Assets
An asset is something owned by your organization where a vulnerability can be found, such as a web server, a source code file, or an IP address.
Every vulnerability in the NetSPI Platform is associated with an asset. Assets are created automatically when importing finding data.
Asset Types
The platform supports 30 distinct asset types for tracking and managing security-related assets. Each asset type serves a specific purpose in representing different components of an organization's infrastructure.
Network & Infrastructure Assets
IP ADDRESS
Represents an IPv4 or IPv6 address in the network. Tracks geolocation (latitude, longitude, city, country), ASN association, monitoring status, and liveness. Can be associated with hosts, domains, and cloud resources. Supports EASM monitoring capabilities.
DOMAIN
Represents a domain name or subdomain. Tracks monitoring status, liveness, CDN information, and can be associated with IP addresses and cloud accounts. Supports subdomain detection and EASM monitoring.
HOST
Represents a physical or virtual machine in the network. Tracks operating system information, hostnames, MAC addresses, serial numbers, and Active Directory integration (AD Object GUID/SID). Can be associated with multiple IP addresses and cloud resources.
NETWORK DEVICE
Represents network infrastructure equipment such as routers, switches, firewalls, or other networking hardware. Tracks device type, operating system, and associated IP addresses and domains.
SUBNET
Represents a network subnet or IP range. Tracks CIDR notation, start/end IP ranges, VLAN ID, DHCP configuration, and whether it's a wireless network. Can be associated with companies.
DNS RECORD
Represents DNS records (A, CNAME, MX, TXT, etc.) associated with domains. Tracks record type, target addresses, and domain relationships.
Application & Software Assets
APP
Represents a software application. Tracks name, version information (major/minor/edition/service pack), URL, CPE name for vulnerability correlation, release date, end-of-life date, vendor, and category.
APPLICATION INSTANCE
Represents a deployed instance of an application running on a host. Tracks service name, service account, startup parameters, install path, process information, authentication mode, and host/port associations. Supports LLM-based classification with confidence scores.
SOURCE CODE
Represents a source code repository or codebase that may be subject to security testing.
OPERATING SYSTEM
Represents an operating system installation. Tracks OS type, platform, version details, release date, end-of-life date, and extended support end date. Associated with a vendor company.
PRODUCT (product)
Represents a commercial or third-party software product. Tracks product name, icon, website, description, and product categories. Used for identifying software in the environment.
Cloud Assets
CLOUD RESOURCE
Represents a cloud infrastructure resource (EC2 instances, storage buckets, containers, etc.). Tracks cloud provider (AWS/Azure/GCP), resource type, resource identifier, VPC, account, region, availability zone, and provider-specific attributes.
CLOUD ACCOUNT
Represents a cloud provider account. Tracks account credentials and configuration for AWS (external ID, role ARN), Azure (tenant/client/subscription IDs), and GCP (service account, project ID). Monitors credential expiration and scan status.
Identity & Access Assets
IDENTITY (identity)
Represents a user account or identity in the system. Tracks username, email, first/last name, SAM account name, identity type, Active Directory attributes, authentication realm, and flags for privileged access, MFA status, and role-based access.
GROUP (group)
Represents a security or distribution group. Tracks group name, type, Active Directory attributes, and membership relationships (identities, other groups, hosts). Supports raw permission storage for cloud IAM roles.
PERSON (person)
Represents a human individual in the organization. Tracks personal information (name, email, phone), job title, department, manager relationship, and employment details. Can be linked to multiple identities and companies.
Active Directory Assets
AD DOMAIN
Represents an Active Directory domain. Tracks domain identifiers (GUID, SID, Distinguished Name), common name, parent domain, and forest relationship.
AD FOREST
Represents an Active Directory forest (top-level AD container). Tracks the forest name.
AD ORGANIZATIONAL UNIT
Represents an Active Directory Organizational Unit (OU). Tracks OU name, AD identifiers, distinguished name, and parent domain.
AD SERVICE PRINCIPAL NAME
Represents a Service Principal Name (SPN) registered in Active Directory. Tracks the SPN, host, port, service class, service name, and associated identity.
AD TRUSTED DOMAIN
Represents a trust relationship between Active Directory domains. Tracks trusted domain name, trust direction (inbound/ outbound/bidirectional), transitivity, and AD identifiers.
File & Storage Assets
FILE SHARE
Represents a network file share. Tracks share path, UNC path, share type, file count, total size, and access information.
FILE
Represents an individual file. Tracks file path, hash, parent file share/host, and flags for sensitive data detection (passwords, non-public data, high-risk content).
Organizational Assets
COMPANY
Represents a company or organization. Tracks company name, registration details, headquarters address, website, industry, employee count, parent/acquired company relationships, and contact information.
LOCATION
Represents a physical location or office. Tracks address details (country, city, state, street, zip), location zone, department, owner, and parent relationships (company, other locations).
PHYSICAL COMPONENT
Represents physical infrastructure components (servers, racks, UPS units, etc.). Tracks component type and parent relationships (location, company, other components).
Security & Exposure Assets
CERTIFICATE
Represents an SSL/TLS certificate. Tracks certificate details including subject/issuer information, validity dates, fingerprints, serial number, public key information, and self-signed status.
ASN
Represents an Autonomous System Number and its IP ranges. Tracks ASN value, name, domain, IP range (start/end), ownership status, and monitoring configuration.
Policy & Generic Assets
POLICY
Represents organizational security or compliance policies. Tracks policy name, type, subtype, category, department, and owner.
GENERIC ASSET
A flexible asset type for assets that don't fit other categories. Supports custom type-specific attributes via JSON storage.