Investigate asset fingerprints

Updated at:

Security Center collects asset fingerprint data from your servers — accounts, open ports, running processes, middleware, databases, web services, and more — giving you a detailed inventory of your IT environment. Use this data to spot configuration drift, identify exposed services, and accelerate threat investigation. This topic describes how to collect and view asset fingerprint data for your servers.

Version Limits

  • Subscription: Enterprise or Ultimate (If your current edition does not support this feature, upgrade).

    Note

    The protection edition of the server must be set to the edition you purchased. For more information, see Bind a server protection edition.

  • Pay-as-you-go: Host and Container Security pay-as-you-go is activated (If not activated, purchase).

    Note

    The server protection level must be set to Comprehensive Host Protection or Host and Container Security. For more information, see Bind a server protection level.

How data collection works

Security Center does not automatically collect asset fingerprint data. You must configure automatic periodic collection or trigger a manual collection to obtain the latest asset fingerprint data.

How data collection works

Description

Automatic periodic collection

Security Center supports automatic collection of asset fingerprint data for all assets. You can configure how often you want to automatically capture asset fingerprints.

Collect the latest data for all assets

If you want to immediately view asset fingerprint data for all assets, use Collect Latest Data to collect the latest asset fingerprint data for all assets with one click.

Collect data for a single asset

If you want to immediately view asset fingerprint data for an individual asset, use Collect Data Now to collect the latest asset fingerprint data for the asset with one click.

Important

Asset Center > Hostpage, the AI Component tab has three subtabs: AI Application, AI Tools, and AI Service. The collection method and data source vary by subtab. Details:

  • AI Application Subtab: Displays AI application information collected by the Security Center client installed on your servers.

  • AI Tools, AI Service Subtab: Displays information about AI tools and AI services scanned by the agentless detection feature. If you do not use agentless scanning or have no AI-related assets, these subtabs show no data.

Collect asset fingerprints

Prerequisites

The Security Center client is installed and online on the servers from which you want to collect data. See Install the Security Center client.

Configure automatic periodic collection

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Asset Center > Host. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. In Account tab, click Configuration Management.

  4. In Configuration Management dialog box, set the frequency of acquisition of individual asset fingerprints, and then click OK.

    Important
    • Security Center does not automatically trigger collection tasks to obtain the latest asset fingerprint data. The default refresh rate for all fingerprint types is Disabled. You can set different refresh rates for different fingerprint types.

    • The collection frequency that you set for Middleware also applies to Database, Web Service, and AI Component.Middleware

After you save the configuration, Security Center automatically collects fingerprint data at the specified frequency and updates the corresponding tabs. You can view the latest fingerprint data under each asset fingerprint tab.

Collect the latest data for all assets

  1. InAsset Center > Host > Accounttab, click Collect Latest Data.

  2. In the Collect Latest Data dialog box, select the asset fingerprint types that you want to collect, and click OK.

    Optional asset types include Account, Port, Process, Software, Scheduled task, Middleware, Kernel module, Startup item, and Website.

    Note

    Data collection takes approximately 1 to 5 minutes. Please wait.

Collect data for a single asset

  1. InAsset Center > Host > ServerIn the server list under the tab, click Actions column View of the server for which you want to collect asset fingerprint data.

  2. On the asset details page, click the Asset Fingerprints tab, and then click the tab for the asset fingerprint type that you want to collect.

    Important

    Only servers tied to Security Center Enterprise or Ultimate will display the Asset Fingerprint Investigation tab.

    Select the corresponding tab (for example, Process), and click Collect Latest Data below the tab to manually trigger data collection for that fingerprint type.

  3. In the upper-right corner, click Collect Data Now, on the Collection task issued successfully In the dialog box, click OK.

Note

Data collection takes approximately 1 to 5 minutes. Please wait.

View asset fingerprint data

  1. Log on to Security Center console.

  2. In the left-side navigation pane, choose Asset Center > Host. In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.

