How often do you scan your NIMs for vulnerabilities?

What are the best practices on this? What software do you use? Say Palo Alto Networks? Or at least Falco?