Remediation with CloudBots

CloudBots automatically correct compliance issues that are discovered in your cloud accounts by CloudGuard compliance checks. You can configure your CloudGuard account to use CloudGuard CloudBots.

On the Posture Management > Remediation page, you can configure remediation steps for specific rules in your rulesets.

You must deploy CloudGuard CloudBots in the cloud accounts, to which remediation steps are applied. See for details.


CloudGuard CloudBots are small programs or scripts that act on the account or cloud asset to correct missing or misconfigured settings, for example, to close Security Groups that are too open. They are invoked by CloudGuard when compliance rules fail.

CloudGuard CloudBots work only with rules that are invoked from Continuous Compliance policies and not from manually-invoked compliance policies.

CloudBots provide:

  • Active protection of your cloud environment

  • Reduction in the workload on the enterprise cloud IT team, by performing remedial actions on misconfigured cloud assets and accounts automatically

  • The response time to remedy a problem is reduced, reducing the window of exposure to risk as a result of the misconfiguration.

  • Since CloudBots work with continuous compliance assessments, your cloud environments are assessed repeatedly, so any changes (as a result of unintentional or unauthorized access to the cloud assets) are detected and corrected almost immediately.

  • CloudBots reliably apply the same correction to misconfigurations of the same type. That is, correcting an account policy misconfiguration is the same for all accounts. In addition, a full audit trace can be kept of all actions, so you are aware of changes that are applied.