Understand asset details in Microsoft Defender EASM
In brief
The article title, headings, terminology, explanatory wording, and screenshot markup were updated. Terms such as “Signature algorithm Object Identifier” and “Autonomous System Numbers” are now expanded.
What Defender admins need to know
No administrator action is required; use the updated article when interpreting asset details.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Understand asset details in Microsoft Defender External Attack Surface Management
Microsoft Defender External Attack Surface Management (Defender EASM) frequently scans all inventory assets and collects robust contextual metadata that powers Attack Surface Insights. This datacontextual metadata can also be viewed more granularly on the asset details page. The data that's provided changes depending on the asset type. For instance, the platform provides unique Whois data for domains, hosts, and IP addresses. ItThe platform provides signature algorithm data for Secure Sockets Layer (SSL) certificates.
This article describes how to view and interpret the expansive data collected by Microsoft for each of your inventory assets. ItThis article defines thisthe metadata for each asset type and explains how the insights derived from itthat metadata can help you manage the security posture of your online infrastructure.
For more information, see Understanding inventory assets to familiarize yourself with the key concepts mentioned in this article.
Asset details summary view
You can view the asset details page for any asset by selecting its name from your inventory list. On the left pane of this page, you can view an asset summary that provides key information about that particular asset. The asset summary in the left pane primarily includes data that applies to all asset types, although more fields are available in some cases. For more information on the metadata provided for each asset type in the summary section, see the following chart.General asset information table.
:::image type="content" source="media/inventory-1.png" alt-text="Screenshot that shows an asset details page with the summary pane highlighted.":::

General asset information
The General information section includes high-level information that's key to understanding your assets at a glance. Most of these fields apply to all assets. ThisThe General information section can also include information that's specific to one or more asset types.
| Name | Definition | Asset types |
|---|---|---|
| SSL version | The version of SSL that the certificate was registered. | SSL certificate |
| Certificate key algorithm | The key algorithm used to encrypt the SSL certificate. | SSL certificate |
| Certificate key size | The number of bits in an SSL certificate key. | SSL certificate |
| Signature algorithm |
The OID that identifies the hash algorithm used to sign the certificate request. | SSL certificate |
| Self-signed | Indicates whether the SSL certificate was self-signed. | SSL certificate |
| Name server record | Any name servers detected on the asset. | IP address |
| Mail server record | Any mail servers detected on the asset. | IP address |
| IP blocks | The IP block that contains the IP address asset. | IP address |
| ASNsAutonomous System Numbers (ASNs) | The ASNAutonomous System Number (ASN) associated with an asset. | IP address |
IP block information
Understand the data tabs
On the rightmost pane of the asset details page, users can access more expansive data related to the selected asset. ThisThe asset data in this pane is organized in a series of categorized tabs. The available metadata tabs change depending on the type of asset you're viewing.
Certain tabs display a Recent only toggle in the upper-right corner. By default, Defender EASM displays all data that we've collected for each asset, including historical observations that may not be actively running on your current attack surface. While this historical context is very valuable for certain use cases, the Recent only toggle limits all results on the Asset Details page to those most recently observed on the asset. We recommend that you use the Recent only toggle when you only wish to view data that represents the current state of the asset for remediation purposes.
:::image type="content" source="media/inventory-1b.png" alt-text="Screenshot that highlights the Recent only toggle from the Overview page of Asset Details.":::
Overview tab
The Overview tab provides more context to ensure that significant insights are quickly identifiable when you view the details of an asset. This sectionThe Overview tab includes key discovery data for all asset types. ItThe Overview tab provides insight about how Microsoft maps the asset to your known infrastructure.
The Overview tab can also include dashboard widgets that visualize insights that are relevant to the asset type in question.
:::image type="content" source="media/inventory-2.png" alt-text="Screenshot that shows the asset details page Overview pane.":::

