Investigate asset fingerprints
Security Center collects asset fingerprint data from your servers — accounts, open ports, running processes, middleware, databases, web services, and more — giving you a detailed inventory of your IT environment. Use this data to spot configuration drift, identify exposed services, and accelerate threat investigation. This topic describes how to collect and view asset fingerprint data for your servers.
Version Limits
Subscription: Enterprise or Ultimate (If your current edition does not support this feature, upgrade).
NoteThe protection edition of the server must be set to the edition you purchased. For more information, see Bind a server protection edition.
Pay-as-you-go: Host and Container Security pay-as-you-go is activated (If not activated, purchase).
NoteThe server protection level must be set to Comprehensive Host Protection or Host and Container Security. For more information, see Bind a server protection level.
How data collection works
Security Center does not automatically collect asset fingerprint data. You must configure automatic periodic collection or trigger a manual collection to obtain the latest asset fingerprint data.
How data collection works | Description |
Security Center supports automatic collection of asset fingerprint data for all assets. You can configure how often you want to automatically capture asset fingerprints. | |
If you want to immediately view asset fingerprint data for all assets, use Collect Latest Data to collect the latest asset fingerprint data for all assets with one click. | |
If you want to immediately view asset fingerprint data for an individual asset, use Collect Data Now to collect the latest asset fingerprint data for the asset with one click. |
page, the AI Component tab has three subtabs: AI Application, AI Tools, and AI Service. The collection method and data source vary by subtab. Details:
AI Application Subtab: Displays AI application information collected by the Security Center client installed on your servers.
AI Tools, AI Service Subtab: Displays information about AI tools and AI services scanned by the agentless detection feature. If you do not use agentless scanning or have no AI-related assets, these subtabs show no data.
Collect asset fingerprints
Prerequisites
The Security Center client is installed and online on the servers from which you want to collect data. See Install the Security Center client.
Configure automatic periodic collection
Log on to Security Center console.
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
In Account tab, click Configuration Management.
In Configuration Management dialog box, set the frequency of acquisition of individual asset fingerprints, and then click OK.
ImportantSecurity Center does not automatically trigger collection tasks to obtain the latest asset fingerprint data. The default refresh rate for all fingerprint types is Disabled. You can set different refresh rates for different fingerprint types.
The collection frequency that you set for Middleware also applies to Database, Web Service, and AI Component.Middleware
After you save the configuration, Security Center automatically collects fingerprint data at the specified frequency and updates the corresponding tabs. You can view the latest fingerprint data under each asset fingerprint tab.
Collect the latest data for all assets
Intab, click Collect Latest Data.
In the Collect Latest Data dialog box, select the asset fingerprint types that you want to collect, and click OK.
Optional asset types include Account, Port, Process, Software, Scheduled task, Middleware, Kernel module, Startup item, and Website.
NoteData collection takes approximately 1 to 5 minutes. Please wait.
Collect data for a single asset
InIn the server list under the tab, click Actions column View of the server for which you want to collect asset fingerprint data.
On the asset details page, click the Asset Fingerprints tab, and then click the tab for the asset fingerprint type that you want to collect.
ImportantOnly servers tied to Security Center Enterprise or Ultimate will display the Asset Fingerprint Investigation tab.
Select the corresponding tab (for example, Process), and click Collect Latest Data below the tab to manually trigger data collection for that fingerprint type.
In the upper-right corner, click Collect Data Now, on the Collection task issued successfully In the dialog box, click OK.
Data collection takes approximately 1 to 5 minutes. Please wait.
View asset fingerprint data
Log on to Security Center console.
In the left-side navigation pane, choose . In the upper-left corner of the console, select the region where the asset to be protected is located: Chinese Mainland or Outside Chinese Mainland.
In Host page to view asset fingerprint data.
View asset fingerprint for all assets
In Host page, click on the fingerprint tab of the asset you want to view, for example HostAccount tab to view the corresponding asset fingerprint data.
The left panel shows a list of all accounts and the number of fingerprints for each account. In the upper part of the main area, click Collect Latest Data to manually collect the latest fingerprint data for an individual asset. Use the Server Name/IP drop-down box to filter the target server. The main table displays the root permissions, user groups, expiration time, password expiration status, password lock status, user expiration status, and other security attributes of each account.
Asset fingerprint list: includes all asset fingerprints and the number of servers to which each fingerprint is applied.
Asset fingerprint details list: Click a target fingerprint in the asset fingerprint list on the left (for example, an account name). The fingerprint details that correspond to the target fingerprint are displayed in the asset fingerprint list on the right.
Asset fingerprint search: You can enter information in the search box to search for the target fingerprint. Fuzzy search is supported.
View asset fingerprint of an individual asset
In HostServer In the server list under the tab, click Actions column View of the server for which you want to view the asset fingerprint
On the asset details page, click the Asset Fingerprints tab, and then click the asset fingerprint tab that you want to view.
ImportantOnly servers tied to Security Center Enterprise or Ultimate will display the Asset Fingerprint Investigation tab.
Asset fingerprint reference
Asset Fingerprint Type | Description |
Account | Collect the account information of the server, including the following:
|
port | Collect the port information of the external server, including the following:
|
Process | Collect process information from the server, including the following:
|
Middleware | Gathers middleware information for the server. Middleware refers to system components that can run independently, such as MySQL (database), Docker (container component), etc. Specifically, collect the following:
|
AI Components | AI Application: AI application information on the server collected by the Security Center client. AI components refer to the basic functional modules that make up an AI system, such as data module components, model module components, inference module components, etc. The information collected includes the following:
|
AI Tools: Agentless detection function from cloud server ECS,cloud disk snapshots,Information about the AI tools scanned in the mirror. AI Tool refers to software libraries and framework components used to develop, train, deploy, or invoke AI models. These tools, often in the form of Python packages, are the basis for building and running large model applications. The information collected includes the following:
| |
AI Service: Agentless detection function from cloud server ECS,cloud disk snapshots,The AI service information scanned in the mirror. AI Service refers to a large language model (LLM) interface provided by an external platform, which can be called through the network, and is designed to support the application implementation of various artificial intelligence functions such as intelligent question answering, code generation, image understanding, etc. The information collected includes the following:
| |
Database | Collect information about the database on the server, including the following:
|
Web service | Web service information. Regularly collect information about web services on the server, including the following:
|
Software | Software assets. Regularly collect software information from the server, including the following:
|
Scheduled task | Periodically collect task path information that is periodically executed on your server. The following information is collected for the specific task:
|
Startup item | Startup item information. Periodically collect startup item information from the server, including the following:
|
Kernel module | Kernel module information. Regularly collect the kernel module information of the server, including the following:
|
Website | Website information. Regularly collect information about the server's website, including the following:
|
Related documents.
If you need more information about the current security status of your assets, you can view the details of the server in the Asset Center. For more information, seeManage servers.
For more information on the IDC probe discovery feature, seeOnboard IDC assets.