You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Azure Resource Graph (ARG) provides a REST API that can be used to programmatically access vulnerability assessment results for both Azure registry and runtime vulnerabilities recommendations.
16
16
Learn more about [ARG references and query examples](/azure/governance/resource-graph/overview).
17
17
18
-
Azureand AWS container registry vulnerabilities sub-assessments are published to ARG as part of the security resources. Learn more about [security sub-assessments](/azure/governance/resource-graph/samples/samples-by-category?tabs=azure-cli#list-container-registry-vulnerability-assessment-results).
18
+
Azure, AWS, and GCP container registry vulnerabilities sub-assessments are published to ARG as part of the security resources. Learn more about [security sub-assessments](/azure/governance/resource-graph/samples/samples-by-category?tabs=azure-cli#list-container-registry-vulnerability-assessment-results).
19
19
20
20
## ARG query examples
21
21
22
22
To pull specific sub assessments, you need the assessment key.
23
-
* For Azure container vulnerability assessment powered by MDVM the key is `c0b7cfc6-3172-465a-b378-53c7ff2cc0d5`.
24
-
* For AWS container vulnerability assessment powered by MDVM the key is `c27441ae-775c-45be-8ffa-655de37362ce`.
23
+
* For Azure container vulnerability assessment powered by MDVM, the key is `c0b7cfc6-3172-465a-b378-53c7ff2cc0d5`.
24
+
* For AWS container vulnerability assessment powered by MDVM, the key is `c27441ae-775c-45be-8ffa-655de37362ce`.
25
+
* For GCP container vulnerability assessment powered by MDVM, the key is `5cc3a2c1-8397-456f-8792-fe9d0d4c9145`.
25
26
26
27
The following is a generic security sub assessment query example that can be used as an example to build queries with. This query pulls the first sub assessment generated in the last hour.
"description": "This vulnerability affects the following vendors: Alpine, Debian, Libtiff, Suse, Ubuntu. To view more details about this vulnerability please visit the vendor website.",
| NotApplicable | string | Assessment for this resource did not happen |
667
+
| NotApplicable | string | Assessment for this resource didn't happen |
512
668
| Unhealthy | string | The resource has a security issue that needs to be addressed |
513
669
514
670
### SecuritySubAssessment
@@ -526,7 +682,7 @@ Security subassessment on a resource
526
682
| properties.id | string | Vulnerability ID |
527
683
| properties.impact | string | Description of the impact of this subassessment |
528
684
| properties.remediation | string | Information on how to remediate this subassessment |
529
-
| properties.resourceDetails | ResourceDetails: <br> [Azure Resource Details](/azure/defender-for-cloud/subassessment-rest-api#resourcedetails---azure) <br> [AWS Resource Details](/azure/defender-for-cloud/subassessment-rest-api#resourcedetails---aws)| Details of the resource that was assessed |
685
+
| properties.resourceDetails | ResourceDetails: <br> [Azure Resource Details](/azure/defender-for-cloud/subassessment-rest-api#resourcedetails---azure) <br> [AWS/GCP Resource Details](/azure/defender-for-cloud/subassessment-rest-api#resourcedetails---aws--gcp)| Details of the resource that was assessed |
530
686
| properties.status |[SubAssessmentStatus](/azure/defender-for-cloud/subassessment-rest-api#subassessmentstatus)| Status of the subassessment |
531
687
| properties.timeGenerated | string | The date and time the subassessment was generated |
0 commit comments