To communicate with vulnerability assessment (VA) sources, add them to the system, add communication parameters for the VA vendor, schedule parameters for how often data is retrieved, and change severity calculations.
On the system navigation tree, select a Trellix Enterprise Security Manager - Event Receiver, then click the Properties icon
.Click Vulnerability Assessment.
Type the Frontline client ID number. Digital Defense Frontline requires Client ID.
On FusionVM, the name of the company that must be scanned. If you leave company name blank, the system scans all companies to which the user belongs. Separate multiple company names with commas.
(Qualys QualysGuard) Select the method to retrieve the VA data. HTTP/HTTPS is the default. Options include: SCP, FTP, NFS, CIFS, and Manual upload.
Note
A Qualys QualysGuard log file manual upload has a file size limit of 2 GB.
Type the domain of the Windows system (optional, unless your domain controller or server exists in a domain).
Identify the directory where exported scan files reside.
Identify the exported scan file format (XML, NBE).
Identify the location where Saint was installed on the server. The installation directory for a Saint appliance scanner is
/usr/local/sm/
Identify IP addresses:
eEye REM — IP address of the eEye server that sends trap information
eEye Retina — IP address of the client holding exported scan files (.rtd)
Nessus, OpenVAS, LanGuard, and Rapid7 Metasploit Pro — IP address of the client holding exported scan files
NGS — IP address of the system storing the Squirrel reports
Rapid7, Lumension, nCircle, and Saint — IP address of the respective server
Identify the method used to retrieve exported scan files (SCP, FTP, NFS, or CIFS mount). LanGuard always uses CIFS.
If you select nfs in the Method field, the system adds Mount Directory fields. Enter the mount directory set when you configured nfs.
Identify passwords:
Nessus, OpenVAS, LanGuard, and Rapid7 Metasploit Pro — The password of SCP or FTP.
NGS — The password for the SCP and FTP methods.
Qualys and FusionVM — The password for the Qualys Front Office or FusionVM user name.
Rapid7 Nexpose, Lumension, nCircle, and Saint — The password to use when connecting to the web server.
Digital Defense Frontline — The web interface password.
Identify the port Rapid7 Nexpose, Lumension, nCircle, or Saint web server are listening on. The default for Rapid7 Nexpose is 3780, for Lumension is 205, for nCircle is 443, and for Saint is 22.
Identify the name of a particular project or workspace, or leave it blank to grab all projects or work spaces.
Identify the proxy IP address, user name, password for the proxy user name, and the port on which the HTTP proxy is listening.
Type the URL of the Qualys or FusionVM server to query.
Identify the remote path and share name for CIFS method Nessus, OpenVAS, eEye Retina, Metasploit Pro, LanGuard, and NGS.
You can use back or forward slashes in the path name (for example,
Program Files\CIFS\va
or
/Program Files/CIFS/va)
Indicate the frequency to retrieve VA data from the Trellix Enterprise Security Manager - Event Receiver:
Daily — Select the time you want the data retrieved each day.
Weekly — Select the day of the week and the time on that day you want the data retrieved.
Monthly — Select the day of the month and the time on that day that you want the data retrieved.
If you do not want the data retrieved at a preset time, select Disabled.
Note
eEye REM does not support data retrieval from the source so the data must be retrieved from the Trellix Enterprise Security Manager - Event Receiver.
Indicate the frequency to retrieve VA data from the VA source.
Saint — Identify the session data is gathered from. To include all sessions, type All.
If you select authNoPriv or authPriv in the SNMP security level field, SNMP authentication password is active. Enter the password for the authentication protocol selected in the SNMP authentication protocol field.
If you select authNoPriv or authPriv in the SNMP security level field, SNMP authentication protocol is active. Select the type of protocol for this source: MD5 or SHA1 (SHA1 and SHA see the same protocol type). Make sure that your REM Events Server configuration matches your selection.
Select the SNMP community that was set when you configured the REM Events Server.
If you select authPriv in the SNMP security level field, SNMP privacy password SNMP Community are active. Enter the password for the DES or AES privacy protocol. In FIPS mode, AES is the only option available.
If you select authPriv in the SNMP security level field, SNMP privacy protocol is active and you can select either DES or AES. In FIPS mode, AES is the only option available.
Select the security level for this source:
noAuthNoPriv — No authentication protocol and no privacy protocol
authNoPriv — Authentication protocol but no privacy protocol
authPriv — Both authentication and privacy protocol.
Note
SNMP authentication and privacy fields become active based on the security level you select. Make sure that your REM Events Server configuration matches your selection.
Select the security name in REM Events Server Configuration.
Select the version of SNMP for the source. The SNMP fields are activated based on the version you select.
(Optional) The SNMPv3 Engine ID of the trap sender, if you use an SNMPv3 profile.
(Optional) Type the password that is required to access the Saint installation directory.
Indicate the default time-out value for a source or provide a specific time-out value. You can increase the time-out value to allow more VA data retrieval time. If you provide a value, it is used for all communications.
(Optional) Authentication token that can be set in the Metasploit Global Settings.
URL to the Digital Defense Frontline server.
If you select to use the HTTP proxy, the Proxy IP Address, Proxy Port, Proxy Username, and Proxy Password fields become active.
If you select ftp in the Method field, this field becomes active. Then select when to use passive mode.
Select Use sudo if you have access to the Saint installation directory and want to use this access.
Select whether to use a previously defined profile. Use System Profile (eEye REM) deactivates all SNMP fields. When you select one of the existing system profiles, the system populates fields with the information in the selected profile.
If you use Windows authentication mode for the SQL Server, enter the user name of the Windows box. If not, enter the user name of the SQL Server.
Nessus, OpenVAS, and Rapid7 Metasploit Pro — User name of SCP or FTP
NGS — User name for the SCP and FTP methods
Qualys or FusionVM — Front Office or FusionVM user name with which to authenticate
Rapid7 Nexpose, Lumension, nCircle, and Saint — User name when connecting to the web server
Digital Defense Frontline — Web interface user name
Identify the VA source name.
Identify the wildcard expression used to describe the name of exported scan files. The wildcard expression can use an asterisk (*) or question mark (?) with the standard definition of wildcard in a file name.
Note
If you have both NBE and XML files, specify if you want NBE or XML files in this field (for example, *.NBE or *.XML). If you only use an asterisk (*), you get an error.
Write any changes to the device.
Click Apply or OK.