> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes.md).

# Asset classes

The asset inventory organizes your organization's resources into a hierarchy:

1. **Class:** The highest-level grouping based on general purpose or domain, such as compute, network, or data.
2. **Category:** A detailed grouping within a class based on normalized function, such as virtual machine, container, or bucket).
3. **Type:** The most specific, provider-level implementation, such as AWS EC2 instance or GCP Compute Engine instance.

The following asset classes are available in the inventory:

| Asset class       | Description                                                                                                                                                                | License                                                                                                                                                                                                                                                            |
| ----------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| AI                | Provides a detailed view of AI-related assets, their attributes, and associated risks.                                                                                     | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>This feature is included with a Cloud Posture Security or Cloud Runtime Security add-on.</p></div>                                             |
| API               | Provides a comprehensive view of Application Programming Interfaces (APIs) across your cloud platforms.                                                                    | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>This feature is included with a Cloud Runtime Security add-on.</p></div>                                                                       |
| Application       | Provides a high-level summary and detailed insights into the business applications within your environment.                                                                | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>This feature is included with a Cloud Posture Security or Cloud Runtime Security add-on.</p></div>                                             |
| Code              | Provides an overview of code assets, including all code repositories, Infrastructure as Code (IaC) resources, CI/CD pipelines, and software packages.                      | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>This feature is included with the AppSec add-on.</p></div>                                                                                     |
| Compute           | Provides a detailed overview of compute resources, including CaaS resources, virtual machines, containers, serverless functions, Kubernetes clusters, and general devices. |                                                                                                                                                                                                                                                                    |
| Data              | Provides an overview of data assets and their associated risks, highlighting sensitive assets and assets marked as open to the world.                                      | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>This feature is included with a Cloud Posture Security or Cloud Runtime Security add-on.</p></div>                                             |
| Device            | Overview of physical or virtual devices with a Cortex XDR agent installed.                                                                                                 |                                                                                                                                                                                                                                                                    |
| External Surface  | Provides an overview of external-facing assets, including services versus websites, domains versus certificates, and their distribution across providers.                  | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>This feature is included with the Attack Surface Management (ASM) add-on.</p></div>                                                            |
| Identity          | Provides an overview of identity-related assets, giving visibility into both user and service-based identities and their associated permissions.                           | <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Notice</strong></p><p>This feature is included with a Cloud Posture Security or Cloud Runtime Security add-on or the Identity Threat Module (ITDR) add-on.</p></div> |
| Network           | Provides an overview of network-related assets, including Load Balancers, Network Interfaces, Security Groups, and Subnets.                                                |                                                                                                                                                                                                                                                                    |
| Security Services | A complete overview of the security services being actively managed within your environment.                                                                               |                                                                                                                                                                                                                                                                    |
| All Other Assets  | All assets that are uncategorized.                                                                                                                                         |                                                                                                                                                                                                                                                                    |

**VM images assets**

Cortex VM image scanning is an agentless scanning feature that enables you to inspect the risks and vulnerabilities of a cloud workload without installing an agent or affecting the execution of your workload.

Agentless scanning of VM images is automatically enabled upon onboarding a cloud account to Cortex Cloud. Disabling this feature prevents VM images on your account from being scanned for vulnerabilities and risks, reducing your account's overall security coverage.

Cortex Agentless scanning includes private virtual machine images across the following major cloud platforms:

* **Amazon Web Services (AWS):** Cortex exclusively scans private Amazon Machine Images (AMIs).
* **Microsoft Azure:** Scanning is limited to private gallery versioned Images.
* **Google Cloud Platform (GCP):** Cortex Cloud supports scanning of private VM images.

After you onboard your cloud account, it is continuously scanned regardless of how many workloads are under that account. Whether you add or remove hosts and containers, agentless scanning keeps your workload’s security issues visible.

**VM images assets inventory**

To access VM images assets, go to **Inventory**, select **All Assets** → **Compute** → **VM Images**.

The VM images assets page includes a dashboard and an inventory table.