Discovery chain data
The discovery chain outlines the observed connections between a discovery seed and the asset. ThisDiscovery chain information helps users visualize these connections and better understand why an asset was determined to belong to their organization.
In the example, you can see that the seed domain is tied to this asset through the contact email in its Whois record. That same contact email was used to register the IP block that includes this particular IP address asset.
:::image type="content" source="media/inventory-3.png" alt-text="Screenshot that shows the discovery chain.":::

Discovery information tab
IP reputation tab
The IP reputation tab displays a list of potential threats related to a given IP address. This section outlines any detected malicious or suspicious activity that relates to the IP address. This informationIP reputation data is key to understanding the trustworthiness of your own attack surface. These threats can help organizations uncover past or present vulnerabilities in their infrastructure.
The Defender EASM IP reputation data displays instances when the IP address was detected on a threat list. For instance, the recent detection in the following example shows that the IP address relates to a host known to be running a cryptocurrency miner. This IP reputation entryThe cryptocurrency-miner detection in this example was derived from a suspicious host list supplied by CoinBlockers. Results are organized by the Last seen date to show the most relevant detections first.
In this example,the IP reputation screenshot, the IP address is present on an abnormally high number of threat feeds. This informationThe unusually high number of threat-feed detections indicates that the asset should be thoroughly investigated to prevent malicious activity in the future.
:::image type="content" source="media/inventory-4.png" alt-text="Screenshot that shows the asset details page IP reputation tab.":::

Services tab
The Services tab is available for IP address, domain, and host assets. The Services tab provides information on services observed to be running on the asset. ItThe Services tab includes IP addresses, name and mail servers, and open ports that correspond with other types of infrastructure (for example, remote access services).
Defender EASM's services data is key to understanding the infrastructure that powers your asset. It can also alert you to resources that are exposed on the open internet that should be protected.
:::image type="content" source="media/inventory-5.png" alt-text="Screenshot that shows the asset details page Services tab.":::

IP addresses section
The IP addresses section provides insight on any IP addresses that are running on the asset's infrastructure. On the Services tab, Defender EASM provides the name of the IP address and the First seen and Last seen dates. The Recent column indicates whether the IP address was observed during the most recent scan of the asset. If there's no checkbox in this column, the IP address was seen in prior scans, but it isn't currently running on the asset.
:::image type="content" source="media/inventory-6.png" alt-text="Screenshot that shows the asset details page IP address section of the Services tab.":::

Mail servers section
The Mail servers section provides a list of any mail servers that are running on the asset. This informationThe presence of mail servers indicates that the asset is capable of sending emails. In this section, Defender EASM provides the name of the mail server and the First seen and Last seen dates. The Recent column indicates whether the mail server was detected during the most recent scan of the asset.
:::image type="content" source="media/inventory-7.png" alt-text="Screenshot that shows the asset details page Mail server section of the Services tab.":::

Name servers section
The Name servers section displays any name servers that are running on the asset to provide resolution for a host. In this section, Defender EASM provides the name of the mail server and the First seen and Last seen dates. The Recent column indicates whether the name server was detected during the most recent scan of the asset.
:::image type="content" source="media/inventory-8.png" alt-text="Screenshot that shows the asset details page Name server section of the Services tab.":::

Open ports section
The Open ports section lists any open ports detected on the asset. Microsoft regularly scans around 230 distinct ports. This data is useful to identify any unsecured services that shouldn't be accessible from the open internet. TheseExamples of unsecured services include databases, IoT devices, and network services like routers and switches. It's also helpful in identifying shadow IT infrastructure or insecure remote access services.
In this section, Defender EASM provides the open port number, a description of the port, the last state it was observed in, and the First seen and Last seen dates. The Recent column indicates whether the port was observed as open during the most recent scan. Defender EASM considers a port open when our system can successfully complete a syn-ack handshake that results in attributed banners. When we can establish a TCP connection but are unable to complete our service fingerprinting, we mark the port as filtered. A closed port is still accessible but there is no service listening on the port and thus denies connections.
:::image type="content" source="media/inventory-9.png" alt-text="Screenshot that shows the asset details page Open ports section of the Services tab.":::

