Insights (Exposures tab)
Use the External Attack Surface > Insights > Exposures tab to view details on exposures detected by EASM. The Default Workspace includes insights data from all workspaces. If you only want to see data for a specific workspace, select it from the Workspace list at the top.
At the top of the page are your Exposures key performance indicators:
- Exposed internal assets
- High risk services
- Ransomware
- RCE / PE (Remote Code Execution and Privilege Escalation)
- High risk vulnerabilities
- Email and IP breaches
- CISA KEVs (Known Exploited Vulnerabilities)
Selecting a blue number in an indicator applies a filter in the Exposures list so it shows only those items.
Filtering the exposures list
You can filter these exposure list columns:
- Severity, such as high or critical.
- Vector, such as data leaks or patching cadence.
- Age, you can narrow down your search results by the age of exposures detected. You can use the following pre-set options for quick filtering:
Show all: Displays all data regardless of its age.
Greater than 3 days: Shows data older than 3 days.
Greater than 14 days: Shows data older than 14 days.
Greater than 30 days: Shows data older than 30 days.
Greater than 365 days: Shows data older than 365 days.
Custom Range: For more specific filtering, select the Custom range option. This allows you to define a specific date range.
- Status, such as open or closed. A closed status means the vulnerability was not detected.
- Tags, such as ransomware or public.
Select the filter button on a column header to see its selectable filters. The column chooser button
to the left of the search field lets you select which columns are visible.
Quick Filters at the top of the table provide additional filtering based on data gathered from your assets. The available selections within a quick filter depend on what EASM has detected in your assets. Quick filters work in combination with column filters. For more information, see Quick Filters.
Use the Export button to export the exposures list to Excel (.xslx) or text (.csv). Any column filters you have applied will also apply to the export.
Viewing CVE details
Selecting an exposure CVE number in the list takes you to the details page for that CVE. This page includes extensive information in these categories:
- Summary: Links to relevant patches, release notes, evidence detected for the exposure (if available), vendor, and third-party advisories.
- Vulnerabilities: Lists the CVEs associated with the exposure you selected. Some exposures have more than one CVE. Common Weakness Enumerations (CWE) are also listed, along with the platforms affected.
- Threats: Lists the threats associated with the CVE and links to sites with more details.
- Fixes: Links to fixes for the exposure. Not all CVEs have fixes. This section will not appear if no fixes are available, but you can still refer to the recommended patches section in the summary.
- Impacted assets: Lists the assets affected by the CVE.
Marking an exposure as resolved
When you know that you have fixed an exposure, you can mark it resolved. Resolving an exposure removes it from the External Attack Surface > Insights > Exposures list. Data from exposures with a resolved state also contribute to many of the widgets on other pages.
To mark an exposure as resolved
- Select Attack Surface > Insights > Exposures.
- Find the exposures that you want to mark.
- In the Resolve column, select the box next to those exposures.
- Select the Resolve button at the top of the list.
- The resolve exposures box appears. Select the reason you are marking them fixed and enter a summary of the resolution.
- Select Resolve exposure.