Network segmentation is a foundational security control that can be easily undermined by network misconfigurations and multi-homed machines. runZero Enterprise users can visualize potential network paths between any two assets in an organization using the Asset Route Pathing report.
This report generates a graph of multiple potential paths by analyzing IPv4 and IPv6 traceroute data in combination with subnet analysis of detected multi-homed assets–without requiring access to the hosts or network equipment. This unique methodology identifies surprising and unexpected paths between assets that may not be accounted for by existing security controls or reviews.
With a view of potential paths, security professionals can verify whether a low-trust asset, such as a machine on a wireless guest network, can reach a high-value target, such as a database server within a cardholder data environment (CDE). This feature highlights potential network segmentation violations and opportunities for an attacker to move laterally from one segment to another.
Get the latest news and expert insights delivered in your inbox.