Skip to content
SecPod  – Documentation
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO
  • Toggle website search
Search this website
Menu Close
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO
  • Toggle website search
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO

Saner Platform

  • Saner Platform Release Notes
    • Saner Platform Integration Release: ServiceNow Integration Introduced, Freshservice Enhanced
    • Release Notes Saner 6.4.1
    • Release Notes SanerNow 6.4
    • Release Notes SanerNow 6.3.1
    • Release Notes SanerNow 6.3
    • Release Notes SanerNow 6.2.1
    • Release Notes SanerNow 6.2.0.3
    • Release Notes SanerNow 6.2.0.1
    • Release Notes SanerNow 6.2
    • Release Notes SanerNow 6.1.1
    • Release Notes SanerNow 6.1
    • Release Notes SanerNow 6.0
    • Release Notes SanerNow 5.3.1
    • Release Notes SanerNow 5.3
    • Release Notes SanerNow 5.2
    • Release Notes SanerNow 5.1
    • Release Notes SanerNow 5.0
    • Release Notes SanerNow 4.8.0.0
    • Release Notes SanerNow 4.7.0.0
    • Release Notes SanerNow 4.6.0.0
    • Release Notes SanerNow 4.5.0.0
    • Release Notes SanerNow 4.4.0.0
    • Release Notes SanerNow 4.3.0.0
    • Release Notes SanerNow 4.2.2.1
    • Release Notes SanerNow 4.2.2.0
    • Release Notes SanerNow 4.2.1.0
    • Release Notes SanerNow 4.2.0.0
    • Release Notes SanerNow 4.1.1.0
    • Release Notes SanerNow 4.0.0.5
  • Saner Platform Guide
    • Saner Administration Guide
    • Saner Device Management User Guide
    • Saner Platform and ServiceNow Integration Guide
    • Saner Platform and Freshservice Integration Guide
    • Saner Platform Function Guides
  • FAQs
    • Saner CVEM Technical FAQs
  • How Tos
    • General
      • How to increase the subscription count for an Account in Saner CVEM
      • How to increment license count for an Organization in Saner CVEM
      • How to provision Saner tools for an Organization
      • How to change subscription type in Saner CVEM
      • How to sign-up with Saner CVEM?
      • How to create a new account in Saner CVEM?
      • How to enable SSO authentication policy in Saner CVEM?
      • How to set alerts in Saner?
      • How to view, download and filter the audit logs?
      • How to designate Saner Agent to perform network scan?
      • How to Co-Brand with your logo?
      • How to fetch the details of the mandatory fields from the Okta account?
      • How to create MFA policy for Okta?
      • How to fetch the details of the mandatory fields from the PingID account?
      • How to create MFA policy for PingID?
      • How to fetch the details of the mandatory fields from the PingOne account?
      • How to create MFA policy for PingOne?
      • How to download and install Saner Agent in Mac?
      • How to download and install Saner agent in Linux?
      • How to download and install the Saner agent in Windows?
      • How to update the expiry date of an existing subscription?
      • How to manage users and their preferences using role-based access?
      • How to uninstall Saner Agent using Saner Offline deployer tool.
      • How to onboard a new organization?
      • How to deploy Saner Agent using Saner Offline deployer tool.
      • How to install a Saner agent through the command line?
      • How to uninstall the Saner agent through command line?
    • Saner Reports
      • How to configure mail settings to email Report PDF?
      • How to create a custom report in Saner?
      • How to schedule for the report back up?
    • Saner Device Management
      • How to create custom groups in Saner CVEM
    • Saner Mail Settings
      • How to create new mail settings in Saner?
      • How to use OAuth-enabled authentication in Saner mail settings
      • How to create OAuth Client ID and Client Secret for Gmail
      • How to create OAuth Client ID and Client Secret for Microsoft 365.
  • Supported OSs and Platforms
    • Operating Systems and Platforms Supported
    • Supported Third-party Applications for Patching

