Company Settings
Q: What can I configure in Company Profile?
A: Company Profile settings allow you to manage general company information.
Q: What options are available under General Settings?
A: General Settings include configuring licensing, module entitlements, and license counts.
Q: How can I manage user access?
A: Manage user access through Users, Roles and access control, and Allowed email domains.
Q: What components are under Data capture?
A: Data capture involves managing Connectors and Sensors.
Q: How can Dashboards be customized?
A: Customize Dashboards through Default dashboards and Custom dashboards.
Q: What does Asset Inventory include?
A: Asset Inventory includes Sites and locations and Subnet to site mapping.
Q: What does Exposure Management cover?
A: Exposure Management covers Metrics and targets, Remediation SLA matrix, and Project/Ticketing Rules.
Q: What are the settings available under Cyber Risk?
A: Cyber Risk settings include Asset criticality, Control settings, and Risk scenarios.
Support
Q: What is the BX5 Asset Analysis?
A: It is a tool for accessing asset telemetry configuration, monitoring sensor deployment, and analyzing data sources.
Q: How does BX5 categorize assets?
A: It categorizes assets using predefined logic into on-premise and cloud types for better risk analysis.
Q: How can I contact support for BX5?
A: Use the contact form provided on the help page to reach support.
Implementing the CTEM Cycle with Balbix
Q: What is Continuous Threat Exposure Management (CTEM)?
A: CTEM is a proactive cybersecurity framework designed to continuously identify, assess, prioritize, and mitigate threats and vulnerabilities.
Q: What is the first step in the CTEM Cycle?
A: The first step is Scoping, which involves defining the attack surface beyond traditional infrastructure.
Q: What does the Discovery phase entail?
A: The Discovery phase involves identifying visible and hidden assets, vulnerabilities, and understanding their business context.
Q: How is Prioritization achieved in CTEM?
A: Prioritization involves making informed decisions on what to fix first, considering multiple factors like business risk and asset criticality.
Q: What is the purpose of the Validation phase?
A: The Validation phase involves verifying assumptions about security issues and understanding potential attack paths.
Q: What occurs during the Mobilization phase?
A: Mobilization involves turning security insights into action, coordinating people, processes, and technology for risk reduction.
Trend Chart
Q: What does the Trend Chart Widget display?
A: It displays how breach likelihood evolves over time, tracking changes in risk posture and spotting patterns or spikes requiring further investigation.
Q: How does this widget track breach risk?
A: It tracks how breach risk in US dollars changes over time to see trends and shifts in potential financial exposure.
Q: What does the asset count widget show?
A: It shows how the total count of assets changes over time, helping track growth or shrinkage in the environment and identify unusual fluctuations.
Q: How does the widget monitor risk score changes?
A: It shows how the overall risk score changes over time to monitor improvements or deteriorations in security posture.
Q: What does the MTTP widget measure?
A: It measures average duration between discovery of a vulnerability and application of a patch, helping understand response effectiveness to security issues.
Q: What indicates a high MTTP?
A: It may indicate bottlenecks in the patching process or insufficient resources.
Q: How do you evaluate MTTP impact?
A: By tracking MTTP over time to assess process improvements or new policies, ensuring faster vulnerability addressing.
Q: What does the MTTR widget measure?
A: It measures average duration from identifying a security issue to full resolution, covering the entire remediation process.
Q: What does MTTR help understand?
A: It helps understand delays in testing or validation and checks effective vulnerability closure.
Q: How does comparing MTTP and MTTR help?
A: It provides insight into patching speed and remediation workflow efficiency.
Q: What happens when no patch is available?
A: MTTP is irrelevant, but MTTR remains important for addressing vulnerabilities.
Q: What does a fast MTTP indicate?
A: It indicates an efficient patching process, while a fast MTTR signals strong overall security posture.
Q: What does MOVA widget track?
A: It tracks mean open vulnerability age, measuring days vulnerabilities remain unaddressed.
Q: What does upward MOVA trend indicate?
A: Longer remediation times or stretched resources, while a downward trend suggests improvement in closing vulnerabilities quickly.
Bar Chart
Q: What does the bar chart widget display about risk scores?
A: This widget displays the risk scores for specific asset categories or groups, using color coding to indicate severity (Low, Medium, High). In this example, both Linux/Unix Servers and Perimeter have a risk score of 89, categorized as high, helping you quickly identify and prioritize areas of greatest concern. Note that this widget will show the highest risk score found in the asset category.
Q: How does the bar chart widget help with breach likelihood?
A: This widget displays the likelihood of a breach for specific asset categories or groups, using color coding to indicate severity (Low, Medium, High). This comparison helps you quickly see which areas may be at greater risk of compromise and prioritize accordingly.
Q: What financial data does the widget display?
A: This widget displays the potential financial damage, in US dollars, that could result from a breach across different asset groups, helping you identify where a breach would carry the highest monetary consequences.
Q: What is the purpose of the breach risk widget?
A: This widget displays the overall breach risk, in US dollars, for each asset group or category. It helps you see where the financial exposure is greatest and focus your remediation efforts accordingly.
Q: How does the widget show asset distribution?
A: This widget displays the total number of assets for each group or category, allowing you to quickly see how your environment is distributed and where your largest concentrations lie.
Q: What does the vulnerability severity widget compare?
A: This widget displays a comparison of vulnerability severities—Low, Medium, and High—across different asset groups. It helps you identify which groups have higher concentrations of critical vulnerabilities and prioritize remediation efforts accordingly.
Donut Chart
Q: What does the Donut Chart widget display?
A: It displays an overall risk score in a color-coded donut chart, showing a numerical risk value surrounded by segments reflecting severity levels like Low, Medium, or High for a quick threat assessment.
Q: How does the asset breakdown in the Donut Chart help?
A: It provides an overview of asset counts by categories with color-coded segments, allowing a quick understanding of your environment’s composition and focus for security measures.
Q: What does the breach likelihood widget indicate?
A: It shows a numeric value indicating overall breach likelihood, with color-coded segments reflecting risk levels to help prioritize security efforts.
Business Outcomes
Q: What is a business outcome at Balbix?
A: A business outcome is a concise, defined, and observable result or change in business performance, supported by specific metrics.
Q: What does CAASM provide for cyber risk reduction?
A: CAASM provides foundational visibility capabilities essential for cyber risk reduction, including asset visibility, inventory, and vulnerability assessment.
Q: How does Balbix streamlining audit compliance reporting help?
A: It generates more accurate and comprehensive reports for asset inventory, security controls, and EOL software, reducing preparation time for audits.
Q: What is the impact of reduced operational overhead with Balbix?
A: It eliminates the burden of manual processes, allowing IT and cybersecurity teams to focus on strategic initiatives.
Q: How does Balbix enhance shadow IT management?
A: It reduces resistance to data collection from shadow IT and third-party systems, maintaining visibility over assets outside IT governance.
Q: How does improved CMDB accuracy benefit IT teams?
A: It enhances productivity by updating assets and attributes, addressing the challenge of CMDBs becoming outdated.
Q: What outcomes can be expected from RBVM implementation?
A: You can expect faster mitigation of critical vulnerabilities, enhanced compliance, cost savings, and improved vulnerability prioritization.
Q: What is the purpose of CRQ in cyber risk management?
A: CRQ helps measure, communicate, and manage cyber risk in monetary terms, improving project prioritization and stakeholder awareness.
Q: How does Balbix optimize security investments?
A: By consolidating tools, prioritizing activities, and ensuring the maximum return on security investments.
Connectors List
Q: What types of connectors are available?
A: There are various types including Cloud Connector, Cloud Native Application Protection Platform, IOT/OT, Risk Based Vulnerability Management, Flexible Connector, Endpoint Protection, and many more.
Q: What category does AWS belong to?
A: Amazon Web Services (AWS) belongs to the Cloud Connector category.
Q: What is required to set up an AWS connector?
A: You need to provide the Instance Name.
Q: What is the type of the Aqua Security connector?
A: The Aqua Security connector is a Cloud Native Application Protection Platform.
Q: What API parameters are used for the Armis connector?
A: Parameters include Instance Name, Armis Security Token, Asset last seen days filter, Armis API Base URL, and Armis Aql Filter.
Q: What do you need to connect to Azure?
A: You need Instance Name, Tenant ID, Client ID, Client Secret, and other specific API parameters.
Q: What asset management connector can be set up with an Org ID?
A: The Flexera connector allows setup with an Org ID.
Q: Which connector uses OAuth 2.0 for authentication?
A: ServiceNow Generic CMDB and Servicenow Ticketing both use OAuth 2.0 Login URL for authentication.
Q: Which connector is used for endpoint protection by VMware?
A: VMware Carbon Black is used for endpoint protection.
Q: What is required as API parameters for the Black Kite connector?
A: Required parameters are Instance Name, Client ID, Company Domain Name, API Base URL, and Client Secret.
BX5 Asset Analysis
Q: What can I access through the BX5 Asset Analysis settings?
A: You can access asset telemetry configuration, review sensor deployment status, track data ingestion sources, compare raw and deduplicated assets, evaluate asset data quality, identify incomplete telemetry, detect outdated records, monitor asset lifecycle, and navigate across different asset groups.
Q: What does the Configured Sensors count show?
A: It shows the number of configured sensors.
Q: What is the difference between Raw Assets and Analyzed Assets?
A: Raw Assets are the number of assets ingested before deduplication, while Analyzed Assets are the number after deduplication.
Q: What does the Categorized Assets table display?
A: It displays assets with sufficient data fidelity for accurate categorization.
Q: What are Assets with Poor Visibility?
A: Assets with insufficient data fidelity for accurate categorization, excluded from dashboards and risk calculations.
Q: What are Transient Assets?
A: Assets last observed more than 7 days ago (or 2 days for cloud assets), with both first and last observed times within the same day, excluded from dashboards and risk calculations.
Q: What are Recently Retired Assets?
A: Assets retired within the last 7 days due to lack of observations, excluded from dashboards and risk calculations. For assets observed only via Balbix sensors such as the Balbix Host Analyzer, the retirement period is 30 days—meaning the asset will be retired if the sensor has not reported any activity for 30 consecutive days.
Q: How is BX5's architecture designed?
A: It is built around data aggregation, deduplication, and AI-driven analysis, ingesting data from multiple sources and enriching it with contextual information for risk analysis.
Q: What is the purpose of data deduplication and normalization in BX5?
A: To eliminate redundant asset entries and standardize asset attributes for compatibility with analytical models and consistent risk scoring.
Q: How does BX5 enrich asset details?
A: By enhancing asset records with contextual information such as business impact, exposure level, and operational relevance for accurate risk prioritization.
Q: How does BX5 handle asset categorization?
A: It categorizes assets into on-premise and cloud types using predefined classification logic.
Q: What are Unverified Assets in BX5?
A: Assets lacking sufficient data for proper categorization, requiring customer verification or data augmentation.
Q: What is the outcome of BX5's asset processing?
A: It ensures clarity in asset fidelity, helping prioritize security initiatives and allocate resources efficiently.
Connectors
Q: How can I add new data sources to the platform?
A: Use the Add Connector workflow, select a connector from the Connector Cards, input details in the Connector Parameters form, and activate the integration.
Q: What is the Test Connection function used for?
A: To validate access.
Q: How can I define update intervals for data sources?
A: Use the Sync Frequency setting.
Q: Where can I view existing connector configurations?
A: In the Connector Details tab.
Q: How can I monitor integration activity?
A: By using the Sync History tab.
Q: What does the Sync Analytics tab display?
A: It displays data ingestion metrics.
Q: What is the purpose of Connectors?
A: To gather data from various external systems, unify it in one place, and keep it up to date continuously.
Create remediation projects
Q: What is a Remediation Project?
A: A Remediation Project includes multiple vulnerabilities that can be mitigated together, allowing security teams to track, prioritize, and manage vulnerabilities systematically to reduce overall risk.
Q: How can vulnerabilities be grouped in Remediation Projects?
A: They can be grouped by common criteria, such as severity, entity type, or affected system.
Q: What entities can you create remediation projects for with Balbix?
A: You can create remediation projects for various entities within your organization, including Assets and Applications.
Q: What are the benefits of using remediation projects?
A: Benefits include centralized management, prioritization of high-severity vulnerabilities, collaboration between teams, and auditing and reporting for compliance and risk management.
Using the Exposure Score Simulator
Q: What is the purpose of the Exposure Score Simulator?
A: It is designed to quantify and manage cybersecurity risks by assigning exposure scores ranging from 0 to 100 to identify, prioritize, and address vulnerabilities effectively.
Q: How does the simulator assist organizations?
A: It combines technical analysis with business impact assessment to guide decision-making and enhance risk mitigation strategies.
Q: What are some key benefits of using the simulator?
A: Organizations can focus resources efficiently, demonstrate security improvements, enhance compliance posture, and strengthen decision-making.
Q: What is the Exposure Score Framework?
A: It categorizes scores from low to critical, simplifying risk prioritization based on severity.
Q: How is the exposure score determined?
A: By analyzing dimensions such as vulnerability attributes, threat landscape, security controls, asset impact, and asset location.
Q: How does the simulator evaluate likelihood and impact?
A: Likelihood reflects probability of exploitation, while impact considers business consequences; combined, they form the exposure score.
Q: What are some mitigation scenarios modeled by the simulator?
A: Scenarios range from fully mitigated to high exploitation potential, demonstrating how various strategies affect exposure scores.
Q: How can users interact with the simulator?
A: By selecting vulnerabilities, assets, updating threat levels, adjusting security controls, and including simulation validation, users can refine their analysis.
Q: What visual insights does the simulator provide?
A: Dynamic visuals like Sankey diagrams and graphs illustrating exposure score changes over time, highlighting risk factors and mitigation effectiveness.
Create vulnerability filters
Q: What can you create in the Asset Vulnerabilities menu?
A: You can create filters and advanced filters for Unique Vulnerabilities and Vulnerability Instances.
Q: What attributes can be used to create filters?
A: Attributes include Publish Date, CVSS scores, CVSS severity, Threats, Vulnerability Tags, Has Ticket, Remediation Project, Exposure Score, Exposure Severity, State, Roles, Asset Tags, and various location-related fields.
Q: How do advanced filters apply boolean logic?
A: Within a group, attributes are evaluated as AND, while groups themselves are evaluated with OR.
Create automations
Q: What are automations in security tasks?
A: Automations streamline repetitive tasks by defining rules and actions, reducing manual effort, and ensuring consistency across security operations.
Q: How do automations identify assets or vulnerabilities?
A: Using filters and predefined criteria, automations automatically identify assets, vulnerabilities, applications, or findings that meet defined conditions.
Q: What actions can automations trigger once assets are identified?
A: They can trigger actions such as tagging, sending notifications, creating tickets, or generating exports to address risks or maintain compliance.
Q: What types of specialized automations does Balbix provide?
A: Balbix provides specialized automations for Assets, Asset Vulnerabilities, Applications, and Appsec Findings, offering targeted actions for distinct security requirements.
Q: What is the benefit of leveraging automations?
A: Leveraging automations increases operational efficiency, accelerates remediation, and aligns security processes with organizational policies and strategies.
Q: What are the types of automations based on element types?
A: The types are Asset Vulnerabilities Automation, Assets Automation, Applications Automation, and Appsec Findings Automation.
Q: What actions can Asset Vulnerabilities Automation trigger?
A: It can trigger actions like Send Slack, Send Email, Send Export, Create Ticket, and Create Remediation Project.
Q: What inputs does Applications automation use?
A: Applications automation uses only an application filter, which can be new or a saved filter.
Q: What actions can Appsec Findings automation trigger?
A: It can trigger actions like Send Export, Create Ticket, and Create Remediation Project.
Bix
Q: What is BIX?
A: BIX is a conversational AI-powered cybersecurity assistant built into the Balbix platform and available through the BIX iOS app, providing actionable insights into your organization's cybersecurity posture.
Q: Why should you use BIX?
A: BIX simplifies cybersecurity by providing fast and reliable answers to complex questions, helping stakeholders manage cyber risk effectively and empower organizations to strengthen their cybersecurity posture with confidence.
Q: What can you ask BIX?
A: You can ask BIX a wide range of questions about cybersecurity insights, such as top vulnerabilities in your environment, assets likely to be breached, mean time to remediate vulnerabilities, and more.
Q: Why use the iOS BIX app?
A: The iOS BIX app offers anywhere, anytime access to critical security insights, real-time responsiveness, and an optimized user experience.
Q: What key features does the iOS BIX app include?
A: Key features include security best practices, 24/7 availability, comprehensive search, chat history, push notifications, and email responses.
Q: What types of cybersecurity risks can BIX help me address?
A: BIX provides insights into various risks and exposures, including EOL systems, misconfigurations, unpatched vulnerabilities, insider threats, malware, and weak passwords, while suggesting next best steps.
Q: Can I report a security incident and create a remediation project using BIX?
A: Yes, you can report security incidents by describing the issue in the chat and instructing BIX to create a remediation project.
Q: What best practices can I follow to enhance my security posture?
A: BIX recommends best practices such as using strong passwords, enabling two-factor authentication, regularly updating software, patch management, deploying EDR solutions, and conducting employee security awareness training.
Access Request to Certification
Q: What is the Certified Balbix Specialist Certification?
A: It consists of 2 courses: Principles of Continuous Threat Exposure Management and Balbix User Course V2.
Q: What will I learn in Principles of Continuous Threat Exposure Management?
A: You will learn in detail how to implement the CTEM Cycle.
Q: What does Balbix User Course V2 cover?
A: It teaches how to use the Balbix Platform to implement the principles of the CTEM Cycle.
Q: How do I request access to the certification courses?
A: Please fill out the provided form to request access.
Board Reporting
Q: What is the purpose of board reporting?
A: To provide executives and board members with concise, relevant insights into company performance, risks, and strategic initiatives.
Q: How often should board reports be prepared?
A: Board reports are typically prepared on a quarterly basis, though frequency can vary depending on the organization.
Q: What key metrics should be included in board reporting?
A: Key metrics include financial performance, strategic progress, risk management updates, and relevant market trends.
Q: How can data visualization enhance board reports?
A: Data visualization can make complex data more accessible, highlight significant trends, and support data-driven decision-making.
Q: What role does narrative play in board reporting?
A: Narrative provides context, explains deviations from expected performance, and outlines planned responses to challenges.
Q: How should risks be communicated in board reports?
A: Risks should be communicated clearly, highlighting their potential impact and the actions being taken to mitigate them.
Q: What is the value of including forecasts in board reports?
A: Forecasts provide insight into potential future performance and support strategic planning and resource allocation.
Q: How can board reports drive strategic alignment?
A: By linking performance data to strategic goals, board reports reinforce alignment between operations and overall strategy.
Q: What challenges are associated with preparing board reports?
A: Challenges include ensuring data accuracy, maintaining confidentiality, and presenting complex information clearly and concisely.
Q: How can technology support effective board reporting?
A: Technology can streamline data collection, facilitate collaboration, and enhance report presentation through advanced analytics and visualization tools.
CYBER RISK SUMMARY
Q: What can you do in the Cyber Risk Summary menu?
A: You can view enterprise-wide cyber risk metrics, filter risk data by selecting different asset groups, analyze overall risk trajectory using the Risk Trend graph, interpret financial impact with the Loss Exceedance Curve, identify high-risk business areas through the Top Risk Business Groups visualization, examine control performance using the Top 10 Controls by Effectiveness chart, and access prioritized mitigation data via the CTEM Bird’s Eye link.
Q: What does the CTEM Birds Eye view present?
A: It presents a snapshot of your organization’s overall cyber risk in monetary units, breaking it down by distinct categories to show where vulnerabilities might be most critical, with each category represented as a branch from the central node.
Q: How is risk calculated in the Cyber Risk Summary?
A: Risk is calculated based on the scenario impact, which estimates the financial consequences of an incident, and the scenario likelihood, which reflects the probability of the event occurring.
Q: What does enterprise impact represent?
A: It represents the overall potential financial damage.
Q: What do exposures show in the Cyber Risk Summary?
A: Exposures show the level of risk present in the environment.
Q: How are Next Best Steps mitigation actions categorized?
A: They are categorized into Operational/Enterprise Management Actions, which address system vulnerabilities, and Control-Based Actions, which enhance security measures.
Q: What does the CTEM Birds Eye view provide?
A: It provides a holistic snapshot of your organization’s security posture, integrating data from multiple sources and visualizing the relationships among assets, applications, and exposures.
Q: What role do data sources play in the CTEM Birds Eye view?
A: Data Sources represent the various security and IT tools feeding information into the platform, contributing unique insights for a complete picture of your environment.
Q: What are assets in the CTEM Birds Eye view?
A: Assets are the individual entities being protected, such as servers, workstations, and IoT devices, assessed for risk profile based on collected details.
Q: What are exposures in the CTEM Birds Eye view?
A: Exposures are security gaps identified across assets and applications, prioritized to focus on the most critical issues first.
Q: How is cyber risk represented?
A: Cyber Risk represents the overall potential financial damage your organization could face if vulnerabilities were exploited, factoring in breach likelihood and impact.
Q: What does Dispatched for Automated Mitigation indicate?
A: It indicates exposures that the platform has routed to an automated process for remediation of routine tasks.
Q: What does Dispatched for Manual Mitigation refer to?
A: It refers to exposures requiring human review or intervention due to complexity or operational risks.
Q: What is the purpose of Exposures Deprioritized?
A: To deem issues low-risk or acceptable to leave unaddressed, ensuring the focus remains on critical exposures.
Q: What does Raw Assets Analyzed show?
A: It shows the total number of newly discovered assets, reflecting the thoroughness of asset inventory efforts.
Q: What does Raw Exposures Analyzed represent?
A: It represents the total number of exposures identified, indicating potential security gaps before prioritization or remediation.
Q: What is Work Avoided?
A: It is the estimated reduction in manual labor thanks to automated processes and intelligent prioritization, streamlining security operations.
Q: What does the Risk Trend graph display?
A: It displays expected financial risk due to cyber threats over time, with visibility into risk exposure trends and effectiveness of mitigation strategies.
Q: How is the Loss Exceedance Curve (LEC) used?
A: It assesses potential financial exposure to cyber risks, helping estimate likelihood of extreme financial losses for risk management and insurance modeling.
Q: How does the Top Risk Business Groups chart visualize risk exposure?
A: It visualizes the risk exposure of business units based on breach likelihood and potential financial impact, with color-coded risk levels.
Q: What does the Top 10 Controls by Effectiveness chart rank?
A: It ranks cybersecurity controls based on effectiveness, supporting decisions for cybersecurity strategy by prioritizing controls with the greatest return on investment.
Risk Settings
Q: Where can you find Risk Settings?
A: Risk Settings can be found at https://rs002tra.balbix.net/app/d3/cyber-risk/risk-settings.
Q: What can you do with CRQ Readiness Check?
A: Review organization's CRQ readiness using the Readiness Self-Assessment covering Inventory Coverage, Entity Categorization and Tagging, and Exposure Assessment Fidelity.
Q: What can be configured in Edit Enterprise Impact?
A: Edit enterprise-level risk valuation, configure risk impact categories, and view and validate predefined assumptions.
Q: What are some of the risk impact categories?
A: Incident & Response Costs, Data Recovery & Restoration Costs, Business Interruption Costs, Fines, Legal & Defence Costs, Financial Fraud, Physical Damage Costs, and Indirect Losses.
Q: What is the purpose of the Cost Assumptions List?
A: To view and validate predefined assumptions.
Q: What is performed in the Maturity Assessment tool?
A: Perform a detailed control maturity evaluation by selecting specific controls for evaluation and configuration.
Q: What are the modules you can configure in Risk Settings?
A: CRQ Readiness Check, Impact Settings, Assessment, and Other Settings.
Q: What is CRQ Readiness Check?
A: A non-binding questionnaire to assess readiness for CRQ.
