Skip to content
SecPod  – Documentation
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO
  • Toggle website search
Search this website
Menu Close
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO
  • Toggle website search
  • Docs Home
  • Categories
    • Saner Platform
    • Saner Cloud
    • Saner CVEM
    • Security Intelligence
  • More
    • About SecPod
    • Blog
    • Security & Privacy
    • Support Center
    • Resources
  • SCHEDULE A DEMO

Saner Platform

  • Saner Platform Release Notes
    • Saner Platform Integration Release: ServiceNow Integration Introduced, Freshservice Enhanced
    • Release Notes Saner 6.4.1
    • Release Notes SanerNow 6.4
    • Release Notes SanerNow 6.3.1
    • Release Notes SanerNow 6.3
    • Release Notes SanerNow 6.2.1
    • Release Notes SanerNow 6.2.0.3
    • Release Notes SanerNow 6.2.0.1
    • Release Notes SanerNow 6.2
    • Release Notes SanerNow 6.1.1
    • Release Notes SanerNow 6.1
    • Release Notes SanerNow 6.0
    • Release Notes SanerNow 5.3.1
    • Release Notes SanerNow 5.3
    • Release Notes SanerNow 5.2
    • Release Notes SanerNow 5.1
    • Release Notes SanerNow 5.0
    • Release Notes SanerNow 4.8.0.0
    • Release Notes SanerNow 4.7.0.0
    • Release Notes SanerNow 4.6.0.0
    • Release Notes SanerNow 4.5.0.0
    • Release Notes SanerNow 4.4.0.0
    • Release Notes SanerNow 4.3.0.0
    • Release Notes SanerNow 4.2.2.1
    • Release Notes SanerNow 4.2.2.0
    • Release Notes SanerNow 4.2.1.0
    • Release Notes SanerNow 4.2.0.0
    • Release Notes SanerNow 4.1.1.0
    • Release Notes SanerNow 4.0.0.5
  • Saner Platform Guide
    • Prerequisites For Saner SaaS Platform Deployment
    • Saner Administration Guide
    • Saner Device Management User Guide
    • Saner Platform and ServiceNow Integration Guide
    • Saner Platform and Freshservice Integration Guide
    • Saner Platform Function Guides
  • FAQs
    • Saner CVEM Technical FAQs
  • How Tos
    • General
      • How to increase the subscription count for an Account in Saner CVEM
      • How to increment license count for an Organization in Saner CVEM
      • How to provision Saner tools for an Organization
      • How to change subscription type in Saner CVEM
      • How to sign-up with Saner CVEM?
      • How to create a new account in Saner CVEM?
      • How to create a new user in Saner CVEM?
      • How to enable SSO authentication policy in Saner CVEM?
      • How to set alerts in Saner?
      • How to view, download and filter the audit logs?
      • How to designate Saner Agent to perform network scan?
      • How to Co-Brand with your logo?
      • How to fetch the details of the mandatory fields from the Okta account?
      • How to create MFA policy for Okta?
      • How to fetch the details of the mandatory fields from the PingID account?
      • How to create MFA policy for PingID?
      • How to fetch the details of the mandatory fields from the PingOne account?
      • How to create MFA policy for PingOne?
      • How to download and install Saner Agent in Mac?
      • How to download and install Saner agent in Linux?
      • How to download and install the Saner agent in Windows?
      • How to update the expiry date of an existing subscription?
      • How to manage users and their preferences using role-based access?
      • How to uninstall Saner Agent using Saner Offline deployer tool.
      • How to onboard a new organization?
      • How to deploy Saner Agent using Saner Offline deployer tool.
      • How to install a Saner agent through the command line?
      • How to uninstall the Saner agent through command line?
    • Saner Reports
      • How to configure mail settings to email Report PDF?
      • How to create a custom report in Saner?
      • How to schedule for the report back up?
    • Saner Device Management
      • How to create custom groups in Saner CVEM
    • Saner Mail Settings
      • How to create new mail settings in Saner?
      • How to use OAuth-enabled authentication in Saner mail settings
      • How to create OAuth Client ID and Client Secret for Gmail
      • How to create OAuth Client ID and Client Secret for Microsoft 365.
  • Supported OSs and Platforms
    • Operating Systems and Platforms Supported
    • Supported Third-party Applications for Patching