Saner Cloud

  • Before You Begin
    • Glossary of Terms
    • Read me First
  • Get Started
    • Prerequisites For Saner SaaS Platform Deployment
    • Saner Cloud Deployment Guides
      • GCP OAuth Scopes for Saner CNAPP
      • Onboarding a GCP Organization to Saner Cloud(CLI)
      • Onboarding a GCP Project to Saner Cloud (CLI)
      • Onboarding a GCP Organization to Saner Cloud(Manual)
      • Onboarding a GCP Project to Saner Cloud(Manual)
      • Azure Onboarding
      • Troubleshooting
      • Get Started with Saner CNAPP AWS Cloud Deployment V1.0
      • Onboarding with AWS Credentials(Least Recommended Method)
      • Onboarding with AWS Role(Manual)
      • Onboarding with AWS Role CloudFormation (Automatic): Recommended
    • Roles and Permissions
      • Roles and Permissions for AWS Remediation Access
      • Roles and Permissions for Azure Onboarding, Detection, and Remediation
      • Roles and Permissions for GCP Project-level Detection and Remediation Access
      • Roles and Permissions for GCP Organization-level Detection and Remediation Access
    • Saner COSP Deployment Guides
      • Onboarding K8s Cluster to Saner COSP
      • Onboarding K8s Cluster to Saner COSP Through OIDC Protocol
  • Learn About
    • Saner CNAPP Best Practices
    • Secure Your IAM entities with Cloud Infrastructure Entitlement Management (CIEM)
    • Critical Events to Monitor in GCP
    • Saner CSRP Classification Based on Scoring Decision
    • Cloud Cyber Hygiene Scoring(CCHS) Approach
    • Remediation Rollback
    • Automation and Job-driven Remediation
    • Cost and Usage
    • Excessive Permission Categories Evaluated Across Different Cloud Services
    • Publicly Accessible Resources
    • Patch Aging and Patch Impact
    • SecPod Default Benchmarks
    • Watchlists
    • Cloud Workload Protection Platform(CWPP)
    • Overview of Report Views in Saner Cloud
    • Whitelisting Resources
    • Saner Plasma AI Assistant for Seamless User Interaction
    • Critical Events to Monitor in AWS
    • High-Privilege Actions in Critical Activity Logs for AWS
    • Audit Logs in Saner Cloud
    • Excessive Permissions
    • Alerts in SanerCloud
  • Tell Me How
    • How to Remediate in Saner Cloud?
    • How to Configure Automation Rule to Remediate Misconfigurations?
    • How to Manage Report Views at Organization-level in Saner Cloud?
    • How to Get a Cohesive View from Saner Cloud Unified Dashboard?
    • How to Use Tags to Quickly Filter Resources?
    • How to Troubleshoot Issues with Audit Logs?
    • How to Manage Groups and Tags in Saner Cloud?
    • How to Manage Report Views for a User Account in Saner Cloud?
    • How to Troubleshoot or Analyze with Critical Activity Logs?
    • How to Setup Alerts Across SanerCloud Tools?
    • How to Take Action on Alert Notifications from SanerCloud?
    • How to Remediate Findings in Saner COSP?
    • How to Rollback an Applied Remediation in Saner COSP?
    • How to Configure Automation Rules for COSP Misconfiguration Remediation?
    • CCHS
      • How to Monitor Resource Risk Trends for CHS?
      • How to Assess Resource Health through Severity Distribution?
      • How to Evaluate Service-Level Risks Using CHS Scores?
      • How to Analyze Cyber Hygiene Scores through Trend Chart?
      • How to Identify High-Risk Resources by Geo Location?
      • How to Get an Overview of Cyber Hygiene for Cloud Resources?
      • How to Review Organization-Level Cyber Hygiene Across Accounts?
      • How to Assess Risk Distribution for Different Cloud Providers?
      • How to Review Major Issues Contributing to the Drop of Cyber Hygiene Score at Account-Level?
      • How to Analyze Module-wise Risk through CHS Distribution?
      • How to View the Cyber Hygiene Score Distributed Across Cloud Environments?
      • How to Track Security Posture with Cyber Hygiene Score?
      • How to Configure Account Weightage?
    • CSRP
      • How to Monitor and Analyze Audit Logs for Risk Prioritization?
      • How to Configure Risk Based Cloud Security Alerts?
      • How to Generate Reports and Visualizations?
      • How to Filter Risks by Tags for Targeted Analysis?
      • How to Manage Prioritized Risks at Account-level?
      • How to View the Detailed Breakdown of a Specific Cloud Cyber Security Standard (CCSS) Risk Finding?
      • How to Review and Prioritize Resources Based on Associated Risks?
      • How to Assess Risk Distribution on Essential Resources?
      • How to Assess and Prioritize Risks Across Resource Categories?
