AWS security scanner
The AWS security scanner that explains what it finds
Most AWS security scanners hand you a long list of findings and leave you to work out what matters. bearhug scans continuously using AWS Security Hub and GuardDuty, ranks findings by severity, explains each one in plain English and lets you fix common issues in one click.
What bearhug scans for
- Configuration vulnerabilities from the Security Hub security standards you have enabled, such as public buckets, open ports and missing encryption.
- Threat detections from Amazon GuardDuty, such as unusual API calls or signs of compromised credentials.
- Compliance gaps, with findings mapped to SOC 2, ISO 27001, PCI DSS, GDPR and Cyber Essentials controls.
bearhug does not currently scan application code, container images or operating system packages for software vulnerabilities. It focuses on the configuration and threat findings behind many AWS security incidents.
How the scan works
bearhug is agentless. When you connect an AWS account, a CloudFormation stack creates a read-only IAM role and an Amazon EventBridge rule and enables Security Hub and GuardDuty. Findings from Security Hub and GuardDuty then stream to bearhug as AWS raises them. bearhug ranks them by severity, explains them in plain English and matches them with a recommended fix.
Every finding keeps the severity AWS assigns, from critical through high, medium and low to informational, so the dashboard always shows the most serious issues first. Critical and high findings that are new also trigger a plain-English email alert.
Because bearhug reads findings from AWS services rather than probing your instances, scanning has no effect on the performance of your applications. See the full how it works details.
Scanner vs CSPM: what is the difference?
A scanner runs a check; a CSPM keeps checking, tracks trends and helps you fix. bearhug does both for AWS.
A scanner that runs once a quarter tells you what was wrong on the day it ran. By the next deployment, the picture has changed. CSPM keeps watching, shows whether your posture is improving and helps you close findings rather than just list them. Read more about AWS CSPM.
How it compares with other AWS security tools
| AWS Security Hub alone | Enterprise CNAPP | bearhug | |
|---|---|---|---|
| Plain-English explanations | No, technical findings only | Varies | Yes, for every finding |
| One-click fixes | No, build your own automation | Some | Yes, for supported findings, with rollback |
| Price | Charged by AWS, per resource or by usage | $20,000+ a year | $100 per AWS account per month, plus AWS charges |
| Set-up time | Enable and configure in the console | Weeks | Under five minutes |
See the full AWS Security Hub vs bearhug comparison, or our guide to the best CSPM tools for start-ups.
What to do with your first scan results
- Start with critical and high findings. These are the issues most likely to lead to exposed data or a compromised account.
- Close public access first. Public S3 buckets and security groups open to the internet are the quickest wins, and bearhug can fix both in one click.
- Tighten IAM next. Remove unused access keys, enable MFA and reduce broad permissions.
- Turn on logging and encryption. Enable CloudTrail and encryption at rest so you are ready for an investigation or an audit.
- Watch the trend. Use the daily trend chart to confirm that open findings are falling week by week.
Configuration scanning and vulnerability scanning
The phrase ‘security scanner’ covers two different jobs. Software vulnerability scanning, which Amazon Inspector provides on AWS, looks for known vulnerabilities in the packages and code running on your instances, containers and functions. Configuration scanning looks at how your AWS services are set up: who can access what, what is exposed to the internet and what is logged and encrypted.
Both matter, but configuration mistakes are often the easier route in, because they need no exploit at all. A public bucket or an open database port is simply there to be found. bearhug focuses on configuration and threat detection today, using AWS Security Hub and Amazon GuardDuty.
What makes a good AWS security scanner
- Agentless. Nothing to install, patch or keep running on your servers.
- Continuous. Findings arrive as your environment changes, not once a quarter.
- Prioritised. Critical and high issues are obvious, so you know where to start.
- Explained. Every finding says what is wrong, why it matters and how to fix it.
- Actionable. Common issues can be fixed directly, with a way to roll back.
- Predictable to run. Clear pricing that does not grow with every new resource.
Who uses bearhug as their AWS security scanner
bearhug suits teams that want the coverage of an AWS security scanner without adding another specialist tool to learn and maintain.
- Start-ups and SMBs that need to show customers and investors their AWS account is secure.
- Engineering teams without a security engineer, who need findings they can act on without translation.
- Teams preparing for SOC 2 or ISO 27001, who want AWS findings mapped to the controls auditors ask about.
- Anyone already using Security Hub who finds its raw findings hard to prioritise.
Every connected account costs $100 per month, with every feature included. See pricing and cost examples.
AWS security scanner questions
Yes. bearhug uses AWS-native services and a CloudFormation stack. There is nothing to install on your servers.
Findings stream continuously as AWS generates them, so there is no scan schedule to manage.
No. bearhug reads findings from AWS services and does not scan your instances directly.
Not currently. bearhug covers configuration and threat findings from AWS Security Hub and Amazon GuardDuty. It does not scan application code, container images or operating system packages.
bearhug works in any AWS Region where Security Hub is available. Findings come from the controls enabled in each Region, and some controls are not available in every Region. Findings from every connected account appear in the same dashboard.
bearhug costs $100 per AWS account per month, with every feature included. It is billed in USD through AWS Marketplace, and any Security Hub or GuardDuty charges are billed separately by AWS.
Connect in five minutes and start scanning your AWS account
14-day free trial. The paid plan is $100 per AWS account per month, billed through AWS Marketplace.
No credit card. No procurement. Starts from your AWS console.