Q: What can be configured in Edit Enterprise Impact section?
A: Groups, Currency, Industry type, Number of customers, Number of annual working days, Headquarters country, Annual revenue, Number of employees.
Q: What costs are included in Incident and Response Costs?
A: Notification Costs, Credit Monitoring Costs, Card Replacement Costs, Forensic Investigation Costs, Public Relations Cost, Average Employee Training Costs, External Cyber Experts Cost.
Q: What kinds of costs are categorized under Business Interruption Costs?
A: Business Downtime Costs, Direct Loss of Funds Costs, Monetary Theft.
Q: What is the objective of the Control Maturity Assessment?
A: To set the maturity level for various controls like Entity Management, Business Continuity, and recovering planning.
Q: What are the possible Maturity Levels?
A: Not implemented, Initial (Ad hoc), Repeatable (Managed), Defined (Standardized), Managed (Monitored & Measurable), Optimized (Continuous Improvement).
Q: What can you do in the Risk Settings section?
A: Review CRQ readiness, complete readiness assessments, edit risk valuations, configure impact categories, validate assumptions, review financial impacts, set impact values, evaluate control maturity, and configure specific controls.
Q: What is the CRQ Readiness Check?
A: A non-binding questionnaire to assess readiness for CRQ, covering inventory coverage, entity categorization, tagging, and exposure assessment fidelity.
Q: What can be configured in the Edit Enterprise Impact section?
A: You can configure groups, currency, industry type, number of customers, annual working days, headquarters country, annual revenue, number of employees, and firmographics.
Q: What costs can be configured in Risk Settings?
A: Incident and response costs, data recovery costs, business interruption costs, fines, legal and defense costs, financial fraud costs, physical damage costs, and indirect losses.
Q: What are some maturity levels in the Control Maturity Assessment?
A: Not implemented, Initial (Ad hoc), Repeatable (Managed), Defined (Standardized), Managed (Monitored & Measurable), and Optimized (Continuous Improvement).
Risk Analytics
Q: What is RISK ANALYTICS?
A: It is a process to identify, assess, and prioritize risks using data analysis, modeling, and assessment methods.
Q: How does it help businesses?
A: It helps in making informed decisions, improving risk management strategies, and enhancing organizational resilience.
Q: What tools are used in RISK ANALYTICS?
A: Tools include statistical software, data visualization platforms, and machine learning algorithms.
Q: What industries benefit from RISK ANALYTICS?
A: Industries such as finance, healthcare, and manufacturing benefit from improved risk assessment and decision-making.
Q: How does RISK ANALYTICS improve risk management?
A: By providing insights into potential threats, it allows organizations to implement proactive risk mitigation strategies.
Configure Company Profile and General Settings
Q: What parameters can be configured in the Company Profile?
A: You can configure Company Name, Company HQ Location, Company Industry Type, Company Employee Count, Company Revenue, Company Estimated Asset Count, Company Estimated Asset Count by Asset Type, and Company Estimated Sensitive Records Count.
Q: What parameters can be configured in the General Settings?
A: You can configure Current Deployment Phase, Locale, Default Mode, Risk Unit, Company Brand Color (Light Mode), Company Brand Color (Dark Mode), Maximum Records per Exported File, Risk Lower Limit, Impact Lower Limit, and Likelihood Lower Limit.
Widget List
Q: What is the purpose of the Risk Equation widget?
A: It displays a calculated risk value in US dollars, derived from multiplying the likelihood of a security incident by its potential financial impact.
Q: What does the Risk Composition widget show?
A: It shows a breakdown of risk posture across several risk categories, helping understand how each component changes when mitigation measures are applied.
Q: What information does the Vulnerabilities List widget provide?
A: It provides a searchable table of known vulnerabilities, sorted by maximum exposure score, helping prioritize vulnerabilities.
Q: How does the Vulnerability Summary widget assist?
A: It shows the total count of unique vulnerabilities categorized by severity level, aiding in prioritizing remediation efforts.
Q: What is displayed by the Security Controls ROI widget?
A: It displays the comparative risk before and after implementing security controls, showing risk reduction.
Q: What does the Controls Compliance Instances widget cover?
A: It displays how many controls have passed or failed compliance, providing a snapshot of compliance status.
Q: What details does the Next Best Steps widget list?
A: It lists prioritized remediation actions with estimated risk reduction, helping track impactful tasks.
Q: What insight does the Vulnerabilities Count Comparison widget give?
A: It shows total vulnerabilities for an asset group by severity, guiding focused remediation efforts.
Q: What does the Top Vulnerable Items widget show?
A: It displays items or vendors with the greatest number of known vulnerabilities by severity level, helping prioritize remediation.
Q: How does the Assets with Exposures widget help?
A: It displays assets and estimated breach risk, aiding in identifying and prioritizing critical assets.
Q: What does the Assets with Exposures by Site widget highlight?
A: It lists sites alongside unpatched asset counts, guiding remediation efforts to critical locations.
Q: What is displayed by the Assets with Exposures by Owners widget?
A: It lists owners with unpatched asset counts, focusing remediation on critical owners.
Q: How does the Vulnerabilities Instance Coverage widget assist in management?
A: It displays vulnerabilities by data source, spotting gaps or overlaps in detection.
Q: What information does the Asset List widget provide?
A: It displays discovered assets and potential breach impact, identifying high-cost compromise risks.
Q: What is shown in the Assets by Site widget?
A: It shows each site with asset counts, identifying largest asset footprints for focused security efforts.
Q: What does the Assets by Owner widget help with?
A: It shows owners with asset counts, aiding in focused security efforts on critical owners.
Q: What does the Asset Coverage widget compare?
A: It compares asset counts by data sources, spotting coverage gaps for a comprehensive asset view.
Q: What insight does the Software Inventory widget offer?
A: It displays top installed software packages by instance count, aiding in tracking patch levels and vulnerabilities.
Q: What does the Data Source Telemetry widget display?
A: It displays top data sources with covered devices, ensuring comprehensive security data coverage.
Q: What does the Asset Types widget breakdown show?
A: It shows asset breakdown by category, aiding in understanding environment composition.
Q: What does the Power Widget - Bar Chart - Risk Score widget show?
A: It displays risk scores for asset categories using color coding to indicate severity, helping prioritize concerns.
Q: What does the Power Widget - Bar Chart - Breach Likelihood widget compare?
A: It displays likelihood of breach for asset categories, helping prioritize risk areas.
Q: What does the Power Widget - Bar Chart - Breach Impact widget indicate?
A: It displays potential financial damage from breaches across asset groups, identifying high-consequence breaches.
Q: What information does the Power Widget - Bar Chart - Breach Risk widget provide?
A: It displays overall breach risk for asset groups, focusing remediation efforts on high financial exposure areas.
Q: What insight does the Power Widget - Bar Chart - Number of Assets widget offer?
A: It displays total assets per group, allowing environment distribution visualization.
Q: What does the Power Widget - Bar Chart - Vuln Summary widget reveal?
A: It displays vulnerability severities across asset groups, prioritizing critical vulnerabilities.
Q: What does the Power Widget - Trend Chart - Breach Likelihood widget track?
A: It tracks breach likelihood changes over time, spotting patterns or spikes.
Q: What insight does the Power Widget - Trend Chart - Breach Risk widget provide?
A: It tracks breach risk changes over time, gauging security improvements and potential threats.
Q: What does the Power Widget - Trend Chart - Number of Assets widget show?
A: It tracks asset count changes over time, identifying environment growth or fluctuations.
Q: What does the Power Widget - Trend Chart - Risk Score widget monitor?
A: It tracks overall risk score changes over time, assessing impact of new measures or threats.
Q: How does the Power Widget - Trend Chart - MTTP widget assist monitoring?
A: It tracks mean time to patch changes, evaluating patching process efficiency.
Q: What does the Power Widget - Trend Chart - MTTR widget measure?
A: It tracks mean time to remediate changes, measuring entire remediation process duration.
Q: What does the Power Widget - Trend Chart - MOVA widget show?
A: It displays mean open vulnerability age changes, ensuring proactive vulnerability management.
Q: What does the Power Widget - Donut Chart - Risk Score widget display?
A: It shows overall risk score in a color-coded donut chart for quick security posture assessment.
Q: What information does the Power Widget - Donut Chart - Number of Assets widget provide?
A: It provides asset count overview by category, aiding in understanding environment composition.
Q: How does the Power Widget - Donut Chart - Breach Likelihood widget help?
A: It visualizes breach likelihood, allowing quick urgency assessment for security efforts prioritization.
```
Configure Connectors
Q: How can connectors be added?
A: Connectors can be added either via API, or via file upload. API connectors will refresh automatically. File uploads are manual processes.
Q: Where can I see all the connectors?
A: You can see all the connectors in the Connectors List (https://help.balbix.com/docs/connector-list).
Configure Tag Manager
Q: How do you configure tags in Tag Manager?
A: In the Tag Manager menu, you can create your own tags to apply to assets, assign a tag color, and add attributes like impact level, asset zone, device type, and various owner types.
Q: What impact levels can be assigned to tags?
A: Impact levels can be mission critical, critical, high, medium, low, or none.
Q: What asset zones can be assigned to tags?
A: Asset zones can be core, perimeter, core-airgapped, core-internal, perimeter-DMZ, or perimeter-internet facing.
Q: What operations can you perform on tags?
A: You can search, edit, and delete tags.
Configure Users and Access
Q: What actions can you perform in the Users menu?
A: Add a user, assign role to a user, reset the password for a user, reset multi-factor authorization (MFA) for a user, remove user access, resend invite email to a user, delete a user account, edit users, send users a Bix instruction.
Q: What actions can you perform in the Roles and access control menu?
A: Add a role, view and edit roles, duplicate roles, delete roles.
Q: What actions can you perform in the Allowed email domains menu?
A: Add allowed email domain, remove allowed email domain.
Review Licensing
Q: What can I review in Module Entitlements?
A: You can review the activation and renewal dates for the modules you have access to.
Q: What can I view in License Count?
A: You can review your infrastructure count, application count, and user count. You can also request an increase in your license count.
Q: What information is available in Licensed Users?
A: You can review how many seats you have for exposure assessment, exposure management, and cyber risk quantification. You can also configure the seats.
Risk Equation Widget
Q: What does the Risk Equation widget show?
A: It shows how your total cyber risk is calculated using the formula: Risk = Likelihood × Impact, providing a live, dollar-based estimate of current risk exposure.
Q: How does the Risk Equation widget help assess risk reduction efforts?
A: By showing changes in likelihood and impact values as you patch vulnerabilities, reduce exposure, or improve security controls, providing a measurable way to track progress.
Q: How does the Risk Equation widget support decision-making?
A: It helps determine where to focus efforts by highlighting whether a high likelihood or impact is driving risk, aiding in prioritizing mitigation actions.
Risk Composition Widget
Q: What does the Risk Composition widget show?
A: It breaks down the financial structure of your cyber risk, giving visibility into the risk at each stage of your security posture, showing maximum breach impact, inherent risk, post-mitigation risk, and residual risk.
Q: What is Breach Impact?
A: It is the estimated financial loss if a significant security incident occurs with no controls, representing worst-case business disruption, data loss, penalties, and recovery costs.
Q: What is Inherent Risk?
A: It is the risk level before any security controls, reflecting raw exposure based on asset value, vulnerabilities, and threat landscape.
Q: What does Post Mitigation Risk represent?
A: It shows the remaining risk after accounting for current security controls like patching, segmentation, or endpoint protections, indicating risk reduction by existing controls.
Q: What is Residual Risk?
A: It is the final risk level after all known mitigations, controls, and risk transfer, which the organization must accept or further reduce.
Q: How can the Risk Composition widget aid decision-making?
A: By evaluating mitigation strategy effectiveness, showing risk reduction, helping justify control investments, demonstrating existing measures' value, and identifying areas needing action.
Assets with Exposures by Owners Widget
Q: What does the Assets with Exposures by Owners widget show?
A: It shows which owners are responsible for the highest number of unpatched assets in your environment, tying specific owners to a count of assets with known exposures to visualize accountability.
Q: How can the Assets with Exposures by Owners widget be used?
A: It can engage stakeholders, drive targeted action, implement gamification, and help coordinate efforts across departments by associating exposure counts with named owners.
Q: Why is the Assets with Exposures by Owners widget useful?
A: It aligns risk remediation with business context by addressing exposures through ownership and operational responsibility, useful for environments with distributed asset management or cross-functional teams.
Vulnerabilities Instance Coverage Widget
Q: What does the Vulnerabilities Instance Coverage widget show?
A: It shows the total number of vulnerability instances detected in your environment, categorized by data source, segmented by severity.
Q: How can you use the widget to assess detection strategy completeness?
A: By evaluating contributions from each source, identifying underutilized tools, integration issues, or limited visibility in specific infrastructure parts.
Q: How does the widget support validation and tuning of your data pipeline?
A: By comparing findings from different sources to identify enhancement areas for AI, consolidation engines, and additional integration work.
Vulnerabilities Count Comparison Widget
Q: What does the Vulnerabilities Count Comparison Widget show?
A: It shows the total number of vulnerabilities for a particular asset group, broken down by severity categories (Unknown, Low, Medium, High, Critical).
Q: How does the Vulnerabilities Count Comparison Widget help?
A: It helps you quickly identify where the bulk of your high-severity vulnerabilities lie, guiding more focused remediation efforts.
Security Controls ROI Widget
Q: What is the purpose of the Security Controls ROI widget?
A: It quantifies the financial value of your current security controls by comparing risk with and without them, presenting total risk reduction to show return on cybersecurity investments.
Q: What does "Without Security Controls" represent?
A: It represents the financial risk your organization would face if no security measures were in place, reflecting inherent risk from vulnerabilities and asset value.
Q: What does "With Security Controls" show?
A: It shows actual financial risk after applying the security controls currently deployed, reflecting risk after your defensive posture.
Q: How is "Likelihood" defined in the context of the widget?
A: It refers to the probability of a successful cyber incident, expressed as a percentage, showing how controls reduce the chance of exploitation.
Q: What is "Total Risk Reduction"?
A: It is the difference in financial risk between the uncontrolled and controlled states, quantifying the impact of your security investments in monetary terms.
Q: How can the widget help evaluate control effectiveness?
A: By showing risk and likelihood reductions, it indicates areas where controls prevent or contain threats, offering guidance on future investments.
Q: How does the widget assist in communicating with leadership?
A: By expressing control effectiveness in financial terms, it shifts conversation from technical details to business impact, aiding decision-making on future investments.
Controls Compliance Instances Widget
Q: What does the Controls Compliance Instances widget do?
A: It helps assess how effectively your security controls are being implemented across different control categories, with a breakdown of passed and failed checks.
Q: What is the purpose of the widget?
A: To provide immediate visibility into where controls are functioning correctly and where they are not.
Q: How can this widget be used?
A: To quickly identify areas needing attention, signaling gaps in control enforcement that could weaken your overall risk posture.
Q: Why is IG1 important in controls compliance?
A: A high failure count in IG1 indicates foundational issues that should be prioritized for remediation.
Q: How does the widget support decision-making?
A: By providing a consolidated view to focus on the highest-impact failures, improving control coverage and reducing exposure efficiently.
Assets with Exposures by Site Widget
Q: What does the "Assets with Exposures by Site" widget show?
A: It shows where unpatched or exposed assets are concentrated across your organization’s physical or logical locations, helping identify locations with the highest operational risk.
Q: How can the widget be used for remediation efforts?
A: It helps coordinate and prioritize site-specific remediation efforts, enabling targeted visibility to streamline coordination between security and operations teams across distributed environments.
Q: What alignment does the widget enable?
A: It aligns risk reduction efforts with organizational structure, providing a clear starting point for site-level initiatives based on exposed asset distribution.
Next Best Steps Widget
Q: What is the purpose of the Next Best Steps widget?
A: It helps prioritize remediation by listing impactful actions to reduce cyber risk, with an estimated financial risk reduction for each task.
Q: How does the widget support decision-making?
A: By comparing tasks based on technical urgency and potential return, aiding strategic decisions to reduce exposure.
Q: How can the widget assist in operational planning?
A: It guides planning by providing a prioritized list of recommended actions, simplifying management of vulnerabilities and misconfigurations.
Q: How is the widget organized?
A: It is organized into Proposed, In Progress, and Completed tabs to track remediation workflow and coordinate efforts across teams.
Q: What is the benefit of using the widget?
A: It turns risk insights into measurable action, ensuring accountability and monitoring progress effectively.
Assets with Exposures Widget
Q: What does the Assets with Exposures widget identify?
A: It identifies individual systems in your environment that carry the highest breach risk, listing a hostname and its associated risk value in monetary terms.
Q: What does the monetary risk value represent?
A: The potential financial impact if that asset were compromised.
Q: How does the widget help in risk management?
A: It helps pinpoint which assets contribute most to your overall risk posture.
Vulnerability Summary Widget
Q: What does the Vulnerability Summary widget provide?
A: It provides a high-level view of all unique vulnerabilities identified across your environment, grouped by severity level.
Q: How does the Vulnerability Summary widget help?
A: It helps you understand the overall scale of your vulnerability landscape and categorize it into critical, high, medium, or low categories.
Q: What does the count in the center of the Vulnerability Summary widget represent?
A: It reflects the total number of unique vulnerabilities, not instances.
Top Vulnerable Items Widget
Q: What does the Top Vulnerable Items widget highlight?
A: It highlights vendors or platforms with the highest number of known vulnerabilities, displayed with a severity breakdown from low to critical.
Q: What is the purpose of the horizontal bar in the widget?
A: The horizontal bar helps you quickly assess which products contribute most to your organization's vulnerability footprint.
Q: How can this widget assist in remediation efforts?
A: It allows focusing on vendors requiring immediate attention and aids in prioritizing remediation and vendor management efforts.
Q: What is signaled if Microsoft has the largest share of vulnerabilities?
A: It signals that patching or configuration processes for Microsoft products may need strengthening, especially in the medium to critical range.
Q: How does the widget support prioritization at the vendor level?
A: It makes it easier to coordinate bulk remediation across product lines and teams, tracking the effectiveness of vendor-specific strategies.
Vulnerabilities List Widget
Q: What does the Vulnerabilities List widget provide?
A: It gives a ranked view of the vulnerabilities present in your environment, prioritized by their Max Exposure Score.
Q: How is the Max Exposure Score determined?
A: It reflects the highest level of risk exposure associated with each vulnerability across all affected assets, incorporating severity, exploitability, reachability, and business context.
Q: Why does the ranking not always correspond to the highest CVSS scores?
A: Balbix includes real-time exposure conditions and asset criticality, going beyond static scoring.
Q: What functionality does the widget provide?
A: It is sortable, searchable, and highlights vulnerabilities with the highest scores at the top to help prioritize remediation efforts.
Exports
Q: Where can I find export options?
A: You can find these options in the Exports menu.
Q: What can I do in the Exports view?
A: Access previously generated files and filter export records by selecting a Date Range. You can also locate and select specific exports using the Checkbox Selector, and download selected export files using the Download button.
Alerts
Q: What can I access through the BX5 Asset Analysis settings?
A: You can access asset telemetry configuration, review sensor deployment status, track data ingestion sources, compare raw and deduplicated assets, evaluate asset data quality, identify incomplete telemetry, detect outdated records, monitor asset lifecycle, and navigate across different asset groups.
Q: What does the Configured Sensors count show?
A: It shows the number of configured sensors.
Q: What is the difference between Raw Assets and Analyzed Assets?
A: Raw Assets are the number of assets ingested before deduplication, while Analyzed Assets are the number after deduplication.
Q: What does the Categorized Assets table display?
A: It displays assets with sufficient data fidelity for accurate categorization.
Q: What are Assets with Poor Visibility?
A: Assets with insufficient data fidelity for accurate categorization, excluded from dashboards and risk calculations.
Q: What are Transient Assets?
A: Assets last observed more than 7 days ago (or 2 days for cloud assets), with both first and last observed times within the same day, excluded from dashboards and risk calculations.
Q: What are Recently Retired Assets?
A: Assets retired within the last 7 days due to lack of observations, excluded from dashboards and risk calculations.
Q: How is BX5's architecture designed?
A: It is built around data aggregation, deduplication, and AI-driven analysis, ingesting data from multiple sources and enriching it with contextual information for risk analysis.
Q: What is the purpose of data deduplication and normalization in BX5?
A: To eliminate redundant asset entries and standardize asset attributes for compatibility with analytical models and consistent risk scoring.
Q: How does BX5 enrich asset details?
A: By enhancing asset records with contextual information such as business impact, exposure level, and operational relevance for accurate risk prioritization.
Q: How does BX5 handle asset categorization?
A: It categorizes assets into on-premise and cloud types using predefined classification logic.
Q: What are Unverified Assets in BX5?
A: Assets lacking sufficient data for proper categorization, requiring customer verification or data augmentation.
Q: What is the outcome of BX5's asset processing?
A: It ensures clarity in asset fidelity, helping prioritize security initiatives and allocate resources efficiently.
Logs
Q: How do I access logs in the system?
A: Click Logs in the left navigation menu. Use the From and To date/time fields at the top to filter logs.
Q: What information do the log table columns show?
A: The columns include Event Info, Type, Time, and Actor, showing what occurred, when, and who initiated it.
Q: How can I search for specific events in the logs?
A: Use the search bar in the upper-right corner to locate specific events by keyword. The table updates automatically after changes.
Configure asset and apps automations
Q: What is the scope of automation in Configure Asset and Apps Automations?
A: It can be current table filter, new filter, assets in specified group, or assets matching saved filter.
Q: What are the automation trigger types?
A: Upon next evaluation, based on a schedule, or on a specific date.
Q: What actions can be triggered with automation?
A: Send Slack, send email, add tags, send export, remove tags, set element attributes.
Q: What can you configure if you select Set Element Attributes?
A: Attribute to update, select asset type, select asset subtype.
Q: How do you activate the automation immediately?
A: Select "Make this active on creation".
Create user-defined groups and assign owners
Q: How do I create a user-defined group?
A: Use the workflow to create a new user-defined group.
Q: How can I assign an owner to a user-defined group?
A: Follow the steps in the workflow to assign an owner to the group.
Configure asset and apps dashboards
Q: What does the Asset List widget display?
A: It displays all discovered assets along with their potential breach impact in monetary terms, each asset’s hostname, and associated risk value to quickly identify assets with the highest potential cost if compromised.
Q: What information does the Assets by Site widget provide?
A: It shows each site alongside the total number of assets located there, helping to identify where the largest asset footprints lie for focused security and remediation efforts.
Q: What is the purpose of the Asset Coverage widget?
A: It compares the number of assets identified by different data sources to spot potential coverage gaps and ensure a comprehensive view of all assets.
Q: How does the Software Inventory widget assist users?
A: It displays the top installed software packages sorted by the total number of instances in the environment to track patch levels and potential vulnerabilities effectively.
Q: What does the Data Source Telemetry widget show?
A: It displays the top data sources contributing telemetry and the number of devices or assets each source covers to ensure comprehensive coverage and spot potential gaps.
Q: What information is provided by the Asset Types widget?
A: It shows a breakdown of assets by category, such as desktops/laptops, servers, IoT devices, etc., alongside their respective counts to understand the composition of the environment.
Set owners for predefined groups
Q: What can I access through the BX5 Asset Analysis settings?
A: You can access asset telemetry configuration, review sensor deployment status, track data ingestion sources, compare raw and deduplicated assets, evaluate asset data quality, identify incomplete telemetry, detect outdated records, monitor asset lifecycle, and navigate across different asset groups.
Q: What does the Configured Sensors count show?
A: It shows the number of configured sensors.
Q: What is the difference between Raw Assets and Analyzed Assets?
A: Raw Assets are the number of assets ingested before deduplication, while Analyzed Assets are the number after deduplication.