Saner Cloud

  • Before You Begin
    • Glossary of Terms
    • Read me First
  • Get Started
    • Prerequisites For Saner SaaS Platform Deployment
    • Saner Cloud Deployment Guides
      • Azure Onboarding
      • Troubleshooting
      • Get Started with Saner CNAPP AWS Cloud Deployment V1.0
      • Onboarding with AWS Credentials(Least Recommended Method)
      • Onboarding with AWS Role(Manual)
      • Onboarding with AWS Role CloudFormation (Automatic): Recommended
    • Roles and Permissions
      • Roles and Permissions for AWS Remediation Access
      • Roles and Permissions for Azure Onboarding, Detection, and Remediation
  • Learn About
    • Saner CSRP Classification Based on Scoring Decision
    • Cloud Cyber Hygiene Scoring(CCHS) Approach
    • Remediation Rollback
    • Automation and Job-driven Remediation
    • Cost and Usage
    • Excessive Permission Categories Evaluated Across Different Cloud Services
    • Publicly Accessible Resources
    • Patch Aging and Patch Impact
    • SecPod Default Benchmarks
    • Watchlists
    • Cloud Workload Protection Platform(CWPP)
    • Overview of Report Views in Saner Cloud
    • Whitelisting Resources
    • Saner Plasma AI Assistant for Seamless User Interaction
    • Critical Events to Monitor in AWS
    • High-Privilege Actions in Critical Activity Logs for AWS
    • Audit Logs in Saner Cloud
    • Excessive Permissions
    • Alerts in SanerCloud
  • User Guides
    • Cloud Security Risk Prioritization(CSRP) User guide
    • Cloud Cyber Hygiene Score(CCHS) User Guide
    • Cloud Security Remediation Management(CSRM) User Guide
    • Cloud Infrastructure Entitlement Management(CIEM) User Guide
    • Cloud Security Posture Anomaly(CSPA) User Guide
    • Cloud Security Asset Exposure(CSAE) User Guide
    • Cloud Security Posture Management(CSPM) User Guide
  • Tell Me How
    • How to Remediate in Saner Cloud?
    • How to Configure Automation Rule to Remediate Misconfigurations?
    • How to Manage Report Views at Organization-level in Saner Cloud?
    • How to Get a Cohesive View from Saner Cloud Unified Dashboard?
    • How to Use Tags to Quickly Filter Resources?
    • How to Troubleshoot Issues with Audit Logs?
    • How to Manage Groups and Tags in Saner Cloud?
    • How to Manage Report Views for a User Account in Saner Cloud?
    • How to Troubleshoot or Analyze with Critical Activity Logs?
    • How to Setup Alerts Across SanerCloud Tools?
    • How to Take Action on Alert Notifications from SanerCloud?
    • CCHS
      • How to Monitor Resource Risk Trends for CHS?
      • How to Assess Resource Health through Severity Distribution?
      • How to Evaluate Service-Level Risks Using CHS Scores?
      • How to Analyze Cyber Hygiene Scores through Trend Chart?
      • How to Identify High-Risk Resources by Geo Location?
      • How to Get an Overview of Cyber Hygiene for Cloud Resources?
      • How to Review Organization-Level Cyber Hygiene Across Accounts?
      • How to Assess Risk Distribution for Different Cloud Providers?
      • How to Review Major Issues Contributing to the Drop of Cyber Hygiene Score at Account-Level?
      • How to Analyze Module-wise Risk through CHS Distribution?
      • How to View the Cyber Hygiene Score Distributed Across Cloud Environments?
      • How to Track Security Posture with Cyber Hygiene Score?
      • How to Configure Account Weightage?
    • CSRP
      • How to Monitor and Analyze Audit Logs for Risk Prioritization?
      • How to Configure Risk Based Cloud Security Alerts?
      • How to Generate Reports and Visualizations?
      • How to Filter Risks by Tags for Targeted Analysis?
      • How to Manage Prioritized Risks at Account-level?
      • How to View the Detailed Breakdown of a Specific Cloud Cyber Security Standard (CCSS) Risk Finding?
      • How to Review and Prioritize Resources Based on Associated Risks?
      • How to Assess Risk Distribution on Essential Resources?
      • How to Assess and Prioritize Risks Across Resource Categories?
      • How to Identify the Risks Affecting Essential Resources?
      • How to Assess Full Versus Limited Technical Impact of Exploiting an Anomaly?
      • How to Review the Risk Factor Distribution Based on Automatable Reliability?
      • How to Get an Overview of Exploitable Risks?
      • How to Map Risks to MITRE ATT&CK for Threat-Informed Defense?
      • How to Configure Questionnaire and Assess Security Practices Across Core Domains for an Account?
    • CSAE
      • How to Setup Watchlist Configuration for a Resource?
      • How to Identify Outdated Resources for Cleanup?
      • How does Resource Categorization Work in Saner CSAE?
      • How to Identify Resources Exposed to External Network?
      • How to Understand the Resource Footprint Globally Across Various Regions?
      • How to Make Informed Decisions on Your Expenditure based on Resource Usage Graph?
    • CSPM
      • How to Setup Benchmarks in Saner CSPM?
      • How to Use Quick Evaluation Benchmarks?
      • How to Detect Patterns over a Period with Resource Trends?
      • How to Assess System Compliance and Security Posture?
    • CSPA
      • How to Initiate Patch Remediation from CSPA Dashboard?
      • How to Quickly Identify the Detected and Remediated Anomalies for an Account?
      • How to Prioritize Remediation or Fixes based on Confidence Levels?
      • How to Examine the Overall Anomaly Information for Specific Rules or Checks?
      • How to Search and Retrieve Anomaly Data?
      • How to Whitelist Rules or Resources in Cloud Security Scans?
    • CIEM
      • How to See the Active Version for an IAM Policy?
      • How to Address Critical Activities Using Evidence?
