Skip to content

Infrastructure Discovery

Automating Cloud Infrastructure Discovery is a critical component of Cloud Security Posture Management (CSPM) and compliance automation. By programmatically inventorying cloud assets, organizations can identify misconfigurations, track resource usage, and ensure adherence to regulatory standards. Manual discovery methods are error-prone and time-consuming, making automation essential for maintaining visibility across multi-cloud environments. Tools like cloud-asset-inventory (a Terraform module) and native CSP tools (AWS Config, Azure Blueprints, GCP Asset Inventory) enable scalable, repeatable discovery workflows that integrate with CSPM platforms.


Native Cloud Provider Tools

AWS: AWS Config & CloudTrail

AWS Config continuously audits and records resource configurations, while CloudTrail tracks API activity. Together, they provide a comprehensive inventory of infrastructure changes.
Example:

# List all EC2 instances via AWS CLI  
aws ec2 describe-instances --query 'Reservations[].Instances[].InstanceId' --output text

Azure: Azure Blueprints & Resource Graph

Azure Blueprints enforces standardized resource templates, while the Resource Graph API provides a unified view of all Azure resources.
Example:

# Query Azure Resource Graph for virtual machines  
az graph query -q 'resources | where type == "microsoft.compute/virtualmachines" | project name, location'

GCP: Cloud Asset Inventory

GCP’s Cloud Asset Inventory (CAI) exports resource metadata to Cloud Storage or BigQuery, enabling centralized auditing.
Example:

# Export all GCP resources to a CSV file  
gcloud asset export --inventory --output-file=inventory.csv


Third-Party Tools for Multi-Cloud Discovery

cloud-asset-inventory (Terraform Module)

This tool automates discovery of AWS, Azure, and GCP resources by querying native APIs and generating Terraform state files. It integrates with CSPM platforms like Prisma Cloud and CloudHealth.
Example:

# Terraform module to inventory AWS resources  
module "aws_inventory" {
  source = "github.com/hashicorp/terraform-cloud-asset-inventory//aws"
  region = "us-west-2"
}

Palo Alto Prisma Cloud

Prisma Cloud’s asset discovery agent scans cloud environments and provides real-time visibility. It supports integration with CSPM tools via APIs.
Example:

# Prisma Cloud CLI to list all cloud resources  
prisma cloud inventory list --format=json

CloudHealth by VMware

CloudHealth’s agent-based discovery scans on-premises and cloud environments, offering cost and security insights.
Example:

# CloudHealth CLI to export asset inventory  
cloudhealth export --format=csv --output=assets.csv


Integration with CSPM Platforms

Automated discovery tools feed data into CSPM platforms via APIs or integrations. For example:
- Prisma Cloud: Uses cloud-asset-inventory to populate its asset database.
- CloudHealth: Syncs inventory data with CSPM tools for policy enforcement.
- AWS Security Hub: Aggregates findings from AWS Config and third-party tools into a centralized dashboard.

Diagram:

[Cloud Provider APIs]  
       |  
       v  
[Discovery Tool (e.g., cloud-asset-inventory)]  
       |  
       v  
[Data Export (CSV/JSON)]  
       |  
       v  
[CSPM Platform (e.g., Prisma Cloud, CloudHealth)]  
       |  
       v  
[Policy Enforcement & Compliance Reporting]  


Key takeaways

  • Automation is non-negotiable: Manual discovery is impractical for large-scale multi-cloud environments.
  • Native tools are foundational: AWS Config, Azure Blueprints, and GCP CAI provide standardized discovery.
  • Third-party tools bridge gaps: cloud-asset-inventory and CloudHealth enable cross-cloud visibility.
  • Integration with CSPM is critical: Discovery data must flow into security and compliance platforms for actionable insights.