Full AWS Practitioner Certification Question

A software company recently suffered a security breach due to vulnerabilities in custom-built applications running in its on-premises data center. In response, the company is migrating its workloads to Amazon EC2 and wants to proactively detect and report potential software vulnerabilities on those instances. What is the best AWS-native solution to continuously scan the EC2 environment for these vulnerabilities and automatically generate detailed findings?