List of properties by category

This topic describes properties that are available by default in a typical eyeSight deployment. Some properties may not be available depending on the details of your Forescout configuration. Some properties may not be available, or remain unpopulated with data if certain device types are not present in your network.

Authentication properties

 

Authenticated by Certificate
Indicates whether a certificate-based authentication process for the endpoint was successful. If a certificate for this feature is not found on the endpoint, this property returns the value No.
Authentication Certificate Expiration
Indicates the value of the Valid To field of the certificate installed on the endpoint for certificate-based authentication.
Authentication Certificate Issuer
Indicates the value of the Issuer field of the certificate installed on the endpoint for certificate-based authentication.
Authentication Certificate Root CA Subject
Indicates the value of the Subject field of the certificate installed on the endpoint for certificate-based authentication.
Authentication Certificate Serial Number
Indicates the value of the Serial Number field of the certificate installed on the endpoint for certificate-based authentication.
Authentication Certificate Status
Indicates the state of the certificate installed on the endpoint for certificate-based authentication, and any verification errors for the certificate. For example, you can use this property to identify endpoints with revoked certificates. If a certificate for this feature is not found on the endpoint, this property returns the value No certificate.
Authentication Certificate Subject
Indicates the value of the Subject field of the certificate installed on the endpoint for certificate-based authentication.
Authentication Certificate Subject Alternate Name
Indicates the value of the Subject Alternate Name field of the certificate installed on the endpoint for certificate-based authentication.
Authentication Login
Indicates whether the endpoint performed any of the following:
A successful login to an authentication server. To use this feature you must configure your authentication servers. The following authentication services are supported:
HTTP (80/TCP)
Telnet (23/TCP)
NetBIOS-SSN (139/TCP)
Microsoft-DS (445/TCP)
Microsoft-MAPI (135/TCP)
FTP (21/TCP)
IMAP(143/TCP)
POP3(110/TCP)
rlogin (513/TCP)
The user authenticated via the User Directory server as a result of a HTTP Login action.
The user authenticated as a guest as a result of a HTTP Login action.
Authentication Login (Advanced)
Indicates endpoints that logged in to the network using a specific protocol or against a specific server. Enter the protocol name or the server IP address.
Servers referenced here must be defined in the Authentication pane. See Defining Authentication Servers for details.
HTTP Confirmation Events
Indicates whether the end user confirmed an HTTP notification message generated by Forescout eyeControl. Confirmation is discovered via the Confirmation Identifier name, defined in the HTTP Notification action.
Enter the name of the identifier. If discovered, the user confirmed the message.
HTTP Login Failure
Indicates whether the endpoint exceeded the HTTP login failure threshold defined in Options > NAC > HTTP Login Attempts. The User Directory Plugin must be installed to work with this property.
HTTP Login User
Indicates the name of the last user that performed successful HTTP Login authentication.
Signed In Status
Indicates endpoints that are:
Signed-in to the network using a valid domain name. See HTTP Login action for details.
Signed-in as guests.
Signed-out or never signed in.

Classification properties

 

Function
Indicates the most specific function in the Device Profile Library that matches the endpoint. For example, Information Technology > Accessory > VoIP > IP Phone.
If multiple functions match the endpoint, the property is resolved as the most specific value in the Device Profile Library that is common to all the matching functions. For example, if Gaming Console and SmartTV profiles both match the endpoint, the property is resolved as Multimedia & Entertainment.
If there is no common value among all the matching functions, the property is resolved as Multiple Suggestions.
If no function profiles in the Device Profile Library match the endpoint, the property is resolved as Unknown.
Select one or more endpoint functions. To detect all sub-classifications of the selected functions, select the Include sub-classifications checkbox.
Network Function
Indicates the type and function of an endpoint, as determined by various passive and active means, including Nmap. Due to the activation of Nmap, this information may take longer to resolve.
Use of this property requires that you configure the HPS Inspection Engine.
Refer to the Network Function Property Algorithm Technical Note.for details for details.
Operating System
Indicates the most specific operating system in the Device Profile Library that matches the endpoint. For example, Macintosh > OS X 10.11 - El Capitan.
If multiple operating systems match the endpoint, the property is resolved as the most specific value in the Device Profile Library that is common to all the matching operating systems. For example, if Windows Server 2008 Enterprise RTM and Windows Server 2008 Enterprise SP2 profiles both match the endpoint, the property is resolved as Windows Server 2008 Enterprise.
If there is no common value among all the matching operating systems, the property is resolved as Multiple Suggestions.
If no operating system profiles in the Device Profile Library match the endpoint, the property is resolved as Unknown.
Select one or more operating systems. To detect all sub-classifications of the selected operating systems, select the Include sub-classifications check box.
Vendor and Model
Indicates the most specific vendor and model in the Device Profile Library that matches the endpoint. For example, Samsung > Samsung Galaxy Tablet > Samsung Galaxy Tablet 10.
Select one or more vendors or models. To detect all sub-classifications of the selected vendors and models, select the Include sub-classifications check box.

Advanced classification properties

 

