How to Launch Scans from TruConfirm tab

When you launch the TruConfirm assessment from the TruConfirm tab, the system offers you options to scan a range of asset IPs for TruConfirm applicable CVEs, business entities, or asset tags. To launch the scan,

From this page, you can click Create to add an option profile. For more information on the information to be added while configuring your option profile, refer the Option profile from VMDR Online help.

 

  1. Go to the TruConfirm tab > Scan tab.
  2. Click TruConfirm Assessment.
    The platform launches the 
    TruConfirm Assessment steps. By default, the system shows Step 1: Basic Information

  3. Enter the title for the scanner and select the Exploit Validation Source. You can select either Cloud Agent or Scanner Appliance.

    If you select Cloud Agent, the platform does not display the Option Profile and Scanner Appliance fields.


    Insert the basic information required for launching the scan
  4. Click Next.
    The platform shows the Assessment Scope page. This page gives you an overview. You can see the scope of the TruConfirm assessment. You can view the number of assets, unique CVEs, and more.
    The assessment scope provides list of assets and tags
  5. From the Host Details section, click any of the following:
    • Assets: If you select this option, the platform allows you to enter the asset range based on IPv4, IPv6, and FQDN. The platform runs the scans on these assets.

      select the tags

    • Tags: If you select Tags, the platform allows you to select specific tags, as shown in the figure below.
      You can click All Tags to view and select from the complete list of available tags. As you select a tag, it gets added to the right side, as shown in the image below:
      list of selected tags
      Click Add Tag. The platform includes the assets associated with these tags in the scope.
    • Business Entities: If you select Business Entities, the platform allows you to select specific business entities. You can select the business entities from the list and click Apply.
      select the required business entities

    When you select Cloud Agents, you can only select the assets, tags, or Business Entities for which TruConfirm module is activated, and Cloud Agent is installed. You must choose the applicable assets, tags, or Business Entities as part of the scan setup.

  6. From the CVE Details section, you can click any one of the following options:
    • All CVEs: the platform includes all the CVEs in the scan scope.
    • Select CVEs: If you select this option, the platform allows you to select the available CVEs.

      Select the CVE and click Apply.

  7. Click Next
    The platform shows the Configuration tab. This tab offers gives you greater control and automation for your TruConfirm vulnerability scans. From this tab, you can configure precise scan schedules to launch automated scans without manual intervention.
  8. Select any of the following schedules: 
    • Run Now
    • Single Occurrence: this is a one-time scan at a defined date and time.
    • Recurring: these are scans that run on a set cadence. For these recurring scans, you can set schedules to run daily, weekly, or monthly and specify which days of the week scans should run.

      For Cloud Agent, the Run Now schedule type is available; the other two types will be available in subsequent releases.

  9. From the Timezone Settings section:
    • Select the timezone to schedule the scan.
    • Configure the start date and time for the scan.
    • Select the frequency for the scan. 
    • Set the end-date and time for the scan. 

    If you have selected Cloud Agent, you can see an Assessment Timeout section in the Configuration step. This configuration ensures that the TruConfirm assessment is started within the specified scan window.

  10. Click Next.
    The platform shows the Notifications page. You can set up and manage email notifications for your TruConfirm scans, if required. 
    enable the notifications for scan completion
  11. Enter one or multiple email notification recipients.  
  12. From the Notify section, choose when to send notifications, whether it’s when a scan starts, finishes, or encounters an error. As you click an option, the platform allows you to enter the corresponding message.
  13. Click Next.
    The platform shows the Review & Confirm page.
    Review and confirm the details
  14. Click Launch.
    The platform launches the TruConfirm assessment. The entry for this assessment is displayed on the TruConfirm tab > Scan tab. One entry is created for every scan. The status can be queued, running, etc.