Running Asset Scans

Role Availability Read-Only Investigator Analyst Manager

Use an asset An IP-addressable host, including but not limited to network devices, virtual servers, and physical servers. scan to discover hosts Reference to a computer on a network. and services in the deployed network. To accomplish this goal, the scanner sends crafted packets Term used when you are constructing your packets manually; might be used for fuzzying or testing protocols, as you can create exceptional situations that might be useful to evade IDSs or firewalls. They can also be used to fingerprint an asset, for vulnerability analysis, or scans. to the target asset and analyzes the responses. This is not an authenticated scan Authenticated scans are performed from inside the machine using a user account with appropriate privileges.. You can run scans on individual assets.

The asset for which you are scanning must be visible by the sensor through the network. This means that both the sensor and the asset should be able to see each other through at least Layer 3 (network) protocols. If the sensor and the asset are in the same network segment (Layer 2), use Address Resolution Protocol (ARP) requests to discover the asset.

The USM Anywhere Sensor sends ARP, Internet Control Message Protocol (ICMP), and TCP requests to discover hosts on the network to which the sensor is connected. A new asset is created if the sensor receives an acknowledgment from any of the previously mentioned protocols.

Note: If a scan is suspended or otherwise running for more than two hours, it will time out. You can see the timeout result in the asset's Scan History, as well as in the system event generated for that scan.

Important: You cannot scan USM Anywhere Sensors.

Enabling the Asset Scanner App

To enable the Asset Scanner App

  1. Go to Data Sources > Sensors to open the Sensors page.
  2. Click the USM Anywhere Sensor for which you want to enable the asset scanner app.
  3. Click the Asset Scanner tab.

    Note: This item is not available on Amazon Web Services (AWS) sensors.

  4. Click Enable.

    Asset Scanner Tab on the Sensor Page

Running Asset Scans from Assets

To run an asset scan from Assets

  1. Go to Environment > Assets.
  2. Complete one of these options to open the Scan Asset dialog box:
    • Next to the asset name that you want to scan, click the icon, select Full Details, and then select Actions > Asset Scan.
    • Next to the asset name that you want to scan, click the icon, and then select Asset Scan.

    The Asset Scan dialog box opens.

    Scan Asset Dialog Box

  3. Select the scan profile that you want to run:

  4. Select Set Debug Mode if you want to log the results of the scan or if you have a problem with a scan.

    This option is disabled by default.

    Note: The Set Debug Mode option must be used only for debugging purposes because it needs a large amount of disk space for the file or files that it generates. Only AT&T Cybersecurity Technical Support should review these files. You can contact this department for more information.

  5. Click Scan.
  6. In the Asset details page, click Scan History in the table area to display the results of the scan.

    You can see the status of each scan and the details. USM Anywhere also creates a system event named Asset Scanner Result with the same details.

Important: Make sure the Asset Scanner app is enabled. See Enabling the Asset Scanner App for more information.

Note: See Scheduling Asset Scans from Assets and Scheduling Asset Scans from the Job Scheduler Page for more information about how to schedule an asset scan.

Running Asset Scans When Creating a New Asset

To run an asset scan when you are creating a new asset

  1. Go to Environment > Assets.
  2. Select Actions > Advanced to open the Create New Asset dialog box.
  3. See Adding Assets in the UI for more information.

  4. The Scan the newly added asset for asset details field is selected by default. Use it for scanning the newly added asset.

    Important: The Asset Scan options are available only for the VMware Sensor and Hyper-V Sensor. USM Anywhere uses the Discovery profile to conduct the scans.

    Create New Asset: Scan the newly added asset for asset details

  5. Click Save.
  6. A message displays at the top of the page to inform you that the scan has been launched and is running. When the scan is complete, the results are visible in the tab Scan History of the asset details page. See Viewing Assets Details for more information.