Asset Detection and Analysis
Asset inventories drift out of date. The devices that go missing are usually the ones that cannot run an agent: printers, cameras, badge readers, building systems, lab and factory equipment, contractor laptops. Nzyme builds its inventory from the traffic itself, so a device is in it the moment it speaks on your network.
An incomplete inventory is a blind spot: you cannot detect, contain, or investigate a compromise on a device you do not know exists. Unmanaged and unmonitored assets are routinely the entry point attackers use precisely because they sit outside the tools that would otherwise catch them.
Asset management and related pages in the Nzyme web interface.
Every host Nzyme sees becomes an asset with a full record of what it is and what it talks to. There is nothing to install on the devices and nothing to scan.
- A complete inventory, kept current. Every host that communicates on a monitored network is recorded, along with when it was first and last seen.
- Hostnames and addresses. Assets are enriched with the hostnames and the IP addresses Nzyme has observed them using, so a MAC address turns into something you can recognize.
- Fingerprints. Nzyme fingerprints hosts from their traffic, which helps identify what a device actually is rather than what it claims to be.
- Communication analysis. For any asset you can see exactly what it has been talking to, which is how you spot a device reaching somewhere it never should.
- Your own context. Add your own notes and identifying information to a host, and that context follows it everywhere it appears in Nzyme, so the next person does not have to work out what the device is all over again.