  3. In Host page to view asset fingerprint data.

    • View asset fingerprint for all assets

      In Host page, click on the fingerprint tab of the asset you want to view, for example HostAccount tab to view the corresponding asset fingerprint data.

      The left panel shows a list of all accounts and the number of fingerprints for each account. In the upper part of the main area, click Collect Latest Data to manually collect the latest fingerprint data for an individual asset. Use the Server Name/IP drop-down box to filter the target server. The main table displays the root permissions, user groups, expiration time, password expiration status, password lock status, user expiration status, and other security attributes of each account.

      • Asset fingerprint list: includes all asset fingerprints and the number of servers to which each fingerprint is applied.

      • Asset fingerprint details list: Click a target fingerprint in the asset fingerprint list on the left (for example, an account name). The fingerprint details that correspond to the target fingerprint are displayed in the asset fingerprint list on the right.

      • Asset fingerprint search: You can enter information in the search box to search for the target fingerprint. Fuzzy search is supported.

    • View asset fingerprint of an individual asset

      1. In HostServer In the server list under the tab, click Actions column View of the server for which you want to view the asset fingerprint

      2. On the asset details page, click the Asset Fingerprints tab, and then click the asset fingerprint tab that you want to view.

        Important

        Only servers tied to Security Center Enterprise or Ultimate will display the Asset Fingerprint Investigation tab.

Asset fingerprint reference

Asset Fingerprint Type

Description

Account

Collect the account information of the server, including the following:

  • Server Information: The server the account belongs to.

  • Account: The name of the account.

  • Root Permissions: Whether the account has root privileges.

  • User Group: Information about the user group to which the account belongs.

  • Expire At: The expiration time of the account password.

  • Password Expired: Whether the account password has expired.

  • Password Locked: Whether the account password is locked.

  • Account Expired: Whether the account status has expired.

  • Sudo Account: Whether the account has sudo permissions.

  • Interactive Logon Account: Whether the account has login permission.

  • Last Logon: The last time the current account logged on to the server.

  • Last Scan Time: The last time the Security Center collected this type of information from the server.

port

Collect the port information of the external server, including the following:

  • Server Information: Server information where the port is located, including the server name and IP address.

  • Port: Listens on the port number.

  • Network Protocol: Listen to the network protocol used by the port.

  • PID: Identifier of the running process of the server that listens on the port.

  • Associated Process: Listen to the running process of the server corresponding to the port.

  • IP: Listen to the IP of the network card bound by the port.

  • Last Scan Time: The last time the Security Center collected listening port information.

Process

Collect process information from the server, including the following:

  • Server Information: Server information where the process is located, including the server name and IP address.

  • Process Name Name of the process

  • Process Path: The path to start the process.

  • Startup Parameter: Start parameter of the process.

  • Start Time: The start time of the process.

  • User: The user who started the process.

  • Execution Permissions: Permission for the process to start the user.

  • PID: ID of the process.

  • Parent Process ID: ID of the parent process that the process started.

  • MD5 Hash Value of Process File: The MD5 value of the process file.

  • Package Process Installation: Whether to use the processes in the installation package.

  • Process Status: The current state of the process.

  • Last Scan Time: The last time the Security Center collected this type of information from the server.

Middleware

Gathers middleware information for the server. Middleware refers to system components that can run independently, such as MySQL (database), Docker (container component), etc. Specifically, collect the following:

  • Server Information: The server information where the middleware is located, including the server name and IP address.

  • Middleware: Name of the middleware.

  • Middleware: The type of middleware it belongs to.

  • Runtime Environment Version: The version of the environment in which the middleware is running.

  • Version: The version number of the original middleware.

  • PID: ID of the middleware startup process.

  • Process Startup Path: Startup path of the middleware.

  • Version Authentication Information: How to get the middleware version.

  • Parent Process ID: ID of the parent process started by the middleware.

  • User: Startup user of the middleware.

