Skip to main content
availability

This integration is configured through the Invicti ASPM product.

CSPM overview

What is CSPM?

Cloud Security Posture Management (CSPM) provides continuous monitoring and assessment of cloud infrastructure configurations to identify misconfigurations, policy violations, and compliance gaps. It helps organizations maintain a secure cloud environment across providers such as AWS, Azure, and Google Cloud.

note

Invicti AppSec Core includes a preconfigured Invicti SCA scanner that is automatically activated with your package. The integrations on this page are for teams using Invicti ASPM who want to connect their own SCA tools instead. See AppSec Core scanners overview for details on the built-in scanner.

How it works

CSPM tools connect to your cloud environments and continuously evaluate resource configurations against security best practices and compliance frameworks. The assessment process includes:

  • Configuration assessment — checks cloud resources against security benchmarks such as CIS Benchmarks and cloud provider best practices.
  • Compliance monitoring — evaluates configurations against frameworks such as PCI DSS, HIPAA, ISO 27001, NIST, and SOC 2.
  • Drift detection — identifies when configurations change from their intended secure state.
  • Risk scoring — prioritizes findings based on severity and potential impact.

What it can discover

CSPM detects risks across the following categories:

CategoryExamples
Public storage accessS3 buckets, Azure Blob containers, or GCS buckets configured for unintended public access
Overly permissive IAMRoles granting wildcard permissions instead of least-privilege policies
Disabled loggingAudit logs, CloudTrail, or security monitoring turned off
Network misconfigurationsOverly open security groups, publicly exposed databases, unrestricted ingress/egress rules
Encryption gapsUnencrypted storage volumes, databases, or data in transit
Credentials managementLong-lived access keys, plaintext secrets in configuration
Compliance violationsDeviations from CIS Benchmarks, AWS Well-Architected Framework, and other standards

Supported CSPM tools

The following CSPM integrations are available through Invicti ASPM:

ToolCloud providers
Amazon Inspector CSPMAWS
Amazon Security HubAWS
Microsoft Defender for CloudAzure
WizMulti-cloud
Orca SecurityMulti-cloud
Prisma Cloud CSPMMulti-cloud
Lacework CSPMMulti-cloud
Sysdig CSPMMulti-cloud
CrowdStrike CSPMMulti-cloud
ProwlerAWS, Azure, GCP

Choosing a CSPM tool

If you need…Consider
AWS-native CSPMAmazon Inspector CSPM, Amazon Security Hub
Azure-native CSPMMicrosoft Defender for Cloud
Multi-cloud enterprise CSPMWiz, Orca, Prisma Cloud, Lacework
Open-source / no license costProwler
Runtime threat detection + CSPMCrowdStrike CSPM, Sysdig CSPM

Need help?

The Invicti Support team is ready to provide technical assistance. Go to Help Center

Was this page useful?