      • How to View by Type and Usage for any Identity in CIEM?
      • How to Get Visibility into Cloud Entitlements?
      • How to Use Evidence to Address Policies with Excessive Permission?
      • How to Know the Excessive Permissions on a Specific Service?
      • How to Visually See the Relationship between Identity, Entitlement, Policy, or Permission?
      • How to Determine if a Policy has Excessive Permission?
      • How to Initiate Remediation for Different Identities from CIEM?
    • CSRM
      • Rollback an Applied Remediation
      • How to Configure Automation Rule to Remediate Misconfigurations?
      • How to Create a Patching Task for Items Currently in “Approval Pending” State?
      • How to Evaluate Remediation Effort with Patching Impact Chart?
      • How to Prioritize and Address Older or High-Risk Anomalies with Patch Aging?
      • How to Monitor the Overall Status of the Remediation Job?
      • How do I Get to Know the Regions Impacted by a Specific Rule?
      • How to View the Severity of a Missing Patch Affected by a Rule?
      • How to Address Missing Patches Via Remediation Tasks?
      • How to Quickly Access the Necessary Tool for Remediation and Begin Patching Tasks?
  • Frequently Asked Questions
    • Saner Cloud Technical FAQs
  • Saner Cloud Release Notes
    • Protected: Saner Cloud – V.2.0.0.1 Release Notes
    • Saner Cloud – V.1.2.0.1 Release Notes
    • Saner Cloud – V.1.2.0.0 Release Notes
    • Saner Cloud – V.1.1.0.0 Release Notes
    • Saner Cloud – V.1.1 Release Notes
    • Saner Cloud – V.1.0 Release Notes
  • Security Intelligence for Saner Cloud
    • Benchmark Compliance Rules in AWS and Azure
      • AWS
        • SecPod Rules in AWS
          • SecPod Default Rules in AWS: An Overview
          • Understand SecPod Default Rules in AWS
          • Understand SecPod Global Rules in AWS
          • Understand SecPod Regional Rules in AWS
        • PCI DSS 3.2.1 Rules in AWS
          • PCI DSS 3.2.1 Rules in AWS: An Overview
          • Understand PCI DSS 3.2.1 Rules in AWS
          • Understand PCI DSS 3.2.1 Global Rules in AWS
          • Understand PCI DSS 3.2. 1 Regional in AWS
        • CIS Rules in AWS
          • CIS Rules in AWS: An Overview
          • Understand CIS Rules in AWS
          • Understand CIS 3.0.0 Rules in AWS
          • Understand CIS 4.0.1 Rules in AWS
          • Understand CIS 4.0.0 Rules in AWS
          • Understand CIS 3.0.0 Global Rules in AWS
          • Understand CIS 4.0.0 Global Rules in AWS
          • Understand CIS 3.0.0 Regional Rules in AWS
          • Understand CIS 4.0.0 Regional Rules in AWS
        • SOC 2 Rules in AWS
          • SOC 2 Rules in AWS: An Overview
          • Understand SOC 2 Rules in AWS
          • Understand SOC 2 Global Rules in AWS
          • Understand SOC 2 Regional Rules in AWS
        • HIPAA HITRUST Rules in AWS
          • HIPAA HITRUST Rules in AWS: An Overview
          • Understand HIPAA HITRUST Rules in AWS
          • Understand HIPAA HITRUST Global Rules in AWS
          • Understand HIPAA HITRRUST Regional Rules in AWS
        • NIST 800-53 Revision 5 Rules in AWS
          • NIST 800-53 Revision 5 Rules in AWS: An Overview
          • Understand NIST 800-53 Revision 5 Rules in AWS
          • Understand NIST 800-53 Revision 5 Global Rules in AWS
          • Understand NIST 800-53 Revision 5 Regional Rules in AWS
      • Azure
        • CIS Rules in Azure
          • CIS Rules in Azure: An Overview
          • Understand CIS 1.2.0 Rules in Azure
          • Understand CIS 2.1.0 Rules in Azure
          • Understand CIS 1.1.0 Benchmark Compliance Rules in Azure
          • Understand CIS 3.0.0 Benchmark Compliance Rules in Azure
          • Understand CIS 1.2.0 Global Benchmark Compliance Rules in Azure
          • Understand CIS 2.1.0 Global Benchmark Compliance Rules in Azure
          • Understand CIS 3.0.0 Global Benchmark Compliance Rules in Azure
          • Understand CIS 2.1.0 Regional Benchmark Compliance Rules in Azure
          • Understand CIS 3.0.0 Regional Benchmark Compliance Rules in Azure
        • NIST 800-53 Revision Rules in Azure
          • NIST 800-53 Revision 5 Rules in Azure: An Overview
          • Understand NIST 800-53 Revision 5 Rules in Azure
          • Understand NIST 800-53 Revision 5 Global Rules in Azure
          • Understand NIST 800-53 Revision 5 Regional Rules in Azure
        • SecPod Rules in Azure
          • SecPod Default Rules in Azure: An Overview
          • Understand SecPod Global Rules in Azure
          • Understand SecPod Regional Rules in Azure
          • Understand SecPod Default Rules in Azure
        • HIPAA HITRUST Rules in Azure
          • HIPAA HITRUST Rules in Azure: An Overview
          • Understand HIPAA HITRUST 14.7.0 Rules in Azure
          • Understand HIPAA HITRUST 14.7.0 Global Rules in Azure
          • Understand HIPAA HITRUST 14.7.0 Regional Rules in Azure
        • PCI DSS Rules in Azure
          • PCI DSS 3.2.1 Rules in Azure: An Overview
          • Understand PCI DSS 4.0 Rules in Azure
          • Understand PCI DSS 4.0 Global Rules in Azure
          • Understand PCI DSS 4.0 Regional Rules in Azure
        • SOC 2 Rules in Azure
          • SOC 2 Rules in Azure: An Overview
          • Understand SOC2 Rules in Azure
          • Understand SOC2 Global Rules in Azure
          • Understand SOC2 Regional Rules in Azure
    • Posture Anomaly Checks in AWS and Azure
      • Implementing Posture Anomaly Checks in AWS
      • Implementing Posture Anomaly Checks in Azure
    • Infrastructure Entitlement Checks in AWS and Azure
      • Implementing Infrastructure Entitlement Checks in Azure
      • Implementing Infrastructure Entitlement Checks in AWS

