Stack Scan sensor
The Stack Scan sensor provides credential-less discovery (less intrusive discovery) of the installed operating system and open ports on a computer system.
Sensor name that is used in the GUI and logs
StackScanSensor
Prerequisites
The sensor requires the following software:
- Nmap tool. See Configuring Nmap for details.
- WinPcap tool for Windows operating systems. Install it manually.
- Sudo tool for non-Windows operating systems.
For the user to use the nmap tool through sudo, you must install and configure sudo version 1.6.7p5.
Security issues
To configure sudo access for the Agile Service Manager user, you need to set a nopasswd option in the /etc/sudoers file for the Agile Service Manager user.
Limitations
nmap -T Normal -O -sS -sU -oX - IPaddress
Application servers and services discovered using a credential-less (Level 1) discovery are reconciled with the application servers and services using a Level 2 or Level 3 discovery, only if the binding TCP ports are the same. All application servers and services discovered using a Level 1 discovery remain following a Level 2 or Level 3 discovery, but applications and services matching on the binding ports are merged.
Model objects created
The sensor creates the following model objects:
- net.IpAddress
- net.IpInterface
- net.L2Interface
- sys.aix.Aix
- sys.aix.AixUnitaryComputerSystem
- sys.ComputerSystem
- sys.hpux.HpUx
- sys.hpux.HpUxUnitaryComputerSystem
- sys.i5OS.I5OperatingSystem
- sys.linux.Linux
- sys.linux.LinuxUnitaryComputerSystem
- sys.OperatingSystem
- sys.sun.Solaris
- sys.sun.SunSPARCUnitaryComputerSystem
- sys.tru64.Tru64
- sys.windows.WindowsComputerSystem
- sys.windows.WindowsOperatingSystem
- sys.zOS.ZOS
- sys.zOS.ZSeriesComputerSystem