Vulnerability scanning now supported in OT and isolated network environments
WithSecure Elements Vulnerability Management can now scan operational technology (OT) networks and other isolated or segmented environments by routing scan node traffic through an Elements Connector acting as a proxy.
With this change, scan nodes deployed within isolated network segments can route all communication to the Elements backend over ports 80/443 via a centrally deployed Elements Connector — without requiring internet access or additional firewall exceptions from within the segment.
Asset sub-type support in findings
Findings in Exposure Management now include asset sub-type information, giving users a more precise understanding of which type of asset a finding is associated with.
Assets across all supported sources (Identity, ASM, VM, Cloud, and Device Service) now carry an optional sub-type property that provides a second-level classification beyond the primary asset type. For example, identity assets can be distinguished as Member, Guest while internet assets can be classified as Domain, Subdomain, or IPv4 Address.
Asset sub-type data is now available in the Findings list (Environment → Exposure → Findings) via:
- A new "Asset sub-type" column (hidden by default, sortable, can be enabled via column settings)
- A new "Asset sub-type" filter to narrow findings down to a specific asset classification
These improvements make it easier to prioritize and investigate findings based on the precise nature of the affected asset.