To choose a cloud vulnerability scanner, match the tool’s coverage (cloud accounts, virtual machines, containers, Kubernetes, infrastructure as code and identities) to where your risk lives. Then test, in your own environment, how well it separates exploitable findings from theoretical ones. Most buying mistakes happen because “cloud vulnerability scanner” covers very different products. A posture tool that reads AWS configuration, a container image scanner in a CI pipeline and a network scanner built for data centers all carry the same label, but they find different problems. This guide is for CISOs trying to cut tool sprawl, cloud security architects who need multi-cloud and identity visibility, DevSecOps engineers working through a CVE backlog, and SOC leads dealing with cloud blind spots. It compares nine options: cloud-native application protection platforms (CNAPPs), a cloud provider’s own platform, enterprise vulnerability management suites and an external exposure scanner. The comparison draws on vendor documentation and Gartner Peer Insights reviews current as of October 2026, and adds a decision framework, proof-of-concept steps and open-source alternatives.
Key takeaways
- ✓A cloud vulnerability scanner should be judged by which layers it covers (cloud configuration, workloads, containers, Kubernetes, IaC, identities), not by how many CVEs it reports.
- ✓CNAPPs such as Upwind, Wiz, Orca and Microsoft Defender for Cloud combine posture, workload and identity scanning, while tools like Nessus, Qualys VMDR and InsightVM come from traditional vulnerability management.
- ✓The best prioritization filters CVEs by whether the package is loaded at runtime, whether the workload is internet-exposed and whether a realistic attack path exists.
- ✓Agent-based and sensor-based scanners cannot run on AWS Fargate or other serverless platforms that hide the node, so serverless-heavy teams need agentless or API-based coverage.
- ✓A two-to-four-week proof of concept on a real production account shows more about a scanner than any feature sheet does.
Best cloud vulnerability scanners compared
The strongest cloud vulnerability scanners to consider in 2026 are Upwind, Wiz, Orca Security, Microsoft Defender for Cloud, Qualys VMDR, Tenable Nessus, Rapid7 InsightVM, CrowdStrike Falcon Spotlight and Intruder. Each one fits a different buyer.
- ✓Upwind: teams that want to prioritize vulnerabilities by runtime evidence of what is loaded, reachable and exposed.
- ✓Wiz: cloud-native teams that want agentless multi-cloud coverage with attack path analysis.
- ✓Orca Security: multi-cloud teams with heavy compliance mapping requirements.
- ✓Microsoft Defender for Cloud: Azure-centric organizations that also run AWS, GCP or on-premises servers.
- ✓Qualys VMDR: large or hybrid programs that need detection, patching and compliance in one suite.
- ✓Tenable Nessus: broad vulnerability assessment backed by a deep plugin library.
- ✓Rapid7 InsightVM: continuous vulnerability management with remediation tracking.
- ✓CrowdStrike Falcon Spotlight: continuous vulnerability assessment for organizations already using Falcon.
- ✓Intruder: lean teams that need continuous monitoring of internet-facing assets.
