Skip to main content

Exit IP nodes

EASM identifies the public IPv4 and IPv6 addresses that server type endpoints managed by Bitdefender Endpoint Security Tools (BEST) use to communicate with the internet. These addresses are called Exit IP nodes.

Use Exit IP nodes to:

  • Find public IP addresses used by your organization that are not yet included in the EASM scan list.

  • See which managed server type endpoints use each public IP address.

  • Provide Attack path with the external context it needs to show how attackers could enter your network.

Note

Exit IP nodes are available only in GravityZone Cloud.

Identify public IP addresses used by BEST-managed endpoints

You can identify Exit IP nodes in the following places:

  • EASM Dashboard. The Assets widget displays Exit IP nodes as a separate count from the regular IP address count. Click the value to open the Exit IP nodes view of the EASM Assets page.

  • EASM Assets > Exit IP nodes view. This default view lists the IPv4 and IPv6 assets used by BEST-managed endpoints. It includes the IPs used by BEST column and filter.

  • EASM Assets grid. In any view, add the optional IPs used by BEST column, which displays Yes or No for public IP assets. Use the IPs used by BEST filter to show only assets with the value Yes or No. You can combine this filter with other grid filters.

  • Scan completion notifications. When an EASM scan completes successfully, the console and email notifications include the number of Exit IP nodes identified. Click the value to open the filtered Exit IP nodes view.

View the endpoints that use a public IP address

  1. Go to Risk Management > EASM Assets.

  2. Select the Exit IP nodes view, or filter the grid by IPs used by BEST: Yes.

  3. Click an IPv4 or IPv6 asset to open the Asset details panel.

    The General section displays IPs used by BEST: Yes.

  4. Go to the Endpoints section to see the BEST-managed endpoints that use this IP address.

    The list includes only endpoints that still exist in GravityZone and belong to the same company as the EASM asset.

Add Exit IP nodes to the scan list

Attack path uses EASM scan results to show how attackers can reach your network from the internet. For Attack path to display this context, the public IP addresses used by your BEST-managed server type endpoints must be included in the EASM scan list.

When an Exit IP node is not in the scan list, the EASM Assets grid displays a warning icon next to the asset status. Hover over the icon to see the recommendation to add the IP address to the scan list.

To add Exit IP nodes to the scan list:

  1. Go to Risk Management > EASM Assets and select the Exit IP nodes view.

  2. Select the checkboxes of the IP addresses that display the warning icon.

  3. Click Scan action and select Include in scan.

You can also add the IP addresses manually, as IPv4 or IPv6 targets, in the Scan list tab of the scan configuration. For details, refer to Configure, run, or schedule scans.

After the IP address is added to the scan list, the warning icon is no longer displayed. The IP address is included in the next scheduled or manual scan.