Agentic Agentless Detection performs security checks on servers without installing an agent, and you can enable or disable the feature as needed.
What is Agentic Agentless Detection
The Agentless Detection feature allows you to assess the security risks of cloud servers without installing the Security Center agent. The feature scans the images of your servers, uses AI sandbox-based dynamic analysis, and performs multi-dimensional security checks in an isolated environment, including checks for vulnerabilities, malware, configuration baselines, and sensitive files. The feature also supports AI-powered vulnerability fixing.
How it works
Create a full-server image (host scan tasks only): Based on the task configurations, the system creates a full-server image for the disks of the target Elastic Compute Service (ECS) instance.
Share and mount: The system shares the created snapshot or image with the dedicated analysis cluster of Security Center.
Isolated scanning: In an isolated dedicated environment, the analysis engine mounts the file system of the snapshot or image and performs a security scan. The AI sandbox detonates suspicious files or images and analyzes their runtime behaviors to improve the accuracy of threat analysis. This process consumes no computing resources of the target server.
Report generation and cleanup: After the scan is complete, the system generates a risk report and automatically deletes the temporary image based on the configured policies to save storage costs.
Common use cases
"Zero-interference" risk assessment: Perform non-intrusive security risk assessment that consumes no resources on core production systems that cannot run an agent or cannot tolerate performance impact, to ensure business continuity.
Unified cross-platform asset security detection: Cover all asset types, including legacy and proprietary systems, and quickly assess the overall security posture of a cross-platform environment from a unified view.
Visualized multi-dimensional risk detection: A single scan detects multi-dimensional risks such as vulnerabilities, malicious files, configuration baselines, and sensitive information, and visualizes the overall security posture.
Asset compliance and security review: Before you create instances or launch services, review the security of custom images and host snapshots to ensure that the delivered production environment meets security and compliance standards.
AI-powered automatic fixing loop: Based on the AI sandbox analysis results, the feature provides one-click or automated fixing suggestions and execution for risks that can be fixed, such as specific application vulnerabilities, baseline alerts, and malicious file alerts, to create a closed loop from risk detection to remediation.
Enable Agentic Agentless Detection
Activate the service
Log on to Security Center console.Select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
In the Overview page, find the Enable Pay-as-You-Go Service section and turn on the Agentic Agentless DetectionAgentic Agentless DetectionAgentless Detection switch.
On the service activation page, confirm the billing information (Agentless Detection and analysis is billed based on the volume of scanned data, vulnerability fixing is billed based on the number of fixed vulnerabilities, fees are billed on a daily basis, and you can cancel the service at any time), keep Enable policy (recommended) selected by default, and click Activate and Authorize.
ImportantAgentless Detection uses the pay-as-you-go billing method.
You can also go to the page, click Activate Now, and select the check box for the relevant terms of service.
Complete service authorization (first use)
When you use the feature for the first time, the system prompts you to authorize a service role. Follow the on-screen instructions to click Authorize Now.
NoteAfter the authorization succeeds, Security Center automatically creates the service-linked roles AliyunServiceRoleForSas and AliyunServiceRoleForSasAgentless. For more information about the two service-linked roles, see Service-linked roles for Security Center.
Authorization for Agentic Agentless Detection on encrypted Alibaba Cloud ECS disks (first use)
When you use the feature for the first time, if your ECS instances use encrypted disks (encrypted system disks or encrypted data disks) and you want to use Agentless Detection to check the security of the instances, complete the authorization by following the instructions in Authorize Agentless Detection for ECS encrypted disks.
Disable Agentic Agentless Detection
Ways to disable the feature:
In the Security Center console, go to the Overview page. In the Enable Pay-as-You-Go Service section, turn off the Agentic Agentless DetectionAgentic Agentless DetectionAgentless Detection switch.
In the Security Center console, go to the Agentless DetectionAgentless DetectionAgentless Detection page. In the Risk Detection section, click Suspended.
Data cleanup:
The results of detection tasks are retained for only 30 days and are automatically deleted after the retention period expires.
All scan task configurations are retained and are not deleted.
Billing
The fees that are generated when you use the Agentless Detection feature are described as follows:
Scanning and fixing fees (Agentless Detection)
Billing method: pay-as-you-go.
Billing cycle: calendar day.
Unit price:
Agentic Agentless Detection and analysis: USD 0.13/GB.
Agentic vulnerability fixing: USD 1.33/vulnerability.
