Alert icon Keyboard navigation enabled.
Alert icon TAB or Shift+TAB to navigate across. Down ↓ to open menu. ESC to close menu.
Alert icon Down ↓ to select section. Right → to activate. Up ↑ / Down ↓ / Tab to traverse all. ESC to exit.
BeyondTrust
Skip to content Use space or enter to skip.

What can we help you find today?

Instant Results
  • Website Results
  • Technical Documentation

Filter Options

Focus your search

Filtering by

Your recent searches:

Contact Us Chat with Sales Get Support
  • English
  • Deutsch
  • français
  • español
  • 한국어
  • português
  • Home
  • Resources
  • Blog
  • Retina Network Security Scanner 6.5: New Scanning/Reporting for Docker Images Enhances Support for DevOps current page
Link copied

Retina Network Security Scanner 6.5: New Scanning/Reporting for Docker Images Enhances Support for DevOps

Apr 4, 2018
Author:
Adacosta
Alejandro DaCosta
Product Manager
Blog banner default
Retina Network Security Scanner 6.5: New Scanning/Reporting for Docker Images Enhances Support for DevOps
Adacosta
Alejandro DaCosta
Product Manager

I’m pleased to announce the 6.5 release of Retina Network Security Scanner, our solution for scanning, prioritizing and remediating vulnerabilities across the enterprise. This release significantly enhances BeyondTrust’s support for DevOps use cases by adding new scanning and reporting capabilities for Docker images, as well expanded host scanning capabilities. For these and other features, keep reading!

Docker Image Scanning Improves Security

As organizations continue to automate development pipelines to increase their agility and responsiveness to business needs, container-based technologies such as Docker are used to provide DevOps teams everything they need to build, test, run and deploy applications. However, many organizations struggle to know how many Docker instances are in their environments, causing potentially risky gaps in security. To overcome these risks, organizations must have the ability to quickly discover all Docker images in their environments and report on their attributes.

Retina Network Security Scanner version 6.5 introduces new scanning capabilities against Docker containerization technology. With these new capabilities, organizations can quickly discover and accurately enumerate the attributes of images (like software, packages, etc.).

Retina customers have two options:

  1. Performing network-based scans against both Linux and Windows hosts running Docker, with administrative credentials required; or
  2. Retina Host Security Scanner performing on-node scans against Windows hosts running Docker, with no credentials required.

Please see the summary table of capabilities by platform below.

Docker Images on Linux Docker Images on Windows
Basic Image data, OS Identification and Exposed Ports, Repository Tag, Image ID and where available, Image Size, Creation Date and Image Author Basic Image data, OS Identification and Exposed Ports, Repository Tag, Image ID and where available, Image Size, Creation Date and Image Author
Enumerations: Software, Users and User Group Enumerations: Software, Services and Users
Software package auditing of Debian-based images (e.g. Ubuntu), Red Hat-based images (e.g. CentOS, Oracle Linux), Gentoo and Alpine images Registry and file auditing

This new capability means that organizations can improve the control and visibility of Docker container usage, helping to support the further automation of DevOps processes.

New Docker Image Reporting Reduces Risks

Version 6.5 also introduces reporting for vulnerabilities and attributes (enumerations) of Docker images. Customers have the option to include vulnerability details about the associated host which provides greater visibility into the risk not only posed by the images but also on the host on which the images reside. For a representation of this reporting, please see the screenshot below.

ss-rnss-6-5-dock-hosts.jpg


Watch for central management, scanning, normalization and reporting of Docker images in the forthcoming release of Retina CS/BeyondInsight.

Expanded Linux and Mac Platform Support

For many organizations, it can be complex and time-consuming to identify and scan remote Linux and Mac user computers, transient virtual platforms, hardened systems and cloud environments. Further complicating scanning is the need to perform fully authenticated vulnerability scans without the need to pass credentials, and to do it in a matter of minutes! Organizations must have host security scanning that supports Linux and Mac platforms.

