Assets
Assets are hardware and software components within an environment. BreachSpider matches each asset against the CVE corpus to produce findings.
Asset Fields
| Field | Type | Description |
|---|---|---|
| id | integer | Asset ID |
| name | string | Asset name (e.g. "SCADA Server 01") |
| vendor | string | Manufacturer name |
| product | string | Product name |
| version | string | Firmware or software version |
| ip_address | string | IP address (optional) |
| asset_type | string | PLC, HMI, RTU, SCADA, Workstation, Server, Firewall, Switch |
| layer | string | OT, IT, Network, Other |
| is_active | boolean | Whether this asset is currently active |
| match_count | integer | Number of CVE matches |
Match Confidence
| Confidence | Meaning |
|---|---|
| high | Vendor and product name both match - counts in posture scores |
| medium | Vendor match only - shown but not counted in risk score |
| low | Fuzzy match - informational only |
Only high confidence matches count toward dashboard findings, risk scores, and alert triggers.
Windows Patch Level
Windows assets that carry a full build (10.0.<build>.<revision>), or hosts submitted through API v2, are checked against Microsoft's own fixed builds and KBs. Their findings carry four extra fields in GET /api/v1/environments/{env_id}/summary:
| Field | Meaning |
|---|---|
| windows_status | confirmed_open (confidence high) or needs_review (confidence medium); null for non-Windows findings |
| fixed_build | Microsoft's fixed build for this CVE on this Windows product |
| fix_kb | The fix KB, e.g. KB5066586 |
| ms_source | The Microsoft Security Update Guide document behind the result |
CVEs that the host's build already fixes are cleared and are not findings. To see every Microsoft-decided CVE for one asset, cleared ones included:
curl -H "Authorization: Bearer bs_live_..." \
"https://breachspider.com/api/v1/environments/5/assets/42/windows-patch"
{
"windows": true,
"labels": [],
"map_note": null,
"os_build": "10.0.17763.7792",
"counts": {"confirmed open": 1653, "cleared (patched)": 3949, "needs review": 3},
"cves": [
{"cve_id": "CVE-2016-9535", "status": "confirmed open", "fixed_build": "10.0.17763.7919",
"kb": "KB5066586", "source": "https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2025-Oct",
"known_exploited": false, "note": "build below Microsoft's fixed build"}
]
}
Assets without a build return {"windows": false} and keep product-level matching.
Listing Assets
Assets paginate with limit and offset (not page):
curl -H "Authorization: Bearer bs_live_..." \
"https://breachspider.com/api/v1/environments/5/assets?limit=50&offset=0"
Updating an Asset
curl -X PUT \
-H "Authorization: Bearer bs_live_..." \
-H "Content-Type: application/json" \
-d '{
"version": "2.9.7",
"is_active": true
}' \
"https://breachspider.com/api/v1/environments/5/assets/42"
CSV Template Format
The CSV template has these columns:
name,vendor,product,version,ip_address,asset_type,layer,notes
SCADA Server 01,Siemens,SIMATIC S7-1500,2.9.4,192.168.10.15,PLC,OT,
HMI Terminal 01,GE Vernova,CIMPLICITY,12.0,,HMI,OT,Control room