Skip to main content

Scan an EBS Snapshot

Mondoo can scan your EBS volume snapshots to evaluate the security and compliance of Linux-based EC2 instances. It doesn't require an agent or any connection to the instance that could impact your business applications.

Snapshot scanning with Mondoo relies on cnspec, Mondoo's CLI security tool.

Scan EBS volumes

Create a VM for EBS volume scanning

  1. Spin up a small EC2 instance (for example an Amazon Linux instance with the type t2.micro) where you'll attach the EBS snapshot.

  1. Install cnspec on the new instance and register it in the Mondoo Console.

Create an IAM policy for EBS volume scanning

  1. Log into the AWS console.
  2. Navigate to IAM.
  3. In the side navigation, select Policies.
  4. Select the Create policy button.
  5. Under Specify permissions select JSON, add the following block and select "Next":
"Version": "2012-10-17",
"Statement": [
"Action": [
"Resource": "*",
"Effect": "Allow"
"Action": [
"Resource": "*",
"Effect": "Allow"
"Condition": {
"Bool": {
"kms:GrantIsForAWSResource": "true"
"Action": "kms:CreateGrant",
"Resource": "*",
"Effect": "Allow"
  1. Under Policy details -> Policy name give the policy a name such as ebs-scanning-mondoo, assign tags and a description to the role (if you want), and then select Create policy.

Create an IAM role for EBS volume scanning

  1. Log into the AWS console.
  2. Navigate to IAM.
  3. Select Roles.
  4. Select Create Role.
  5. For the Trust entity type, select AWS service and for the Use case, select EC2, the select the "Next" button.
  6. Search for ebs in the Filter policies box, select the policy you just created ebs-scanning-mondoo, and then select the "Next" button.
  7. Under Role details in the field "Role name" give the role a name ebs, assign tags and a description to the role (if you want), and then select Create role.

Attach the new IAM role (ebs) to your new EC2 instance.

Your new role is ready for use and can be attached to existing EC2 instances, or to new EC2 instances as an instance profile when launching new instances.

Using your new EC2 instance for scanning

  1. Log into your new EC2 instance.

  2. Scan a snapshot from your new instance:

cnspec scan aws ec2 ebs snapshot SNAPSHOT_ID

For SNAPSHOT_ID, substitute the ID of the snapshot, for example snap-123456b123a123da2 .

Learn more

To learn about...Read...
Scanning with AWS SSMScan Using AWS Systems Manager
Scanning from a workstationScan from a Workstation
Continuous AWS scanningContinuously Scan AWS
cnspecThe cnspec documentation