Docs
Scan Ingestion

Scan Ingestion

Guide for setting up scan ingestion within the ACE platform.

Scan Ingestion

Scan ingestion in ACE allows users to automatically or manually upload scan results from various sources, such as S3 buckets, into the system. This ensures that the latest scan data is available for analysis and tracking within the relevant environments. This guide will only cover the process of manual scan ingestion. For more information regarding automated scan ingestion, refer to the Automated Scan Ingestion documentation.

How it Works

When ingesting a scan, the ACE service will allow the user to specify a "tool" that was used to generate the scan results. (Trivy, Nessus, Grype, etcetera.) ACE has dedicated parsers for many services, ensuring accurate interpretation and mapping of scan data to the corresponding assets and vulnerabilities, including:

  • ACE 1.0
  • ARF
  • ASFF
  • AWS Config Compliance
  • AWS Inventory
  • Bearer
  • Checkov
  • Grype
  • Nessus
  • Nmap
  • NPM Audit
  • OVAL
  • Syft
  • Tanium
  • Trivy
  • Trufflehog
  • XCCDF
  • Zap

Services without a dedicated parser can still be ingested, but are passed through a Universal AI parser for interpretation and mapping to the appropriate assets and vulnerabilities. Output may contain errors in such a case.

Once uploaded, assets (such as servers, containers, or cloud resources) and vulnerabilities/compliance checks will be available within the assigned environment. The parsers are intelligent, able to recognize repeat assets and consolidate them, and after not seeing an asset in some time, filter it out through the Lifecycle System. The Scan Tools used allow for filtering later on the line to understand the source of specific vulnerabilities or compliance issues.

The

Manual Scan Ingestion

To manually ingest a scan, follow these steps:

  1. Click the Scans button on the sidebar.
  2. Click the Upload Scan button.
  3. Select the environment to which you wish to upload the scan.
  4. Optionally link a parent asset to establish hierarchichal relationships. Otherwise, will be automatically attempted or default to root.
  5. Select the file containing the scan results. (Supported formats include JSON, XML, CSV, .nessus)
  6. Set the tool name. This will be used for asset consolidation and filtering. If uploading repeat scans, ensure the name is the EXACT SAME as previous scans of this type.
  7. Click the Save Scan button.

Note: A scan cannot be saved without a valid License Key. Refer to the Admin Quick Start Guide for instructions on obtaining and configuring a License Key.

Note: The raw scan file is saved for a predetermined period of time and can be adjusted in System Settings. The default is 30 days.

Scan Lists

To view the list of ingested scans, navigate to the Scans page, then click on View Scans. The scan list provides an overview of all scans.

Details

Clicking on a specific scan from the scan list will provide detailed information about that scan.

One can see the number of assets, vulnerabilities, and compliance checks found, as well as the severity of the vulnerabilities and compliance passes, fails, errors, and skips. In the Assets tab, one can see the list of assets discovered during the scan, along with their details such as asset type, IP address, hostname, and associated vulnerabilities. In the Vulnerabilities tab, one can see the list of vulnerabilities identified during the scan, along with their details such as severity, affected assets, and status. In the Compliance tab, one can see the list of compliance checks performed during the scan, along with their details such as result (pass, fail, error, skip) and associated assets.

In the Raw Report tab, one can view the raw scan file that was uploaded, if available. This allows for verification and troubleshooting of the scan ingestion process.

Note: The Raw Report tab may not be available for all scans, depending on the scan tool and the format of the uploaded scan file. If the scan availability date has passed, it will also automatically be deleted.