Cloud Security Scanning
Panther Cloud Security Scanning uses policies to detect misconfigurations in AWS resources
Overview
Cloud Security Scanning in Panther works by capturing the configurations of your Amazon Web Services (AWS) resources and invoking associated policies you've defined to detect misconfigurations. Cloud Security Scanning is automatically enabled when you onboard a Cloud Account in your Panther instance.
This feature can improve your cloud security posture and assist with compliance. Common security misconfigurations detectable by Panther include:
S3 Buckets without encryption
Security Groups allowing inbound SSH traffic from
0.0.0.0/0Access Keys being older than 90 days
IAM policies that are too permissive
When adding a new AWS account, Panther runs a baseline scan and models all of the resources in your account. Account scans are then performed daily. This works by using an assumable IAM Role with ReadOnly permissions.
How to use Cloud Security Scanning
Cloud Security Scanning is automatically enabled in Panther when a cloud account is onboarded. With Cloud Security Scanning, Panther captures the state of cloud resources and invokes any associated policies on a daily cadence to detect misconfigurations.
You can onboard a cloud account in the Panther Console, or using the Panther API.
Additionally, we recommend onboarding your CloudTrail or CloudWatch logs as a log source integration so you can configure detections and receive alerts for active incidents and breaches.
Onboarding a cloud account in the Panther Console
Log in to your Panther Console.
In the left sidebar, click Cloud Accounts then click Create New.
The Cloud Accounts page displays your accounts in a DataGrid with columns for Name, Status, Account ID, Created, and Real Time Scanning status. A hidden-by-default Stack Name column can be enabled through the column-visibility toggle. You can use the toolbar to filter accounts by health status, real-time scanning status, or by a Created date range, and use the quick search to find specific accounts by name or account ID.
On the Basic Information step, enter your account Name and AWS Account ID.
You can also click Show Advanced Options to indicate which AWS Regions, Resource Types, and Resources (by regex) you would like to exclude from cloud scanning. This can help prevent too many alerts from being generated by regions and resources known to be misconfigured.

Click Continue.
Set up an IAM role
Panther needs an IAM role to scan resources from your AWS account. On the Setup an IAM Role step, choose how you'd like to create the role using one of the following tabs:
Using the AWS UI: Launch a CloudFormation stack using the AWS console.
CloudFormation Template: Download Panther's CloudFormation template and deploy it through your own pipeline.
Terraform Template: Download Panther's Terraform template and deploy it through your own pipeline.
Setup Manually: Create the IAM role manually or with other automation.
Regardless of which option you choose, you will paste the resulting Role ARN into the Enter role ARN field at the bottom of the tab, then click Continue.

Creating an IAM Role using the AWS UI
On the Setup an IAM Role step, select the Using the AWS UI tab.
Click Launch Console UI.
You will be redirected to the AWS console in a new browser tab, with the template URL pre-filled.
Check the acknowledgements in the "Capabilities" box, and click Create stack.
When the stack finishes deploying, copy the Role ARN from the stack's Outputs tab.
Navigate back to your Panther Console, paste the value into the Enter role ARN field, and click Continue.
Creating an IAM Role using a CloudFormation Template
On the Setup an IAM Role step, select the CloudFormation Template tab.
Click Download Template to download Panther's CloudFormation template.
Deploy the template through your own pipeline—for example, by running the
aws cloudformation deploycommand shown under Run Command in your CLI.When the stack finishes deploying, copy the Role ARN from the stack's Outputs tab, paste it into the Enter role ARN field, and click Continue.

Creating an IAM Role using a Terraform Template
On the Setup an IAM Role step, select the Terraform Template tab.
Click Download Template to download Panther's Terraform template.
You can also find the Terraform template at this GitHub link.
Deploy the template through your own pipeline—run
terraform initto initialize the directory, then apply the template as shown under Run Command in your CLI.Once deployed, copy the Role ARN from the outputs of your Terraform deployment, paste it into the Enter role ARN field, and click Continue.
Creating an IAM role manually or with other automation
If you wish to create an IAM role via some other mechanism, ensure it has the naming standard and permissions documented in Panther’s provided templates.
On the Setup an IAM Role step, select the Setup Manually tab.
Create the required IAM role manually or through your own automation.
Paste the role's ARN into the Enter role ARN field, and click Continue.
Finish the cloud account setup process
On the Verification step, Panther automatically verifies whether the IAM role has been successfully created. When the check succeeds, you'll see an "Everything looks good!" message confirming your cloud account is set up.
Click Go to Cloud Accounts to return to the Cloud Accounts list.