| Tool | Type | Scanning model | Cloud and Kubernetes coverage | Prioritization context | Shift-left support | Pricing model |
|---|---|---|---|---|---|---|
| Upwind | Runtime-first CNAPP | Agentless discovery plus lightweight eBPF sensors | Multi-cloud; EKS, AKS, GKE, OKE | Runtime-loaded packages, reachability, internet exposure, exploitability | IaC scanning; CI/CD; SBOM; runtime-to-code tracing | Per resource unit; AWS Marketplace |
| Wiz | CNAPP | Agentless snapshots, plus an optional sensor | AWS, Azure, GCP, Oracle Cloud; EKS, AKS, GKE, self-managed clusters | Attack paths, reachability, loaded packages, internet exposure | Terraform, CloudFormation, ARM, Kubernetes; CI/CD; SBOM (SPDX, CycloneDX) | Per workload, quote-based |
| Orca Security | CNAPP | Agentless SideScanning of block storage and cloud APIs | AWS, Azure, GCP; EKS, GKE, AKS | Reachability, loaded packages, exposure, public exploits, CISA KEV | Terraform, CloudFormation, Helm, manifests; IDE and CI/CD gating; SAST, SCA, SBOM | Custom quote; AWS and Azure Marketplace |
| Microsoft Defender for Cloud | Cloud provider CNAPP | Agentless disk snapshots, plus a Defender sensor for containers | Azure, AWS, GCP, on-premises via Azure Arc; AKS, EKS, GKE (including Autopilot) | Reachability, exposure, exploitability, Microsoft threat intelligence, EDR breach signals | Code scanning (per reviewers) | Per protected resource; Azure Marketplace |
| Qualys VMDR | Enterprise VM suite | Integrated detection, prioritization, remediation | Large and hybrid estates | Risk-based prioritization | Verify in PoC | Not published in our sources |
| Tenable Nessus | Vulnerability assessment scanner | Plugin-based scanning | Broad assessment; verify cloud-native depth | Verify in PoC | Verify in PoC | Not published in our sources |
| Rapid7 InsightVM | Continuous VM platform | Continuous scanning with remediation tracking | Verify per cloud | Verify in PoC | Verify in PoC | Not published in our sources |
| CrowdStrike Falcon Spotlight | Cloud-native vulnerability assessment | Continuous monitoring and asset discovery | Verify per cloud | Contextual risk scoring | Verify in PoC | Not published in our sources |
| Intruder | External exposure scanner | Continuous external monitoring | Internet-facing assets | Verify in PoC | Not its focus | Not published in our sources |
The matrix below maps each tool to cloud use cases. “Yes” means our sources confirm the capability. “Verify” means you should test it in a proof of concept before relying on it.
| Tool | Cloud posture | VMs and workloads | Containers and Kubernetes | IaC and CI/CD | Identities (CIEM) | Hybrid / on-prem |
|---|---|---|---|---|---|---|
| Upwind | Yes | Yes | Yes | Yes | Yes | Verify |
| Wiz | Yes | Yes | Yes | Yes | Yes | Self-managed Kubernetes |
| Orca Security | Yes | Yes | Yes | Yes | Yes | Verify |
| Defender for Cloud | Yes | Yes | Yes | Verify | Yes | Yes (Azure Arc) |
| Qualys VMDR | Verify | Yes | Verify | Verify | Verify | Yes |
| Tenable Nessus | Verify | Yes | Verify | Verify | Verify | Verify |
| Rapid7 InsightVM | Verify | Yes | Verify | Verify | Verify | Verify |
| Falcon Spotlight | Verify | Yes | Verify | Verify | Verify | Verify |
| Intruder | Verify | External only | Verify | No | No | External only |
How to choose a cloud vulnerability scanner
Start by deciding which layers of your cloud the scanner must cover. Then check how it prioritizes findings, how it fits your environment and how its findings reach the engineers who fix them.
Know which layer each scanner type covers
Vendors use overlapping acronyms. The table below explains them in plain terms. For a broader map of the categories, see these types of cloud security tools.
| Category | What it scans | What it does not do |
|---|---|---|
| CSPM (cloud security posture management) | Cloud account configuration through provider APIs, such as public buckets and open security groups | Find CVEs inside running software |
| Agentless workload scanning | Disk snapshots of VMs and containers for vulnerable packages and secrets | Show what is executing right now |
| Agent or sensor-based workload protection (CWPP) | Live processes, loaded libraries and network traffic on hosts and nodes | Run on Fargate or serverless platforms that hide the node |
| Container image scanning | Image layers in registries and CI pipelines | Know whether the image is deployed or exposed |
| KSPM (Kubernetes security posture management) | Cluster configuration, RBAC and workload manifests | Assess cloud account settings outside the cluster |
| IaC scanning | Terraform, CloudFormation, ARM and Helm before deployment | Catch drift created after deployment |
| Software composition analysis (SCA) | Open-source dependencies in code repositories | Assess cloud infrastructure |
| CNAPP | Most of the above in one data model | Replace every specialist tool automatically |
Evaluation criteria that matter in the cloud
- ✓Depth per cloud, not a logo list: check which AWS, Azure and GCP services each scanner inspects, and whether managed Kubernetes modes such as GKE Autopilot are covered.
