For existing Amazon Inspector customers using a single account, you can enable agentless scanning by visiting the account management page within the Amazon Inspector console or using APIs.
For existing Amazon Inspector customers using AWS Organizations, your Delegated Admin needs to either completely migrate the entire organization to an agentless solution or continue using the SSM agent-based solution exclusively. You can change the scan mode configuration from the EC2 settings page in the console or through APIs.
For new Amazon Inspector customers, hybrid scan mode is turned on by default when you enable EC2 scanning. In the hybrid scan mode, Amazon Inspector relies on SSM Agents for application inventory collection to perform vulnerability assessments and automatically falls back on agentless scanning for instances that don’t have SSM Agents installed or configured.