Service Banner
Indicates the service and version information, as determined by Nmap. Due to the activation of Nmap, this information may take longer to retrieve.
Use of this property requires that you configure the HPS Inspection Engine.
Network Function Resolution Method
Indicates the method used to classify the device's Network Function property. The following options are available:
Active Banner
Active Fingerprint
Managed (Network Device or Endpoint)
Manual Classification
Passive Banner
Passive Fingerprint
HTTP User Agent
Indicates Learned HTTP User Agent Banner (from portal and Packet Engine).
Function Classified By
Indicates whether the Function classification property was determined by the Device Classification Engine, or was set by an action.
Operating System Classified By
Indicates whether the Operating System classification property was determined by the Device Classification Engine, or was set by an action.
Function Classification Update
Indicates whether a Function classification change is pending for this device due to a Device Profile Library upgrade. You can apply all pending classification changes in the Tools > Options > Device Profile Library window.
Operating System Classification Update
Indicates whether an Operating System classification change is pending for this device due to a Device Profile Library upgrade. You can apply all pending classification changes in the Tools > Options > Device Profile Library window.
Vendor and Model Classification Update
Indicates whether a Vendor and Model classification change is pending for this device due to a Device Profile Library upgrade. You can apply all pending classification changes in the Tools > Options > Device Profile Library window.
Suggested Function
If there are multiple candidates for the endpoint's Function classification, this property indicates all the profiles in the Device Profile Library that match this endpoint. These values are considered less accurate than the resolved Function property value, possibly due to conflicting choices. If the Function property has been changed by a policy or manual action, this property indicates the endpoint's Function classification set by the Device Classification Engine.
Suggested Operating System
If there are multiple candidates for the endpoint's Operating System classification, this property indicates all the profiles in the Device Profile Library that match this endpoint. These values are considered less accurate than the resolved Operating System property value, possibly due to conflicting choices. If the Operating System property has been changed by a policy or manual action, this property indicates the endpoint's Operating System classification set by the Device Classification Engine.
OS Fingerprint
Indicates the type of the operating system running on the endpoint, as determined by Nmap. Use this property instead of OS Class for classification of unlisted and unknown OS names. Due to the activation of Nmap, this information may take longer to retrieve.
Use of this property requires that you configure the HPS Inspection Engine.
Compare OS Fingerprint to (Classification Version 2)
Indicates the difference between current OS Fingerprint and OS Fingerprint Classification Version 2. The following options are available:
Both failed
OS Fingerprint resolution failure
OS Fingerprint (Classification Version 2) resolution failure
Values are identical
Values differ
Compare OS Fingerprint to (Classification Version 3)
Indicates the difference between current OS Fingerprint and OS Fingerprint Classification Version 3. The following options are available:
Both failed
OS Fingerprint resolution failure
OS Fingerprint (Classification Version 3) resolution failure
Values are identical
Values differ
Compare Network Function To (Classification Version 2)
Indicates the difference between current Network Function and Network Classification Version 2. The following options are available:
Both failed
Network Function resolution failure
Network Function (Classification Version 2) resolution failure
Values are identical
Values differ
Compare Network Function To (Classification Version 3)
Indicates the difference between current Network Function and Network Classification Version 3. The following options are available:
Both failed
Network Function resolution failure
Network Function (Classification Version 3) resolution failure
Values are identical
Values differ

Device information properties

 

