Using the inventory

View as Markdown

The inventory page is the heart of runZero Network Discovery and the key to understanding what is on your network. The inventory shows all assets in the Organization, and you can sort, filter, and export it to get specific views of your environment.

Understanding assets

In runZero, an asset is a unique network entity. An asset may have multiple IP addresses and MAC addresses, and those addresses may change as the environment changes. runZero tracks assets with several heuristics, including MAC address, IP address, hostnames, and fingerprint results for the operating system and running services.

In most cases, runZero can follow assets accurately over time in environments using DHCP, even across remote subnets. For external networks, a scan started with fully qualified hostnames consolidates assets by hostname, so cloud-based external systems with dynamic IP addresses stay tracked consistently.

Within an organization, assets are isolated by site, and each site can have address space that overlaps with other sites. When they overlap, sorting the Inventory view by the site column can help, as can filtering the Inventory by a specific site name.

The search field filters the inventory by the criteria you enter. The search query syntax documentation covers the details.

Beyond viewing assets, you can export data from the Inventory page, select assets, and set the comments field. The Rescan action rescans specific systems from the inventory, and Remove Assets and Purge Assets permanently remove data from the inventory view.

You can also share an inventory query as a read-only snapshot with people outside runZero through external reporting.

The Reports button is a shortcut to the main reports on the runZero reports page.

Supported asset types

IT

  • ADSL Modem
  • ADSL Router
  • ATM
  • ATM DSL Unit
  • BMC
  • Broadband Router
  • Cable Modem
  • Desktop
  • Docking Station
  • DOCSIS Cable Modem
  • DSL Modem
  • DSLAM
  • DSU/CSU
  • Ethernet Adapter
  • Fax Server
  • Firewall
  • Frame Relay
  • Hypervisor
  • IDS
  • IPS
  • JTAG Adapter
  • KVM
  • Laptop
  • Lights Out Management
  • Load Balancer
  • Mainframe
  • Management Console
  • Management Processor
  • Media Gateway
  • Media Server
  • Multiplexer
  • NAC
  • NAS
  • Network Appliance
  • Network Management
  • Network Scanner
  • Onboard Administrator
  • Optical Line Terminal
  • PABX
  • Paging Terminal
  • PBX
  • Power Device
  • Powerline
  • Print Server
  • Printer
  • Remote Terminal
  • Router
  • SD-WAN Appliance
  • Security Appliance
  • Security Gateway
  • SIP Gateway
  • SSL-VPN
  • Storage
  • Storage Appliance
  • Tablet
  • Tape Library
  • Terminal Server
  • Thin Client
  • USB Server
  • VoIP Gateway
  • VoIP Router
  • VoIP Server
  • VoIP Switch
  • VPN
  • WAF
  • WAN Accelerator
  • WAP
  • Web Proxy
  • Wireless Controller
  • Wireless Dock
  • Wireless Ethernet Bridge
  • Wireless LAN Controller
  • WLAN Repeater

OT

  • AC Drive Device
  • BACnet Router
  • Building Automation
  • Data Logger
  • DCS
  • Device Server
  • Engineering Workstation
  • Ethernet IO Module
  • Frequency Converter
  • General Purpose Analog I/O
  • General Purpose Discrete I/O
  • High-Speed Counter
  • Historian
  • HMI
  • HMI Controller
  • IED
  • Industrial Control
  • Industrial Robot
  • Motion Control
  • Motion Controller
  • Motor Drive
  • PLC
  • Position Controller
  • Power Relay
  • Process Controller
  • Protocol Gateway
  • PXI Switch Module
  • Redundancy Module
  • Relay Controller
  • Remote Access Server
  • RTU
  • Safety Controller
  • Safety PLC
  • SCADA
  • Servo Controller
  • Servo Drive
  • SIS
  • Soft Starter
  • Specialty I/O
  • Traffic Control
  • Variable Frequency Drive
  • VFD

IoT

  • 3D Printer
  • Access Control
  • Access Controller
  • Air Quality Monitor
  • Alarm Panel
  • Amazon Device
  • Audio Encoder
  • Audio/Video Switch
  • Automobile
  • AV Appliance
  • AV Controller
  • AV Receiver
  • Barcode Scanner
  • Check Scanner
  • Clock
  • Copier
  • Dishwasher
  • Display Controller
  • DVR
  • Environment Control
  • Exercise Equipment
  • Game Console
  • Handheld Blood Analyzer
  • Handheld Scanner
  • Home Appliance
  • IoT
  • IP Camera
  • IP Phone
  • IPTV
  • IR Network Adapter
  • Irrigation Control
  • Lab Equipment
  • Laboratory Instrument
  • Light Bulb
  • Light Switch
  • Mattress
  • Media Player
  • Media Receiver
  • Multifunction Device
  • Musical Instrument
  • Network Audio
  • NVR
  • PDU
  • Point of Sale
  • Power Meter
  • Presenter
  • Projector
  • Radio
  • Room Controller
  • Scale
  • Security System
  • Sensor
  • Set-Top Box
  • SIP Device
  • Smart TV
  • Smart Watch
  • Thermal Imager
  • UPS
  • Vacuum Cleaner
  • Video Conferencing
  • Video Decoder
  • Video Encoder
  • Voice Appliance
  • Voice Assistant
  • VoIP Intercom
  • VR Headset
  • Water Meter
  • Whiteboard
  • Wireless Presenter

Loading assets

The Scan and Import buttons load data into the inventory. runZero analyzes and merges the results and updates asset information as needed.