Billing rules:
Agentic Agentless Detection and analysis: billed based on the actual data volume of the scanned image, instead of the total disk capacity.
Agentic vulnerability fixing: billed based on the number of vulnerabilities that are successfully fixed, instead of the number of tasks or attempts.
If a vulnerability exists on three hosts, fixing it on all three hosts counts as three successful fixes.
If a fixing task involves three vulnerabilities, fixing all the vulnerabilities counts as three successful fixes.
Agentic baseline check fixing and malicious file fixing: billed based on the number of alerts that are successfully fixed, instead of the number of tasks or attempts.
ECS resource usage fees
ImportantWe recommend that you select Retain Only At-risk Image when you configure a host detection task. This way, the system automatically deletes risk-free images after the scan is complete to save storage costs. For more information, see Retention period configuration.
Image fees: Detection tasks create images for your servers. The images are billed based on the image capacity used and the retention duration. The fees are charged by ECS. For more information, see Image billing.
Encrypted disk scanning resource fees: To scan encrypted ECS disks, the following resources are created in your account for each scan. Some of the resources incur a small fee and are released immediately after the scan is complete.
ECS instances: If the encrypted ECS disk that you want to scan is encrypted with a service key, a preemptible ECS instance is created for the encrypted disk scan. The fees are charged by ECS. For more information, see Instance type billing.
VPC instances: a virtual private cloud (VPC) instance named alibaba-cloud-security-scan-vpc. No fees are incurred for creating the instance.
vSwitch instances: a vSwitch instance named alibaba-cloud-security-scan-subnet. No fees are incurred for creating the instance.
FAQ
What are the differences between Agentless Detection and the anti-virus feature?
Item
Agentless Detection
Anti-virus
Working mode
Scans offline snapshots and uses AI sandbox-based dynamic analysis
Performs real-time online monitoring and scanning with both dynamic and static analysis
Server status
Can scan servers that are running or stopped
Can scan only servers that are running and whose agent is online
Detection scope
Vulnerabilities, baselines, malicious samples, and sensitive files.
Viruses, WebShells, intrusion behavior, and vulnerabilities
Handling capability
Supports detection, alerting, and allowlisting, and provides AI-powered automatic fixing or one-click fixing for specific risks.
Provides one-click quarantine, removal, and fixing capabilities.
Performance impact
None.
Minor (the agent occupies a small amount of system resources).
Billing method
Pay-as-you-go (billed by scanned GB).
Subscription (Anti-virus Edition or higher) or pay-as-you-go.
Scan mode
Supports full disk scans.
Supports quick scans and custom directory scans.
Can Agentless Detection automatically fix all risks?
No. Agentless Detection cannot automatically fix all risks. The feature supports AI-powered automatic fixing only for specific application vulnerabilities. For more information about the supported vulnerabilities, see Vulnerability fix support list.
NoteFixing is implemented by creating a new custom security image. The original image is not modified, which ensures business continuity and rollback capability.
For risks that cannot be automatically fixed, follow the handling suggestions on the risk details page to manually fix the risks.
How do I use the advanced detection feature on servers that are not deployed on Alibaba Cloud?
Agentless Detection currently supports access to Alibaba Cloud ECS instances, AWS EC2 instances, and Azure servers.
ImportantAzure servers can be connected for detection only in Outside Chinese Mainland. For more information, see Detect and fix risks.
For servers from other cloud providers or in on-premises data centers, we recommend that you install the Security Center agent and activate Anti-virus Edition or a higher edition to obtain comprehensive security protection capabilities. For more information about the steps, see Purchase Security Center and Install the agent.
Why do some Agentless Detection alerts not show the asset IP address?
When you use Agentless Detection, the asset IP address may be empty for the following reasons:
The instance is released
After the asset instance that corresponds to an alert is released, Security Center can no longer obtain the IP address of the instance because the instance no longer exists in the system. As a result, the IP address can no longer be tracked or displayed.
Data cleanup mechanism
Security Center may clean up the records of released instances, which prevents the related information from being loaded.
Does Agentless Detection support on-premises IDCs?
No. Agentless Detection relies on the image mechanism in the cloud for offline analysis. The system automatically creates image for the specified server to detect risks, but cloud images cannot be created for on-premises servers. To perform security checks on on-premises servers, install the Security Center agent and use agent-based detection features such as anti-virus and vulnerability scanning.