Content Modules

Content Modules deliver data that is used by other Modules for classification, inspection, and control. For example, the Windows Applications Module delivers host properties and actions used by the HPS Inspection Engine to support in-depth discovery and management of software and applications on Windows endpoints.

Module Name Details
Deep Packet Inspection Plugin Uses deep packet inspection techniques to passively audit the network traffic to support endpoint classification and compliance assessment on the eyeSight.

Device Profile Library

A library of pre-defined device classification profiles, each composed of properties and corresponding values that match a specific device type. Each profile maps to a combination of values for function, operating system, and/or vendor and model. The Device Classification Engine uses this information to provide the best possible classification for the device.

Visibility Content

Provides updated protocols, fingerprints, and device profiles used by the Active Probing Plugin and the Deep Packet Inspection Plugin. These updates enhance device visibility and classification capabilities.

Windows Vulnerability DB

Makes vulnerability updates available to the eyeSight soon after they are released from Microsoft. These updates are used when working with vulnerability policies.

IoT Posture Assessment Library

Delivers a library of pre-defined login credentials that are used by the IoT Posture Assessment Engine to aid in determining the security risk of devices.

NIC Vendor DB

Works with the HPS Inspection Engine to map Network Interface Controllers to their vendors based on their MAC address.

Delivers host properties that let you detect and manage endpoints based on this information.

Switch Content

Supplies product definitions about vendor network devices (L2/L3 Switches, Layer 3 Devices) to the Switch Plugin. Each product definition enables Switch Plugin integration with a vendor's network device(s) to both manage these devices and apply actions on connected, targeted endpoints.

Windows Applications

Delivers host properties and actions used by the HPS Inspection Engine to support in-depth discovery and management of software and applications on Windows endpoints.

Security Policy Templates

Security policy templates use existing eyeSight functionality to detect, evaluate, and respond to vulnerabilities and threats - speeding and simplifying your network response. When you install this plugin, templates are available in the Policy view of the Console.

eyeSight eyeSegment module

eyeSight eyeSegment allows you to analyze your physical network traffic from a dynamic zone perspective. This helps you decouple the static constraints of a physical network from the dynamic business logic that modern segmentation policies require.

The eyeSight eyeSegment product provides:

  • Segmentation intelligence driven by the fusion of dynamic zone context and dynamic flow context
  • A network traffic baseline using traffic data accumulated over time
  • A consolidated visibility pane for mapping and analyzing traffic to and from various sources in and out of the network, and for identifying simulated traffic rule violations and conflicts
  • A policy management pane for creating an eyeSegment policy using rules that simulate allowing or denying specific traffic

Use the eyeSight eyeSegment product to:

  • Monitor traffic to understand device dependencies, then map, plan, and deploy network segments.
  • Assess devices on the fly to automate segmentation assignment.
  • Monitor the network for anomalous communication.
  • Focus on a matrix row, column, or cell to view a matrix of all the sub-zones of the selected Source or Destination parent zone. This 'focus' feature allows you to see multiple types and levels of information for hierarchical structures.
  • Use dynamic Source and Destination zones to easily create and visualize an eyeSegment policy that simulates denying traffic for a specific segment and filter, and enable notification or other actions when a simulated traffic violation is detected.
  • Identify simulated traffic violations to improve your enforcement and eyeSight eyeSegment policy rules.
  • Visualize the policy rules as a layer in the matrix, and ensure that devices are not managed by conflicting rules.
  • Export details about selected traffic for further study.

You can define and manage a single matrix that shows traffic for the eyeSighteyeSegment zones you select.

The eyeSight eyeSegment Module requires a valid eyeSegment license. See License Management for the relevant licensing requirements and to learn more about licensing modes.

eyeSight (Undefined variable: product-names.eyeExtend) modules

Note: In Per-Appliance Licensing mode, eyeSight (Undefined variable: product-names.eyeExtend) modules are referred to as Extended Modules in the user interface.

eyeSight (Undefined variable: product-names.eyeExtend) modules expand capabilities by sharing contextual device data with third-party systems and by automating policy enforcement across those disparate systems. Organizations can bridge previously siloed security solutions to accelerate system-wide response and more rapidly mitigate risks.

eyeSight (Undefined variable: product-names.eyeExtend) modules require valid licenses. License requirements for (Undefined variable: product-names.eyeExtend) modules differ depending on the licensing mode your Forescout deployment is using. See License Management for the relevant licensing requirements and to learn more about licensing modes.

Access eyeSight (Undefined variable: product-names.eyeExtend) module software downloads and related documentation from the Customer Support Portal, Downloads Page.

