> ## Documentation Index
> Fetch the complete documentation index at: https://cloud-architect.ipoint-labs.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Find vulnerabilities on Inspector2 using Lambda scanning

> Hands-on lab · 45m

Launch this lab in the IP Lab Portal, then follow the steps below in the AWS console.

<a className="ip-lab-portal-btn" href="https://labs.intellectualpoint.com/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning" target="_blank" rel="noreferrer">
  Open IP Lab Portal
</a>

## Overview

#### Lab Details

1. The lab involves creating an inspector and lambda function
2. Trigging the lambda function to scan the inspector to finding the vulnerabilities
3. Duration: **1 hour**
4. AWS Region: **US East (N. Virginia) us-east-1**

#### Introduction

1. Amazon Inspector is a service provided by Amazon Web Services (AWS) that helps you to automatically assess the security and compliance of your AWS resources, including AWS Lambda functions.
2. It performs security assessments by analyzing your resources and identifying potential vulnerabilities and deviations from best practices.
3. Learn how to navigate the Amazon Inspector console to view detailed findings of scanned Lambda functions, including CVE identifiers and severity ratings.
4. Inspector v2 integrates seamlessly with AWS services such as EC2, ECR, and Lambda, allowing for continuous vulnerability assessment and management.
5. In this lab, you will learn how to scan your AWS Lambda functions using Amazon Inspector

#### Architecture Diagram

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/001.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=fdbbdb7f2b5d3fc5457f2d055d8fc14c" alt="" width="624" height="373" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/001.png" />

#### Task Details

1. Sign in to AWS Management Console
2. Creating an inspector2 and activating it
3. Creating a lambda function and the layers
4. Triggering the lambda function
5. Scanning the lambda function to check the vulnerabilities

#### Launching Lab Environment

1. To Launch the lab Environment, Click On The **Start Lab** Button.
2. Please Wait Until The Cloud Environment Is Provisioned. It Will Take Less Than A Minute To Provision.
3. Once The lab Is Started, You Will Be Provided With **IAM User Name, Password, Access Key, And Secret Access Key**.

> **Note :** You can only start one guided lab at any given time

## Lab guide

#### Lab Steps

#### Task 1: Sign in to AWS Management Console

1. Click On The **Open Console** Button, And You Will Get Redirected To AWS Console In A New Browser Tab.
2. On The AWS Sign-In Page, Leave The Account ID As Default. Never Edit/Remove The 12 Digit Account ID Present In The AWS Console. Otherwise, You Cannot Proceed With The Lab.
3. Now Copy Your **User Name** And **Password** In The Lab Console To The **IAM Username And Password** In AWS Console And Click On The **Sign In** Button.
4. Once Signed In To The AWS Management Console, Make The Default AWS Region As **US East (N. Virginia) Us-East-1**.

#### Task 2: Enable Amazon Inspector for your AWS Account

1. In the AWS console, search for **Amazon Inspector** and click on it.

2. Click on **Get started**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/002.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=503a55e2070a9de9df5ea2fb715570f7" alt="" width="1207" height="304" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/002.png" />

3. And you will be able to see **Activate Inspector**.

4. Click on the **Activate Inspector**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/003.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=28296b4feb5a74eccdb8b20c734789da" alt="" width="1871" height="450" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/003.png" />

5. In the left-side dashboard, scroll down and click on **Account management**.

6. Click on the **Activate** button.

7. Check AWS Lambda Standard scanning.

* **Lambda standard scanning** — With this option enabled, Amazon Inspector only scans for package dependencies in your Lambda functions and associated layers.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/004.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=acb3a58d4457aac7485f11d146c92162" alt="" width="1837" height="453" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/004.png" />

8. Click on **Submit**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/005.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=a5eedec29acaf607d97cada59635db2e" alt="" width="589" height="65" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/005.png" />

#### Task 3: Create a Lambda Function

1. Make sure you are in the **US East (N. Virginia)** region.

2. Go to the **Services menu** and click on **Lambda** under **Compute section**.

3. Click on the **Create a function** button.

4. Choose Author from scratch

* Function name : **testing\_lambda**
* Runtime : Select **Python 3.11**

5. Expand **Change default execution role** select **use an existing role** and select **Lambda\_role** from the drop-down.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/006.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=519117fb3be34ed43dce6bea6e2f4953" alt="" width="1222" height="666" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/006.png" />

6. Click on the **Create function** button.

7. If you scroll down a little bit, you can see the Code source section. Here we are going to replace the python function code.

8. Remove the existing code in AWS lambda\_function.py. Copy the below code and paste it into your **lambda\_function.py** file.

```
import json
import os
import paramiko

def lambda_handler(event, context):
    print("Hello world")
    os.system("ssh -h")
```

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/007.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=9087223ac9114144205ad2b523553c31" alt="" width="1222" height="703" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/007.png" />

9. click on **Deploy** button.

