Exposure management
runZero gives you visibility across your whole internal and external attack surface: IT, OT, IoT, mobile, and cloud. It finds unknown and unmanageable assets, reveals hard-to-find exposures, and targets the risks other approaches miss, with no agents, no authentication, and no appliances.
Unified asset inventory
runZero builds one asset inventory from active scanning, passive traffic sampling, and integrations, backed by deep fingerprinting and correlation. Assets are normalized, deduplicated, and tracked as they move across your environment.
Total attack surface management
runZero manages the attack surface of external, internal, cloud, IoT, and OT environments.
External & cloud
runZero hosts scan engines for external monitoring. A scan scope takes CIDRs, hostnames, and IPs, plus keywords that find targets for you:
domain:runzero.com: finds every host associated with runZero.com, then scans both the IPv4 and IPv6 addresses of the results.asn4:1233: resolves every CIDR associated with ASN 1233 and scans them.country4:us: can scan an entire country, but more often goes in the Excludes field to limit external discovery to a particular region.defaults: expands to every CIDR and hostname registered in the associated site.
You can combine these keywords and use them in both Scope and Exclusions. When you take the Initialize action on the scan page, runZero previews the expanded targets and estimates the scan time from the address count and full scope.
Integrations also identify and monitor the external attack surface. Assets imported from cloud providers like AWS, Azure, and GCP arrive with their external IPs and hostnames.
Internal
runZero enumerates your internal attack surface with active scans, passive discovery, and integrations.
The runZero scanner’s subnet sampling discovers massive internal ranges fast. It trickles packets into the most commonly used octets of each /24 and scans only the subnets where at least one reply came back. It also parses ICMP error messages to identify the network ranges used by the network equipment itself. Use the RFC1918 report to find blind spots and launch scans to close the gaps.
Beyond scans, runZero imports PCAP files directly through the web interface and turns any deployed Explorer into a passive network sensor. Passive discovery uses up to one CPU core to parse all traffic passing through the interface, including broadcast, SPAN port data, and encapsulated traffic (VLAN, VXLAN, GRE, etc.).
Integrations show which internal endpoints are missing a particular security control. If you use CrowdStrike as your EDR, runZero can flag every Windows system missing the agent. The same approach finds gaps in vulnerability management scopes.
IoT & OT
runZero was built for fast, unauthenticated, safe scanning of every device in every environment. That gives you coverage of internet of things (IoT) devices and reliable fingerprinting of operational technology (OT) equipment. runZero worked with the US Department of Energy to make sure active discovery is safe and accurate for OT environments.
If you can’t deploy active scanning, you can still use passive discovery, PCAP imports, and integrations with OT and IoT management tools.
Inside-out
Inside Out Attack Surface Management (IOASM) compares the unique fingerprints of your internal assets with a global database of public endpoints. It’s enabled by default on the runZero-hosted platform and available to self-hosted customers through additional configuration. IOASM can quickly tell you if an internal device is publicly exposed through an unexpected IP, including port forwards, VPNs, IPv6 tunnels, and more. This presentation goes deeper.
IOASM reports four distinct vulnerabilities based on heuristics and detection type:
- (TLS|SSH) Private Key is Public
- (TLS|SSH) Private Key is Widely Shared
- Potential External Access to Internal Asset (SSH, TLS)
- Potential External Access to Internal Asset (MAC Address)
The reported risk also varies with the heuristics. A public service attached to a Remote Desktop or Secure Shell system counts as higher risk than a public TLS key reused by a web application.
IOASM also uses the BadKeys compromised key database.
Vulnerability detection
runZero identifies, imports, and manages vulnerabilities across your total attack surface through query-based detection logic, active scans, and API-based integrations with endpoint management and vulnerability management platforms.
Findings give you one view of every detected security issue, misconfiguration, and other exposure across your assets. See Findings for more.
The Rapid Response program detects zero-hour exposures and notifies you in real time.
The Query Library lists every runZero-provided query. You can also create custom queries that report vulnerabilities on matching assets and services.
Scans find vulnerabilities with an embedded version of Nuclei, an open source vulnerability scanner, paired with curated templates and runZero’s network discovery and fingerprinting engine. You pick vulnerability categories in the scan configuration, and runZero chooses specific templates dynamically by precisely matching assets and services. Out-of-band testing relies on runZero-hosted Interactsh services at reflect-us.rumble.network and reflect-eu.rumble.network.
runZero recalculates vulnerabilities, findings, and asset risk as part of task processing and shows the results in their respective product sections.
Risk prioritization
runZero assigns every asset a normalized risk score. Threat intelligence, vulnerability information, and exposure measurement all influence the score. You can set asset criticality through automated rules or by hand in the product interface, and assign assets to specific owners for remediation. Tags come in from API integrations and can be managed in the interface, including rule-based tagging. Exported assets carry the risk, criticality, and tag information set in the product interface.
Continuous monitoring
runZero continuously monitors your organization for changes to exposure at the asset and service level. Recurring active scans, background passive traffic sampling, and regular sync with your existing infrastructure catch and report new risks quickly. Alerts can be managed in-product, sent by email, or delivered by webhook to the platform of your choice. All asset data can be synced to external platforms, including popular SIEMs and data lakes.