- ✓Ephemeral assets: autoscaling nodes and short-lived containers can disappear between snapshot cycles, so ask about scan frequency and event-driven discovery.
- ✓API rate limits: scanners that poll cloud APIs heavily can hit throttling limits across hundreds of accounts, so ask how the vendor schedules and backs off requests.
- ✓Runtime context: confirm whether the scanner knows which packages are loaded as well as which are installed.
- ✓Attack path and identity analysis: a medium CVE on a workload whose IAM role can read production data outranks a critical CVE on an isolated test box.
- ✓Agentless versus agent tradeoffs: agentless gives fast breadth, while sensors give live depth but need node access and capacity planning.
- ✓Remediation workflow: look for Jira and ServiceNow ticketing, SIEM export, CI/CD gates and fixes traced to the owning repository.
- ✓Reporting for each audience: executive risk trends, engineer-ready fix steps, compliance exports and a searchable asset inventory.
How prioritization separates exploitable from theoretical
Good risk-based vulnerability management filters CVEs through several layers of context instead of sorting by CVSS score. In an illustrative example, a scan finds 4,000 critical and high CVEs across 300 container images. Filtering to images running in production leaves 1,200. Keeping only packages loaded in memory leaves 300. Keeping workloads reachable from the internet leaves 40. Keeping CVEs with public exploit code or a CISA Known Exploited Vulnerabilities (KEV) listing leaves 8 tickets for this sprint. Ask each vendor to show that funnel on your own data.
Choose by environment
| Environment | What to prioritize | Options to shortlist |
|---|---|---|
| AWS-only | Compare a CNAPP against the native baseline of Inspector, GuardDuty and Security Hub | Wiz, Orca, native AWS services |
| Multi-cloud | Equal service coverage across AWS, Azure and GCP, and one normalized risk score | Wiz, Orca, Defender for Cloud |
| Kubernetes-heavy | Sensor support for EKS, AKS and GKE, image scanning in CI, and KSPM | CNAPPs with runtime sensors |
| Serverless-heavy | Agentless and API-based coverage, since sensors cannot run on Fargate or Lambda | Agentless CNAPPs |
| Regulated | Built-in NIST 800-53, FedRAMP, PCI DSS and HIPAA mappings, plus audit exports | Orca, Defender for Cloud, Qualys VMDR |
| Small lean team | Low setup effort and external exposure first | Intruder, Defender for Cloud (Azure shops), open-source tools |
Validate in a proof of concept
- Connect one production account and one non-production account using read-only roles, and record how long the full inventory takes.
- Seed known issues: a public storage bucket, an image with a known exploited CVE and an over-privileged IAM role.
- Compare the scanner’s top 20 findings with what your team already knows is risky.
- Push five findings into Jira or ServiceNow and check that owners, fix steps and asset context arrive intact.
- Fix one issue and time how long the scanner takes to mark it resolved. This is your remediation validation loop.
Before signing, map every finding type to one tool of record. If the CNAPP and an existing VM suite both report the same EC2 CVE, decide which one opens tickets. Otherwise engineers receive duplicate tickets and start ignoring both.
Common selection mistakes
- Buying on CVE count instead of prioritization quality.
- Assuming “supports GCP” means the same depth as AWS.
- Skipping ownership. DevOps owns fixes, SecOps owns triage rules, and both need to agree on SLAs.
- Ignoring workflows such as pre-deployment IaC checks in pull requests, image gates in build pipelines and continuous account monitoring.
The 9 top options reviewed
The nine options below split into four CNAPPs with deep cloud context and five tools rooted in vulnerability management or exposure scanning. Each review uses the same format.
Upwind: best for runtime-based vulnerability prioritization
Customer rating: 4.8/5 from 88 reviews on Gartner Peer Insights (October 2026).
Upwind is a runtime-first CNAPP that pairs agentless discovery with lightweight eBPF sensors. Its vulnerability findings reflect what is actually running, not everything installed in an image or disk. That runtime evidence separates CVEs in loaded, reachable packages from theoretical ones, so DevSecOps teams can work a short fix list instead of the full CVE backlog.