Saner CVEM

  • Saner CVEM Release Notes
    • Release Notes Saner 6.5
    • Saner Platform Integration Release: ServiceNow Integration Introduced, Freshservice Enhanced
    • Release Notes Saner 6.4.1
    • Release Notes SanerNow 6.4
    • Release Notes SanerNow 6.3.1
    • Release Notes SanerNow 6.3
    • Release Notes SanerNow 6.2.1
    • Release Notes SanerNow 6.2.0.3
    • Release Notes SanerNow 6.2.0.1
    • Release Notes SanerNow 6.2
    • Release Notes SanerNow 6.1.1
    • Release Notes SanerNow 6.1
    • SanerNow Risk Prioritization Launch
    • Release Notes SanerNow 6.0
    • Release Notes SanerNow 5.3.1
    • Release Notes SanerNow 5.3
    • Release Notes SanerNow 5.2
    • Release Notes SanerNow 5.1
    • Release Notes SanerNow 5.0
    • Release Notes SanerNow 4.8.0.0
    • Release Notes SanerNow 4.7.0.0
    • Release Notes SanerNow 4.6.0.0
    • Release Notes SanerNow 4.5.0.0
    • Release Notes SanerNow 4.4.0.0
    • Release Notes SanerNow 4.3.0.0
    • Release Notes SanerNow 4.2.2.1
    • Release Notes SanerNow 4.2.2.0
    • Release Notes SanerNow 4.2.1.0
    • Release Notes SanerNow 4.2.0.0
    • Release Notes SanerNow 4.1.1.0
    • Release Notes SanerNow 4.0.0.5
  • Saner CVEM Guide
    • What’s New in Saner CVEM?
    • Getting Started with Saner CVEM
    • Pre-requisites for Saner CVEM Deployment
    • How does Saner CVEM’s deployment architecture work?
  • Saner CVEM Products
    • Overview of Saner Continuous Vulnerability and Exposure Management
    • Saner CVEM Unified Dashboard User Guide
    • Saner CVEM Asset Exposure User Guide
    • Saner CVEM Continuous Posture Anomaly Management User Guide
    • Data Points IT teams can Fetch from Saner CPAM
    • Posture Anomaly Computation Rules
    • Saner CVEM Vulnerability Management User Guide
    • Saner CVEM Compliance Management User Guide
    • Saner CVEM Risk Prioritization User Guide
    • Saner CVEM Patch Management User Guide
    • Saner CVEM Endpoint Management User Guide
    • Saner CVEM Remote Scripting User Guide
    • Saner CVEM Remote Access User Guide
    • Saner CVEM Network Scanner User Guide
    • Saner CVEM Cyber Hygiene Score User Guide
  • How Tos
    • Saner AE
      • How to blacklist and whitelist applications in Saner AE?
      • How to manage asset licenses using Saner AE?
      • How to run an asset scan using Saner AE?
    • Saner CPAM
      • How to create new response in PA tool?
      • How to build your own detection and response in PA tool?
      • How to whitelist an entire PA ID?
      • How to configure Posture Anomaly tool for custom detection?
      • How to fix Anomalies from PA dashboard?
      • How to fix anomalies detected in your account from All Anomalies Page?
      • How to fix anomalies from PA Summary page?
      • How to delete PA scan preferences?
      • How to schedule PA Scans on Daily, Weekly, and Monthly basis?
      • How to launch Posture Anomaly scans?
    • Saner VM
      • How to automate and schedule vulnerability scans?
      • How to exclude vulnerabilities in Saner VM tool
      • How to manage excluded vulnerabilities in Saner VM?
      • How to remediate vulnerabilities from vulnerability management dashboard?
    • Saner CM
      • How to run a compliance scan?
      • How to custom create a security policy?
      • How to align with PCI security compliance management?
      • How to align with NIST 800-171 security compliance management?
      • How to align with NIST 800-53 security compliance management?
      • How to align with HIPAA security compliance management using Saner CM?
    • Saner PM
      • How to fix firmware in Saner?
      • How to exclude patches in Saner PM?
      • How to manage excluded patches in Saner PM?
      • How to automate patch management in Saner PM?
      • How to roll back patches in Saner PM?
      • How to specify Service Level Agreement (SLA) using Remediation SLA in Saner PM?
      • How to apply missing patches in Saner PM?
      • How to apply the most critical patches in Saner PM?
      • How to perform custom remediation for applications that require paid patches using Saner PM
      • How to check the status of patching activity?
    • Saner EM
      • How to collect all security events from Windows Events Log?