      • How to Identify the Risks Affecting Essential Resources?
      • How to Assess Full Versus Limited Technical Impact of Exploiting an Anomaly?
      • How to Review the Risk Factor Distribution Based on Automatable Reliability?
      • How to Get an Overview of Exploitable Risks?
      • How to Map Risks to MITRE ATT&CK for Threat-Informed Defense?
      • How to Configure Questionnaire and Assess Security Practices Across Core Domains for an Account?
    • CSAE
      • How to Setup Watchlist Configuration for a Resource?
      • How to Identify Outdated Resources for Cleanup?
      • How does Resource Categorization Work in Saner CSAE?
      • How to Identify Resources Exposed to External Network?
      • How to Understand the Resource Footprint Globally Across Various Regions?
      • How to Make Informed Decisions on Your Expenditure based on Resource Usage Graph?
    • CSPM
      • How to Setup Benchmarks in Saner CSPM?
      • How to Use Quick Evaluation Benchmarks?
      • How to Detect Patterns over a Period with Resource Trends?
      • How to Assess System Compliance and Security Posture?
    • CSPA
      • How to Initiate Patch Remediation from CSPA Dashboard?
      • How to Quickly Identify the Detected and Remediated Anomalies for an Account?
      • How to Prioritize Remediation or Fixes based on Confidence Levels?
      • How to Examine the Overall Anomaly Information for Specific Rules or Checks?
      • How to Search and Retrieve Anomaly Data?
      • How to Whitelist Rules or Resources in Cloud Security Scans?
    • CIEM
      • How to See the Active Version for an IAM Policy?
      • How to Address Critical Activities Using Evidence?
      • How to View by Type and Usage for any Identity in CIEM?
      • How to Get Visibility into Cloud Entitlements?
      • How to Use Evidence to Address Policies with Excessive Permission?
      • How to Know the Excessive Permissions on a Specific Service?
      • How to Visually See the Relationship between Identity, Entitlement, Policy, or Permission?
      • How to Determine if a Policy has Excessive Permission?
      • How to Initiate Remediation for Different Identities from CIEM?
    • CSRM
      • Rollback an Applied Remediation
      • How to Configure Automation Rule to Remediate Misconfigurations?
      • How to Create a Patching Task for Items Currently in “Approval Pending” State?
      • How to Evaluate Remediation Effort with Patching Impact Chart?
      • How to Prioritize and Address Older or High-Risk Anomalies with Patch Aging?
      • How to Monitor the Overall Status of the Remediation Job?
      • How do I Get to Know the Regions Impacted by a Specific Rule?
      • How to View the Severity of a Missing Patch Affected by a Rule?
      • How to Address Missing Patches Via Remediation Tasks?
      • How to Quickly Access the Necessary Tool for Remediation and Begin Patching Tasks?
  • Saner Cloud User Guides
    • GCP Cloud Infrastructure Entitlement Management (CIEM) User Guide
    • Azure Cloud Infrastructure Entitlement Management(CIEM) User Guide
    • Cloud Security Risk Prioritization(CSRP) User guide
    • Cloud Cyber Hygiene Score(CCHS) User Guide
    • Cloud Security Remediation Management(CSRM) User Guide
    • AWS Cloud Infrastructure Entitlement Management(CIEM) User Guide
    • Cloud Security Posture Anomaly(CSPA) User Guide
    • Cloud Security Asset Exposure(CSAE) User Guide
    • Cloud Security Posture Management(CSPM) User Guide
  • Saner Cloud Release Notes
    • Saner Cloud – V.3.0.1.1 Release Notes
    • Saner Cloud – V.3.0.1.0 Release Notes
    • Saner Cloud – V.3.0.0.0 Release Notes
    • Saner Cloud – V.2.0.0.2 Release Notes
    • Saner Cloud – V.2.0.0.1 Release Notes
    • Saner Cloud – V.2.0.0.0 Release Notes
    • Saner Cloud – V.1.2.0.1 Release Notes
    • Saner Cloud – V.1.2.0.0 Release Notes
    • Saner Cloud – V.1.1.0.0 Release Notes
    • Saner Cloud – V.1.1 Release Notes
    • Saner Cloud – V.1.0 Release Notes
  • Saner COSP User Guides
    • Container Orchestration Security Platform (COSP) User Guide
    • Container Orchestration Asset Exposure(COAE) User Guide
    • Container Orchestration Posture Management(COPM) User Guide
    • Container Orchestration Posture Anomaly(COPA) Userguide
    • Container Orchestration Entitlement Management(COEM) Userguide
    • Container Orchestration Remediation Management(CORM) User Guide
  • Saner COSP Release Notes
    • Saner COSP – V.1.0.0.0 Release Notes
  • Frequently Asked Questions
    • Saner COSP Technical FAQs
    • Saner Cloud Technical FAQs

