Full-scale deployment
Start with the standard deployment plan and add tasks as you need them. It’s broken into six stages that help you plan your requirements, execute the deployment, and optimize your environment around runZero’s best practices.
1. Identify key success outcomes
Total attack surface visibility
- Active discovery on all internal assets
- Active discovery on all externally facing assets
- Passive discovery and enrichment in key network segments
- Integrate with all cloud providers and other relevant data sources
Additional resources
Full-spectrum exposure detection
- Rapid Response findings and asset-level pivoting
- Network misconfiguration findings and control coverage gaps
- Vulnerability enrichment and inside-out findings
Additional resources
Risk prioritization and insights
Additional resources
Compliance, reporting, and KPIs
- Comply with asset inventory and discovery requirements of relevant frameworks
- Comply with secure configuration requirements of relevant frameworks
- Comply with malware protection requirements of relevant frameworks
- Comply with vulnerability management requirements of relevant frameworks
Additional resources
2. Planning your deployment
These first tasks help your team identify target results, get ahead of blockers, and avoid misconfiguring runZero.
Tasks
- Identify the organizational stakeholders
- Administrators (who will set up runZero)
- Integration owners (who will provide credentials for each integration)
- All users take the runZero 101 training
- Administrators take the runZero 201 training
- Decide whether you need to self-host (docs | video)
- Decide whether users will sign in with SSO or local accounts.
- If SSO, start any internal process needed to get the runZero app created in your provider.
- Identify known networks and subnets for discovery, plus any other inventory sources (docs | video)
- If you have them, prepare CSV files to bulk import subnets.
- Configure firewalls to let the Explorer IPs scan the entire network on all ports.
- Define organizations based on your RBAC requirements, including organization-level data retention and expiration thresholds (docs | video).
- Decide where to deploy Explorers.
- Explorer Groups let you combine Explorers logically to simplify task scheduling.
- Identify the inbound integrations you need. Prioritize connectors for platforms such as EDR and CSPM to get full vulnerability and misconfiguration coverage.
- Get the team familiar with runZero search so they can plan initial asset searches and reporting requirements.
3. Initial configuration
Once your plan is in place, configure runZero and run your initial scans. These tasks are in priority order, so working through them in sequence saves you from reconfiguring later.
Tasks
- Deploy the self-hosted console, if you need one (docs | video)
- Set up organizations and configure expiration thresholds for stale data, integrations, and vulnerabilities.
- Set up sites and define subnets for discovery (video)
- Sites do not necessarily correspond to physical locations within runZero. Sites represent distinct networks, which may have overlapping IP space.
- This also includes public IP space and domains for external scanning.
- Install Explorers (video)
- If planned, configure Explorer Groups to organize scanners logically and simplify task distribution.
- Define private network addresses
- If you use public IP ranges internally, set custom private IP ranges in Account Settings.
- Run your initial scan (docs | video)
- Configure credentials and inbound integration connections
4. Review assets and exposures
With initial discovery done and integrations connected, review the results. Paired with runZero’s reporting features, that review helps you expand scan scope, prioritize risk, understand your network better, and identify exposures such as misconfigurations and actively exploited vulnerabilities.
Tasks
-
Review results and exposure overview
- Review the Risk Management Dashboard (the new default dashboard) for a centralized view of risk, with insights, trend data, and asset breakdowns (docs).
- Review the Asset Inventory (docs). It correlates and merges assets across all data sources (scan, passive, and integrations) into a single source of truth.
- Review the Asset Detail View, which consolidates each asset’s attributes, vulnerabilities, and software (docs).
-
Identify and prioritize exposures with Findings
- Review the Findings section. It groups vulnerabilities and misconfigurations into prioritized risk categories (e.g., Internet Exposure, Open Access, End-of-Life, Certificates, Vulnerability, and Best Practice Violations) (docs).
-
Dig deeper with queries
- Find risky assets with the Queries library (docs):
- Learn the query syntax (docs).
- Apply vulnerability records to queries (e.g., for novel internal findings) (docs).
- Filter assets and services by their Finding Code (e.g.,
finding_code:rz-finding-internet-exposed-database) to target remediation (docs). - Search for assets exposed to Known Exploited Vulnerabilities (KEV) lists (CISA KEV, VulnCheck) and use EPSS scores to set priority.
- Find risky assets with the Queries library (docs):
-
Track long-term initiatives
- Use Goals to track them (docs).
- Use Baseline Goals to measure progress against specific inventory subsets (e.g., a goal to remediate all expired certificates or critical vulnerabilities in the
os_eol:<nowsubset).
-
Review reporting
5. Optimization
After your initial analysis, optimize your scans and configuration to follow best practices.
Tasks
- Configure SNMP credentials (video)
- Optimize scans by adjusting scan rates and other settings (docs | video)
- This clickthrough covers more of the configuration options
- Confirm that default credential and vulnerability checks are enabled on all scans.
- The Templates page lists current coverage.
- Configure asset ownership to speed up investigations.
6. Automation
Now that your scans are optimized and your data analyzed, you can automate the routine work: recurring scans, automated queries, and alerts for the team.
Tasks
- Schedule recurring scan tasks and any inbound integration tasks
- Automate queries and configure alerts to match your use cases (video)
- Use rules to automate tagging and asset criticality (walkthrough)
- Set up alerts for system events such as an Explorer going offline or a scan failing.
- Configure outbound integration connections to enrich other IT and security tools
- CMDB
- SIEM
- SOAR
- If runZero currently has no standard outbound integration for a tool you use, the API documentation explains how to export runZero data.
7. Rollout
As the deployment wraps up, confirm that every user has completed training and that everyone who would get value from runZero has access to the platform.
Tasks
- Add users
- Confirm all users are trained on runZero
- Training and core documentation
- runZero playbooks
- Identify other teams with an interest in the asset inventory data, such as:
- Enterprise security team
- Security teams typically use runZero to build a complete asset inventory, find gaps in their vulnerability scanning and endpoint protection, and discover potential vulnerabilities.
- IT Operations team
- IT Operations teams typically use runZero to build a complete inventory of all assets across on-premises and cloud infrastructure, then turn to search and reporting to identify misconfigurations and report on those assets.
- Penetration testing team
- Penetration testing teams typically use runZero to run internal and external reconnaissance, identify vulnerable targets, and find paths to those targets with search and reporting.
- Enterprise security team
Additional resources
After deployment and training, these resources can answer the questions you still have and help you get more out of runZero:
Getting help
If you need help at any point in the process, book a session with a runZero Customer Success Engineer.