With the latest release of the Retina Host Security Scanner, BeyondTrust has expanded platform coverage in beta to include several distros of Linux and Mac, including:

  • Debian 8 (x64)
  • Debian 9 (x64)
  • macOS 10.12.x
  • Oracle Enterprise Linux 7.x (x64)
  • Red Hat Enterprise Linux 7.x (x64)
  • Ubuntu 14.x
  • Ubuntu 16.x

This enhanced capability will help organizations reduce their security risks by centrally reporting on and analyzing all host-based scan data.

Additional CIS Benchmark Certification

While previous versions of Retina have supported Security Content Automation Protocol (SCAP) benchmark assessments – along with CIS, DISA, Microsoft, and more – Retina 6.5 adds support for and certification of the following SCAP benchmarks released by the Central for Internet Security:

  • CIS Benchmark for Microsoft Windows 10, v1.3.0, Level 1 Profile
  • CIS Benchmark for Microsoft Windows 10, v1.3.0, Level 1 + BitLocker Profile
  • CIS Benchmark for Microsoft Windows 10, v1.3.0, Level 2 Profile
  • CIS Benchmark for Microsoft Windows 10, v1.3.0, Level 2 + BitLocker Profile
  • CIS Windows 10 Release 1607 Benchmark v1.2.0
  • CIS Windows 10 Release 1703 Benchmark v1.3.0
Mitigating VPN Vulnerabilities: Understanding the Latest CISA Directive

Blog

Mitigating VPN Vulnerabilities: Understanding the Latest CISA Directive

AD CS 101: Introduction to Active Directory Certificate Services & How to Detect and Mitigate ESC1 Attacks

Blog

AD CS 101: Introduction to Active Directory Certificate Services & How to Detect and Mitigate ESC1 Attacks

Paths to Privilege™ Explained

Resources

Paths to Privilege™ Explained

Latest Posts
  • Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Jun 12, 2026 Hooked on Identity (Part 2): Abusing OAuth Trust Boundaries in Okta
    Blog
    7m
  • Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Jun 9, 2026 Hooked on Identity: Abusing SAML Assertion Inline Hooks in Okta
    Blog
    6m
  • Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Jun 8, 2026 Joining Project Glasswing: Securing the Privilege Backbone of the AI Era
    Blog
    5m
  • The Most Common & Most Dangerous Types of Shadow IT
    Jun 5, 2026 The Most Common & Most Dangerous Types of Shadow IT
    Blog
    19m
  • 14 Password Management Best Practices
    May 28, 2026 14 Password Management Best Practices
    Blog
    12m
Related
  • TNT – Trump ‘n Twitter, Detonated by an Insider Threat
    Nov 3, 2017 TNT – Trump ‘n Twitter, Detonated by an Insider Threat
    Blog
    1m
  • Coronavirus is Stress Testing Remote Access: How to Make Telework Safe, Secure, & Productive
    Mar 11, 2020 Coronavirus is Stress Testing Remote Access: How to Make Telework Safe, Secure, & Productive
    Blog
    1m
Share this Article
  • Link
Tags
  • Attribute Enumeration
  • Container Technologies
  • Dev Ops Support
  • Docker Image Scanning
  • Docker Instances
  • Enterprise Vulnerabilities
  • Host Security Scanner
  • Network Based Scans
  • Retina Network Security Scanner
  • Retina Scanner
Stay up to Date
Get the latest news, ideas, and tactics from BeyondTrust. You may unsubscribe at any time.

Keep up with BeyondTrust

Customer Support Get Started
  • LinkedIn
  • X
  • Facebook
  • Instagram
  • Add BeyondTrust as a preferred source on Google
  • Privacy
  • Security
  • Manage Cookies
  • Do Not Sell My Data
  • WEEE Compliance

Copyright © 2003 — 2026 BeyondTrust Corporation. All rights reserved. Other trademarks identified on this page are owned by their respective owners. BeyondTrust Corporation is not a chartered bank or trust company, or depository institution. It is not authorized to accept deposits or trust accounts and is not licensed or regulated by any state or federal banking authority.

Prefers reduced motion setting detected. Animations will now be reduced as a result.