Trackers tab
Web components are details that describe the infrastructure of an asset as observed through a Microsoft scan. These components provide a high-level understanding of the technologies used on the asset. Microsoft categorizes the specific components and includes version numbers when possible.
:::image type="content" source="media/inventory-10.png" alt-text="Screenshot that shows the top of the Web components tab.":::

The Web components section provides the category, name, and version of the component and a list of any applicable CVEsCommon Vulnerabilities and Exposures (CVEs) that should be remediated. Defender EASM also provides First seen and Last seen date columns and a Recent column. A checked box indicates that this infrastructure was observed during the most recent scan of the asset.
Web components are categorized based on their function.
The Observations tab features two tables: Observations and Non-applicable observations. All active observations determined to be recent within your attack surface will be in the Observations table, whereas the Non-applicable observations table lists any observations that have either been manually marked as non-applicable or were determined by the system to no longer be applicable. To mark observations as non-applicable and therefore exclude that particular observation from dashboard counts, simply select the desired observations and select Set as non-applicable. The observation(s) will immediately disappear from the active Observations table and will instead appear on the Non-applicable observations table. You can revert this change at any time by selection the relevant observation(s) from this table and selecting Set as applicable.
:::image type="content" source="media/cves-3.png" alt-text="Screenshot that shows the Observations tab with multiple CVEs selected to be marked as non-applicable.":::

Connected assets tab
Connected Assets empowers users to graphically link and gather information about assets for investigative analysis. You can explore your environment and its intricate relationships through relationship mappings, which offer clear and concise views. This helpsThese relationship mappings help you identify hidden connections and potential attack paths. By visually mapping out the relationships between assets and vulnerabilities, you can comprehend your environment's complexity and make well-informed decisions to enhance your security posture and apply choke points effectively.
:::image type="content" source="media/connected-1.png" alt-text="Screenshot that shows the Connected assets tab." lightbox="media/connected-1.png":::

On the Connected assets tab, all the assets that are connected to the specified asset are identified in a list. The list provides key information about each policyconnected asset, including:
Asset:Asset: The identified connected asset.Kind:Kind: The type of asset.State:State: The state of the asset.Labels:Labels: Any labels associated with the asset.- First
Seen:Seen: When the asset was first discovered. - Last
Seen:Seen: When the asset was last identified.
From the Connected assets tab, you can modify or remove connected assets. You can also sort or filter the asset list to further categorize the list of connected assets. You can also download a CSV report of the listed assets. Any filters applied will be reflected on the CSV export.
Resources tab
The Resources tab provides insight on any JavaScript resources running on any page or host assets. When applicable to a host, thesethe detected JavaScript resources are aggregated to represent the JavaScript running on all pages on that host. The Resources tab provides an inventory of the JavaScript detected on each asset so that your organization has full visibility into these resources and can detect any changes.
Defender EASM provides the resource URL, resource host, MD5 (Message-Digest Algorithm 5) hash value, and first-seen and last-seen dates to help organizations effectively monitor the use of JavaScript resources across their inventory.
:::image type="content" source="media/inventory-12.png" alt-text="Screenshot that shows the Resources tab.":::

SSL certificates tab
Certificates are used to secure communications between a browser and a web server via SSL. use of certificates ensures that sensitive data in transit can't be read, tampered with, or forged. The SSL certificates tab in Defender EASM lists any SSL certificates detected on the asset, including key data like the issue and expiry dates.
:::image type="content" source="media/inventory-13.png" alt-text="Screenshot that shows the SSL certificates tab.":::

Whois tab
The Whois protocol is used to query and respond to the databases that store data related to the registration and ownership of internet resources. Whois contains key registration data that can apply to domains, hosts, IP addresses, and IP blocks in Defender EASM. On the Whois data tab, Microsoft provides a robust amount of information associated with the registry of the asset.
:::image type="content" source="media/inventory-14.png" alt-text="Screenshot that shows the Whois Values tab.":::

