Use case: Blind spot detection
Overview
Blind spots are the unscanned assets that are detected when you run a patch policy or a vulnerability scan by using the Discovery connector in BMC Helix Automation Console or TrueSight Automation Console. These blind spots represent potential security risks as they are not mapped to Automation Console to perform remediation processes.
What do I need to get started?
- Configure the Discovery connector in BMC Helix Automation Console or TrueSight Automation Console
- Import the scan file through the Discovery connector
How to view and handle the detected blind spots?
This topic describes the steps to identify and handle blind spots.
- Configure the Discovery connector, see Configuring-the-BMC-Discovery-connector.
- Import a vulnerability scan results file. For more details, see Working-with-scans.
- The scanned results appear in the Discovery assets page. << add a screen shot of the discovered assets page>
- Total Discovered Assets: Total number of discovered assets by BMC Discovery. (Except excluded resources based on provided Exclude IPs/Hosts/Range list).
- Unmanaged Assets: Total number of assets that are found by BMC Discovery and are not mapped to endpoints in TrueSight Server Automation.
- Unscanned Assets: Total number of assets, either discovered, or mapped in Server Automation, but not yet scanned for vulnerabilities.
- Select the Unscanned Assets tab to view the blind spots.
- From the list of blind spot servers detected, you can determine whether they need to be included in vulnerability scans/patch flow.
- Manually map the unscanned assets to your endpoint, TrueSight Server Automation or TrueSight Network Automation for them to be accounted as Managed Assets for remediation and patching actions. For more details see, Working-with-assets.
Tip: For faster searching, add an asterisk to the end of your partial query. Example: cert*