The Scan button has two options: Standard Scan and Full RFC 1918 Discovery. The second option sets up a fast scan of all private range IP addresses. Afterwards, the coverage reports show whether assets turned up in unexpected private address ranges.

The Import button has two options. With imported runZero scan data, you can scan networks that have no connectivity to the internet and still view the results in the runZero console. Importing is also useful for reprocessing old scan data, so the site compare feature can show how assets have changed over time.

Bulk asset update

With bulk asset update, you modify assets by exporting a CSV with the Export button, editing the data in a spreadsheet program or text editor, and importing the result back into runZero with the Import button. The import updates existing assets in the organization that have a matching id value.

Bulk asset update can change these fields:

  • Type
  • Operating system
  • OS version
  • Hardware
  • Comments
  • Tags
  • Owner
  • Names
  • Domains

The type, os, os_version, and hardware fields accept only a single value. The comments, tags, owner, names, and domains fields each accept multiple values, written as a space-delimited list of field=value pairs. The tags field also accepts a plain space-delimited list of values without tag=.

Only changes to the tags, comments, and owners fields survive later scans. The latest scan data overwrites changes to the other supported fields.

Removing tags from assets

To remove a tag from one or more assets, select the assets in the inventory with the Select button in the toolbar, then click Modify and choose Set asset tags. In the tag editor, prefix the tag you want to remove with a minus sign (-). runZero removes the matching tag and leaves the asset’s other tags in place.

-tag_name
-tag_name=value

For example, enter -env to remove the env tag, including tags such as env=prod. To remove only a specific tag value, enter -env=prod; other env tags remain in place.

This pattern also works in bulk updates that modify multiple assets at once. If you edit the tags field in a bulk asset update CSV before using Import, the same -tag syntax removes tags from the selected assets.

To remove all tags from a single asset, open the asset details page, click Manage in the top-right corner, and choose Unmerge asset. runZero deletes the current asset record and reprocesses it, which drops stale tags and keeps the valid tags from the most recent tasks.

Connecting to other systems

Community Platform

The Connect button connects runZero to other systems. Which integrations you can connect depends on your license level, but they may include cloud and virtualization platforms, endpoint protection solutions, identity and access management tools, and vulnerability and risk platforms. You can also configure these inbound integrations as scan probes if required.

Viewing services

The Services submenu on the Inventory page switches the table from an asset-focused view to a service-focused view, with one row for each service runZero detected on each asset.

Like the main asset view, the services view has a full search interface. You can filter services by protocol, port, and many other criteria, using the runZero search language.

Note
runZero does not enumerate Windows services through the Service Control Manager because active scanning is unauthenticated. In some cases, you may still see limited Windows service details from unauthenticated DCE/RPC Endpoint Mapper (EPM) data, which runZero uses primarily to identify WiFi and WLAN service availability.

Viewing screenshots

If the runZero Explorer has access to Google Chrome, it attempts to take screenshots of the web pages it finds while scanning your network. You can disable this in the scan options when you set up the scan.

The Screenshots submenu shows the screenshots for all of your assets, and each one links through to the asset record for full details.

Viewing software

The Software submenu on the inventory page flips the table from an asset-focused view to a software-focused view, with one row for each piece of software that runZero or a supported integration detected on each asset.

Like the main asset view, the software view has a full search interface. You can filter software by vendor, product, and many other criteria, using the runZero search language.

Viewing vulnerabilities

The Vulnerabilities submenu on the inventory page flips the table from an asset-focused view to a vulnerability-focused view, with one row for each vulnerability that a supported integration detected on each asset.

Like the main asset view, the vulnerability view has a full search interface. You can filter vulnerabilities by CVSS score, name, CVE, and many other criteria, using the runZero search language.

Viewing certificates

The Certificates submenu opens the certificates inventory: every encryption certificate the runZero Explorer encountered while scanning, in a view you can search and sort like the others.

Viewing wireless networks

If the machine running the runZero Explorer has a working WiFi adapter and the right system tools installed, the Explorer attempts to scan for nearby wireless networks. The Wireless submenu shows the results.

The required tools are:

  • Windows: netsh.exe (part of modern Windows releases)
  • macOS: Airport Utility
  • Linux: iwlist, often available via the wireless-tools package.

Viewing users and groups

The users and groups inventory pages hold data imported from directory services such as Active Directory. Third-party integrations listed under Directory services in the Integrate drop-down menu populate the user directory and group directory.

Updated