Build Inspector assessment exclusion configurations to skip specific resources or rule packages.
Build Inspector assessment exclusion configurations to skip specific resources or rule packages.
Required Fields
AssessmentTemplateArnExclusionPreview.TitleExclusionPreview.ScopesOutput will appear here...The builder validates that AssessmentTemplateArn, ExclusionPreview.Title, and ExclusionPreview.Scopes all resolve before accepting the JSON, the minimum Inspector Classic needs to know which assessment template the exclusion applies to and what it actually excludes; it can't verify the instance IDs or rule package ARNs referenced actually exist in your account.
Build an Inspector Classic assessment exclusion that scopes out specific instances or rule packages from an assessment run, using Scopes keyed by INSTANCE_ID or RULES_PACKAGE_ARN. This applies to Inspector Classic's assessment-template model, not the newer continuous Inspector (which replaced scheduled assessment runs with always-on ECR/EC2/Lambda scanning and uses suppression rules instead of this exclusion mechanism), so confirm which Inspector generation your account is actually running before assuming this exclusion shape applies.
Confirm which Inspector generation (Classic vs. current continuous Inspector) your account actually runs before building an exclusion this shape, applying it against the wrong generation's API produces a rejection, not a warning about the mismatch.
A tag-based exclusion (ResourceGroupTags) silently applies to any future instance carrying that tag, an exclusion set up for one team's known dev instances can quietly exempt a newly-provisioned instance from assessment if it inherits the same tag through an AMI or launch template default.
Exclusions accumulate silently over time and rarely get cleaned up, the example's own Recommendation field ('Review exclusions quarterly') is a genuinely good practice, an old exclusion for a long-decommissioned instance ID is harmless, but a stale rule-package exclusion can mask a real, newly-relevant finding type.
No, this AssessmentTemplateArn-based exclusion model is specific to Inspector Classic's scheduled assessment-run architecture. The current, continuously-running Inspector (covering EC2, ECR, and Lambda) uses a different suppression-rule mechanism instead of assessment-template exclusions, if your account is on the newer Inspector, this exclusion shape doesn't apply and you'd need Inspector's suppression rules instead.
Only for the specific assessment template the exclusion is attached to, if other assessment templates target the same instance without a matching exclusion, it's still scanned under those. Exclusions are scoped per assessment template, not a global 'never scan this instance' setting across the whole account.
Yes, that's exactly what combining an INSTANCE_ID scope entry with a RULES_PACKAGE_ARN scope entry achieves in the same exclusion, both together mean 'this rule package doesn't apply to this specific instance', rather than the broader effect of only specifying the rule package ARN alone, which would exclude that check for every instance in the assessment.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.