> ## Documentation Index
> Fetch the complete documentation index at: https://docs.levelblue.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Running Asset Scans

|                       |               |                  |             |             |
| --------------------- | ------------- | ---------------- | ----------- | ----------- |
| **Role Availability** | **Read-Only** | **Investigator** | **Analyst** | **Manager** |

Use an asset scan to discover hosts and services in the deployed network. To accomplish this goal, the scanner sends crafted packets to the target asset and analyzes the responses. This is not an authenticated scan. You can run scans on individual assets.

<Warning>
  **Important**: This option is available if the sensor associated with the asset allows it.
</Warning>

The asset for which you are scanning must be visible by the sensor through the network. This means that both the sensor and the asset should be able to see each other through at least Layer 3 (network) protocols. If the sensor and the asset are in the same network segment (Layer 2), use Address Resolution Protocol (ARP) requests to discover the asset.

The USM Anywhere Sensor sends ARP, Internet Control Message Protocol (ICMP), and TCP requests to discover hosts on the network to which the sensor is connected. A new asset is created if the sensor receives an acknowledgment from any of the previously mentioned protocols.

<Note>
  **Note**: If a scan is suspended or otherwise running for more than two hours, it will time out. You can see the timeout result in the asset's Scan History, as well as in the system event generated for that scan.
</Note>

<Warning>
  **Important**:  You cannot scan USM Anywhere Sensors.
</Warning>

## Enabling the Asset Scanner App

**To enable the Asset Scanner App**

1. Go to **Data Sources > Sensors** to open the Sensors page.

2. Click the USM Anywhere Sensor for which you want to enable the asset scanner app.

3. Click the **Asset Scanner** tab.

   <Note>
     **Note**: This item is not available on Amazon Web Services (AWS) sensors.
   </Note>

4. Click **Enable**.

   <Frame>
     <img src="https://mintcdn.com/levelblue-5324744e/fC92IJE7ax567GE5/images/usm-anywhere/user-guide/enableassetscanner_thumb_0_60.webp?fit=max&auto=format&n=fC92IJE7ax567GE5&q=85&s=ea10529d8a85f01ba9edfcd42c1f74a7" alt="" width="318" height="60" data-path="images/usm-anywhere/user-guide/enableassetscanner_thumb_0_60.webp" />
   </Frame>

## Running Asset Scans from Assets

**To run an asset scan from Assets**

1. Go to **Environment > Assets**.

2. Complete one of these options to open the Scan Asset dialog box:

   * Next to the asset name that you want to scan, click the <img src="https://mintcdn.com/levelblue-5324744e/jo1779yzvGjLisJx/images/usm-anywhere/chevron-down.svg?fit=max&auto=format&n=jo1779yzvGjLisJx&q=85&s=49cdbebf7934499f2df552d32ed9aa74" className="inline" width="20" height="20" data-path="images/usm-anywhere/chevron-down.svg" /> icon, select **Full Details**, and then select **Actions > Asset Scan**.
   * Next to the asset name that you want to scan, click the <img src="https://mintcdn.com/levelblue-5324744e/jo1779yzvGjLisJx/images/usm-anywhere/chevron-down.svg?fit=max&auto=format&n=jo1779yzvGjLisJx&q=85&s=49cdbebf7934499f2df552d32ed9aa74" className="inline" width="20" height="20" data-path="images/usm-anywhere/chevron-down.svg" /> icon, and then select **Asset Scan**.

   The Asset Scan dialog box opens.

   <Frame>
     <img src="https://mintcdn.com/levelblue-5324744e/LRsr4s1iGr_CM6ff/images/usm-anywhere/user-guide/scanasset.webp?fit=max&auto=format&n=LRsr4s1iGr_CM6ff&q=85&s=c9e7c4fc28d838f00f6f927603fd6c00" alt="" width="484" height="530" data-path="images/usm-anywhere/user-guide/scanasset.webp" />
   </Frame>

3. Select the scan profile that you want to run:

   * **Discovery**: This profile scans the known ports and services searching for the most-used ports. (There are 4571 ports.)
   * **Complete**: This profile scans all TCP and UDP ports to find the possible ports in a deployment. (There are 65535 ports.)
   * **Vulnerability Discovery**: Performs general network discovery and checks for specific known vulnerabilities. It only reports results if they are found.
   * **Extended Vulnerability Discovery**: Performs a Vulnerability Discovery scan, which actively discovers more about the network.
   * **Intensive Vulnerability Discovery**: Performs several tasks to discover vulnerabilities, which uses a significant number of resources on the targeted machine. Because of this, sensitive targets may perceive a brief disruption on their services.

4. Select **Set Debug Mode** if you want to log the results of the scan or if you have a problem with a scan.

   This option is disabled by default.

   <Note>
     **Note**: The Set Debug Mode option must be used only for debugging purposes because it needs a large amount of disk space for the file or files that it generates. Only LevelBlue Technical Support should review these files. You can contact this department for more information.
   </Note>

5. Click **Scan**.

6. In the Asset details page, click **Scan History** in the table area to display the results of the scan.

   You can see the status of each scan and the details. USM Anywhere also creates a system event named Asset Scanner Result with the same details.

<Info>
  **Important**: Make sure the Asset Scanner app is enabled. See Enabling the Asset Scanner App for more information.
</Info>

<Note>
  **Note**: See [Scheduling Asset Scans from Assets](/documentation/usm-anywhere/user-guide/asset-management/asset-administration/scheduling-asset-scans) and \[Scheduling Asset Scans from the Job Scheduler Page]
  (/documentation/usm-anywhere/user-guide/scheduler/scheduling-asset-scans-from-scheduler) for more information about how to schedule an asset scan.
</Note>

## Running Asset Scans When Creating a New Asset

**To run an asset scan when you are creating a new asset**

1. Go to **Environment > Assets**.

2. Select **Actions > Advanced** to open the Create New Asset dialog box.

   See [Adding Assets in the UI](/documentation/usm-anywhere/user-guide/asset-management/asset-administration/adding-assets.htm#Adding2) for more information.

3. The Scan the newly added asset for asset details field is selected by default. Use it for scanning the newly added asset.

   <Info>
     **Important**: The Asset Scan options are available only for the VMware Sensor and Hyper-V Sensor. USM Anywhere uses the Discovery profile to conduct the scans.
   </Info>

   <Frame>
     <img src="https://mintcdn.com/levelblue-5324744e/-bY1Wo2ZbXoIM88S/images/usm-anywhere/user-guide/createassetscannewly_thumb_0_60.webp?fit=max&auto=format&n=-bY1Wo2ZbXoIM88S&q=85&s=469e58314dc641098160ae3057a91b69" alt="" width="38" height="60" data-path="images/usm-anywhere/user-guide/createassetscannewly_thumb_0_60.webp" />
   </Frame>

4. Click **Save**.

   A message displays at the top of the page to inform you that the scan has been launched and is running. When the scan is complete, the results are visible in the tab **Scan History** of the asset details page. See [Viewing Assets Details](/documentation/usm-anywhere/user-guide/asset-management/asset-administration/viewing-asset-details) for more information.