      • How to check password policy set in Windows systems?
      • How to check status of DEP in Windows systems?
      • How to check faulty Anti-Virus (AV) status in Windows systems?
      • How to check for Anti-Virus (AV) status in Windows systems?
      • How to check account lockout policy on Windows systems?
      • How to check if Bit-locker protection is OFF in Windows systems?
      • How to list all inactive users on Windows systems?
      • How to list all guest accounts in Windows systems?
      • How to list all Administrator accounts on Windows systems?
      • How to list last-logon details of users on Windows systems?
      • How to identify all users in Windows systems?
      • How to collect all services that are currently running in Windows systems?
      • How to list all Groups in Windows systems?
      • How to collect all keyboard and pointing devices connected to Windows systems?
      • How to collect all storage devices connected to Windows systems?
      • How to investigate total RAM or CPU threshold (greater than or equal to 80%) in Windows systems?
      • How to collect operating systems information in Windows?
      • How to investigate disks running out of space (<100 MB) in Windows systems?
      • How to collect and investigate disk information on Windows systems?
      • How to collect all installed patches in Windows systems?
      • How to collect all software patches that are hidden in the Windows Update server?
      • How to check the status of Windows Update Server (WSUS/SCCM)?
      • How to collect BIOS information such as serial number, version, manufacturer in Windows systems?
      • How to collect all the important missing patches in Windows systems?
      • How to check wireless security in Linux systems?
      • How to collect mounted disk information on Linux systems?
      • How to check wireless signal quality in Linux systems?
      • How to check all firewall policies on Linux systems?
      • How to collect all Dynamic Host Configuration Protocol (DHCP) information on Linux systems?
      • How to collect DNS information on Linux systems?
      • How to collect ARP entries that are created when a hostname is resolved to an IP address and then to a MAC addressing in Linux?
      • How to check wireless signal quality in Windows systems?
      • How to check wireless security in Windows systems?
      • How to collect all open ports in Windows systems?
      • How to collect all network interfaces in Windows systems?
      • How to investigate DNS cache on Windows systems?
      • How to check all firewall policies on Windows systems?
      • How to collect DNS information on Windows systems?
      • How to collect all the applications with an unknown publisher in Linux systems?
      • How to perform system tuning?
      • How to collect all software licenses in Windows systems?
      • How to identify potentially unwanted programs such as torrent downloaders or unnecessary toolbars running on Windows systems?
      • How to collect a list of applications that are started when you boot your computer?
      • How to collect all the applications with an unknown publisher in Windows systems?
      • How to collect all software licenses in Mac systems?
      • How to collect ARP entries that are created when a hostname is resolved to an IP address and then to a MAC addressing Windows?
      • How to collect all families of operating systems such as Windows, Unix, and macOS?
      • How to collect environment variables set in all operating systems?
      • How to collect all the applications with an unknown publisher in Mac systems?
      • How to delete and quarantine a file?
      • How to start and stop the processes in Saner?
      • How to block blacklisted applications in Saner?
      • How to enable/disable devices in Saner
      • How to manually import devices into Saner?
      • How to deploy software in Saner EM?
      • How to enable and disable firewall settings in Saner AE?
      • How to collect all shared resources on Windows systems?
      • How to collect all Dynamic Host Configuration Protocol (DHCP) information on Windows systems?
      • How to connect to a client machine graphically using Saner Remote Access
  • FAQs
    • Saner CVEM Technical FAQs