Q: What does the Categorized Assets table display?
A: It displays assets with sufficient data fidelity for accurate categorization.
Q: What are Assets with Poor Visibility?
A: Assets with insufficient data fidelity for accurate categorization, excluded from dashboards and risk calculations.
Q: What are Transient Assets?
A: Assets last observed more than 7 days ago (or 2 days for cloud assets), with both first and last observed times within the same day, excluded from dashboards and risk calculations.
Q: What are Recently Retired Assets?
A: Assets retired within the last 7 days due to lack of observations, excluded from dashboards and risk calculations.
Q: How is BX5's architecture designed?
A: It is built around data aggregation, deduplication, and AI-driven analysis, ingesting data from multiple sources and enriching it with contextual information for risk analysis.
Q: What is the purpose of data deduplication and normalization in BX5?
A: To eliminate redundant asset entries and standardize asset attributes for compatibility with analytical models and consistent risk scoring.
Q: How does BX5 enrich asset details?
A: By enhancing asset records with contextual information such as business impact, exposure level, and operational relevance for accurate risk prioritization.
Q: How does BX5 handle asset categorization?
A: It categorizes assets into on-premise and cloud types using predefined classification logic.
Q: What are Unverified Assets in BX5?
A: Assets lacking sufficient data for proper categorization, requiring customer verification or data augmentation.
Q: What is the outcome of BX5's asset processing?
A: It ensures clarity in asset fidelity, helping prioritize security initiatives and allocate resources efficiently.
Create asset filters
Q: What attributes can be used to create filters in the Assets menu?
A: Filters can be created based on Hostname, Asset Type, Site, Roles, Tags, OS Platform, Vuln Count, Groups, OS Patch State, Business Owner, Asset Subtype, Manufacturer, Operating System, Data Sources, Earliest Observation, Latest Observation, MAC Address, Cloud Unique ID, Serial Number, Latest analysis, OS Architecture, OS Vendor, OS Version, Last Seen By Balbix HA, CPU Cores, CPU Model Name, SMBIOS Version, System Model, Total Physical Memory, BIOS Release Date, BIOS Vendor, BIOS Version, Cloud Account ID, Is Running Cloud Asset, Is Cloud Asset, OS Installation Date, Cloud Service Provider, Latest Installed OS Patch, Network Zone, IP Address, Latest Installed OS Patch Publish Date, Latest OS Patch Install Date, Earliest Pending OS Patch, Location: Region, Location: Country, Location: State, Location: City, PowerShell Execution Policy, Is SMBv1 Enabled, Is SMBv2 Enabled, Is SMBv3 Enabled, Is Domain Joined, Windows Domain Name, Windows Domain Role, Is Manually Categorized, Is Reboot Pending, Is Bastion Asset, VM Owner, IT Owner, Latest Pending OS Patch, Is Disk Encrypted, Primary User, Max Exposure Score, Max Exposure Severity, Risk Score, Software Vendor, Software Category, Software Product, Software Product Version, Device Patch State, Software Patch State, Cloud Asset Type, Is Mission Critical, Roll-Up VM Owner, Geolocation, Breach Risk, Breach Likelihood, Breach Impact, Cloud Instance ID, Cloud Resource Group Name, Cloud Region, External IP Address, Earliest Pending OS Patch Publish Date, Is Secure Boot Enabled, OS Release Date, Latest Pending OS Patch Publish Date, Windows Update Configuration, Windows Update Server, Windows Update Server Reachability, Last Successful Windows Update Check, Data Sources: Observing Sensors, OS Product Version, Residual Likelihood, Accepted Likelihood, Inherent Likelihood, Mitigated Likelihood, Accepted Risk, Risk Inherent, Mitigated Risk.
Q: How are advanced filters evaluated?
A: Advanced filters apply boolean logic by evaluating attributes with AND within a group and evaluating groups with OR.
Vulnerability Inference
Q: What is the purpose of the Vulnerability Inference system?
A: It provides a comprehensive mechanism for accurately identifying and managing vulnerabilities that affect software components, ensuring precise attribution and eliminating false positives.
Q: How does the Balbix AI system process vulnerability data?
A: It processes data through a sequential pipeline that handles CVE mapping, identity management, relationship tracking, data consolidation, quality control, and state processing.
Q: What is the "Infer New / Additional Vulnerabilities" option?
A: This option allows Balbix to proactively tag new vulnerabilities as soon as they are released by vendors, ensuring faster and more comprehensive management.
Q: What does "Corroborate Vulnerabilities Only" mean?
A: Balbix will corroborate vulnerabilities ingested from third-party tools, ensuring only high-confidence vulnerabilities are tagged.
Q: How does "Enrich Fix Information" work?
A: It enhances fix details with actionable information such as URLs and patch names, supplemented by Balbix’s data.
Q: What does "Infer EOL Vulnerabilities" do?
A: It automatically detects vulnerabilities related to software components that have reached their End-of-Life.
Q: How are configuration items adjusted?
A: They can be set by accounts with admin access or Balbix customer success administrators, some via system interface, others through Balbix support.
Q: What happens in Stage 1: CVE Tagging and Initial Processing?
A: It analyzes software components, maps CVEs, and tracks patch timing for accurate state management.
Q: What is handled by Version-Specific Substages?
A: These substages ensure accurate processing of software versions for vulnerability tagging, preventing inaccuracies.
Q: What does Stage 2: ID Management achieve?
A: It creates unique identifiers for vulnerabilities, tracking versions of components for consistent associations.
Q: Describe Stage 3: Relationship Mapping.
A: It establishes connections between software components and their vulnerabilities, tracking dependencies and compatibility.
Q: What is the purpose of Stage 4: Consolidation?
A: It merges duplicate entries and standardizes data, ensuring consistency in vulnerability data.
Q: How does Stage 5: Quality Control function?
A: It validates and enriches data, removing uncorroborated vulnerabilities to ensure high-quality data.
Q: What does Stage 6: State Processing involve?
A: It updates component states based on vulnerability data and aggregates the overall security posture.
Q: What is addressed in Stage 7: EOL Processing?
A: It identifies End-of-Life components, generating vulnerability entries for proactive remediation.
Balbix Sensor OS Support List
Q: What does the Balbix Sensors OS support list provide?
A: It provides a list of operating systems and corresponding supported Balbix Sensors.
Q: What does "passively supported" mean for Balbix Sensors?
A: Installers are available, but may not be actively supported, such as due to EOL OS.
Q: Which platforms have actively supported Balbix Sensors?
A: Balbix Linux, Windows 10 (specific versions), Windows Server (various versions), RedHat Enterprise Linux, Rocky Linux, SUSE Linux Enterprise, Ubuntu, Debian, Oracle Enterprise Linux, Amazon Linux, macOS, and others are actively supported.
Q: What does Balbix support for AIX?
A: Actively supports AIX 7.1, 7.2, and 7.3 on POWER8, POWER9.
Q: What networking devices are supported by Balbix?
A: Cisco IOS, IOS XE, NX-OS, Juniper JUNOS, IBM Network Operating System, and others are actively supported.
Understanding MOVA
Q: What is Mean Open Vulnerability Age (MOVA)?
A: Mean Open Vulnerability Age (MOVA) is a key performance indicator in cybersecurity and vulnerability management, representing the average age of all vulnerabilities currently in an "open" state within a defined scope at a specific point in time.
Q: Why is MOVA important?
A: MOVA provides insight into risk persistence and the effectiveness of your vulnerability management, helping quantify persistent risk, assess backlog health, identify process inefficiencies, track remediation effectiveness, inform prioritization, and measure program maturity.
Q: How is MOVA calculated?
A: MOVA is calculated by identifying open vulnerabilities, determining discovery time, calculating individual ages, and averaging these ages to represent the mean age of unresolved vulnerabilities.
Q: How does Balbix help with MOVA?
A: Balbix automatically identifies open vulnerabilities, tracks discovery dates, computes MOVA, and provides insights for tracking progression and addressing bottlenecks in vulnerability management.
Container Image Inventory Unification
Q: What are the key subtypes of container assets?
A: Cluster, Image, Workload, and Instance.
Q: What does a Cluster represent?
A: Persistent orchestration environments where containers run.
Q: What is an Image in a container ecosystem?
A: Packaged application code and dependencies stored in registries.
Q: How is a Workload defined?
A: Configurations for deploying and managing container images within clusters.
Q: What is an Instance?
A: Actual running containers instantiated from images based on workload definitions.
Q: What is a Registry?
A: A service that stores and distributes container images.
Q: What is the significance of a Namespace?
A: A logical grouping within a registry representing an organization, user, or project.
Q: What are Tags in container images?
A: Human-readable labels pointing to specific versions of an image.
Q: What is a Digest in container image terms?
A: A SHA-256 hash uniquely identifying the content of an image.
Q: Why is digest-based tracking important?
A: It ensures consistent tracking and eliminates confusion from tag variability.
Q: What challenges can arise with partial observability?
A: Environment and tool limitations can lead to gaps in metadata and tracking accuracy.
Q: Why are tags not reliable identifiers?
A: They can be overwritten, reused, and represent moving targets over time.
Q: What issues do digest inconsistencies cause?
A: They can lead to duplicate counting or missed correlations across tools.
Balbix Host Analyzer (HA) Deployment Guide
Q: What types of data sources can Balbix harvest data from?
A: Balbix can harvest data from various sources using sensors, connectors, and collectors, usable in different environments.
Q: What does the Balbix Host Analyzer (HA) do?
A: The Balbix HA gathers detailed, real-time information related to installed software, configurations, and observes network traffic.
Q: On which operating systems can Balbix HA be installed?
A: Balbix HA can be installed on Windows, OSX, CentOS, and RedHat Linux.
Q: What is required for HA communication?
A: HA communication requires whitelisting at the process level and firewall whitelisting for Balbix Dashboard communication.
Q: What is the purpose of the Balbix Traffic Analyzer (TA)?
A: The TA inspects and evaluates network traffic to determine user, owner, device configuration, software, and services.
Q: How is TA configured?
A: TA requires configuration with details such as hostname, management interface IP, subnet, and gateway information.
Q: What are the supported operating systems for Balbix HA deployment?
A: Balbix HA supports Windows, Linux (Red Hat, CentOS, Ubuntu), and the latest Mac OS X versions.
Q: What are the minimum system requirements for Balbix HA?
A: Minimum requirements include a dual-core 2GHz CPU, 4GB RAM, 150MB storage, and internet connectivity.
Q: How can Balbix HA be installed on Windows?
A: Installers are provided via Box, and can be run interactively or silently using .exe or .msi files.
Q: How is user activation for Balbix Dashboard access done?
A: A user receives an email with an activation link, sets a password, and enrolls in MFA using Okta Verify.
Q: How can the connectivity of Balbix HA be verified?
A: Verify connectivity by navigating to the Sensors and Connectors section in the Balbix Dashboard and expanding the HA category.
Consolidating Operating Systems and Software: A Unified Approach
Q: What is the purpose of consolidating operating system entries?
A: To ensure that multiple OS entries from various sources are combined into the most accurate representation of the actual OS running on a device.
Q: Why is software consolidation important for IT and security teams?
A: A consolidated view helps in identifying vulnerabilities, deploying patches more effectively, reducing duplicate entries, and providing a unified dataset for audits and reporting.
Q: What does the operating system consolidation process ensure?
A: It ensures consistent vulnerability mapping and asset management by identifying the most accurate OS from multiple entries.
Q: What are transient assets in operating system consolidation?
A: Assets last observed more than 7 days ago (or 2 days for cloud assets), with both first and last observed times within the same day, excluded from dashboards and risk calculations.
Q: How does non-OS software consolidation differ?
A: It consolidates software entries while preserving truly distinct installations, preventing false consolidation of similar software instances.
Q: What does the non-OS software consolidation process involve?
A: Grouping entries by vendor and product name, handling conflicts, and preserving component IDs while filling in missing fields.
Q: How does BX5 handle asset categorization?
A: It classifies assets into on-premise and cloud types using predefined classification logic.
Balbix Exposure Simulator Use Cases
Q: What is the primary aim of the Balbix Exposure Simulator?
A: It is designed for quantifying and analyzing cyber risk associated with specific vulnerabilities within an environmental context.
Q: How can users leverage the simulator's defined parameters?
A: By structuring use cases based on primary analytical intent and mapping them to configurable inputs such as Asset Attributes and Threat Level.
Q: What does the Risk Quantification & Profiling category encompass?
A: It focuses on establishing a calculated risk baseline for specific scenarios to assign precise Exposure Scores.
Q: What is the purpose of the Vulnerability-Asset Instance Risk Assessment use case?
A: To determine the calculated Exposure Score for a specific CVE on a specific asset with defined attributes.
Q: What are the business outcomes of the Inherent vs. Mitigated Risk Baseline use case?
A: It assesses the effectiveness of current control stacks and identifies areas where controls are underperforming.
Q: How does the Asset Archetype Risk Profiling use case assist users?
A: It profiles the typical risk level for asset classes facing high-impact vulnerabilities to inform security policies.
Q: What is the purpose of Impact Analysis & Sensitivity Testing?
A: To explore the sensitivity of the calculated Exposure Score to changes in input parameters.
Q: How does the Security Control Efficacy Impact use case benefit organizations?
A: It evaluates how changes in security control effectiveness impact the Exposure Score for vulnerability scenarios.
Q: What decisions does the Asset Context Change Impact use case help with?
A: It helps evaluate risk implications before deploying assets into sensitive zones or changing asset context.
Q: How is the Threat Landscape Fluctuation Impact use case utilized?
A: It assesses how changes in the threat landscape impact the Exposure Score for existing vulnerabilities.
Q: What is the focus of Comparative Risk Assessment?
A: Comparing the relative risk posed by different elements, such as vulnerabilities or assets, for strategic decision-making.
Balbix D3 Exposure Score Enhancements
Q: What is the purpose of Balbix's risk quantification?
A: To enable organizations to make informed decisions about security investments and prioritize remediation efforts.
Q: What does the document outline regarding Balbix's scoring methodology?
A: It highlights the evolution from the original Balbix score (F1) to the new Exposure score (D3), emphasizing enhancements and commitment to accurate risk assessment.
Q: What limitations do traditional vulnerability metrics have?
A: They often don't account for the specific context of each organization's environment, which Balbix scores aim to address.
Q: What is a core principle shared by both scoring methodologies?
A: Both evaluate risk by considering asset attributes, vulnerability characteristics, and threat intelligence.
Q: How does the Enhanced Approach (D3) improve upon previous methods?
A: It shows distinct risk scores for every occurrence and enables more precise risk prioritization at the asset level.
Q: What is the benefit of having granular score visibility?
A: It allows more accurate representation of risk and better support for targeted remediation efforts.
Q: What does the Enhanced Asset Attribution in D3 include?
A: Expanded asset impact framework, operational status integration, and network zone-based accessibility assessment.
Q: What are the benefits of advanced impact analysis?
A: More accurate risk calculations, better alignment with organizational priorities, and enhanced support for strategic decision-making.
Q: What capabilities does Advanced Threat Intelligence in D3 include?
A: EPSS score integration, OWASP Top Weakness correlation, and expanded threat intelligence sources.
Q: What does Mitigation Efficacy Assessment evaluate in D3?
A: The actual effectiveness of existing security measures and includes dynamic efficacy calculations.
Q: What benchmarking capabilities are enhanced in D3?
A: Industry-wide comparisons, privacy-preserving benchmarking, and geographical comparisons.
Q: What benefits does benchmarking provide?
A: Better understanding of relative security posture and data-driven improvement goals.
Q: What is Risk tolerance customization in D3?
A: It allows alignment of scoring with specific risk appetite and tolerance levels.
Q: How does the Exposure score improve upon the Balbix score?
A: By introducing enhanced capabilities, greater flexibility, and improved alignment with modern security needs.
Q: What additional tool does the Exposure score offer?
A: The exposure score simulator, which allows interactive exploration of the scoring.
Telemetry
Q: What is telemetry?
A: Telemetry refers to the automated process of collecting and transmitting data from various integrated applications and systems into the Balbix platform via connectors, enabling real-time or near-real-time ingestion of diverse datasets for accurate analysis, risk assessments, and prioritization.
Q: Where can I find the Analyzed Assets Telemetry widget?
A: You can find the Analyzed Assets Telemetry widget in inventory>assets.
Q: How are the assets telemetry values determined?
A: Good: Asset is categorized and has at least one software package in the inventory or vulnerability associated with it. Poor: All other assets that don't meet the definition of "Good".
Q: How are the applications telemetry values determined?
A: Good: Apps with vulnerabilities or apps with mapped infrastructure. Poor: All other assets that don't meet the definition of "Good".
Unified Enterprise Asset Classification Model
Q: What is the unified asset classification model?
A: It provides a comprehensive framework for categorizing all types of enterprise assets, creating a standardized taxonomy across different technology domains.
Q: What are the benefits of the unified asset classification model?
A: It bridges traditional silos, accommodates emerging technologies, enables consistent security controls, improves compliance management, and enhances risk assessment capabilities.
Q: How is the unified asset classification model structured?
A: It consists of 16 primary categories with clearly defined subtypes, creating a hierarchical taxonomy with extensible null subtypes and clear parent-child relationships.
Q: What is the purpose of the unified asset classification model for hybrid environments?
A: It provides a holistic view of assets while maintaining their distinct characteristics and supports effective asset management, security implementation, and compliance monitoring.
Data Lifecycle in Balbix
Q: What is the focus of the data lifecycle in Balbix?
A: The data lifecycle focuses on ingesting data from various sources, enriching it with context, and processing it to help organizations understand and mitigate risk.
Q: What are the initial steps in data onboarding and integration?
A: Integrating and onboarding data from connected systems such as vulnerability scanners, cloud platforms, and endpoint management tools.
Q: How does Balbix standardize and structure data?
A: By normalizing diverse formats to its standardized format, ensuring compatibility with its analytical models.
Q: How does Balbix enrich collected data?
A: By establishing relationships between assets, vulnerabilities, and configurations, and enriching data with business context.
Q: What happens during post-ingestion preparation?
A: The data undergoes preparation to ensure accuracy, consistency, and alignment with Balbix’s data model.
Q: What is the purpose of risk-oriented data processing?
A: To refine ingested data into actionable insights prioritizing risk mitigation.
Q: How does Balbix handle automated ticketing?
A: By integrating with IT service management tools to create remediation tickets automatically, prioritized by risk score.
Q: What are the features of Balbix's dashboard?
A: It provides a risk heatmap, prioritized actions, drill-down analysis, and dynamic reporting.
Q: How does Balbix ensure continuous updates?
A: By syncing with connected tools, updating data in near real-time with changes in assets, vulnerabilities, or configurations.
Asset Roles
Q: What methods does Balbix use to label assets?
A: Balbix supports static tags applied by users or external sources, and roles automatically detected and applied by Balbix.
Q: How do asset-level tags and roles benefit users?
A: They enable quick searching, identifying specific assets for tracking, remediation, or reporting, and influence associated asset risk.
Q: How are asset-level tags typically ingested?
A: They are ingested from third-party data sources via connectors and can also be added or changed manually by users.
Q: How do roles function compared to tags?
A: Roles function as "dynamic tags" automatically applied based on insights inferred from available asset-level data.
Q: What is the purpose of asset roles?
A: To represent the business function of an asset, its contributions, or the service(s) it is hosting.
Q: How does Balbix infer roles?
A: By using ports and asset information, software stack, and processing asset tags.
Q: How does Balbix determine an asset’s role based on ports?
A: By analyzing which ports need to be open for specific asset types to determine roles.
Q: What role does the software stack play in inferring asset roles?
A: The platform examines running software to determine the asset’s role, applying roles accordingly.
Q: How are asset roles detected for cloud services?
A: By applying the cloud service name per the vendor as a Role, such as AWS EC2 instances having "AWS-EC2" as the Role.
Q: How many roles does Balbix have available for assets?
A: Balbix currently has 100+ roles available, including LDAP, DNS, web server, FTP, SSH, database, and cloud-based roles.
Q: Is the role list subject to updates?
A: Yes, the list is subject to change and updated periodically.
EPSS Technical Note
Q: What version of EPSS does Balbix currently use?
A: Balbix currently uses V4, released 3/17/25.
Q: Where is the data sourced from?
A: The data is sourced from FIRST, available at https://api.first.org/epss/ and https://www.first.org/epss/api.
Q: Where can you see Balbix listed?
A: You can see Balbix listed at https://www.first.org/epss/who_is_using/.
Exposure Management Concepts
Q: What is RBVM?
A: RBVM (Risk-Based Vulnerability Management) is the process by which vulnerabilities are managed and remediated based on the overall risk they pose to the affected asset, group of assets, and the enterprise.
Q: What are the key components of RBVM?
A: Risk is calculated as Likelihood x Impact, involving knowledge of inventory and vulnerabilities, exposure considerations, associated threats and security controls.
Q: What are the limitations of CVSS-based prioritization?
A: CVSS assumes worst-case scenarios without considering specific enterprise conditions, leading to over-simplification and less effective prioritization.
Q: How does Balbix Exposure Management enhance vulnerability management?
A: Balbix integrates CVSS severity, dynamic threat information, control efficacy, asset criticality, and exposure analysis to prioritize vulnerabilities effectively.
Q: What is the significance of threat level in vulnerability management?
A: Threat level evaluates exploitation potential based on known exploits, adversary intent, and tags from entities like CISA.
Q: What role does TTP analysis play in vulnerability management?
A: TTP analysis focuses on how vulnerabilities are exploited using standardized methods like the MITRE ATT&CK framework, assessing exposure, exploitability, and impact.
Q: How is asset criticality analyzed?
A: Asset criticality is evaluated through enterprise-level impacts and asset-level tags, roles, and categories to prioritize vulnerabilities by business significance.
Q: What is the importance of asset operating location in vulnerability management?
A: Operating location determines exposure level to adversaries, assessing external exposure, control dependencies, and complexity of exploitation.
Q: How does security control analysis contribute to vulnerability management?
A: It evaluates control coverage and efficacy against TTPs to understand how well vulnerabilities are mitigated by existing controls.
Q: What are the benefits of 4th Gen RBVM with CRQ?
A: It integrates multiple dimensions like CVSS severity, TTP analysis, and control efficacy to provide comprehensive, dynamic, and data-driven vulnerability prioritization.
Mitigation Efficacy Overview
Q: What is mitigation efficacy?
A: It measures how effectively security controls reduce vulnerabilities within an organization.
Q: How does the methodology work?
A: It maps vulnerabilities to ATT&CK TTPs and aligns them with security controls for data-driven decision-making.
Q: What is ATT&CK TTP usage?
A: The system establishes relationships between vulnerabilities and controls using ATT&CK TTPs.
Q: What does the process create?
A: It creates a matrix including vulnerabilities, techniques, controls, and weights.
Q: What are key outcomes?
A: Identifies likely attack areas, highlights optimal controls, and enables optimized investments.
Q: How is technique-based efficacy calculated?
A: By dividing the number of controls passed by the total tested.
Q: What is unmapped efficacy?
A: Unmapped vulnerabilities use a conservative calculation when no TTPs are identified.
Q: What does the final efficacy calculation involve?
A: It uses the minimum of effective and mitre efficacy for final calculation.
Q: How does integration with MITRE Engenuity Evaluations help?
A: It improves accuracy by incorporating vendor evaluations, ensuring validity against testing.
Threat Intelligence Sources
Q: What does Balbix utilize for threat intelligence?
A: Balbix leverages commercial, government, open source, and proprietary feeds for risk-based prioritization and risk quantification in relation to the global threat landscape.
Q: What is the purpose of the National Vulnerability Database (NVD)?
A: NVD provides standardized data on software vulnerabilities through SCAP, supporting automated vulnerability management and security measurement.
Q: How does the CISA KEV Catalog assist organizations?
