Security & IAM
Amazon Inspector
Amazon Inspector continuously discovers and scans supported Amazon EC2, Amazon ECR, and AWS Lambda resources for software vulnerabilities, unintended network exposure, and code-security issues where applicable.
Explore pricing models, common use cases, infrastructure support, and the AWS services that commonly work with Amazon Inspector.
Amazon Inspector pricing and cost programs
Pricing model: Continuous vulnerability scanning usage
- On-Demand
- Available
- Reserved Instances or reserved capacity
- Not applicable
- Savings Plans
- Not applicable
- Spot
- Not applicable
Billing dimensions: EC2 instances scanned · Container images scanned · Lambda functions scanned · Code repositories scanned
Programs and modes: EC2 scanning · ECR scanning · Lambda scanning · Code Security
Each protected resource type has a distinct metering unit and trial terms.
Free Tier: Available — verify current offers
Pricing reviewed 2026-07-25. Reviewed against the linked official AWS pricing page. Recheck regional rates and program terms before purchase.
Official AWS sources reviewed 2026-07-21.
Why implement Amazon Inspector?
- Continuously reassesses supported resources when packages, images, functions, or vulnerability intelligence change.
- Correlates vulnerabilities with resource and exposure context and integrates findings with Security Hub and EventBridge.
- Supports centralized multi-account operation and coverage reporting without customers operating a separate vulnerability scanner for these resource types.
How to implement Amazon Inspector
- Designate a delegated administrator, enable Inspector for all required accounts, Regions, and resource types, and configure organization auto-enable for new accounts deliberately.
- Review coverage status, SSM and agentless prerequisites, ECR rescan duration, Lambda runtime and code-scanning support, exclusions, and unsupported resources so gaps are explicit.
- Route findings by exploitability, exposure, severity, asset criticality, and fix availability; patch instances, rebuild images or functions, deploy, and confirm that rescanning closes the finding.
Amazon Inspector best practices
- Monitor coverage as closely as findings because stopped, unsupported, stale, or misconfigured resources can create false confidence.
- Prefer immutable rebuild and redeploy for images and functions, patch long-lived instances through controlled Systems Manager workflows, and define risk-based remediation targets.
- Use suppression rules only for documented, time-bound accepted risk, integrate with Security Hub and ticketing, and verify the deployed artifact rather than merely closing a ticket.
Amazon Inspector use cases and server impact
- EC2 package vulnerability detection
- ECR container-image scanning
- Lambda package and code vulnerability review
Replaces much supported-resource vulnerability-scanner infrastructure, but patching, rebuilding, ownership, exception governance, unsupported assets, and verification remain customer work.
Official implementation resources
Commonly paired AWS services
- Amazon Elastic Compute Cloud — Resizable virtual servers
- Amazon Elastic Container Registry — Container registry
- AWS Lambda — Run code without servers
- AWS Systems Manager — Operational control
- AWS Security Hub — Security posture
- Amazon EventBridge — Event bus
- AWS Organizations — Multi-account mgmt