Serverless function scanning

Prisma Cloud can scan serverless functions for vulnerabilities. Prisma Cloud supports AWS Lambda, Google Cloud Functions, and Azure Functions.
Serverless computing is an execution model in which a cloud provider dynamically manages the allocation of machine resources and schedules the execution of functions provided by users. Serverless architectures delegate the operational responsibilities, along with many security concerns, to the cloud provider. In particular, your app itself is still prone to attack. The vulnerabilities in your code and associated dependencies are the footholds attackers use to compromise an app. Prisma Cloud can show you a function’s dependencies, and surface the vulnerabilities in those dependent components.


For serverless, Prisma Cloud can scan Node.js, Python, Java, C#, Ruby, and Go packages. For a list of supported runtimes see system requirements.
Prisma Cloud scans are triggered by the following events:
  • When the settings change, including when new functions are added for scanning.
  • When you explicitly click the
    button in the
    Monitor > Vulnerabilities > Functions > Scanned Functions
  • Periodically. By default, Prisma Cloud rescans serverless functions every 24 hours, but you can configure a custom interval in
    Manage > System > Scan

Scanning a serverless function

Configure Prisma Cloud to periodically scan your serverless functions. Unlike image scanning, all function scanning is handled by Console.
  1. Open Console.
  2. Go to
    Defend > Vulnerabilities > Functions > Functions
  3. Click on
    Add scope
    . In the dialog, enter the following settings:
    1. (AWS only) Select
      Scan only latest versions
      to only scan the latest version of each function. Otherwise, the scanning will cover all versions of each function up to the specified
    2. (AWS only) Select
      Scan Lambda Layers
      to enable scanning function layers as well.
    3. (AWS only) Specify which regions to scan in
      AWS Scanning scope
      . By default, the scope is applied to
      Regular regions
      . Other options include
      China regions
      Government regions
    4. Specify a
      for the number of functions to scan.
      Prisma Cloud scans the X most recent functions, where X is the limit value. Set this value to '0' to scan all functions.
      For scanning Google Cloud Functions with GCP organization level credentials, the limit value is for the entire organization. Increase the limit as needed to cover all the projects within your GCP organization.
    5. Select the accounts to scan by credential. If you wish to add an account, click on
      Add credential
      If you create a credential in the credentials store (
      Manage > Authentication > Credentials store
      ), your service principal authenticates with a password. To authenticate with a certificate, create a cloud account.
    6. Click
  4. Click the green save button.
  5. View the scan report.
    Go to
    Monitor > Vulnerabilities > Functions > Scanned functions
    All vulnerabilities identified in the latest serverless scan report can be exported to a CSV file by clicking on the CSV button in the top right of the table.

View AWS Lambda Layers scan report

Prisma Cloud can scan the AWS Lambda Layers code as part of the Lambda function’s code scanning. This capability can help you determine whether the vulnerability issues are associated with the function or function Layers. Follow the steps below to view the Lambda Layers scan results:
  1. Open Console.
  2. Make sure you selected the
    Scan Lambda layers
    in the Defend > Vulnerabilities > Functions > Functions > Serverless Accounts >
    Function scan scope
  3. Go to
    Monitor > Vulnerabilities > Functions > Scanned functions
  4. Filter the table to include functions with the desired Layer by adding the
    You can also filter the results by a specific layer name or postfix wildcards. Example: Layers:* OR Layers:arn:aws:lambda:*
  5. Open the
    Function details
    dialog to view the details about the Layers and the vulnerabilities associated with them:
    1. Click on a specific function
    2. See the Function’s vulnerabilities, compliance issues and package info in the related tabs. Use the
      Found in
      column to determine if the component is associated with the Function or with the Function’s Layers.
    3. Use the
      Layers info
      tab to see the full list of the Function’s Layers, and aggregated information about the Layers vulnerabilities. In case that there are vulnerabilities associated with the layer you will be able to expand the layer raw to list all the vulnerabilities.

Authenticating with AWS

The serverless scanner is implemented as part of Console. The scanner requires the following permissions policy: