Inspector Software Appliance User Guide

Similar documents
Reporter User Guide RapidFire Tools, Inc. All rights reserved Ver 4T

Remote Data Collector Installation and User Guide

Detector Service Delivery System (SDS) Version 3.0

HIPAA Compliance Module. Using the HIPAA Module without Inspector Instructions. User Guide RapidFire Tools, Inc. All rights reserved.

PCI Compliance Assessment Module

PCI Compliance Assessment Module with Inspector

Datto BDR Needs Assessment Module

INSTALLATION GUIDE. Virtual Appliance for Inspector and Reporter 9/20/2018 1:32 PM

Virtual Appliance Installation Guide

ForeScout Extended Module for Tenable Vulnerability Management

Scanning-Less Scanning. Installation Guide

HIPAA Compliance Assessment Module

High Availability Enabling SSL Database Migration Auto Backup and Auto Update Mail Server and Proxy Settings Support...

ForeScout Extended Module for ServiceNow

ForeScout Extended Module for Advanced Compliance

INSTALLATION GUIDE. RapidFire Tools Server for Cyber Hawk 9/20/2018 2:28 PM

Version 2.3 User Guide

About XenClient Synchronizer

ForeScout Extended Module for Qualys VM

Configuring the SMA 500v Virtual Appliance

ZENworks 2017 Audit Management Reference. December 2016

ForeScout CounterACT. (AWS) Plugin. Configuration Guide. Version 1.3

Global Management System (GMS) Virtual Appliance 6.0 Getting Started Guide

Copyright 2015 Integrated Research Limited

Comodo HackerGuardian Software Version 10.0

VPN Solutions for Zerto Virtual Replication to Azure. IPSec Configuration Guide

Veritas System Recovery 18 Management Solution Administrator's Guide

ForeScout Extended Module for IBM BigFix

Installation and Configuration Guide

Drobo 5D3 User Guide

SonicWall Secure Mobile Access SMA 500v Virtual Appliance 8.6. Getting Started Guide

Online Help StruxureWare Data Center Expert

Forescout. eyeextend for Palo Alto Networks Wildfire. Configuration Guide. Version 2.2

SyAM Software Management Utilities. Client Deployment

1.0. Quest Enterprise Reporter Discovery Manager USER GUIDE

Dell SupportAssist Agent User s Guide

OpenManage Integration for VMware vcenter Quick Install Guide for vsphere Client, Version 2.3.1

Dell SupportAssist for PCs and Tablets User s Guide

Print Audit 5 - Step by Step Walkthrough

DOCUMENTATION. UVM Appliance Azure. Quick Start Guide

IBM FlashSystem 720 & FlashSystem 820 Remote Support Overview

SRA Virtual Appliance Getting Started Guide

ForeScout Extended Module for ArcSight

ForeScout CounterACT. Assessment Engine. Configuration Guide. Version 1.0

version 5.4 Installation Guide

WhatsConfigured for WhatsUp Gold 2016 User Guide

KYOCERA Net Admin User Guide

vcenter CapacityIQ Installation Guide

Installation and Configuration Guide

vsphere Update Manager Installation and Administration Guide 17 APR 2018 VMware vsphere 6.7 vsphere Update Manager 6.7

ARCSERVE UDP CLOUD DIRECT DISASTER RECOVERY APPLIANCE VMWARE

User Guide. Version R95. English

This guide details the deployment and initial configuration necessary to maximize the value of JetAdvantage Insights.

OPC UA Configuration Manager Help 2010 Kepware Technologies

Task Scheduling. Introduction to Task Scheduling. Configuring a Recurring Task

Configuration Guide. Requires Vorex version 3.9 or later and VSA version or later. English

Drobo 5N2 User Guide

Platform Compatibility... 1 Enhancements... 2 Known Issues... 3 Upgrading SonicOS Enhanced Image Procedures... 3 Related Technical Documentation...

ForeScout CounterACT. Plugin. Configuration Guide. Version 2.1

VMware vfabric Data Director Installation Guide

ForeScout Extended Module for Carbon Black

AppSpider Enterprise. Getting Started Guide

Table of Contents. Introduction to PerfectStorage... 1

ForeScout Extended Module for ServiceNow

User Guide. Version R9. English

CounterACT VMware vsphere Plugin

Client Installation and User's Guide

vcenter Server Heartbeat Administrator's Guide VMware vcenter Server Heartbeat 6.6 Update 2

USER GUIDE Deployment

System, Environment, & Configuration Requirements for FASTER Web 6.4

Fiery proserver User Guide

TechDirect User's Guide for ProDeploy Client Suite

1 Drobo 8D User Guide Before You Begin Product Features at a Glance Checking Box Contents... 9

Altaro Hyper-V Backup User Guide

Quick St Copyright (c) Silve

Server Installation. Parent page: System Installation, Licensing & Management

Synchronizer Quick Installation Guide

Cyber security tips and self-assessment for business

Veritas System Recovery 16 Management Solution Administrator's Guide

Application Notes for Installing and Configuring Avaya Control Manager Enterprise Edition in a High Availability mode.

All Applications Release Bulletin February 2013

Wavelink Communicator User Guide

Installing VMware vsphere 5.1 Components

vcenter CapacityIQ Installation Guide

Novell ZENworks 10 Patch Management SP3

Forescout. eyeextend for IBM BigFix. Configuration Guide. Version 1.2

UNICORN Administration and Technical Manual

IPM Secure Hardening Guidelines

vcenter Support Assistant User's Guide

Using OptiView Console

PropertyBoss Upgrade

Nextiva Drive The Setup Process Mobility & Storage Option

Installing and Administering VMware vsphere Update Manager. Update 2 VMware vsphere 5.5 vsphere Update Manager 5.5

Welcome to PDQ Inventory

vcenter Support Assistant User's Guide

Windows Me Plug-and-Play

Client Installation and User's Guide

Provisioning the K1000 Agent

1. ECI Hosted Clients Installing Release 6.3 for the First Time (ECI Hosted) Upgrading to Release 6.3SP2 (ECI Hosted)

Dell SupportAssist for PCs. User's Guide for Windows 10 in S Mode

Transcription:

User Guide 2017 RapidFire Tools, Inc. All rights reserved 20170804 Ver 3V

Contents Overview... 3 Components of the... 3... 3 Inspector Diagnostic Tool... 3 Network Detective Application... 3 Features... 4 Network Assessment Network Scan... 4 Layer 2/3 Discovery of Network Devices (Exclusive to the Inspector)... 4 Internal Vulnerability Scan (Exclusive to the Inspector)... 4 HIPAA Compliance and Risk Assessment Scans... 5 PCI Compliance and Risk Assessment Scans... 5 External Vulnerability Scan... 5 Automated Assessment Reporting... 5 Remote Updating of the... 5 Automated Scanning and Scheduling Best Practices... 6 Getting Started... 7 Deployment Options... 7 Inspector System Requirements... 7 Setting Up Inspector... 8 Initial Set Up of the Inspector Appliance... 8 Connecting the Optional Small Form Factor Server Computer... 8 Starting the on Hyper-V and VMware... 9 Associating the Inspector Appliance to a Network Detective Site... 9 Adding an Inspector to a Site... 9 Creating New Scans... 12 Selecting and Configuring Data Collection Scans Using Inspector... 15 Network Scan... 15 SQL Server Data Collection... 23 Local Data Scans... 24 Internal Vulnerability Scan... 26 1

Layer 2/3 Discovery and Network Scan... 32 HIPAA Compliance Scans... 40 PCI Compliance Scans... 40 External Vulnerability Scan... 42 Managing the Scan Queue... 43 Scheduling a Scan... 46 Scan Task Library versus Scan Tasks Queue... 47 Cancelling a Scan... 47 Downloading Scans... 48 Configuring the Local Data Scan Merges... 50 Using the Manage Inspector Appliance Feature to Configure Automatic Report Generation... 54 Setting Up Automatic Reports for Network Assessments... 54 Setting Up Automatic Reports for Security Assessments... 57 Setting Up Automatic Reports for SQL Server Assessments... 60 Setting Up Automatic Reports for HIPAA Compliance Assessments... 63 Setting Up Automatic Reports for PCI Compliance Assessments... 66 Updating a Software Appliance... 69 Appendices... 71 Appendix I... 71 Inspector Diagnostic Tool... 71 2

Overview The is an appliance-based system used for performing scheduled IT assessment scans and deeper dive diagnostics. This guide is designed to provide an overview and specific steps required to install and configure the and schedule the collection of network and security assessment data, SQL Server assessment data, Internal Network Vulnerability assessment data, Layer2/3 Discovery and Network assessment data, Local Login Anomaly assessment data, HIPAA Compliance assessment data, and PCI Compliance assessment data to be used with other Network Detective modules. Components of the This is the Inspector software application that operates on either the Network Detective Hardware Appliance or on a user supplied Microsoft Hyper-V based system. Optional Network Detective Hardware Appliance This is an optional hardware component that can be purchased from RapidFire Tools to host and operate the. It is a small, portable appliance which plugs into the target network through an Ethernet connection. Inspector Diagnostic Tool This tool is used for configuring and troubleshooting the Inspector. The Diagnostic Tool should be run on the same network as the Inspector to perform diagnostics checks such as for Inspector connectivity or for available updates. Network Detective Application This is the same Network Detective desktop application and report generator that is used with any other Network Detective modules. This application contains additional features to manage the Inspector remotely. 3

Features One key purpose of the Inspector is to perform scans from the point-of-view of the client s internal network. Below is an overview of the scans that can be performed by the. Network Assessment Network Scan Note that this feature requires the Network Assessment Module. The full Network Assessment Scan from the point-of-view of the. The resulting scan can be used to generate reports from the Network Assessment module. Layer 2/3 Discovery of Network Devices (Exclusive to the Inspector) Run when the Network Assessment Network Scan is executed. Scans network devices for Layer 2 and Layer 3 connectivity information. The scans are used to generate Layer 2/3 diagram and detail reports. Internal Vulnerability Scan (Exclusive to the Inspector) This scan takes advantage of the point-of-view provided by being connected to the client s internal network. Data is collected about Open Ports and Protocol Vulnerability that would be exploited once a hacker is in the network. The Internal Vulnerability Scan focuses on INSIDE attacking INSIDE whereas the External Vulnerability scan checks for OUTSIDE attacking EDGE (INSIDE). Internal vulnerability scans are similar to external vulnerability scans; however, are performed from inside the target network. They look for vulnerabilities that are normally blocked externally by firewalls. Within a network, un-patched or vulnerable systems may exist that an external scan may not capture. This scan option performs a vulnerability scans with additional options which may be more intensive than the external equivalent. Please be aware that the scans may be resource intensive and should be run during non-business hours if possible. 4

