Edit

View and remediate vulnerabilities for running containers

Defender for Cloud helps you find and fix vulnerabilities in images that your Kubernetes workloads use.

To create these findings, Defender for Cloud first builds a list of your Kubernetes workloads. It uses supported discovery and protection components to do this. Then it matches that list against known vulnerability data for the images those workloads run.

Findings for running containers appear as security recommendations. The following steps use the Flat list view, which shows results at the resource level. Learn more about reviewing recommendations by title or by resource.

Note

You might see both grouped and individual recommendation formats in the portal during this transition. Learn more about transitioning from grouped to individual recommendations.

Prerequisites

Before you begin, enable Defender for Containers or Defender CSPM on your subscription. Turn on one of these component sets:

  • Registry access and either Kubernetes API access or Defender sensor. This option links scanned registry images to running workloads.
  • Agentless scanning for machines and either Kubernetes API access or Defender sensor. This option checks for runtime vulnerabilities without a registry.

View vulnerabilities for running containers

To view vulnerabilities for a running container:

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Recommendations.

  3. Select the Vulnerabilities tab.

  4. Select the Flat list view.

  5. Select Add filter.

  6. Select Resource type.

  7. Select Container.

    Screenshot of the Resource type filter in Microsoft Defender for Cloud Recommendations with Container selected.

  8. Select Apply.

  9. Select a recommendation.

  10. Review the details, including risk info, fix steps, and metadata.

  11. Select the Associated CVEs tab to see the CVEs for that item.

  12. Select a CVE to view its severity, affected components, and fix version.