Asset Route Pathing
Most users should start with the Network Map, which lets you set sources and targets, trace inbound or outbound paths, apply per-hop include/exclude filters, and rank choke points in one interactive view.
The asset route pathing report visualizes the potential network paths between a source asset and a destination asset in an organization. Following the paths, you can see the assets connected between source and target. Each of them is an opportunity an attacker could use to break into your target asset.
The runZero Explorer performs a traceroute between itself and the source, and another between itself and the target. runZero then compares the data to infer shared points between the assets. runZero does not get any paths from a direct traceroute. This is its best effort, based on the scan data it has, to identify the assets it sees as viable points between two assets.
Share this report with your IT and security teams to show which assets could act as pivot points to your critical assets. With that information, they can identify systems that may need hardening and check whether the appropriate critical controls are in place to prevent unauthorized access to those assets.
If your environment is highly segmented, you can use this report to quickly find paths from low security assets to critical assets. For example, it can show whether a device in a wireless guest network can reach a system in the PCI cardholder data environment.
Terminology
The report uses these terms:
- Hop - Any node between the source and destination.
- Node - Any asset or hop. A node can be an IP, an asset, or unknown.
- Asset - Any device in your runZero inventory.
- Network path - runZero does not get any paths from a direct traceroute. Instead, it uses the data it has to identify and display potential network paths between the target and source.
Generating the asset route pathing report
- Launch the asset route pathing report.
- On the Asset route pathing page, select a source asset and a destination asset. Use the search to filter assets by keyword, or the table pagination to browse all of your assets.
- With a source and destination selected, start the trace.
- The results show the potential paths between the source and destination asset.
Analyzing the report
Locate your source asset and target asset. Review any hops between them and secure those paths. Look at the services running on those systems that may offer entry points for attacks, and harden them.
Nodes in the asset route pathing report are color-coded so you can identify the source asset and destination asset.
The report uses these colors:
- Green - The source asset
- Red - The destination asset
- Orange - A multi-homed asset that may act as a pivot point
- Blue - A standard layer-3 routing hop
- Gray - Asset is unknown
A hop labeled Unknown is an intermediate hop in the layer-3 path that did not respond with ICMP errors for TTL exceeded packets.
Sharing the report
You can share the results from the asset route pathing report by exporting a PNG or dotfile of the report, or by sharing a direct link to it.
- To export a PNG snapshot of the asset route pathing report, click Export view. The PNG downloads to your computer.
- To render the image in formats like SVG, PSD, and PNG, export a dotfile and feed it into a Graphviz engine or an open source visualization tool.
- To share a link, copy the URL while viewing the generated report. Other team members with a runZero account and access to the organization can open it.
Exporting a dotfile
A dotfile is a text file that Graphviz engines and open source visualization tools can read. With the dotfile, you can render the image in other formats, like SVG, PSD, and PNG.
- Launch the asset route pathing report.
- On the Trace path page, select a source asset and a destination asset. Use the search to filter assets by keyword, or the table pagination to browse all of your assets.
- With a source and destination selected, generate the report.
- When the visualization appears, click the Export report button. A window prompts you for a name and download location for the file.
- Enter a name for the file and choose where to save it on your computer.
- Save the file.
FAQs
Why are there hops in the report that aren’t in my inventory?
Not every hop is a runZero asset. runZero fills in IP addresses for some asset hops from information in the traceroute data. Sometimes that data includes asset information that isn’t part of the inventory, which is why those hops appear in the report.
Can runZero determine how two assets are talking to each other?
No. runZero can only identify potential paths, not whether they are routable. It does not test or validate the paths.
Why isn’t the asset route pathing report available?
The asset route pathing report is only available to runZero Platform customers.