Security Intelligence

  • Overview of Security Content and Intelligence
  • Security Content Statistics
  • OVAL Definitions Platform Coverage
  • OVAL Definitions Class-wise Distribution
  • OVAL Definitions Family-wise Distribution
  • Application and OS Remediation Coverage
  • Compliance Benchmark Coverage
  • List of Vulnerability to Exploit/Malware Mapping covered in Saner
  • Network Scanner Product Support Matrix
  • Privilege levels for authenticated scans using Saner Network Scanner
View Categories
  • Home
  • Docs
  • Saner CVEM
  • Saner CVEM Products
  • Saner CVEM Cyber Hygiene Score User Guide

Saner CVEM Cyber Hygiene Score User Guide

Print Friendly, PDF & Email

Overview

The Saner Cyber Hygiene Score is a new feature that assigns a security score to organizations, accounts, and devices in the Saner ecosystem.

Cyber hygiene refers to the practices an organization follows to protect its network, assets, and users from cyberattacks.

The Cyber Hygiene Score quantifies the overall attack surface of a device. It takes into account Common Vulnerabilities and Exposures (CVEs), Common Configuration Enumerations (CCEs), missing patches, and posture anomalies.

The score provides a clear view of your organization’s security posture. It helps you identify areas that need attention and take informed steps to improve device and network security.

Types of Scores in CHS

Raw Score

Saner computes the raw score by giving an equal weightage of 25% each to CVEs, CCEs, Missing Patches, and Posture Anomalies, leading to four subscores being computed. A raw score is the sum of the four subscores and can be customized. The higher the raw score of a device, the less secure it is.

Global Score

Global score is a normalized raw score that ranges from 0-100. The higher the global score a device has, the more secure it is. Each Account in an Organization has a different score, and we can compare the Global Score of a device from one Account to another device from another Account.

Local Score

The Local score is computed as another normalized raw score that indicates where the device stands in an Account. The safest device in an Account will score 100, while the least safe device gets a 0. The main intention behind computing Local Score is to find the best device in the Account. You can compare the Local Score of machines within the Account.

Cyber Hygiene Score

The Cyber Hygiene Score of a device is the weighted average of a device’s Global Score and Local Score. The default weightage of 80% Global Score and 20% Local Score is considered during the computation of the Cyber Hygiene Score.

Patched Account Score

The Patched Account Score is an ideal account score for an Account. It is achieved when all the missing patches are applied, vulnerabilities patched, and Posture Anomalies and CCEs remediated. The Patched Risk Score is an ideal Risk Score that every Account should strive to achieve by leveraging various Saner tools. However, while calculating the Patched Account Score, we consider that you’ve been getting vulnerabilities and misconfigurations and will continue to get vulnerabilities in the future. Saner’s Machine Learning algorithm computes the Patched Account Score by training how your score has been in the past and how it might be in the future.

Account Score

The Account Score is the average of the Risk Score of the devices in an Account.

Organization Score

The Organization Score is the weighted average of the scores of all the Accounts under the Organization. At the same time, while computing the Organization Score, the number of devices in the Account is the weight.

Pre-requisites for CHS

CHS is available to all Saner subscribers. However, you must subscribe to at least one of the following Saner tools to compute the CHS Score.

  1. Saner VM
  2. Saner PM
  3. Saner CM
  4. Saner PA

Get Started with CHS

Login to the Saner web console and access the Unified Dashboard. Click on the score meter icon on the top right of the page. You will be redirected to the CHS Organization Dashboard.

Login to the Saner web console and access the Unified Dashboard. Click on the score meter icon on the top right of the page. You will be redirected to the CHS Organization Dashboard.

CHS Organization Dashboard

CHS Organization Dashboard gives detailed information about the Accounts that belong to the Organization you selected. Let’s look at each of these grids and the information provided by them.

Cyber Hygiene Score

The Cyber Hygiene Score grid displays the CHS Score for the Organization. It is the weighted average of the scores of all the Accounts in an Organization to which the user has access. CHS Score is categorized into the following levels:

CHS Score CategoryRangeColor Code
Low0 – 39Red
Medium40 – 79Yellow
High80 – 100Green

You can refer to the Types of Scores in CHS section to learn more about how scores are computed.

Cyber Hygiene Trend

The Cyber Hygiene Trend graph visually represents the change in Organization score over 30 days. You can download the Cyber Hygiene Trend report in a CSV format. Click on the icon on the top right of the Cyber Hygiene Trend grid. A pop-up message will appear, asking you to confirm the location where you want the file to be saved.

Accounts Table

Accounts Table displays the following information.

  • Account Name – This column displays all the Accounts part of the selected Organization.
  • Score –  This column displays the CHS Score for individual Accounts.
  • Devices – This column shows the total number of devices in an Account.
  • Severity –  This column shows the severity category for the devices
  • Last Scan Date – This column displays the date and time of the most recent CHS Scan done on the Account.

