Site Comparison

View as Markdown

Platform

The Site and organization comparison feature generates a side-by-side analysis of two sites, so you can see:

  • How assets change over time, including their TCP/UDP services, TCP/UDP ports, and service protocols. Use this data to evaluate historical changes to assets at a specific point in time.
  • How exposure changes when you scan your network from different locations. For example, if you use public IP addresses internally and externally, you may want to scan those addresses from inside and outside your network to understand your potential exposure.

The report is a summary view of differences. It only captures certain attributes that were added to or removed from an asset, such as IP addresses, TCP ports, TCP service counts, UDP ports, UDP service counts, service protocols, and service counts. It does not track every modification to an asset, such as fingerprint or service banner changes.

After the report runs, its data is static. If your inventory changes afterward, some assets may no longer be reachable from the report.

Generate a site comparison

A site comparison needs a current site and a comparison site. The sites can be in different organizations. You can also select “All sites” to compare all sites in an organization against a different site and organization.

When the report runs, runZero assembles the two sets of assets, compares them with its asset matching algorithms, and generates a set of differences that you can browse in the report.

To generate a site comparison:

  1. Verify that your current organization contains the inventory of assets you want to compare.
  2. Go to the site comparison page.
  3. On the site comparison configuration page, the current organization is the one you have selected. Change the current site if needed. For the comparison, choose the organization and site you want to run the analysis against.
  4. Run the report. runZero creates a task to perform the comparisons and takes you to the task page.
  5. When the task completes, the report appears in the list of recent analysis reports at the top of the Reports page. You can then view and search the results.

View how assets change over time

To see how assets have changed over time, compare the data from an old scan task with your most recent inventory. A point-in-time comparison needs a new project to import the old scan data into.

To set up a point-in-time analysis:

  1. Go to the organization or project that contains the scan task data you want to use.
  2. Go to your completed tasks and locate the task with the data for the point in time you want to compare.
  3. From the task page, download the task data. The file name starts with scan_ and ends with .json.gz. This is the file you’ll import into your new project. You don’t need to uncompress it, unless you’re curious about the JSON data.
  4. Create a new project for your import. If you intend to run the analysis regularly, you can create an organization.
  5. After you create the project, go to the Inventory page and import your scan task data into it.

Now you can compare your current inventory with its previous version. Go to the site comparison page and select the organization and site for your current inventory as the site to compare against.

After the report runs, it shows a table with the differences between the two sites, which in this case are two points in time, going from past to present.

You can also run the comparison the other way: select your current organization first, then choose the project with the past data as the comparison site. The results are the same with their sense reversed. Services that show as added going from past to present show as removed going from present to past.

View how exposure differs between networks

The site comparison report can also show how exposure varies with where you scan your network from. Comparing two inventories taken from two perspectives gives you a better view of your attack surface, which can help with active defense or risk reduction. For example, if you use external IPs internally and externally, you may want to scan those addresses from inside your network and from outside it, then run the site comparison report on the results from those two sites.

To set up a diff of exposures between networks:

  1. Set up a site with an Explorer on one network.
  2. Set up another site with an Explorer on a different network. This site can be in the same organization as the first.
  3. Scan the same address range with each Explorer. Verify you have the correct site selected for each scan.
  4. After the scans complete, run the site comparison to generate the diff. The report shows a table with the differences between the two sites.

Analyze the results in the site comparison report

The site comparison generates a table showing how assets’ addresses, names, services, ports, and protocols differ between sites. Red text with a minus (-) sign marks attributes removed going from left to right. Green text with a plus (+) sign marks attributes added.

How to read the columns:

  • Address and Other Address - The first address column contains the asset’s addresses in the organization that was current when you requested the report. The second address column, Other Address, contains the asset’s addresses in the organization and site compared against it.
  • Name and Other Name - The first name column contains the asset’s names in the organization that was current when you generated the report. The second name column, Other Name, contains the asset’s names in the organization and site compared against it.
  • TCP and UDP services - These columns show how the total number of TCP and UDP services differs between sites.
  • TCP and UDP ports - These columns show the ports added or removed between sites.

Click the green info (i) icon to view a more detailed comparison of the asset.

Clicking one of the asset addresses opens the full current asset record, if the asset still exists in the relevant organization and site.

Search the site comparison report

You can search the report with the runZero search query language. In the keyword descriptions below, the main set is the assets in the organization that was current when you generated the report (the address and name columns). The comparison set is the assets in the organization and site you chose to compare against (the other address and other name columns).

Keyword Meaning
address: Search for assets in the main set with a specified IP address. Use none to find assets that are missing from the main set.
net: or cidr: Filter assets by their network CIDR range in the main set.
other_address: Search for assets in the comparison set with a specified IP address. Use none to find assets that are missing from the comparison set.
other_net: or other_cidr: Filter assets by their network CIDR range in the comparison set.
id: Search by asset ID in the main set.
other_id: Search by asset ID in the comparison set.
tcp: Search for a TCP port change by number.
udp: Search for a UDP port change by number.
protocol: Search for a TCP or UDP port change by service name.
Updated