Reviewing results
Task details
After each discovery task completes, the task details page summarizes how many assets were updated. runZero correlates assets across IPs and data sources, so the numbers can differ from what IP-based matching alone would give.
The change summary on the task details page includes these statistics:
- Asset changes:
- Newly discovered assets are devices found during the task whose fingerprints match no device seen before.
- Assets marked offline are assets runZero had seen before on the scanned network that didn’t respond on any of their IP addresses during this scan. The offline status is a flag on the asset and doesn’t count as a change to it. A device may be marked offline because it was powered down or disconnected, or because of network problems.
- Assets back online are assets that were marked offline at some point but responded to the runZero Explorer during this scan. The online status is a flag on the asset and doesn’t count as a change to it.
- Assets changed is the number of assets where some property other than online status changed, such as the device’s IP addresses or hostname, or responses from new ports or protocols.
- Assets unchanged is the number of assets seen exactly where runZero found them in the last scan, with no change to their responses.
- Assets ignored is the number of times the Explorer got a response from probing an IP address that turned out to be bogus in some way. This typically happens when a web proxy, stateful firewall, or SIP gateway answers as if it were the asset at every address on a subnet.
- Total assets seen by task is Assets changed plus Assets unchanged: the number of asset records that are now up to date.
- User changes:
- Newly discovered users are users seen for the first time during the integration sync.
- Users changed are users whose attributes changed during the integration sync.
- Users unchanged are users that did not change during the integration sync.
- Users updated by task is Users changed plus Users unchanged: how many user records are now up to date.
- Group changes:
- Newly discovered groups are groups seen for the first time during the integration sync.
- Groups changed are groups whose attributes changed during the integration sync.
- Groups unchanged are groups that did not change during the integration sync.
- Groups updated by task is Groups changed plus Groups unchanged: how many group records are now up to date.
Dashboard & inventory views
The dashboard fills with results after the first scan completes. It shows trend data and insights that help you see how your inventory changes over time. Pick a time period and site for the trend data with the selectors at the top right of the dashboard page.
The main asset trends graph shows the number of assets in each of the four main states: live, offline, scanned, and unscanned. Beneath the graph, further breakdowns show the top 10 in each asset category: asset type, operating system, hardware, and tags.
The service trends graph shows how many services in total were found in your asset inventory, with breakdowns for ARP, ICMP, TCP, and UDP. Below it are the top 10 TCP ports, UDP ports, protocols, and products detected.
Click the menu button at the top right of a table and select “View more” for a more detailed inventory of that category.
Insights from queries
Queries and reports help you draw insights from your inventory. Start with the pre-built queries in the Query Library. Some of them come from runZero’s Rapid Response to emerging threats and are described on our blog.
The runZero query language searches and filters your asset inventory by asset field and value pairs. The search query syntax page documents the language. Once you know it, you can write your own queries.
To run a query automatically, open it and set “Automatically track query results on the dashboard”. The query then runs when scans complete, and the dashboard page notifies you of any resulting insights.
Sample Queries
Asset inventory
- Equipment that is likely 8+ years old:
alive:t mac_age:>8years - Assets with end-of-life OS:
os_eol:<now - Virtual machines:
has:virtual - Devices acting as a router:
router:true - Devices that may be bridging:
has_public:t and has_private:t
Service inventory
- Protocol on a non-standard port example:
protocol:ssh not port:22 - Publicly addressed assets running RDP or VNC:
has_public:t and (protocol:rdp or protocol:vnc) - Authenticated web services that are not encrypted:
(_asset.protocol:http AND not _asset.protocol:tls) AND ( html.inputs:"password:" OR last.html.inputs:"password:" OR has:http.head.wwwAuthenticate OR has:last.http.head.wwwAuthenticate ) - Older TLS versions in use:
alive:t AND protocol:"=tls" AND ( tls.versionName:"=TLS 1.0" OR tls.versionName:"=TLS 1.1")
Our blog describes more sample queries:
- Finding duplicate SSH host keys
- Identifying rogue remote access solutions
- Finding device serial numbers
Reports
After the dashboard and inventory, your next stop is the runZero Reports page.
Switch topology
This report uses SNMP information to map how the switches on your network are connected. Each switch shows its IP address, name, and the number of assets connected to it. If runZero detected MAC addresses that weren’t found within the scan scope, a count of unmapped assets appears below the switch.
Click a switch for a pop-up with the number of identified and unmapped assets. From there, click through to view the unmapped assets in a table of unmapped MACs by switch port.
Double-click a switch to expand that part of the diagram and show the individual assets connected to it.
The switch topology report isn’t always exact. It relies on which switch claims to have seen each MAC address, and that may not be the nearest access switch. The algorithm picks the switch port with the fewest shared MACs as the best match, but switch cache timeouts and how the switches were scanned can still produce an answer you don’t expect.
Subnet utilization
The subnet utilization report lists the subnets scanned on your network and what percentage of each is in use. If you scanned 10.0.1.0/24 and found 25 assets, the report shows 10% of the subnet’s available IP addresses in use.
Network bridges
The network bridges report finds devices that bridge multiple network segments, which helps you locate unintentional bridging between your internal networks and the Internet.
The report shows your internal networks in green and external networks in red, then the multihomed assets that bridge an internal network to an external one.
RFC 1918 coverage
The RFC 1918 coverage report shows how much of the private internal address space you have scanned for assets. It helps you find rogue assets, unscanned subnets, and secondary interfaces on scanned devices. The section on coverage reports has more.
Unmapped MACs
This report uses SNMP information to list MAC addresses runZero found evidence for but never encountered as asset addresses during the network scan. The addresses are grouped by the switch that reported them, along with the vendor, manufacture date, and switch port of the possible asset, to help you identify it.
Outliers
The outliers reports summarize how often different values occur in specific attributes of assets and services, sorted from most frequent to least.
The HTTP servers outliers report, for example, lists every HTTP server runZero encountered, starting with the most common.
Beyond the one-click outliers reports, you can produce an outliers report for any asset or service attribute.
- Switch topology shows how your assets are connected and finds “unmapped” MAC addresses (in red) that weren’t in your scan scope (the Unmapped MACs report summarizes them)
- Bridging visualizes which hosts may have both public and private connections
- RFC 1918 coverage can identify potential blind spots on your network, like missing (unscanned) subnets, rogue devices, and “hinted” IPs that are secondary interfaces on unscanned network ranges
- The “View all” button at the top right lists other reports for investigating outliers
Domain membership report
The domain membership report lists the Active Directory domains runZero encountered and how many assets are in each.
Analysis reports
Analysis reports are the more advanced reports. They may run as tasks rather than being generated on the fly.
The first analysis report is Compare Sites, which generates searchable reports of the differences between two sites.
The Outlier Overview Report analyzes assets across the organization and summarizes the most unusual values for attributes such as hardware type and SNMP enterprise ID.
The Specific Outlier Report breaks down the outlying values of an attribute you select.
The Organization Overview Report builds a high-level summary of the entire organization and can optionally include lists of the assets found.
Alerts
Beyond the reports and queries you run yourself, runZero can send automatic alerts to designated channels for post-scan inventory queries, asset changes, Explorer and scan issues, security operations, or API events.
Channels are internal notifications in the runZero web console, email, or webhooks that connect to services such as Slack or Mattermost. Alerts use the same query language as the sample queries above, so they’re a good way to automate notification for critical events.