Skip to content

8. Software Inventory and the Software List

The Software page has two tabs that work together. Software is what your scans actually found installed. Software List is your own record of what is supposed to be there. NESSviewer keeps count of the differences and offers them to you for review — it never changes your list on its own.

One row per host per product, built from three sources in your scans: Windows and Unix package enumeration, application identifiers attached to plugin results, and the scanner’s own per-host software inventory. Product names are cleaned up as they are read, so vendor and date fragments do not end up in the name.

Column What it shows
Host IP The machine the software was found on.
Hostname Its name.
Host Description Its description, where one is available.
OS Its operating system.
PluginID Which plugin reported it. Blank where it came from the scanner’s host inventory rather than a plugin.
Software The product or package name.
Date Installed The install date, where the scan reported one.
Version The version. Best effort — some sources do not carry one, so this can be blank.

The switch labelled Aggregate by software name collapses the grid to one row per product across the whole estate:

Column What it shows
Software The product name.
Version Every distinct version seen, separated by semicolons — the quickest way to spot machines left behind on an old build.
Plugin IDs The plugins that identified it.
Host Count How many machines have it.
Hostnames / Host IPs Which machines.
Operating Systems The operating systems those machines run.
Date Installed The distinct install dates seen.

Clicking a row opens a panel headed with the software name, showing the plugin behind the detection: Plugin Name, Description, Plugin ID, Exploit Framework, Synopsis, CPE, Publication Date and Plugin Output. These are read-only.

This is your own list. It can live in one of two places, and you choose which with the Use Baseline switch.

Control What it does
New Creates a new list. You choose where to save it; software-list.json is suggested. Tooltip: Create a new list (choose where to save it; edits auto-save).
Load… Opens an existing list file.
The dropdown beside it Your recently used list files, up to ten. It also shows which file is currently open.
Auto-load on startup Loads your most recent list automatically each time NESSviewer starts.
Use Baseline Sources the list from the baseline open under Files → Baseline instead of from a file, and saves edits back into the baseline. Tooltip: Source this list from the baseline open in Files > Baseline — edits here save into the baseline. Off = the JSON file above.

While Use Baseline is on, the file controls are greyed out — the baseline is the list. If you turn it on with no baseline open, a dialog appears titled No Baseline Open reading Open or create a baseline in Files > Baseline first.

There is no Save button. Every change — a tick, a field edit, a bulk update, an added or deleted row — saves itself about three-quarters of a second after you stop. Batch operations save once for the whole batch.

8.3 Reconciling your list against the scans

Section titled “8.3 Reconciling your list against the scans”

NESSviewer continuously compares your list to what the scans enumerated, matching on the `Enumerated Name` — the name exactly as the scan reported it. That is why that field is locked on rows that came from a scan: it is the key the comparison depends on.

Two amber flags appear above the grid when there is something to look at. Clicking either opens the review dialog, as do the Add Items and Remove Items buttons.

Flag Meaning
⚠ {n} scanned item(s) not on the list — Add The scans found software your list does not mention. New software appeared, or your list is behind.
⚠ {n} list item(s) not in the loaded scans — Remove Your list has scan-identified items the current scans no longer see. Software was removed, or a host was not scanned this time.

Both buttons open the same dialog, titled Add Software or Remove Software, with a subtitle stating what it found — for example 14 scanned item(s) are not on the list. Check the ones to add.

It lists every candidate with a checkbox, the name, and the version on the right. Everything starts ticked. Select All and Select None are at the top with a live counter reading {n} of {total} selected, and the confirm button carries the count: Apply (14). Cancel closes without changing anything.

Applying adds the ticked items to your list with today’s date and From Scan ticked, or — for removals — stamps today’s date into Date Removed while keeping the row.

Column What it holds
Enumerated Name The name exactly as the scan reported it. This is the matching key, and it is locked on scan-identified rows.
Software Name The friendly name for your deliverables. Defaults to the enumerated name; edit it freely.
Version The version.
On List A tick you control: this item belongs on the official software list. Untick for things you are merely accounting for, such as bundled components.
From Scan Read-only. Ticked when the entry came from a scan rather than from you.
Software Type eMASS software type — COTS, GOTS, Open Source and so on.
Software Vendor The vendor.
Approval Status Where it stands in your approval process.
End of Life/Support Date When vendor support ends.
Critical? The eMASS “Critical Information System Asset?” flag.
Location Where it runs — site, enclave, region.
Purpose What it is for. This is the eMASS Purpose field.
Date Added / Date Removed When the entry was added, and when it was marked removed. Date Removed stays blank while the entry is active.

Click a row to open the editor panel, headed Edit Software. The fields follow the columns above, with a few notes:

  • Enumerated Name (key) carries the sub-label The name from the scan, used as the matching key. Editable only for manually added items.

  • On software list is a switch with the sub-label Counts toward the curated software list.

  • Critical? is a switch with the sub-label eMASS “Critical Information System Asset?”.

  • Software Type, Software Vendor, Approval Status and Location are combo boxes: they suggest common values and whatever you have already used elsewhere in the list, but you can type anything.

At the bottom are three buttons:

Button What it does
Mark Removed Stamps today’s date into Date Removed and keeps the row, preserving the history.
Restore Clears Date Removed, making the entry active again.
Delete from list Removes the row completely. There is no confirmation and no undo.

Add Row (tooltip Add a blank entry to edit manually) appends a blank entry dated today and opens the editor. Manual entries have From Scan unticked and are never offered for removal.

Tick the checkboxes on several rows, then use the toolbar’s Update or Remove.

`Update` opens a dialog titled Update Software with the subtitle {n} selected. It offers On Software List, Software Type, Software Vendor, Approval Status, End of Life, Critical?, Location and Purpose. Only the fields you choose to set are written to the selected rows, so you can set a vendor on forty entries without disturbing anything else. Afterwards the status reads Updated {n} item(s).

`Remove` deletes the selected rows permanently. It asks first, with a dialog titled Remove Items:

Delete {n} item(s) from the list? This cannot be undone — use Mark Removed in the drawer to keep them with a removal date instead.

The buttons are Delete and Cancel.

Your list is stored as a plain, readable JSON file wherever you chose to put it — or inside the baseline document if Use Baseline is on. It is not hidden in application data, so it can go in version control or on a shared drive with the rest of your documentation.

The file names, recent-file lists, Auto-load on startup and Use Baseline settings are remembered between sessions. Whether the Software tab is aggregated is not — that resets each time you start.