CBL-Mariner

Shinde, Balaji 116 Reputation points
2022-05-05T11:04:02.067+00:00

Hi All,

I am from Nuance communications. We are planning to use CBL-Mariner in azure as an image which our users can use to deploy VM from it and run docker containers on top of it.

While reading few articles, https://eng.ms/docs/products/mariner-linux/overview/overview and https://eng.ms/docs/products/mariner-linux/gettingstarted/azurevm. It looks like we have to install AzSecPack(https://msazure.visualstudio.com/ASMDocs/_wiki/wikis/ASMDocs.wiki/80705/Azure-Security-Pack) on our mariner VMs. We already have our EDR, logging and monitoring tools. Do we still need to use AzSecPack? can AzSecPack run together along with our tools. or is it that we have to only use AzSecPack?

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,162 questions
0 comments No comments
{count} votes

Accepted answer
  1. srbhatta-MSFT 8,546 Reputation points Microsoft Employee
    2022-05-10T05:02:21.907+00:00

    Hi @Shinde, Balaji ,
    Thanks for your patience and apologies for the delay in responding here. I checked with the Team internally and here is the information I have gathered.
    As you already must be knowing, Mariner is built for internal Azure usage. It is not yet supported by all the security scanners. That is on the list of the Product Team for this semester. Currently only Qualys and Trivy are supported.

    Hope this answers your question.

    -------------

    Please accept as answer and upvote if you think the information provided was useful.

    0 comments No comments

0 additional answers

Sort by: Most helpful