Runtime Protection
Use Runtime Protection to investigate Amazon Inspector findings for your workloads, including EC2 instances, Lambda functions, and ECR images where findings have been collected.
Find an affected workload
- Open Runtime Protection and choose Hosts.
- Search by host name or resource ID, or filter by account, region, and resource type.
- Select a host to inspect its findings.
- Open Findings to search and filter individual records across your environment.
The page highlights critical findings, available fixes, and reported exploits. Summary counts include recorded findings across statuses, so review the individual status when prioritizing work.
Investigate a finding
Select a finding to open its preview, then choose View Full Details. The full page brings together:
- Severity, recorded status, and Inspector score when available.
- The affected package and any reported fixed version.
- Guidance for addressing the issue.
- The affected resource, account, and region.
- A lifecycle showing when the finding was recorded, updated, and observed closed.
- Up to three references for further reading.
Use the available task action to track follow-up work, or record a risk exception when appropriate.
Understand finding status
| Status | How to interpret it |
|---|---|
| Active | The issue is still reported as active. |
| Closed | Byrsa has observed the finding as closed and recorded a closure date. |
| Suppressed | The finding is suppressed; this is not counted as resolution. |
| Passed | An older record may have this status without a recorded closure date. |
Closure first observed is when Byrsa learned that the finding was closed. It may be later than the change in AWS. A reopened finding loses its current closure date; a later closure receives a new one.
Use the dashboard's Resolution view to follow closure progress. If no runtime data appears, ask your administrator to check Inspector coverage and collection.