accounts: missing MFA, standing admins, and effective Azure permissions that can reach sensitive data.
Containers
Container & Kubernetes Security
EKS, AKS, and any Kubernetes API you connect, ECR scan-on-push, and public services in one queue — agentless by default, with an optional sensor for runtime evidence and deploy-time blocking.
Compliance
Cloud Compliance Monitoring
CIS, SOC 2, PCI DSS, HIPAA, ISO 27001, NIST CSF, FedRAMP, GDPR, DPDP, an AI workload baseline, and your own frameworks — mapped to live findings, with signed evidence packs for auditors.