A: It helps organizations prioritize remediation by listing actively exploited vulnerabilities and is used to bolster vulnerability management and incident response.
Q: What services does VulDB offer?
A: VulDB provides real-time updates on vulnerabilities, threat actor activities, and risk assessments, integrating cyber threat intelligence to strengthen security posture.
Q: What is the role of the Common Weakness Enumeration (CWE)?
A: CWE categorizes software and hardware weaknesses, providing a standardized language for identifying and mitigating common security flaws.
Q: How is Exploit Database (Exploit-DB) used?
A: Exploit-DB archives publicly disclosed exploits and PoC code, aiding penetration testers and security researchers in understanding how vulnerabilities can be exploited.
Q: What is the Exploit Prediction Scoring System (EPSS)?
A: EPSS estimates the likelihood of a software vulnerability being exploited, providing a probability score for prioritizing remediation efforts.
Q: What is highlighted in the OWASP Top Ten?
A: The OWASP Top Ten outlines the most critical security risks for web applications, serving as a guide for improving application security practices.
Q: What is the Microsoft Active Protections Program (MAPP)?
A: MAPP is a collaboration to share advance vulnerability information, enabling partners to deploy protections ahead of public disclosure.
Understanding MTTR
Q: What is Mean Time to Remediate (MTTR)?
A: Mean Time to Remediate (MTTR) is a metric that measures the average time it takes to permanently fix vulnerabilities from discovery to resolution. It tracks duration until the underlying vulnerability is eliminated, involving actions like applying patches, making configuration changes, and decommissioning systems.
Q: Why is MTTR Important?
A: MTTR is crucial for evaluating vulnerability management effectiveness. It measures fix velocity, risk reduction speed, process efficiency, SLA compliance, resource needs, and prioritization strategy success. It also helps in benchmarking and goal setting.
Q: How is MTTR Calculated?
A: MTTR is calculated by defining scope and period, identifying remediated vulnerabilities, determining relevant timestamps, calculating individual remediation times, and averaging them. It involves measuring time from discovery to confirmed remediation of vulnerabilities.
Q: How does Balbix Help with MTTR?
A: Balbix tracks vulnerability discovery and resolution status, automatically calculates MTTR across scopes and timeframes, and eliminates manual tracking. It provides insights into remediation velocity, process efficiency, and compliance posture.
Understanding MTTP
Q: What is Mean Time to Patch (MTTP)?
A: Mean Time to Patch (MTTP) is a cybersecurity metric focused on the average time it takes for an organization to deploy a security patch, measured from the moment the vulnerability was first detected.
Q: How does Balbix help with MTTP?
A: Balbix integrates vulnerability data with asset information, tracks when vulnerabilities are discovered, and when patches are applied, enabling automatic calculation and tracking of MTTP without manual effort.
Q: Why is MTTP important?
A: Patching eliminates known vulnerabilities. MTTP measures patch management efficiency, highlights bottlenecks, quantifies exposure, assesses response to threats, monitors compliance, informs resource allocation, and benchmarks patch performance.
Q: How is MTTP calculated?
A: MTTP is the average time from when a vulnerability is discovered until the patch is applied. It involves identifying vulnerabilities closed by patching, determining timestamps, calculating patching time, and averaging those times.
Q: How is MTTP interpreted within Balbix?
A: Lower MTTP indicates an efficient patch process. It’s important to track trends, segment analysis, compare with MTTR, and consider patch availability for comprehensive insights.
Trellix Endpoint Security Connector Guide
Q: What does Trellix Endpoint Security provide?
A: It provides hardware, software, and services to investigate cybersecurity attacks, protect against malicious software, and analyze IT security risks.
Q: How does Balbix integrate with Trellix Endpoint Security?
A: It ingests IT Infrastructure assets and associated vulnerabilities discovered by Trellix Endpoint Security.
Q: What does Balbix do with the ingested data?
A: It uses AI to aggregate, normalize, and deduplicate the data, combining it with information from existing IT and cybersecurity tools to create a unified, up-to-date asset inventory view.
Q: What insights does Balbix deliver from the consolidated data?
A: Deployment gap analysis, risk-based vulnerability prioritization with detailed ranking and scoring, and risk quantification.
Q: How do these insights help?
A: They provide a comprehensive risk assessment for individual assets, asset groups, or the entire enterprise, empowering informed and effective security decisions.
Q: What is the integration type for Balbix and Trellix?
A: Fetch: An inbound API integration used to fetch IT Infrastructure assets, associated vulnerabilities, and risk event details.
Q: What types of assets are fetched?
A: Host devices including desktops and laptops.
Q: What types of data are fetched?
A: Asset names, hardware information, interface information, OS information, BIOS information, system information, software information, agent information, risk event information.
Q: What prerequisites are needed to configure the Balbix connector?
A: Create Trellix Endpoint Security API credentials with the appropriate permissions.
Q: What are the steps to get API keys?
A: Access API keys via the Trellix Developer Portal, ensuring the bearer token has tenantId and required scope.
Q: How do you set up access for API?
A: Register a client type, assign scopes, and create an access token using the client credentials grant.
Q: How to set up webhooks for Trellix event feed?
A: Set up a REST endpoint, register with the Trellix event hub, and validate by returning a signed response to a validation request.
Q: What are the steps to create and configure the Balbix connector?
A: Select the connector and configure it by filling required fields and verifying the connection, then schedule the connector.
Qualys Web Application Scanning Connector Guide
Q: What does Qualys Web Application Scanning (WAS) do?
A: It is a cloud-based application security product that discovers, detects, and catalogs web applications and APIs.
Q: How does Balbix integrate with Qualys WAS?
A: Balbix ingests web applications and associated vulnerabilities discovered by Qualys WAS.
Q: What does Balbix leverages to analyze data?
A: Balbix leverages AI to aggregate, normalize, and deduplicate data, creating a unified view of asset inventory and vulnerabilities.
Q: What insights does Balbix's AI provide?
A: It provides deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is the outcome of Balbix's data analysis?
A: A comprehensive assessment of risk, enabling informed and effective security decisions.
Q: What information can the integration table provide?
A: Information about integration type, asset types, and data types fetched by the Balbix connector for Qualys WAS.
Q: What is the Integration Type used by Balbix?
A: An inbound API integration used to fetch web applications and vulnerabilities.
Q: What types of assets are fetched by Balbix?
A: Web applications.
Q: What types of data are fetched?
A: Application name, URL, ID, owner, vulnerabilities information, and relevant timestamps.
Q: What are the prerequisites to configure the Balbix connector?
A: Create Qualys WAS API credentials with the appropriate permissions.
Q: What roles and permissions are required?
A: Manager role with full scope, Reader role with full scope, or non-manager role with API Access and Read Asset permission.
Q: How do you provide permissions and access to all objects in a subscription?
A: Use Qualys administration utility to edit user roles and scopes for full permissions.
Q: How do you enable user access to the API?
A: Click User next to logout, select User Role, and choose API option to enable API access.
Q: What are the steps to create and configure the Balbix connector?
A: Select Data Sources, add a connector, select Qualys WAS, choose API as the Integration Option, and proceed with configuration.
AWS Inspector
Q: What does Amazon Inspector do?
A: It is a vulnerability management service that automatically scans AWS resources for software vulnerabilities and exposures.
Q: What information does the Balbix integration with AWS Inspector ingest?
A: It ingests vulnerability information for EC2 and Lambda AWS resources, focusing on CVEs vulnerability type.
Q: How does Balbix use the ingested data from AWS Inspector?
A: It aggregates, normalizes, and deduplicates the data to provide a unified view, gap analysis, and risk prioritization.
Q: What integration type is used for AWS Inspector in Balbix?
A: Fetch - Inbound API integration to fetch vulnerabilities for cloud assets.
Q: What types of data are fetched by Balbix from AWS Inspector?
A: Asset names, host name, interface information, OS information, software information, vulnerability information specific to CVEs, and remediations.
Q: What prerequisites must be met before setting up the Balbix connector for AWS Inspector?
A: AWS Inspector services must be enabled in the AWS cloud account, and API credentials must be created.
Q: How do you create a role and assign permissions for AWS Inspector integration?
A: Use the IAM Service to create a role, assign a permissions policy, and copy the Role ARN for later use.
Q: What is required when configuring the connector in Balbix?
A: Fill in fields like Instance Name, External ID, Account ID, and AWS Role ARN.
Q: How can you schedule the connector in Balbix?
A: Set the sync frequency to run once or on a recurring schedule over a specified number of days.
Q: What should you do after reviewing the connector configuration details in Balbix?
A: Confirm accuracy, choose to run the connector immediately or save it for future use.
CrowdStrike Falcon Connector Guide
Q: What does CrowdStrike Falcon provide?
A: CrowdStrike Falcon provides next-generation antivirus, endpoint detection and response (EDR), managed threat hunting, and threat intelligence.
Q: What is the Balbix integration with CrowdStrike Falcon?
A: The Balbix integration with CrowdStrike Falcon ingests infrastructure assets, system information, and operational or business data configured by your IT and cybersecurity teams for assets managed by CrowdStrike Falcon.
Q: How does Balbix process CrowdStrike Falcon data?
A: Balbix uses AI to aggregate, normalize, and deduplicate the ingested data from CrowdStrike Falcon along with information from your existing IT and cybersecurity tools, creating a unified view of your entire asset inventory.
Q: What insights does Balbix's AI provide?
A: Deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is required to configure the Balbix connector for CrowdStrike Falcon?
A: Generate a CrowdStrike API client ID and secret for their current set of APIs or legacy APIs, and ensure you have appropriate administrator permissions in the Falcon Administrator role.
Q: How do you generate credentials using current API authentication?
A: Log in to the Falcon Admin panel, go to Support > API Client and Keys, and follow the steps to add a new API client, selecting the appropriate API scopes.
Q: How do you generate credentials using legacy API authentication?
A: Verify account validity, generate a GPG key pair, and contact CrowdStrike Support to request an API key for the Query API.
Q: What steps are required to create and configure the Balbix connector?
A: Select the Connector, configure the Connector, schedule the Connector, and review Connector details.
VMware vCenter Connector Guide
Q: What does VMware vCenter provide?
A: It provides a centralized platform for controlling vSphere environments for visibility across hybrid clouds.
Q: How does Balbix integrate with VMware vCenter?
A: It ingests IT infrastructure assets and inventory discovered by VMware vCenter, aggregating, normalizing, and deduplicating data for a unified asset view.
Q: What insights does Balbix’s AI provide?
A: Ai models analyze data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is the integration type for VMware vCenter?
A: Fetch: An inbound API integration used to fetch IT infrastructure assets and OS information.
Q: What types of assets and data are fetched?
A: Host devices including servers and virtual machines, asset names, interface information, OS information, and relevant timestamps.
Q: What are the prerequisites for configuring the Balbix connector?
A: A VMware vCenter user account with appropriate roles and permissions assigned is required.
Q: How do you create a user in VMware vCenter?
A: Log in with an Admin role, go to Menu > Administration, click Users and Groups, add a user, and assign read-only permissions.
Q: What role is required to fetch local user accounts?
A: A Super Administrator role is required.
Q: How do you select and configure the Balbix connector?
A: Go to Data Sources, select a connector, fill in configuration fields, and test the connection.
Q: Where can you find more information about the VMware vCenter API?
A: VMware vCenter Developer Documentation.
VMware Workspace One UEM Connector Guides
Q: What is VMware Workspace One?
A: VMware Workspace One is a management platform allowing IT administrators to centrally control end users' mobile devices and cloud-hosted virtual desktops and applications from the cloud or an on-premises deployment.
Q: How does Balbix integrate with VMware Workspace One UEM?
A: The Balbix integration with VMware Workspace One UEM ingests IT infrastructure assets and software information, leveraging AI to aggregate, normalize, and deduplicate ingested data to create a unified asset inventory view.
Q: What insights does Balbix provide?
A: Balbix provides insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification for informed and effective security decisions.
Q: What is the integration type for Balbix and VMware Workspace One UEM?
A: It is a Fetch integration, an inbound API integration used to fetch infrastructure assets, users, and software.
Q: What types of assets are fetched?
A: Host devices, including servers, virtual machines, desktops, and laptops, are fetched.
Q: What types of data are fetched?
A: Asset names, hardware information, interface information, OS and BIOS information, system information, user information, timestamps, and tags are fetched.
Q: What are the prerequisites for configuring Balbix with VMware Workspace One UEM?
A: Ensure all prerequisites are met, including having a valid username and password for basic authentication.
Q: How do you create an API key for VMware Workspace One UEM?
A: Log in with an Admin account, navigate to System > Advanced > API > REST API, click +ADD, enter a Service Name, set the Account Type to Admin, and securely save the generated API key.
Q: How is the Balbix connector for VMware Workspace One UEM configured?
A: Select the connector, fill in configuration fields, test the connection, and schedule it.
Q: Where can you find more information about VMware Workspace One UEM APIs?
A: You can refer to the "VMware Workspace One UEM - Get API Credentials" and "VMware Workspace One UEM API Explorer" documents for more details.
Qualys Connector
Q: Can I use only AM or only VMDR?
A: Yes. Simply check the corresponding box for the service(s) you wish to enable.
Q: What happens to my existing AM/VMDR connectors?
A: They will be automatically migrated to the new connector framework. You can continue using them as-is, but we recommend consolidating into a single connector.
Q: Is there any downtime during migration?
A: No. Migrations are seamless and occur in the background.
Tenable Security Center Connector Guide
Q: What is Tenable Security Center?
A: Tenable Security Center is a vulnerability assessment solution that automatically discovers and assesses a customer's environment for vulnerabilities, misconfigurations, and other cybersecurity issues.
Q: How does Balbix integrate with Tenable Security Center?
A: Balbix integrates by ingesting infrastructure assets and associated vulnerabilities discovered by Tenable Security Center, leveraging AI to aggregate, normalize, and deduplicate data.
Q: What insights does Balbix provide after integration?
A: Balbix provides insights such as deployment gap analysis, risk-based vulnerability prioritization with detailed ranking and scoring, and risk quantification.
Q: What types of assets are fetched by the integration?
A: Host devices including servers, virtual machines, desktops, and laptops are fetched.
Q: What types of data are fetched?
A: Data fetched includes asset names, hardware information, interface information, OS information, software information, custom vulnerabilities information, timestamps, and custom vulnerabilities descriptions.
Q: What are the prerequisites for configuring the Balbix connector?
A: You must first create Tenable Security API credentials with the appropriate permissions.
Q: How do you add a user in Tenable Security Center?
A: Click Users > Users, and on the Users page, click Add to view the Add User window, then assign a role.
Q: How do you generate an API Key?
A: On the Users page, select the checkbox next to the user, click API key > Generate Key, and save the API key and secret.
Q: How is the connector configured after prerequisites?
A: Select the connector from Data Sources, fill in the configuration fields, and test the connection.
ServiceNow CMDB Connector Guide
Q: What is ServiceNow’s Configuration Management Database (CMDB)?
A: It enables users to build logical representations of assets, services, and their relationships within an organization's infrastructure.
Q: What does the Balbix integration with ServiceNow CMDB do?
A: It ingests infrastructure assets, basic system information, and operational and business information configured by your IT, business, and cybersecurity teams.
Q: How does Balbix leverage AI in integration?
A: Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, providing a unified view of your entire asset inventory.
Q: What insights does Balbix’s AI provide?
A: It provides deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What type of integration is used in the Balbix integration?
A: A Fetch inbound API integration to get assets and related metadata.
Q: What types of assets are fetched?
A: Infrastructure assets managed as configuration items within ServiceNow CMDB, including computers, firewalls, and more.
Q: What types of data are fetched?
A: Asset names, hardware information, interface information, OS information, operational and business tags.
Q: What is required to configure the Balbix connector?
A: You must create ServiceNow API credentials with the appropriate permissions.
Q: What authentication methods are available?
A: Basic authentication using a username and password, OAuth 2.0, and API Key.
Q: What are the required permissions for the integration?
A: cmdb_read for inbound integration, while ticketing is handled by a separate connector with different permissions.
Q: How do you set up OAuth access?
A: Create a role, grant read access, set up a service account, and create an OAuth application.
Datacenter Connector Guide
Q: What does the Datacenter Connector ingest?
A: It ingests datacenter information and data with fields such as subnet account ID, datacenter name, provider, type, and details.
Q: How does the Datacenter Connector work?
A: It works via file upload and does not have API capabilities.
Q: What details are available from the Connector?
A: Subnet information including datacenter_details, datacenter_owner_email, datacenter_secondary_owner_email, datacenter_account_id, datacenter_provider, datacenter_type, and datacenter_name.
Q: What is the use of the Datacenter Connector?
A: It is primarily used for ingesting data into the datacenter_info table to associate a VM Owner with a cloud asset.
Q: What are the required fields for the Datacenter Connector?
A: Datacenter Account ID, datacenter_type, and datacenter_provider.
Q: How do you activate the Datacenter Connector?
A: To activate this connector, please contact support@balbix.com.
Microsoft Defender Connector Guide
Q: What does Microsoft Defender enable enterprises to do?
A: It enables enterprises to prevent, detect, investigate, and respond to advanced threats.
Q: What does the Balbix integration with Microsoft Defender do?
A: It ingests assets and associated vulnerabilities discovered by Microsoft Defender.
Q: What insights does Balbix provide through its AI models?
A: It provides deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What types of assets does the Balbix integration fetch?
A: It fetches host devices, including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched by the Balbix integration?
A: Asset names, hardware information, interface information, software information, vulnerabilities information, and relevant timestamps.
Q: What are the prerequisites for configuring the Balbix connector?
A: Creating Microsoft Defender API credentials with appropriate permissions is required.
Q: What steps are involved in creating an app registration in MS Entra ID?
A: Log in, select Microsoft Entra ID, add an app registration, enter details, and register.
Q: How do you add API permissions for the Balbix app?
A: Select API Permissions, add permissions from WindowsDefenderATP and Microsoft Graph, and grant admin consent.
Q: What steps are needed to create a custom IAM role in MS Azure?
A: Go to Subscriptions, select a subscription, access control, add a custom role, add permissions, and assign roles.
Q: How is a client secret generated in Microsoft Defender?
A: Go to Microsoft Entra ID, select the Balbix app, create a new client secret, and save it.
Q: What additional functionality does the connector's secure configuration assessments provide?
A: It retrieves assessment status and last observed timestamps for enhanced security posture assessment.
Rapid7 Nexpose On-Prem Connector Guide
Q: What does Rapid7 Nexpose provide?
A: It provides vulnerability assessment for local, remote, cloud, containerized, and virtual infrastructures.
Q: How does Balbix integrate with Rapid7 Nexpose?
A: Balbix ingests IT Infrastructure assets and associated vulnerabilities discovered by Rapid7 Nexpose.
Q: What functionalities does Balbix offer in this integration?
A: It aggregates, normalizes, and deduplicates data, creating a unified view of asset inventory including vulnerabilities and their context.
Q: What insights does Balbix provide from this integration?
A: Deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What types of assets are fetched in the integration?
A: Host devices, including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched in the integration?
A: Asset names, hardware info, interface info, OS info, software info, custom vulnerabilities info, and timestamps.
Q: What prerequisites are needed to configure the Balbix connector?
A: Rapid7 Nexpose API credentials with appropriate permissions.
Q: What steps are involved in creating a new user for the Rapid7 Nexpose API?
A: Log in, manage users, add user, fill details, choose role, select site permissions, specify asset group permissions, save account info.
Q: How do you start configuring the Balbix connector for Rapid7 Nexpose?
A: Select and configure a connector from Data Sources by choosing the Rapid7 Nexpose option.
Q: What information is required to configure the Rapid7 Nexpose connector?
A: Instance name, Nexpose API base URL, username, password, Balbix Data Aggregator Agent, and asset last seen days filter.
Q: Where can you find more information about Rapid7 Nexpose API?
A: Rapid7 Nexpose RESTful API documentation at https://docs.rapid7.com/nexpose/restful-api/
Google Cloud Platform Connector Guide
Q: What services does Google Cloud Platform (GCP) provide?
A: GCP provides an extensive suite of cloud computing services including compute, data storage, data analytics, and machine learning.
Q: What data does Balbix ingest from GCP?
A: Balbix ingests data from GCP services such as Compute, Storage, SQL, GKE Cluster & Deployments, Functions, KMS, Pub/Sub and Secrets Manager.
Q: How does Balbix process ingested data?
A: Balbix aggregates, normalizes, and deduplicates data, integrating it with existing IT and cybersecurity tools for a unified asset inventory view.
Q: What insights does Balbix provide through AI analysis?
A: Balbix provides insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification for effective security decisions.
Q: What is required to configure the Balbix connector for GCP?
A: Create Google Cloud Platform API credentials with appropriate permissions, including a JSON key file to upload in the connector configuration.
Q: How do you select a connector in the Balbix setup?
A: Go to Data Sources, click + Add Connector, select Google Cloud Platform (GCP), and click Next to configure the connector.
Q: What configuration details are needed for the Balbix connector?
A: Required fields include the Instance Name, Org ID, Private Key ID, Client Email, Client ID, and the JSON key file.
Nozomi Networks On-Prem Connector Guide
Q: What is the purpose of the Nozomi Networks and Balbix integration?
A: The integration ingests OT Assets and vulnerabilities discovered by Nozomi, aggregates, normalizes, and deduplicates data to create a unified asset inventory, providing insights such as risk-based vulnerability prioritization.
Q: What types of assets are fetched by the integration?
A: OT assets.
Q: What data does the integration fetch?
A: Asset names, hardware info, interface info, OS info, BIOS info, system info, vulnerabilities info, and timestamps.
Q: What are the prerequisites for configuring the Balbix connector?
A: You must create Nozomi Networks API credentials with the appropriate permissions.
Q: How do you create an API key in Nozomi Networks?
A: Log in, go to Admin > Other Actions, click Edit OpenAPI keys, click +Generate, enter details, and save the key.
Q: What steps are involved in creating and configuring the Balbix connector?
A: Select connector, fill in configuration fields, test connection, schedule connector, and review details.
Cisco Advanced Malware Protection Connector Guide
Q: What does Cisco Advanced Malware Protection (AMP) provide?
A: It provides threat intelligence, sandboxing, and malware blocking to detect, contain, and remove malware.
Q: What does Balbix integration with Cisco AMP do?
A: It ingests infrastructure assets and associated vulnerabilities discovered by Cisco AMP.
Q: How does Balbix use AI in integration with Cisco AMP?
A: Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, creating a unified view of asset inventory with vulnerabilities and their business and operational context.
Q: What insights does Balbix provide using AI models?
A: It provides insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is the integration type for Cisco AMP with Balbix?
A: It is a Fetch integration, an inbound API used to fetch infrastructure assets and vulnerabilities.
Q: What types of assets are fetched by the integration?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched for these assets?
A: Asset names, hardware information, interface information, OS information, software information, and associated vulnerabilities.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Cisco AMP API credentials with the appropriate permissions.
Q: How do you configure API credentials?
A: Log in to your Cisco AMP Console, go to Accounts > Organization Settings, click Configure API Credentials, and generate the client ID and secure API key.
Q: How do you set up your Cisco AMP Connector?
A: After prerequisites, go to Data Sources, click + Add Connector in Connectors table, select Cisco AMP tile, and configure the connector.
XM Cyber Connector Guide
Q: What is XM Cyber?
A: XM Cyber is a breach and attack simulation solution that helps organizations improve their cybersecurity posture by simulating attack scenarios to identify weak defenses and control gaps.
Q: How does Balbix integrate with XM Cyber?
A: The Balbix integration with XM Cyber ingests findings from XM Cyber's attack simulations on IT infrastructure assets and applies them to the applicable assets and vulnerabilities.
Q: What does Balbix leverage AI for?
A: Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, creating a unified view of your entire asset inventory, including vulnerabilities and their context.
Q: What insights does Balbix provide?