- ✓Prioritizes CVEs by whether the vulnerable package is loaded at runtime, reachable, internet-exposed and exploitable.
- ✓Adds context from CSPM, CIEM, API security and DSPM. A CVE on a workload with an identity that is actually used, or with an API that carries sensitive data, rises above an isolated finding.
- ✓Links scanning to response through cloud detection and response. Its Agentic Pack AI agents investigate threats, validate exposure and generate fixes using runtime context.
- ✓Supports shift-left workflows with IaC scanning, CI/CD and SBOMs. It routes prioritized findings to Jira, ServiceNow, PagerDuty and AWS Security Hub.
Deployment notes: eBPF sensors run on VMs, containers and Kubernetes nodes (EKS, AKS, GKE and OKE). Agentless discovery covers the wider cloud account. Pricing model: per resource unit, available on AWS Marketplace.
Wiz: best for cloud-native multi-cloud teams
Customer rating: 4.8/5 from 284 reviews on Gartner Peer Insights (October 2026).
Wiz is an agentless CNAPP covering CSPM, CWPP, CIEM, detection and response, DSPM, API and AI security. Its main draw is attack path analysis. Reviewers describe going from hundreds of irrelevant findings to a handful of actionable issues.
- ✓Prioritizes by reachability, loaded packages, internet exposure and exploitability.
- ✓Covers IaC (Terraform, CloudFormation, ARM, Kubernetes), CI/CD, and SBOMs in SPDX and CycloneDX formats, and traces runtime findings back to the commit or Dockerfile.
- ✓Maps findings to CIS, NIST, SOC 2, PCI-DSS and HIPAA, and integrates with ServiceNow, Jira, Zendesk, SIEM and SOAR.
- ✗One reviewer says detection and response capabilities still need development.
- ✗Reviewers find it better suited to hands-on practitioners than to GRC teams that need high-level reporting.
Deployment notes: Wiz’s sensor cannot run on Fargate, serverless platforms or managed services without node access. Pricing model: quote-based and scaled by workload count.
Orca Security: best for compliance-heavy multi-cloud teams
Customer rating: 4.7/5 from 243 reviews on Gartner Peer Insights (October 2026).
Orca uses agentless SideScanning, which reads workload data from block storage and cloud APIs across AWS, Azure and GCP. Its strengths are compliance breadth and the explicit exploitability signals in its prioritization.
- ✓Prioritizes by reachability, runtime-loaded packages, internet exposure, public exploit code, unauthenticated remote exploitability and CISA KEV listing.
- ✓Supports NIST SP 800-53, NIST CSF, DISA STIG, ISO 27001, PCI DSS, HIPAA, GDPR, SOC 2, FedRAMP and CIS Benchmarks.
- ✓Offers IaC scanning, IDE and CI/CD gating, SAST, SCA, secrets detection and SBOM generation, with Jira, ServiceNow, Azure DevOps, GitHub and GitLab integrations.
- ✗Reviewers report noisy alerts for EKS workloads and limited compliance customization.
- ✗Some reviewers cite documentation gaps and difficulty connecting Chinese cloud providers.
Deployment notes: Orca’s sensor does not run on Fargate or GKE Autopilot. Pricing model: custom quotes through private offers, available on AWS and Azure Marketplace.
Microsoft Defender for Cloud: best for Azure-centric organizations
Customer rating: 4.4/5 from 145 reviews on Gartner Peer Insights (October 2026).
Defender for Cloud analyzes VM disk snapshots out of band and deletes them after collecting metadata. It covers Azure, AWS, GCP and on-premises servers through Azure Arc. Its prioritization draws on Microsoft ecosystem signals such as threat intelligence and Defender EDR breach data. It also consolidates functions that AWS splits across GuardDuty, Inspector and Security Hub.
- ✓Covers AKS, EKS, GKE (including Autopilot) and Red Hat OpenShift 4.6+ in preview.
- ✓Ships with the Microsoft Cloud Security Benchmark, NIST CSF v2.0, PCI DSS v4.0.1, ISO 27001/27002/27017, HITRUST, GDPR, NIS2, CIS and CMMC.
