Skip to content

Assets

Assets are hardware and software components within an environment. BreachSpider matches each asset against the CVE corpus to produce findings.

Asset Fields

Field Type Description
id integer Asset ID
name string Asset name (e.g. "SCADA Server 01")
vendor string Manufacturer name
product string Product name
version string Firmware or software version
ip_address string IP address (optional)
asset_type string PLC, HMI, RTU, SCADA, Workstation, Server, Firewall, Switch
layer string OT, IT, Network, Other
is_active boolean Whether this asset is currently active
match_count integer Number of CVE matches

Match Confidence

Confidence Meaning
high Vendor and product name both match - counts in posture scores
medium Vendor match only - shown but not counted in risk score
low Fuzzy match - informational only

Only high confidence matches count toward dashboard findings, risk scores, and alert triggers.

Windows Patch Level

Windows assets that carry a full build (10.0.<build>.<revision>), or hosts submitted through API v2, are checked against Microsoft's own fixed builds and KBs. Their findings carry four extra fields in GET /api/v1/environments/{env_id}/summary:

Field Meaning
windows_status confirmed_open (confidence high) or needs_review (confidence medium); null for non-Windows findings
fixed_build Microsoft's fixed build for this CVE on this Windows product
fix_kb The fix KB, e.g. KB5066586
ms_source The Microsoft Security Update Guide document behind the result

CVEs that the host's build already fixes are cleared and are not findings. To see every Microsoft-decided CVE for one asset, cleared ones included:

curl -H "Authorization: Bearer bs_live_..." \
  "https://breachspider.com/api/v1/environments/5/assets/42/windows-patch"
{
  "windows": true,
  "labels": [],
  "map_note": null,
  "os_build": "10.0.17763.7792",
  "counts": {"confirmed open": 1653, "cleared (patched)": 3949, "needs review": 3},
  "cves": [
    {"cve_id": "CVE-2016-9535", "status": "confirmed open", "fixed_build": "10.0.17763.7919",
     "kb": "KB5066586", "source": "https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2025-Oct",
     "known_exploited": false, "note": "build below Microsoft's fixed build"}
  ]
}

Assets without a build return {"windows": false} and keep product-level matching.

Listing Assets

Assets paginate with limit and offset (not page):

curl -H "Authorization: Bearer bs_live_..." \
  "https://breachspider.com/api/v1/environments/5/assets?limit=50&offset=0"

Updating an Asset

curl -X PUT \
  -H "Authorization: Bearer bs_live_..." \
  -H "Content-Type: application/json" \
  -d '{
    "version": "2.9.7",
    "is_active": true
  }' \
  "https://breachspider.com/api/v1/environments/5/assets/42"

CSV Template Format

The CSV template has these columns:

name,vendor,product,version,ip_address,asset_type,layer,notes
SCADA Server 01,Siemens,SIMATIC S7-1500,2.9.4,192.168.10.15,PLC,OT,
HMI Terminal 01,GE Vernova,CIMPLICITY,12.0,,HMI,OT,Control room