Access IP
Indicates the endpoint IP address that Forescout eyeSight used the last time it connected successfully to the endpoint.
Assigned Label
Labels mark and group endpoints based on properties or other evaluated values. Policies can apply further management logic based on labels assigned by a previous policy. This lets you construct complex policy behaviors that track endpoint history.
This condition compares a text string to the labels assigned to the endpoint. The text string you specify is compared to each of the labels assigned to the endpoint.
You can specify various matching logic options, such as partial string matching.
You can apply time constraints to the condition. Forescout eyeSight matches only endpoints that satisfy the matching condition during the specified time period.
Comment
Indicates devices that contain device Comment text defined by the Forescout user. (Right-click an endpoint in the Detections pane to add a comment. The comment is retained for the life of the endpoint in the Console.)
Special characters such as `~!@#$%^&=*()+[]\;'/{}|:"? are not allowed in the comment field and are removed if entered.
Compliance Status
Indicates the endpoint status based on policies categorized as Compliance policies.
Corporate / Guest Status
Indicates the endpoint status based on policies categorized as Corporate/Guest Control policies.
Counter
Compares the value of a counter to a numerical value.
Name: The name of an existing counter.
Counter: Value(s) that the condition compares to the current value of the counter. You can specify a single value, a list of values, or a range of values.
Note: Enable the Evaluate irresolvable criteria as True option when the Counter property is used to verify the presence of a newly created counter.
Forescout Script Result
Runs a script or command on the Appliance, and examines the result.
Forescout eyeSight evaluates the script or command for each endpoint that matches previous conditions of the policy. This result is compared to the specified values and matching logic of the condition.
Ignore Failed Script Result - Enter true to ignore any partial output received by eyeSight before the session failed. The property is evaluated as Irresolvable.
Enter false to preserve output from the failed session in the property, and use that output to evaluate the condition.
Note: If you are running a script to retrieve a value that includes the endpoint's IP address, the script should not include the {IP} tag, as Forescout eyeSight automatically appends the IP address to the list of arguments passed to the script.
Device Interfaces
Detects endpoints with specific device interface information. This information may be part of the interface name, vendor and MAC address. Use of this property requires the proper configuration and activation of the HPS Inspection Engine.
Device is DHCP Relay
Indicates whether endpoints are running DHCP Relay services. Use of this property requires the proper configuration and activation of the HPS Inspection Engine.
Device is DHCP Server
Indicates whether endpoints are DHCP servers. Use of this property requires the proper configuration and activation of the HPS Inspection Engine.
Device is NAT
Indicates whether the endpoint performs a Network Address Translation, potentially hiding other devices behind it.
If you have enabled Partial Enforcement mode, this condition will not work. See Set the Enforcement Mode for details.
DHCP Server Address
Indicates whether the device IP address was received from a DHCP server. If so the value of the property is the IP address of the DHCP server.
In addition to DHCP server properties, such as this one, which are discovered by Forescout eyeSight, additional DHCP host properties are discovered by the DHCP Classifier Plugin. This plugin extracts host information from DHCP messages and uses DHCP fingerprinting to determine the operating system and other host configuration information. For more information, refer to the DHCP External Classifier Plugin Configuration Guide. Select Tools > Options > Modules, select the plugin, and then select Help.
DNS Name
Indicates the endpoint's DNS name.
Host is online
Indicates whether the endpoint is connected to the network.
IPv4 Address
IPv6 Address
Indicates one or more IP addresses of an endpoint. Matching criteria include:
Any IP address
Addresses in a named Forescout Internal Network segment
Addresses in a specific IP range or subnet
IP addresses that start with, end or match a certain numerical expression
Endpoints without a known IPv4 address (endpoints will be detected when Forescout eyeSight discovers their MAC address).
For details about working with IPv6 addresses, refer to the Work with IPV6 Addressable Endpoints How-to Guide.
Last Known IPv4 Address
Indicates an IPv4 Address that once referred to this endpoint, but was assigned to another endpoint. See Work with Hosts Whose IPv4 Address Is Used by Another Host.
MAC Address
Indicates the MAC address of the endpoint.
Member of Group
Lets you investigate endpoints that are part of a group.
Nested Device ID
The detected ID of a sub-module or controller within an endpoint.
Nested Device Parent IP
The IP address of an endpoint that contains sub-modules or controllers.
NetBIOS Domain
Indicates the NetBIOS Domain to which the endpoint is logged on.
NetBIOS Hostname
Indicates the NetBIOS host name of the endpoint.
Network Adapters
Indicates specific types of network adapters, for example, adapters having a specific device name, MAC address or connection status. Endpoints must be managed by SecureConnector to resolve this property.
NIC Vendor
Indicates the vendor of the NIC, as detected by Forescout eyeSight based on the MAC prefix.
The HPS NIC Vendor DB updates vendor information used to resolve this property. eyeSight can automatically add newly supported vendors to a policy condition that you create with this property. For more information about this plugin, select ToolsOptions > Modules, select the plugin, and then select Help.
NIC Vendor Value
Indicates a string value associated with the NIC Vendor. You can create conditions that match several variants of a vendor name, or look for a specific substring in a name.
The HPS NIC Vendor DB updates vendor information used to resolve this property. Forescout eyeSight can automatically add newly supported vendors to a policy condition that you create with this property. For more information about this plugin, select Tools > Options > Modules, select the plugin, and then select Help.
Number of IPv4 Addresses
Number of IPv6 Addresses
Indicates the number of IP addresses of each type that Forescout eyeSight detected for an endpoint.
You can specify IPv4 addresses to ignore when calculating the Number of IPv4 Addresses property. For details refer to Configure Tuning in the HPS Inspection Engine Configuration Guide.
The count of IPv6 addresses depends on the Purge IPv6 Timeout defined for inactive IPv6 addresses.
There are parallel Track Changes properties.
Open Ports
Indicates the availability of open ports on the endpoint. This is determined by inspecting real-time traffic as well as using Nmap.
The condition is considered "true" if any of the listed ports are detected.
OS CPE Format
Indicates the operating system running on the endpoint, in Common Platform Enumeration format. This property is reported by the Windows Applications, Linux, OS X and ARF Reports Plugins. The property contains the CPE 2.3 representation of the operating system bound to a formatted string.
You can use Forescout property expression types (For example, Contains, In List, or Matches) to create policy conditions that identify logical parts or substrings of the CPE name string.
Segment Name
Retrieves the leaf node name of the network segment on which the endpoint resides. Condition options let you apply string matching criteria to this value.
Segment Path
Retrieves the full pathname of the network segment on which the endpoint resides. Condition options let you apply various string matching criteria to this value.
SMB Relay
Indicates the endpoint may be spoofing session-layer SMB authentication. Forescout eyeSight compares the IP address of the SMB session used by the endpoint to the IP addresses it discovers on the endpoint. If the IP address of the SMB session is not included in the addresses discovered on the endpoint, eyeSight assigns this property the value True and reports a NAT detection event using the Device Is NAT host property. Use this property to improve detection of man-in-the-middle attacks.
There is a parallel Track Changes property.
snmpwalk Command Output
OID: Enter the ID.
SNMP version: Enter the SNMP version.
Community: Enter the community for versions 1/2c.
User (V3): Enter the user and password (version 3).
Password (V3): Enter the user and password (version 3).
Extra snmpwalk options: Include additional snmpwalk options. If you include -x for SNMPv3 privacy, the same password used for authentication is used for privacy.
Filter: Include only specific information in the output by piping into a Linux command.
Ignore Failed Script Result: Enter true to ignore any partial output received by Forescout eyeSight before the session failed. The property is evaluated as Irresolvable. Enter false to preserve output from the failed session in the property, and use that output to evaluate the condition.
Note: Enter *UNUSED* in a field if you want Forescout eyeSight to ignore the parameter.
SSH Command Output
SSH Username/SSH Password: Specify credentials used to log in and establish an SSH session on the endpoint. These credentials are not encrypted.
SSH Connection Flags (optional): (Optional) Specify additional Open SSH option flags that are applied when the SSH session is established.
Command: Enter the command submitted on the endpoint.
Pipe session through AWK filter (optional): (Optional) Specify a Linux filter command to filter output before evaluating the condition.
When command/session fails, evaluate condition: Select as Irresolvable to ignore any partial output when the session fails. The property is evaluated as Irresolvable. Select Based on data received to preserve output from the failed session in the property, and use that output to evaluate the condition.
Note: Enter *UNUSED* in a field if you want Forescout eyeSight to ignore the parameter.
SSH Command Output (interactive)
SSH Username/SSH Password: Specify credentials used to log in and establish an SSH session on the endpoint. These credentials are not encrypted.
SSH Connection Flags (optional): (Optional) Specify additional Open SSH option flags that are applied when the SSH session is established.
Interactive Session Script: Enter an alternating series of commands and expected responses, beginning with a command. Each command is on an odd numbered line, each expected response is on an even line. Expected response lines contain regular expressions used to match actual output.
Response timeout: The maximum interval, in seconds, that Forescout eyeSight waits after submission of each command for an output response.
Login timeout: The maximum interval, in seconds, that Forescout eyeSight waits when it logs in to establish the SSH session.
Pipe session through AWK filter (optional): (Optional) Specify a Linux filter command to filter output before evaluating the condition.
When command/session fails, evaluate condition -
Select as Irresolvable to ignore any partial output when the session fails. The property is evaluated as Irresolvable.
Select based on data received to preserve output from the failed session in the property, and use that output to evaluate the condition.
After eyeSight establishes an SSH session on the endpoint, it submits the first command listed in the Interactive Session Script field. eyeSight waits for a response, and tests the response output against the expected response in the next line of the script.
If the actual response output does not match the expected response, or if the session times out without a response, eyeSight ends the interactive session.
If the output matches the expected response, eyeSight submits the next command in the session script.
eyeSight ends the session after a response is received for the last command, or after the session times out.
The property contains a log of all submitted commands and complete actual responses.
Note: Enter *UNUSED* in a field if you want Forescout eyeSight to ignore the parameter
Traffic seen
Indicates when network traffic was last seen.
URL Content
URL: Enter the path of the URL from which you want to retrieve information. You can use the {ip} tag to specify the endpoint IP address, for example, http://{ip}/info.html
User/Password: Enter user credentials if access to the pane requires authentication.
Kerberos Domain: Specify a Kerberos (Active Directory) domain if the user is part of a domain.
Extra curl options. Set additional curl options (check out 'man curl' on Linux)
Filter: Include only specific information in the output by piping into a Linux command. For example, to exclude the text XYZ use " grep -v "XYZ""
Ignore Failed Script Result: Enter true to ignore any partial output received by Forescout eyeSight before the session failed. The property is evaluated as Irresolvable. Enter false to preserve output from the failed session in the property, and use that output to evaluate the condition.
Note: Enter *UNUSED* in a field if you want Forescout eyeSight to ignore the parameter.
User
Indicates the domain user name currently logged on to the endpoint. This property is reported by the HPS Inspection Engine and OS X Plugins.