A: Balbix provides insights such as deployment gap analysis, risk-based vulnerability prioritization, risk quantification, and a comprehensive assessment of risk.
Q: What is the Integration Type for XM Cyber in Balbix?
A: The integration type is Fetch, an inbound API integration to fetch the simulated attack results and the associated IT infrastructure assets.
Q: What types of assets are fetched with XM Cyber integration?
A: Host devices, including servers, virtual machines, desktops, and laptops, are fetched.
Q: What types of data are fetched?
A: Asset ID, asset name, asset type, interface information, location, OS information, vulnerability information, exploit status, compromised rate, and associated MITRE ATT&CK information.
Q: What is required to configure the Balbix connector?
A: You must create XM Cyber API credentials with the appropriate permissions to configure the Balbix connector.
Q: How do you obtain a JWT access token for XM Cyber?
A: Run a curl command with the specified parameters to generate the JWT access token.
Q: What is the first step to configure the Balbix connector for XM Cyber?
A: Select a connector from the Data Sources and choose XM Cyber to configure it.
Q: How do you specify the XM Cyber API Base URL?
A: Enter the base API URL of the server where the information will be fetched, ensuring the user has necessary privileges.
Q: Where can you find the XM Cyber API reference documentation?
A: The documentation is available in the XM Cloud Deploy API.
Nozomi Networks SaaS Connector Guide
Q: What does Balbix integration with Nozomi Networks achieve?
A: It ingests OT Assets and associated vulnerabilities, leverages AI to aggregate, normalize, and deduplicate data, creating a unified asset inventory view, including vulnerabilities and their business and operational context.
Q: What types of assets does the integration fetch?
A: It fetches IoT and OT assets.
Q: What data types are fetched by the integration?
A: Asset names, hardware information, interface information, OS information, BIOS information, system information, vulnerabilities information, and relevant timestamps.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Nozomi Networks API credentials with appropriate permissions following the outlined steps.
Q: How do you create a user for the connector?
A: Click Users in the admin menu, enter name and email, select the user group, and click Invite.
Q: How do you assign roles and permissions?
A: Assign a role through the admin menu, selecting the appropriate permissions and scope for Vantage.
Q: How do you create an API key in Nozomi Networks?
A: Log in, go to Profile, click API Keys, describe the key, specify IP ranges, select an organization, and click Generate.
Q: What are the key details you need to note down when creating an API key?
A: Note the key name, key token, and allowed IP ranges.
Q: What is the process to create and configure the Balbix connector?
A: Select the connector in Data Sources, configure using the required fields, and test the connection.
Q: Where can you find the API reference documentation for Nozomi Networks?
A: Visit the Nozomi Networks: Configuring API Access for Data Integration Applications and Nozomi Networks Vantage Overview pages.
ServiceNow IT Service Management Connector Guide
Q: What is ServiceNow IT Service Management (ITSM)?
A: ServiceNow ITSM is a cloud-based platform designed to improve IT services, increase user satisfaction, and boost IT flexibility and agility.
Q: How does the Balbix integration with ServiceNow ITSM help?
A: It enables users to create incidents in ServiceNow to drive the efficient remediation of vulnerabilities prioritized by Balbix.
Q: What does Balbix do with the ingested data?
A: Balbix leverages AI to aggregate, normalize, and deduplicate data, providing a unified view of your asset inventory, including vulnerabilities and their contexts.
Q: What insights does Balbix provide from the data?
A: Balbix provides deployment gap analysis, risk-based vulnerability prioritization, and risk quantification to aid in security decision-making.
Q: What is the Integration Type for Balbix and ServiceNow ITSM?
A: It is an outbound API integration to create incidents in ServiceNow ITSM.
Q: What forms of authentication does ServiceNow ITSM support?
A: It supports authentication via Basic, OAuth 2.0, and API Key.
Q: What roles are required for using the Balbix connector with ServiceNow ITSM?
A: Roles required include itil, catalog, catalog_manager, and catalog_editor.
Q: What permissions are needed for connector configuration?
A: sys_user.read permission is required.
Q: What steps are involved in setting up a service account for the connector?
A: Create a role with read access, set up a service account, optionally create an OAuth application, and optionally generate an API key.
Q: How do you test a Balbix connector?
A: Click Test Connection, and review the results which will display Success or Failed based on the configuration.
Q: What is the purpose of mapping fields in connector setup?
A: It maps ServiceNow ITSM API fields to corresponding Balbix fields as part of the configuration process.
Q: How do you schedule the connector?
A: Set the connector sync frequency to either one time or repeat over a chosen number of days.
Q: What should you do after configuring the connector details?
A: Review all the details and decide to run the connector immediately or add it without running for future execution.
Malwarebytes Connector Guide
Q: What is Malwarebytes Endpoint Protection?
A: It is a cloud-based security platform combining detection and remediation technologies into a single cloud-managed agent.
Q: How does Balbix integrate with Malwarebytes?
A: Balbix ingests IT Infrastructure assets and vulnerabilities discovered by Malwarebytes, and uses AI to aggregate, normalize, and deduplicate data to create a unified asset inventory view.
Q: What insights does Balbix provide?
A: It provides deployment gap analysis, risk-based vulnerability prioritization, risk quantification, and a comprehensive assessment of risk.
Q: What is the integration type for the Malwarebytes connector?
A: It is a Fetch integration used to fetch infrastructure assets, OS vulnerabilities, software vulnerabilities, and patch information.
Q: What types of assets are fetched?
A: Host devices, including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched?
A: Asset names, hardware information, interface information, OS information, software information, patch information, system information, compliance and misconfiguration information, and timestamps.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Malwarebytes API credentials with the appropriate permissions.
Q: How do you obtain an access token?
A: Use the Malwarebytes endpoint, requiring a valid client_id and client_secret pair, for authentication.
Q: How do you configure the connector?
A: Select a connector, configure using required fields, schedule, and review connector details.
Q: Where can you find additional API reference documentation?
A: Refer to the Malwarebytes API Doc and Malwarebytes API Authentication links provided.
Broadcom SES Connector Guide
Q: What does Broadcom Symantec Endpoint Security (SES) protect against?
A: It protects laptops, desktops, and servers in your network against malware, risks, and vulnerabilities.
Q: What does the Balbix integration with Broadcom SES do?
A: It ingests IT infrastructure assets, software, and vulnerabilities discovered by Broadcom SES.
Q: How does Balbix leverage AI in its integration?
A: Balbix uses AI to aggregate, normalize, and deduplicate ingested data to create a unified view of your asset inventory.
Q: What insights does Balbix provide through its AI models?
A: Balbix provides deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What integration type is used with the Broadcom SES connector?
A: An inbound API integration is used to fetch infrastructure assets, software, CVE vulnerabilities, and misconfigurations.
Q: What types of assets are fetched by the integration?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched by the integration?
A: Asset names, hardware and interface information, OS and BIOS information, and CVE and custom vulnerability information.
Q: What are the prerequisites for configuring the Balbix connector?
A: First, create Broadcom SES API credentials with the appropriate permissions.
Q: How do you generate OAuth credentials for API access?
A: Add a client application in the Symantec Endpoint Security console and obtain the necessary OAuth credentials.
Q: What are the steps to configure the Balbix connector for Broadcom SES?
A: Select the connector, configure the fields, schedule the connector, and review its details.
ImmuniWeb Connector Guide
Q: What does ImmuniWeb help customers discover and assess?
A: It helps customers discover and assess the security of their entire enterprise attack surface, including Microsoft Azure, AWS, other clouds, on-premises, or from their supply chain.
Q: How does the Balbix integration with ImmuniWeb work?
A: It ingests web applications and associated vulnerabilities to create a unified view of your entire asset inventory, including vulnerabilities and their business and operational context.
Q: What do Balbix's AI models provide?
A: They provide insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What type of integration is used with ImmuniWeb?
A: A Fetch inbound API integration is used to fetch IT infrastructure applications, related CVEs, and custom vulnerabilities.
Q: What types of assets and data are fetched by the Balbix integration?
A: Web applications and data such as Application Name, application URL, CVE information, customer vulnerabilities, and relevant timestamps.
Q: What are the prerequisites for configuring the Balbix connector?
A: You must create ImmuniWeb API credentials with the appropriate permissions.
Q: How do you create an API key in ImmuniWeb?
A: Log in to ImmuniWeb AI Platform, go to the API & ACCESS tab, then the Discovery tab, and click CREATE NEW API KEY.
Cisco Vulnerability Management (formerly Kenna Security) Connector Guide
Q: What does the Cisco Vulnerability Management platform provide?
A: It provides risk scoring, prioritization, and benchmarking.
Q: What does the Balbix integration with Cisco Vulnerability Management involve?
A: It ingests IT infrastructure assets and associated vulnerabilities prioritized by Cisco Vulnerability Management.
Q: How does Balbix handle the data it collects?
A: Balbix aggregates, normalizes, and deduplicates the ingested data along with information integrated from existing IT and cybersecurity tools.
Q: What insights does Balbix provide?
A: Deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What types of assets does the integration fetch?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched by the integration?
A: Asset names, hardware information, interface information, OS information, port information, system information, custom vulnerabilities information, CVE information, and all relevant timestamps.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Cisco Vulnerability Management API credentials with the appropriate permissions.
Q: How can you find the correct API base URL?
A: Examine the subdomain format of your subscription's URL or contact your Cisco/Kenna administrator for assistance.
Q: What is required for API authentication?
A: Include an X-Risk-Token header with all requests using your API token.
Q: What is the process for creating and configuring the Balbix connector?
A: Select the connector, configure it by filling in the required fields, test the connection, and schedule it.
Palo Alto Networks Panorama Connector Guide
Q: What does the Palo Alto Networks Panorama management server provide?
A: It provides centralized monitoring and management of multiple next-generation firewalls and appliance clusters.
Q: What does the Balbix integration with Palo Alto Networks Panorama do?
A: It ingests IT infrastructure assets and leverages AI to aggregate, normalize, and deduplicate data, providing a unified view of asset inventory.
Q: What insights does Balbix provide?
A: It provides deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is the integration type for Balbix with Palo Alto Networks Panorama?
A: Fetch: An inbound API integration used to fetch IT infrastructure assets.
Q: What types of assets are fetched by the integration?
A: Host devices including servers, virtual machines, desktops, laptops.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Palo Alto Networks Panorama API credentials with the appropriate permissions.
Q: What is required for Panorama Domain configuration?
A: The hostname or IP address of the Palo Alto Panorama server or PA Firewall server.
Q: What user role is required to fetch assets?
A: Superuser (read-only) role.
Q: How do you start configuring the Balbix connector?
A: Go to Data Sources from the navigation bar, click + Add Connector, select Palo Alto Networks Panorama, then configure.
Q: What should be filled in the connector configuration fields?
A: Instance Name, Panorama Firewall IP, Panorama Username, and Password.
Kandji Connector Guide
Q: What is Kandji?
A: Kandji is the Apple device management and security platform empowering secure and productive global work.
Q: What does the Balbix integration with Kandji do?
A: It ingests Apple IT infrastructure assets, operating system, and software information discovered by Kandji.
Q: How does Balbix handle the integrated data?
A: Balbix uses AI to aggregate, normalize, and deduplicate ingested data, creating a unified view of the asset inventory with vulnerabilities and their context.
Q: What insights does Balbix provide from the data?
A: Deployment gap analysis, risk-based vulnerability prioritization, and risk quantification for informed security decisions.
Q: What is the integration type for the Kandji connector?
A: Fetch: an inbound API integration used to fetch IT infrastructure assets, OS, and software.
Q: What types of assets does the integration fetch?
A: Host devices including Apple desktops, laptops, personal phones, and tablets.
Q: What types of data are fetched?
A: Asset names, hardware information, interface information, OS information, software information, and system information.
Q: What are prerequisites to configure the Balbix connector?
A: Create Kandji API credentials with appropriate permissions and an API token.
Q: How can you create an API token in Kandji?
A: Log in, navigate to settings, add an API token in the Access tab, and assign necessary permissions.
Q: How do you configure the connector for Balbix?
A: Select a connector, fill required fields, test connection, and schedule it.
Q: What APIs does Balbix use for integration?
A: Kandji API, V1 and Devices API, V1.
Q: Where can you learn about the Kandji API?
A: Refer to the Kandji API documentation and Kandji Support API.
Microsoft Azure Connector Guide
Q: What does the Balbix integration with Microsoft Azure do?
A: It ingests data from core services like Azure VMs, Azure Service Bus, and others to create a unified asset inventory with vulnerabilities and context. Balbix then analyzes this data for insights such as deployment gap analysis and risk prioritization.
Q: What type of integration is used with Microsoft Azure?
A: An inbound API integration to fetch IT cloud assets, misconfigurations, and tags.
Q: What types of assets are fetched by the Balbix connector?
A: Infrastructure cloud resources like virtual machines, databases, containers, serverless functions, and IAM resources.
Q: What types of data are fetched through the integration?
A: Asset names, configurations, hardware, interface and system information, relevant timestamps, and tags.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Microsoft Azure API credentials with necessary permissions, register an app, add API permissions, and create an API key.
Q: How do you register an app in Microsoft Azure for Balbix integration?
A: Log in to the MS Azure portal, select Microsoft Entra ID, add an app registration with relevant information, and save the Application ID and Directory ID.
Q: How do you add API permissions for the Balbix app?
A: On the Balbix App Registration page, select API Permissions, add new permissions, and grant admin consent for Default Directory.
Q: What roles should be assigned for generating an API key?
A: Assign a custom IAM role and the Reader role for the registered Balbix app service.
Q: How do you generate an API key for Balbix from Microsoft Azure?
A: Go to Azure Active Directory, select the Balbix application, navigate to Certificates & secrets, add a new client secret, and save it securely.
Q: How do you configure the Balbix connector?
A: Select a connector, configure with necessary fields like Instance Name, Client ID, Tenant ID, and Client Secret, test the connection, and save the configuration.
VMware Carbon Black Connector Guide
Q: What does VMware Carbon Black provide?
A: VMware Carbon Black offers next-generation anti-virus, endpoint detection and response, advanced threat hunting, and endpoint-focused vulnerability assessment in a single console with a single sensor.
Q: What is the Balbix integration with VMware Carbon Black?
A: Balbix integrates by ingesting IT assets, software, and vulnerability information discovered by VMware Carbon Black to provide a unified view of your asset inventory.
Q: How does Balbix use AI with VMware Carbon Black data?
A: Balbix uses AI to aggregate, normalize, and deduplicate data, analyzing it for deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is required to configure the Balbix connector?
A: You must create VMware Carbon Black API credentials with appropriate permissions, including Devices, Vulnerability Assessment, and User Management.
Q: How do you create API credentials for VMware Carbon Black?
A: Create a custom role, set up an OAuth app, and generate an OAuth App ID and Secret by following the VMware Carbon Black OAuth Access Control documentation.
Q: What types of assets are fetched with VMware Carbon Black?
A: Host devices including servers and virtual machines are fetched.
Q: What types of data are fetched with VMware Carbon Black?
A: Data such as asset names, interface information, operating system, software information, vulnerability information, and timestamps are fetched.
Sophos Connector Guide
Q: What does the Balbix integration with Sophos do?
A: It ingests IT infrastructure assets and associated vulnerabilities information to provide a unified view of your entire asset inventory.
Q: How does Balbix leverage AI in the integration?
A: Balbix uses AI to aggregate, normalize, and deduplicate data, providing insights such as deployment gap analysis and risk-based vulnerability prioritization.
Q: What types of assets can be fetched using the integration?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched with the Balbix connector for Sophos?
A: Asset names, interface information (MAC address, IP address), OS information, software information, user account information.
Q: What are the prerequisites for using the Balbix connector for Sophos?
A: A tenant account and API credentials generated via Sophos Endpoint APIs are required.
Q: How can you generate an API key from Sophos?
A: Sign in to the Sophos Central Admin portal, go to Global Settings, click API Credentials, and create a name for your credentials.
Q: What is the first step in creating and configuring the Balbix connector for Sophos?
A: Go to Data Sources, click + Add Connector, select a connector, click the + icon on the Sophos tile, and configure the connector.
Balbix Subnet Connector Guide
Q: What does the Balbix Subnet connector ingest?
A: It ingests network infrastructure and configuration data from IP Address Management (IPAM) data sources.
Q: Why is asset location information critical?
A: It is critical for comprehensive visibility, effective risk prioritization, remediation, and reporting.
Q: How does Balbix use AI in the process?
A: Balbix uses AI to aggregate, normalize, and deduplicate data to create a unified asset inventory view with insights like deployment gap analysis and risk prioritization.
Q: What is the integration type for the Balbix Subnet connector?
A: The integration type is Fetch, which uses inbound CSV ingestion for subnet IP address, subnet mask, and location information.
Q: What happens if location columns are empty in the CSV file?
A: If the columns are empty, the Balbix Subnet connector uses the location information based on Site-name.
Q: What are the steps to create and configure the Balbix Subnet connector?
A: The steps include selecting the connector, configuring it with required fields, uploading data and configuration files, mapping connector fields, and final review and run.
Tanium Connector Guide
Q: What does Tanium's platform do?
A: It identifies data locations, patches devices, and enforces critical security controls.
Q: How does Balbix integrate with Tanium?
A: It ingests infrastructure assets, system information, software details, vulnerability data, and patch information for assets managed by Tanium.
Q: How does Balbix process Tanium data?
A: Balbix uses AI to aggregate, normalize, and deduplicate the ingested data from Tanium and existing IT and cybersecurity tools.
Q: What insights does Balbix provide?
A: Insights include deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What types of assets does Balbix fetch?
A: Host devices, including servers, virtual machines, desktops, and laptops.
Q: What types of data does Balbix fetch?
A: Asset names, hardware information, CPU information, interface information, OS information, BIOS information, system information, software information, vulnerability information, control assessment information, and patch information.
Q: What prerequisites are needed for the Balbix connector?
A: You must create Tanium API credentials with necessary permissions.
Q: How do you create Tanium API credentials?
A: Create a Tanium user account or persona and generate an API key.
Q: What roles are required for a Tanium user account?
A: Asset Report Reader, Asset API User, Comply Report Reviewer, Gateway User.
Q: How do you generate an API key in Tanium?
A: Log in, go to Administration > Permissions > API Tokens, click New API Token, configure details, and save it.
Q: What is the first step in setting up a Tanium connector?
A: Select the connector in the Data Sources section and add it.
Aqua Security for Cloud Workload Protection Connector Guide
Q: What does Aqua Security Cloud Workload Protection provide?
A: It provides container and cloud native cybersecurity for Docker, Kubernetes, serverless, and other cloud native technologies.
Q: How does the Balbix integration work with Aqua Security Cloud Workload Protection?
A: It ingests infrastructure cloud workloads, containers, clusters, and vulnerabilities discovered by Aqua Security to provide a unified view of asset inventory, vulnerabilities, and context.
Q: What types of assets are fetched through the Balbix integration with Aqua Security?
A: Host devices including servers, virtual machines, cloud containers, active images information.
Q: What types of data are fetched for virtual machines?
A: Asset name, hardware information, interface information, OS information, site information, cloud account ID, cloud asset type, image information, K8s cluster information, compliance information, software information, CVE information, tags.
Q: What data is fetched for clusters through the integration?
A: Cluster name, type, cloud account ID, cloud asset type, native asset type, status, Kubernetes version, platform version, node list.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Aqua API credentials with appropriate permissions, auth permissions, roles, and generate an API key.
Q: What role name is required for creating permissions and roles?
A: The required role name is api_auditor.
Q: How do you generate an API key from Aqua Security?
A: Go to Account Management > Settings > API Keys and click Generate Key to copy and save the API key and secret.
Q: What connectors table step must be completed to set up the Aqua Security connector?
A: Select the connector from the Data Sources section, click + Add Connector, and select Aqua Security.
Q: What is required when configuring the connector's base URL?
A: Enter https://api.cloudsploit.com as the base API URL with necessary user privileges.
Microsoft Intune Connector Guide
Q: What is Microsoft Intune?
A: Microsoft Intune is a cloud-based endpoint management solution for managing and protecting cloud-connected endpoints across various operating systems.
Q: How does Balbix integrate with Microsoft Intune?
A: The Balbix integration ingests IT infrastructure assets and OS information discovered by Microsoft Intune, leveraging AI for data aggregation, normalization, and deduplication to create a unified view of your asset inventory.
Q: What insights does Balbix provide through this integration?
A: Balbix provides insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification to enable informed and effective security decisions.
Q: What types of assets are fetched by the Balbix connector for Microsoft Intune?
A: Host devices including servers, desktops, laptops, smartphones, and tablets.
Q: What types of data are fetched from Microsoft Intune by the Balbix connector?
A: Asset names, hardware information, interface information (MAC address), OS information, and system information.
Q: What are the prerequisites for setting up the Balbix connector with Microsoft Intune?
A: Create Microsoft Intune API credentials with required permissions and access through Microsoft Graph APIs, including application ID and user credential permissions.
Q: How do you register an app in Microsoft Entra for Balbix integration?
A: Sign in to the Microsoft Intune admin center, register the app under the Microsoft Entra ID, and configure necessary permissions and credentials.
Q: What are the steps to add API permissions for the Balbix app?
A: Add permissions on the Balbix App Registration page under Manage > API Permissions, selecting Microsoft Graph and adding relevant scopes.
Q: How do you create a client secret for Balbix application in Microsoft Entra?
A: In Microsoft Entra ID, go to App registrations, select Balbix application, and generate a client secret under Certificates & secrets.
Q: What are the steps for creating and configuring the Balbix connector for Microsoft Intune?
A: Select the connector, configure required fields, test connection, and schedule the connector to fetch asset information.
Rapid7 InsightVM Connector Guide
Q: What does Rapid7 InsightVM provide?
A: It provides vulnerability assessment for local, remote, cloud, containerized, and virtual infrastructures.
Q: How does Balbix integrate with Rapid7 InsightVM?
A: Balbix ingests IT Infrastructure assets and associated vulnerabilities discovered by Rapid7 InsightVM.
Q: What is the result of Balbix's data analysis?
A: It provides insights like deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What types of assets are fetched by the integration?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data does the integration fetch?
A: Asset names, hardware information, interface information, OS information, custom vulnerabilities, and timestamps.
Q: What are the prerequisites for configuring the Balbix connector for Rapid7 InsightVM?
A: You must create Rapid7 InsightVM API credentials with the appropriate permissions.
Q: What is an Organization Key?
A: A powerful key assigned to the entire organization, granting full access to actions across all products.
Q: Who can generate an Organization Key?
A: Only a platform or organization administrator can generate an organization key.
Q: How do you create a User Key in Rapid7 InsightVM?
A: Log in to your Insight account, go to the API Keys page, click New User Key, and save the generated key.
Q: What is the first step to create a Balbix connector for Rapid7 InsightVM?
A: Select the connector by going to Data Sources and expanding the Connectors table.
Cisco Umbrella Connector Guide
Q: What does Cisco Umbrella provide?
A: Cisco Umbrella is a cloud security service that provides DNS-layer security, web security via selective proxy, and application discovery and blocking.
Q: What information does the Balbix integration with Cisco Umbrella ingest?
A: It ingests infrastructure assets, operating system information, and operational/business context for assets managed by Cisco Umbrella.
Q: How does Balbix provide insights into risks?
A: Balbix's AI models analyze data to offer deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is the integration type for Balbix with Cisco Umbrella?
A: It is an inbound API integration used to fetch assets and related metadata such as tags.
Q: What types of assets can be fetched using the Balbix integration?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What data is fetched by Balbix from Cisco Umbrella?
A: Asset names, interface information (MAC address, IP address), OS information, system information, and tags.
Q: What are the prerequisites for configuring the Balbix connector with Cisco Umbrella?
A: You need to create Cisco Umbrella API credentials with appropriate permissions and generate an API key.
