Documentation Center
AlienVault® USM Anywhere™

Running Asset Groups Scans

  Role Availability   Read-Only   Analyst   Manager

USM Anywhere allows you to run a scan against assets included in an asset groupAsset groups are administratively created objects that group similar assets for specific purposes.. To accomplish this goal, the scanner sends crafted packetsTerm used when you are constructing your packets manually; might be used for fuzzying or testing protocols, as you can create exceptional situations that might be useful to evade IDSs or firewalls. They can also be used to fingerprint an asset, for vulnerability analysis, or scans. to the target asset group and analyzes the responses. This is not an authenticated scan.

Note: If you want to discover new assets you can run an asset discovery scan, see Running an Asset Discovery.

To run an asset group scan from Asset Groups

  1. Navigate to ENVIRONMENT > ASSET GROUPS.
    • Click the blue chevron icon () located next to the asset group name you want to scan, select Full Details, and then click Actions > Asset Group Scan.

      or

    • Click the blue chevron icon () located next to the asset group name you want to scan and select Asset Group Scan to directly start the asset group scan.

    The Scan Asset popup window displays.

  2. Select the scan profile you want to run

  3. Click Scan.
  4. In the Asset Groups details page, click the Scan History tab in the table area to display the results of the scan. You can see the status of each scan and the details.

Note: See Scheduling Asset Group Scans for further information about how to schedule an asset group scan.

Running an Asset Discovery

Asset Discovery finds and provides you visibility into the assetsAn IP-addressable host, including but not limited to network devices, virtual servers, and physical servers. in your environments. You can discover all the IP-enabled devices on your network, determining what software and services are installed on them, how they’re configured, and active threats being executed against them.

To run an asset discovery from Settings

  1. Navigate to DATA SOURCES > SENSORS.
  2. The Sensors page displays.

  3. Click on the sensorSensors are deployed into an on-premises, cloud, or multi-cloud environment to collect log and other security-related data. This data is normalized and then securely forwarded to USM Anywhere for analysis and correlation. you want to run an asset discovery.
  4. Click the Asset Discovery tab.
  5. The Asset Discovery popup window displays.

  6. Click Yes to scan the network. This step may be different depending on the sensor you have installed.
  7. Note: In AWSSuite of cloud computing services from Amazon that make up an on-demand computing platform. Sensors this option is not available because the instances are automatically set.

  8. Click Scan Another to start a new scan or click Next to continue with the following step.
  9. In the Asset Groups details page, click the Scan History tab in the table area to display the results of the scan. You can see the status of each scan and the details.