About Forescout eyeFocus

This topic provides a conceptual overview and technical summary of Forescout eyeFocus(formerly Risk and Exposure Management or REM) product.

Cybersecurity teams use eyeFocus (formerly REM) to understand their cyber-attack surface, identify assets and their associated exposure, quantify risk, and act on the most significant threats to their network using prioritized, risk-based remediation.

eyeFocus is a cloud-powered solution designed to further enhance your network security posture by leveraging the rich, contextual device data in your on-prem eyeSight deployment and sharing it with the Forescout Cloud Platform.

eyeFocus identifies managed and unmanaged assets across your attack surface, automatically quantifying the risk they pose to the network. SOC teams gain significant advantages utilizing the risk-based approach for prioritizing remediation workflows, and for incident investigation through persistent asset intelligence that tracks configuration state changes over time.

When used in conjunction with eyeSight, the eyeFocus service delivers the following key functionality:

  • Modern asset view of persistent inventory of all device types
  • Unique multifactor risk score based on configuration, function and behavior
  • High-fidelity cloud classification
  • Patented deep packet inspection technology
  • Correlation of vulnerability exploitability and asset exposure
  • Integrations with leading security products and ability to track effectiveness
  • Actionable risk and exposure insights for response actions
  • Cloud data lake of risk and threat intelligence
The information will be stored in the Forescout Cloud data lake for 90 days for persistent visibility and analysis by your security teams. It will also be correlated in the cloud to calculate a unique multifactor risk score for each device. Rather than focusing on a single viewpoint, the Forescout Risk score quantifies risk factors across configuration, function and behavior to help provide a true picture of the exposure gaps in your attack surface.

The following diagram summarizes the Risk and Exposure attributes used to calculate Risk Score:

  • Configuration: The unique configuration requirements of each individual asset by classification to identify the exposure of each asset, and the exploitability. See Known Vulnerabilities (CVEs) and Exposed Services. 
  • Function: Devices are targeted depending on their criticality within the organization. See Device Criticality.
  • Behavior: Devices are targeted depending on the actions they perform. See Internet Exposure.

Referring to the figure below, the eyeFocus service is deployed as SaaS on the Forescout Cloud platform. The EM (Enterprise Manager) / Appliances are deployed on-premise, and are responsible for collecting data from connected devices. The eyeFocus Risk Engine on the Forescout Cloud platform continuously calculates a Risk Score based on device enrichment detections and risk context, per device, which reflects the current and potential risk state of the device and combines both the internal and the external risk threats.

The eyeSight appliances poll the cloud via the Cloud Data Exchange Plugin regularly for the latest risk score, risk and exposure attributes, and additional device and classification context. Any newly identified exposure attributes are immediately factored into the Risk engine calculations and a new Risk score created. The configuration and state changes are shown as events on the Device-status-over-time timeline view for the individual device.

Forescout recommends integrating a suitable Vulnerability Assessment Tool, via the Forescout eyeExtend ecosystem to further enrich the accuracy of CVE's detected on managed assets.

For tracking internet exposure, we recommend configuring a suitable switch, firewall, or router to send NetFlow or SPAN data to the Appliances, uploads the Internal and Internet traffic flows for the connected devices. Forescout Cloud is scalable, guarantees high availability, and synchronizes data with the on premises Forescout Console.

To get started configuring the necessary systems to use eyeFocus, please see and complete the QuickStart Task List.

For an overview of navigating the eyeFocus interface, see Forescout Cloud Navigation