The following fields are included in the table in the Values section on the Whois tab.
The Change history tab displays a list of modifications that have been applied to an asset over time. This information helps you track these changes over time and better understand the lifecycle of the asset. This tab displays a variety of changes, including but not limited to asset states, labels and external IDs. For each change, we list the user who implemented the change and a timestamp.
:::image type="content" source="media/change-history-1.png" alt-text="Screenshot that shows the Change history tab." lightbox="media/change-history-1.png":::
Related content
@@ -1,33 +1,33 @@ ----title: Understand Asset Details+title: Understand asset details in Microsoft Defender EASM description: Learn how to view and interpret asset details in Microsoft Defender External Attack Surface Management, including the metadata collected for different asset types and how it supports attack surface insights. author: danielledennis ms.author: dandennis ms.service: defender-easm-ms.date: 06/15/2026+ms.date: 07/02/2026 ms.topic: how-to-ms.custom: sfi-image-nochange, msecd-doc-authoring-1014+ms.custom: sfi-image-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted --- -# Understand asset details+# Understand asset details in Microsoft Defender External Attack Surface Management -Microsoft Defender External Attack Surface Management (Defender EASM) frequently scans all inventory assets and collects robust contextual metadata that powers Attack Surface Insights. This data can also be viewed more granularly on the asset details page. The data that's provided changes depending on the asset type. For instance, the platform provides unique Whois data for domains, hosts, and IP addresses. It provides signature algorithm data for Secure Sockets Layer (SSL) certificates.+Microsoft Defender External Attack Surface Management (Defender EASM) frequently scans all inventory assets and collects robust contextual metadata that powers Attack Surface Insights. This contextual metadata can also be viewed more granularly on the asset details page. The data that's provided changes depending on the asset type. For instance, the platform provides unique Whois data for domains, hosts, and IP addresses. The platform provides signature algorithm data for Secure Sockets Layer (SSL) certificates. -This article describes how to view and interpret the expansive data collected by Microsoft for each of your inventory assets. It defines this metadata for each asset type and explains how the insights derived from it can help you manage the security posture of your online infrastructure.+This article describes how to view and interpret the expansive data collected by Microsoft for each of your inventory assets. This article defines the metadata for each asset type and explains how the insights derived from that metadata can help you manage the security posture of your online infrastructure. For more information, see [Understanding inventory assets](understanding-inventory-assets.md) to familiarize yourself with the key concepts mentioned in this article. ## Asset details summary view -You can view the asset details page for any asset by selecting its name from your inventory list. On the left pane of this page, you can view an asset summary that provides key information about that particular asset. The asset summary in the left pane primarily includes data that applies to all asset types, although more fields are available in some cases. For more information on the metadata provided for each asset type in the summary section, see the following chart.+You can view the asset details page for any asset by selecting its name from your inventory list. On the left pane of this page, you can view an asset summary that provides key information about that particular asset. The asset summary in the left pane primarily includes data that applies to all asset types, although more fields are available in some cases. For more information on the metadata provided for each asset type in the summary section, see the [General asset information](#general-information) table. -+:::image type="content" source="media/inventory-1.png" alt-text="Screenshot that shows an asset details page with the summary pane highlighted."::: <a name="general-information"></a> ### General asset information -The General information section includes high-level information that's key to understanding your assets at a glance. Most of these fields apply to all assets. This section can also include information that's specific to one or more asset types.+The General information section includes high-level information that's key to understanding your assets at a glance. Most of these fields apply to all assets. The General information section can also include information that's specific to one or more asset types. | Name | Definition | Asset types | |--|--|--|@@ -54,7 +54,7 @@ The General information section includes high-level information that's key to un | SSL version | The version of SSL that the certificate was registered. | SSL certificate | | Certificate key algorithm | The key algorithm used to encrypt the SSL certificate. | SSL certificate | | Certificate key size | The number of bits in an SSL certificate key. | SSL certificate |-| Signature algorithm OID | The OID that identifies the hash algorithm used to sign the certificate request. | SSL certificate |+| Signature algorithm Object Identifier (OID) | The OID that identifies the hash algorithm used to sign the certificate request. | SSL certificate | | Self-signed | Indicates whether the SSL certificate was self-signed.