VM images asset table

The following table describes the default exposed properties of the VM images asset table. Select the column picker to view additional properties.

| Column           | Description                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                  |
| ---------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| Provider         | Cloud Account Provider                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                       |
| Name             | Name of the VM image                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Region           | Geographical location within a cloud provider's infrastructure where that VM image is located                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                |
| Architecture     | Architecture of the VM image. For example: x86\_64                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Image OS         | The OS distribution version. For example: 2020 or 20                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| OS Distribution  | Operating System distribution details                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                        |
| Operating System | Operating System on the VM image                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                             |
| OS version       | Version of the operating system                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                              |
| Tags             | User-defined label to correlate VM images and Instances                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                      |
| Size             | Size of the VM image                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                         |
| Created At       | The time when the VM Image was created in the Cloud provider                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                 |
| First Observed   | The first scan time of the VM image                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                          |
| Last Observed    | The last scan time of the VM image                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                                           |
| Scanners         | <p>List of scanners that have successfully scanned the Core Image asset. As the core image can be scanned by multiple scanners, the values are stored as a concatenated string of all scanner types. If no scanner data exists for an asset in the database, the default value is an empty array. This column is hidden from the default view.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The data in the Scanners column is accurate only for Core Image assets. Ignore the Scanners value for assets categorized as Registry, Build, or Runtime images, as it may not reflect an accurate scan status.</p></div> |
| Last Scan        | <p>The Last Scan time reflects the most recent scan across all scanners for a Core Image. If no scan data is available in the database for the core image, the default value is 0. This column is hidden from the default view.</p><div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><p><strong>Note</strong></p><p>The Last Scan value is only accurate for Core Image assets; ignore the Last Scan values for Registry, Build, and Runtime images, as they may be incorrect.</p></div>                                                                                                                                                                    |

**VM images asset details**

The VM image asset card provides a unified view of a VM image, consolidating VM details and related configuration issues and vulnerabilities found during VM image scanning.

Ask the AppSec agentic assistant agent

From the **VM Images** table, right-click a VM image > **Open in Agentic Assistant** > select **Application Security** from the agents menu, and query VM image specific insights. This action is also available from the VM image side panel.

Asset card tabs

* **Overview tab:** Displays a high-level summary of the VM image including OS details, findings, cases, VM scan information, and the relationship graph between the VM instance and the VM image.

  <div data-gb-custom-block data-tag="hint" data-style="info" class="hint hint-info"><h3>Note</h3><p>If the VM image is not used to create any VM instance, the graph section will show no results. This feature enables you to precisely identify the registry and repository source of any running image, directly linking runtime security findings to their origin. As a result, you can answer audit and security questions, such as determining which registry images are currently deployed in runtime.</p></div>
* **Configurations tab:** Lists all the cloud configuration issues seen during the VM image scanning. The **Asset Configuration JSON** section provides details of the VM image in JSON format.
* **Vulnerabilities tab:** Lists the vulnerability findings during VM image scans as well as the packages with related vulnerabilities found during VM image scans.

**Identity assets**

Powered by the Cortex Cloud Identity Security module, the Identity Asset Inventory helps you discover your entire cloud identity estate. It analyzes your environment to determine exactly what actions identities can take and which resources they can access, providing the context needed to trigger security detection rules.

**Identity categories**

The identity inventory is organized into the following categories:

* **All Identity Assets:** Provides a view of all identity-related assets
* **Human Identities:** All cloud, identity provider (IdP), and platform users.
* **Machine Identities:** Non-human identities that can assume permissions and perform cloud Identity and Access Management (IAM) actions, such as VMs and functions.
* **Managed Vaults:** Tracks secure storage environments for credentials and keys.
* **Secrets**: Provides an inventory of credentials to help identify active or dormant secrets and review their replication and compliance
* **External Identity Providers:** Tracks third-party identity services integrated with your environment.
* **Cloud Service Accounts:** A category unifying AWS roles, Microsoft Azure service accounts and managed Identities, and Google Cloud Platform (GCP) service accounts.
* **IAM Group** Tracks Identity and Access Management groups.
* **IAM Policies:** Tracks permission documents, such as AWS policies, Azure roles, and Google Cloud Platform roles

**Expanded identity details**

Clicking an identity asset in the inventory opens a detailed asset card that provides deep contextual analysis. Because managing identity security requires understanding how assets interact with one another, the information available on these cards helps map the complex web of relationships and permissions within your environment.

While the specific layout changes depending on whether you are viewing a human identity, a machine identity, or a secret, the asset details generally provide an aggregated view of the permissions associated with the asset. By exploring the identity details, you can understand exactly how an identity is granted its permissions by viewing the groups it belongs to, the cloud service accounts it can impersonate, and any policy attachments or inline policies. You can also review an identity's specific access levels to destination assets, which highlights unused permissions, excessive permissions, and the account access type

**Effective permission calculation**

Cortex XDR dynamically calculates exactly what actions an identity can take and which resources it can access, analyzing the complex web of relationships and nested groups to track effective usage across the environment.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-xdr-5.x/detect-investigate-and-respond-to-threats/asset-management/asset-classes.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
