List of properties by category
This topic describes properties that are available by default in a typical eyeSight deployment. Some properties may not be available depending on the details of your Forescout configuration. Some properties may not be available, or remain unpopulated with data if certain device types are not present in your network.
Authentication properties
Classification properties
Advanced classification properties
Device information properties
" grep -v "XYZ""Event properties
External devices properties
Guest registration properties
Health monitoring properties
The following properties are used to help you monitor Appliance health. These properties are included in policies created by Health Monitoring Templates. Running these templates populates Health Monitoring Dashboard widgets.
Linux properties
Macintosh properties
The OS X Plugin supports the following properties for macOS endpoints.
Remote inspection properties
The following properties indicate which management services are available on the endpoint that Forescout eyeSight can use to perform Remote Inspection.
These properties do not have an Irresolvable state. When the plugin or module cannot establish connection with the service, the property value is False. Do not use the Evaluate Irresolvable Criteria as option with these properties.
The following corresponding Track Changes policies are listed under the Track Changes folder:
- MS-RRP reachability changed
- MS-SMB reachability changed
- MS-WMI reachability changed
SNMP properties
Use of SNMP properties requires the proper configuration and activation of the HPS Inspection Engine. When entering the following values, use these guidelines:
- For SNMP V1, use:
-v 1 -c <community> - For SNMP V2, use:
-v 2 -c <community> - For SNMP V3, use:
-v 3 -u <user> -A <password>Use the SNMP Parameters field to enter optional SNMP connection parameters. The following parameters are supported:
Parameter Description -p <port>
Specify the port used for SNMP messaging on the server.
-r <retries>
Specify the number of times to retry the request.
-t <seconds>
Specify the timeout period before retrying the request.
-E <engine_ID>
Specify the Context Engine ID for REQUEST messages (SNMP v3 only).
-n <cont_name>
Specify the Context Name (SNMP v3 only).
SNMP-MIB-II ifNumberIndicates the number of network interfaces (regardless of their current state) present on this system. The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.In the SNMP-MIB-II ifNumber field, enter the number of interfaces to be detected on the SNMP agent.SNMP-MIB-IIsysDescriptionIndicates a textual description of the entity. This value should include the full name and version identification of the system's hardware type, software operating-system, and networking software. It is mandatory that this only contain printable ASCII characters. The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.In the SNMP-MIB-II sysDescription field, enter the description that should match the SNMP agent system description. If you are not sure of the name, you can use the regular expression option, and enter wildcard text - for example, ci.* if you want to detect a Cisco switch.SNMP-MIB-II sysLocationIndicates the physical location of this node (for example, telephone closet, third floor). The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.In the SNMP-MIB-II sysLocation field, enter the location that should match the SNMP agent. If you are not sure of the name, you can use the regular expression option, and enter wildcard text (.*).SNMP-MIB-II sysNameIndicates an administratively assigned name for this managed endpoint. By convention, this is the endpoint's fully qualified domain name. The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.In the SNMP-MIB-II sysName field, enter the requested system name to match.SNMP-MIB-II sysUpTimeIndicates the time since the network management portion of the system was last re-initialized. The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.Use the Older than or Before options to create a condition based on the time the SNMP agent was last turned on.SNMP-OIDIndicates an OID value, on the SNMP agent. The collection of this information depends on access parameters (SNMP Parameters) specific to the SNMP version of the inspected endpoint.In the SNMP OID field, enter the requested OID value on the endpoint. If the OID query and the SNMP-OID Value match, then the condition is registered.
Switch properties
An extensive range of properties are resolved for Switches that are configured to work with Forescout eyeSight. The section provides an overview of the Switch properties.
Select Options from the Tools menu and then select Switch to configure the Switch Plugin. Select Help for information about configuration and for more information about working with switch properties.
Basic managed switch information
The following properties resolve basic information about a managed switch:
assign_sgt is disabled, the property is marked as Obsolete in the relevant policies. For details about this flag, refer to the Forescout Switch Plugin Configuration Guide.<IP address/FQDN>:<port>.Cisco IP Phone 6921.Vendor is currently not supported for this property. sysDescr (1.3.6.1.2.1.1.1).Network device compliance properties
For any Cisco network device managed by the Switch Plugin, use the following policy properties to create policies that determine network device compliance:
show running-config command.MM/DD/YY HH:MM:SS AM/PM, of the plugin's running config information query of the device.Track changes properties
Items in this category check whether a property value has changed, for example, if a user name changed. Detecting changes in endpoints is a powerful method of identifying possible attacks or noncompliance.