Event properties

 

ARP Spoofing
Indicates whether the number of different MAC address reported for an IP address exceeds the number specified here. This lets you keep track of the different MAC addresses used by an IP address as advertised by ARP responses. Normally, there should be only one MAC address per IP address.
This property lets you detect attempts to maliciously direct network traffic.
To work with this condition, the Appliance must monitor ARP traffic, i.e., the broadcast domain where ARP requests are transmitted. Refer to the Port Mirroring Technical Note for more information about configuring your environment for detecting ARP spoofing.
Admission
Indicates whether one or more admission events were detected. Admission event types include:
New IP: By default, endpoints are considered new if they were not detected at your network within a 30-day period. For example, if an IP was detected on the first of the month, and then detected again 31 days later, the detection initiates the activation. The default time period can be changed. See Policy Preferences for details.
IP Address Change
Switch Port Change
DHCP Request
Authentication via the HTTP Login action
Log in to an authentication server
SecureConnector connection
If you have installed plugins/modules, additional admission events types may be available. For example, the New Wireless Host Connected Events option is available if you installed the Wireless Plugin.
Malicious Event
Indicates the type of threat protection event to respond to. Parameters selected here are applied in addition to parameters defined in the Threat Protection Policy. See Threat Protection for details.
Miscellaneous Events
Indicates endpoints whose IP address was used by a newly connecting endpoint. This may happen, for example, if the original endpoint was offline for a certain period and the newly connecting endpoint received its IP.
When this happens, the original endpoint is displayed in the Console without an IP address until it reconnects.
NetFlow Sessions as Client / NetFlow Sessions as Server
Sessions let you run policies based on real-time identification of network traffic patterns between servers and clients, helping you pinpoint:
When sessions are initiated
Which protocols are used
For example, use this property to ensure compliance of data flow security for audit usage or to track down network users trying to access sensitive protected data, such as credit card information or financial accounts.
Indicates which endpoints generated sessions to specific servers using a defined protocol.
Sessions as Client: Indicates which endpoints generated sessions to specific servers using a defined protocol.
Sessions as Server: Indicates which servers received sessions from specified endpoints using a defined protocol.
Traps Received
Indicates that an SNMP trap was received on the port where the endpoint is connected.

External devices properties

 

External Devices
Refers to external devices connected to an endpoint by cross-referencing all the device attributes listed below. In order for an endpoint to match the defined condition, all attributes in this list must match.
Name: Detects endpoints connected to an external device with a specific device name.
ID: Detects endpoints connected to an external device with a specific device ID number.
Class: Detects endpoints that are connected to specific external device classes, including:
Wireless communication devices
Portable devices
Windows CE USB devices
Printers
PCMCIA and Flash memory devices
Other devices
Network adapters
Modems
Infrared devices
Imaging devices
Disk Drives
DVD/CD-ROM drives
Bluetooth Radios
Bus Type: Detects the bus on which the external device is connected.
Status: Detects the connection status.

Guest registration properties

 

Guest Account Approve Date
Indicates when the guest network access was approved.
Guest Approved By
For users allowed network access as guests via the HTTP Login action, this field indicates the email address of the sponsor who approved the network access.
Guest Registration Status
Indicates the status of a guest network access request.
Guest Tags
Indicates the value of the tags assigned by the sponsor to the guest.
See Managing Guest Tags for details.
Guest Registration Information
For users allowed network access as guests via the HTTP Login action, this field indicates the information that was provided when the guest self-registered or was registered by a sponsor or operator:
Guest Account Approve Date
Guest Comment
Guest Company
Guest Contact Person
Guest Contact Person Email
Guest Custom[1-5] form fields
Guest Email Address
Guest Full Name
Guest Location
Guest Phone Number
Guest Registration browser user agent
Guest Registration Date
Guest Title
User Name
You can use any of this information to enforce actions on guests.

Health monitoring properties

The following properties are used to help you monitor Appliance health. These properties are included in policies created by Health Monitoring Templates. Running these templates populates Health Monitoring Dashboard widgets.

Note: If you are running a script to retrieve a value that includes the endpoint's IP address, the script should not include the {IP} tag, as Forescout eyeSight automatically appends the IP address to the list of arguments passed to the script.

Linux properties

Linux Expected Script Result
Use this property to run a command or file that detects certain endpoint attributes, statuses or any other information defined in the script or command. Commands and file can also be used to carry out actions on endpoints.
Enter a command or browse to a file that you want to run. The commands and scripts that you create are automatically saved on all Appliances. All file extensions are supported and can be run.
A Run Script Action is also available.
Linux File Date
Indicates the last modification date and time of a defined file on an endpoint.
Linux File Exists
Indicates whether a specified file exists on an endpoint.
Linux File Size
Indicates the size (in bytes) of a specified file on an endpoint.
Linux Hostname
Indicates the Linux host name.
Linux Manageable (SSH Direct Access)
Indicates whether the endpoint is connected to eyeSight via SSH and is manageable via Remote Inspection.
Linux Manageable (SecureConnector)
Indicates whether the endpoint is connected to eyeSight via SecureConnector.
Linux Processes Running
Indicates the full pathnames of processes running on an endpoint.
Linux SecureConnector Version
Indicates the version of the SecureConnector package running on the endpoint.
Linux User
Indicates all the users logged in to the endpoint. The list of usernames is comma-separated.
Linux Version
Indicates the specific version of Linux running on the endpoint.
OS CPE Format
Indicates the operating system running on the endpoint, in Common Platform Enumeration format. The plugin resolves this general Forescout property for Linux endpoints.
User
This is a general Forescout property. For Linux endpoints, the plugin populates this property with the username of the user currently logged in to the endpoint console. You can query the User Directory based on this value.

