Skip to main content10ETLabsRequest demo

Vulnerabilities

Cloud Vulnerability Management

CVE noise dies when you rank by blast radius, not by CVSS alone.

10ETLabs vulnerability views start from control-plane signals: ECR repositories without scan-on-push, and related posture. Package CVEs come from opt-in DeepScan, which scans VM disks agentlessly inside your own account (with EPSS and CISA KEV exploitability), or from the optional host sensor. What you get is prioritized gaps on the path to data.

Security operations screens showing network and host signals

Vulnerabilities

ECR scan-on-push gaps and DeepScan or host-sensor CVEs, ranked by blast radius.

See it work

Every cloud’s findings, one ranked queue

Findings from each provider share one shape, then 10ET Score orders them by exposure and blast radius.

Many clouds · one ranked queue

01Scan each cloud

Posture jobs list each connected provider’s control plane with its reader role or token — AWS deepest, then Azure, GCP, and Kubernetes.

Sample findings using real rule titles. Scores follow the 10ET Score formula.

What you get

Registry and image posture

ECR repositories with scan-on-push disabled are flagged. Image contents are not scanned agentlessly in this release.

Prioritized by 10ET Score

A registry gap on an internet-exposed cluster outranks a low finding on a private sandbox account.

Same ticket shape

Vuln rows are findings with remediation text. Analysts can resolve or suppress under RBAC.

Optional Prowler depth

If Prowler is on PATH and enabled, extra AWS checks merge into the same queue.

In this module

  1. Step 1

    Collect registry and compute metadata

    Inventory already knows which images and clusters exist.

  2. Step 2

    Emit control-plane vuln findings

    Rules fire when ECR scan-on-push is off; host-sensor CVEs merge into the same queue.

  3. Step 3

    Work the ranked list

    Open Vulnerabilities. Filter by cloud unit. Escalate only what reaches sensitive assets.

In this release

  • Control-plane vulnerability findings
  • 10ET Score ranking
  • Optional Prowler merge on AWS
Request a demo

On the roadmap

  • ACR and Artifact Registry posture
  • Container image contents

Labeled roadmap for this module only. Site-wide scope is on Trust and FAQ.

More of the platform

Other modules — not a reprint of this page.

AI security

AI workload security

Trace attack paths to models and agents on SageMaker, Bedrock, Azure AI Foundry and Vertex AI — exposed notebooks, public training data, model weights anyone can swap, retrieval sources fed from public buckets, and workload identities with admin rights.

Code security

Agentless code-to-cloud security

Check Terraform, CloudFormation, ARM, and Kubernetes YAML against built-in pattern rules — in the console or on every pull request — then see the same risk classes on live AWS, Azure, GCP, Kubernetes, and other VPS.

CSPM

Cloud Security Posture Management

Misconfiguration and identity-risk checks across AWS, Azure, GCP, Kubernetes, and other VPS — AWS-first, re-checked on every scan you run or schedule.

CWPP

Cloud Workload Protection

Inventory VMs, Lambda functions, and hosts from the control plane, and look inside VM disks with opt-in, agentless DeepScan.

CIEM

Cloud Identity & Access

AWS IAM, Azure Entra ID and GCP service accounts: missing MFA, standing admins, and effective Azure permissions that can reach sensitive data.

Containers

Container & Kubernetes Security

EKS, AKS, and any Kubernetes API you connect, ECR scan-on-push, and public services in one queue — agentless by default, with an optional sensor for runtime evidence and deploy-time blocking.

Compliance

Cloud Compliance Monitoring

CIS, SOC 2, PCI DSS, HIPAA, ISO 27001, NIST CSF, FedRAMP, GDPR, DPDP, an AI workload baseline, and your own frameworks — mapped to live findings, with signed evidence packs for auditors.