HIPAA Compliance and Risk Assessment Scans Note that this feature requires the HIPAA Assessment Module. These network and local scans can be scheduled and executed by Inspector in order to identify ephi, network vulnerabilities, security vulnerabilities, and local computer vulnerabilities necessary to perform a HIPAA IT Risk Assessment. PCI Compliance and Risk Assessment Scans Note that this feature requires the PCI Assessment Module. These network and local scans can be scheduled and executed by Inspector in order to identify credit/debit card Primary Account Number (PAN) data, network vulnerabilities, security vulnerabilities, and local computer vulnerabilities necessary to perform a PCI Data Security Standard (DSS) Compliance and IT Risk Assessment. External Vulnerability Scan External Vulnerability scans are performed at the external Network Edge to check for security holes and weakness that can help you help make better network security decisions. The External Vulnerability Scan performed by Inspector includes a full NMap Scan which checks all 65,535 ports and reports which are open. This is an essential scan and is a standard security check to ensure a viable security policy has been defined, implemented and maintained to protect the network from outside attacks Automated Assessment Reporting Automatic Report Generation enables you to use the Inspector to schedule and generate of a number of assessment reports associated with the following: Network Assessments Security Assessments SQL Server HIPAA Compliance Assessments PCI Compliance Assessments Remote Updating of the The is easy to update remotely. Updates include bug fixes, new features, and additional scans types. 5

Automated Scanning and Scheduling Best Practices It is recommended that Network, Local Computer, External Vulnerability, Layer 2/3 Discovery and Network, and the Local Collector Push for Login Anomaly Reporting scans are scheduled to be performed on a weekly basis. It is recommended that Internal Vulnerability scans are scheduled to be performed on a monthly basis or after any significant IT infrastructure change has taken place. 6

Getting Started Deployment Options There are two deployment options available to users: deployment on a user owned and operated Hyper-V base system deployment on the Network Detective Hardware Appliance Inspector System Requirements Below are the minimum requirements for installing and operating Inspector. Please note the Operational Requirements that must be met after Inspector has been installed and deployed. Hyper-V Install Requirements: Hyper-V Enabled Operating System (Windows 8.1+) 6 GB Available RAM 40 GB Hard Drive Space VMware Install Requirements: ESXi 5.5+ 6 GB Available RAM 40 GB Hard Drive Space Operational Requirements: i5 Processor for dedicated use. Xeon server class processors for non-dedicated. 16 GB Available RAM 40 GB Hard Drive Space 7

Setting Up Inspector Initial Set Up of the Inspector Appliance 1. Install the Inspector Appliance on your client s network by either: a) going to www.rapidfiretools.com/nd to download and install the Network Detective Virtual Appliance on a Hyper-V or VMware enabled computer operating within your client s network. For more information about installing the Virtual Appliance, please download the Virtual Appliance Installation Guide. b) connecting the Inspector Appliance installed on the Small Form Factor Server Computer that you purchased from RapidFire Tools to your client s Network. For more information on connecting the Small Form Factor Computer to your network, refer to the next section below. After the installation of the Inspector Appliance is complete, be sure to allocate the memory resources necessary to meet the minimum system Operational Requirements as detailed in the Inspector System Requirements section above. 2. After successfully deploying the Inspector Appliance, visit www.rapidfiretools.com/nd to download and install the latest version of the Network Detective Application. Then run Network Detective and login with your credentials. 3. Create a new Site by selecting the New Site option. Set the Site Name for the Site in Network Detective. Select the OK button to create the site. Connecting the Optional Small Form Factor Server Computer To set up the Small Form Factor Server Computer used to operate the, first go to the physical location of the target network. After finding a secure location for the device, connecting it to the network can be accomplished in two easy steps: 8

Starting the on Hyper-V and VMware Start the on the Hyper-V or VMware based system. Take note of the Inspector Appliance ID which will be required when you Associate the with your Assessment Project. Associating the Inspector Appliance to a Network Detective Site Before using the, the Inspector must be associated with a Site in the Network Detective Application. Adding an Inspector to a Site After starting a new assessment, or within an existing assessment, in order to Associate an Inspector Software Appliance with the Assessment Project, you must first select the V symbol to expand the assessment properties view. This action will expand the Assessment s properties for you to view and to add a Software Appliance to the Assessment. To add an Appliance to an Assessment, from the Assessment Window select the Appliance button, then the Appliances Add button as noted above. 9

Select the Appliance ID of the Appliance from the drop down menu. Note: When users have purchased a Network Detective Hardware Appliance, the Appliance ID can be found on a printed label on the Hardware Appliance itself. After successfully adding an Appliance it will appear under the Appliance bar in the Assessment Window. To view a list of all Appliances and their associated Sites, navigate to the Appliance tab from the top bar of the Network Detective Home screen. This will show a summary of all Appliances, their activity status, and other useful information. 10

To return to the Site that you are using to perform your assessment, click on Home above and select the Site that you are using to perform your assessment. 11

Creating New Scans After associating an Appliance with a customer specific Site used for performing assessments, it is very simple to configure Network Scans, Local Computer Scans, Internal Vulnerability Scans, Layer 2/3 Discovery and Network, and the Local Push Collector for Login Anomaly Reporting Scans using the remotely from within the Network Detective desktop application. With the, it is only necessary to go through the configuration and setup of a Network Scan one time. After completing the setup, the Scan configurations will be stored and associated with the to be run either on-demand or on a set schedule. To set up a scan, first, go to the target Site s Assessment Window and verify that an Inspector has been successfully associated with the Site. The Inspector(s) will appear under the Appliances bar. If the Site does not already have an active Assessment, start a new Assessment by clicking Start and following the prompts to choose the desired type of Assessment. If an active Assessment is underway and available, the Assessment will be presented when the Site file is opened. 12

Upon selecting the Active Assessment, you will be directed to the assessment s Assessment Window. From the Site s active Assessment, select Initiate Appliance Scan from the Scans bar. The Manage Appliance Tasks window will be displayed enabling you to select the IT or Compliance Assessment scan you want to perform, configure the scan task, and to store the scan task in the Inspector Task Library for either manual or scheduled execution. 13

