Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

Table of Contents
minLevel1
maxLevel6
outlinefalse
typelist
printablefalse

...

Table of Contents


Getting Started

Email

ConnectSecure has already signed you up for the new instance.

...

To log into the portal please click on the portal link as shown in the picture above. Please click on the URL in this mail and log in using the username and password given in the mailActivate the user by following the instructions on the “Activate User” screen as seen below. Here is where you can set your password too.

Two-factor Authentication

...

Once the authentication is set, you will be redirected to the portal.

Please proceed to get started by creating a new company.

Creating a New Company

Navigate to the "Global View" and follow these steps to create a new company

...

Domain Name: Include domain names for comprehensive coverage.

...


...


Save Changes: After adding credentials and configuring discovery settings, save the changes to apply the new configurations.

...

Verify Credentials: Once credentials are added, perform a verification to ensure they are valid and can be used for scanning.

Choose an OS type to add master credentials: Windows, MacOS, Linux, VMware, and Network devices.

Depending on the network setup, select either Active Directory or Asset Credential as the credential type.


...

...



...

...



...

Agent Installation

Navigate to the “Agents” section and click on "Download Agent".

...

...

Image Added


Copy the script by selecting the "Copy to Clipboard" option.

...

Locate and click on the "Action Button" (often represented by three dots or a gear icon) associated with the specific agent that needs to be configuredtha.

...


...



From the menu that appears, select "Map Discovery & Credentials"

...

In the "Map Discovery & Credentials" section, locate the options you will find options to associate Discovery Settings and Credentials with the selected agent.

...

Similarly, map the necessary credentials Credentials to the agent by choosing the relevant credentials from the list.

...

Image Added


Once you have mapped the Discovery Settings and Credentials are mapped, click the "Save" button to apply the changes.

...

After successfully mapping the Discovery Settings and Credentials, return to the "Agents" section.

Locate the agent that has been configured the under the Discovery Settings and Credentials. for which you configured the settings and credentials.

Click on the "Scan" button to initiate the scanning process for the configured agent.

...

Click on 'Assets' to access the assets view.

...

In this section, is a comprehensive you will find a comprehensive list of scanned assets. 

The list includes assets along with their associated risk scores and vulnerability counts.

...

Clicking on the IP Address will redirect , you to the detailed view of the chosen asset.

...


...

In this section, you can find the following information about the assets are availableasset:

  • System information

  • Storage

  • Network information

  • BIOS Information

  • Firewall Policy

  • Problems

  • Solutions

  • Firewall Rules

  • Internal Ports

  • External Ports

  • Software

  • Asset Patches

  • Extension Programs

  • Services

  • User Shares

...

For network vulnerabilities, please we can find the scripts to remediate them.

...

Image Added


Please We can directly copy the script and run it on the machine for remediation.

...

Problems

Click on 'Assets' to access the Problems view.

...

In this section, we can identify all the problems related to assets at the company level can be identified.

...

Image Added

In this section, one we can choose to suppress Problems, by triggering an email to the designated user for approval. This user can be internal or external.

...

Click on 'Assets' to access the Remediation Plan.

...

Image Added

The Remediation Plan lists missing OS (Operating System) security patches and the latest application versions that have not yet been installed.

Image RemovedImage Added

Application Vulnerabilities

Click on 'Assets' to access the Application Vulnerabilities.

...

Image Added

In this section, we can find the Application Vulnerabilities and missing OS (Operating System) security patches are listed.

...

Image Added

Pending OS Patches

Click on 'Assets' to access the Pending OS Patches.

...

In this section, we can review the pending OS patches across the company's view.

...

Image Added

Ports

Click on 'Assets' to access the Ports section.


In this section, we can review the Ports details across the company's view.

...

Image Added

Anchor
_Toc1037062264
_Toc1037062264
Anchor
_Toc361142251
_Toc361142251
Vulnerabilities

Go to the 'Company View'.

Click on “Vulnerabilities” to access the Vulnerabilities view.

...

Anchor
_Toc852353683
_Toc852353683
Anchor
_Toc2023570376
_Toc2023570376
In this section, we can suppress vulnerabilities, triggering an email to the designated user for approval. This user can be internal or external.

...

Image Added

Select the reason for suppressing the vulnerability.

User Type: Choose the user type for whom the suppression request is intended: Internal User or External User.

Suppression Comments: Provide comments explaining the justification for suppressing the

vulnerability.

Suppression Start Date and End Date:

Specify the start and end dates for the vulnerability suppression.

Image RemovedImage Added

Save: Click the "Save" button to approve the suppression request.

...

Compliance

Go to the 'Company View'.

Click on “Compliance” to access the Compliance view.

In this section, we can access the compliance details for CIS, PCIDSS, HIPAA, Cyber Essentials, NIST 800-53, Essential Eight across multiple platforms such as Windows Server, Azure Server, Windows Desktop, Linux, and Mac.

Image RemovedImage Added

And for Manual Compliance, we can upload evidence to mark it as compliant or not applicable, there are provisions to upload evidence.

...

Image Added

Active Directory

Click on “Active Directory” to access the Active Directory Section.

...

Image Added


Here we can find:
Problems
Identifies and lists issues or challenges.

...


...

AD Summary

Provides a summary of Active Directory-related information.

...

Image Added

Azure AD Summary

Offers a summary of Azure Active Directory-related information.

...

Image Added

Active Directory: Presents detailed information and insights related to the Active Directory.

...


...

Azure Active Directory: Provides detailed information and insights concerning Azure Active Directory.

...

Image Added

Microsoft Secure Score: Offers information and metrics related to the security score assigned by Microsoft, indicating the overall security posture.

Image RemovedImage Added

PII Scan

Click on “PII Scan” to access the PII Scan Section.

...

Image Added

Add a scan profile

Click on +Add to add a new scan profile.

...

Image Added

Scan settings

Under Scan Settings , lets you choose all by selecting the Select All option. Users can select optional information from fields like Surname, Phone, Date Of Birth, Postal Code, OAuth Token, Location, Email, IP, Credit Card, Phone, SSN, and Street.

...

Image Added

Select Default Extension

Select the Default Extension Type Select All option. Users can select optional extension types html, json, yaml, yml, tex, xml, ts, sh, wpd, php, go, cpp, c, js, xlsm.

...

Image Added

Select the appropriate Source Type and an Agent to use for PII Scan.

...

Select the Default Source Type as Files to be used for this scan.

Select Source Type as Files and provide information for Path Settings such as Included Location(s). Exclude the Location for the system to be scanned.

...

Once all required fields are selected, please click on Save to successfully save the this PII Profile with a message as Saved Successfully.

Initiate PII Scan

Locate and select the profile for which you want to initiate the PII scan.

...

Once the scan is complete, review the results to identify any flagged Personally Identifiable Information. This may include names, addresses, social security numbers, or other sensitive data.

...

Image Added

Based on the scan results, take appropriate actions. This could involve redacting or encrypting sensitive information, notifying relevant parties, or implementing additional security measures.

...

Image Added

Clicking on the highlighted PII data will redirect you to the detailed view of the chosen PII data.

...