- ✗Reviewers report high alert volume and generic recommendations that need significant tuning.
- ✗Native SIEM, ticketing and CI/CD integrations are not explicitly documented as out of the box, and reviewers say costs need careful management.
Deployment notes: the sensor does not run on Fargate or serverless functions. Pricing model: per protected resource (servers, databases, storage, containers), available on Azure Marketplace.
Qualys VMDR: best for large and hybrid programs
Qualys VMDR combines detection, prioritization, remediation, asset discovery, patching and compliance in one suite. It makes the most sense when cloud is one part of a larger estate that also includes data centers and endpoints.
- ✓Pairs patch management with detection, which shortens the path from finding to fix.
- ✗Our sources position it for broad VM programs. Verify its Kubernetes posture, IaC and identity coverage in a PoC.
Pricing model: not published in our sources, so confirm the billing unit (per asset, per IP or per agent).
Tenable Nessus: best for broad vulnerability assessment
Nessus is a widely trusted scanner known for its deep plugin library and strong assessment coverage. Pick it when you need thorough host-level checks.
- ✓Offers broad assessment coverage across operating systems and applications through its plugins.
- ✗It is built as an assessment scanner, so test whether it provides cloud misconfiguration, runtime and attack path context before treating it as your cloud tool of record.
Pricing model: not published in our sources.
Rapid7 InsightVM: best for continuous vulnerability management
InsightVM focuses on continuous vulnerability management with live dashboards and remediation tracking. It suits teams that measure SLA performance on fixes.
- ✓Remediation tracking supports ownership reporting across DevOps and SecOps.
- ✗Our sources do not detail its container, Kubernetes or IaC depth, so verify these in a PoC.
Pricing model: not published in our sources.
CrowdStrike Falcon Spotlight: best for existing Falcon customers
Falcon Spotlight provides cloud-native vulnerability assessment with continuous monitoring, asset discovery and contextual risk scoring. It is the obvious choice when Falcon is already your endpoint platform.
- ✓Continuous monitoring avoids gaps between scheduled scans.
- ✗Verify its coverage of cloud configuration, IaC and identities, which our sources do not confirm.
Pricing model: not published in our sources.
Intruder: best for lean teams watching external exposure
Intruder focuses on continuous monitoring of external exposure and is a good fit for smaller security teams. It works as a fast first layer that answers one question: what can an attacker see from the internet?
- ✓Narrow scope keeps findings focused on internet-facing risk.
- ✗It does not replace workload, Kubernetes or IaC scanning inside your accounts.
Pricing model: not published in our sources.
Free and open-source cloud vulnerability scanners
Good free cloud vulnerability scanners exist, but each covers a narrow layer and needs engineering time to run and maintain.
- ✓Trivy: the Cloud Security Alliance’s research note on TeamPCP’s cloud-native kill chain describes Trivy as one of the most widely deployed open-source container security scanners, in a study of how attackers weaponize scanners.
- ✓OpenVAS: a self-hosted open-source scanner with no vendor lock-in, though community feedback says it can be hard to configure.
- ✓Point Wild’s who-touched-my-packages (wtmp): a free tool released in March 2026 that detects malicious packages and credential exfiltration, with CLI, API and GitHub integration.
- ✓Qualysec Free Website Vulnerability Scanner: an online scanner for cloud-hosted websites that needs no setup.
Scanners run with privileged CI tokens, which makes them supply-chain targets. Pin scanner images by digest, verify release signatures and scope pipeline credentials to read-only access.
Open source is enough when a small team runs a few clusters, scans images in CI and can triage results by hand. Enterprises need a CNAPP or VM platform once they must correlate findings across hundreds of accounts, map them to compliance frameworks, route them to owners and prove remediation to auditors. Online, SaaS-based scanners suit teams that do not want to install software. They connect through read-only cloud roles, and sensors remain optional.
How we evaluated these scanners
We scored each scanner on cloud coverage depth, prioritization quality, shift-left support, operational fit, compliance reporting and pricing clarity. Our sources were vendor documentation, third-party analyses and Gartner Peer Insights reviews current as of October 2026.
