Use case library
Appendix
- Total attack surface visibility
- Full-spectrum exposure detection
- Risk prioritization and insights
- Compliance, reporting, and KPIs
Total attack surface visibility
Managing your organization’s attack surface starts with seeing all of it: internal and external assets, cloud and security tooling integrations, and passive discovery. Together they give you full oversight and put you ahead of threats.
Active discovery on all internal assets
Identify every internal asset within your defined network boundaries, and keep the inventory current by actively monitoring the networks you manage.
Steps:
- Define the networks of interest: managed networks and known subnets.
- Configure Organizations and Sites.
- Install Explorers.
- Configure scans.
- Review the inventory to verify connectivity and confirm fingerprinting looks right.
Active discovery on all externally facing assets
See the external assets that make up your public-facing footprint, such as domains and IP ranges, so you can address vulnerabilities in your external attack surface before anyone exploits them. Monitoring these assets surfaces vulnerabilities and misconfigurations early. Continuous scanning and updates keep your external inventory current and those assets secure.
Steps:
- Define external ranges, domains, and subdomains.
- Add the external ranges, domains, subdomains, and ASN4 numbers to the scan scope.
- Run the scan using runZero hosted zones.
- Review the inventory to verify the findings.
Passive discovery and enrichment in key network segments
Use network TAPs or SPAN ports to identify assets and gather insight without active scanning. You get continuous monitoring with minimal disruption to network operations. Passive discovery complements active methods: it observes traffic patterns and enriches asset data without interrupting critical operations, so it’s a good fit for sensitive network segments.
Steps:
- Set up a network TAP or SPAN port, or use an existing one.
- Put an Explorer on the network TAP or on a host attached to the SPAN port.
- Configure the Explorer to listen on the relevant interfaces, set the scan scope, and leave it running.
Integrate with all cloud providers and other relevant data sources
Connect cloud providers and other data sources for complete visibility across hybrid environments, and simplify asset management by unifying data in one platform. Automated updates from connected sources give you real-time visibility into assets across platforms, cut manual effort, and keep data consistent.
Steps:
- Configure integrations with EDR, MDM, directory services, cloud solutions, and vulnerability management platforms.
- Make sure each on-prem solution has an Explorer to run through; cloud solutions don’t need one.
Full-spectrum exposure detection
Correlate Rapid Response insights, asset-level context, control coverage gaps, and enriched vulnerability data for full visibility across your environment. Layering these sources speeds up detection, sharpens prioritization, and focuses your response.
Rapid Response findings and asset-level pivoting
Investigate Rapid Response findings by moving from high-level dashboards to individual assets. The workflow brings together threat intelligence, exposure history, and asset impact so you can act fast.
Steps:
- Review the Risk Dashboard.
- Read the Rapid Response blog for past examples.
- Open the Rapid Response queries to examine historical trends.
Network misconfiguration findings and control coverage gaps
Use targeted queries and contextual inventory views to find network misconfigurations and security control gaps, such as missing EDR or VM coverage. You can then prioritize risk reduction around the real gaps in your defenses.
Steps:
- Review sample network misconfiguration findings.
- View all assets with an associated finding.
- View assets missing EDR coverage.
Vulnerability enrichment and inside-out findings
Add context to your vulnerability management with KEV status, exposure points, and related asset attributes. Combine these filters with the Network Map to trace exploitable attack paths and rank choke points.
Steps:
- Review KEV (Known Exploited Vulnerabilities) findings.
- View assets with a finding and vulnerability on the KEV.
- Open the Network Map filtered to assets with an associated finding to see the pivot points and choke points among them.
Risk prioritization and insights
Tie dashboards, alerts, and asset context to risk so the issues that matter most surface first. Customizable workflows and real-time metrics improve your decisions and cut noise.
Custom dashboards for dynamic visibility
Build dashboards around your environment and objectives. Combine stock widgets, saved queries, and custom metrics to track what matters and surface trends.
Steps:
- Go to the runZero home page to create a new dashboard.
- Click Widgets to add your selection.
Rules and alerts for automated monitoring
Turn searches into alerts with rules that notify your team of meaningful changes. Templates and channels make alerts quicker to create and deliver.
Steps:
- See the sample alert templates.
- Go to create rule.
- Finalize the logic, review, and save.
Asset criticality, ownership, and search filters
Tag assets with criticality and ownership metadata to sharpen search results and response. These values also drive automated rule actions.
Steps:
- Search for specific assets in the inventory view.
- Update asset criticality or ownership directly from the inventory.
- Use a rule with the Modify assets Action to update the values you want.
Compliance, reporting, and KPIs
Compliance standards call for accurate asset tracking, secure configurations, and effective vulnerability management. runZero simplifies all three to help you meet regulatory demands.
Comply with asset inventory and discovery requirements of relevant frameworks
Meet industry standards with accurate, complete asset discovery, and demonstrate compliance through detailed inventory and reporting. A complete inventory helps you satisfy regulatory audits. Combining active, passive, and integration-based discovery leaves no asset overlooked.
Steps:
- Review documentation mapping runZero to compliance frameworks.
- Review the active, passive, and integration options.
- Use the task history to see when scans or integrations ran.
- Display the inventory for real-time compliance visibility.
Comply with secure configuration requirements of relevant frameworks
Find and fix insecure protocols and configurations to meet secure configuration standards and stay in line with regulatory requirements. Secure configurations cut the risk from legacy protocols and insecure settings. Automation speeds up identifying and remediating issues.
Steps:
- Review documentation mapping runZero to compliance frameworks.
- Search for insecure protocols such as FTP, TFTP, Telnet, and HTTP.
- Save the searches for tracking and add them to a dashboard for reporting.
Comply with malware protection requirements of relevant frameworks
Integrate your Endpoint Detection and Response (EDR) solutions to meet malware protection standards, then find and close protection gaps. Effective malware protection depends on real-time monitoring and quick response. With the range of integration options, you can detect and resolve gaps faster.
Steps:
- Review documentation mapping runZero to compliance frameworks.
- Review EDR integrations and options for custom integration.
- Search for gaps in EDR and alert on newly found gaps.
Comply with vulnerability management requirements of relevant frameworks
Use integrations and the inventory to meet vulnerability management requirements and track vulnerabilities until they’re fixed. Meeting those requirements takes continuous monitoring, prioritization, and remediation. Automation gives you the insight to keep each step moving.
Steps:
- Review documentation mapping runZero to compliance frameworks.
- Search for gaps in vulnerability scanning.
- Use the vulnerability inventory with KEV and EPSS enrichment for deeper insight.