Macintosh properties

 

The OS X Plugin supports the following properties for macOS endpoints.

Macintosh Expected Script Result
Runs a command or file that detects certain endpoint attributes, statuses or any other information defined in the script or command. Commands and file can also be used to carry out actions on endpoints.
Enter a command or browse to a file that you want to run. The commands and scripts that you create are automatically saved on all Appliances. All file extensions are supported and can be run.
A Run Script action is also available.
Macintosh Applications Installed
Indicates the applications present on an endpoint.
For endpoints running OS X 10.8, the Certificate field is not reported.
Macintosh File Date
Indicates the last modification date and time of a defined file on an endpoint.
Macintosh File Exists
Indicates the existence of a specified file on an endpoint.
Macintosh File Size
Indicates the size (in bytes) of a specified file on an endpoint.
Macintosh Hostname
Indicates the macOS host name.
Macintosh Manageable (SecureConnector)
OSX SecureConnector Connected/Disconnected
Indicates whether the endpoint is connected to eyeSight via SecureConnector.
OSX SecureConnector Connected/Disconnected is the related Track Changes property.
Macintosh Processes Running
Indicates the processes running on an endpoint.
Macintosh SecureConnector Version (OSX Plugin)
Indicates the version of the SecureConnector package running on the endpoint.
Macintosh Software Updates Missing
Indicates macOS security and other updates that are missing on the detected endpoint.
To resolve this property on endpoints running OS X 10.8, Forescout eyeSight must use an admin account to access the endpoint.
Macintosh User
Indicates all the users logged in to the endpoint. The list of usernames is comma-separated.
Macintosh Version
Indicates the version of macOS running on the endpoint.
OS CPE Format
Indicates the operating system running on the endpoint, in Common Platform Enumeration format. The plugin resolves this general Forescout property for macOS endpoints.
OSX SecureConnector Connected/Disconnected
OSX SecureConnector Connected/Disconnected is the related Track Changes property.
User
This is a general Forescout property. For macOS endpoints, the plugin populates this property with the username of the user currently logged in to the endpoint console. You can query the User Directory based on this value.

Remote inspection properties

The following properties indicate which management services are available on the endpoint that Forescout eyeSight can use to perform Remote Inspection.

MS-RRP Reachable
Indicates whether Forescout eyeSight can use the Remote Registry Protocol for Remote Inspection tasks on the endpoint.
MS-SMB Reachable
Indicates whether Forescout eyeSight can use the SAMBA protocol for Remote Inspection tasks on the endpoint.
MS-WMI Reachable
Indicates whether Forescout eyeSight can use the Windows Management Interface for Remote Inspection tasks on the endpoint. In previous releases, this property was named Windows Manageable Domain by WMI.

These properties do not have an Irresolvable state. When the plugin or module cannot establish connection with the service, the property value is False. Do not use the Evaluate Irresolvable Criteria as option with these properties.

The following corresponding Track Changes policies are listed under the Track Changes folder:

  • MS-RRP reachability changed
  • MS-SMB reachability changed
  • MS-WMI reachability changed

SNMP properties

Use of SNMP properties requires the proper configuration and activation of the HPS Inspection Engine. When entering the following values, use these guidelines:

  • For SNMP V1, use: -v 1 -c <community>
  • For SNMP V2, use: -v 2 -c <community>
  • For SNMP V3, use: -v 3 -u <user> -A <password>

    Use the SNMP Parameters field to enter optional SNMP connection parameters. The following parameters are supported:

    ParameterDescription

    -p <port>

    Specify the port used for SNMP messaging on the server.

    -r <retries>

    Specify the number of times to retry the request.

    -t <seconds>

    Specify the timeout period before retrying the request.

    -E <engine_ID>

    Specify the Context Engine ID for REQUEST messages (SNMP v3 only).

    -n <cont_name>

    Specify the Context Name (SNMP v3 only).

    SNMP-MIB-II ifNumber
    Indicates the number of network interfaces (regardless of their current state) present on this system. The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.
    In the SNMP-MIB-II ifNumber field, enter the number of interfaces to be detected on the SNMP agent.
    SNMP-MIB-II
    sysDescription
    Indicates a textual description of the entity. This value should include the full name and version identification of the system's hardware type, software operating-system, and networking software. It is mandatory that this only contain printable ASCII characters. The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.
    In the SNMP-MIB-II sysDescription field, enter the description that should match the SNMP agent system description. If you are not sure of the name, you can use the regular expression option, and enter wildcard text - for example, ci.* if you want to detect a Cisco switch.
    SNMP-MIB-II sysLocation
    Indicates the physical location of this node (for example, telephone closet, third floor). The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.
    In the SNMP-MIB-II sysLocation field, enter the location that should match the SNMP agent. If you are not sure of the name, you can use the regular expression option, and enter wildcard text (.*).
    SNMP-MIB-II sysName
    Indicates an administratively assigned name for this managed endpoint. By convention, this is the endpoint's fully qualified domain name. The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.
    In the SNMP-MIB-II sysName field, enter the requested system name to match.
    SNMP-MIB-II sysUpTime
    Indicates the time since the network management portion of the system was last re-initialized. The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.
    Use the Older than or Before options to create a condition based on the time the SNMP agent was last turned on.
    SNMP-OID
    Indicates an OID value, on the SNMP agent. The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.
    In the SNMP OID field, enter the requested OID value on the endpoint. If the OID query and the SNMP-OID Value match, then the condition is registered.

Switch properties

An extensive range of properties are resolved for Switches that are configured to work with Forescout eyeSight. The section provides an overview of the Switch properties.

