Infrastructure scanning examines the configuration files that define your cloud resources, containers, and deployment infrastructure. As more teams adopt infrastructure-as-code (IaC), the configuration files themselves become a source of security risk. A misconfigured S3 bucket policy or an overly permissive security group can expose data or create attack vectors.
The shift to infrastructure-as-code has a security upside: configuration is now reviewable, testable, and version-controlled. But it also means security teams need tools that understand Terraform, CloudFormation, Kubernetes manifests, and Dockerfiles.
What Gets Scanned
Infrastructure scanning covers several categories of configuration:
-
Cloud resource definitions in Terraform, CloudFormation, Pulumi, or provider-specific formats. These might create storage buckets, databases, networking rules, or IAM policies that have security implications.
-
Container configurations including Dockerfiles and container image definitions. Common issues include running as root, using outdated base images, or exposing unnecessary ports.
-
Kubernetes manifests that define how workloads run. Security contexts, network policies, and resource limits all affect the security posture of deployed applications.
-
CI/CD pipeline definitions that might expose secrets, grant excessive permissions, or pull from untrusted sources.
Common Misconfigurations
The CIS Benchmarks catalog security best practices for major cloud providers and platforms. Many infrastructure scanning tools check against these benchmarks. Common findings include:
Public access enabled on storage buckets or databases. Encryption disabled at rest or in transit. Overly permissive IAM policies that grant more access than necessary. Missing logging or monitoring configuration. Default credentials or security groups left in place.
NIST's cloud security guidelines provide additional context on securing cloud infrastructure.
Shift Left for Infrastructure
Like other security testing, infrastructure scanning works best when it happens early. Scanning IaC templates before they're applied catches misconfigurations before they create real-world exposure. Many teams integrate scanning into pull request workflows, requiring security review before infrastructure changes merge.
This "policy as code" approach treats security requirements as testable rules. Rather than manual review of every change, automated checks enforce that new infrastructure meets baseline security standards.
AI-Generated Infrastructure Code
AI coding agents are increasingly used to generate infrastructure code. An agent can scaffold Terraform modules, write Kubernetes manifests, or create CI/CD pipelines. But the generated configurations may not follow security best practices.
An AI might generate a database configuration that's publicly accessible because that's simpler than setting up proper networking. Or create an IAM policy that grants full admin access because that definitely works, even if it violates least privilege.
ACSM tools can provide guardrails for infrastructure code generation, guiding AI agents toward secure configurations. Corridor analyzes infrastructure code alongside application code, catching misconfigurations before they're committed.