If this is the first time a Scan has been initiated from the, follow the Network Detective Data Collector s Create Task prompts to configure the Scan. 14

Selecting and Configuring Data Collection Scans Using Inspector Below is an overview of the scans that can be set-up and performed using the Inspector Software Appliance and the steps to set-up the scans to be performed automatically or manually. Network Scan Note that the Network Assessment Reports are only available as part of the Network Assessment module. Step 1: Initiate Appliance Scan From the Site s active Assessment, select Initiate Appliance Scan from the Import Scans bar. The Manage Appliance Tasks window will be displayed enabling you to select the IT or Compliance Assessment Scan you want to perform, configure the scan task, and to store the scan task in the Inspector Task Library for either manual or scheduled execution. 15

Step 2: Select Scan Type Choose Network Scan from the wizard and click the Next button. 16

Step 3: Input Credentials Input administrative credentials to access the Domain Controller or indicate that the target network does not contain a Domain Controller. Step 4: Select Local Domains Choose either to scan all Domains detected on the target network or to restrict the Scan to selected Organizational Units (OUs) and Domains. 17

Step 5: Input External Domains External Domain names allow others to visit the target site and facilitate services, such as email. Input External Domains here to include them as part of the data collection. Examples of External Domains include: example.com mycompany.biz Step 6: Specify IP Ranges 18

The IP ranges from the target network will be auto-detected and included in the scan. To include additional subnets input them here. Step 7: Add SNMP Information By default, the software will retrieve data from devices with the community string public. If desired, define an additional community string (such as private ) and enter it here. Step 8: Use MBSA Check Run MBSA to perform a weak password check. Check Include Patch Analysis to gather information on missing patches (this second option will increase the time required to perform the scan). 19

Step 9: Verify and Schedule Check Send an email notification when schedule completes to notify a desire address upon completion of the scan. This option is recommended as the time a scan takes to complete varies depending on the target network. Click on the Finish button to complete the scheduling of the Network Scan task which will display the Appliance Tasks and Queue window. The scheduled Network Scan can be confirmed in the Appliance Tasks and Queue window that is displayed in the Task Library list referenced below. 20

Upon viewing the scan task, you can select the run now option link under the Queue column to initiate the scan which will place the scan into the Queued Tasks list. Or, you can click on schedule link to execute the scan sometime in the future by selecting the interval (daily, weekly, monthly, annually, or just once) option and the time that the scan should be scheduled to run. When you click the schedule link, The CRON Builder scheduler window is displayed and is used to set the schedule action s execution time. Please note that the time zone used for the CRON Builder time is Eastern Standard Time (EST). 21

Note the Pending task present in the Queued Task list after the Run Now option has been selected for the Network Scan in the window below. 22

SQL Server Data Collection To create this scan task, perform the following steps: 1. Select the Scan Type SQL Server Collection. 2. Follow the prompts to set-up the Credentials for the SQL Servers being assessed. 3. Verify the settings and Schedule the Scan. Note that the SQL Server Module s Assessment Reports are only available as part of the SQL Server Module subscription. 23

Local Data Scans Configuring Network Local Collection Push Scan 1. Select the Network Local Collection Push scan to perform a network scan on remote computers. 2. Follow the prompts to set-up the Credentials and Remote Computer IP Addresses for the equipment being scanned. 3. Verify the settings and schedule the scan. Configuring Security Local Collector Push Scan 1. Select the Security Local Collector Push Scan to perform a security scan on remote computers. 24

2. Follow the prompts to set-up the Credentials and Remote Computer IP Addresses for the equipment being scanned. 3. Verify the settings and schedule the scan. 25

Internal Vulnerability Scan The Internal Vulnerability Scan is an exclusive feature available through the Inspector. Step 1: Initiate Appliance Scan From the Site s active Assessment, select Initiate Appliance Scan from the Scans bar. The Manage Appliance Tasks window will be displayed enabling you to select the IT or compliance Assessment scan you want to perform, configure the scan task, and to store the scan task in the Inspector Task Library for either manual or scheduled execution. 26

If this is the first time a Scan has been initiated from the Inspector appliance, follow the Network Detective Data Collector Create Task Wizard prompts to configure the Scan. Step 2: Select Scan Type Choose Internal Vulnerability Scan from the wizard and click Next. The Ports to Scan window will be displayed. 27

Step 3: Specify Ports to Scan When the Ports to Scan window is displayed. The Ports to Scan setup option allows you to select one of two available scanning options. One option, referenced as the Standard Scan, is used to scan Standard TCP ports and Top 1000 UDP ports. The second option, referenced as the Comprehensive Scan, is used to execute a comprehensive scan of all TCP ports and Top 1000 UDP ports. To proceed, select the appropriate number of ports to scan for your assessment s purposes. Then select the Next button. The IP Ranges screen will be displayed. Step 4: Specify IP Ranges At this point the Inspector appliance will perform Auto-Detect to identify an IP address range that can be scanned. Alternatively, you can manually set the IP address range that you would like to scan during the scheduled internal vulnerability scan. IMPORTANT: THE AUTO-DETECT FEATURE WILL IDENTIFY THE IP RANGE OF THE INTERNAL SUBNET THAT IS FROM THE INSPECTOR. THIS COULD RESULT IN A SUBSTANTIALLY LARGER NUMBER OF IP ADDRESSES THAT WILL BE SCANNED VERSES THE ACTUAL NUMBER OF WORKSTATIONS, SERVERS, AND OTHER IP-BASED NETWORK COMPONENTS WHICH COULD BE A FAR SMALLER NUMBER. 28

