Skip to main content

Zones, subnets, URLs, and tags

This is where you define what the CyberOptix CTEM Platform scans. Nothing internal is touched until something here says it should be.

Four pieces, and they do different jobs:

Answers
Subnets and URLsWhat could be scanned
ZonesWhat actually is, by whom, and when
TagsHow you find it afterwards

Subnets and URLs​

The raw inventory of things you own. Subnets are network ranges in CIDR; URLs are web applications.

Adding them here makes them available, not scanned. Scanning happens when a zone includes them - which is what lets you record your estate without committing to scan all of it.

Zones​

A zone is a scanning scope. It brings together what to scan, who scans it, and when:

Screenshot pending

SCREENSHOT: the zone configuration form.

ComponentPurpose
Subnets and URLsWhat is in scope
Scanner groupWhich scanners do the work
Scan schedulesHow often each scan type runs
Nmap parametersHow aggressively to probe
Excluded hostsAddresses inside the range that must not be touched
Blackout windowsWhen not to scan

The scanner group is assigned to the zone, not to the assets. That indirection is what lets you replace a scanner without editing scope, and lets one group serve several zones. See Scanner groups and tasks.

Model zones on reachability​

A zone should answer "what can a scanner in this position actually reach?" - because that is the constraint it exists to express. Splitting by network position (DMZ, internal, management) works. Splitting by ownership does not: that is a business unit, and a scanner cannot see a team.

Excluded hosts​

Addresses that must not be scanned even though they sit inside an included range.

Use this for anything that reacts badly to being probed - fragile industrial equipment, medical devices, a legacy appliance that falls over on a port scan. It is a safety control, and it is easier to add before an incident than to explain afterwards.

Blackout windows​

Periods when scanning must not run: a trading window, a month-end batch, a maintenance weekend. One-off windows and recurring ones are configured separately, so a nightly batch job does not need re-entering every day.

Set these before the first scan, not after

Excluded hosts and blackout windows are the two settings people configure in response to something going wrong. Both take a minute in advance.

Scan schedules​

Each scan type runs on its own cadence, because their costs differ enormously. A common starting point:

Scan typeCadenceWhy
DiscoveryDaily or weeklyCheap, and new hosts are what you most want to catch
Port scanDaily or weeklyCheap, catches service changes
Vulnerability scanWeekly or monthlyExpensive, results change slowly
Web application scanWeekly or monthlyExpensive, and noisy against production

Discovery frequently and assessment less often is usually right: it is cheap to notice a new host and expensive to deeply test every host every night.

Nmap parameters​

How aggressively scanners probe - a trade between speed, thoroughness, and how much load is put on the target. Fragile networks want gentler parameters; a lab can take more. Custom parameter sets are configured under Administration if the supplied ones do not fit.

Tags​

Free-form labels, and the highest-return thing on this page for the least effort.

Zones and business units are structural and deliberately rigid. Tags are for everything else you will want to filter by later: production, pci-scope, owner:platform-team, decommission-q3.

Tag as assets are discovered, not later. The first pass through a new inventory is the only time anyone has the context fresh, and every subsequent triage is faster for it. "Critical findings on production assets in PCI scope" is a one-line filter if you tagged, and an afternoon if you did not.

Getting to a first scan​

  1. Add the subnets and URLs you own.
  2. Create a scanner group and deploy a scanner into it.
  3. Create a zone: include the subnets, assign the group, set schedules.
  4. Add excluded hosts and blackout windows before anything runs.
  5. Let discovery run, then tag what comes back.

API​

The endpoints behind this section are in the API reference.

Next​