Cortex XSIAM scans your public-facing websites, identifying insecure websites, web components, and technologies running on your web assets.
Cortex XSIAM websites data extends Attack Surface Management (ASM) protection by identifying insecure websites, web components, and technologies running on your managed and unmanaged web assets. Cortex XSIAM scans your public-facing websites, creating a continuously updated inventory of your web assets, including the server software and other technologies powering your web applications.
Websites data in Cortex XSIAM enables you to accomplish the following:
Develop a single source of truth for all of your organization's web inventory
Track and monitor your risk due to third-party libraries
Continuously discover and monitor external web application inventory and third-party technologies
Identify insecure and misconfigured websites, vulnerable technologies, and dependencies
Improve security ratings by identifying sites failing security best practices
The difference between websites and external services
In Cortex XSIAM, external services are public-facing network services; for example, an RDP server or an HTTP server. Websites represent the content and the software stack that was used to generate the website.
An HTTP service represents a single HTTP server (on-prem) or a cohesive group of HTTP servers (cloud). A website can be served by a single HTTP server or by multiple HTTP servers. Some of these HTTP servers could be hosted by a cloud provider, others on-prem. Generally, the relationship between HTTP services and websites can be described as follows:
A website is supported by one or more HTTP services.
A cloud HTTP service serves a single website.
An on-prem HTTP service serves multiple websites, potentially hundreds.
The difference between websites and domains
A domain is simply the registration of a domain (for example, your organization might own www.example.com). You can have a domain without a website behind it. You can also have a domain that does not resolve to an IP address (which means it does not have a website behind it). Cortex XSIAM includes websites with a domain name or an IP address.