IF THIS INTERNAL VULNERABILTIY SCAN IS CONFIGUED TO INTERROGATE A LARGE NUMBER OF IP ADDRESSES THAT ARE NOT USED BY ANY DEVICE, THE VULNERABILITY SCAN MAY RESULT IN TAKING AN EXPONENTIALLY LONGER TIME THAN NECESSARY. Define the IP Range that you would like to scan and select Next button. The Create Task - Verify and Schedule window will be displayed. Step 5: Verify and Schedule Scan Task After the Create Task - Verify and Schedule window is displayed you can finalize the creation of the scan task. 29

To have an Email Notification sent to you when the scan task completes, select the Send email notification when schedule completes option, and type in the email address where the notification should be sent. Click on the Finish button to complete the scheduling of the internal vulnerability scan task which will display the Appliance Tasks and Queue window. The scheduled internal vulnerability scan can be confirmed in the Appliance Tasks and Queue window that is displayed in the Task Library list referenced below. Upon viewing the scan task, you can select the run now option link under the Queue column to initiate the scan which will place the scan into the Queued Tasks list. Or, you can click on schedule link to execute the scan sometime in the future by selecting the interval (daily, weekly, monthly, annually, or just once) option and the time that the scan should be scheduled to run. 30

When you click the schedule link, The CRON Builder scheduler window is displayed and is used to set the schedule action s execution time. Please note that the time zone used for the CRON Builder time is Eastern Standard Time (EST). Note the Pending task present in the Queued Task list after the Run Now option has been selected for the Vulnerability Scan in the window below. 31

Layer 2/3 Discovery and Network Scan The Layer 2/3 Discovery and Network Scan is an exclusive feature available through the Inspector. Step 1: Initiate Appliance Scan From the Site s active Assessment, select Initiate Appliance Scan from the Scans bar. The Manage Appliance Tasks window will be displayed enabling you to select the IT or Compliance Assessment scan you want to perform, configure the scan task, and to store the scan task in the Inspector Task Library for either manual or scheduled execution. 32

If this is the first time a Scan has been initiated from the Inspector appliance, follow the Network Detective Data Collector prompts to configure the Scan Step 2: Select Scan Type Within the Assessment window, select the scan you are performing. Choose Layer 2/3 Discovery Network Scan from the wizard and click the Next button. 33

Step 3: Input Credentials Input administrative credentials to access the Domain Controller or indicate that the target network does not contain a Domain Controller. Step 4: Select Local Domains Choose either to scan all Domains detected on the target network or to restrict the Scan to selected Organizational Units (OUs) and Domains. 34

Step 5: Input External Domains External Domain names allow others to visit the target site and facilitate services, such as email. Input External Domains here to include them as part of the data collection. Then select the Next button to continue. Examples of External Domains include: example.com mycompany.biz 35

Step 6: Specify IP Ranges The IP ranges from the target network will be auto-detected and included in the scan. To include additional subnets input them here. Then select the Next button to continue. Step 7: Add SNMP Information By default, the software will retrieve data from devices with the community string public. If desired, define an additional community string (such as private ) and enter it here. Then select the Next button to continue. 36

Step 8: Use MBSA Check Run MBSA to perform a weak password check. Check Include Patch Analysis to gather information on missing patches (this second option will increase the time required to perform the scan). Step 9: Verify and Schedule Check Send an email notification when schedule completes to notify a desire address upon completion of the scan. This option is recommended as the time a scan takes to complete varies depending on the target network. 37

Click on the Finish button to complete the scheduling of the Configuring the Layer 2/3 Discovery Network Scan task which will display the Appliance Tasks and Queue window. The scheduled internal vulnerability scan can be confirmed in the Appliance Tasks and Queue window that is displayed in the Task Library list referenced below. Upon viewing the scan task, you can select the run now option link under the Queue column to initiate the scan which will place the scan into the Queued Tasks list. Or, you can click on schedule link to execute the scan sometime in the future by selecting the interval (daily, weekly, monthly, annually, or just once) option and the time that the scan should be scheduled to run. 38

When you click the schedule link, The CRON Builder scheduler window is displayed and is used to set the schedule action s execution time. Please note that the time zone used for the CRON Builder time is Eastern Standard Time (EST). Note the Pending task present in the Queued Task list after the Run Now option has been selected for the Layer 2/3 Discovery Network Scan in the window below. 39

HIPAA Compliance Scans To learn more about how to configure the scans related to a HIPAA Compliance Assessment, please refer to the HIPAA Module with Inspector User Guide. Note that the HIPAA Module s Assessment Reports are only available as part of the HIPAA Module subscription. PCI Compliance Scans To learn more about how to configure the scans related to a PCI Compliance Assessment, please refer to the PCI Module with Inspector User Guide. 40

Note that the PCI Module s Assessment Reports are only available as part of the PCI Module subscription. 41

External Vulnerability Scan To create this scan task, perform the following steps: 1. Choose External Scans Scan Type from the wizard and click the Next button. 2. Select the Scan Type External Vulnerability Scan. 2. Follow the prompts to set-up the IP Addresses of the equipment/network being scanned. 3. Verify the settings and Schedule the Scan. 42

Managing the Scan Queue After going through the steps to Associate the Software Appliance with a Site and configuring Network Scans and storing them in the Task Library, it is a simple process to run either an immediate or scheduled Data Collection on the target network. Note that the Scan configuration process must only be completed one time and the resulting configuration will be stored for future use. This simplifies both automate and remote execution of Data Collections. To view the Scan Queue, first associate your Appliance with a Site. Then navigate to the target Site s Assessment Window. After starting a new assessment, or within an existing assessment, in order to Manage an Appliance within the Assessment Project, you must first select the V symbol to expand the assessment properties view. This action will expand the Assessment s properties for you to view and to add an Appliance to the Assessment. Under the Appliances bar in the Active Assessment window select the Manage button. This will bring up the Manage Appliance window and present the Task Library and the Queued Tasks. 43

