Inventory Columns
In Tenable Attack Surface Management, an inventory is where you view your organization's assets. You can view the inventory details in a table format. Add or remove columns to the inventory table to get specific details of an asset in your inventory.
To configure the columns for the inventory table:
- In the upper-right corner of the Inventory page, click the
icon.
A drop-down menu appears.
-
Select Manage Columns.
The Select data types to list page appears with the list of columns that you can enable or disable.
-
On the Explore page, use the Columns drop-down list to Customize Columns. See Explore.
The following table shows the available columns that you can choose and their descriptions.
Column Name | Description |
---|---|
Security | |
SSL/TLS Expiration | Date until the SSL certificate of the asset is valid. |
SSL/TLS Fingerprint | SSL fingerprint of the asset. |
SSL/TLS EV Certificate | States whether the asset has an Extended Validation (EV) certificate. |
SSL/TLS Issuer Country | SSL certificate issuer country. |
SSL/TLS Issuer Organization | SSL certificate issuer organization. |
SSL/TLS Valid From | The date from which the SSL certificate of the asset is valid. |
SSL/TLS Subject Alt Name | SSL subject alternate names of the asset. |
SSL/TLS Cypher Suites | Cypher suites available on the asset. |
SSL/TLS Key Length | Peer certificate RSA bit size. |
SSL/TLS Protocol | SSL protocols used by the asset. |
SSL/TLS error | SSL errors produced by the asset. |
SSL/TLS Serial Number | SSL serial number of the asset. |
Captchas | CAPTCHA software used by the asset. |
Cookie Compliance | Cookie compliance used by the asset. |
Secret Keys | Secret keys used by the asset. Tenable Attack Surface Management collects this data by executing multiple regular expressions against the rendered HTML of the site. |
Login | Whether the asset redirects to or contains a login page. |
JARM Hash | A hash that can be used to group assets having similar SSL configurations. |
Bug Bounty URL | Bug bounty programs that the asset is part of. |
HTTP Response | |
Content type | The type of content served by the asset. |
Content language | The language of content served by the asset. |
Vary | The value of the Vary HTTP header set by the asset. |
Response Header Value | HTTP header values returned by the asset. |
Response Security Header Value | HTTP security header values returned by the asset. |
Sets Cookies | States whether the asset sets cookies or not. |
Content Length | The length of the content served by the asset in bytes. |
Canonical URL | Canonical URL found in the HTML body returned by the asset. |
Response code | The response code returned from the final URL the asset redirects to. |
HTML | Raw response body returned by the asset. |
Document Title | HTML document title. |
Networking | |
Host | Hostname of the asset. |
Record Type | DNS record type of asset. |
Record Value | DNS record value of the asset. |
Redirect Chain | The chain of HTTP or client-side redirects that navigated the system to screenshot.finalurl. |
IP | IP address of the asset. |
Is subdomain | Indicates whether the hostname of the asset is a subdomain or not. |
Final response code | The response code returned from the final URL the asset redirects to. |
ASN | The Autonomous System organization of the asset. |
ASN Number | The Autonomous System Number (ASN) of the asset. |
Final url | The final URL the asset redirects to. |
Domain | Domain name of asset. |
Hosting Provider | Cloud provider of the asset. |
Cloud Hosted | Whether the Asset is cloud-hosted or not. |
Network Devices | Network devices used by the asset. |
Mixed Content | Mixed content returned by the asset. |
Network Storage | Network storage software used by the asset. |
CDN | CDNs used by the asset. |
Remote Access | Remote access software used by the asset. |
Containers | Container software used by the asset. |
SaaS | SaaS solutions used by the asset. |
PaaS | PaaS solutions used by the asset. |
IaaS | IaaS solutions used by the asset. |
Load Balancer | Load Balancers used by the asset. |
Reverse Proxy | Reverse proxies used by the asset. |
Nameservers | DNS nameservers of the asset based on WHOIS data. |
Programming | |
Mobile Frameworks | Mobile frameworks used by the asset. |
Programming Languages | Programming languages used by the asset. |
Web Frameworks | Web frameworks used by the asset. |
Dev Tools | Development tools used by the asset. |
JavaScript Libraries | JavaScript libraries used by the asset. |
JavaScript Frameworks | JavaScript frameworks used by the asset. |
Landing Page Builders | Landing page builders used by the asset. |
Documentation Tools | Documentation tools used by the asset. |
Geolocation | |
Continent | Location of the asset. |
Country | Location of the asset. |
City | Location of the asset. |
Latitude | Location of the asset. |
Longitude | Location of the asset. |
Timezone | Location of the asset. |
Postal | Postal code of the asset. |
In EU | Whether the asset is located in the EU or not. |
Subdivisions | Location of the asset. |
Registered Country | Country where the asset was registered. |
Maps | Maps software used by the asset. |
Services | |
Ports | Ports open on the asset. |
Services | Service running on the asset. |
Banners | Banners returned by services running on the asset. |
CPE | Services running on the asset in Common Platform Enumeration (CPE) format. |
CVE | IDs of CVEs that apply to the asset. |
CVSSv3 Scores | Unique CVSS3 scores that apply to the asset. |
CVSSv3 Vectors | Unique CVSS3 vector strings that apply to the asset. |