| SSL certificate | <a name="network"></a>@@ -67,7 +67,7 @@ The following IP address information provides more context about the use of the | Name server record | Any name servers detected on the asset. | IP address | | Mail server record | Any mail servers detected on the asset. | IP address | | IP blocks | The IP block that contains the IP address asset. | IP address |-| ASNs | The ASN associated with an asset. | IP address |+| Autonomous System Numbers (ASNs) | The Autonomous System Number (ASN) associated with an asset. | IP address | <a name="block-information"></a> ### IP block information@@ -76,7 +76,7 @@ The following data is specific to IP blocks and provides contextual information | Name | Definition | Asset types | |--|--|--|-| CIDR | The Classless Inter-Domain Routing (CIDR) for an IP block. | IP block |+| Classless Inter-Domain Routing (CIDR) | The CIDR notation for an IP block. | IP block | | Network name | The network name associated to the IP block. | IP block | | Organization name | The organization name found in the registration information for the IP block. | IP block | | Org ID | The organization ID found in the registration information for the IP block. | IP block |@@ -113,28 +113,29 @@ The following data is specific to the issuer of an SSL certificate. <a name="data-tabs"></a> ## Understand the data tabs -On the rightmost pane of the asset details page, users can access more expansive data related to the selected asset. This data is organized in a series of categorized tabs. The available metadata tabs change depending on the type of asset you're viewing.+On the rightmost pane of the asset details page, users can access more expansive data related to the selected asset. The asset data in this pane is organized in a series of categorized tabs. The available metadata tabs change depending on the type of asset you're viewing. Certain tabs display a **Recent only** toggle in the upper-right corner. By default, Defender EASM displays all data that we've collected for each asset, including historical observations that may not be actively running on your current attack surface. While this historical context is very valuable for certain use cases, the **Recent only** toggle limits all results on the Asset Details page to those most recently observed on the asset. We recommend that you use the **Recent only** toggle when you only wish to view data that represents the current state of the asset for remediation purposes. -+:::image type="content" source="media/inventory-1b.png" alt-text="Screenshot that highlights the Recent only toggle from the Overview page of Asset Details."::: -### Overview+<a name="overview"></a>+### Overview tab -The **Overview** tab provides more context to ensure that significant insights are quickly identifiable when you view the details of an asset. This section includes key discovery data for all asset types. It provides insight about how Microsoft maps the asset to your known infrastructure.+The **Overview** tab provides more context to ensure that significant insights are quickly identifiable when you view the details of an asset. The Overview tab includes key discovery data for all asset types. The Overview tab provides insight about how Microsoft maps the asset to your known infrastructure. The Overview tab can also include dashboard widgets that visualize insights that are relevant to the asset type in question. -+:::image type="content" source="media/inventory-2.png" alt-text="Screenshot that shows the asset details page Overview pane."::: <a name="discovery-chain"></a> ### Discovery chain data -The discovery chain outlines the observed connections between a discovery seed and the asset. This information helps users visualize these connections and better understand why an asset was determined to belong to their organization.+The discovery chain outlines the observed connections between a discovery seed and the asset. Discovery chain information helps users visualize these connections and better understand why an asset was determined to belong to their organization. In the example, you can see that the seed domain is tied to this asset through the contact email in its Whois record. That same contact email was used to register the IP block that includes this particular IP address asset. -+:::image type="content" source="media/inventory-3.png" alt-text="Screenshot that shows the discovery chain."::: <a name="discovery-information"></a> ### Discovery information tab@@ -150,52 +151,52 @@ Options include: <a name="ip-reputation"></a> ### IP reputation tab -The **IP reputation** tab displays a list of potential threats related to a given IP address. This section outlines any detected malicious or suspicious activity that relates to the IP address. This information is key to understanding the trustworthiness of your own attack surface. These threats can help organizations uncover past or present vulnerabilities in their infrastructure.