- Coverage depth (25%): clouds, managed Kubernetes services, serverless and identity coverage, including documented gaps such as where sensors cannot run.
- Prioritization (25%): use of reachability, runtime-loaded packages, internet exposure, exploit intelligence and attack paths.
- Shift-left and remediation (20%): IaC formats, CI/CD gating, SBOMs, runtime-to-code tracing and ticketing.
- Operational fit (15%): deployment model, permissions and time to first prioritized findings.
- Compliance and reporting (10%): named frameworks and audit exports.
- Pricing clarity (5%): a published billing unit and marketplace availability.
Where our sources did not confirm a capability, we marked it “Verify” rather than assume it. We also weighted the shifts shaping cloud scanning in 2026:
- ✓Agentless-first discovery combined with optional runtime sensors.
- ✓Identity-centric risk, where IAM permissions decide which CVEs matter.
- ✓AI-assisted triage and fix generation.
- ✓Unified CNAPP platforms that replace point tools.
- ✓Runtime-to-build correlation that sends fixes to the owning repository.
Where Upwind fits in a cloud scanning stack
Upwind fits teams that want to prioritize vulnerabilities by what is running rather than by what static scans report. It is a runtime-first CNAPP that combines agentless discovery with lightweight eBPF sensors on VMs, containers and Kubernetes (EKS, AKS, GKE and OKE). It is rated 4.8/5 from 88 reviews on Gartner Peer Insights as of October 2026. Reviewers say it caught significant vulnerabilities that their other scanners missed. A few reviewers note that its GCP support is less mature than its AWS coverage. For a wider shortlist, compare it against the best CNAPP tools.
- ✓Ranks CVEs by whether they are reachable, loaded, internet-exposed and exploitable.
- ✓Covers CSPM, CWPP, CIEM, DSPM, API security and cloud detection and response.
- ✓Scans IaC, integrates with CI/CD and SBOMs, and traces runtime findings to the line of code.
- ✓Integrates with Jira, ServiceNow, PagerDuty, AWS Security Hub, Terraform and CloudFormation.
- ✓Priced per resource unit and available on AWS Marketplace.
Bottom line: match the scanner to the risk
The right scanner is the one that covers your riskiest layer and turns findings into a short, defensible fix list. Multi-cloud and Kubernetes-heavy teams should start with a CNAPP such as Wiz or Orca, or with a runtime-first platform. Azure-centric organizations get the most from Defender for Cloud. Hybrid enterprises often keep Qualys VMDR, Nessus or InsightVM for data centers and add cloud context on top. Lean teams can start with Intruder and open-source tools. Whichever cloud vulnerability scanner you shortlist, run the proof of concept on real accounts, measure the prioritization funnel, and assign one tool of record per finding type before you sign.
FAQ
What should a cloud vulnerability scanner cover?
The article says you should judge a cloud vulnerability scanner by the layers it covers: cloud configuration, VMs and workloads, containers, Kubernetes, infrastructure as code and identities. The right choice depends on where your real cloud risk lives, not on how many CVEs the tool reports.
Why is CVE count a poor way to choose a scanner?
Because the best tools prioritize exploitable risk, not raw volume. This guide recommends filtering findings by whether the image is actually running, whether the package is loaded at runtime, whether the workload is internet-exposed and whether public exploit code or a CISA KEV listing exists.
Which scanners are best for multi-cloud environments?
For multi-cloud teams, the article recommends shortlisting Wiz, Orca Security and Microsoft Defender for Cloud. The priority is equal service coverage across AWS, Azure and GCP, plus one normalized way to score and prioritize risk.
Can agent-based cloud scanners run on Fargate or other serverless platforms?
Not always. The article notes that agent-based or sensor-based scanners cannot run on AWS Fargate or other serverless platforms that hide the node. Serverless-heavy teams should favor agentless or API-based coverage instead.
How long should a proof of concept for a cloud vulnerability scanner last?
The guide recommends a two-to-four-week proof of concept on real production and non-production accounts. It suggests timing inventory speed, seeding known issues, comparing the top findings with known risks, testing Jira or ServiceNow workflows and measuring how quickly fixes are marked resolved.
