There are four types of scans available in OneView. Threat Scan, Hyper Scan, and Custom Scan check for threats, while the Inventory & Vulnerability Scan updates endpoint information in the console.
Scans can be run manually from the console and endpoint, or scheduled from the console.
- For more information on initiating a scan from the console, see Endpoint actions in OneView.
- Threat Scans can be initiated on a local endpoint by right-clicking on the Endpoint Agent tray icon and selecting Start Threat Scan.
- For more information on scheduled scans, see Scheduled scans in OneView
Scan objects and settings
These are the objects and settings referenced throughout the scan descriptions below. Not every scan type or OS uses every item.
| Object or setting | Definition |
|---|---|
| Memory Objects | Memory allocated by operating system processes, drivers, and other applications. |
| Startup Objects | Executable files and modifications made during computer startup. |
| Registry Objects | Configuration changes made to the Windows registry. |
| File System Objects | Files that may contain malicious programs or harmful code snippets. |
| Potentially Unwanted Programs (PUPs) | Toolbars, bundleware, bloatware, or similar programs that exhibit unwelcome behavior. |
| Potentially Unwanted Modifications (PUMs) | Specific modifications made to the Windows Registry. Malware may modify the Windows registry to obfuscate its location and make remediation difficult. |
| Archives | Archive files are scanned up to four levels deep. Encrypted archives are not scanned. Supported archive types include ZIP, 7Z, RAR, CAB, and MSI. |
| Rootkits | System kernel, firmware, and memory are checked for rootkit activity. |
| Adware | Malicious software that displays advertisements or tracks online behavior. Not configurable, automatically scanned on macOS. |
| Malicious browser extensions | Browser add-ons that steal data and hijack searches. Not configurable, automatically scanned on macOS. |
| Scan all local drives | Scans all local drives hosted on an endpoint. Does not scan mounted or external drives unless specified in the Scan Path. |
| Scan Path |
The top-level folder for the Custom Scan.
|
Detection scan types
- Threat Scan: Detects common threats using heuristic analysis to identify malicious behavior in unfamiliar files. Recommended to run daily. Settings configured in policy apply to all Threat Scan initiation methods: manual, scheduled, or on-demand.
- Hyper Scan: Quick scan for fast detection and cleanup. If threats are found, follow up with a Threat Scan for deeper analysis.
- Custom Scan: Allows precise control over what gets scanned and which drives. Configure it under Configure > Schedules, or run it on demand from Manage > Endpoints. Recommended: run weekly full scans of all local drives.
| Scan type | Windows | Mac | Linux |
|---|---|---|---|
| Threat Scan | Memory Objects Startup Objects Registry Objects File System Objects PUPs PUMs |
Memory Objects File System Objects PUPs Rootkits Adware Malicious browser extensions |
File System Objects |
| Hyper Scan | Memory Objects Startup Objects |
File System Objects PUPs Adware Malicious browser extensions |
N/A |
| Custom Scan | Memory Objects Startup Objects Registry Objects Archives Rootkits PUPs PUMs Scan all local drives Scan Path |
Memory Objects File System Objects PUPs Rootkits Adware Malicious browser extensions Scan all local drives Scan Path |
N/A |
Inventory & Vulnerability Scan
Retrieves software inventory, installed AI tools, and hardware information based on enabled Software Management settings, and updates endpoint details in the console. Recommended to run daily.
Information collected during the asset scan is updated on the Endpoint Properties screen. Information scanned may include:
- Storage Devices: Connected storage, USB storage, and other devices.
- Memory Objects: Physical and virtual memory of the endpoint.
- Startup Programs: Registry entries for installed startup programs on the endpoint.
- Installed Software: Software installed on the endpoint.
- Software Updates: Software updates that occurred on the endpoint.
- Vulnerability Data: Identifies known vulnerabilities in installed software on Windows and macOS endpoints.
For information on changing what software inventory information is collected on endpoints, see Software management policy settings in OneView.
To view Endpoint Properties, go to Manage > Endpoints and click an endpoint name. View more information on the endpoint by selecting the tabs at the top of the Endpoint Properties screen. For more information, see Endpoints page in OneView.
Notes
- Offline endpoints store scan results locally until the endpoint reconnects.
- Network and shared drives are not scanned across endpoints.
- ChromeOS devices cannot be scanned.