Q: How do you generate an API key in Cisco Umbrella?
A: Log in to Cisco Umbrella, go to Admin > API Keys, click Add, enter details, select scopes, choose Read-only, click Create Key, and save the key and secret.
Q: What steps are involved in setting up the Cisco Umbrella connector in Balbix?
A: Select the connector, configure it with necessary fields, schedule it, and review the connector details.
Q: What reference documentation is available for the Cisco Umbrella API?
A: Cisco Cloud Security API: Umbrella API, V2 and other related documentation is available at Cisco's developer site.
Rapid7 Nexpose File-Based Connector Guide
Q: What is Rapid7 Nexpose?
A: Rapid7 Nexpose is an on-premises vulnerability management solution that helps organizations reduce threat exposure by enabling assessment and response around changes in the environment related to vulnerabilities, configurations, and controls.
Q: How does the Balbix integration with Rapid7 Nexpose work?
A: The Balbix integration with Rapid7 Nexpose ingests IT Infrastructure assets and associated vulnerabilities discovered by Rapid7 Nexpose.
Q: What does Balbix leverage for data processing?
A: Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, along with information integrated from your existing IT and cybersecurity tools, creating a unified view of your asset inventory.
Q: What insights does Balbix provide?
A: It provides insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What does the integration type 'Fetch' refer to?
A: An inbound API integration used to fetch IT infrastructure assets, OS information, and associated vulnerabilities.
Q: What types of assets are fetched?
A: Host devices including servers, virtual machines, desktops, laptops, and networking assets.
Q: What types of data are fetched?
A: Asset names, hardware information, interface information, OS information, custom vulnerabilities information, timestamps, and tags.
Q: How do you create and configure the Rapid7 Nexpose connector?
A: By selecting the connector in the Data Sources, choosing File-Based as the Integration Option, configuring the necessary fields, and mapping connector fields.
Q: What is required for the connector setup?
A: Entering configuration fields like Instance Name, Data Source Type, File Encoding, Delimiter, and uploading necessary files.
Q: Where can you find more information on the Rapid7 Nexpose API?
A: Refer to the Rapid7 Nexpose Exports documentation at https://docs.rapid7.com/nexpose/distributing-sharing-and-exporting-reports/
Balbix Flexible Connector
Q: What is the Balbix Flexible Connector?
A: It is a powerful generic connector that can ingest data from nearly any source, enabling new integrations within hours.
Q: What types of information can the connector ingest?
A: It can ingest infrastructure assets, business applications, vulnerabilities, configuration control assessments, and business/operational metadata.
Q: How does the connector handle data ingestion?
A: It is configured to ingest data in a CSV snapshot format, map to appropriate Balbix data fields, and set up the required operational frequency.
Q: What is the integration type for the connector?
A: The integration type is Fetch, which is an inbound CSV ingestion to fetch various data elements.
Q: What types of data are fetched by the Flexible Connector?
A: It fetches infrastructure host assets and business applications.
Q: What is included in infrastructure asset data fetched?
A: Asset names, hardware information, processor info, open port info, location info, and more are included.
Q: What is included in business application data fetched?
A: Application name, URL, ID, owner, vulnerabilities, configuration compliance, and relevant timestamps are included.
Q: What steps are involved in creating and configuring the connector?
A: Steps include selecting the connector, configuring fields, mapping fields, and final review and run.
Orca Security Connector Guide
Q: What does Orca Security provide?
A: Orca Security provides a comprehensive cloud security posture management solution that continuously detects misconfigurations, policy violations, and compliance risks in cloud environments, including cloud-native services.
Q: How does Balbix integrate with Orca Security?
A: Balbix integration with Orca ingests cloud IT infrastructure assets and associated vulnerabilities discovered by Orca Security, leveraging AI for aggregation, normalization, and deduplication to create a unified view of asset inventory.
Q: What insights does Balbix's AI provide?
A: Balbix’s AI models analyze data to provide insights such as deployment gap analysis, risk-based vulnerability prioritization, detailed ranking and scoring, and risk quantification.
Q: What is the outcome of Balbix's risk assessment?
A: It delivers a comprehensive assessment of risk for assets, groups of assets, or the entire enterprise, enabling more informed and effective security decisions.
Q: What is the integration type for the Orca Security connector?
A: The integration type is an inbound API integration used to fetch cloud assets and vulnerabilities.
Q: What types of assets and data are fetched?
A: Host devices including servers and virtual machines are fetched, along with asset name, hardware information, interface information, OS information, system information, software information, CVE information, and process information.
Q: What are the prerequisites for configuring the Balbix connector?
A: You must first create Orca Security API credentials with the appropriate permissions.
Q: How do you create an API token in Orca Security?
A: Log in to your Orca Security Instance, go to Settings > Users & Permissions > API, click Create API Token, enter the required information, choose Viewer from the Role drop-down menu, and click Create Token. Copy and securely save the token information.
Armis Connector Guide
Q: What is Armis?
A: Armis is an agentless device security platform used to help enterprises see and protect unmanaged and IoT devices.
Q: How does Balbix integrate with Armis?
A: Balbix ingests IoT, OT assets, associated software and vulnerabilities information from Armis.
Q: What does Balbix use AI for?
A: Balbix uses AI to aggregate, normalize and deduplicate ingested information, providing a unified view of asset inventory, vulnerabilities, and business and operational context.
Q: What analysis does Balbix provide?
A: Balbix provides deployment gap analysis, risk-based vulnerability prioritization, and risk quantification for assets.
Q: What is the Balbix integration type for Armis?
A: It is a Fetch inbound API integration used to fetch assets, associated software, and vulnerabilities.
Q: What types of assets and data are fetched from Armis?
A: IoT, OT assets, asset names, hardware information, interface information, OS information, software information, system information, and vulnerability information are fetched.
Q: What are the prerequisites for configuring the Balbix connector?
A: You must create Armis API credentials with the appropriate permissions.
Q: How do you obtain an Armis API key?
A: Log in to the Armis management console to obtain an API key, noting fields such as name, value, usage, quota, and expiration.
Q: What steps are involved in setting up the Armis connector?
A: Go to Data Sources, select the connector, configure the connector, schedule it, and review connector details.
Q: Where can I find more information about the Armis API?
A: Refer to the Armis - Explore the API documentation.
Wolken CMDB Connector Guide
Q: What does Wolken CMDB do?
A: It simplifies processes for employees by enabling a data warehouse-like repository storing IT assets and infrastructures.
Q: What is the Balbix integration with Wolken CMDB?
A: It ingests IT infrastructure assets, location, and business tags discovered by Wolken CMDB.
Q: How does Balbix process the data from Wolken CMDB?
A: Balbix uses AI to aggregate, normalize, and deduplicate data to create a unified asset inventory view.
Q: What insights does Balbix provide?
A: It provides deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What type of integration is the Balbix connector?
A: It is an inbound API integration used to fetch IT infrastructure assets and related tags.
Q: What types of assets are fetched by Balbix?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched?
A: Asset names, hardware information, interface information, OS information, system information, timestamps, location info, and tags.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Wolken CMDB API credentials with the appropriate permissions.
Trend Micro Apex One™ Connector Guide
Q: What is Trend Micro Apex One™?
A: It is an endpoint security solution protecting against malware, scripts, injection, ransomware, memory and browser attacks, and exploits.
Q: What does the Balbix integration with Trend Micro Apex One do?
A: It ingests IT infrastructure assets information discovered by Trend Micro Apex One.
Q: How does Balbix process integrated data?
A: Balbix uses AI to aggregate, normalize, and deduplicate ingested data to create a unified view of your entire asset inventory, assessing risk and enabling informed security decisions.
Q: What types of assets does the Balbix integration fetch?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched?
A: Asset names and interface information like MAC addresses and IP addresses.
Q: What prerequisites are required before creating a Balbix connector?
A: Authenticate to your Trend Micro Apex One account with valid credentials.
Q: What is the first step to configure the Balbix connector?
A: Select the Connector from the Data Sources in the left navigation bar and choose the Trend Micro Apex One Endpoint Security tile.
Q: What information is needed to configure the Trend Micro Apex One connector?
A: Instance Name, Base URL, Application ID, and API Key.
Q: What is the purpose of the Test Connection step?
A: To verify the connector configuration before proceeding.
Q: Where can you find more information about the Trend Micro Apex One API?
A: Visit the Trend Micro Apex One Online Help Center at the provided URL.
Palo Alto Networks Cortex XDR Connector Guide
Q: What is Palo Alto Networks Cortex XDR?
A: It is an extended detection and response platform that provides agent-based endpoint protection, behavior-based threat detection, and rapid threat investigation for root cause analysis and response.
Q: What does Balbix integration with PAN Cortex XDR do?
A: It ingests IT infrastructure assets, software, and user information for endpoints protected by Cortex XDR and leverages AI to aggregate, normalize, and deduplicate data.
Q: What insights does Balbix provide?
A: Deployment gap analysis, risk-based vulnerability prioritization, risk quantification, and a comprehensive assessment of risk for single assets, groups, or the entire enterprise.
Q: What types of assets are fetched by the integration?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched?
A: Asset names, hardware information, interface information, OS and software information, patch information, and user account information.
Q: What are the prerequisites for configuring the Balbix connector?
A: You must create Palo Alto Networks Cortex XDR API credentials with appropriate permissions.
Q: How do you create an API Key in Cortex XDR?
A: Go to Configurations > Integrations > API Keys, click + New Key, choose Standard as the security level, select a role with endpoint management permission, and generate the key.
Q: How do you get the FQDN?
A: Obtain it from the API Keys table by clicking on your API key and then clicking Copy URL.
Q: What are the steps to create and configure the Balbix connector?
A: Go to Data Sources, add a connector, select Palo Alto Networks Cortex XDR, choose API as the Integration Option, and fill in the required configuration fields.
Black Kite Connector Guide
Q: What does Black Kite provide?
A: Black Kite provides external cyber risk assessments analyzing the organization's supply chain cybersecurity posture from technical, financial, and compliance dimensions.
Q: What does Balbix do with data from Black Kite?
A: Balbix integrates data to create a unified asset inventory view and analyzes it using AI for insights like deployment gap analysis and risk-based vulnerability prioritization.
Q: What is the integration type for Balbix with Black Kite?
A: The integration type is 'Fetch', an inbound API integration to retrieve IT infrastructure domains, assets, and associated vulnerability information.
Q: What types of assets does Balbix fetch?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What data types are fetched by Balbix from Black Kite?
A: Asset names, location, interface information, vulnerabilities, and relevant timestamps, such as first and last observed.
Q: What are the prerequisites for configuring the Balbix connector?
A: Generate a Black Kite client ID and client secret.
Q: How do you start setting up the Black Kite connector?
A: Go to Data Sources, click '+ Add Connector', and select a Black Kite connector from the list.
Q: What information is needed to configure the Black Kite API in Balbix?
A: Base API URL, Black Kite client ID, client secret, and company domain name.
Q: Where can you find more information about the Black Kite API?
A: On the Black Kite API documentation page at https://app.blackkitetech.com/ApiDocs/v2/swagger/.
Lacework Connector Guide
Q: What does the integration between Balbix and Lacework involve?
A: It involves ingesting assets, software, and vulnerabilities information discovered by Lacework to create a unified asset inventory with vulnerabilities and their context.
Q: How does Balbix use AI in the integration?
A: Balbix uses AI to aggregate, normalize, and deduplicate data, providing insights like deployment gap analysis and risk-based vulnerability prioritization.
Q: What types of assets does the Balbix integration fetch?
A: It fetches host devices, including servers, virtual machines, and containers.
Q: What data does the integration fetch?
A: Asset names, hardware, interface information, OS information, software, and vulnerabilities.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Lacework API credentials with appropriate permissions.
Q: How is an API key generated in Lacework?
A: Go to Settings > Configuration > API keys, select the tab, add a key, enter a name, toggle service user, and save.
Q: What happens if the API key creator's role changes?
A: If an administrator creator is downgraded, the API key won't work for tokens or API access.
Q: What are the steps after prerequisites for configuring the connector?
A: Select, configure, schedule the connector, and review details using outlined steps.
Q: Where can I find more information on Lacework API?
A: Refer to Lacework API 2.0 Documentation and Access Control Overview.
Device42 Connector Guide
Q: What is Device42?
A: Device42 is a cloud-based CMDB that maps relationships and dependencies for physical and virtual machines, cloud servers and containers, network components, software, services, and applications.
Q: What does the Balbix integration with Device42 provide?
A: The Balbix integration ingests IT infrastructure assets and software information to create a unified view of your entire asset inventory, including vulnerabilities and their business and operational context.
Q: How does Balbix analyze data from Device42?
A: Balbix uses AI to aggregate, normalize, and deduplicate data, providing insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is the purpose of Balbix's risk assessment?
A: It delivers a comprehensive assessment of risk, enabling more informed and effective security decisions.
Q: What types of assets does the integration fetch?
A: It fetches host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched by the integration?
A: Asset names, software information, and relevant timestamps are fetched.
Q: What are the prerequisites to configure the Balbix connector?
A: You must first create Device42 API credentials with the appropriate permissions.
Q: How do you access the Device42 API?
A: Access is possible through either basic authentication with a username and password or OAuth 2.0 using an OAuth provider and profile.
Q: What are the steps to select the connector?
A: Go to Data Sources from the navigation bar, click + Add Connector, select a connector to configure, and choose API as the integration option.
Q: What are the steps to configure the connector using OAuth?
A: Fill in the required fields to authenticate using OAuth client credentials, including the instance name and Device42 API base URL.
Q: How is the connector configured using basic authentication?
A: Fill in the fields using a username and password, including the instance name, Device42 API base URL, and API key.
Q: Where can you find API reference documentation for Device42?
A: API reference documentation is available at the Device42 API website.
Trend Micro Cloud One™ Workload Security Connector Guide
Q: What does Balbix integrate with?
A: It integrates with Trend Micro Cloud One™ Workload Security to ingest IT infrastructure assets and associated vulnerabilities.
Q: How does Balbix process data?
A: It aggregates, normalizes, and deduplicates ingested data, providing a unified view of the asset inventory and analyzing data for insights such as deployment gap analysis and risk-based vulnerability prioritization.
Q: What is required to configure the Balbix connector?
A: You must create Trend Micro Cloud One Workload Security API credentials with appropriate permissions.
Q: How can you create an API key in Trend Micro Cloud One?
A: Sign in to Trend Micro Cloud One, navigate to Administration, and create an API key specifying the Alias, Description, Role, Language, and Timezone.
Q: What types of assets and data does the integration fetch?
A: It fetches host devices like servers and virtual machines, and data such as asset names, IP address information, OS, agent details, and CVE information.
Wiz Connector Guide
Q: What is Wiz?
A: Wiz is a cloud security platform that detects and remediates misconfigurations from build time to runtime across hybrid cloud environments.
Q: How does Wiz provide a comprehensive view of cloud environments?
A: Wiz leverages native cloud APIs and services to identify vulnerabilities and threats in real time.
Q: How does Balbix integrate with Wiz?
A: Balbix ingests cloud infrastructure assets, associated vulnerabilities, software entities, and operational/business information configured by your IT and cybersecurity teams.
Q: What does Balbix's AI do with Wiz data?
A: Balbix uses AI to aggregate, normalize, and deduplicate the data, creating a unified view of your entire asset inventory.
Q: What insights does Balbix provide with AI models?
A: Balbix delivers insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What type of integration is used for the Wiz connector?
A: Fetch, an inbound API integration used to retrieve assets and their related metadata.
Q: What data is fetched by the Wiz connector?
A: Asset names, interface information, OS information, associated tags, software details, vulnerabilities, and timestamps.
Q: What are the prerequisites for setting up the Balbix connector for Wiz?
A: You must create Wiz API credentials with necessary permissions.
Q: What steps are required to create Wiz API credentials?
A: Get the Wiz API URL, client ID, and secret by logging in, navigating to user settings, and setting up a service account.
Q: What are the rate limits for the Wiz REST API?
A: The limit is 50 requests per minute for most endpoints, with some having 10 requests per minute.
Q: What should you do if you encounter rate limit issues?
A: Balbix manages rate limits by pausing and retrying API calls; for assistance, contact support@balbix.com.
Q: Where can you find Wiz API documentation?
A: See the Wiz API Overview on their support site.
RiskIQ Connector Guide
Q: What does RiskIQ help customers do?
A: It helps customers discover and assess the security of their entire enterprise attack surface in various environments including Microsoft Azure, AWS, and on-premises.
Q: What does the Balbix integration with RiskIQ do?
A: It ingests IT infrastructure assets and associated vulnerabilities discovered by RiskIQ.
Q: How does Balbix leverage AI in the integration with RiskIQ?
A: It aggregates, normalizes, and deduplicates ingested data to create a unified view of the entire asset inventory, including vulnerabilities and business context.
Q: What insights does Balbix's AI provide?
A: Deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is the integration type for Balbix's integration with RiskIQ?
A: Fetch: An inbound API integration used to fetch IT infrastructure assets and associated CVEs.
Q: What types of assets are fetched in the integration?
A: Host devices including servers, virtual machines, desktops, laptops.
Q: What types of data are fetched in the integration?
A: Asset name, interface information, OS information, open port information, software information, location information, vulnerabilities, and timestamps.
Q: What are the prerequisites for configuring the Balbix connector with RiskIQ?
A: Creating RiskIQ API credentials with appropriate permissions and registering for a RiskIQ Community account.
Q: What should you do if the RiskIQ API does not respond?
A: Consider starting a 30-day trial of RiskIQ’s product for enhanced data access.
CrowdStrike Connector Guide
Q: What security features does CrowdStrike provide?
A: CrowdStrike provides next-generation antivirus, endpoint detection and response (EDR), managed threat hunting, and threat intelligence.
Q: What type of management does CrowdStrike offer?
A: CrowdStrike offers vulnerability management through a single agent for both endpoint security and vulnerability management.
Q: What data does the Balbix integration with CrowdStrike ingest?
A: It ingests key data including infrastructure assets, system information, vulnerabilities, affected software details, and operational/business information configured by IT and cybersecurity teams for assets managed by CrowdStrike.
Q: How does Balbix process CrowdStrike data?
A: Balbix leverages AI to aggregate, normalize, and deduplicate ingested data from CrowdStrike and other IT and cybersecurity tools to create a unified view of your asset inventory.
Q: What insights do Balbix’s AI models provide using CrowdStrike data?
A: They provide deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is the integration type for the Balbix integration with CrowdStrike?
A: Fetch, an inbound API integration used to fetch assets, vulnerabilities, and related metadata such as tags.
Q: What types of assets are fetched by the Balbix integration?
A: Host devices, including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched by Balbix integration?
A: Asset names, hardware information, interface information, OS information, BIOS information, system information, all relevant timestamps, CVE ID and exploit status, affected software product names, tags, and CrowdStrike agent version.
Q: What are the prerequisites for configuring the Balbix connector for CrowdStrike?
A: You must create CrowdStrike API credentials with appropriate permissions to configure the Balbix connector.
Q: How do you request an API key from CrowdStrike?
A: Generate a GPG key pair, send the public key to support@crowdstrike.com, request access to the Query API, receive encrypted credentials, and decrypt using your private GPG key.
Tenable Vulnerability Management Connector Guide
Q: What is Tenable Vulnerability Management?
A: It is a vulnerability assessment solution that automatically discovers and evaluates an organization’s environment for vulnerabilities, misconfigurations, and other cybersecurity issues.
Q: What does the Balbix integration with Tenable Vulnerability Management ingest?
A: It ingests on-premises and cloud infrastructure assets, associated vulnerabilities, software entities, configured operational or business data, and controls assessment information.
Q: How does Balbix process Tenable data?
A: Balbix uses AI to aggregate, normalize, and deduplicate the ingested data from Tenable, along with information from existing IT and cybersecurity tools, creating a unified view of the entire asset inventory.
Q: What insights does Balbix’s AI provide?
A: Deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What is the Integration Type for the Balbix-Tenable connector?
A: Fetch: An inbound API integration used to fetch assets, vulnerabilities, and related metadata.
Q: What types of assets are fetched through the integration?
A: Infrastructure devices such as servers, virtual machines, desktops, laptops, networking, and IoT.
Q: What types of data does the integration fetch?
A: Asset names, DNS, hardware information, CPU information, open port information, location information, interface information, OS information, BIOS information, tags, software information, system status, vulnerabilities, timestamps, and control assessment findings.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Tenable Vulnerability Management API credentials with appropriate permissions, including basic role with view access to Assets and view, export access to Vulnerabilities.
Q: How do you set up access to the Tenable Cloud Security API?
A: Verify you have a valid user account with appropriate permissions, then generate the API keys for the account.
Q: How can you generate an API key for Tenable Cloud Security?
A: Log in to the Tenable Cloud Security portal, navigate to the API Keys tab, click Generate, and securely save the keys for use with the Balbix connector.
Q: What is the workflow to set up the Tenable VM connector?
A: Select the connector, configure it by filling in required fields, schedule the connector, and review the connector details.
Q: Are there any rate limits for this connector?
A: There are no rate limits for this connector.
Cymulate Connector Guide
Q: What is Cymulate?
A: Cymulate is a breach and attack simulation (BAS) solution that helps organizations improve their cybersecurity posture by simulating attack test cases to identify weak defenses and control gaps.
Q: How does the Balbix integration with Cymulate work?
A: It ingests findings from Cymulate's attack simulations on IT infrastructure and applies them to the applicable assets and vulnerabilities, supporting the Cymulate Endpoint Security module.
Q: What does Balbix leverage AI for?
A: To aggregate, normalize, and deduplicate ingested data, creating a unified view of the entire asset inventory including vulnerabilities, business, and operational context.
Q: What insights does Balbix provide?
A: Insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification for informed and effective security decisions.
Q: What is the Integration Type for Balbix with Cymulate?
A: Fetch: An inbound API integration used to fetch simulated attack results and associated IT infrastructure assets.
Q: What types of assets does the integration fetch?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched in the integration?
A: Simulated attack results with associated assets including asset ID, name, tags, OS information, risk, vulnerabilities, status, test case details, and MITRE ATT&CK information.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Cymulate API credentials with appropriate permissions and obtain the API key associated with a user account authorized to fetch assets.
Q: How do you create and configure the Balbix connector for Cymulate?
A: Select a connector, fill in the required configuration fields, and ensure the connection is tested and scheduled according to outlined steps.
Blackberry CylanceENDPOINT Connector Guide
Q: What is CylanceENDPOINT by Blackberry?
A: It is a self-defending, operationally efficient endpoint protection platform that uses Cylance AI to simplify investigation and response.
Q: What does the Balbix integration with CylanceENDPOINT do?
A: It ingests infrastructure assets and associated vulnerabilities discovered by CylanceENDPOINT.
Q: How does Balbix enhance data from CylanceENDPOINT?
A: Balbix aggregates, normalizes, and deduplicates data with information from existing IT and cybersecurity tools, creating a unified view of assets and vulnerabilities.
Q: What insights do Balbix’s AI models provide?
A: They analyze data to offer deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What types of assets does the integration fetch?
A: Host devices including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched by the integration?
A: Asset names, hardware information, interface information, OS information, system information, vulnerability information, and relevant timestamps.
Q: What is required to configure the Balbix connector?
A: You must create CylanceENDPOINT API credentials with appropriate permissions.
Q: How do you create an application ID and secret for Balbix?
A: Log in to the CylanceENDPOINT console, add an application, specify a name, check 'Read' boxes, save the ID and secret.
Q: How do you configure the Balbix connector after prerequisites?
A: Select and configure the connector, fill in required fields, test connection, and schedule the connector.
Q: Where can you find more information on the CylanceENDPOINT API?
A: See the CylanceENDPOINT API reference documentation at the provided link.
Jamf Pro Connector Guide
Q: What is Jamf Pro?