Select Options from the Tools menu and then select Switch to configure the Switch Plugin. Select Help for information about configuration and for more information about working with switch properties.

Basic managed switch information

The following properties resolve basic information about a managed switch:

SGT
The Security Group Tag (SGT) assigned to an endpoint. An SGT is a number in the range of 1 - 65,535.
Endpoints with an assigned SGT are connected to a managed Cisco switch in a Cisco TrustSec domain.
When the property is currently included in existing policies and the advanced configuration flag assign_sgt is disabled, the property is marked as Obsolete in the relevant policies. For details about this flag, refer to the Forescout Switch Plugin Configuration Guide.
Switch Port Configurations
Note: For use with Cisco and Arista devices only.
The configuration detail of the switch interface to which an endpoint is connected.
For this property to be resolvable, the Switch Plugin must be configured to use CLI to learn the endpoints that are connected to the managed switch. For details, refer to the Forescout Switch Plugin Configuration Guide.
Number of Hosts on Port
The number of endpoints connected to a specific port. You can write a condition for this number to instruct the Switch Plugin to detect ports with more than one endpoint (MAC address) if, for example, a hub and a guest computer have been connected together with a company endpoint on a company switch port. Ports connecting between switches are excluded from this calculation.
Switch Hostname
The switch name as defined in the managed switch.
Switch IP/FQDN
Either the IP address or the fully qualified domain name of the switch.
Switch IP/FQDN and Port Name
Either the IP address or the fully qualified domain name of the switch and the port name (the physical Ethernet interface information of the port). The format is <IP address/FQDN>:<port>.
Switch Location
The switch location based on the switch MIB.
Switch OS
The operating system of the switch device to which the endpoint is connected.
Switch Port ACL
The name of the ACL applied to the switch port.
Switch Port Action
The action, either Assign to VLAN, Provision VLAN or Switch Block, that is assigned to the switch port.
Switch Port Alias
The description of the port as defined in the switch configuration and modified by the Switch Plugin.
Switch Port Connect
The physical connectivity between the endpoint and the switch port.
Switch Port PoE Connected Device
Note: For use with Arista, Brocade, Cisco, Huawei, and Tejas devices only.
Description of the PoE device that is connected to the PoE-enabled switch port, as provided by the managed switch. For example, Cisco IP Phone 6921.
For all other plugin-managed switches, this property displays the value N/A (not available).
Switch Port PoE Power Consumption
Note: For use with Arista, Brocade, Cisco, Huawei, and Tejas devices only.
Power consumption of the PoE device that is connected to the PoE-enabled switch port, as provided by the managed switch. The power consumption value provided is in milliwatts (mW). For example, 750.
When either a non-PoE device or no device is connected to the PoE-enabled switch port, the property value is zero (0).
For switch vendors that the plugin does not support switch port PoE, the Console displays the following information for this property: Vendor is currently not supported for this property.
Switch Port Name
The hard-coded port name.
Switch Port VLAN
The VLAN associated with the switch port.
Switch Port VLAN Name
The name of the VLAN associated with the switch port.
Switch Port Voice Device
Whether the endpoint connected to the switch port is a VoIP device.
Switch Port Voice VLAN
The switch port VLAN to which the VoIP endpoint is connected.
Switch Vendor
The switch vendor name.
Switch Virtual Interface
Identifies whether the switch interface is a Switch Virtual Interface or not. The property is supported for managed switches only.
Switch VoIP Port
Whether the switch port is a VoIP port.
System Description
Detects the system description information provided by the managed device. System description information is as specified by the network device SNMPv2-MIB property sysDescr (1.3.6.1.2.1.1.1).
Switch Device Vendor and Type
The vendor and the device type of a managed switch device. Examples: Cisco (switch) or Cisco_ASA (firewall).
Currently, this property is only available for use in/resolved by a policy that is created using a Vulnerability and Response (VR) policy template.

Network device compliance properties

For any Cisco network device managed by the Switch Plugin, use the following policy properties to create policies that determine network device compliance:

Running Config
Note: For use with Cisco devices only.
Detects running config information of switches managed by the Switch Plugin, as generated by the show running-config command.
The Switch Plugin resolves this property for information in the following instances: (a) After plugin start and initially detecting the switch and (b) Whenever running config information changes.
Before working with this property, several configuration tasks must be performed.
As the amount of information provided by the resolved Running Config property can be very extensive, you can filter this information.
Running Config Time
Note: For use with Cisco devices only.
Contains the timestamp, MM/DD/YY HH:MM:SS AM/PM, of the plugin's running config information query of the device.
Interface Table
Note: For use with Cisco devices only.
Detects the specific interface configuration provided in a device running config for the interface.
Per interface, the resolved property provides the following information:
Interface Name: The interface name and when available the interface location information.
Interface Configuration (raw): The specific, interface configuration, as provided in a device running config.

Track changes properties

Items in this category check whether a property value has changed, for example, if a user name changed. Detecting changes in endpoints is a powerful method of identifying possible attacks or noncompliance.

All these properties exist under other categories, but here these properties check whether the value has changed. For example, the Windows File Size property in the Windows folder detects the size of a file at a specific location. In the Track Changes folder, Forescout eyeSight detects if the file size at that location changed.

Some of the Track Changes properties require the proper configuration and activation of the HPS Inspection Engine.

User directory properties

The following user attributes indicate if the user's account in the User Directory is disabled or expired:

  • Account is Disabled
  • Account is Expired

The following user attributes may vary depending on the User Directory configuration:

  • Common Name, Employee Number, Password Last Set
  • Company, Initials, Phone
  • Department, Last Name, Street Address
  • Display Name, LDAP User Name, Title
  • Distinguished Name, Member Of, User Given Name
  • Email, Mobile Phone

