Connector Release 2.12
October 10, 2025
Connector 2.12 introduces changes to Connector rate limits, edit functionalities, and Snapshot Scan features.
Member Connector Edit Support – Enhanced Configuration Flexibility
With Connector 2.12, you have greater flexibility in managing member connector configurations while maintaining consistency with organizational standards.
Feature Highlights
-
Preserving Connector Identity:
When attaching individual connectors to an Organization and selecting Apply Organization Configurations, the Name and Description of the individual connector remain unchanged. This aligns with legacy behavior, ensuring that the connector identity is preserved. -
Editable Member Connectors:
You can now edit the configurations of member connectors after deployment. This includes updates to scan types, scheduling, and other operational settings. -
Reset to Organization Configurations:
At any time, users can choose to reset member connector configurations to match the Organization-level settings, offering a balance between customization and standardization. -
Detach Connector Limits
When detaching connectors from an Organization, you have a fixed limit of 50 connector detachments allowed for your subscription. This ensures smooth and uninterrupted operations for between your member and organization connectors.
As part of this update, we are also updating the functionality of the Attach feature in the application and API. You cannot attach connectors in a Disabled state with an Organization connector.
Enhanced AWS and Azure Snapshot Scan Versions
With Connector 2.12, we have introduced the AWS V9 and V10, and Azure V3 CFT versions. These new templates come with several enhancements.
Cost-Optimized VPC Deployment for Snapshot
We’ve streamlined the VPC architecture for snapshot-based assessments:
- Private Subnet by Default: All EC2 instances now deploy in a private subnet with no NAT gateway, significantly reducing deployment costs.
- No Internet Access: Instances connect to S3 via gateway endpoints, ensuring secure and isolated communication.
- Simplified Setup: You no longer need to choose between public and private subnet options. Private subnet is now the default.
AWS GovCloud Support
Snapshot-based assessments now support AWS GovCloud regions:
- Added support for the regions:
us-gov-east-1andus-gov-east-2 - All features work as in the commercial cloud except:
- Event-based discovery is not supported
- CLI-only deployment: CFT-S and CFT-T must be deployed via CLI (not console). Templates are not downloadable via the Connectors module
AWS Snapshot Scan Skipping Based on FlexScan Activity
To optimize scan efficiency and avoid redundancy, we have introduced two new checkboxes to skip Snapshot scans if the workload has been previously assessed by API-based or Agent-based scans.
When selected,
- Snapshot scans automatically skip assets that have been scanned via Cloud Agent or API-based assessment in the last 4 hours
- Scan priority:
Cloud Agent > API-based Assessment > Snapshot-based Assessment
To select these checkboxes, you can edit or create a connector, navigate to the Tags and Activation screen, and find the checkboxes under the Snapshot-based Scan checkbox.