Running a Scan On-Demand Scans can be executed immediately through the use of the Run Now feature. To run a Scan configuration, locate the task in the Task Library and select run now. 44

After the task has been queued, it will run as soon as resources are available. A Scan that is run ondemand (i.e. instead of on a schedule) will have no value in the table under the Next Run column. 45

Scheduling a Scan To schedule a scan, select the Schedule option available within a Scan Task listed within the Task Library. To run a Scan configuration on a regular basis or at a future date, locate the Scan in the Task Library and select schedule. This will bring up the CRON Builder. Choose a date, time, or other periodic range from the drop-downs in the CRON Builder. Please note that the time zone used for the CRON Builder time is Eastern Standard Time (EST). After selecting a time frame, the scans will be executed according to the given schedule. Please be aware that only one scan of a particular type can execute on the Inspector appliance at a time. 46

After the schedule is set, the table entry for the Scan in Queued Tasks will display the next run time and whether or not the scan will repeat the schedule. Please be aware that the scans may be intensive and should be run during non-business hours if possible. Scan Task Library versus Scan Tasks Queue The Scan Task Library contains saved Scan configurations which can be run on demand or on a schedule to conduct Network Scans. The advantage of the Scan Task Library is that the Network Scan configurations can be reused and run on-demand or on a schedule. There is no need to repeatedly enter the same information (such as the domain controller password or the IP Range) each time a data collection is performed using this model. The scans Tasks Queue lists the scans that are pending. Cancelling a Scan After the Site has been opened, select the V to expand the Assessment window to view any appliances associated with the site. Then select the Manage option present above the Appliance Status bar. The Manage Inspector window will be displayed. Then view the Queued Tasks located within the Manage Appliance window. 47

From Queued Tasks, click the Delete button for the Scan. This will only delete the Scan from the Queue so it will not be run until it has been re-scheduled. The Scan configuration will still be stored in the Task Library. Downloading Scans Successfully completed Network Scans are immediately available to download through the Network Detective Application. After downloading these Scan files, they can be used to explore data or generate reports as needed. First, go to the Active Assessment of the Site associated with the Appliance. From the Assessment Window, select Download Scans from the Scans bar. 48

All available Scans which have not yet been downloaded will be shown in a list. Check the desired Scans and choose Download Selected or select Download All to receive all Scans. After being successfully downloaded, Scans will immediately be displayed under the Scans bar and available for data exploration or report generation. 49

Configuring the Local Data Scan Merges When local scans are performed by the Appliance, they can be merged into a particular domain data set. The Configuration of Local Scan Merges feature allows you to select which method you prefer to use when merging local scans. This setting will impact Alerts, Bulletins, and Automated Report Generation. To select the process to be used by the Appliance to Merge any Local Scan Data into a primary domain data set, perform the following steps. Step 1 Select the Site Double click your mouse pointer on the Site that you are configuring automated scan and reports to be performed upon in order to view and access the Site. 50

Step 2 Select Manage Appliance After the Site has been opened, select the V to expand the Assessment window to view any appliances associated with the site. Then select the Manage option present above the Appliance Status bar. The Manage Inspector window will be displayed. 51

Step 3 Set Scan Data Merge Configuration Select the Configuration tab in the Manage Inspector Window to view the Local Scan Merge settings. 52

Step 4 Set the Local Scan Merge Settings Select the preferred Local Scan Merge method, or select, Do Not Merge Local Scans. Then select the Save and Close button to store the data merge settings. 53

Using the Manage Inspector Appliance Feature to Configure Automatic Report Generation Below is an overview of the steps required to setup Automatic Report Generation for the following Assessment types: Network Assessments Security Assessments SQL Server Assessments HIPAA Compliance Assessments PCI Compliance Assessments Setting Up Automatic Reports for Network Assessments Automatic report generation for the Network Assessment Module requires that the scans be run on an Inspector before a report can be generated. Following are the steps necessary to set up automatically generated reports for the Network Assessment Module: 1. Create a new assessment that is of the type Network Assessment. Associate your Inspector with the Site that this new Assessment is created. 2. Manage the Inspector and create a new Scan Task that collects the Network Assessment data. 54

3. After the scan task is created, Schedule the scan task for the times that are appropriate for this Assessment. 4. Using the Manage Inspector feature and the Task Library Window, create a Report Task that specifies desired reports from the Network Assessment Module. Keep in mind that reports for specific Assessment types can only be produced after the Scans required for a specific Assessment type have been performed. 5. Schedule the created Report Task for a time which is certain to be after the scan is complete. Reports will use whatever data is on the Inspector based on the most recent scan that has been completed, so if the scan is not complete then the reports will not have the most recent scan s data either. 6. If the user has specified that reports be delivered by email, the specified email should receive an email with a.zip file of the reports attached as long as the zip file is less than 5 MB in size. 7. Report generation can take several minutes. After sufficient time has passed after the report generation task schedule, view the generated reports by navigating to the Download Reports item on the left hand side of the Network Detective application. The Download Inspector Reports option will appear at the top of the Network Detective window. Then 55

press the Download Inspector Reports button at the top. A dialog will appear with reports generated by the Inspector. 8. Select and right click on a report to download the report. 56

