Aqua CSPM — Core Capabilities Overview
Aqua CSPM — Core Capabilities Overview
Overview
Aqua Cloud Security Posture Management (CSPM) provides agentless visibility into cloud infrastructure security posture across supported cloud providers. This article describes key CSPM capabilities—including agentless scanning, security scoring, visualizer reports, Infrastructure as Code (IaC) scanning, and malware detection—to help teams understand what the module delivers and where to find additional documentation.
Understanding these capabilities is essential for security and compliance teams evaluating CSPM coverage, planning cloud security workflows, and aligning Aqua CSPM with broader cloud-native security programs.
Understanding Aqua CSPM
Aqua CSPM continuously assesses cloud account configurations and workloads against security best practices and compliance frameworks. The module operates without requiring agents deployed on cloud resources, enabling broad coverage across cloud environments with minimal operational overhead.
CSPM integrates with Aqua's broader cloud-native application protection platform, providing posture management alongside vulnerability and threat detection capabilities.
Agentless Scanning
Aqua CSPM supports agentless scanning for cloud resource assessment. Agentless scanning evaluates cloud infrastructure by connecting to cloud provider APIs and analyzing resource configurations, permissions, and security settings without installing software on individual workloads.
Key characteristics:
- No agent deployment required on cloud resources
- API-based assessment of cloud account posture
- Broad coverage across supported cloud platforms
- Complements agent-based detection for threats that may evade agentless methods
Aqua CSPM uses agentless scanning as a primary assessment method and can also identify threats that agentless detection alone may not surface, providing layered security visibility.
CSPM Security Scoring
Aqua CSPM assigns a security score represented as a letter grade from A (lowest risk) to F (highest risk) for each monitored cloud account. The score reflects the overall security risk posture based on identified misconfigurations, policy violations, and security findings.
How scoring helps:
| Benefit | Description |
|---|---|
| At-a-glance risk assessment | Quickly identify which cloud accounts require immediate attention |
| Prioritization | Focus remediation efforts on accounts with the lowest scores |
| Trend tracking | Monitor posture improvement over time as issues are resolved |
| Stakeholder communication | Provide a simple, standardized metric for security reporting |
For detailed scoring methodology, weighting, and grade thresholds, see Aqua CSPM Scoring.
Visualizer Reports
Visualizer reports provide graphical representations of security risks observed across your cloud environment. Rather than presenting findings as flat lists, visualizer reports map relationships between resources, misconfigurations, and risk factors to help teams understand attack paths and exposure.
Use cases:
- Visualize how misconfigurations connect across cloud resources
- Identify high-risk resource clusters and dependency chains
- Communicate security posture to technical and non-technical stakeholders
- Prioritize remediation based on visual risk context
Documentation:
Infrastructure as Code (IaC) Scanning
IaC scanning evaluates infrastructure definitions—such as Terraform, CloudFormation, Kubernetes manifests, and other supported formats—for security misconfigurations before resources are deployed to cloud environments.
Aqua provides IaC security scanning through Trivy, Aqua's open-source security scanner. Trivy supports scanning of multiple IaC formats and integrates into CI/CD pipelines for shift-left security.
Supported approach:
- Scan IaC templates and manifests during development and build stages
- Detect misconfigurations, exposed secrets, and policy violations early
- Integrate with existing DevOps workflows
For setup instructions, supported technologies, and usage examples, see IaC Security with Trivy.
Malware Detection in CSPM
Aqua CSPM includes malware detection capabilities that identify malicious files and suspicious content within cloud workloads and storage. Detection methods vary by workload type and cloud service, leveraging signature-based and behavioral analysis techniques.
What malware detection covers:
- Identification of known malware signatures in cloud-stored artifacts
- Detection of suspicious file patterns in supported cloud workloads
- Integration with CSPM findings for unified risk visibility
Documentation:
- Malware Detection Overview
- Cloud Security Posture Management (CSPM)
- CSPM Tools and Capabilities
- Vulnerability Management Tools
For specific detection methods applied within the CSPM module, refer to the Cloud Native Academy resources above, which describe how Aqua implements detection across cloud environments.
Aqua Hub Considerations
Module Inclusion
Whether Aqua Hub includes the CSPM module alone or the full Aqua CNAPP suite (CSPM + CWPP) depends on the license and subscription in place. Module availability is determined at the time of purchase and is not a support configuration item.
Contact your Aqua account representative or sales team for details on what modules are included in your specific subscription.
Role-Based Access Control (RBAC)
RBAC for Aqua Hub is currently under development and is expected to be completed in upcoming platform releases. RBAC behavior in Aqua Hub may differ from RBAC in the current Aqua Console until this work is finalized.
Check release notes and product announcements for updates on Aqua Hub RBAC availability.
Platform Coverage
Applicable To:
- Aqua SaaS (CSPM module)
- Supported cloud providers as documented in current Aqua CSPM release notes
Affected Components:
- Aqua CSPM
- Visualizer Reports
- CSPM Security Scoring
- Trivy (IaC scanning — open source)
Summary
| Capability | Description |
|---|---|
| Agentless Scanning | API-based cloud posture assessment without deploying agents |
| CSPM Scoring | Letter grade (A–F) representing cloud account security risk |
| Visualizer Reports | Graphical display of security risks and resource relationships |
| IaC Scanning | Pre-deployment scanning via Trivy open-source scanner |
| Malware Detection | Identification of malicious files in supported cloud workloads |
| Aqua Hub Modules | CSPM vs. CNAPP inclusion depends on license — contact sales |
| Aqua Hub RBAC | Under development; expected in upcoming releases |
Related Resources
Did you find it helpful? Yes No
Send feedback