+The **IP reputation** tab displays a list of potential threats related to a given IP address. This section outlines any detected malicious or suspicious activity that relates to the IP address. IP reputation data is key to understanding the trustworthiness of your own attack surface. These threats can help organizations uncover past or present vulnerabilities in their infrastructure. -The Defender EASM IP reputation data displays instances when the IP address was detected on a threat list. For instance, the recent detection in the following example shows that the IP address relates to a host known to be running a cryptocurrency miner. This IP reputation entry was derived from a suspicious host list supplied by CoinBlockers. Results are organized by the **Last seen** date to show the most relevant detections first.+The Defender EASM IP reputation data displays instances when the IP address was detected on a threat list. For instance, the recent detection in the following example shows that the IP address relates to a host known to be running a cryptocurrency miner. The cryptocurrency-miner detection in this example was derived from a suspicious host list supplied by CoinBlockers. Results are organized by the **Last seen** date to show the most relevant detections first. -In this example, the IP address is present on an abnormally high number of threat feeds. This information indicates that the asset should be thoroughly investigated to prevent malicious activity in the future.+In the IP reputation screenshot, the IP address is present on an abnormally high number of threat feeds. The unusually high number of threat-feed detections indicates that the asset should be thoroughly investigated to prevent malicious activity in the future. -+:::image type="content" source="media/inventory-4.png" alt-text="Screenshot that shows the asset details page IP reputation tab."::: <a name="services"></a> ### Services tab -The **Services** tab is available for IP address, domain, and host assets. The Services tab provides information on services observed to be running on the asset. It includes IP addresses, name and mail servers, and open ports that correspond with other types of infrastructure (for example, remote access services).+The **Services** tab is available for IP address, domain, and host assets. The Services tab provides information on services observed to be running on the asset. The Services tab includes IP addresses, name and mail servers, and open ports that correspond with other types of infrastructure (for example, remote access services). Defender EASM's services data is key to understanding the infrastructure that powers your asset. It can also alert you to resources that are exposed on the open internet that should be protected. -+:::image type="content" source="media/inventory-5.png" alt-text="Screenshot that shows the asset details page Services tab."::: <a name="ip-addresses"></a> ### IP addresses section The IP addresses section provides insight on any IP addresses that are running on the asset's infrastructure. On the **Services** tab, Defender EASM provides the name of the IP address and the **First seen** and **Last seen** dates. The **Recent** column indicates whether the IP address was observed during the most recent scan of the asset. If there's no checkbox in this column, the IP address was seen in prior scans, but it isn't currently running on the asset. -+:::image type="content" source="media/inventory-6.png" alt-text="Screenshot that shows the asset details page IP address section of the Services tab."::: <a name="mail-servers"></a> ### Mail servers section -The Mail servers section provides a list of any mail servers that are running on the asset. This information indicates that the asset is capable of sending emails. In this section, Defender EASM provides the name of the mail server and the **First seen** and **Last seen** dates. The **Recent** column indicates whether the mail server was detected during the most recent scan of the asset.+The Mail servers section provides a list of any mail servers that are running on the asset. The presence of mail servers indicates that the asset is capable of sending emails. In this section, Defender EASM provides the name of the mail server and the **First seen** and **Last seen** dates. The **Recent** column indicates whether the mail server was detected during the most recent scan of the asset. -+:::image type="content" source="media/inventory-7.png" alt-text="Screenshot that shows the asset details page Mail server section of the Services tab."::: <a name="name-servers"></a> ### Name servers section The Name servers section displays any name servers that are running on the asset to provide resolution for a host. In this section, Defender EASM provides the name of the mail server and the **First seen** and **Last seen** dates. The **Recent** column indicates whether the name server was detected during the most recent scan of the asset. -+:::image type="content" source="media/inventory-8.png" alt-text="Screenshot that shows the asset details page Name server section of the Services tab."::: <a name="open-ports"></a> ### Open ports section -The Open ports section lists any open ports detected on the asset. Microsoft regularly scans around 230 distinct ports. This data is useful to identify any unsecured services that shouldn't be accessible from the open internet. These services include databases, IoT devices, and network services like routers and switches. It's also helpful in identifying shadow IT infrastructure or insecure remote access services.