How to handle temporary / ephemeral builds with Vulnerability Response

rogerburns
Tera Expert

We have an issue with temporary or ephemeral builds that are built on a network, scanned by our VR scanner (CrowdStrike) and then patched. After the patching process, the builder then captures the snapshot of the build and then destroys it.  However, due to latency the integration with CrowdStrike will then insert a Discovered Item as it cannot find a matching device and populates it with many VITs.  This then requires someone to find that DI and reclassify something that is not even active anymore.  This causes a lot of rework and we are looking to find out how other organizations are handling those temporary builds with regards to VR. 

0 REPLIES 0