Edit

Build a Cloud Security Explorer query to identify software vulnerabilities in virtual machines (VMs) and container images

You can use Cloud Security Explorer to identify software vulnerabilities. The following examples show how to build queries for virtual machines (VMs) and container images.

For an introduction to Cloud Security Explorer queries, see Build queries with Cloud Security Explorer.

Create a query to identify software vulnerabilities in VMs

To create a query that finds software vulnerabilities in VMs:

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Cloud Security Explorer.

    Screenshot of main page of Cloud Security Explorer.

  3. Filter for the software installed on VMs.

    Screenshot of Cloud Security Explorer query options to retrieve list of VMs with software installed.

  4. Select View details for the VM you want to investigate.

  5. In the Result details pane, go to Insights and select the software from the drop-down list for review.

    Screenshot shows results of Cloud Security Explorer query to retrieve VMs with software installed.

  6. View the details of the installed software in the Insights section.

    Screenshot shows Cloud Security Explorer query result details and insight results from the selected VM.

Create a query to identify software vulnerabilities in container images

To create a query that finds software vulnerabilities in container images:

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Cloud Security Explorer.

    Screenshot of main page of Cloud Security Explorer.

  3. Filter for the software installed in container images.

    Screenshot of Cloud Security Explorer query options to retrieve list of container images with software installed.

  4. Select View details for the container image you want to investigate.

  5. In the Result details pane, go to Insights and select the software from the drop-down list for review.

    Screenshot shows results of Cloud Security Explorer query to retrieve container images with software installed.

  6. View the details of the installed software in the Insights section.

    Screenshot shows Cloud Security Explorer query result details and insight results from the selected containers image.