You can download the information presented in the Accounts table in a CSV format. Click the  icon to download and save the file on your machine.

Configure Weightage

Each module, namely Vulnerabilities,  Misconfigurations, Missing Patches, and Posture Anomalies contributes to your sub-score. Depending on your IT infrastructure requirements, you can prioritize how much each module will contribute to your subscore. You can configure the weightage for the Accounts in the Organization. You can do it manually or use the Auto-adjust feature.

Click the gear icon on the right side of the CHS homepage. A pop-up window appears, allowing you to enter the weightage manually. However, ensure that the total sum of the weightages doesn’t exceed 100.

Also, you can use the Auto-adjust feature to configure the weightage for the Accounts. Auto-adjust feature allows you to set the weightage by using the slider.

Click the Save button to save the newly specified weightages.

Note
You can configure weightages for individual Accounts. However, you can also configure weightages for all the Accounts in an Organization by checking the Select All checkbox.

Navigation Help

Saner CHS has built-in Navigation help. Click on the icon to access the navigation help.

Click the Next button to navigate to the next slide. The navigation help gives you a brief tour of the CHS Organization dashboard.

CHS Account Dashboard

CHS Account Dashboard provides detailed information about the devices in the Account. Let’s take a look at each of the grids and the information provided by them.

Cyber Hygiene Score

The Cyber Hygiene Score grid displays the CHS Score for the Account. A metered graph represents the latest overall cyber hygiene score of the Account. CHS Score is categorized into the following levels:

CHS Score CategoryRangeColor Code
High0 – 39Green
Medium40 – 79Yellow
Low80 – 100Red

Contributors

The Contributors grid displays the contribution of each of the four Saner CVEM modules (VM, PM, CM, and PA) towards the CHS Score of the Account. You get a clear view of the factors – CVEs, CCEs, Missing Patches, and PAs that are bringing down the CHS score of the Account.

You can download the information presented in the Contributors graph in a CSV format. Click on the  icon to download and save the file on your machine.

Cyber Hygiene Trend

The Cyber Hygiene Trend graph shows the trend in the Cyber Hygiene Score over the past 30 days. The trending graph gives a visual representation of change in score over time, helping the user to analyze the difference in the count of vulnerabilities and other risks that exist in an account. The CHS trending graph also helps to examine the impact of remediation actions performed on the Account.

Similarly, the Cyber Hygiene Trend graph shows the score prediction for the next day, assuming that the user undertakes all the recommended remediation actions against detected vulnerabilities and risks. The difference between the predicted and actual scores of an Account reflects the impact of remedial actions performed by the user.

You can download the information presented in the Cyber Hygiene Trend graph in a CSV format. Click on the  icon to download and save the file on your machine.

Frequency Distribution of Devices by Score

The Frequency Distribution of Devices graph shows the number of devices that fall into each score band. Clicking on the number displayed on the Device tile provides the device’s hostname that falls into the particular score band.

Clicking on the hostname takes you to the Device Details page. Here, you can find more information about the device.

The top section of the page displays the following details:

  • Cyber Hygiene Score: CHS Score for the device will be displayed right below the display icon.
  • Device Name: This field displays the host’s name detected during the network scan.
  • Operating System: This field displays the name of the operating system detected running on the host during the network scan.
  • Processor/Architecture: This field displays the type of processor installed on the system and the manufacturer of the processor.
  • Total Number of Cores: This field displays the number of cores available on the processor.
  • Installed Memory: This field displays the total memory available on the device.
  • Primary Mac Address: This field displays the host’s mac address detected during the network scan by the Network Scanner.
  • Primary IP Address: This field displays the IP Address assigned to the host.
  • Group: This field displays the group to which the device belongs.
  • Agent Version: This field displays the build version of the Saner Agent installed on the device.
  • Last Scan: This field displays the date and time Network Scanner performed the last network scan on the host.
  • Next Scan: This field displays the date and time during which the following network scan will be performed on the host by Network Scanner.
  • Last Updated: This field displays the date and time the Saner Agent downloaded the security content from Saner CVEM Server.
  • Next Update: This field displays the date and time the Saner Agent will download the security content from Saner CVEM Server.
  • Last Remediated: This field displays the date and time patches were applied to the device.
  • Status: This field displays whether the device is online /offline. And the ongoing scan status on the device.
  • Export Device Report: This button downloads all the details about the host presented on the screen in a .pdf format.

You will find six menu options on the left side of the Device Details page. They’re as

  1. Device Details
  2. Assets
  3. Posture Anomaly
  4. Vulnerabilities
  5. Misconfigurations
  6. Patches

Assets

This section displays all the software installed on the endpoint device with their relevant version number.

Vulnerabilities

This section displays all the vulnerabilities detected on the endpoint device.

Misconfigurations

This section displays all the Common Configuration Enumeration (CCE) IDs applicable to the endpoint device.