#### Task 4: Creating Layers for Lambda function

1. In the Lambda console, click on the **Layers** section in the left-hand navigation pane

2. Click on the **Create Layer** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/008.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=68fcfc8a6b9be5d30203627f997c736e" alt="" width="1222" height="338" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/008.png" />

3. Layer name: **paramiko\_layer**

4. Description: Creating a paramiko layer for the lambda function

5. Click on the below link to download the zip file to upload in the layers.

* [Paramiko\_layer](https://labresources.whizlabs.com/201bee982ab8b39f7f533332ebef383c/paramiko-test.zip)

6. Compatible architectures: **x86\_64**

7. Runtime: **python 3.11**

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/009.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=b1134023f8cb4cbf63321cd2e14552ba" alt="" width="1222" height="723" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/009.png" />

8. Click on the **Create** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/010.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=3dde0dbf2a30b6c1bde32c01df5623d8" alt="" width="1222" height="522" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/010.png" />

#### Task 5:  Adding the layers to the lambda function

1. In the Lambda console, click on the **function** you created earlier.

2. In the **Code** section, scroll down to the **Layers** section.

3. Click on the **Add Layer** button.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/011.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=3fb9909a0c3ba77f5205b597554db19f" alt="" width="1222" height="125" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/011.png" />

4. Go to the **Custom Layers** section.

5. Under the custom layers dropdown, choose the Paramiko layer you created earlier.

6. Click on the **version dropdown** and select the appropriate version.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/012.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=efd5421d1159278866c4d32a89003766" alt="" width="1222" height="445" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/012.png" />

7. Click the **Add** button.

8. After creating the layer scroll it will look like these.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/013.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=6eaa06ff74ebc7d3e51b5947a402e98d" alt="" width="1222" height="109" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/013.png" />

9. Now, go back to your Lambda function and click the **Test** button and click **Create new test event**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/014.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=6138056b8fdc6c09438a5a2594435dcc" alt="" width="1222" height="460" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/014.png" />

10. Enter the name as **lambda\_test** and click **Save**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/015.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=5605910dbe7fb04859d572bea063d67b" alt="" width="1020" height="958" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/015.png" />

11. Now click **Invoke** button. It will trigger the Inspector Lambda scanning.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/016.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=d05b4b4432c868b68b94a134da0dcc89" alt="" width="1222" height="490" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/016.png" />

#### Task 6: Finding the vulnerability for the Lambda function

1. Go back to the **Inspector** console.

2. Scroll down and click on **Resources coverage** from the left panel.

3. Click on the **Lambda functions** to see the status of the scanning.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/017.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=7a01dcd0f482ed5ba6161c75fb2a14d4" alt="" width="1222" height="522" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/017.png" />

4. Now click **Findings** from the left panel and click **By Lambda function**.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/018.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=5338fdafc7d35a8b26aa2233da915002" alt="" width="1222" height="321" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/018.png" />

5. Click on the **testing\_lambda** and scroll down, you will be able to see the different CVE names.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/019.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=c4f9dcffb2fc3289e39ef36858e6a53c" alt="" width="1222" height="689" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/019.png" />

6. Click on any **CVE title** to see the findings details.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/020.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=e19f842e9441879bea9c9c2515ea6997" alt="" width="1222" height="668" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/020.png" />

7. Scroll down CVE tab to see more details.

8. In Vulnerability details click on the Vulnerability ID to see the National vulnerability database.

**National vulnerability database:**

* **Government Repository:** Managed by the U.S. National Institute of Standards and Technology (NIST).
* **Vulnerability Information:** Contains detailed data on known software vulnerabilities.
* **CVE Identifiers:** Uses Common Vulnerabilities and Exposures (CVE) identifiers for each vulnerability.
* **Severity Ratings:** Provides severity scores using the Common Vulnerability Scoring System (CVSS).
* **Impact Analysis:** Describes potential impacts on confidentiality, integrity, and availability.
* **Remediation Guidance:** Offers recommendations for fixing or mitigating vulnerabilities.
* **Search Tools:** Includes tools for searching and analyzing vulnerabilities.

<img src="https://mintcdn.com/ip-cloud-architect-pathway/m1eiflSdu4MAgXTP/images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/021.png?fit=max&auto=format&n=m1eiflSdu4MAgXTP&q=85&s=656ea760184beb3846914b2d7ff4916d" alt="" width="856" height="646" data-path="images/labs/find-vulnerabilities-on-inspector2-using-lambda-scanning/021.png" />

> **Do you know?**
> Amazon Inspector for Lambda functions provides advanced security features, including dependency vulnerability scanning, Lambda layer analysis, and environment variable inspection. It enforces least privilege, checks runtime policies for compliance, and evaluates network accessibility to prevent public exposure. Inspector also maps findings to compliance frameworks like PCI-DSS, HIPAA, and GDPR, ensuring regulatory adherence for serverless applications.

#### Completion and Conclusion

1. You Have Successfully logged into AWS console.
2. You Have Successfully created inspector2.
3. You Have Successfully created lambda.
4. You Have Successfully triggered the lambda scanning.
5. You Have Successfully found the vulnerability using lambda scanning.

#### End Lab

1. **Sign Out** Of AWS Account.
2. You Have Successfully Completed The Lab.
3. Once You Have Completed The Steps, Click On **End Lab** From Your IP Lab Portal And Wait Till The Process Gets Completed.

## What gets checked

When you press **Check my work**, the platform verifies each of these:

* **Create an AWS Lambda Function** — Check whether a Lambda Function is created or not
* **Check Lambda Findings in InspectorV2** — Check whether lambda findings are present or not

## Related help

* [FAQs and Troubleshooting](/aws-saa/support/faqs-and-troubleshooting)


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.