Skip to main content


mondoo scan aws ec2-ebs

Scan an AWS instance using an EBS volume scan

mondoo scan aws ec2-ebs user@host [flags]


      --annotation stringToString        annotation for asset (default [])
--ask-pass ask for connection password
--discover string enable the discovery of nested assets. Supported are 'all|instances|host-instances|container|container-images'
--discover-filter stringToString additional filter for asset discovery (default [])
--exit-0-on-success return 0 as exit code if the scan execution was successful
-h, --help help for ec2-ebs
--id-detector string user-override for platform id detection mechanism, supported are hostname, machine-id, aws-ec2, cloud-detect, ssh-host-key, transport-platform-id
-i, --identity-file string Selects a file from which the identity (private key) for public key authentication is read
--incognito incognito mode. do not report scan results to the Mondoo platform.
--insecure disable TLS/SSL checks or SSH hostkey config
--inventory-ansible set inventory format to ansible
--inventory-domainlist set inventory format to domain list
--inventory-file string path to inventory file
--no-pager disable interactive scan output pagination
--option stringToString addition connection options, multiple options can be passed in via --option key=value (default [])
-o, --output string set output format. one of csv|json|junit|yaml
--pager string enable scan output pagination with custom pagination command. default is 'less -R'
-p, --password string password e.g. for ssh/winrm
--path string path to a local file or directory that the connection should use
--policy strings list of policies to be executed (requires incognito mode), multiple policies can be passed in via --policy POLICY
--policy-bundle strings path to local policy bundle file
--score-threshold int if any score falls below the threshold, exit 1 (default 100)
--sudo run with sudo

Options inherited from parent commands

      --config string      config file (default is $HOME/.config/mondoo/mondoo.yml)
--log-level string set log-level: error, warn, info, debug, trace (default "info")
-v, --verbose verbose output