  • Listener IP Address: IP address where the middleware starts listening.

  • Listening Port: The port on which the middleware starts listening.

  • Listener Status: The current listening state of the middleware.

  • Listener Port Protocol: The network protocol on which the middleware is currently listening.

  • Start Time: Start time of the middleware.

  • Process Command Line: Parameters for the middleware startup execution command.

  • Container Name: Name of the container where the middleware is located.

  • Image Name: Name of the image where the middleware is located.

  • Configure Path: The absolute path where the middleware startup configuration is located.

  • Last Scan Time: The last time the Security Center collected this type of information from the server.

AI Components

AI Application: AI application information on the server collected by the Security Center client. AI components refer to the basic functional modules that make up an AI system, such as data module components, model module components, inference module components, etc. The information collected includes the following:

  • Server Information: The server information where the AI component is located, including the server name and IP address.

  • AI Component: The name of the AI component.

  • Type: Type of AI component.

  • Version: Version of the AI component.

  • PID: ID of the AI component process.

  • Process Startup Path: Startup path of the AI component.

  • Version Authentication Information: How to verify and obtain the version of the AI component.

  • Parent Process ID: ID of the parent process that started the AI component.

  • User: The system user account to which the process initiated by the AI component belongs.

  • Listener IP Address: The network address of the AI component binding. A value of 0.0.0.0 means that the service listens on the specified ports on all IPv4 network interfaces; a value of:: means that the service listens on the specified ports on all IPv6 network interfaces.

  • Listening Port: The port on which the AI component starts listening.

  • Listener Status: The current listening state of the AI component.

  • Listener Port Protocol: The network protocol on which the AI component is currently listening.

  • Start Time: The startup time of the AI component.

  • Process Startup Command: The complete process start command and parameters of the AI component.

  • Container Name: Name of the container instance where the AI component is located.

  • Image Name: Mirror repository full path identification of the AI component.

  • Configure Path: Absolute path list of key profiles for AI components.

  • Last Scan Time: The last time the Security Center collected this type of information from the server.

AI Tools: Agentless detection function from cloud server ECS,cloud disk snapshots,Information about the AI tools scanned in the mirror.

AI Tool refers to software libraries and framework components used to develop, train, deploy, or invoke AI models. These tools, often in the form of Python packages, are the basis for building and running large model applications. The information collected includes the following:

  • Server information: The server information where the AI tool is located, including the server name and IP address.

  • AI Tool: The name of the AI tool.

  • Version: The version number of the AI tool.

  • Installation path: The installation path of the AI tool.

  • Latest Scan Time: Agentless detects when this information was last scanned.

AI Service: Agentless detection function from cloud server ECS,cloud disk snapshots,The AI service information scanned in the mirror.

AI Service refers to a large language model (LLM) interface provided by an external platform, which can be called through the network, and is designed to support the application implementation of various artificial intelligence functions such as intelligent question answering, code generation, image understanding, etc. The information collected includes the following:

  • Server information: The server information where the AI service is located, including the server name and IP address.

  • AI Service: The name of the AI service.

  • EndPoint: The address of the interface that the AI service provides access to.

  • File location: The path to the profile for the AI service.

  • Latest Scan Time: Agentless detects when this information was last scanned.

Database

Collect information about the database on the server, including the following:

  • Server Information: Server information where the database is located, including the server name and IP address.

  • Database Name The name of the database.

  • Type: The type of database.

  • Version: The version number of the database.

  • PID: ID of the startup process for the database.

  • Process Startup Path: The startup path of the database.

  • Version Authentication Information: How to get the database version.

  • Parent Process ID: ID of the parent process started by the database.

  • User: The startup user of the database.

  • Listener IP Address: The IP address where the database starts listening.

  • Listening Port: Port on which the database starts listening.

  • Listener Status: The current listening state of the database.

  • Listener Port Protocol: The network protocol on which the database is currently listening.

  • Start Time: The start time of the database.

