Understanding findings
Findings condense vulnerabilities, misconfigurations, and best practices into one prioritized, curated, and aggregated list, so you can identify and remediate the most critical risk in your environment. runZero Findings are available from the Findings menu and from the Risk Management dashboard.
What are findings?
Findings surface the risks attackers are most likely to target, so security teams can focus remediation on risks with real operational impact.
Findings group similar vulnerabilities and misconfigurations to show the whole risk they represent. Each finding contains a description of the risk, remediation steps, risk rankings, and a list of every asset and entity the risk affects.
Finding categories
runZero places each finding into a category based on the type of risk it represents. Categories include:
- Internet Exposure: assets and services that may be unintentionally exposed to the internet
- Certificates: expired or soon-to-expire certificates, and widely shared private keys
- Vulnerability: actively exploited vulnerabilities, or critical vulnerabilities that runZero believes are critical to address
- End-of-Life: operating systems, hardware, and applications that have reached End-of-Life (EOL) or End-of-Service (EOS) and are no longer supported by the vendor
- Open Access: network services such as unauthenticated databases and sensitive applications that are accessible without authentication
- Compliance: assets and services that violate security best practices
- Best Practice: general best practices covering insecure authentication, service misconfiguration, and obsolete protocols
- Rapid Response: emerging and novel threats covered in detail by runZero Rapid Response blog posts
Findings list
The findings list is in the main navigation menu, directly below the Inventory item. You can search, sort, and export findings like other views in the console.
Finding details
Click a finding’s name to open its details: an overview of the risks discovered, any related external resources, and remediation information to help you address the risk. Below the finding summary is a list of every asset instance the finding applies to, so you can prioritize remediation quickly.
How are findings different from vulnerabilities?
A vulnerability is a specific security issue, usually tied closely to a specific CVE or security advisory. The runZero Explorer finds vulnerabilities, or you import them through one of the supported integrations. A single asset can have hundreds of thousands of vulnerabilities, and your whole environment even more.
A finding is a curated, aggregated, and prioritized list of the risks attackers are most likely to target. A single finding may group several similar vulnerabilities. Findings are not always tied to a CVE, and they may include misconfigurations, best practices, and other security issues that may not make sense as a vulnerability.