AlienVault® USM Anywhere™

Running Asset Groups Scans

Role Availability Read-Only Analyst   Manager

USM Anywhere enables you to run a scan against assets included in an asset groupAsset groups are administratively created objects that group similar assets for specific purposes.. To accomplish this goal, the scanner sends crafted packetsTerm used when you are constructing your packets manually; might be used for fuzzying or testing protocols, as you can create exceptional situations that might be useful to evade IDSs or firewalls. They can also be used to fingerprint an asset, for vulnerability analysis, or scans. to the target asset group and analyzes the responses. This is not an authenticated scan.

Note: If you want to discover new assets you can run an asset discovery scan, see Running an Asset Discovery.

To run an asset group scan from Asset Groups

  1. Go to Environment > Asset Groups.
    • Next to the asset group name that you want to scan, click the icon , select Full Details, and then select Actions > Asset Group Scan.

      or

    • Next to the asset group name that you want to scan, click the icon and select Asset Group Scan to directly start the asset group scan.
  2. Select the scan profile that you want to run:

    Select Set Debug Mode if you want to log the results of the scan or if you have a problem with a scan. This option is disabled by default.

    Note: Keep in mind that the Set Debug Mode option must be used only for debugging purposes because it needs a large amount of disk space for the file or files that it generates. These files must be only reviewed by the AT&T Cybersecurity Technical Support department. You can contact this department for more information.

  3. Click Scan.
  4. In the Asset Groups details page, click Scan History in the table area to display the results of the scan. You can see the status of each scan and the details.

Note: See Scheduling Asset Group Scans for more information about how to schedule an asset group scan.

Running an Asset Discovery

Asset Discovery finds and provides you visibility into the assetsAn IP-addressable host, including but not limited to network devices, virtual servers, and physical servers. in your environments. You can discover all the IP-enabled devices on your network, determining what software and services are installed on them, how they are configured, and active threats being executed against them.

To run an asset discovery from Settings

  1. Go to Data Sources > Sensors to open the Sensors page.
  2. Click the sensorSensors are deployed into an on-premises, cloud, or multi-cloud environment to collect log and other security-related data. This data is normalized and then securely forwarded to USM Anywhere for analysis and correlation. you want to run an asset discovery.
  3. Click the Asset Discovery tab to open the Asset Discovery new window.
  4. Click Yes to scan the network. This step may be different depending on the sensor you have installed.
  5. Note: In AWSSuite of cloud computing services from Amazon that make up an on-demand computing platform. Sensors this option is not available because the instances are automatically set.

  6. Click Scan Another to start a new scan or click Next to continue with the following step.
  7. In the Asset Groups details page, click Scan History in the table area to display the results of the scan. You can see the status of each scan and the details.