Asset Discovery on MyNCSC
Asset Discovery is now available to all Organisation Administrators using MyNCSC. This page explains how Asset Discovery could enhance awareness of your shadow IT.
Many organisations which participated in the Asset Discovery pilot found it to be a valuable addition to their security toolkit.
What does Asset Discovery do?
Asset Discovery helps you identify “shadow” and legacy IT that may no longer be monitored by your organisation. This is done by searching a variety of online data sources based on your existing portfolio, it does not involve direct interaction with your IT.
It identifies potentially relevant assets. These may generate additional findings (primarily through Mail Check and Web Check) if added to your portfolio, or they may be legacy assets suitable for decommissioning.
How to use Asset Discovery
- Email notifications: On a monthly basis we will check our data and email you notification of any additional assets (sub-domains) we have discovered.
- Reviewing asset discoveries: These discovered assets will be available to review in your organisation’s Asset area on MyNCSC (see the Discovered assets tab). You can review them either in tabular form in MyNCSC, or you can download a CSV file.
- Working with colleagues: Asset discovery is only available to Organisation Administrators in MyNCSC. Using the CSV download feature, Administrators can consult colleagues in their organisation about the results.
- Adding discovered assets to MyNCSC: Once you have reviewed your organisation’s discovered assets, you can either add them directly from the table, or you can upload in bulk from a CSV file (using the Add Assets button). In accordance with MyNCSC Terms and Conditions, you should only add assets related to IT systems that your organisation owns or has the right of use over.
- Ignoring discovered assets: If you do not want to add these assets to MyNCSC you can use the table to select and ignore them. Your organisation will no longer be notified of these ignored assets. You will still be able to view them by filtering the table on the Discovered assets tab.
- Decommissioning assets: Legacy assets no longer used by your organisation still contribute to its attack surface. It is good practice to decommission these.
What data sources and techniques are used in Asset Discovery?
MyNCSC currently uses the following techniques for discovering sub-domains of domains in your asset portfolio:
- DNS enumeration: This technique involves checking publicly available DNS records to see if your organisation is using commonly occurring subdomains like “api.example.gov.uk”.
- Reverse DNS lookup: This technique involves checking for relevant subdomains in publicly available pointer (PTR) records.
- Certificate Transparency logs: This technique involves searching publicly available Certificate Transparency logs that your organisation has made available online.