Saner CVEM

  • Saner CVEM Release Notes
    • Release Notes Saner CVEM 6.6.1
    • Release Notes Saner CVEM 6.6
    • Release Notes Saner 6.5
    • Saner Platform Integration Release: ServiceNow Integration Introduced, Freshservice Enhanced
    • Release Notes Saner 6.4.1
    • Release Notes SanerNow 6.4
    • Release Notes SanerNow 6.3.1
    • Release Notes SanerNow 6.3
    • Release Notes SanerNow 6.2.1
    • Release Notes SanerNow 6.2.0.3
    • Release Notes SanerNow 6.2.0.1
    • Release Notes SanerNow 6.2
    • Release Notes SanerNow 6.1.1
    • Release Notes SanerNow 6.1
    • SanerNow Risk Prioritization Launch
    • Release Notes SanerNow 6.0
    • Release Notes SanerNow 5.3.1
    • Release Notes SanerNow 5.3
    • Release Notes SanerNow 5.2
    • Release Notes SanerNow 5.1
    • Release Notes SanerNow 5.0
    • Release Notes SanerNow 4.8.0.0
    • Release Notes SanerNow 4.7.0.0
    • Release Notes SanerNow 4.6.0.0
    • Release Notes SanerNow 4.5.0.0
    • Release Notes SanerNow 4.4.0.0
    • Release Notes SanerNow 4.3.0.0
    • Release Notes SanerNow 4.2.2.1
    • Release Notes SanerNow 4.2.2.0
    • Release Notes SanerNow 4.2.1.0
    • Release Notes SanerNow 4.2.0.0
    • Release Notes SanerNow 4.1.1.0
    • Release Notes SanerNow 4.0.0.5
    • Saner CVEM
      • Release Notes Saner CVEM 6.6
  • Saner CVEM Guide
    • Prerequisites For Saner SaaS Platform Deployment
    • What’s New in Saner CVEM?
    • Getting Started with Saner CVEM
    • Pre-requisites for Saner CVEM Deployment
    • How does Saner CVEM’s deployment architecture work?
  • Saner CVEM Products
    • Overview of Saner Continuous Vulnerability and Exposure Management
    • Saner CVEM Unified Dashboard User Guide
    • Saner CVEM Asset Exposure User Guide
    • Saner CVEM Continuous Posture Anomaly Management User Guide
    • Data Points IT teams can Fetch from Saner CPAM
    • Posture Anomaly Computation Rules
    • Saner CVEM Vulnerability Management User Guide
    • Saner CVEM Compliance Management User Guide
    • Saner CVEM Risk Prioritization User Guide
    • Saner CVEM Patch Management User Guide
    • Saner CVEM Endpoint Management User Guide
    • Saner CVEM Remote Scripting User Guide
    • Saner CVEM Remote Access User Guide
    • Saner CVEM Network Scanner User Guide
    • Saner CVEM Cyber Hygiene Score User Guide
  • How Tos
    • Saner AE
      • How to blacklist and whitelist applications in Saner AE?
      • How to manage asset licenses using Saner AE?
      • How to run an asset scan using Saner AE?
    • Saner CPAM
      • How to create new response in PA tool?
      • How to build your own detection and response in PA tool?
      • How to whitelist an entire PA ID?
      • How to configure Posture Anomaly tool for custom detection?
      • How to fix Anomalies from PA dashboard?
      • How to fix anomalies detected in your account from All Anomalies Page?
      • How to fix anomalies from PA Summary page?
      • How to delete PA scan preferences?
      • How to schedule PA Scans on Daily, Weekly, and Monthly basis?
      • How to launch Posture Anomaly scans?
    • Saner VM
      • How to automate and schedule vulnerability scans?
      • How to exclude vulnerabilities in Saner VM tool
      • How to manage excluded vulnerabilities in Saner VM?
      • How to remediate vulnerabilities from vulnerability management dashboard?
    • Saner CM
      • How to run a compliance scan?
      • How to custom create a security policy?
      • How to align with PCI security compliance management?
      • How to align with NIST 800-171 security compliance management?
      • How to align with NIST 800-53 security compliance management?
      • How to align with HIPAA security compliance management using Saner CM?
    • Saner PM
      • How to fix firmware in Saner?
      • How to exclude patches in Saner PM?
      • How to manage excluded patches in Saner PM?
      • How to automate patch management in Saner PM?
      • How to roll back patches in Saner PM?
      • How to apply missing patches in Saner PM?
      • How to apply the most critical patches in Saner PM?
      • How to perform custom remediation for applications that require paid patches using Saner PM
      • How to check the status of patching activity?
    • Saner EM
      • How to collect all security events from Windows Events Log?
      • How to check password policy set in Windows systems?
      • How to check status of DEP in Windows systems?
      • How to check faulty Anti-Virus (AV) status in Windows systems?
      • How to check for Anti-Virus (AV) status in Windows systems?
      • How to check account lockout policy on Windows systems?
      • How to check if Bit-locker protection is OFF in Windows systems?
      • How to list all inactive users on Windows systems?
      • How to list all guest accounts in Windows systems?
      • How to list all Administrator accounts on Windows systems?
      • How to list last-logon details of users on Windows systems?
      • How to identify all users in Windows systems?
      • How to collect all services that are currently running in Windows systems?
      • How to list all Groups in Windows systems?
      • How to collect all keyboard and pointing devices connected to Windows systems?
      • How to collect all storage devices connected to Windows systems?
      • How to investigate total RAM or CPU threshold (greater than or equal to 80%) in Windows systems?
      • How to collect operating systems information in Windows?
      • How to investigate disks running out of space (<100 MB) in Windows systems?
      • How to collect and investigate disk information on Windows systems?
      • How to collect all installed patches in Windows systems?
      • How to collect all software patches that are hidden in the Windows Update server?
      • How to check the status of Windows Update Server (WSUS/SCCM)?
      • How to collect BIOS information such as serial number, version, manufacturer in Windows systems?
      • How to collect all the important missing patches in Windows systems?
      • How to check wireless security in Linux systems?
      • How to collect mounted disk information on Linux systems?
      • How to check wireless signal quality in Linux systems?
      • How to check all firewall policies on Linux systems?
      • How to collect all Dynamic Host Configuration Protocol (DHCP) information on Linux systems?
      • How to collect DNS information on Linux systems?
      • How to collect ARP entries that are created when a hostname is resolved to an IP address and then to a MAC addressing in Linux?
      • How to check wireless signal quality in Windows systems?
      • How to check wireless security in Windows systems?
      • How to collect all open ports in Windows systems?
      • How to collect all network interfaces in Windows systems?
      • How to investigate DNS cache on Windows systems?
      • How to check all firewall policies on Windows systems?
      • How to collect DNS information on Windows systems?
      • How to collect all the applications with an unknown publisher in Linux systems?
      • How to perform system tuning?
      • How to collect all software licenses in Windows systems?
      • How to identify potentially unwanted programs such as torrent downloaders or unnecessary toolbars running on Windows systems?
      • How to collect a list of applications that are started when you boot your computer?
      • How to collect all the applications with an unknown publisher in Windows systems?
      • How to collect all software licenses in Mac systems?
      • How to collect ARP entries that are created when a hostname is resolved to an IP address and then to a MAC addressing Windows?
      • How to collect all families of operating systems such as Windows, Unix, and macOS?
      • How to collect environment variables set in all operating systems?
      • How to collect all the applications with an unknown publisher in Mac systems?
      • How to delete and quarantine a file?
      • How to start and stop the processes in Saner?
      • How to block blacklisted applications in Saner?
      • How to enable/disable devices in Saner
      • How to manually import devices into Saner?
      • How to deploy software in Saner EM?
      • How to enable and disable firewall settings in Saner AE?
      • How to collect all shared resources on Windows systems?
      • How to collect all Dynamic Host Configuration Protocol (DHCP) information on Windows systems?
      • How to connect to a client machine graphically using Saner Remote Access
  • FAQs
    • Saner CVEM Technical FAQs

