Guide · AWS Inspector · Vulnerability Scanning

AWS Inspector v2 for MCP Servers — Vulnerability Scanning Overview, Pricing, and Activation

AWS Inspector v2 continuously scans EC2 instances, ECR container images, and Lambda functions for software package vulnerabilities, network reachability issues, and CIS benchmark violations — covering the three most common deployment targets for MCP servers with a 30-day free trial and per-resource pricing thereafter ($0.11/instance/month for EC2, $0.09/image push for ECR, $0.30/function/month for Lambda). Inspector Classic (v1) was retired in December 2023; all guidance below applies to Inspector v2, which replaced it with continuous scanning, automatic re-scanning on new CVE publication, and AWS Organizations integration — eliminating the need to schedule scan runs manually. The key distinction from point-in-time security scans is that Inspector never stops: when a zero-day is published at 3 AM, Inspector re-evaluates all your deployed resources within hours and creates new findings without any operator action.

TL;DR

Enable Inspector v2 with aws inspector2 enable --resource-types EC2 ECR LAMBDA LAMBDA_CODE — a service-linked role is created automatically. EC2 scanning requires SSM Agent on each instance; ECR requires switching repositories to enhanced scanning; Lambda requires no agent. For EC2 scanning details see the EC2 scanning guide. For ECR see the ECR scanning guide. For Lambda see the Lambda scanning guide. For managing findings and suppression rules see the findings guide.

Resource types and finding types

Inspector v2 scans four resource types and produces four finding types. Understanding which finding types apply to which resources is essential for scoping costs and configuring suppression rules:

Resource typeFinding typeWhat it reports
EC2 instancePACKAGE_VULNERABILITYKnown CVEs in OS packages (yum/apt/zypper) and language runtime packages (pip/npm/gem) installed on the instance
EC2 instanceNETWORK_REACHABILITYPorts reachable from the internet based on VPC security group + NACL + route table analysis — not active probing
EC2 instanceCISCIS Benchmark Level 1 / Level 2 OS configuration hardening checks
ECR imagePACKAGE_VULNERABILITYCVEs in OS packages and language packages inside container layers
Lambda function (standard)PACKAGE_VULNERABILITYCVEs in packages bundled in the function deployment package and all attached layers
Lambda function (code)CODE_VULNERABILITYSAST findings via CodeGuru Security: injection flaws, cryptographic misuse, hard-coded credentials

Each finding carries an Inspector Score (0.0–10.0) that starts from the CVSS v3.1 base score and is adjusted by Inspector-proprietary signals: presence in CISA KEV (Known Exploited Vulnerabilities), active exploitation evidence in threat intelligence feeds, and network reachability context for EC2. A vulnerability with a CVSS base of 5.0 can become an Inspector Score 9.2 if a working public exploit exists and the affected port is reachable from the internet. Triage on Inspector Score, not raw CVSS.

Activating Inspector v2

Activation creates the service-linked role AWSServiceRoleForAmazonInspector2 and begins scanning immediately for qualifying resources in the region.

# Enable all four resource types in us-east-1
aws inspector2 enable \
  --resource-types EC2 ECR LAMBDA LAMBDA_CODE \
  --region us-east-1

# Verify activation state for each resource type
aws inspector2 batch-get-account-status \
  --account-ids "$(aws sts get-caller-identity --query Account --output text)" \
  --query 'accounts[0].resourceState'

The response includes a state per resource type: ENABLED, ENABLING (transient), DISABLED, or SUSPENDED. EC2 scanning reaches ENABLED within a few minutes for the service itself; actual instance scan coverage depends on SSM Agent connectivity and may take 30–60 minutes for large fleets. Lambda and ECR reach ENABLED within minutes.

# Check which resources are covered (and which are not)
aws inspector2 list-coverage \
  --query 'coveredResources[].{Type:resourceType,Id:resourceId,Status:scanStatus.statusCode,Reason:scanStatus.reason}' \
  --output table | head -40

statusCode: INACTIVE means the resource is not being scanned and not being billed. For EC2 this almost always means SSM Agent is not installed or not connected to SSM — see the EC2 scanning guide. Resources with statusCode: SCANNING are active and being billed after the 30-day trial.