Setting Up Automatic Reports for Security Assessments Automatic report generation for the Security Assessment Module requires that the scans be run on an Inspector before a report can be generated. Following are the steps necessary to set up automatically generated reports for the Security Assessment Module: 1. Create a new assessment that is of the type Security Assessment. 2. Associate your Inspector with the Site that this new Assessment is created. 3. Manage the Inspector and create a new Scan Task that collects the Security Assessment data. 4. Schedule the Scan Task for the times that are appropriate for this Assessment. 5. Using the Manage Inspector feature and the Task Library Window, create a Report Task that specifies desired reports from the Security Assessment Module. Keep in mind that reports for specific Assessment types can only be produced after the Scans required for a specific Assessment type have been performed. 57

6. Schedule the created Report Task for a time which is certain to be after the scan is complete. Reports will use whatever data is on the Inspector based on the most recent scan that has been completed, so if the scan is not complete then the reports will not have the most recent scan s data either. 7. If the user has specified that reports be delivered by email, the specified email should receive an email with a.zip file of the reports attached as long as the zip file is less than 5 MB in size. 8. Report generation can take several minutes. After sufficient time has passed after the report generation task schedule time, view the generated reports by navigating to the Download Reports item on the left hand side of the Network Detective application. The Download Inspector Reports option will appear at the top of the Network Detective window. Then press the Download Inspector Reports button at the top. A dialog will appear with reports generated by the Inspector. 58

9. Select and right click on a report to download the report. 59

Setting Up Automatic Reports for SQL Server Assessments Automatic report generation for the SQL Server Assessment Module requires that the scans be run on an Inspector before a report can be generated. Following are the steps necessary to set up automatically generated reports for the SQL Server Assessment Module: 1. Create a new assessment that is of the type SQL Server Assessment. 2. Associate your Inspector with the Site that this new Assessment is created. 3. Manage the Inspector and create a new Scan Task that collects the SQL Server Assessment data. 4. Schedule the Scan Task for the times that are appropriate for this Assessment. 5. Using the Manage Inspector feature and the Task Library Window, create a Report Task that specifies desired reports from the SQL Server Assessment Module. Keep in mind that reports for specific Assessment types can only be produced after the Scans required for a specific Assessment type have been performed. 60

6. Schedule the created Report Task for a time which is certain to be after the scan is complete. Reports will use whatever data is on the Inspector based on the most recent scan that has been completed, so if the scan is not complete then the reports will not have the most recent scan s data either. 7. If the user has specified that reports be delivered by email, the specified email should receive an email with a.zip file of the reports attached as long as the zip file is less than 5 MB in size. 8. Report generation can take several minutes. After sufficient time has passed after the report generation task schedule time, view the generated reports by navigating to the Download Reports item on the left hand side of the Network Detective application. The Download Inspector Reports option will appear at the top of the Network Detective window. Then press the Download Inspector Reports button at the top. A dialog will appear with reports generated by the Inspector. 61

9. Select and right click on a report to download the report. 62

Setting Up Automatic Reports for HIPAA Compliance Assessments Automatic report generation for the HIPAA Compliance Module requires that a full assessment that includes scans, worksheets and surveys be completed and synced with the Inspector Software Appliance before reports can be generated. This is the only way for user completed forms to be transferred to the Inspector. Once the assessment is complete and synced, new scans can be run on an Inspector and new reports be generated with the previously specified Inform-based Survey and Worksheet data. Following are the steps necessary to set up automatically generated reports for the HIPAA Compliance Module: 1. Using Network Detective, create a new assessment that is of the type HIPAA Risk Assessment. 2. Associate your with the Site that this new HIPAA Assessment is created within. 3. Complete all the requirements for a successful HIPAA Risk Assessment within this new assessment. This includes external scans, network scans, local scans, and all appropriate inform-based Surveys and Worksheets. When this step is complete the user should be able to generate all HIPAA reports. The user is free to use the Inspector during this initiate HIPAA Assessment to gather the scan information as appropriate. 4. Once satisfied with a complete HIPAA assessment, press the Finish button. Confirm that you wish to upload the data to the Inspector to be used with automatic report generation. 5. Start a new Assessment that is of the type HIPAA Risk Assessment 6. On the Create New Assessment Wizard Screen, select the checkbox to sync the assessment to the Inspector. 63

7. Manage the Inspector and set up a task schedule or schedules for collecting data as desired. 8. Schedule the created Report Task for a time which is certain to be after the scan is complete. Reports will use whatever data is on the Inspector based on the most recent scan that has been completed, so if the scan is not complete then the reports will not have the most recent scan s data either. Keep in mind that reports for specific Assessment types can only be produced after the Scans required for a specific Assessment type have been performed. 9. If the user has specified that reports be delivered by email, the specified email should receive an email with a.zip file of the reports attached as long as the zip file is less than 5 MB in size. 10. Report generation can take several minutes. After sufficient time has passed after the report generation task schedule, view the generated reports by navigating to the Download Reports item on the left hand side of the Network Detective application. The Download Inspector Reports option will appear at the top of the Network Detective window. Then press the Download Inspector Reports button at the top. A dialog will appear with reports generated by the Inspector. 11. Select and right click on a report to download the report. 12. If an Exception Report is present in the available reports, or was contained in the.zip file sent in the notification email OR if you feel that data in the generated report is using data from an inform-based worksheet or survey that is outdated: 64

a. Note any missing elements present in the Exception report (if present) b. Update Inform forms in currently active Assessment to reflect that data desired. c. If current Informs do not contain the topics that are noted as missing: i. Press the Finish button for the currently active Assessment. ii. DO NOT agree to the question which asks if you would like to sync the data to the Inspector. iii. Start a new active Assessment. Check the checkbox which says Sync with latest Inspector scan iv. New assessment with latest data from Inspector will be created. Update Inform as appropriate. d. Press Finish button for currently active Assessment e. DO agree to sync the data to the Inspector. f. Then return to step 5 above. 65

