Documentation Index

Fetch the complete documentation index at: https://docs.safe.security/llms.txt

Use this file to discover all available pages before exploring further.

BX5 Asset Analysis

Prev Next

You can find these options in the BX5 Asset Analysis menu.

What You Can Do Here

  • Access asset telemetry configuration through the BX5 Asset Analysis settings.

  • Review sensor deployment status using the Configured Sensors count.

  • Track data ingestion sources via the Configured Data Connectors metric.

  • Compare raw and deduplicated assets using the Raw Assets and Analyzed Assets views.

  • Evaluate quality of asset data using the Categorized Assets table.

  • Identify incomplete telemetry using the Assets with Poor Visibility table.

  • Detect outdated records through the Transient Assets list.

  • Monitor asset lifecycle via the Recently Retired Assets table.

  • Navigate across different asset groups using the table view tabs.


You can also see the walkthrough in this link

The BX5 Asset Analysis shows you the following information:

  • The number of configured Sensors.

  • the number of configured data Connectors.

  • Raw Assets is the number of assets ingested from data sources before deduplication.

  • Analyzed Assets is the number of assets after deduplication.

  • Categorized Assets shows you the assets that have sufficient data fidelity for accurate categorization.

  • Assets with Poor Visibility shows you the assets have insufficient data fidelity for accurate asset categorization, and are therefore excluded from dashboards and risk calculations.

  • Transient Assets shows you assets that where last observed more than 7 days ago (or 2 days ago for cloud assets), with both first and last observed times within the same day; they are excluded from dashboards and risk calculations.

  • Recently Retired Assets were retired within the last 7 days due to lack of observations; they are excluded from dashboards and risk calculations. For assets observed only via Balbix sensors such as the Balbix Host Analyzer, the retirement period is 30 days—meaning the asset will be retired if the sensor has not reported any activity for 30 consecutive days.

BX5 System Architecture

BX5’s architecture is built around data aggregation, deduplication, and AI-driven analysis. The system ingests data from multiple sources, processes it to remove redundancies, and enriches it with contextual information. The AI fabric then classifies, categorizes, and scores exposures and assets for a comprehensive risk analysis.

Data Process Flow

  1. Data Ingestion

    • Integration with third-party tools and Balbix-native sensors

    • API-driven ingestion of asset data

    • Continuous syncing and updates from connected systems

  2. Data Deduplication and Normalization

    • Eliminating Redundant Asset Entries: BX5 intelligently identifies and removes duplicate records to ensure asset data remains clean, reducing noise in vulnerability and risk assessments.

    • Structuring Data According to the Balbix Unified Asset Model: Standardizing and normalizing asset attributes ensures compatibility with analytical models and consistent risk scoring.

    • Contextual Enrichment of Asset Details: The AI fabric enhances asset records with contextual information, such as business impact, exposure level, and operational relevance. This allows for more accurate risk prioritization.

    • Customer-Driven Workflow: Instead of making judgement on with low-fidelity data, BX5 clearly distinguishes between high-fidelity categorized assets and unverified assets, ensuring customers can make informed decisions regarding additional data verification steps.

  3. Asset Categorization and Verification

    • Categorizing Assets into On-Premise and Cloud Types: The AI fabric applies predefined classification logic to separate assets based on their location and infrastructure type. Please refer to the categorization document for further.

    • Identifying Unverified Assets for Further Input: BX5 highlights assets that lack sufficient data for proper categorization, shifting responsibility to the customer for verification or data augmentation.

    • Segregation for Parallel Workstreams: BX5 does significant processing to ensure assets are grouped into two key categories:

      1. High-Fidelity Categorized Assets: These are leveraged for exposure and risk management, driving security response workflows.

      2. Unverified Assets: Customers are provided with clear action items to reduce unknowns by either adding more data sources or manually verifying assets.

    • Key Outcome: BX5’s asset processing ensures clarity in asset fidelity, making it easier for customers to prioritize security initiatives. By separating assets into distinct categories, organizations can efficiently allocate resources and focus efforts where they matter most.

Asset Retirement

Assets are retired when they have not been observed for a defined period of time. For integrations, an asset is considered retired if it is not reported in the most recent connector run. If multiple data sources are reporting the asset, it will only be retired once all of them have stopped reporting it.

For assets observed only via Balbix sensors such as the Balbix Host Analyzer, the retirement period is 30 days - meaning the asset will be retired if the sensor has not reported any activity for 30 consecutive days.

To allow for user review and to account for scenarios such as agent uninstalls, data source gaps, or user errors, Balbix retains retired assets in the dashboard view for an additional 7 days after retirement. This provides users a window to review and address any potential issues related to asset reporting and data source coverage.