Onboarding a cloud account using the Panther API
To onboard a cloud account with the Panther API, use the CreateCloudAccount operation. Note that after using this operation, you will still need to set up an IAM role in your AWS account—follow the Creating an IAM role manually or with other automation instructions above.
Real-time monitoring
You can optionally enable real-time monitoring of your cloud resources, in addition to the daily scan performed by the Cloud Security Scanning service.
Real-time monitoring means that whenever a change is made to a cloud resource (including configuration modifications, creations, and deletions), Panther invokes any policies associated with that resource. This means that if the change causes the resource to fail a policy, you will be alerted in near-real-time, instead of at the time of the next daily scan.
To set up real-time monitoring, either onboard AWS CloudTrail as a log source, or follow the CloudWatch events process below.
CloudTrail logs
To set up real-time monitoring via CloudTrail logs, follow the instructions to onboard CloudTrail logs.
CloudWatch events
To leverage CloudWatch events for resource scanning and monitoring, you must configure a CloudFormation stack in AWS and then onboard your Cloud Account.
Configure CloudFormation to leverage CloudWatch events
Before getting started, review the panther-cloudwatch-events.yml CloudFormation template within panther-auxiliary. This YAML file contains the CloudFormation stack information necessary to configure Panther's real-time CloudWatch Event collection.
It works by creating CloudWatch Event rules which feed to Panther's SQS Queue proxied by a local SNS topic in each region. Latency between an event occurring in AWS and the event being detected by CloudWatch Event rules is typically 1 minute or less.
Download the
panther-cloudwatch-events.ymltemplate from panther-auxiliary.Launch your AWS console and navigate to the CloudFormation service.
Click Create stack and choose the option "With new resources."
In the Template section, choose the option Upload a template file. Select your
panther-cloudwatch-events.ymlfile.Click Next.
In the Specify Details section, fill in the necessary fields, including the following:
Stack name:
panther-real-time-eventsQueueArn:
arn:aws:sqs:<PantherRegion>:<PantherAccountID>:panther-aws-events-queue
Click Next.
On the Configure stack options page, click Next.
On the Review page, make sure you have configured your settings correctly. Click Next.
After configuring the template, follow the instructions to onboard your cloud account.
Cloud resource attributes
To learn more about the attributes that can be referenced in Cloud Security policies, see Cloud Resource Attributes.
Managing Cloud Accounts
Cloud Accounts DataGrid
The Cloud Accounts page displays all your connected AWS accounts in an interactive DataGrid that provides:
Columns: Name (clickable to edit), Status, Account ID, Created, and Real Time Scanning status. Stack Name is available as a hidden-by-default column through the column-visibility toggle in the toolbar.
Filtering: Click the filter (funnel) icon to open a filter panel where you can filter by health status, real-time scanning status, or a Created date range. Active filters appear as chips above the grid with a Clear All control that preserves the quick-search text.
Search: Quick text search across account names and AWS Account IDs.
Sorting: Click column headers to sort accounts.
Actions: Use the kebab menu (⋮) on each row to edit or delete accounts. The actions menu only appears for users with the Cloud Account Modify permission.

The filter panel exposes Health and Real-time Scanning checkboxes plus a Created date range selector:

Account Health Notifications
When a cloud account becomes unhealthy (e.g., due to IAM role issues), the Status column on the list will switch to Unhealthy, and an Account has turned Unhealthy notification will appear on the account's edit page, above the configuration form. The notification lists every failing health metric (audit role and/or real-time monitoring) with its summary message, and each entry has a View Error Message link that reveals the raw error details.

Troubleshooting Cloud Security Scanning
Visit the Panther Knowledge Base to view articles about Cloud Security Scanning policies and articles about Cloud Accounts that answer frequently asked questions and help you resolve common errors and issues.
Last updated
Was this helpful?