All these properties exist under other categories, but here these properties check whether the value has changed. For example, the Windows File Size property in the Windows folder detects the size of a file at a specific location. In the Track Changes folder, Forescout eyeSight detects if the file size at that location changed.
Some of the Track Changes properties require the proper configuration and activation of the HPS Inspection Engine.
User directory properties
The following user attributes indicate if the user's account in the User Directory is disabled or expired:
- Account is Disabled
- Account is Expired
The following user attributes may vary depending on the User Directory configuration:
- Common Name, Employee Number, Password Last Set
- Company, Initials, Phone
- Department, Last Name, Street Address
- Display Name, LDAP User Name, Title
- Distinguished Name, Member Of, User Given Name
- Email, Mobile Phone
Windows properties
fsprocsvc. The service does not open any new network connection or generate traffic. Communication is carried out over Microsoft's SMB/RPC (139/TCP or 445/TCP) and authentication is carried out using domain credentials. If there is no request to run a new command within two hours, the service dissolves automatically. Refer to the HPS Inspection Engine Configuration Guide. for more information about this service.HKEY_LOCAL_MACHINE\HW\DESCRIPTION\System\BIOS\
Identifies the Windows services that are currently installed on a Windows endpoint. The resolved property provides the Display name of each installed Windows service. A Windows service's display name can vary across Windows endpoints, depending upon each machine's OS language.
Note: In eyeSight versions prior to 8.3, this property is named Windows Services Installed.Identifies the Windows services that are currently running on a Windows endpoint. The resolved property provides the Display name of each running Windows service. A Windows service's display name can vary across Windows endpoints, depending upon each machine's OS language.
Note: In eyeSight versions prior to 8.3, this property is named Windows Services Running.cpe:/<part>:<vendor>:<product>:<version>:<update>:<edition>:<language>:<sw_edition>:<target_sw>:<target_hw>:<other>
Windows application properties
The Windows Applications Plugin is used to resolve several properties.
To create policy conditions based on these properties, choose from the list of supported third-party applications. Forescout eyeSight has analyzed the structure, footprint, and related processes of these applications, so the plugin detects them more accurately and inspects them more deeply. New releases of the Windows Applications Plugin add supported applications or enhance support for known applications.
You can choose to automatically add newly supported vendor applications to a policy condition that you create with these properties. See Detect New Vulnerabilities and Newly Supported Vendor Applications for details.
When you define policy rules to handle detected endpoints, remember that the scope of these properties is limited to supported applications - they do not detect or inspect unsupported applications.
For example:
- The Instant Messaging Installed property detects endpoints on which at least one supported messaging application is installed. It does not detect other applications that may be present on the endpoint. When no supported applications are detected on the endpoint, the property resolves to the value None, but unsupported messaging applications may be present.
- Similarly, the Hard Drive Encryption State property detects drives/partitions encrypted by supported applications. When no drives are encrypted by supported applications, the property resolves to the value Not Encrypted for each partition on the endpoint, but partitions may be encrypted by unsupported applications.
Note: Use other host properties to create conditions that inspect endpoints and detect files or processes of unsupported applications.Windows Applications InstalledIndicates which applications are installed on the Windows endpoint via Add/Remove Programs. This property resolves the name of the applications, and their version number if available.When you define policies with Windows Applications Installed and select For all property values and Name, all the installed applications must match the Name for the host to match the condition.Cloud Storage InstalledIndicates that at least one of the following cloud storage applications is installed on the endpoint.Cloud Storage RunningIndicates that at least one of the following cloud storage applications is running on the endpoint.Hard Drive Encryption InstalledIndicates the hard drive encryption applications(s) installed on the endpoint.Hard Drive Encryption StateIndicates whether hard drives on the endpoint are encrypted, and which application, if any, was used to encrypt each drive.Instant Messaging InstalledIndicates that an instant messaging application is installed on the endpoint.Instant Messaging RunningIndicates that an instant messaging application is running on the endpoint.Microsoft Applications installedIndicates the existence of Microsoft products on the endpoint.Peer-to-peer InstalledIndicates endpoints that have installed peer-to-peer applications.Peer-to-peer RunningIndicates endpoints that are running peer-to-peer applications.
Windows security properties
The Windows Applications Plugin updates vendor information used to resolve several of these properties. You can choose to automatically add newly supported vendors to a policy condition that you create with these properties. See Detect New Vulnerabilities and Newly Supported Vendor Applications for details.
minute read