Multi-account activation via AWS Organizations

Inspector v2 follows the delegated-administrator pattern used by GuardDuty and Security Hub. One account is designated as the Inspector delegated administrator; it sees findings from all member accounts and configures scanning policies fleet-wide.

# Step 1 — in the management account: designate delegated admin
aws inspector2 enable-delegated-admin-account \
  --delegated-admin-account-id "111122223333" \
  --region us-east-1

# Step 2 — in the delegated admin account: set auto-enable for new org members
# (lambdaCode: false unless you want CodeGuru SAST charges)
aws inspector2 update-organization-configuration \
  --auto-enable '{
    "ec2": true,
    "ecr": true,
    "lambda": true,
    "lambdaCode": false
  }'

# Step 3 — enable Inspector in existing member accounts
aws inspector2 enable \
  --resource-types EC2 ECR LAMBDA \
  --account-ids 222233334444 333344445555 444455556666

New accounts joining the organization are automatically enrolled within 30 minutes when auto-enable is set. Member accounts cannot disable Inspector if the organization configuration has any resource type set to auto-enable: true — the delegated admin must change the org configuration first.

Pricing and cost estimation

Resource typeFree periodAfter free trialProration
EC2 instances30-day account trial$0.11 per instance per monthDaily
ECR images30-day account trial$0.09 per unique image scannedPer push event
Lambda standard30-day account trial$0.30 per function per monthDaily
Lambda code (SAST)30-day account trial$0.30 per function per monthDaily (additive to standard)
CIS scans (EC2)IncludedIncluded in EC2 charge—

The free trial applies at the account level — all resources in the account are free for 30 days regardless of count. After the trial, the charge is per active resource. An EC2 instance running for 15 of 31 days is charged for 15/31 × $0.11. An ECR image that is pushed once and then triggers 10 re-scans over its lifetime because of new CVE publications is charged only once at push time — re-scans are included.

# Cost estimate: count active resources before trial ends
EC2_COUNT=$(aws inspector2 list-coverage \
  --filter-criteria '{"resourceType":[{"comparison":"EQUALS","value":"AWS_EC2_INSTANCE"}],"scanStatusCode":[{"comparison":"EQUALS","value":"ACTIVE"}]}' \
  --query 'length(coveredResources)')
LAMBDA_COUNT=$(aws inspector2 list-coverage \
  --filter-criteria '{"resourceType":[{"comparison":"EQUALS","value":"AWS_LAMBDA_FUNCTION"}],"scanStatusCode":[{"comparison":"EQUALS","value":"ACTIVE"}]}' \
  --query 'length(coveredResources)')
echo "EC2 monthly: \$$(echo "$EC2_COUNT * 0.11" | bc)"
echo "Lambda monthly: \$$(echo "$LAMBDA_COUNT * 0.30" | bc)"

Inspector Score severity bands and SLA targets

SeverityInspector Score rangeRecommended remediation SLA
CRITICAL9.0–10.024 hours — known exploited, active exploitation evidence
HIGH7.0–8.97 days — high CVSS, exploit PoC public
MEDIUM4.0–6.930 days — exploitable but no active exploitation
LOW1.0–3.9Next regular patch cycle or suppress with business justification
INFORMATIONAL0.0–0.9Suppress unless audit requirement mandates resolution

What Inspector v2 does not cover

Inspector scans packages and static configuration — it does not replace runtime monitoring:

Failure modes reference

FailureSymptomFix
EC2 shows INACTIVE coverageListCoverage returns statusCode INACTIVE for instancesSSM Agent not installed or not registered as managed instance; see EC2 scanning guide for SSM setup
ECR images not scannedECR repository shows "Basic" scanning in console after enabling InspectorRepository must be switched to enhanced scanning; Inspector does not override basic scanning automatically — see ECR scanning guide
No CODE_VULNERABILITY findingsLambda code scanning enabled but no SAST findings appearCodeGuru Security must also be active; container-image Lambda functions are not scanned for code vulnerabilities (only .zip)
inspector2:Enable AccessDeniedExceptionCannot activate InspectorNeeds inspector2:Enable + iam:CreateServiceLinkedRole; org delegated admin setup also needs inspector2:EnableDelegatedAdminAccount in management account
Re-enable does not restore findingsDisabled then re-enabled Inspector; prior findings goneFindings are retained 30 days after disable; after 30 days they are permanently deleted; re-enable starts fresh scans