  • Process Startup Command: Parameters for launching the database to execute the command.

  • Container Name: Name of the container where the database is located.

  • Image Name: Name of the mirror where the database is located.

  • Configure Path: The absolute path where the database startup configuration is located.

  • Last Scan Time: The last time the Security Center collected this type of information from the server.

Web service

Web service information. Regularly collect information about web services on the server, including the following:

  • Server Information: Server information, including server name and IP address.

  • Web Service Name: Web service name.

  • Type: Type of web service.

  • Runtime Environment Version: The version of the JDK environment in which the web service is running.

  • Version: Version number of the web service.

  • PID: ID of the web service startup process.

  • Process Startup Path: Startup path of the web service.

  • Version Authentication Information: How to get the version.

  • Parent Process ID: ID of the parent process started by the web service.

  • User: The user who started the web service.

  • Listener IP Address: The address where the web service starts listening on the IP.

  • Listening Port: Port on which the web service starts listening.

  • Listener Status: The current listening state of the web service.

  • Listener Port Protocol: The network protocol on which the web service is currently listening.

  • Start Time: Start time of the web service.

  • Process Startup Command: Parameters for the Web service startup execute command.

  • Container Name: Name of the container where the web service is located.

  • Image Name: Name of the image where the web service is located.

  • Configure Path: Absolute path where the web service startup configuration is located.

  • Web Directory: Path to the web configuration page.

  • Last Scan Time: The last time the Security Center collected this type of information from the server.

Software

Software assets. Regularly collect software information from the server, including the following:

  • Server Information: The server on which the software resides, including the server name and IP address.

  • Software Name: Name of the software.

  • Version: The version number of the software.

  • Software Startup Path: The path to the software startup.

  • Software Update Time: when the software version was updated.

  • Last Scan Time: The last time the Security Center collected software information.

Scheduled task

Periodically collect task path information that is periodically executed on your server. The following information is collected for the specific task:

  • Server Information: Server information where the scheduled task is located, including the server name and IP address.

  • Run Command: The command line from which the task is scheduled to execute.

  • Task Period: Schedules the timing period of a task.

  • MD5: hash of the scheduled task process.

  • Account Name: The account on which the task was initiated.

  • Last Scan Time: The last time the Security Center collected this type of information from the server.

Startup item

Startup item information. Periodically collect startup item information from the server, including the following:

  • Server Information: The server information where the boot entry is located, including the server name and IP address.

  • Startup Item Path: The path where the service is started.

  • Last Scan Time: The last time the Security Center collected this type of information from the server.

Kernel module

Kernel module information. Regularly collect the kernel module information of the server, including the following:

  • Server Information: Server information where the kernel module is located, including the server name and IP address.

  • Module Name: The name of the kernel module.

  • Module Size: The size of the kernel module file.

  • Module File Path: The path where the kernel module is located.

  • Total Submodules: Number of other dependent modules.

  • Last Scan Time: The last time the Security Center collected this type of information from the server.

Website

Website information. Regularly collect information about the server's website, including the following:

  • Server Information: Information about the server where the Web site is located, including the server name and IP address.

  • Domain Name: The domain name configured for the website.

  • Website Type: The type of software that the web service uses.

  • Port: Listening port for the web service.

  • Web Path: The path to the WebHome directory.

  • Web Root Path: The path to the root directory in the web configuration.

  • User: The user who started the web service.

  • Directory Permission: Permissions for the web directory.

  • Monitoring Protocol: Web-initiated snooping protocol.

  • PID: ID of the process.

  • Start Time: Start time of the web service.

  • Image Name: Name of the image where the Web site is located.

  • Container Name: The name of the container where the Web site is located.

  • Last Scan Time: The last time the Security Center collected this type of information from the server.

Related documents.

  • If you need more information about the current security status of your assets, you can view the details of the server in the Asset Center. For more information, seeManage servers.

  • For more information on the IDC probe discovery feature, seeOnboard IDC assets.