8. Software Inventory and the Software List
The Software page has two tabs that work together. Software is what your scans actually found installed. Software List is your own record of what is supposed to be there. NESSviewer keeps count of the differences and offers them to you for review — it never changes your list on its own.
8.1 The Software tab
Section titled “8.1 The Software tab”One row per host per product, built from three sources in your scans: Windows and Unix package enumeration, application identifiers attached to plugin results, and the scanner’s own per-host software inventory. Product names are cleaned up as they are read, so vendor and date fragments do not end up in the name.
| Column | What it shows |
|---|---|
| Host IP | The machine the software was found on. |
| Hostname | Its name. |
| Host Description | Its description, where one is available. |
| OS | Its operating system. |
| PluginID | Which plugin reported it. Blank where it came from the scanner’s host inventory rather than a plugin. |
| Software | The product or package name. |
| Date Installed | The install date, where the scan reported one. |
| Version | The version. Best effort — some sources do not carry one, so this can be blank. |
Aggregate by software name
Section titled “Aggregate by software name”The switch labelled Aggregate by software name collapses the grid to one row per product across the whole estate:
| Column | What it shows |
|---|---|
| Software | The product name. |
| Version | Every distinct version seen, separated by semicolons — the quickest way to spot machines left behind on an old build. |
| Plugin IDs | The plugins that identified it. |
| Host Count | How many machines have it. |
| Hostnames / Host IPs | Which machines. |
| Operating Systems | The operating systems those machines run. |
| Date Installed | The distinct install dates seen. |
The details panel
Section titled “The details panel”Clicking a row opens a panel headed with the software name, showing the plugin behind the detection: Plugin Name, Description, Plugin ID, Exploit Framework, Synopsis, CPE, Publication Date and Plugin Output. These are read-only.
8.2 The Software List tab
Section titled “8.2 The Software List tab”This is your own list. It can live in one of two places, and you choose which with the Use Baseline switch.
| Control | What it does |
|---|---|
| New | Creates a new list. You choose where to save it; software-list.json is suggested. Tooltip: Create a new list (choose where to save it; edits auto-save). |
| Load… | Opens an existing list file. |
| The dropdown beside it | Your recently used list files, up to ten. It also shows which file is currently open. |
| Auto-load on startup | Loads your most recent list automatically each time NESSviewer starts. |
| Use Baseline | Sources the list from the baseline open under Files → Baseline instead of from a file, and saves edits back into the baseline. Tooltip: Source this list from the baseline open in Files > Baseline — edits here save into the baseline. Off = the JSON file above. |
While Use Baseline is on, the file controls are greyed out — the baseline is the list. If you turn it on with no baseline open, a dialog appears titled No Baseline Open reading Open or create a baseline in Files > Baseline first.
Saving
Section titled “Saving”There is no Save button. Every change — a tick, a field edit, a bulk update, an added or deleted row — saves itself about three-quarters of a second after you stop. Batch operations save once for the whole batch.
8.3 Reconciling your list against the scans
Section titled “8.3 Reconciling your list against the scans”NESSviewer continuously compares your list to what the scans enumerated, matching on the `Enumerated Name` — the name exactly as the scan reported it. That is why that field is locked on rows that came from a scan: it is the key the comparison depends on.
Two amber flags appear above the grid when there is something to look at. Clicking either opens the review dialog, as do the Add Items and Remove Items buttons.
| Flag | Meaning |
|---|---|
| ⚠ {n} scanned item(s) not on the list — Add | The scans found software your list does not mention. New software appeared, or your list is behind. |
| ⚠ {n} list item(s) not in the loaded scans — Remove | Your list has scan-identified items the current scans no longer see. Software was removed, or a host was not scanned this time. |
The review dialog
Section titled “The review dialog”Both buttons open the same dialog, titled Add Software or Remove Software, with a subtitle stating what it found — for example 14 scanned item(s) are not on the list. Check the ones to add.
It lists every candidate with a checkbox, the name, and the version on the right. Everything starts ticked. Select All and Select None are at the top with a live counter reading {n} of {total} selected, and the confirm button carries the count: Apply (14). Cancel closes without changing anything.
Applying adds the ticked items to your list with today’s date and From Scan ticked, or — for removals — stamps today’s date into Date Removed while keeping the row.
8.4 The list columns and the editor
Section titled “8.4 The list columns and the editor”| Column | What it holds |
|---|---|
| Enumerated Name | The name exactly as the scan reported it. This is the matching key, and it is locked on scan-identified rows. |
| Software Name | The friendly name for your deliverables. Defaults to the enumerated name; edit it freely. |
| Version | The version. |
| On List | A tick you control: this item belongs on the official software list. Untick for things you are merely accounting for, such as bundled components. |
| From Scan | Read-only. Ticked when the entry came from a scan rather than from you. |
| Software Type | eMASS software type — COTS, GOTS, Open Source and so on. |
| Software Vendor | The vendor. |
| Approval Status | Where it stands in your approval process. |
| End of Life/Support Date | When vendor support ends. |
| Critical? | The eMASS “Critical Information System Asset?” flag. |
| Location | Where it runs — site, enclave, region. |
| Purpose | What it is for. This is the eMASS Purpose field. |
| Date Added / Date Removed | When the entry was added, and when it was marked removed. Date Removed stays blank while the entry is active. |
Editing one entry
Section titled “Editing one entry”Click a row to open the editor panel, headed Edit Software. The fields follow the columns above, with a few notes:
-
Enumerated Name (key) carries the sub-label The name from the scan, used as the matching key. Editable only for manually added items.
-
On software list is a switch with the sub-label Counts toward the curated software list.
-
Critical? is a switch with the sub-label eMASS “Critical Information System Asset?”.
-
Software Type, Software Vendor, Approval Status and Location are combo boxes: they suggest common values and whatever you have already used elsewhere in the list, but you can type anything.
At the bottom are three buttons:
| Button | What it does |
|---|---|
| Mark Removed | Stamps today’s date into Date Removed and keeps the row, preserving the history. |
| Restore | Clears Date Removed, making the entry active again. |
| Delete from list | Removes the row completely. There is no confirmation and no undo. |
Adding an entry by hand
Section titled “Adding an entry by hand”Add Row (tooltip Add a blank entry to edit manually) appends a blank entry dated today and opens the editor. Manual entries have From Scan unticked and are never offered for removal.
8.5 Changing many entries at once
Section titled “8.5 Changing many entries at once”Tick the checkboxes on several rows, then use the toolbar’s Update or Remove.
`Update` opens a dialog titled Update Software with the subtitle {n} selected. It offers On Software List, Software Type, Software Vendor, Approval Status, End of Life, Critical?, Location and Purpose. Only the fields you choose to set are written to the selected rows, so you can set a vendor on forty entries without disturbing anything else. Afterwards the status reads Updated {n} item(s).
`Remove` deletes the selected rows permanently. It asks first, with a dialog titled Remove Items:
Delete {n} item(s) from the list? This cannot be undone — use Mark Removed in the drawer to keep them with a removal date instead.
The buttons are Delete and Cancel.
8.6 Where your list lives
Section titled “8.6 Where your list lives”Your list is stored as a plain, readable JSON file wherever you chose to put it — or inside the baseline document if Use Baseline is on. It is not hidden in application data, so it can go in version control or on a shared drive with the rest of your documentation.
The file names, recent-file lists, Auto-load on startup and Use Baseline settings are remembered between sessions. Whether the Software tab is aggregated is not — that resets each time you start.