Security Intelligence for Saner CVEM

  • Overview of Security Content and Intelligence
  • Security Content Statistics
  • OVAL Definitions Platform Coverage
  • OVAL Definitions Class-wise Distribution
  • OVAL Definitions Family-wise Distribution
  • Application and OS Remediation Coverage
  • Compliance Benchmark Coverage
  • List of Vulnerability to Exploit/Malware Mapping covered in Saner
  • Network Scanner Product Support Matrix
  • Privilege levels for authenticated scans using Saner Network Scanner

Security Intelligence for Saner Cloud

  • Benchmark Compliance Rules in AWS, Azure, and GCP
    • GCP
      • SecPod Rules in GCP
        • SecPod Default Rules in GCP: An Overview
        • Understand SecPod Default Rules in GCP
        • Understand SecPod Global Rules in GCP
        • Understand SecPod Regional Rules in GCP
      • CIS Rules in GCP
        • CIS Benchmark Compliance Rules in GCP: An Overview
        • Understand CIS 4.0.0 Rules in GCP
        • Understand CIS 4.0.0 Global Rules in GCP
        • Understand CIS 4.0.0 Regional Rules in GCP
    • AWS
      • SecPod Rules in AWS
        • SecPod Default Rules in AWS: An Overview
        • Understand SecPod Default Rules in AWS
        • Understand SecPod Global Rules in AWS
        • Understand SecPod Regional Rules in AWS
      • PCI DSS 3.2.1 Rules in AWS
        • PCI DSS 3.2.1 Rules in AWS: An Overview
        • Understand PCI DSS 3.2.1 Rules in AWS
        • Understand PCI DSS 3.2.1 Global Rules in AWS
        • Understand PCI DSS 3.2. 1 Regional in AWS
      • CIS Rules in AWS
        • CIS Rules in AWS: An Overview
        • Understand CIS Rules in AWS
        • Understand CIS 3.0.0 Rules in AWS
        • Understand CIS 4.0.1 Rules in AWS
        • Understand CIS 4.0.0 Rules in AWS
        • Understand CIS 3.0.0 Global Rules in AWS
        • Understand CIS 4.0.0 Global Rules in AWS
        • Understand CIS 3.0.0 Regional Rules in AWS
        • Understand CIS 4.0.0 Regional Rules in AWS
      • SOC 2 Rules in AWS
        • SOC 2 Rules in AWS: An Overview
        • Understand SOC 2 Rules in AWS
        • Understand SOC 2 Global Rules in AWS
        • Understand SOC 2 Regional Rules in AWS
      • HIPAA HITRUST Rules in AWS
        • HIPAA HITRUST Rules in AWS: An Overview
        • Understand HIPAA HITRUST Rules in AWS
        • Understand HIPAA HITRUST Global Rules in AWS
        • Understand HIPAA HITRRUST Regional Rules in AWS
      • NIST 800-53 Revision 5 Rules in AWS
        • NIST 800-53 Revision 5 Rules in AWS: An Overview
        • Understand NIST 800-53 Revision 5 Rules in AWS
        • Understand NIST 800-53 Revision 5 Global Rules in AWS
        • Understand NIST 800-53 Revision 5 Regional Rules in AWS
    • Azure
      • CIS Rules in Azure
        • CIS Rules in Azure: An Overview
        • Understand CIS 1.2.0 Rules in Azure
        • Understand CIS 2.1.0 Rules in Azure
        • Understand CIS 1.1.0 Benchmark Compliance Rules in Azure
        • Understand CIS 3.0.0 Benchmark Compliance Rules in Azure
        • Understand CIS 1.2.0 Global Benchmark Compliance Rules in Azure
        • Understand CIS 2.1.0 Global Benchmark Compliance Rules in Azure
        • Understand CIS 3.0.0 Global Benchmark Compliance Rules in Azure
        • Understand CIS 2.1.0 Regional Benchmark Compliance Rules in Azure
        • Understand CIS 3.0.0 Regional Benchmark Compliance Rules in Azure
      • NIST 800-53 Revision Rules in Azure
        • NIST 800-53 Revision 5 Rules in Azure: An Overview
        • Understand NIST 800-53 Revision 5 Rules in Azure
        • Understand NIST 800-53 Revision 5 Global Rules in Azure
        • Understand NIST 800-53 Revision 5 Regional Rules in Azure
      • SecPod Rules in Azure
        • SecPod Default Rules in Azure: An Overview
        • Understand SecPod Global Rules in Azure
        • Understand SecPod Regional Rules in Azure
        • Understand SecPod Default Rules in Azure
      • HIPAA HITRUST Rules in Azure
        • HIPAA HITRUST Rules in Azure: An Overview
        • Understand HIPAA HITRUST 14.7.0 Rules in Azure
        • Understand HIPAA HITRUST 14.7.0 Global Rules in Azure
        • Understand HIPAA HITRUST 14.7.0 Regional Rules in Azure
      • PCI DSS Rules in Azure
        • PCI DSS 3.2.1 Rules in Azure: An Overview
        • Understand PCI DSS 4.0 Rules in Azure
        • Understand PCI DSS 4.0 Global Rules in Azure
        • Understand PCI DSS 4.0 Regional Rules in Azure
      • SOC 2 Rules in Azure
        • SOC 2 Rules in Azure: An Overview
        • Understand SOC2 Rules in Azure
        • Understand SOC2 Global Rules in Azure
        • Understand SOC2 Regional Rules in Azure
  • Posture Anomaly Checks in AWS, Azure, and GCP
    • Implementing Posture Anomaly Checks in AWS
    • Implementing Posture Anomaly Checks in Azure
    • Implementing Posture Anomaly Checks in GCP
  • Infrastructure Entitlement Checks in AWS, Azure, and GCP
    • Implementing Infrastructure Entitlement Checks in AWS
    • Implementing Infrastructure Entitlement Checks in Azure
    • Implementing Infrastructure Entitlement Checks in GCP
View Categories
  • Home
  • Docs
  • Saner Cloud
  • Saner COSP User Guides
  • Container Orchestration Remediation Management(CORM) User Guide

