NetBlade
Windows Step 12 of 12 ~30 min Intermediate

Everything under control: a daily, weekly and monthly routine for IT consultants

Run several client networks with NetBlade: one site per client, a setup checklist, daily, weekly and monthly routines, and a clean handover to the client.

The other articles each set up one part of NetBlade. This one turns them into a way of working: how to organise several clients, what to set up on day one, what to look at every day, every week and every month, and how to hand a network over cleanly. Read it once end to end, then keep it as your checklist. The goal is simple: at any moment, you can say what is on each client’s network, what is wrong with it, and what you are doing about it.

Before you start

  • NetBlade installed with an active subscription or trial, and the agent running (Get started).
  • A mail server set up in Settings, Mail servers and webhooks, and tested (Alerts).
  • Your report header set: logo, Who signs the reports, Contact (Reports).

1. Decide where NetBlade runs

NetBlade looks at the networks the PC it runs on is connected to. There is no server and no cloud, and each installation keeps its own database. That leaves two ways to cover several clients, and you should choose deliberately.

Your own laptop, visiting clients. Each network you scan while connected becomes a site. When you are on site, the agent rescans and reads that client on its schedule. When you leave, it stops scanning that network, but it keeps checking what it already knows against the vulnerability feed every day, and your reports and alerts keep working from your desk.

A PC at the client. A PC that stays on the client’s network (a small always-on workstation, for example) keeps scanning, reading and alerting every day, as long as someone is signed in to Windows on it. This is the choice for clients who want continuous monitoring.

Whichever you choose, keep these limits in mind:

  • The agent runs only while a user is signed in to Windows. Not before sign-in, not on a machine sitting at the login screen. A PC at a client must stay signed in, locked if you like, for the agent to work.
  • Sites are created only from the network the PC is connected to. A range scanned across a VPN or a router is scanned but not stored, because a site is recognised by its gateway and NetBlade cannot tell one 192.168.1.0/24 from another.
  • Scheduled scans and reads touch only the site the PC is on right now. A laptop in a hotel will never send your client’s credentials to whatever answers at the same address there.

2. Organise: one site per client

  • Rename every site with the client’s name, in Sites, Rename. If a client has several offices, each is its own site: “Rossi Srl - Milan”, “Rossi Srl - Turin”.
  • File credentials per site (Where it applies: One site), never Anywhere, so one client’s passwords are never tried at another’s (Credentials).
  • Use the asset fields. On a device’s card, Edit… sets a name and type that no scan overwrites, Tags, Notes, and Your own fields such as asset number, floor or contract. For many devices at once, Select, then Mass edit.
  • Save views for the questions you ask every week. In Devices, Advanced filter, combine conditions and Save as view…, for example “Servers without antivirus” or “Windows 10 PCs at Rossi”. They wait in the Views menu.

3. Set up a new client: the day-one checklist

Work through this in order the first time you are on a client’s network. Each line links to the article with the details.

  1. Scan the network: Network and discovery, Scan, This network (…). Rename the site. (Get started)
  2. Identify every device in Sites, then correct names and types where NetBlade guessed wrong. The Dashboard’s What is out there shows devices with no type: fix them with Mass edit.
  3. File a Windows credential for the site, test it on one pilot PC, and prepare the PCs, with the enable script where needed. Save the undo scripts. (Prepare your Windows PCs)
  4. Read every device in Sites. Check the result line: read, without a credential that applies, findings.
  5. File SNMP credentials for switches, printers and NAS, and SSH for Linux servers; read them. (SNMP, Linux)
  6. Read the network on the Map page. (Network map)
  7. Set the schedules in Sites: AUTO on, HOW OFTEN Every hour, and IN DEPTH Once a day (or Every week for a laptop that visits).
  8. Add Monitor targets for what must never be down: the internet gateway, the file server, the line-of-business server.
  9. Create alerts for the site: exploited vulnerabilities, defences switched off, watched targets down at once; new devices, ports and software changes in the daily summary. (Alerts)
  10. Schedule reports: «Summary for the owner» monthly to the owner, «Technical annex» and «Vulnerabilities» monthly to you. (Reports)
  11. Make a first baseline: generate «Summary for the owner» and «Compliance» today and keep them. In three months they are the “before” in your “before and after”.

4. What to look at first on a new network

A first read produces a long list. Take it in this order:

  1. Coverage. The Dashboard’s coverage line: how many devices were read in depth out of how many. Until most PCs are read, every other number is incomplete. Fix unreadable PCs first.
  2. Exploited vulnerabilities. Vulnerabilities, Exploited only, By update. These are being used in attacks right now.
  3. Out of support. Systems past their end of support on To fix. Nothing installed on top fixes them.
  4. Defences off. No antivirus, firewall off, UAC off, on To fix.
  5. Exposure. Remote Desktop reachable, Telnet, VNC, databases on the network, factory SNMP communities.
  6. Everything else, in the order To fix gives it.

5. Every day: five minutes

Open NetBlade on the Dashboard.

