Aqua CSPM — Core Capabilities Overview

Overview

Aqua Cloud Security Posture Management (CSPM) provides agentless visibility into cloud infrastructure security posture across supported cloud providers. This article describes key CSPM capabilities—including agentless scanning, security scoring, visualizer reports, Infrastructure as Code (IaC) scanning, and malware detection—to help teams understand what the module delivers and where to find additional documentation.

Understanding these capabilities is essential for security and compliance teams evaluating CSPM coverage, planning cloud security workflows, and aligning Aqua CSPM with broader cloud-native security programs.

Understanding Aqua CSPM

Aqua CSPM continuously assesses cloud account configurations and workloads against security best practices and compliance frameworks. The module operates without requiring agents deployed on cloud resources, enabling broad coverage across cloud environments with minimal operational overhead.

CSPM integrates with Aqua's broader cloud-native application protection platform, providing posture management alongside vulnerability and threat detection capabilities.

Agentless Scanning

Aqua CSPM supports agentless scanning for cloud resource assessment. Agentless scanning evaluates cloud infrastructure by connecting to cloud provider APIs and analyzing resource configurations, permissions, and security settings without installing software on individual workloads.

Key characteristics:

  • No agent deployment required on cloud resources
  • API-based assessment of cloud account posture
  • Broad coverage across supported cloud platforms
  • Complements agent-based detection for threats that may evade agentless methods

Aqua CSPM uses agentless scanning as a primary assessment method and can also identify threats that agentless detection alone may not surface, providing layered security visibility.

CSPM Security Scoring

Aqua CSPM assigns a security score represented as a letter grade from A (lowest risk) to F (highest risk) for each monitored cloud account. The score reflects the overall security risk posture based on identified misconfigurations, policy violations, and security findings.

How scoring helps:

BenefitDescription
At-a-glance risk assessmentQuickly identify which cloud accounts require immediate attention
PrioritizationFocus remediation efforts on accounts with the lowest scores
Trend trackingMonitor posture improvement over time as issues are resolved
Stakeholder communicationProvide a simple, standardized metric for security reporting

For detailed scoring methodology, weighting, and grade thresholds, see Aqua CSPM Scoring.

Visualizer Reports

Visualizer reports provide graphical representations of security risks observed across your cloud environment. Rather than presenting findings as flat lists, visualizer reports map relationships between resources, misconfigurations, and risk factors to help teams understand attack paths and exposure.

Use cases:

  • Visualize how misconfigurations connect across cloud resources
  • Identify high-risk resource clusters and dependency chains
  • Communicate security posture to technical and non-technical stakeholders
  • Prioritize remediation based on visual risk context

Documentation:

Infrastructure as Code (IaC) Scanning

IaC scanning evaluates infrastructure definitions—such as Terraform, CloudFormation, Kubernetes manifests, and other supported formats—for security misconfigurations before resources are deployed to cloud environments.

Aqua provides IaC security scanning through Trivy, Aqua's open-source security scanner. Trivy supports scanning of multiple IaC formats and integrates into CI/CD pipelines for shift-left security.

Supported approach:

  • Scan IaC templates and manifests during development and build stages
  • Detect misconfigurations, exposed secrets, and policy violations early
  • Integrate with existing DevOps workflows

For setup instructions, supported technologies, and usage examples, see IaC Security with Trivy.

Malware Detection in CSPM

Aqua CSPM includes malware detection capabilities that identify malicious files and suspicious content within cloud workloads and storage. Detection methods vary by workload type and cloud service, leveraging signature-based and behavioral analysis techniques.

What malware detection covers:

  • Identification of known malware signatures in cloud-stored artifacts
  • Detection of suspicious file patterns in supported cloud workloads
  • Integration with CSPM findings for unified risk visibility

Documentation:

For specific detection methods applied within the CSPM module, refer to the Cloud Native Academy resources above, which describe how Aqua implements detection across cloud environments.

Aqua Hub Considerations

Module Inclusion

Whether Aqua Hub includes the CSPM module alone or the full Aqua CNAPP suite (CSPM + CWPP) depends on the license and subscription in place. Module availability is determined at the time of purchase and is not a support configuration item.

Contact your Aqua account representative or sales team for details on what modules are included in your specific subscription.

Role-Based Access Control (RBAC)

RBAC for Aqua Hub is currently under development and is expected to be completed in upcoming platform releases. RBAC behavior in Aqua Hub may differ from RBAC in the current Aqua Console until this work is finalized.

Check release notes and product announcements for updates on Aqua Hub RBAC availability.

Platform Coverage

Applicable To:

  • Aqua SaaS (CSPM module)
  • Supported cloud providers as documented in current Aqua CSPM release notes

Affected Components:

  • Aqua CSPM
  • Visualizer Reports
  • CSPM Security Scoring
  • Trivy (IaC scanning — open source)

Summary

CapabilityDescription
Agentless ScanningAPI-based cloud posture assessment without deploying agents
CSPM ScoringLetter grade (A–F) representing cloud account security risk
Visualizer ReportsGraphical display of security risks and resource relationships
IaC ScanningPre-deployment scanning via Trivy open-source scanner
Malware DetectionIdentification of malicious files in supported cloud workloads
Aqua Hub ModulesCSPM vs. CNAPP inclusion depends on license — contact sales
Aqua Hub RBACUnder development; expected in upcoming releases