Container Orchestration Remediation Management(CORM) User Guide

Print Friendly, PDF & Email

Saner Container Orchestration Remediation Management (CORM) tool presents a centralized platform for automating, monitoring, and optimizing remediation efforts across container orchestration systems. It allows administrators to evaluate the effectiveness of patching initiatives through intuitive charts, helping them prioritize tasks that provide the greatest security impact. By utilizing Patch Aging, older or high-risk vulnerabilities are highlighted to ensure that critical issues are addressed promptly. The Patching Impact analysis enables teams to focus on patches that affect the largest number of systems, maximizing operational efficiency.

Saner CORM also provides real-time oversight of remediation activities by monitoring and analyzing job statuses across multiple tools. Users can identify and prioritize the Top 10 Missing Patches, track the workflow status of remediation tasks, and review patch distribution by resource type. Additionally, insights into patch distribution across various tools allow administrators to assess coverage gaps and optimize patch deployment strategies, ensuring strong security and compliance throughout the infrastructure.

How to Quickly Access the Necessary Tool for Remediation and Begin Patching Tasks?

Choose the Tool and Remediate

Access the relevant tool: COPM, COEM, or COPA(displayed as links) from the top-right of the dashboard.

For example, if you select COPM, then the COPM tabular listing opens for you to begin the patching activities.

Follow the link to learn more on: How to Remediate Findings in Saner COSP?

Assess Patch-wise Distribution Across Tools

The Product-wise patch count chart allows for quick assessment of patch distribution across various container orchestration tools, namely COPM, COEM, and COPA, each represented by a unique color. Move your cursor over the chart to see the count for each tool. Clicking on the chart opens the CORM tabular listing where you begin the patching activities.

This helps with focused investigation into areas or resources that have not been scanned or are missing patches, allowing users to prioritize patching based on the severity of misconfigurations.

The chart visually displays the patch counts for each tool, using the following color coding: Red for COPM, Gray for COPA, and Orange for COEM. Move your cursor over the different tools in the chart to see the count.

Additionally, you have the option to export detailed data to a CSV file for further analysis or reporting.

View the Top Patch Count by Resource Type

The Top Patch Count by Resource Type dashboard block presents a bar graph that displays the number of patches associated with various resource types. Clicking on the chart opens the CORM tabular listing where you begin the patching activities.

The x-axis represents the different resource types, while the y-axis indicates the corresponding patch counts.

Move your cursor over the bar to see the exact patch count for a specific resource type. Additionally, the data can be exported to a CSV file for further analysis or reporting.

Top 10 Patch Count by Namespace

The Top 10 Patch Count by Namespace radar chart in the CORM dashboard provides a clear, namespace-level view of patch distribution across the Kubernetes environment, helping teams quickly identify where remediation efforts are most needed. Each axis represents a namespace, and the distance from the center indicates the number of patches, allowing easy comparison of patch concentration across workloads. In this case the chart illustrates the copm-validation has the highest patch count, signaling a priority for remediation, while others show moderate activity and some namespaces have minimal or no patches.

This visualization allows risk-based prioritization, targeted remediation, and improved visibility, ensuring efficient management of vulnerabilities without impacting the entire cluster.

Identify and Prioritize the Top 10 Missing Patches

The Top 10 Missing Patches dashboard view allows users to select a tool: COPM, COEM, or COPA, and display the most critical missing patches in a table format.

This table includes essential columns such as Remediation ID with title, Issue ID, the affected resource type with count, if rollback is available or not, and severity that provides a clear overview of high-priority patches that require attention.

This feature helps teams swiftly identify issues, prioritize remediation efforts, and reduce security risks across the environment.

How to Address Missing Patches Via Remediation Tasks?

