Detection key configurations for Vulnerability Response

  • Release version: Xanadu
  • Updated January 15, 2026
  • 1 minute to read
  • Use configurable detection keys to choose between Asset ID and Configuration Item, with validations, UI controls, and a schedule job to update existing detections.

    The Detection Key Configuration provides you with greater control over how vulnerability detections are uniquely identified within the system. Previously, the detection key relied exclusively on the asset ID. Now, you can choose between:

    • Asset ID (Discovered Item Source ID)
    • Configuration Item (CI)

    This flexibility helps align detection logic with internal asset management practices, especially when CI-level tracking is required.

    Additionally, the following updates have been added:

    • A new Configure Detection Granularity module.
    • A new Configuration Item column on the Detection Key table.
    • Editable detection key fields with controlled access.
    • Validation checks to preserve data integrity during in-progress jobs.
    • Schedule jobs to apply updated detection keys to existing detection records.