Patches

This section displays the Installed Patches on the endpoint. At the same time, information related to Missing Security Patches, Missing Non-Security Patches, and Firmware is also shown.

Devices with Cyber Hygiene Score

The Devices with Cyber Hygiene Score table gives a detailed account of all the devices present in the Account. Details shown in the table are as follows.

  • Host Name – This column displays the hostname of the device.
  • IP Address –  This column displays the IP Address associated with the device.
  • Operating System –  This column displays the operating system installed on the device.
  • Group –  This column displays the group to which the device belongs.
  • Family –  This column displays the OS family to which the device belongs.
  • Local Score – This column displays the local score of the device.
  • Global Score – This column displays the global score of the device.
  • Cyber Hygiene Score – This column displays the CHS Score of the device.
  • Status – This column displays the device’s status – whether Active, Inactive, or in Reboot Needed state.

The data provided in the Devices with Cyber Hygiene Score table can be filtered using the below filters.

  • Source
  • OS
  • Family
  • Severity
  • Status

You can download the information presented from the Devices with Cyber Hygiene Score table in a CSV format. Click the icon to download and save the file on your machine.

Top 5 Risk Exposures

The Top 5 Risk Exposures table lists the top 5 risks found in each category (Vulnerabilities, Misconfigurations, Missing Patches, and Posture Anomalies).

The Vulnerabilities tab displays the top 5 vulnerabilities found in the Account. Below-mentioned information shows up in the vulnerabilities table.

  • ID  –  This column displays the CVE-ID associated with the vulnerability.
  • Title – This column gives a brief description of the vulnerability.
  • Asset – This column displays the number of Assets in the Account affected by the vulnerability.
  • Hosts – This column displays the total number of hosts in the Account affected by the vulnerability.
  • Detection Date – This column displays the date when the Saner VM detected the vulnerability in the Account.
  • Release Date – This column shows the date the CVE was made public.
  • Severity – This column displays the severity status of the vulnerability detected.

The Misconfigurations tab displays the top 5  misconfigurations found in the Account. Below-mentioned details show up in the misconfigurations.

  • Risk ID  –  This column displays the CCE-ID associated with the misconfiguration.
  • Title – This column gives a brief description of the misconfiguration.
  • Asset – This column displays the number of Assets in the Account affected by the misconfiguration.
  • Hosts – This column displays the total number of hosts in the Account affected by the misconfiguration.
  • Detection Date – This column displays the date when Saner VM detected the misconfiguration in the Account.
  • Release Date – This column displays the date when the misconfiguration was made publicly known.
  • Severity – This column displays the severity status of the misconfiguration detected.

The Missing Patches tab displays the top 5  missing patches in the Account. Below-mentioned details show up in the missing patches table.

  • Assets  –  This column displays the assets that need immediate patching.
  • Patch – This column displays the link from where the patch can be downloaded.
  • Vendor – This column displays the name of the vendor who released the patch for the asset.
  • Detection Date – This column displays the date when Saner PM detected the missing patch for the Asset.
  • Release Date – This column displays the date when the vendor released the patch.
  • Reboot Status – This column displays whether a device reboot is needed after applying the patch.
  • Severity – This column displays the severity status of the missing patches detected.
  • Hosts – This column displays the total number of hosts with assets requiring immediate patching.

The Posture Anomalies tab displays the top 5 PAs found in the Account. The following details get displayed on the Posture Anomalies table.

  • PA ID  –  This column displays the PA ID associated with the anomaly found in the Account.
  • Title – This column briefly describes the anomaly found in the Account.
  • Anomalies – This column displays the total number of anomalies relevant to the particular PA ID found in the Account.
  • Confidence – This column displays the name of the vendor who released the patch for the asset.
  • Hosts – This column displays the number of hosts affected by the particular anomaly.
  • Detection Date – This column displays the date Saner detected the particular anomaly in the Account.

Share This Article :

  • X
  • LinkedIn
Still stuck? How can we help?

Saner Documentation Feedback

Saner CVEM Network Scanner User Guide
Table of Contents
  • Overview
  • Types of Scores in CHS
    • Raw Score
    • Global Score
    • Local Score
    • Cyber Hygiene Score
    • Patched Account Score
    • Account Score
    • Organization Score
  • Pre-requisites for CHS
  • Get Started with CHS
  • CHS Organization Dashboard
  • Cyber Hygiene Score
  • Cyber Hygiene Trend
  • Accounts Table
  • Configure Weightage
  • Navigation Help
  • CHS Account Dashboard
  • Cyber Hygiene Score
  • Contributors
  • Cyber Hygiene Trend
  • Frequency Distribution of Devices by Score
  • Devices with Cyber Hygiene Score
  • Top 5 Risk Exposures
Copyright 2025 - SecPod. All Rights Reserved. Privacy Policy.
SanerNow Version 6.5.x