+The Open ports section lists any open ports detected on the asset. Microsoft regularly scans around 230 distinct ports. This data is useful to identify any unsecured services that shouldn't be accessible from the open internet. Examples of unsecured services include databases, IoT devices, and network services like routers and switches. It's also helpful in identifying shadow IT infrastructure or insecure remote access services. In this section, Defender EASM provides the open port number, a description of the port, the last state it was observed in, and the **First seen** and **Last seen** dates. The **Recent** column indicates whether the port was observed as open during the most recent scan. Defender EASM considers a port **open** when our system can successfully complete a syn-ack handshake that results in attributed banners. When we can establish a TCP connection but are unable to complete our service fingerprinting, we mark the port as **filtered**. A **closed** port is still accessible but there is no service listening on the port and thus denies connections. -+:::image type="content" source="media/inventory-9.png" alt-text="Screenshot that shows the asset details page Open ports section of the Services tab."::: <a name="trackers"></a> ### Trackers tab@@ -209,9 +210,9 @@ In the Trackers section, Defender EASM provides the tracker type (for example, G Web components are details that describe the infrastructure of an asset as observed through a Microsoft scan. These components provide a high-level understanding of the technologies used on the asset. Microsoft categorizes the specific components and includes version numbers when possible. -+:::image type="content" source="media/inventory-10.png" alt-text="Screenshot that shows the top of the Web components tab."::: -The **Web components** section provides the category, name, and version of the component and a list of any applicable CVEs that should be remediated. Defender EASM also provides **First seen** and **Last seen** date columns and a **Recent** column. A checked box indicates that this infrastructure was observed during the most recent scan of the asset.+The **Web components** section provides the category, name, and version of the component and a list of any applicable Common Vulnerabilities and Exposures (CVEs) that should be remediated. Defender EASM also provides **First seen** and **Last seen** date columns and a **Recent** column. A checked box indicates that this infrastructure was observed during the most recent scan of the asset. Web components are categorized based on their function. @@ -243,48 +244,48 @@ For more information on observations, see [Understanding dashboards](understandi The **Observations** tab features two tables: **Observations** and **Non-applicable observations**. All active observations determined to be **recent** within your attack surface will be in the **Observations** table, whereas the **Non-applicable observations** table lists any observations that have either been manually marked as non-applicable or were determined by the system to no longer be applicable. To mark observations as non-applicable and therefore exclude that particular observation from dashboard counts, simply select the desired observations and select **Set as non-applicable**. The observation(s) will immediately disappear from the active **Observations** table and will instead appear on the **Non-applicable observations** table. You can revert this change at any time by selection the relevant observation(s) from this table and selecting **Set as applicable**. - +:::image type="content" source="media/cves-3.png" alt-text="Screenshot that shows the Observations tab with multiple CVEs selected to be marked as non-applicable."::: <a name="connected-assets"></a> ### Connected assets tab -Connected Assets empowers users to graphically link and gather information about assets for investigative analysis. You can explore your environment and its intricate relationships through relationship mappings, which offer clear and concise views. This helps you identify hidden connections and potential attack paths. By visually mapping out the relationships between assets and vulnerabilities, you can comprehend your environment's complexity and make well-informed decisions to enhance your security posture and apply choke points effectively. +Connected Assets empowers users to graphically link and gather information about assets for investigative analysis. You can explore your environment and its intricate relationships through relationship mappings, which offer clear and concise views. These relationship