Click the Remediation ID corresponding to a tool in the Top 10 Missing Patches view. The relevant tabular listing opens for you to begin the patching activities.

The Create Patching Task window opens.

Step1: Select Resources
  1. From the list of Affected resources, choose the ones you want to remediate
  2. Use the checkbox to select or deselect resources as needed
  3. Click Next Step to proceed
Step2: Choose the Remediation Template to Apply
  1. Select the appropriate option to Review or configure the remediation settings for your patching task.
  2. Once satisfied with the configuration, click Next Step.
Step3: Schedule Job
  1. Enter the Task Name and Description in the required fields.
  2. Use the dropdown to select one of the Remediation schedule:
    • Immediate – To apply the remediation immediately
    • Select Date & Time – To schedule the remediation for a specific time
  3. After entering the schedule details, click Next Step.
Step4: Review and Consent
  • Admin Users: Get to see the Consent checkbox and directly approve and execute the rollback task
  • Regular Users: Consent checkbox appears in disabled mode. Users need to create the Rollback task and the system auto-routes the task to Admin for review and approval
  1. Carefully review the patching task settings and configurations.
  2. Provide your consent by selecting the checkbox that confirms settings have been reviewed and aligned with security and operational requirements.
  3. Click Create Task to finalize and submit the patching task.
Step5: Monitor Remediation Task
  1. Once created, the patch remediation task appears in the Remediation Status block on the CORM (Container Orchestration Remediation Management) dashboard.
  2. Use this section to observe the progress and status(such as Pending Approval, Not Initiated, In Progress, Success, Failed, or Completed) of your patch remediation task.
What do the different stages of patch remediation status mean?

— Pending Approval: The remediation job requires approval before execution. This stage ensures that all necessary stakeholders review the job and its impact before proceeding, reducing the risk of unintended consequences.

— Not Initiated: The remediation job is created but not yet started. This status indicates that prerequisites are not met, or the job is scheduled to start at a later time.

— In Progress: The remediation job is currently being executed. The system is actively applying fixes or patches to address the identified vulnerabilities or issues.

— Success: The remediation job has been completed successfully, and all targeted issues have been resolved as expected. No further action is required for this job.

— Failed: The remediation job did not complete due to errors or issues during execution. This status requires investigation to determine the root cause and potentially retry or escalate the job.

— Completed: status typically indicates that the remediation job has completed While “Completed” may overlap with “Success,” it could also include scenarios where the job ended with partial success or manual interventions.

What to do when you encounter an error message when creating a patching task?

You encounter the error message during patch task creation, typically when the target resources are invalid or inactive in the system, remediation template is not configured correctly, or schedule details are incorrectly specified.

As a precursory step, go ahead and revisit the previous steps:

  • Select Resources: Ensure the target resources are valid and active in the system
  • Rem Template: Verify the selected remediation template is configured correctly
  • Schedule Job: Double-check if the scheduling details, such as time, are correctly filled and conflict-free

If the issue still persists, click “Contact Support” in the interface to directly notify SecPod’s support team. Provide them with:

  • A detailed description of the steps leading to the error
  • Affected resources and templates used
  • Logs or screenshots, including this error screen
  • Any specific error codes or IDs visible in the logs

Monitor and Analyze Job Status Across Tools

The Job Status dashboard block allows users to select a specific tool, COPM, COEM, or COPA, and view the status of its jobs in a structured table format.

The table includes important columns such as Name, Description, Overall Status, Type, Owner, and Resource Count, providing a clear overview of each job’s details and progress.

This setup enables teams to quickly assess operational health, track ongoing processes, and identify jobs that may require attention or intervention.

You have an option to sort the “Owner”column in both ascending and descending order, use the search box to quickly find specific entries, and export the data in CSV format for reporting purposes. Additionally, you can adjust the number of records shown, making navigation easier.

Use Charts to Evaluate Effectiveness and Prioritize Patches

The Patch Aging and Patching Impact charts offer a thorough overview of the effectiveness of patch management.

The Patch Aging chart is a time-based line graph that illustrates the relationship between the number of pending patches and their age in days. This helps teams prioritize addressing older, high-risk findings first. The chart visually indicates how long patches remain unapplied within an IT environment; upward trends suggest delays that increase exposure to security risks. Creative icons along the timeline represent different stages of patch aging, including growth, decline, and resurgence, enabling organizations to manage and track deployment timelines more effectively.

The Patching Impact chart emphasizes the success of remediation efforts by plotting the number of security rules fixed against the number of patches applied. The X-axis represents the number of patches applied, while the Y-axis displays the number of affected rules. Hovering over points on the chart reveals the direct impact of patching on reducing vulnerabilities or misconfigurations, assisting teams in prioritizing patches that provide the highest security benefits.

Prioritize and Address Older or High-Risk Anomalies with Patch Aging

A time-based line plot shows the correlation between the number of pending patches and their age in days, helping teams address older, high-risk findings first.

The Patch Aging chart visually represents the duration during which patches remain unapplied in an IT environment. It illustrates the relationship between the number of pending patches and the number of days they have been outstanding.

This chart assists organizations in tracking and managing their patch deployment timelines. An upward trend indicates delays in patch deployment, which increases the organization’s exposure to risks over an extended period. The creative visual employs characters or icons along the timeline to depict different stages of patch aging, including growth, decline, and subsequent resurgence.

