Skip to main content

Run the first scan

With an account connected, Argus is ready to evaluate it against the full check suite: hundreds of security checks across the services in use.

Launch it​

The connect wizard ends on a Scanning step once the connection test passes.

  • Free includes an automatic weekly scan. The step tells you when your first scan is starting (for a workspace with no scans yet); after that, Argus scans every week, 7 days after the last completed scan. The daily schedule is shown locked as a Pro feature. See Billing & plans.
  • Pro lets you choose. Scan every day and Run the first scan now are both on by default. The daily schedule starts with a scan right away, so with it on the first scan is already included; turn it off to run a single scan now, or neither. Skip for now leaves the account unscanned, and a schedule can be added any time from Scans → Schedules.

Later on Pro, go to Scans, click Launch scan, pick the account, optionally name the run, for example Pre-release audit, and choose Run now or Every day.

The run appears in the Scans list with a live progress bar. How long it takes depends on how many services and regions the account uses, and a run does not always begin the moment it is launched, since runs are processed one at a time. See Troubleshooting for what a run that looks stalled means.

Read the results​

When the scan completes, its row shows the trigger, the duration, and the result as fail and pass counts. From the row's actions menu:

  • View findings. Jumps to Findings scoped to this scan: every failed check ranked by severity, each with the affected resource, a risk explanation, and step-by-step remediation.
  • View compliance. How the run scores against compliance frameworks.
  • Download report. A ZIP with the full results. Reports are generated on demand, so the first download can take a moment.

Check the Overview​

The Overview dashboard now has data, across every connected account:

  • Headline tiles. Your posture (the share of checked findings that pass) with the change in failing findings versus last week once a week of history exists; open findings, with how many are muted and how many resources were scanned; Critical and High counts (failing findings only); and what is new since the last scan, with how many findings started passing. The findings tiles open the Findings page already filtered.
  • Posture score. The same pass rate as a 0-100 gauge: every finding counted once, none weighted.
  • Failing findings by severity. Click any segment of the donut to open the failing findings of that severity.
  • Compliance watchlist. Your five weakest frameworks, worst first, each with its passed, failed and manual requirements and a failing count beside its score. It counts requirements, not findings: a requirement passes only when it passes in every account, so a framework can read 0% while most of your checks pass. There is no averaged compliance score: each framework stands on its own.
  • Posture by area. The share of findings passing, weighted by risk and impact, overall and for four areas (IAM, Exposure, Logging and monitoring, Encryption), with its heaviest gaps. The overall is its own score, not an average of the areas, so one weak area can sit under a high overall. Area scores round down, so an area reads 100 only when nothing in it fails. It is not a compliance framework. It appears once a scan's reports are ready.
  • Exposure. Failing findings for internet-exposed resources, exposed secrets, privilege escalation and EC2 instances still allowing IMDSv1.
  • Accounts. The accounts with the most open findings, with their posture.

A sensible first triage​

  1. Open Findings. It opens on failing checks, sorted by severity.
  2. Work the Critical findings first. Each finding's detail includes remediation commands where available.
  3. For anything that is an accepted risk, such as a sanctioned public bucket or a deliberate wildcard, mute it with a reason instead of ignoring it.
  4. Re-scan after remediating and watch the New and Changed delta values to confirm fixes landed.