Advanced Threat Detection (ATD)

ATD eyeSight (Undefined variable: product-names.eyeExtend) modules provide security orchestration between the eyeSight and your ATD system. The combined solution lets you automatically detect indicators of compromise (IOCs) on your network and quarantine infected devices, thereby limiting malware propagation and breaking the cyber kill chain. (Undefined variable: product-names.eyeExtend) modules in this category include Check Point Threat Prevention, FireEye NX, and Palo Alto Networks WildFire.

Advanced Threat Detection (ATD)

ATD eyeSight (Undefined variable: product-names.eyeExtend) modules provide security orchestration between the eyeSight and your ATD system. The combined solution lets you automatically detect indicators of compromise (IOCs) on your network and quarantine infected devices, thereby limiting malware propagation and breaking the cyber kill chain. (Undefined variable: product-names.eyeExtend) modules in this category include Check Point Threat Prevention, FireEye NX, and Palo Alto Networks WildFire.

Advanced Threat Detection (ATD)

ATD eyeSight (Undefined variable: product-names.eyeExtend) modules provide security orchestration between the eyeSight and your ATD system. The combined solution lets you automatically detect indicators of compromise (IOCs) on your network and quarantine infected devices, thereby limiting malware propagation and breaking the cyber kill chain. (Undefined variable: product-names.eyeExtend) modules in this category include Check Point Threat Prevention, FireEye NX, and Palo Alto Networks WildFire.

Advanced Threat Detection (ATD)

ATD eyeSight (Undefined variable: product-names.eyeExtend) modules provide security orchestration between the eyeSight and your ATD system. The combined solution lets you automatically detect indicators of compromise (IOCs) on your network and quarantine infected devices, thereby limiting malware propagation and breaking the cyber kill chain. (Undefined variable: product-names.eyeExtend) modules in this category include Check Point Threat Prevention, FireEye NX, and Palo Alto Networks WildFire.

Advanced Threat Detection (ATD)

ATD eyeSight (Undefined variable: product-names.eyeExtend) modules provide security orchestration between the eyeSight and your ATD system. The combined solution lets you automatically detect indicators of compromise (IOCs) on your network and quarantine infected devices, thereby limiting malware propagation and breaking the cyber kill chain. (Undefined variable: product-names.eyeExtend) modules in this category include Check Point Threat Prevention, FireEye NX, and Palo Alto Networks WildFire.

Advanced Threat Detection (ATD)

ATD eyeSight (Undefined variable: product-names.eyeExtend) modules provide security orchestration between the eyeSight and your ATD system. The combined solution lets you automatically detect indicators of compromise (IOCs) on your network and quarantine infected devices, thereby limiting malware propagation and breaking the cyber kill chain. (Undefined variable: product-names.eyeExtend) modules in this category include Check Point Threat Prevention, FireEye NX, and Palo Alto Networks WildFire.

Advanced Threat Detection (ATD)

ATD eyeSight (Undefined variable: product-names.eyeExtend) modules provide security orchestration between the eyeSight and your ATD system. The combined solution lets you automatically detect indicators of compromise (IOCs) on your network and quarantine infected devices, thereby limiting malware propagation and breaking the cyber kill chain. (Undefined variable: product-names.eyeExtend) modules in this category include Check Point Threat Prevention, FireEye NX, and Palo Alto Networks WildFire.

Advanced Threat Detection (ATD)

ATD eyeSight (Undefined variable: product-names.eyeExtend) modules provide security orchestration between the eyeSight and your ATD system. The combined solution lets you automatically detect indicators of compromise (IOCs) on your network and quarantine infected devices, thereby limiting malware propagation and breaking the cyber kill chain. (Undefined variable: product-names.eyeExtend) modules in this category include Check Point Threat Prevention, FireEye NX, and Palo Alto Networks WildFire.

Advanced Threat Detection (ATD)

ATD eyeSight (Undefined variable: product-names.eyeExtend) modules provide security orchestration between the eyeSight and your ATD system. The combined solution lets you automatically detect indicators of compromise (IOCs) on your network and quarantine infected devices, thereby limiting malware propagation and breaking the cyber kill chain. (Undefined variable: product-names.eyeExtend) modules in this category include Check Point Threat Prevention, FireEye NX, and Palo Alto Networks WildFire.

Advanced Threat Detection (ATD)

ATD eyeSight (Undefined variable: product-names.eyeExtend) modules provide security orchestration between the eyeSight and your ATD system. The combined solution lets you automatically detect indicators of compromise (IOCs) on your network and quarantine infected devices, thereby limiting malware propagation and breaking the cyber kill chain. (Undefined variable: product-names.eyeExtend) modules in this category include Check Point Threat Prevention, FireEye NX, and Palo Alto Networks WildFire.