Windows properties

NetBIOS Membership Type
Indicates whether the endpoint is a domain or workgroup member.
SMB Signing
Indicates support for SMB Signing on the Windows endpoint. Valid values are:
Required: the endpoint requires that all SMB communication is signed.
Enabled: the endpoint supports SMB signing but does not require it.
Disabled: the endpoint does not support SMB signing, even when it is requested by the communicating entity
Windows Active Users
Indicates the username/domain of one or more users currently logged in to a Windows endpoint
Windows Domain Member
Indicates whether the endpoint is a member of any of the domains defined in the HPS Inspection Engine.
Windows Expected Script Result
For use on managed Windows machines only.
Use this property to run a command or file to detect certain endpoint attributes, statuses, or any other information defined in the script or command. Commands and file can also be used to carry out actions on endpoints.
(If you use a file that exists on the endpoint, enter its absolute path).
You can also enter output text that should be matched on the endpoint against the output of the script.
Use this property, for example, to find users sharing the My Music folder.
A script is run by starting a service called fsprocsvc. The service does not open any new network connection or generate traffic. Communication is carried out over Microsoft's SMB/RPC (139/TCP or 445/TCP) and authentication is carried out using domain credentials. If there is no request to run a new command within two hours, the service dissolves automatically. Refer to the HPS Inspection Engine Configuration Guide. for more information about this service.
You can reference the result of the script using a property tag.
Windows File Date
Indicates the date that a specific file was last modified. Use this property, for example, to check that endpoints on the network have a specific file, from a specific date. Examples would be a security configuration file or an antivirus signature file. By using this condition, you can create a policy that enforces existence of the specific file, from a specific date, on every endpoint.
Windows File Exists
Indicates a file name. Use this property, for example, to check that endpoints on the network have a specific file. You can use the following Windows environment variables when you specify a pathname in a condition:
%COMMONPROGRAMFILES% %PROGRAMFILES% %TEMP%
%HOMEDRIVE% %SYSTEMDRIVE% %USERPROFILE%
%HOMEPATH% %SYSTEMROOT% %WINDIR%
Windows File MD5 Signature
Indicates endpoints with specific MD5 signatures.
Windows File Size
Indicates a file name and size (in bytes). Use this property to check that endpoints on the network have a specific file of a specific file size.
Windows File Version
Indicates the version of a defined file on an endpoint.
Windows File Version Comparison
Indicates the existence of a defined file with a version higher than specified.
Windows Is Behind NAT
Indicates whether the endpoint was detected behind a NAT device.
Windows Last Login Event
Indicates the last detected login event on Windows endpoints that are managed by SecureConnector installed as a service. The property is resolved to one of the following values:
None: No Login or Logout events have been detected, or the endpoint is not managed by SecureConnector as a service.
Login: The most recent Windows Login/Logout Event received by SecureConnector was Login.
Logout: The most recent Windows Login/Logout Event received by SecureConnector was Logout.
Windows Logged On
Indicates whether a user is logged in to the endpoint.
Windows Manageable Domain
Indicates whether Forescout eyeSight has access to the endpoint's remote registry and file system. If either criterion is not met, the endpoint is unmanageable. This is typical of endpoints that are foreign to the domain.
Irresolvable endpoints are resolved based on their previous recheck status.
Windows Manageable Domain (Current)
Similar to the Windows Manageable Domain property, except that if irresolvable, the status not manageable is applied until the next recheck.
This property differs from the Windows Manageable Domain property, which resolves irresolvable endpoints based on their previous recheck status.
Windows Manageable Local
Indicates that Forescout eyeSight either has or does not have access to localhost credentials on the detected machine. These credentials include the local user name, password and domain. When this information is available, the endpoint is manageable and can be inspected.
Windows Manageable SecureConnector
Indicates whether Forescout SecureConnector is running on the endpoint. See Start SecureConnector / Stop SecureConnector for details.
When an endpoint with multiple interfaces connects to eyeSight through one NIC, only that host (NIC) is reported by this property.
When Forescout actions are applied to a dual-homed endpoint, the action is applied to all interfaces of the endpoint, even if another host (NIC) on the same endpoint is managed by SecureConnector. If a blocking action is applied to the endpoint, it may lose access to network services it uses.
The Advanced Tools Plugin provides an additional host property that can be used to detect and manage dual-homed endpoints using SecureConnector.
Windows Processes Running
Indicates Windows processes running on inspected endpoints.
Windows Processes Running and User
Indicates a currently active process on a Windows endpoint, and the username/domain of the user that owns the process.
Windows Registry Key Exists
Indicates the existence of a specified Windows registry key. Only the following key roots are available: HKEY_CLASSES_ROOT, HKEY_LOCAL_MACHINE and HKEY_USERS.
Windows Registry Value
Indicates the value of a specified Windows-registry key. Only the following key roots are available: HKEY_CLASSES_ROOT, HKEY_LOCAL_MACHINE and HKEY_USERS.
To retrieve the default value of a registry key, end the pathname with a backslash as in this example:
HKEY_LOCAL_MACHINE\HW\DESCRIPTION\System\BIOS\
Windows Registry Value Exists
Indicates the existence of a value for a specified Windows registry key.
Windows SecureConnector Connection Encryption
Indicates the TLS version used in communications with SecureConnector on Windows.
Windows SecureConnector Deployment Type
Indicates the SecureConnector deployment mode installed on the endpoint.
Windows SecureConnector Systray Display
Indicates the SecureConnector visible mode installed on the endpoint.
Windows Services Installed (Display Name)

Identifies the Windows services that are currently installed on a Windows endpoint. The resolved property provides the Display name of each installed Windows service. A Windows service's display name can vary across Windows endpoints, depending upon each machine's OS language.

Note: In eyeSight versions prior to 8.3, this property is named Windows Services Installed.
Windows Services Installed (Service Name)
Identifies the Windows services that are currently installed on a Windows endpoint. The resolved property provides the Service name of each installed Windows service. A Windows service's service name is consistent across Windows endpoints because service names are independent of the machine's OS language.
Windows Services Running (Display Name)

Identifies the Windows services that are currently running on a Windows endpoint. The resolved property provides the Display name of each running Windows service. A Windows service's display name can vary across Windows endpoints, depending upon each machine's OS language.

