Agentless Cloud CVE Scanning That Catches What's Still Running
Enterprise cloud environments fail in two ways: assets nobody knows about, and known vulnerabilities nobody prioritized. ArcScan is a cloud security SaaS that closes both gaps: agentless discovery builds a live inventory of your AWS and Azure estate, and continuous vulnerability management tells you which exposures actually matter and drives the fix through a governed pipeline.
See every cloud asset first
Connect an AWS account or Azure subscription. Credentials are encrypted at rest and only decrypted at scan time. ArcScan pulls your live inventory, covering more than 40 AWS resource types and 30 Azure security policies, into a typed asset graph. The resource topology view maps real relationships across 10 edge kinds: which role can reach which bucket, which load balancer fronts which instance. Crucially, east-west traffic observed on the hosts themselves is labeled separately from cloud control-plane routing read out of NSG rules, VNet peering, and Front Door configuration, so you can tell what actually talks to what from what is merely permitted to.
Network sweeps extend discovery to hosts, open ports, and service banners; a credentialed agentless probe over SSH, WinRM, SNMP, SMB, or IPMI adds the installed-package inventory that CVE matching runs against. AWS SSM inventory, syft-generated SBOMs, ECR container image scanning, and Terraform state ingestion feed the same graph. For segmented or air-gapped networks the optional Arc Probe agent (cosign-signed, mTLS, outbound only) reaches what agentless cannot. The vulnerability program starts from an inventory instead of a guess.
Vulnerability management with real prioritization
Every discovered package is matched against nine live advisory feeds: NVD, OSV, GHSA, RHSA, USN, DSA, Alpine, ALAS, and MSRC for Windows. CISA KEV status and EPSS scores are layered on top as enrichment, surfacing the CVEs attackers are actually using, and reachability analysis asks whether the vulnerable code is exposed in your environment at all. Blast-radius and attack-path context from your asset graph show what an exploited host can reach. Instead of a 4,000-row CSV of CVSS scores, your enterprise security team gets a ranked queue: exploited, reachable, and yours. Delta alerting tells you when a CVE you already carry flips to known-exploited overnight.
Two things keep that queue honest. Version matching is distro-scoped, so a Debian backport is not reported as an unpatched upstream release. And orphaned .dist-info and .egg-info directories left behind by a half-removed package are recorded as not installed and never matched, with a cleanup playbook available to delete them so your other scanners stop flagging them too.
Posture scanning aligned to CIS benchmarks
Deterministic policy checks run against your cloud inventory with no AI call required: open security groups and firewalls, publicly accessible databases, unencrypted storage, over-permissive IAM, stale users, and public IPs. Each finding includes severity, its CIS reference, and concrete remediation guidance. AWS identity and entitlement analysis (CIEM) runs over the collected IAM graph; Azure RBAC CIEM is not yet available. Data-store discovery classifies where sensitive data lives, with content sampling on AWS S3 today and exposure-only inventory elsewhere, marked as such rather than passed as clean. Drift detection against baselines and scheduled recurring scans keep posture continuous rather than point-in-time.
Fix it, prove it, integrate it
- Governed remediation: ArcScan generates the fix and its rollback, computes blast radius before anything runs, executes a check-mode dry run, lints for dangerous operations, then holds for policy and human approval inside your maintenance window. Approve and it applies via Ansible, or open a remediation PR or file a ticket instead. Every step is written to a hash-chained audit log.
- Patch scoping you actually control: exclude hosts or apps per run, or by standing rule at host, package-on-host, or path-prefix granularity, each tagged vendor managed, risk accepted, or false positive. Cannot upgrade at all? Pin with apt hold or dnf versionlock and ArcScan reports the package as pinned, not as fixed.
- Reliability you can audit: patch success rate, MTTR mean and median split by severity, rollback counts, and the proposed-to-applied funnel, computed from your own runs, plus a post-apply verification scan that confirms the CVE actually cleared.
- Patched-but-not-rebooted detection: Linux hosts running an older kernel than the one installed are flagged rather than passed, with an RBAC-gated reboot action to close the loop.
- ServiceNow integration: incidents, change requests, CMDB CI and dependency sync, and change-request gating that blocks automation until the CR is approved. Jira and FreshService supported as well.
- Artificial intelligence where it helps — AI-powered analysis of cloud findings and AI-generated remediation, with deterministic checks kept AI-free.
- Compliance evidence: 21 control packs including NIST 800-53, NIST 800-171, FedRAMP, CIS, HIPAA, PCI-DSS, SOC 2 and ISO 27001, with a crosswalk engine, HMAC-signed evidence bundles that verify offline, and a read-only external auditor portal.
- SIEM export: stream findings as ArcSight CEF, ingestible by Splunk, Sentinel, QRadar, ArcSight, and Chronicle. SARIF 2.1, CSV, and JSON exports are available on the same endpoints.
- SBOM and CBOM export: CycloneDX 1.5 and SPDX 2.3 from the discovered package inventory, plus CycloneDX 1.6 CBOM from Quantum Arc's post-quantum crypto discovery, with a CNSA 2.0 readiness report. Linux agents today.
Enterprise SaaS, federal-ready
ArcScan runs as a multi-tenant SaaS with four organization roles and five functional roles, object-level permission checks, SCIM 2.0 provisioning, SAML and OAuth SSO, TOTP and WebAuthn 2FA, and a tamper-evident hash-chained audit log with anomaly detection. MSPs and partners get a client console with org switching, SLA and MTTR rollups, branded QBR PDFs, and white-label reports. For regulated and defense environments it also ships as an air-gapped Linux bundle with a local AI model and a FIPS-approved AES-256-GCM encryption mode, built by an SDVOSB, eligible for federal set-aside contracts.
Connect your cloud free →