Setting Up Automatic Reports for PCI Compliance Assessments Automatic report generation for the PCI Compliance Module requires that a full assessment that includes scans, worksheets and surveys be completed and synced with the Inspector before reports can be generated. This is the only way for user completed forms to be transferred to the Inspector. Once the assessment is complete and synced, new scans can be run on an Inspector and new reports be generated with the previously specified Inform-based Survey and Worksheet data. Following are the steps necessary to set up automatically generated reports for the PCI Compliance Module: 1. Using Network Detective, create a new assessment that is of the type PCI Risk Assessment. 2. Associate your Inspector with the Site that this new PCI Assessment is created. 3. Complete all the requirements for a successful PCI Risk Assessment within this new assessment. This includes external scans, network scans, local scans, and all appropriate inform-based surveys and worksheets. When this step is complete the user should be able to generate all PCI reports. The user is free to use the Inspector during this initial PCI Assessment to gather the scan information as appropriate. 4. Once satisfied with a complete assessment, press the Finish button. Confirm that you wish to upload the data to the Inspector to be used with automatic report generation. 5. Start a new Assessment that is of the type PCI Risk Assessment. 6. On the Create New Assessment Wizard Screen, select the checkbox to sync the assessment to the Inspector. 66

7. Manage the Inspector and set up a task schedule or schedules for collecting data as desired. 8. Manage the Inspector and set up reporting tasks for times that are certain to be not when the data collection tasks are running. Keep in mind that reports for specific Assessment types can only be produced after the Scans required for a specific Assessment type have been performed. 9. If the user has specified that reports be delivered by mail, the specified email should receive an email with a zip of the reports attached as long as the zip file is less than 5 MB in size. 10. Report generation can take several minutes. After sufficient time has passed after the report generation task schedule, view the generated reports by navigating to the Download Reports item on the left hand side, and press the Download Inspector Reports button at the top. A dialog will appear with reports generated by the Inspector. 11. Select and right click on a report to download the report. 12. If an Exception Report is present in the available reports, or was contained in the zip sent in the notification email OR if you feel that data in the generated report is using data from an inform-based worksheet or survey that is outdated: a. Note any missing elements present in the Exception report (if present) b. Update Inform forms in currently active Assessment to reflect that data desired. c. If current Informs do not contain the topics that are noted as missing: 67

Then return to step 5 above. i. Press the Finish button for the currently active Assessment. ii. DO NOT agree to the question which asks if you would like to sync the data to the Inspector. iii. Start a new active Assessment. Check the checkbox which says Sync with latest Inspector scan iv. New assessment with latest data from Inspector will be created. Update Inform as appropriate. d. Press Finish button for currently active Assessment e. DO agree to sync the data to the Inspector. 68

Updating a Software Appliance After installing a Software Appliance at the Site s physical location and associating the Software Appliance with a Site in the Network Detective Application, it s important to regularly update the Appliance to get the most out of the features available on the Software Appliance you are using which may include one or more of the following Data Collections, Automated Reports, Tech-Alerts, and Security Bulletins. In the Network Detective Application, navigate to Network Detective ribbon bar and select the Appliances icon. This action will display the Software Appliances window that lists all of the Appliances that are available for use within Network Detective. To update the selected Software Appliance, right click on the Appliance s name, and select the Update menu option presented as displayed below. 69

Note that the Update menu will only be visible if software updates are available. IMPORTANT: The Appliance Update Now feature, when activated to update the Software Appliance, will shut down any tasks that are currently running on the Software Appliance. Before updating the Software Appliance, either stop a currently running task listed in the Task Library window Queued Tasks list, or perform the update after running tasks are completed. A dialog will appear confirming the request for a software update. 70

Appendices Appendix I Inspector Diagnostic Tool The Diagnostic Tool is used to gather relevant diagnostic information, test connectivity, manage updates, and allow remote support to the Inspector appliance. 71

Available Commands There are a number of commands available within the Appliance Manager. Location and Information Locate Network Detective Appliance Re-initialize the Inspector discovery process and attempts to retrieve the Device ID number and other diagnostic information. Get Appliance Device ID Display the Inspector Appliance s Device ID, used when associating the Inspector Appliance with a Site in the Network Detective Application. Diagnostics and Troubleshooting Appliance Diagnostics Queries the Inspector for diagnostic information used to verify running status, software, connectivity, and NIC Information. Ping Test from Appliance Performs a ping test directed at a specified host or IP address from the point of view of the Inspector itself. Note: network connectivity is required for the Inspector to operate properly. Get Log Files Retrieves diagnostics logs from the Inspector. Returns a link to download a.zip file containing run log information which may be used for further troubleshooting. Service Control Appliance Service Status Queries the Inspector to return its current status. The possible statuses are as follows: Idle: The device is online, but performing no action. Queued: The device is online and performing no action. A schedule is active and queued to run. Running: The device is online and currently running a schedule. Appliance Service Restart Requests a Service Restart from the Inspector. Exercise caution when using this command because it may interrupt any running Scan. Updating via USB Update Appliance via USB Requests the Inspector to update via USB. Attempts to detect a USB device. If a USB device is detected containing the necessary files is found to be connected to the Inspector an update will be performed. 72

Please ensure that a USB stick containing the update is plugged into the USB port of the Inspector appliance. Check USB Update Status Returns the current status of a running update. Also attempts to detect any USB device with available updates. Remote Assistance Toggle Remote Assistance Status Instructs the Inspector to make itself available for Remote Assistance and to allow a technician to access the device for support. Check Remote Assistance Status Return the current status of Remote Assistance. Shutdown and Restart Restarts the Inspector Appliance. Shutdown Appliance Shuts down the Inspector Appliance. 73