Note: In eyeSight versions prior to 8.3, this property is named Windows Services Running.
Windows Services Running (Service Name)
Identifies the Windows services that are currently running on a Windows endpoint. The resolved property provides the Service name of each running Windows service. A Windows service's service name is consistent across Windows endpoints because service names are independent of the machine's OS language.
Windows Shared Folders
Indicates whether a specific folder is currently shared on a Windows endpoint. Use this property, for example, to find network users sharing music folders.
The ability to detect shared directories increases network security by helping users stop unwanted data from propagating across the network.
This property returns the name of the directory.
Windows Version
Indicates to specific Windows versions detected or missing on the endpoint.
Windows Version CPE Format
Indicates the Windows version running on an endpoint in Common Platform Enumeration format. The property contains the full CPE 2.3 name string, bound to a URI, as follows:
cpe:/<part>:<vendor>:<product>:<version>:<update>:<edition>:<language>:<sw_edition>:<target_sw>:<target_hw>:<other>
Use text matching tools to create policy conditions that match substrings of the CPE name string.
The value of this property is duplicated in the more general OS CPE Format host property.
Windows Version Fine-tuned
Indicates the specific version of Windows running on the host.

Windows application properties

The Windows Applications Plugin is used to resolve several properties.

To create policy conditions based on these properties, choose from the list of supported third-party applications. Forescout eyeSight has analyzed the structure, footprint, and related processes of these applications, so the plugin detects them more accurately and inspects them more deeply. New releases of the Windows Applications Plugin add supported applications or enhance support for known applications.

You can choose to automatically add newly supported vendor applications to a policy condition that you create with these properties. See Detect New Vulnerabilities and Newly Supported Vendor Applications for details.

When you define policy rules to handle detected endpoints, remember that the scope of these properties is limited to supported applications - they do not detect or inspect unsupported applications.

For example:

  • The Instant Messaging Installed property detects endpoints on which at least one supported messaging application is installed. It does not detect other applications that may be present on the endpoint. When no supported applications are detected on the endpoint, the property resolves to the value None, but unsupported messaging applications may be present.
  • Similarly, the Hard Drive Encryption State property detects drives/partitions encrypted by supported applications. When no drives are encrypted by supported applications, the property resolves to the value Not Encrypted for each partition on the endpoint, but partitions may be encrypted by unsupported applications.
    Note: Use other host properties to create conditions that inspect endpoints and detect files or processes of unsupported applications.
    Windows Applications Installed
    Indicates which applications are installed on the Windows endpoint via Add/Remove Programs. This property resolves the name of the applications, and their version number if available.
    When you define policies with Windows Applications Installed and select For all property values and Name, all the installed applications must match the Name for the host to match the condition.
    Cloud Storage Installed
    Indicates that at least one of the following cloud storage applications is installed on the endpoint.
    Cloud Storage Running
    Indicates that at least one of the following cloud storage applications is running on the endpoint.
    Hard Drive Encryption Installed
    Indicates the hard drive encryption applications(s) installed on the endpoint.
    Hard Drive Encryption State
    Indicates whether hard drives on the endpoint are encrypted, and which application, if any, was used to encrypt each drive.
    Instant Messaging Installed
    Indicates that an instant messaging application is installed on the endpoint.
    Instant Messaging Running
    Indicates that an instant messaging application is running on the endpoint.
    Microsoft Applications installed
    Indicates the existence of Microsoft products on the endpoint.
    Peer-to-peer Installed
    Indicates endpoints that have installed peer-to-peer applications.
    Peer-to-peer Running
    Indicates endpoints that are running peer-to-peer applications.

Windows security properties

The Windows Applications Plugin updates vendor information used to resolve several of these properties. You can choose to automatically add newly supported vendors to a policy condition that you create with these properties. See Detect New Vulnerabilities and Newly Supported Vendor Applications for details.

Anti-Spyware Installed
Indicates whether Anti-Spyware is installed.
Antivirus Installed
Indicates whether an antivirus service is installed.
Antivirus Running
Indicates whether an antivirus service is currently running on the endpoint.
Antivirus Update Date
Indicates the date of the last antivirus signature update performed on the endpoint. The antivirus application must be running to be detected. This means an update is installed on any antivirus vendor running on the endpoint.
Windows Hotfix Installed
Indicates the existence of a security update on the endpoint, based on Hotfix ID and caption.
Intranet WSUS Server
Indicates the host name or IP address of the intranet WSUS server on the endpoint. Use this property when working with the Microsoft Vulnerability properties and the Start Windows Updates action. The server version on the endpoint and the server version installed on the network must match in order for endpoints to be remediated by a WSUS server.
Microsoft Vulnerabilities
Indicates the existence of published Microsoft operating system and application vulnerabilities on the endpoint.
To use this property:
The Windows Update Agent must be available on the endpoint.
The endpoint must be managed by either Remote Inspection or SecureConnector.
Refer to the HPS Inspection Engine Configuration Guide for details.
You can automatically add newly supported vulnerabilities to a policy condition that you create with this property. See Detect New Vulnerabilities and Newly Supported Vendor Applications.
Use the Windows Self Remediation action to download missing patches to endpoints.
Microsoft Vulnerabilities Fine-tuned
Indicates the existence of Microsoft published OS and Office vulnerabilities detected on the endpoint. Fine-tune inspection according to specific criteria.
The following criteria can be searched:
Label
Update Time
Severity
Product
CVE
An advanced option for the Microsoft Vulnerabilities property lets you improve performance and reduce network bandwidth. Use the option to define the rate to recheck endpoint vulnerabilities on machines where vulnerabilities were already checked and not found.
These endpoints will not be rechecked at a rate higher than the rate that you define. If the rate that you define is more frequent than the rate in the Recheck policy, the Recheck policy rate is applied. If you disable this option, the Recheck policy rate is applied.
Personal Firewall
Indicates if a personal firewall has been detected on the endpoint.
Windows Updates Installed - Reboot Required
Indicates if Windows updates were installed, and if the endpoint is waiting for a reboot.
Use this property in conjunction with Microsoft Vulnerability Updates to indicate if a reboot of the endpoint is needed to complete the installation of a security update.
Windows Security Center Antivirus Status
Indicates antivirus applications detected on the endpoint by the Windows Security Center, as well as endpoint status.
Windows Update Agent Installed
Indicates whether the Windows Update Agent (WUA) is installed on network endpoints. The agent is required to resolve the Microsoft Vulnerabilities and Microsoft Vulnerabilities Fine-tuned properties, as well as carry out the Start Windows Updates action.