Skip to main content

Creating a Cloud Security Misconfiguration Scan

Overview

This guide explains how to configure and launch a Cloud Security Misconfiguration (CSPM) scan in DeepTraQ. CSPM scans analyze your cloud infrastructure to detect configuration weaknesses, security risks, and compliance gaps across cloud resources.

DeepTraQ allows you to run comprehensive infrastructure scans, privileged user assessments, and workload exposure checks. The platform also uses AI to convert scan findings into actionable security insights and remediation recommendations.


Supported Platforms

DeepTraQ CSPM scans support the following cloud environments:

  • AWS
  • Azure
  • Google Cloud Platform (GCP)
  • Oracle Cloud Infrastructure (OCI)

Prerequisites

  • A cloud account integration must be configured in DeepTraQ
  • The target cloud environment must be accessible for scanning
  • Appropriate permissions must be granted for the selected cloud provider
  • Access to the Cloud Security Misconfigurations module

Steps

  1. Open the DeepTraQ platform.
  2. Navigate to Cloud Security Misconfigurations.
  3. Click New Scan to begin creating a CSPM scan.

This section lists all previously created scans and their current status.

Select the Cloud Provider

  1. Choose the cloud provider you want to scan.
  2. Supported providers include:
    • AWS
    • Azure
    • GCP
    • Oracle

For example, select AWS to scan an AWS cloud environment.

Select the Cloud Account

  1. Click Select Cloud Account.
  2. Choose the integrated cloud account you want to scan.

If the cloud provider is not integrated yet, refer to the cloud integration documentation before continuing.

Configure Scan Information

Provide basic information to identify the scan.

  1. Enter a Scan Name.
  2. Provide a Description explaining the purpose of the scan.
  3. Select the environment you want to scan.

This helps organize scans and makes them easier to track later.

Choose the Scan Type

Click Next to select the scan type. DeepTraQ provides three scan options:

  • Comprehensive Cloud Environment Scan
    Performs a full security assessment of your entire cloud infrastructure.

  • Privileged User Scan
    Identifies risks related to highly privileged identities and access policies.

  • Workloads Exposure Scan
    Detects exposed workloads and services that may be accessible from external networks.

For a full infrastructure assessment, select Comprehensive Cloud Environment Scan.

Configure Reporting Options

In the reporting configuration stage, DeepTraQ prepares scan outputs and AI-generated insights.

AI capabilities can transform raw findings into:

  • actionable remediation guidance
  • summarized security insights
  • prioritized findings for faster remediation

Configure Scan Options

Scan options allow you to customize how scan data is recorded and stored.

Recommended options include:

  • Save vulnerabilities with info-level findings for deeper visibility
  • Retain all scan artifacts for debugging and investigation

These options help during troubleshooting and allow deeper analysis of scan results.

Enable AI-Generated Reports (Optional)

You can enable AI-powered reporting to automatically generate:

  • summarized security insights
  • remediation guidance
  • prioritized vulnerability reports

If you prefer manual analysis, leave the AI option disabled.

Configure Scan Scheduling

DeepTraQ allows flexible scan scheduling for continuous cloud monitoring.

You can choose from the following options:

  • Run Immediately – Start the scan right away.
  • Schedule Later – Run the scan at a specific future time.
  • Periodic Scanning – Enable recurring scans for continuous monitoring.

Regular scans help detect configuration drift and new security risks.

Configure Scan Notifications

You can configure email notifications to receive scan summaries when the scan completes.

  1. Enable Trigger Email When Scan Is Done.
  2. Choose the notification recipients.

Notification options include:

  • Send notification to the currently logged-in user
  • Add additional email addresses and press Enter

These notifications provide quick visibility into scan outcomes.

Launch the Scan

After configuration is complete:

  1. Click Launch Scan.
  2. DeepTraQ begins scanning the cloud environment.

During the scan, DeepTrack AI analyzes the environment to identify security misconfigurations and generate reports.

View Created Scans

All configured scans appear in the Cloud Security Misconfigurations dashboard.

From this list you can:

  • view scan status
  • review completed scans
  • launch scans again when needed

Run an Existing Scan

To rerun a previously configured scan:

  1. Locate the scan in the dashboard.
  2. Click Run.

The scan will execute using the previously configured parameters.

Field Reference

FieldDescriptionExample
Cloud ProviderSelects the cloud platform to be scannedAWS
Cloud AccountThe integrated cloud account used for the scanProduction AWS Account
Scan NameUnique name used to identify the scanWeekly CSPM Audit
DescriptionShort explanation of the scan purposeSecurity posture review
EnvironmentDefines which environment is being scannedProduction
Scan TypeType of CSPM assessment performedComprehensive Cloud Environment Scan
Save Vulnerabilities with Info LevelsStores informational-level findings for deeper analysisEnabled
Retain Scan ArtifactsSaves all scan artifacts for troubleshootingEnabled
Enable AI ReportsEnables automated AI-generated remediation insightsEnabled
SchedulingDetermines when the scan runsImmediate
Email NotificationsSends summary emails when scan completessecurity-team@company.com