A: Jamf Pro is an enterprise mobility management (EMM) tool that provides unified endpoint management for Apple devices.
Q: What does the Balbix integration with Jamf Pro do?
A: It ingests assets, software and patch information for Apple devices discovered by Jamf Pro.
Q: How does Balbix use AI with Jamf Pro data?
A: Balbix leverages AI to aggregate, normalize, and deduplicate ingested data, creating a unified view of your entire asset inventory including vulnerabilities.
Q: What insights can Balbix's AI models provide?
A: Deployment gap analysis, risk-based vulnerability prioritization with detailed ranking and scoring, and risk quantification.
Q: What is the benefit of Balbix's AI analysis?
A: It delivers a comprehensive assessment of risk, enabling more informed and effective security decisions.
Q: What types of assets does the integration fetch?
A: Host devices including Apple desktops and laptops.
Q: What types of data are fetched?
A: Asset names, hardware information, interface information, OS information, software information, system and patch information, timestamps.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Jamf Pro API credentials with the appropriate permissions.
Q: How do you create a user account in Jamf Pro?
A: Log in to the Jamf Pro admin panel, go to Settings, select Jamf Pro User Accounts & Groups, create a new user with Full Access and appropriate privileges.
SentinelOne Connector Guide
Q: What is SentinelOne's primary function?
A: SentinelOne is an endpoint protection solution that prevents, detects, and responds to attacks across all major vectors.
Q: What does the Balbix integration with SentinelOne do?
A: It ingests IT infrastructure assets and software vulnerabilities discovered by SentinelOne.
Q: How does Balbix leverage AI in the integration?
A: Balbix uses AI to aggregate, normalize, and deduplicate ingested data and integrate it with existing IT and cybersecurity tools.
Q: What insights does Balbix provide through its AI models?
A: Balbix provides deployment gap analysis, risk-based vulnerability prioritization with detailed ranking and scoring, and risk quantification.
Q: What is the outcome of Balbix's analysis?
A: It delivers a comprehensive assessment of risk for assets or enterprises, enabling more informed and effective security decisions.
Q: What is the integration type for the Balbix SentinelOne connector?
A: Fetch: An inbound API integration used to fetch IT infrastructure assets and software vulnerabilities.
Q: What types of assets does the connector fetch?
A: Host devices, including servers, virtual machines, desktops, and laptops.
Q: What types of data are fetched by the connector?
A: Asset names, hardware information, interface information, OS information, BIOS information, system information, software information, vulnerability information, user information, and all relevant timestamps.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create SentinelOne API credentials with necessary permissions.
Q: How do you create an API token from SentinelOne?
A: Log in to the console, go to My User, and generate an API token under API Token Operations.
Q: How do you configure the Balbix connector?
A: Select a connector, add configuration details like instance name and base URL, and enter the API key and filters.
Q: Where can you find more about the SentinelOne API?
A: Visit the SentinelOne API reference documentation on their website.
Amazon Web Services (AWS) Connector Guide
Q: What is Amazon Web Services (AWS)?
A: AWS is a comprehensive and broadly adopted public cloud platform that allows users to deploy virtual machines and networks and access over 200 native AWS services.
Q: How does the Balbix integration with AWS work?
A: It ingests data from core AWS services such as EC2, S3, and IAM, along with database, container, and analytics services, to provide a unified view of your asset inventory.
Q: What insights does Balbix's AI provide?
A: It offers deployment gap analysis, risk-based vulnerability prioritization, and risk quantification to ensure comprehensive risk assessment.
Q: What type of integration does Balbix use for AWS?
A: An inbound API integration used to fetch cloud assets, misconfigurations, and tags.
Q: What types of assets and data does Balbix fetch?
A: It fetches infrastructure cloud resources and data such as asset names, configurations, hardware information, OS information, system information, and tags.
Q: What prerequisites are required for configuring the Balbix AWS connector?
A: Creating AWS API credentials with appropriate permissions is necessary to complete the configuration.
Q: What are the key steps for creating a role for AWS access?
A: Create a role, assign permissions, and securely store the Role ARN for configuring the Balbix connector.
Q: What are the steps for setting up the AWS connector once prerequisites are complete?
A: Select the connector, configure it, schedule it, and review the connector details.
Qualys Policy Compliance Connector Guide
Q: What is Qualys Policy Compliance?
A: A cloud service performing automated security configuration assessments on IT systems on-premises, remote, or in the cloud.
Q: What does the Balbix integration with Qualys Policy Compliance do?
A: It ingests IT system security configurations discovered by Qualys Policy Compliance for risk analysis.
Q: How does Balbix process data from Qualys?
A: Balbix leverages AI to aggregate, normalize, and deduplicate data, creating a unified asset inventory view.
Q: What insights does Balbix provide?
A: Deployment gap analysis, risk-based vulnerability prioritization, and risk quantification for informed security decisions.
Q: What types of assets does the integration fetch?
A: Infrastructure devices like servers, virtual machines, desktops, laptops, networking, and IoT.
Q: What data is fetched by the integration?
A: Asset names, interface info (MAC/IP), controls assessment info, policy info, posture info, and relevant timestamps.
Q: What is required to configure the Balbix connector?
A: A Qualys Policy Compliance user account with appropriate roles and permissions.
Q: What roles/permissions are needed?
A: Manager, Reader roles with full scope, or Non-manager with specific API and Read Asset permissions.
Q: How do you provide permissions in Qualys?
A: Select Users > User Management in Qualys, edit user roles, and enable full permissions and scope.
Q: How is user access to the API enabled?
A: In Qualys, go to User > User Profile, select User Role, choose API option, then save.
Q: What is step one to configure the connector?
A: Select a connector from Data Sources, add and choose the Qualys Compliance tile, then proceed to configure.
Q: How is the connector configured?
A: Fill in configuration fields: Instance Name, Qualys VMDR Inventory and Vulnerability Base URLs, Username, and Password.
Q: What documentation is available for more info?
A: Several Qualys API documents including Quick Reference, User Guides, and Documentation for Vulnerability Management and Policy Compliance.
Balbix Forwarder Connector Guide
Q: What is the Balbix Forwarder?
A: The Balbix Forwarder enables secure communication between Balbix Host Analyzer agents and the Balbix Cloud in restricted internet environments.
Q: How does the Forwarder operate?
A: It runs on a Balbix Data Aggregator in Direct Access mode and securely forwards data from internal environments to the cloud.
Q: Is the Forwarder available in Proxy mode?
A: No, it is only supported in Direct Access deployments.
Q: How does Balbix use data from the Forwarder?
A: Balbix aggregates, analyzes using AI models, and enriches endpoint asset data with contextual business and operational data.
Q: What are the benefits of using Forwarder data?
A: Coverage analysis, risk-based vulnerability prioritization, asset-level and group-level risk quantification, and endpoint visibility in isolated environments.
Q: What integration type does the Forwarder use?
A: Internal data bridge from Host Analyzer agents via Data Aggregator.
Q: Which assets are supported by the Forwarder?
A: Windows and Linux endpoints running Balbix Host Analyzer.
Q: What kind of data does the Forwarder fetch?
A: OS, hardware, network interfaces, tags, agent versions, timestamps.
Q: What are the communication requirements for the Forwarder?
A: HA to DA (port 8443), DA to Balbix Cloud (port 443).
Q: What prerequisites are needed for the Forwarder?
A: DA must be installed in Direct Access mode, with open ports 2181 and 8443, and access to Balbix Dashboard with connector permissions.
Q: How do you create the Forwarder connector?
A: Log in to the Balbix Dashboard, navigate to Data Sources → Connectors, add a new connector, select Balbix Forwarder, and configure the settings.
Q: What configuration is required for the connector?
A: Instance Name, Data Aggregator Agent, and connector schedule must be configured and saved.
Nexthink Connector Guide
Q: What insights does Nexthink provide?
A: Nexthink provides insights into activity across devices, operating systems, and workplace locations to improve IT experiences for employees.
Q: What does the Balbix integration with Nexthink involve?
A: The integration ingests IT infrastructure assets, software, and application information discovered by Nexthink.
Q: How does Balbix process the ingested data?
A: Balbix leverages AI to aggregate, normalize, and deduplicate data, creating a unified asset inventory view that includes vulnerabilities and their business and operational context.
Q: What insights does Balbix provide?
A: Balbix provides insights such as deployment gap analysis, risk-based vulnerability prioritization, and risk quantification.
Q: What types of assets and data does Balbix fetch?
A: Balbix fetches host devices, including desktops and laptops, and data like asset names, hardware info, and OS information.
Q: What are the prerequisites for configuring the Balbix connector?
A: You must create Nexthink API credentials with appropriate permissions for configuration.
Q: What API access is required for Nexthink integration?
A: Accounts with Data Privacy set to None and Finder Access enabled can use the NXQL API.
Q: What is the default port for connecting to the NXQL API?
A: The default port is 1671 for on-premises engines and 443 for Nexthink Cloud engines.
Flexera Connector Guide
Q: What does Balbix integration with Flexera provide?
A: It ingests IT infrastructure assets and software information discovered by Flexera, creating a unified view of your asset inventory, including vulnerabilities.
Q: How does Balbix leverage AI?
A: Balbix uses AI to aggregate, normalize, and deduplicate ingested data, then analyzes it to provide insights like deployment gap analysis and risk-based vulnerability prioritization.
Q: What types of assets are fetched by the Flexera connector?
A: Host devices including desktops and laptops.
Q: What types of data are fetched?
A: Asset names, hardware information, interface information, OS information, system information, and software information.
Q: What are the prerequisites for configuring the Balbix connector?
A: You must create Flexera API credentials with the appropriate permissions.
Q: How do API requests handle authentication?
A: All API requests require authentication using an access token obtained from Flexera IAM.
Q: What steps are involved in creating and configuring the Balbix connector?
A: Select the connector, configure it by filling in required fields, schedule the connector, and review connector details.
Jira Ticketing Connector Guide
Q: What is Jira Ticketing designed for?
A: It is a cloud-based platform designed to improve IT services, increase user satisfaction, and boost IT flexibility and agility.
Q: How does Balbix integrate with Jira Ticketing?
A: It allows users to create incidents in their Jira instance, whether on-premises or cloud-based, to efficiently remediate vulnerabilities prioritized by Balbix.
Q: What does Balbix leverage AI for?
A: To aggregate, normalize, and deduplicate ingested data, creating a unified view of the entire asset inventory, including vulnerabilities and their business and operational context.
Q: What insights are provided by Balbix’s AI models?
A: Deployment gap analysis, risk-based vulnerability prioritization with detailed ranking and scoring, and risk quantification.
Q: How does Balbix benefit security decisions?
A: By delivering a comprehensive assessment of risk for informed and effective security decisions.
Q: What is the integration summary for Jira Ticketing?
A: An outbound API integration used to create incidents within Jira Ticketing.
Q: What fields are included in Types of Incidents?
A: Project, issue type, component, assignee, reporter, labels, description, summary.
Q: What are the prerequisites for configuring the Balbix connector?
A: Create Jira Ticketing API credentials with appropriate permissions.
Q: What is required for authentication with the On-Premises Instance Type?
A: Generate personal access tokens.
Q: How is a Cloud Instance Type authenticated?
A: Create a unique API token for each user.
Q: What should be done after completing the prerequisites?
A: Follow the steps to create and configure the Balbix connector for Jira Ticketing.
Q: What should be configured for the connector using the Cloud Auth Type?
A: Fill in the configuration fields, including Instance Name, Jira Base URL, auth type, API token, and username.
Q: Where can you find more information on Jira Ticketing API?
A: Documentation on Atlassian's site, including API reference links.
Asset Types Widget
Q: What does the Asset Types widget display?
A: The Asset Types widget displays the distribution of assets across various categories in your environment, such as desktops, servers, IoT devices, and cloud infrastructure.
Q: How does the Asset Types widget help in understanding assets?
A: It gives you a clear view of the composition of your asset inventory, helping you understand the nature and diversity of the systems you need to protect.
Software Inventory Widget
Q: What does the Software Inventory widget provide?
A: It provides a ranked list of the most commonly detected software applications across your environment, including software names and the number of instances found.
Q: How does the Software Inventory widget help with tracking?
A: It gives you a clear view of your software landscape and distribution at scale, critical for managing vulnerabilities, licenses, and configuration drift.
Q: What initiatives does this view support?
A: It supports software governance and standardization initiatives, helping detect unauthorized software and enforce baselines.
Q: What can you achieve with this widget during audits?
A: It offers a fast and actionable overview of your software footprint for security, compliance, or operational efficiency audits.
Assets by Owner Widget
Q: What does the Assets by Owner widget display?
A: It displays how assets are distributed across business owners in your organization, listing each owner along with the total number of assets they are responsible for.
Q: Why is the Assets by Owner widget useful?
A: It provides visibility into ownership at scale, allowing you to align asset management and security accountability with organizational roles.
Q: How can you use the Assets by Owner widget effectively?
A: You can identify which individuals or teams manage the largest portions of your asset inventory, aiding in remediation, enforcing controls, and directing communication and follow-up efforts.
Q: What might high asset counts indicate?
A: They may indicate a need for additional support or segmentation of ownership.
Asset Coverage Widget
Q: What does the Asset Coverage widget show?
A: It shows how many assets are being discovered or reported by each integrated data source.
Q: How can the Asset Coverage widget help?
A: By comparing asset counts across sources, it helps verify inventory completeness and meaningful tool contribution to visibility.
Q: What might a significant discrepancy between sources indicate?
A: It may indicate integration issues, misconfigured connectors, or blind spots in your environment.
Q: How can this widget validate the effectiveness of your asset discovery pipeline?
A: If one source identifies most assets while others show minimal contribution, it may reveal reliance on a single tool or a gap in coverage strategy.
Q: Why is it important to understand which platforms are reporting assets?
A: To ensure you’re not missing unmanaged or shadow systems, which are often the root of unseen risk.
Asset List Widget
Q: What does the Asset List widget display?
A: It displays individual assets in your environment along with their associated Breach Impact values, estimating the potential financial loss if compromised.
Q: How can the Asset List widget be utilized?
A: You can identify and prioritize assets based on their criticality to the business, focusing on systems with higher breach impact values to reduce risk efficiently.
Q: How does the Asset List widget support collaboration?
A: By tying each asset to a financial risk metric, it justifies targeted remediation actions, allocates resources, and enforces control coverage.
Q: What is the practical view provided by the Asset List widget?
A: It offers a practical view into asset-level risk, enabling action based on business impact rather than just technical attributes.
Data Source Telemetry Widget
Q: What does the Data Source Telemetry widget show?
A: It shows how many assets are being contributed by each connected data source in your environment, with each bar representing the volume of telemetry from a specific connector.
Q: How does the widget help assess data sources?
A: It allows you to assess the coverage, relevance, and activity level of each source and ensure your telemetry architecture is functioning as expected.
Q: What can low telemetry from a source indicate?
A: It may indicate a misconfiguration, data ingestion issue, or lack of deployment coverage.
Q: What does high telemetry volume suggest?
A: It suggests strong integration and active asset tracking.
Q: How does the view support data ecosystem optimization?
A: By identifying overlapping, filling gaps, and ensuring accurate monitoring of major asset types such as endpoints, cloud infrastructure, mobile devices, and IoT.
Assets by Site Widget
Q: What does the Assets by Site widget provide?
A: It provides a breakdown of asset distribution across different physical or cloud locations, listing each site with the total number of assets located there.
Q: Why is the Assets by Site view useful?
A: It is useful for understanding how infrastructure is spread geographically, helping localize inventory and risk management efforts, especially in distributed environments.
Q: How does the widget contextualize other metrics?
A: It allows comparison of issues' concentration and their relation to the total asset footprint in each location, when combined with views by site such as exposure or compliance.
Q: What is ensured by using the Assets by Site widget?
A: It ensures that security efforts are scaled appropriately based on the size and importance of each site.
Automation
Q: What can you find in the Automation menu?
A: You can find options for launching automation setup, creating automation, defining automation scope, applying conditions, choosing triggers, selecting actions, and managing rules.
Q: How do you launch the automation setup?
A: By using the Create Automation button.
Q: What can you do in the Automation Configuration step?
A: Assign a name and select the data type.
Q: How do you define the automation scope?
A: Using the Scope of Automation filter panel.
Q: How can you apply conditions?
A: By configuring parameters within the Filter Builder.
Q: What trigger types are available?
A: Upon next evaluation, on schedule, or on a specific date.
Q: What action types can you select?
A: Send Slack, Send Email, Send Export, Create Ticket, or Create Remediation Project.
Q: How do you set ticket-specific options?
A: Using the Ticketing System Parameters form.
Q: How do you save the automation rule?
A: By clicking Create Automation.
Q: How can you modify or remove existing rules?
A: Using the Edit Automation and Delete Automation options.
Findings
Q: What can I do in the Findings menu?
A: Analyze control-related issues using the Findings by Exposure visualization, understand data ingestion sources via the Findings by Data Source breakdown, assess risk severity with the Findings by Threat Level chart, and explore the Controls Table to view mapped findings across controls.
Q: How can I investigate individual controls?
A: Use the Overview, Exposure Score, Threat Intel, and Adversary TTPs tabs to explore detailed information.
Q: What does the Overview tab provide?
A: A high-level snapshot of the control finding, including Max Exposure Score, CVSS score, and a complete description of the control finding.
Q: What is shown in the Exposure Score tab?
A: The complete calculation tree for the exposure score and the impact of different parameters such as Impact of Compromise, Likelihood of Compromise, Asset Impact, Accessibility, Threat, and Mitigation Efficiency.
Q: What information does the Threat Intel tab offer?
A: A high-level overview of the threat signal affecting the control.
Q: What can be found in the Adversary TTPs tab?
A: Tactics, techniques, and procedures from Mitre ATT&CK that can be used against vulnerabilities flagged by the control.
Q: What information is available in the Fixes tab?
A: Recommendations on how to fix the control.
Q: What does the Active Instances tab show?
A: All active instances of the control finding.
Q: What actions can be taken on selected controls?
A: Create Ticket, Create Project, Share via Email, Export control data, or customize the view via Export and Edit Columns options.
Q: How can I switch to a finding-centric view?
A: Use the Finding Instances table.
Reports
Q: What can you find in the Reports menu?
A: You can find options like Controls by Status, Failed Controls by Severity, Failed Controls by Framework, Controls by Data Sources, Controls by Technology, and Controls by Framework.
Q: What can you do in the Reports section?
A: Track control performance, identify critical control gaps, review compliance challenges, analyze control deployment origins, understand technology distribution, explore control coverage, and apply filters to focus reporting.
Validation Summary
Q: What can you do in the Validation Summary?
A: You can monitor security control effectiveness using the Controls by Status summary, identify high-risk areas through the Failed Controls by Severity chart, and analyze control deployment sources via the Controls by Data Sources view.
Q: How can you evaluate control validation results?
A: Evaluate control validation results in the Controls Validation Summary table and review individual control outcomes in the Passed Count and Failed Count columns.
Q: How do you access detailed validation metrics?
A: Access detailed validation metrics by selecting a control and opening its Details tab. Apply filters to narrow results within the Validation Summary.
Q: What does the Validation Summary menu allow you to review?
A: It allows you to review the Passed Count and Failed Count for each control and their instances, and the Details of the control. You can also see widgets like Controls by Status, Failed Controls by Severity, and Controls by Data Sources.
Widget List
Q: What is the Risk Equation widget?
A: This widget displays a calculated risk value in US dollars, derived from multiplying the likelihood of a security incident by its potential financial impact.
Q: What does the Risk Composition widget show?
A: It shows a breakdown of your risk posture across several risk categories in monetary terms, helping you identify where additional efforts may be needed.
Q: What information does the Vulnerabilities List widget provide?
A: It provides a searchable table of known vulnerabilities, sorted by their maximum exposure score, to help prioritize vulnerabilities.
Q: What is displayed in the Vulnerability Summary widget?
A: It shows the total count of unique vulnerabilities and categorizes them by severity level—critical, high, medium, and low.
Q: What does the Security Controls ROI widget display?
A: It displays the comparative risk before and after implementing security controls, showing risk reduction in monetary terms.
Q: What does the Controls Compliance Instances widget offer?
A: It displays how many controls have passed or failed compliance across different categories, providing a snapshot of compliance status.
Q: What is the purpose of the Next Best Steps widget?
A: It lists prioritized remediation actions across different stages, helping you identify and track tasks with significant risk reduction impact.
Q: What does the Vulnerabilities Count Comparison widget show?
A: It shows the total number of vulnerabilities for an asset group, broken down by severity categories, to guide remediation efforts.
Q: What is the function of the Top Vulnerable Items widget?
A: It displays items or vendors with the greatest number of known vulnerabilities, segmented by severity level, for prioritizing remediation efforts.
Q: How does the Assets with Exposures widget assist you?
A: It displays a list of assets alongside their estimated breach risk in monetary terms, to prioritize assets for remediation.
Q: What information is in the Assets with Exposures by Site widget?
A: It lists each site alongside the count of unpatched assets to identify locations with the highest volume of vulnerabilities.
Q: How does the Assets with Exposures by Owners widget help?
A: It lists each owner alongside the count of unpatched assets to identify where to focus remediation efforts.
Q: What data does the Vulnerabilities Instance Coverage widget provide?
A: It displays the total count of vulnerabilities identified by different data sources, helping spot detection gaps or overlaps.
Q: What does the Asset List widget contain?
A: It displays all discovered assets with their potential breach impact in monetary terms, identifying high-risk assets.
Q: How does the Assets by Site widget assist in security efforts?
A: It shows each site with the total number of assets, helping focus on critical locations.
Q: What is the purpose of the Assets by Owner widget?
A: It shows each owner with the total number of assets assigned, guiding security efforts on critical owners.
Q: What does the Asset Coverage widget highlight?
A: It compares assets identified by different sources, helping spot potential coverage gaps.
Q: What information is in the Software Inventory widget?
A: It displays the top installed software packages by the number of instances, to track patch levels.
Q: How does the Data Source Telemetry widget help maintain coverage?
A: It displays top data sources contributing telemetry with device or asset coverage, ensuring comprehensive data.
Q: What is the function of the Asset Types widget?
A: It shows a breakdown of assets by category and count, helping understand environment composition.
Q: What does the Power Widget – Bar Chart – Risk Score widget show?
A: It displays risk scores for asset categories using color coding to indicate severity.
Q: How does the Power Widget – Bar Chart – Breach Likelihood widget assist in prioritization?
A: It displays breach likelihood for asset categories, helping prioritize risk areas.
Q: What does the Power Widget – Bar Chart – Breach Impact widget indicate?
A: It displays potential financial damage from a breach, identifying areas with high monetary consequences.
Q: How does the Power Widget – Bar Chart – Breach Risk widget guide remediation efforts?
A: It displays overall breach risk in US dollars, showing where financial exposure is greatest.
Q: What does the Power Widget – Bar Chart – Number of Assets widget reveal?
A: It displays the total number of assets for each group, showing environment distribution.
Q: How does the Power Widget – Bar Chart – Vuln Summary widget assist with vulnerabilities?
A: It displays vulnerability severities across asset groups, prioritizing critical areas.
Q: What trends does the Power Widget – Trend Chart – Breach Likelihood widget show?
A: It shows how breach likelihood evolves over time, spotting patterns that require investigation.
Q: How does the Power Widget – Trend Chart – Breach Risk widget function?
A: It tracks breach risk changes over time, gauging security improvements' impact.
Q: What does the Power Widget – Trend Chart – Number of Assets widget track?
A: It shows asset count changes over time, identifying environment growth or shrinkage.
Q: How does the Power Widget – Trend Chart – Risk Score widget help monitor security?
A: It shows risk score changes over time, assessing security posture improvements.
Q: What does the Power Widget – Trend Chart – MTTP widget measure?
