The InsightVM console contains vulnerability data for all of your assets, and access to the console will be managed centrally. If you would like to add an administrator to your site, please send an email to security@uchicago.edu with the following information:
You should become familiar with the terminology used in the InsightVM Security Console before learning to operate it. The two most common terms used are "Site" and "Asset." A brief definition of both terms is found below:
Site: A site is a collection of assets that are targeted for a scan. You must create a site in order to run a scan of your environment and find vulnerabilities. A site consists of:
Note: IT Security will facilitate the creation of sites, but you will have full autonomy over the site that is created for you.
Asset: An asset is a single device on a network that the application discovers during a scan. In order to perform a scan on a site, you must assign assets to it.
The InsightVM Security Console web interface (https://vulnscan.uchicago.edu) supports the following browsers:
Visit InsightVM Security Console with a modern browser such as Chrome, Edge, Firefox, or Safari.
Log in with your CNetID and password. If you are unable to log in, you likely need to be granted access to the site; please see the section on Request Access for New Administrators.
After your first successful scan, you can begin to assess your environment for high-risk assets, vulnerabilities, or policy violations. The IT Security team can introduce you to operating at the console and assist as you review and assess your first scan results.
You can view the assets that you have access to by selecting the Assets icon and viewing the Assets table on the Assets page. Your assets can be sorted in many ways, total vulnerabilities, exploitable vulnerabilities, last scans, operating system, and more.
See the Assess section of the InsightVM help site for more extensive documentation on assessing vulnerabilities.