Skip to main content

SBOM

SBOM (software bill of materials) is the fleet-wide list of software discovered across all your endpoints- one row per software/version, with where it's installed, its support dates, and its known vulnerabilities. (The single-endpoint version is the SBOM tab on a machine's page.)

How to get here

You need View Inventory permission.

  1. In the left sidebar, click Inventory to expand it, then click SBOM.

Navigate to: Inventory → SBOM

URL path: /inventory/softwares- the URL slug is softwares, even though the menu item and page both read SBOM.

The SBOM screen

The SBOM software list with the filter pane and the software tableThe SBOM software list with the filter pane and the software table

A filter pane on the left (platform / location / department, shared with the rest of Inventory) narrows the list; the table fills the right.

ColumnWhat it shows
(icon)A warning icon for prohibited software, and a colour-coded vulnerability dot (factoring CVE count and end-of-life).
IDInternal software ID.
NameSoftware name.
VersionInstalled version.
PublisherVendor / author.
Release DateWhen this version shipped.
EOSEnd-of-support date.
EOLEnd-of-life date.
VulnerabilityCVE count- a clickable link (licensed editions).
EndpointsHow many machines have it- a clickable count.

Use Search and the filter pane to narrow the list.

Drill-downs

Vulnerabilities for a software

Click a row's Vulnerability count to open a drawer detailing that software's known CVEs.

The software vulnerability drawerThe software vulnerability drawer

Where a software is installed

Click a row's Endpoints count to open the assets drawer- the machines that have it:

The endpoints drawer for a software, listing the machines that have itThe endpoints drawer for a software, listing the machines that have it
ColumnWhat it shows
Host NameThe machine (links to its endpoint detail).
Platform VersionThe machine's OS version.

Tips & troubleshooting

  • A row has a red dot or warning icon. It's vulnerable, past end-of-life, or marked prohibited- open the Vulnerability count to see the CVEs.
  • The Vulnerability column is missing. It requires the patch/vulnerability licensed edition.