A: It measures mean time to patch changes, ensuring vulnerabilities are addressed quickly.
Q: How does the Power Widget – Trend Chart – MTTR widget evaluate remediation?
A: It tracks mean time to remediate changes, ensuring vulnerabilities are fully resolved efficiently.
Q: What is monitored with the Power Widget – Trend Chart – MOVA widget?
A: It measures mean open vulnerability age changes, ensuring risks don't linger.
Q: What insight does the Power Widget – Donut Chart – Risk Score widget provide?
A: It displays overall risk score in a color-coded donut chart for quick risk assessment.
Q: How does the Power Widget – Donut Chart – Number of Assets widget assist in environment understanding?
A: It shows asset count by category, helping focus security measures.
Q: What does the Power Widget – Donut Chart – Breach Likelihood widget show?
A: It provides breach likelihood in a donut chart for quick risk prioritization.
Dashboard Overview
Q: What is the purpose of the Dashboard menu?
A: It allows you to monitor overall cyber risk posture, track risk reduction progress, understand risk calculation, and evaluate remediation performance.
Q: How can you identify breach likelihood patterns?
A: By using the Breach Likelihood by Asset Type chart.
Q: What does the Risk Burndown visualization do?
A: It tracks risk reduction progress.
Q: What information does the Risk Equation panel provide?
A: It helps understand how risk is calculated.
Q: What does the CTEM Bird’s Eye view help with?
A: It reviews prioritized exposures and examines active data sources.
Q: What does the Categorized Assets, Apps, and Exposures section show?
A: It assesses coverage across assets, applications, and exposures.
Q: What are the Mean Time to Remediate (MTTR) metrics for?
A: They evaluate remediation performance.
Q: What can you do with the Inventory view?
A: Explore inventory details and assess application exposure.
Q: What is the purpose of the Work Avoided metric?
A: It quantifies operational savings.
Q: What does the Dispatched for Automated Mitigation section display?
A: It shows exposures dispatched for automated mitigation.
ServiceNow Connector Upgrade
Q: What is the purpose of the Balbix ServiceNow RITM integration?
A: It streamlines the creation of ServiceNow Requested Item tickets from Balbix vulnerability insights, aligning with ServiceNow’s fulfillment model for precise control over remediation tasks.
Q: What does each Requested Item (RITM) represent in ServiceNow?
A: An RITM is an individual item or service within a request, supporting independent fulfillment, tasking, and SLAs.
Q: Why are ticketing templates used?
A: They define the structure, content, and logic for how tickets are created, promoting consistency, streamlining workflows, and enabling automation.
Q: What benefits do ticketing templates provide?
A: They ensure consistent ticket quality, operational efficiency, readiness for automation, ServiceNow-centric alignment, and granular field-level control.
Q: What features does the integration offer?
A: It includes smarter field handling, ticket templates for reusability, streamlined ticketing rule configuration, enhanced user experience, and improved CSV handling, among others.
AppSec Findings
Q: What can you do in the Appsec Findings menu?
A: Analyze application security findings by exposure level, identify scan coverage, assess severity of issues, understand testing methodology, review application vulnerabilities, examine issue occurrences per application, apply data filters, create complex logic filters, export data, configure automations, adjust views, and explore detailed vulnerability metadata.
Q: What does the Overview tab in Vulnerability Characteristics provide?
A: It presents a high-level summary of the vulnerability, showing the name, severity rating, maximum exposure score, CVSS 3.x score, EPSS score, asset count, active instances, publication date, earliest appearance, and may include references and advisories.
Q: What can be found in the Exposure Score tab?
A: A detailed look at how the overall risk score is calculated, with an aggregated exposure score and a breakdown into "Impact of Compromise" and "Likelihood of Compromise" sections.
Q: What is shown in the Threat Intel tab?
A: It aggregates external intelligence data, showing threat mentions, vulnerability tags, recent threat chatter graph, and enables assessment of the current intelligence landscape.
Q: What does the Adversary TTPs tab map?
A: It maps tactics, techniques, and procedures to MITRE ATT&CK, detailing potential attack methods and corresponding techniques.
Q: What information is available in the Fixes tab?
A: Recommended remediation strategies and mitigation measures, including dependencies or prerequisites for a successful fix.
Q: What details are provided in the Active Instances tab?
A: A detailed list of assets currently affected by the vulnerability, including asset's name, identification details, and a snapshot of its risk profile related to the vulnerability.
EM Settings
Q: What can you do in the EM Settings?
A: You can create automation rules for exposure management, define rule metadata, specify Exposure Type, select and configure a Ticketing System, associate the rule with a Project, define the Issue Type, and confirm configurations through the Ticketing System Parameters panel.
Exposure Simulations
Q: What does the Exposure Score Simulator do?
A: It calculates vulnerability exposure scores by analyzing factors like asset attributes, vulnerability characteristics, threat intelligence, and security controls. It provides a risk assessment by computing inherent, accepted, mitigated, and residual exposure scores on a scale of 0-100.
Q: How can you simulate risk impact?
A: You can simulate risk impact for specific vulnerabilities using the Exposure Simulations interface by selecting a CVE and asset, adjusting asset attributes, modifying vulnerability analysis parameters, configuring threat level, and setting security controls efficacy and validation.
Q: What can you configure in the Vulnerability Analysis section?
A: You can configure attack vector, dependencies, scope, privileges required, interaction required, attack complexity, confidentiality, integrity, availability, and vulnerability age.
Q: What does the Threat Level section allow you to do?
A: It allows you to configure threat chatter level, EPSS level, and select threat tags such as ransomware, malware, CISA KEV, known exploit.
Q: What is shown in the Exposure Score Calculation section?
A: It shows the final Exposure Score resulting from the parameters configured.
Q: How does asset role affect severity calculations?
A: Business roles associated with the asset directly influence severity calculations through role-based impact weights.
Q: What impact does network zone/subzone have on exposure?
A: It significantly affects accessibility scores; deeper zones reduce exposure.
Q: How do kernel components affect severity scores?
A: Kernel components increase severity scores.
Q: How does attack vector influence exposure?
A: Remote vectors increase accessibility; local vectors reduce exposure.
Q: What effect do additional dependencies have?
A: Additional dependencies decrease likelihood.
Q: How does higher threat chatter affect threat score?
A: Higher chatter increases threat score.
Q: What is the purpose of security control validation?
A: Validation through BAS and Red Team testing ensures effectiveness; failed tests override control efficacy.
```
Remediation & Mitigations
Q: What can I do in the Remediation & Mitigations menu?
A: You can review open remediation tasks, investigate specific efforts, analyze resolutions, review exposures, understand impacted infrastructure, organize remediation efforts, view summary information, examine associated fixes and exposures, and identify all entities involved in a project.
Q: What information does the Ticket Details tab provide?
A: It provides a snapshot of key ticket details, including status, priority, assignee, summary, ticket key, metadata, number of assets and vulnerabilities, and any attachments.
Q: What can I see in the Ticket Summary view?
A: You can see entities and exposures tied to the ticket, remediation progress, vulnerable entities, active exposures by severity, and remediation progress over time.
Q: What does the Fixes tab show?
A: It shows recommended updates or solutions for vulnerabilities, highlighting fix versions, components, and remediation status, with a filter and column customization options.
Q: What is the purpose of the Exposures tab?
A: It lists vulnerabilities with maximum exposure score, remediation progress, status, and impacted entities, allowing filtering and column customization.
Q: What information does the Entities tab provide?
A: It lists assets involved in vulnerabilities, showing remediation progress, status, and fixes in scope, with search and column customization options.
Q: What is displayed in the Project Summary view?
A: It provides a snapshot of project status, due date, and progress, with charts for vulnerable entities and active exposures, and remediation progress over time.
Q: What does the Project Details tab offer?
A: It offers comprehensive project information, including name, description, due date, status, progress, ownership, team, and relevant metadata.
Asset Vulnerabilities
Q: What can I access in the Asset Vulnerabilities menu?
A: You can analyze vulnerabilities by exposure level, identify coverage sources, assess severity distribution, categorize vulnerability types, review total unique vulnerabilities and affected assets, investigate specific impacted hosts, apply data filters, create complex filter logic, reset applied filters, trigger automation workflows, export data, and customize columns.
Q: What does the Overview tab present?
A: The Overview tab presents a summary of the selected vulnerability, including its name, severity rating, exposure score, CVSS score, EPSS score, asset count, active instances, and publication date. It may also include references, advisories, and MITRE ATT&CK tactics.
Q: What is detailed in the Exposure Score tab?
A: The Exposure Score tab details the calculation of the risk score, showing the "Impact of Compromise" and "Likelihood of Compromise" sections with their contributing factors.
Q: What information does the Threat Intel tab provide?
A: The Threat Intel tab aggregates external intelligence, showing threat mentions from various sources and categorizing vulnerabilities with tags. It includes a recent threat chatter graph to assess external intelligence relevance.
Q: What does the Adversary TTPs tab show?
A: The Adversary TTPs tab provides insight into tactics, techniques, and procedures related to the vulnerability, mapping potential attack methods to MITRE ATT&CK.
Q: What is outlined in the Fixes tab?
A: The Fixes tab outlines recommended remediation strategies, detailing remediation steps and necessary dependencies or prerequisites.
Q: What is displayed in the Active Instances tab?
A: The Active Instances tab shows assets currently affected by the vulnerability, with information such as asset name, identification details, and risk profile.
Exceptions
Q: What can I access through the BX5 Asset Analysis settings?
A: You can access asset telemetry configuration, review sensor deployment status, track data ingestion sources, compare raw and deduplicated assets, evaluate asset data quality, identify incomplete telemetry, detect outdated records, monitor asset lifecycle, and navigate across different asset groups.
Q: What does the Configured Sensors count show?
A: It shows the number of configured sensors.
Q: What is the difference between Raw Assets and Analyzed Assets?
A: Raw Assets are the number of assets ingested before deduplication, while Analyzed Assets are the number after deduplication.
Q: What does the Categorized Assets table display?
A: It displays assets with sufficient data fidelity for accurate categorization.
Q: What are Assets with Poor Visibility?
A: Assets with insufficient data fidelity for accurate categorization, excluded from dashboards and risk calculations.
Q: What are Transient Assets?
A: Assets last observed more than 7 days ago (or 2 days for cloud assets), with both first and last observed times within the same day, excluded from dashboards and risk calculations.
Q: What are Recently Retired Assets?
A: Assets retired within the last 7 days due to lack of observations, excluded from dashboards and risk calculations.
Q: How is BX5's architecture designed?
A: It is built around data aggregation, deduplication, and AI-driven analysis, ingesting data from multiple sources and enriching it with contextual information for risk analysis.
Q: What is the purpose of data deduplication and normalization in BX5?
A: To eliminate redundant asset entries and standardize asset attributes for compatibility with analytical models and consistent risk scoring.
Q: How does BX5 enrich asset details?
A: By enhancing asset records with contextual information such as business impact, exposure level, and operational relevance for accurate risk prioritization.
Q: How does BX5 handle asset categorization?
A: It categorizes assets into on-premise and cloud types using predefined classification logic.
Q: What are Unverified Assets in BX5?
A: Assets lacking sufficient data for proper categorization, requiring customer verification or data augmentation.
Q: What is the outcome of BX5's asset processing?
A: It ensures clarity in asset fidelity, helping prioritize security initiatives and allocate resources efficiently.
EM Analytics
Q: What options are available in the EM Analytics menu?
A: The EM Analytics menu offers widgets that provide a data-driven look at vulnerabilities and risks, snapshots of new threats, unresolved issues, and assets or software most exposed.
Q: How do the widgets help identify risks?
A: Widgets focus on different dimensions to identify where the environment is most at risk, showing whether a vulnerability is widespread or if critical flaws could have a severe impact.
Q: Do the widgets track SLA breaches?
A: Yes, they highlight SLA breaches, track patching efforts, and monitor trends in newly discovered and fixed issues.
Q: How do the widgets enhance decision-making?
A: They guide decision-making by pinpointing critical exposures, revealing patterns in vulnerabilities, and tracking mitigation strategies.
Q: What does the “Open Vulnerability by Vuln Tags: Today” widget show?
A: It shows unique vulnerabilities with specific threat tags, providing a snapshot of issues with critical labels like “CISA Known Exploit” or “Malware Linked”.
Q: How does Balbix classify vulnerabilities?
A: Balbix classifies vulnerabilities based on exploit patterns, malware signatures, and other indicators of compromise for risk assessment.
Q: What distinguishes the “Open Vulnerability Instance Count by Vuln Tags: Today” widget?
A: It categorizes vulnerabilities by threat tags and counts every occurrence across the environment, not just unique vulnerabilities.
Q: What is the purpose of the “Open Vulnerability Instance Count by Vuln Tags: Trend” widget?
A: It tracks vulnerabilities over time, helping to spot trends and assess whether mitigation strategies are effective.
Q: What does the “New Vulnerabilities and Fix Counts: Trend” widget do?
A: It compares the number of new vulnerabilities to fixes over time, helping gauge if the gap between them is closing.
Q: What information does the “New Vulnerability and Fix Instance Counts: Trends” widget provide?
A: It measures new and fixed vulnerabilities across affected systems to highlight exploit proliferation.
Q: How does the “New Vulnerability Count” widget assist users?
A: It breaks down new vulnerabilities by CVSS and Exposure Severity to help teams prioritize responses.
Q: What does the “Open Vulnerability Count: Trend” widget track?
A: It tracks unique unresolved vulnerabilities over time, providing a snapshot of overall exposure.
Q: What focus does the “Open Vulnerability Instance Count: Trend” widget have?
A: It focuses on tallying every occurrence of vulnerabilities to prioritize response strategies based on volume.
Q: What insights does the “Top Vulnerable Assets: Open Vulnerability Instance Count by CVSS Severity” widget offer?
A: It highlights assets with the highest vulnerability instances, aiding in resource allocation and prioritization.
Q: What is the function of the “Top Vulnerabilities: Open Vulnerability Instance Count” widget?
A: It lists widespread vulnerabilities by CVE ID, focusing on how frequently each appears across the environment.
Q: What role does the “Top Vulnerable Softwares: Open Vulnerability Instance Count by CVSS Severity” widget play?
A: It identifies software with the largest number of vulnerability instances, helping prioritize which platforms need addressing.
Assets
Q: What can you monitor using the Analyzed Assets metric?
A: You can monitor total asset visibility.
Q: What can the Analyzed Assets Telemetry provide?
A: It provides device-level insights.
Q: How can you identify exposed assets?
A: By using the Analyzed Assets with Exposures view.
Q: What options are available for filtering asset data?
A: You can use the Add Filter and Advanced Filters options.
Q: How can you categorize assets?
A: By using the Tag control.
Q: How do you modify asset classification?
A: Via the Edit Type function.
Q: How can you adjust asset-level metadata?
A: Through the Edit Attribute panel.
Q: What can you use for automation, exporting data, or customizing views?
A: The Automation, Export, and Edit Columns links.
Q: How can you access detailed asset views?
A: Through the Summary and Inventory Details tabs.
Q: Where can you explore technical data?
A: By reviewing the Software, Vulnerabilities, Controls, and Ports tabs.
Q: What can you see in the Summary tab?
A: A summary of the asset, vulnerability summary, risk equation, top vulnerability findings, and top vulnerable software.
Q: What attributes are visible in the Inventory Details tab?
A: Host attributes, owner information, operating system information, system information, networking information, roles, tags, and data sources.
Q: What information is available in the Software tab?
A: All software installed in the asset.
Q: What information is available in the Vulnerabilities tab?
A: All vulnerabilities present in the asset.
Q: What does the Controls tab show?
A: All the controls applied to the asset.
Q: What does the Ports tab provide?
A: The IP address of the asset and which ports are open.
Apps
Q: What options are available in the Apps menu?
A: You can monitor application coverage, evaluate operational insights, identify vulnerable applications, filter application data, perform exports, configure automation, and access detailed application data.
Q: What does the Summary tab display?
A: The Summary tab displays Findings Summary, Findings by Type, and Top Findings.
Q: What information is available in the Inventory Details tab?
A: The Inventory Details tab shows General Attributes such as Name, type, URL, Website IP, Group, Alias, IDE, Parent Domain, Status, Top Level App, Owner Attributes including Business Owner, VM Owner, Application Owner, IT Owner, Tags, and Data Sources.
Q: What does the Findings tab display?
A: The Findings tab displays all the findings related to the app.
Q: What information does the Infrastructure tab provide?
A: The Infrastructure tab shows all the infrastructure (assets) related to the app.
Group Management
Q: What can you do in the Group Management menu?
A: Manage group-level asset segmentation using the Asset Groups panel in Group Management.
Q: What can you view in the Group Management Summary tab?
A: View group-level summaries including Assets by Type, Assets with Exposures, and Assets by OS.
Q: How can you review assets in Group Management?
A: Review all associated assets through the Inventory tab.
Q: What analysis can you perform in the Vulnerabilities tab?
A: Analyze vulnerabilities across grouped assets.
Q: What information is available in the OS/Software tab?
A: Examine installed software and operating systems.
Q: What can you evaluate in the Telemetry tab?
A: Evaluate data ingestion quality and source breakdowns.
Q: How can security be assessed in Group Management?
A: Assess security controls and related issues using the Controls tab.
Q: What can you view in the Tags/Roles tab?
A: View group-specific metadata and permissions.
Inventory Settings
Q: What can you configure in the Inventory Settings?
A: You can configure Company, Company Profile, General Settings, Licensing, User and Access, Data capture, Data analysis, Tag manager, Dashboards, Asset Inventory, BX5 Asset Analysis, Exposure Management, and Cyber Risk settings.
Q: Where can you access the Inventory Settings?
A: You can access them through the Inventory Settings menu.
Q: What can you configure under Licensing in Inventory Settings?
A: You can configure Module entitlements, License counts, and Licensed users.
Q: What is configurable under User and Access in Inventory Settings?
A: You can configure Users, Roles and access control, and Allowed email domains.
Q: What can you manage under Data capture in Inventory Settings?
A: You can manage Connectors and Sensors.
Q: What dashboards can you configure in Inventory Settings?
A: You can configure Default and Custom dashboards.
Q: What is encompassed under Asset Inventory in Inventory Settings?
A: Sites and locations, and Subnet to site mapping.
Q: What settings are included under Exposure Management in Inventory Settings?
A: Metrics and targets, Remediation SLA matrix, Project/Ticketing Rules, and other settings.
Q: What areas are covered under Cyber Risk in Inventory Settings?
A: Asset criticality, Control settings, Risk scenarios, and other settings.
Balbix Host Analyzer (HA) Deployment and Operation Guide
Q: What is the Balbix Host Analyzer (HA)?
A: It is lightweight endpoint software that collects real-time information about installed software, configurations, logged-in users, and other system details across desktops, laptops, and servers running Windows, macOS, AIX, and most Linux distributions.
Q: How many asset attributes does the HA collect?
A: It gathers more than 350 discrete attributes for every system on which it is installed.
Q: What broad categories of information does the HA observe?
A: Categories include system info, system status, firmware and OS images, installed software and security controls, SBOM and service BOM, server features, open ports, network interfaces, discoverability data, network shares, and installed certificates.
Q: Does installing or updating the HA ever require a reboot?
A: No. Installation and subsequent silent updates never need a system reboot or downtime.
Q: What are the minimum recommended system requirements for running the HA?
A: A 2 GHz dual-core CPU, 4 GB RAM (8 GB recommended), 800 MB storage, and outbound Internet connectivity.
Q: Why must certain Balbix URLs be whitelisted?
A: Whitelisting ensures the HA can reach its regional “brain” endpoints for secure data transfer and updates; each HA instance holds a unique client certificate for this TLS connection.
Q: How resource-intensive is the HA during normal operation?
A: Average consumption is about 0.5 % CPU, 200 MB RAM, 800 MB disk, and roughly 4 MB of network data per day.
Q: What mechanism keeps the HA software up to date?
A: It uses Google’s lightweight Omaha protocol to download and apply updates automatically without IT intervention.
Q: Where can administrators obtain the installer packages?
A: All platform-specific installers are downloaded directly from the Balbix dashboard.
Q: Which Microsoft Windows versions are supported?
A: Windows 7, 8.1, 10, 11, plus Windows Server 2008 R2, 2012, 2012 R2, 2016, 2019, and 2022.
Q: What is the basic Windows installation procedure?
A: Download the ZIP, extract it, run the MSI with msiexec or double-click, optionally run the bx-troubleshooter tool first, and deploy at scale via KACE, SCCM, Casper, or GPO.
Q: How is a static proxy configured for Windows HA communications?
A: Use netsh winhttp set proxy proxy-server="IP:Port" to define the proxy, and netsh winhttp reset proxy to clear it; on 64-bit Windows 7/2008 R2 also run the commands from SysWoW64\netsh.exe.
Q: How do you silently uninstall the HA on Windows?
A: Run the legacy setup executable with --uninstall --system-level --verbose-logging from the installed path.
Q: How can you verify the installed HA version on Windows?
A: Open Control Panel → Programs and Features and inspect the Balbix BxA entry for version and install date.
Q: What is the HA memory footprint on Windows?
A: It typically uses between 80 MB and 130 MB of RAM.
Q: Where are Windows HA logs stored?
A: All logs reside in C:\ProgramData\Balbix.
Q: Which primary Windows services does the HA run?
A: The bxna (host analysis) and bxupdate (software update) services.
Q: Name two key HA processes on Windows.
A: bx_na.exe (the agent) and bxtray_win.exe (the system-tray UI).
Q: Which Linux distributions are officially supported?
A: Amazon Linux 2/2023, CentOS 6–7, Debian 8–12, RHEL 6–9, Rocky 8–9, Oracle 7, SUSE 11–15, Ubuntu 14.04–22.04, and most others on request.
Q: How do you install the HA on Debian-based Linux systems?
A: Run sudo dpkg -i package.deb or sudo apt-get install -f package.deb.
Q: Which orchestration tools are commonly used for Linux HA deployment at scale?
A: Puppet, Chef, and Ansible.
Q: How much memory and CPU does the HA consume on Linux?
A: It averages 20 MB RAM (peaking at 100 MB) and <0.5 % CPU, running at nice value 10 so all other tasks take precedence.
Q: Where are Linux HA logs located?
A: /var/log/bxha/.
Q: What is the primary Linux systemd service for the HA?
A: bxha.service (or /etc/init.d/bxha on non-systemd systems) provides host analysis.
Q: Which macOS versions does the HA support?
A: macOS 11 (Big Sur) and newer on both Intel and Apple Silicon.
Q: How is the HA installed on macOS?
A: Download the DMG, open BxA.pkg, and follow the installer prompts; Munki or Jamf can automate large-scale deployment.
Q: What is the average HA memory usage on macOS?
A: About 50 MB on average, up to 200 MB at peak.
Q: Where are macOS HA logs stored?
A: /Library/Balbix/Logs.
Q: How much daily network bandwidth does the HA consume?
A: Approximately 200 KB per endpoint per day.
Q: How frequently does the HA scan an endpoint?
A: It performs a full baseline scan within an hour of installation, then only differential scans triggered by observed changes, functioning as an always-on observational agent rather than a timed scanner.
Q: Does the HA alter packets or hook kernel modules?
A: No. It performs no packet modification and relies solely on standard OS-exposed APIs.
Q: What Windows utility helps diagnose installation problems before deploying the HA?
A: bx-troubleshooter-xx.exe runs host and network checks, reporting any issues with recommended resolutions.
Q: Where can administrators find detailed installation or connectivity logs for troubleshooting?
A: Review BalbixUpdate.log and BalbixUpdate.log.bak in each platform’s log directory to locate SEND FAILED messages and error codes.
Q: How can you contact Balbix Technical Support?
A: Reach out via your local account team, the support form, support@balbix.com, or call +1-866-936-3180 during U.S. business hours.