Server | Web server running on the asset based on HTTP response headers. |
RBL | Realtime Blackhole Lists (RBL) that contain the asset. |
Web Servers | Web servers running on the asset. |
Email service | Emails used by the asset. |
Web applications | |
Browser fingerprinting | Browser fingerprinting tools. |
Buy now pay later | Buy now pay later tools. |
Cart abandonment | Cart abandonment tools. |
Content curation | Content curation tools. |
Customer data platform | Customer data platform tools. |
Digital asset management | Digital asset management tools. |
Geolocation | Geolocation tools. |
Hosting | Hosting information. |
Loyalty & rewards | Loyalty and rewards tools. |
Performance | Performance tools. |
Referral marketing | Referral marketing tools. |
Reservations & delivery | Reservations and delivery platforms. |
Reviews | |
RUM | Real User Monitoring (RUM) tools. |
Segmentation | Segmentation tools. |
Shipping carriers | Shipping carrier tools. |
Translation | Translation tools. |
Wordpress plugins | WordPress plugin tools. |
Wordpress themes | WordPress theme tools. |
Recruitment & staffing | Recruitment and staffing tools. |
Returns | Returns technologies. |
Livestreaming | Livestreaming tools. |
Ticket booking | Ticket booking tools. |
Augmented reality | Augmented reality tools. |
Cross border ecommerce | Cross-border ecommerce tools. |
Message Boards | Message boards used by the asset. |
CMS | Content Management Systems (CMS) used by the asset. |
Database Managers | Database managers used by the asset. |
Wikis | Wiki software used by the asset. |
Hosting Panels | Hosting panels used by the asset. |
Wordpress Vulnerability IDs | WPScan Vulnerability Database IDs. |
Blogs | Blogging software used by the asset. |
Wordpress Core Version | WordPress Core version. |
WordPress Scanned Plugins | The WordPress scanned plugins that run on the asset. |
Editors | Editor software used by the asset. |
Search Engines | Search engines used by the asset. |
Web Mail | Web mail used by the asset. |
Cryptominer | Cryptomining software used by the asset. |
Static Site Generator | Static site generators used by the asset. |
User Onboarding | User onboarding software used by the asset. |
Document Management Systems | Document management systems used by the asset. |
Control Systems | Control systems used by the asset. |
Issue Trackers | Control systems used by the asset. |
Accessibility | Accessibility libraries used by the asset. |
Appointment scheduling | Appointment scheduling libraries used by the asset. |
LMS | Learning management systems used by the asset. |
Tag Managers | Tag managers used by the asset. |
Data | |
Analytics | Analytics software used by the asset. |
Databases | Databases used by the asset. |
Social | |
Social Profiles | Social profiles used by the asset. |
Live Chat | Live chat software used by the asset. |
Comment Systems | Comment systems used by the asset. |
Social logins | Social logins used by the asset. |
Media | |
Photo Galleries | Photo galleries used by the asset. |
Media Servers | Media servers used by the asset. |
Webcams | Webcam software used by the asset. |
Printers | Printer libraries used by the asset. |
Font Scripts | Font scripts used by the Asset. |
Video Players | Video players used by the asset. |
Rich Text Editors | Rich text editors used by the asset. |
JavaScript Graphics | JavaScript graphics used by the asset. |
Finance | |
Shopify apps | Shopify app tools. |
Ecommerce | Cross-border ecommerce tools. |
Payment Processors | Payment processors used by the asset. |
Paywalls | Paywalls used by the asset. |
Accounting | Accounting systems used by the asset. |
Affiliate programs | Affiliate programs used by the asset. |
Marketing | |
Google Analytics Keys | Referral marketing tools. |
Google Adsense Keys | Google AdSense keys used by the asset. |
Advertising Networks | Advertising networks used by the asset. |
Marketing Automation | Referral marketing tools. |
CRM | Customer relationship management systems used by the asset. |
SEO | Search engine optimization software used by the asset. |
General | |
Widgets | Javascript widgets used by the asset. |
Cache Tools | Cache tools used by the asset. |
Operating Systems | Operating systems used by the asset. |
Web Server Extensions | Web server extensions used by the asset. |
Feed Readers | Feed readers used by the asset. |
Build CI Systems | Build Continuous Integration systems used by the asset. |
Miscellaneous | Miscellaneous software used by the asset. |
Tenable.asm | |
Asset ID | The unique id of the asset. |
Severity | The severity ranking of the asset based on its security risk. |
Added to Inventory | Timestamp of date when the asset was added to the current inventory. |
Tag | IDs of simple Tags associated with the asset. Corresponds with the Tag column on the user interface. |
WHOIS | |
Administrative contact email | Administrative contact email of the asset. |
Administrative contact name | Administrative contact name of the asset. |
Administrative contact organization | Administrative contact organization of the asset. |
Billing contact email | Billing contact email of the asset. |
Contact email | Contact email of the asset. |
Domain name expiration | Age out date of the asset. |
Registrant city | Registrant city of the asset. |
Registrant country | Registrant country of the asset. |
Registrant email | Registrant email of the asset. |
Registrant fax | Registrant fax of the asset. |
Registrant name | Registrant name of the asset. |
Registrant postal code | Registrant postal code of the asset. |
Registrant state | Registrant state of the asset. |
Registrant street | Registrant street of the asset. |