mappings help you identify hidden connections and potential attack paths. By visually mapping out the relationships between assets and vulnerabilities, you can comprehend your environment's complexity and make well-informed decisions to enhance your security posture and apply choke points effectively. -[](media/connected-1.png#lightbox)+:::image type="content" source="media/connected-1.png" alt-text="Screenshot that shows the Connected assets tab." lightbox="media/connected-1.png"::: -On the Connected assets tab, all the assets that are connected to the specified asset are identified in a list. The list provides key information about each policy including:+On the **Connected assets** tab, all the assets that are connected to the specified asset are identified in a list. The list provides key information about each connected asset, including: -- **Asset:** The identified connected asset.-- **Kind:** The type of asset.-- **State:** The state of the asset.-- **Labels:** Any labels associated with the asset.-- **First Seen:** When the asset was first discovered.-- **Last Seen:** When the asset was last identified.+- **Asset**: The identified connected asset.+- **Kind**: The type of asset.+- **State**: The state of the asset.+- **Labels**: Any labels associated with the asset.+- **First Seen**: When the asset was first discovered.+- **Last Seen**: When the asset was last identified. From the Connected assets tab, you can modify or remove connected assets. You can also sort or filter the asset list to further categorize the list of connected assets. You can also download a CSV report of the listed assets. Any filters applied will be reflected on the CSV export. <a name="resources"></a> ### Resources tab -The **Resources** tab provides insight on any JavaScript resources running on any page or host assets. When applicable to a host, these resources are aggregated to represent the JavaScript running on all pages on that host. The Resources tab provides an inventory of the JavaScript detected on each asset so that your organization has full visibility into these resources and can detect any changes.+The **Resources** tab provides insight on any JavaScript resources running on any page or host assets. When applicable to a host, the detected JavaScript resources are aggregated to represent the JavaScript running on all pages on that host. The Resources tab provides an inventory of the JavaScript detected on each asset so that your organization has full visibility into these resources and can detect any changes. -Defender EASM provides the resource URL, resource host, MD5 value, and first-seen and last-seen dates to help organizations effectively monitor the use of JavaScript resources across their inventory.+Defender EASM provides the resource URL, resource host, MD5 (Message-Digest Algorithm 5) hash value, and first-seen and last-seen dates to help organizations effectively monitor the use of JavaScript resources across their inventory. -+:::image type="content" source="media/inventory-12.png" alt-text="Screenshot that shows the Resources tab."::: <a name="ssl-certificates"></a> ### SSL certificates tab Certificates are used to secure communications between a browser and a web server via SSL. use of certificates ensures that sensitive data in transit can't be read, tampered with, or forged. The SSL certificates tab in Defender EASM lists any SSL certificates detected on the asset, including key data like the issue and expiry dates. -+:::image type="content" source="media/inventory-13.png" alt-text="Screenshot that shows the SSL certificates tab."::: <a name="whois"></a> ### Whois tab The Whois protocol is used to query and respond to the databases that store data related to the registration and ownership of internet resources. Whois contains key registration data that can apply to domains, hosts, IP addresses, and IP blocks in Defender EASM. On the **Whois** data tab, Microsoft provides a robust amount of information associated with the registry of the asset. -+:::image type="content" source="media/inventory-14.png" alt-text="Screenshot that shows the Whois Values tab."::: The following fields are included in the table in the **Values** section on the **Whois** tab. @@ -311,9 +312,9 @@ Many organizations opt to obfuscate their registry information. Sometimes contac The **Change history** tab displays a list of modifications that have been applied to an asset over time. This information helps you track these changes over time and better understand the lifecycle of the asset. This tab displays a variety of changes, including but not limited to asset states, labels and external IDs. For each change, we list the user who implemented the change and a timestamp. -[ ](media/change-history-1.png#lightbox)+:::image type="content" source="media/change-history-1.png" alt-text="Screenshot that shows the Change history tab." lightbox="media/change-history-1.png"::: ## Related content -- [Understand dashboards](understanding-dashboards.md)-- [Use and manage discovery](using-and-managing-discovery.md)+- [Understand Defender EASM dashboards](understanding-dashboards.md)+- [Use and manage Defender EASM discovery](using-and-managing-discovery.md) 