Home / Companies / Datadog / Blog / Post Details
Content Deep Dive

How we replaced our host vulnerability scanner with the Datadog Agent

Blog post from Datadog

Post Details
Company
Date Published
Author
Joel Calce, Christina DePinto, James Shank, Mallory Mooney
Word Count
1,588
Company Posts That Month
13
Language
English
Hacker News Points
-
Post removed?
No
Summary

Datadog migrated its host vulnerability scanning from a remote SSH-based scanner to the Datadog Agent after fleet growth made it difficult to consistently assess all hosts before scanner credentials expired. The Agent-based approach, integrated with existing infrastructure and observability workflows, became the system of record for vulnerability findings and maintained scan freshness above 99 percent for in-scope hosts within 24 hours. During a six-month parallel evaluation, Datadog compared coverage, package identification, vulnerability detection, reporting, audit evidence, and remediation workflows, while investigating differences such as software classification, handling of unloaded kernels, and distinct methods of grouping CVEs. The migration enabled teams to prioritize vulnerabilities using production context, address shared issues through image and infrastructure release processes, and support compliance obligations including SOC 2 Type II, ISO 27001, PCI DSS, and FedRAMP High. Following cutover, Datadog retired its dedicated scanners and remote credentials, emphasizing that comparable migrations should define existing controls, establish replacement requirements, and validate meaningful differences through parallel operation.

Trends Found in this Post
Trend Post Mentions Total Month Mentions Posts Companies MoM
Observability 1 No monthly metrics for this publish month.
Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.