  • The agent chip next to the title should say «Agent running». If it says anything else, click it and fix that first: nothing else on the page is current without it.
  • The app itself: the last scheduled scan should be recent and the vulnerability feed younger than a week.
  • Worth doing first: anything new at the top? If something is being exploited, that is today’s job.
  • The last seven days: new devices, devices that stopped answering, defences switched off, machines that became unreadable. Each count opens its detail.
  • Your inbox: the alerts and the daily summaries from each site.

Tip: On a PC at a client, the daily look happens through your alerts and summaries. That is exactly why they must be few and meaningful.

6. Every week: about an hour per client

  1. Vulnerabilities. Press Check again, work through Exploited only, then the rest of By update; update, Deep scan, check again. The full routine is in Vulnerabilities, step 6.
  2. To fix. Configuration items: pending restarts, disks almost full, updates stopped for 60 days or more.
  3. New devices. In Devices, sort by First seen. Name, type and tag every newcomer; for anything you cannot explain, Identify it and find out.
  4. Gone and stale devices. The Dashboard’s What is out there shows devices not seen for a while. Retired equipment gets deleted (Select, Delete), so the inventory stays true.
  5. Unreadable machines. Any PC that became unreadable: password changed, firewall reset, or reinstalled. Fix before it drops out of your reports.
  6. Ports newly open and software changes. Each one should have an explanation.

7. Every month: the review

  1. Compliance. Press Check again. Work on the rule broken on most devices. (Compliance)
  2. Exceptions. Tick Show accepted on To fix and re-read every accepted entry with its reason in the device’s notes. Reopen what no longer holds.
  3. Credentials. In Credentials, Test each one you rely on. Rotate where the client’s policy says so, or where people have left.
  4. Reports. Check the scheduled sends went out (each shows «last sent»). Read the owner’s summary before the owner does.
  5. Support dates. Look for «Support ends soon» on To fix. An office where every PC goes out of support on the same day is a conversation in March and an emergency in October.
  6. Licences and hardware. Export «Software inventory» and «Hardware inventory» as CSV when the client renews licences or plans replacements.
  7. Map. Read the network again if anything was moved or added.

8. Hand over to the client

When a contract ends, or when you hand a network to someone else, leave it better documented than you found it.

  1. Refresh everything. Scan now, Read every device, Read the network, and Check again on Vulnerabilities and Compliance.
  2. Produce the handover pack with the client’s site as Scope and Last 90 days as Period:
    • «Summary for the owner», PDF;
    • «Technical annex» and «Vulnerabilities», PDF, for whoever takes over;
    • «Compliance», PDF, with its register of exceptions;
    • «Device inventory», «Software inventory» and «Hardware inventory», CSV;
    • «Changes in the period», PDF.
  3. Undo what you opened. Run the undo scripts on the PCs you prepared, so NetBlade’s firewall rules and remote access for local accounts are gone, and turn WinRM off with Disable-PSRemoting where the new administrator does not need it. (Prepare your Windows PCs, step 9)
  4. Stop the automation. Turn off the site’s scheduled sends and alerts, and AUTO and IN DEPTH in Sites.
  5. Remove the credentials filed for that site in Credentials. Then disable or change the accounts themselves on the client’s systems.
  6. Forget the site in Sites, if you no longer need its history. It removes the site, its devices, everything read from them and its timeline, after a confirmation.

Warning: Forget does not delete credentials: those filed for the site stay, with no site any more. Delete them explicitly (step 5), or they will sit in your credential list with nowhere to apply.

9. Keep yourself honest

The strength of NetBlade is that it says what it does not know. Keep that in how you work and what you tell clients:

  • A quiet week and a week nobody looked read the same. Check the agent’s last run before trusting silence.
  • A device nobody has read cannot report a problem. Coverage first, always.
  • A program outside the dictionary gets no verdict. Say so if asked “is everything patched?”.
  • It is a scan of what answered, not an audit, a certification or a penetration test. The reports say it; so should you.

Check that it worked

You have everything under control when, for each client, you can open NetBlade and within a minute answer:

  • How many devices, and how many read in depth?
  • What is being exploited right now, and on which machines?
  • What changed this week?
  • Which rules are broken, and which exceptions are on record, with a reason?
  • When did the owner last receive a report?

If something goes wrong

  • A client site stopped updating. Check where the NetBlade PC is: scheduled scans only run on the network it is connected to, and only while someone is signed in to Windows.
  • The agent chip says the agent is stopped. Without an active subscription the agent does not run; otherwise, check Settings, The agent and Task Manager’s Startup apps.
  • Reports went out late. The PC was off or signed out at send time; they go out when it is back.
  • Two clients use the same addresses. That is fine: each site is recognised by its gateway, not by its range.
  • Coverage keeps dropping at one client. Someone is changing passwords or firewall settings. Talk to them, and file the credential they give you for that site only.

Next

For the reference behind every button in these articles, see the NetBlade for Windows guide. To revisit the start, go back to Get started.

← All how-to guides Feature guide → The product: NetBlade Windows →