From the Saner CORM dashboard, just go down to the “Patching Aging” block for further analysis.

Prioritize Patches Having Maximum Impact with Patching Impact

The Patching Impact chart helps you prioritize patches that have the maximum impact, ensuring critical misconfigurations are addressed first. The graph also illustrates the relationship between the number of patches applied and the reduction in the number of rules.   X-Axis indicates the number of patches applied Y-axis indicates the number of rules affected.

The point that you highlight by moving your cursor indicates the impact of patching on reducing risks or misconfigurations.

Commonly Asked Questions

How can I identify older, unaddressed vulnerabilities?

The Patch Aging chart provides a time-based visualization of pending patches against their age (in days). It helps identify older, unaddressed vulnerabilities so teams can prioritize remediation efforts effectively.

Is there a way the tool helps to focus on high-risk or aging vulnerabilities?

The Patch Aging chart highlights patches that have remained unapplied for extended periods, and helps teams to focus on high-risk, aging vulnerabilities that increase exposure over time.

What does an upward trend in the Patch Aging chart indicate?

An upward trend signifies delays in patch deployment, leading to prolonged exposure to vulnerabilities and increased security risk.

How are patch lifecycle stages represented in the Patch Aging chart?

The chart uses visual indicators (icons/characters) along the timeline to represent stages such as growth, decline, and resurgence of pending patches.

How to access the Patch Aging chart?

The chart is available in the “Patch Aging” block within the Saner CORM dashboard for detailed analysis.

What insights does the Patching Impact chart provide?

The Patching Impact chart shows the relationship between the number of patches applied (X-axis) and the number of affected security rules resolved (Y-axis), helping measure remediation effectiveness.

How does the Patching Impact chart assist in prioritization?

It helps identify patches that resolve the highest number of vulnerabilities or misconfigurations, enabling teams to prioritize high-impact patches.

What information is available on hovering over the Patching Impact chart?

Hovering over data points reveals the exact impact of applied patches on reducing risks or misconfigurations.

What is the function of the Job Status dashboard block?

It provides a structured view of job execution status across tools such as COPM, COEM, and COPA.

What details are included in the Job Status table?

The table includes Name, Description, Overall Status, Type, Owner, and Resource Count for each job.

How can users filter or locate specific jobs?

Users can sort by Owner, use the search box for quick lookup, and adjust the number of displayed records.

Can Job Status data be exported?

Yes, the data can be exported in CSV format for reporting and further analysis.

What is the purpose of the Top 10 Missing Patches view?

It highlights the most critical missing patches across selected tools, helping teams quickly identify high-priority vulnerabilities.

What information is displayed in this table?

It includes Patch Name, Description, Severity, Affected Systems, Release Date, and Status.

How does this feature support remediation efforts?

It enables rapid identification and prioritization of critical patches, reducing security risks efficiently.

What does the Workflow Status chart display?

It shows the count and status of remediation workflows categorized as Completed, Failed, and Pending Approval.

How does the Workflow Status chart help operations teams?

It provides a quick overview of remediation progress and helps identify workflows requiring attention.

Can workflow data be exported?

Yes, users can export workflow data to CSV for further analysis and reporting.

What is the Top Patch Count by Resource Type chart?

It is a bar graph showing the number of patches associated with different resource types.

How can users interpret this chart?

The X-axis represents resource types, while the Y-axis shows patch counts, helping identify which resources require more patching attention.

Is detailed data available for this chart?

Yes, users can hover over bars to view exact counts and export the data to CSV.

What does the Product-wise Patch Count chart represent?

It shows the distribution of patches across different tools — COPM, COEM, and COPA.

How are tools differentiated in the chart?

Each tool is represented by a distinct color (e.g., Red for COPM, Gray for COPA, Orange for COEM).

How does this chart support decision-making?

It helps identify gaps in patch coverage across tools, enabling targeted remediation and prioritization.

Can Product-wise patch data be exported?

Yes, detailed data can be exported to CSV for reporting and deeper analysis.

Related Topics

How to Configure Automation Rules for COSP Misconfiguration Remediation?

How to Rollback a Remediation in Saner COSP?

How to Remediate Findings in Saner COSP?

Share This Article :

  • X
  • LinkedIn
Still stuck? How can we help?

Saner Documentation Feedback

Container Orchestration Entitlement Management(COEM) UserguideContainer Orchestration Security Platform (COSP) User Guide
Table of Contents
  • How to Quickly Access the Necessary Tool for Remediation and Begin Patching Tasks?
  • Assess Patch-wise Distribution Across Tools
  • View the Top Patch Count by Resource Type
  • Top 10 Patch Count by Namespace
  • Identify and Prioritize the Top 10 Missing Patches
    • How to Address Missing Patches Via Remediation Tasks?
  • Monitor and Analyze Job Status Across Tools
  • Use Charts to Evaluate Effectiveness and Prioritize Patches
    • Prioritize and Address Older or High-Risk Anomalies with Patch Aging
    • Prioritize Patches Having Maximum Impact with Patching Impact
Copyright 2026 - SecPod. All Rights Reserved. Privacy Policy.
SanerNow Version 6.5.x