Skip to content
Back to skills

Services

ASecurity

runZero discovered services: listing services, filtering by port or protocol, identifying vulnerabilities, and auditing exposed services across sites.

  • 48 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 2, 2026
ai-agentsapidatabasesecurity

Works with

  • terminal
  • cli
  • api

Security analysis

A100/100

Scanned October 2, 2026

npx -y skills add wyre-technology/msp-claude-plugins --skill services --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Services?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Services
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/wyre-technology-services-69ed5825/badge)](https://www.skillsdirectory.com/skills/wyre-technology-services-69ed5825)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: "runZero Services"
description: >
  runZero discovered services: listing services, filtering by port or protocol,
  identifying vulnerabilities, and auditing exposed services across sites.
when_to_use: >-
  When reviewing discovered services, open ports, protocols, or service exposure across
  runZero sites. Use when: runzero service, discovered service, service inventory, open
  port, service protocol, service vulnerability, port scan, exposed service, or service
  audit.
---

# RunZero Services

## Overview

RunZero discovers services running on every asset -- open ports, protocols, software versions, and TLS configurations. Service data is critical for vulnerability assessment, compliance auditing, and attack surface management. This skill covers listing, filtering, and analyzing discovered services.

## Anti-triggers

- **CVE findings.** runZero reports what is listening and which version
  answered — it does not score or track vulnerabilities. Patch
  prioritisation is `sentinelone-vulnerabilities`; cloud posture is
  `sentinelone-misconfigurations`.
- **Firewall rules and port forwarding.** An open port here was observed
  from the explorer's vantage point; the rule that permits it is
  `meraki-security-appliance`.
- **The machine rather than the listener** — use `runzero-assets`.

## Key Concepts

### Service Attributes

Each discovered service includes:

| Attribute | Description |
|-----------|-------------|
| `port` | TCP/UDP port number |
| `protocol` | Application protocol (HTTP, SSH, RDP, etc.) |
| `transport` | Transport layer (TCP, UDP) |
| `summary` | Service banner or description |
| `software` | Detected software and version |
| `tls` | TLS/SSL configuration details |
| `asset_id` | The asset this service runs on |
| `first_seen` | When the service was first discovered |
| `last_seen` | When the service was last observed |

### Common Protocols

| Protocol | Default Port | Risk Considerations |
|----------|-------------|---------------------|
| `ssh` | 22 | Check for weak ciphers, old versions |
| `rdp` | 3389 | High-risk if exposed externally |
| `http` | 80 | Check for unencrypted admin panels |
| `https` | 443 | Verify TLS version and certificate |
| `smb` | 445 | Ransomware vector if exposed |
| `snmp` | 161 | Check for default community strings |
| `telnet` | 23 | Unencrypted; should be disabled |
| `ftp` | 21 | Unencrypted; check for anonymous access |

### Vulnerability Indicators

RunZero flags services with security concerns:

- Expired or self-signed TLS certificates
- Outdated software versions with known CVEs
- Insecure protocols (Telnet, FTP, SNMPv1)
- Default credentials detected
- Exposed management interfaces

## API Patterns

### List Services

```
runzero_services_list
```

Parameters:
- `site_id` -- Filter by site
- `search` -- RunZero query string
- `count` -- Results per page
- `offset` -- Pagination offset

**Example response:**

```json
{
  "services": [
    {
      "id": "svc-uuid-123",
      "asset_id": "asset-uuid-456",
      "port": 3389,
      "transport": "tcp",
      "protocol": "rdp",
      "summary": "Microsoft Terminal Services",
      "software": "Windows RDP 10.0",
      "first_seen": "2026-01-15T10:00:00Z",
      "last_seen": "2026-03-27T08:30:00Z"
    }
  ]
}
```

### Get Service Details

```
runzero_services_get
```

Parameters:
- `service_id` -- The specific service UUID

### Export Services

```
runzero_services_export
```

Parameters:
- `search` -- RunZero query to filter services
- `site_id` -- Filter by site

Use for bulk service data retrieval.

### Service Query Examples

```
protocol:rdp AND alive:true
port:445 AND NOT address:10.0.0.0/8
protocol:ssh AND software:OpenSSH AND software:<8
protocol:telnet
port:443 AND tls.version:TLSv1.0
```

## Common Workflows

### Exposed Service Audit

1. Search for high-risk services: `protocol:rdp OR protocol:telnet OR protocol:ftp`
2. Filter to externally-facing assets if possible
3. Flag services that should not be exposed
4. Generate remediation recommendations

### TLS Certificate Audit

1. Search for HTTPS services: `protocol:https`
2. Check for expired certificates, weak TLS versions
3. Identify self-signed certificates
4. Generate certificate expiry report

### Port Scan Summary

1. Export all services for a site
2. Aggregate by port and protocol
3. Count unique assets per service type
4. Identify unexpected or unauthorized services

### Vulnerability Surface Analysis

1. Search for services with known vulnerable software versions
2. Cross-reference with CVE databases
3. Prioritize by severity and exposure
4. Generate actionable remediation report

### SMB/RDP Exposure Check

1. Search: `protocol:rdp OR protocol:smb`
2. Identify assets exposing these services
3. Check if any are externally reachable
4. Recommend firewall rules or VPN-only access

## Error Handling

### Service Not Found

**Cause:** Invalid service UUID or service no longer detected
**Solution:** Search by port/protocol on the asset instead

### Large Result Sets

**Cause:** Broad queries returning thousands of services
**Solution:** Add site or protocol filters; use the Export API

## Best Practices

- Use the Export API for service inventories across large environments
- Focus security audits on high-risk protocols (RDP, SMB, Telnet, FTP)
- Monitor for new services appearing between scans
- Track TLS certificate expiry dates proactively
- Cross-reference discovered services with firewall rules
- Generate per-client service reports for security reviews

## Related Skills

- [api-patterns](../api-patterns/SKILL.md) - Query language and pagination
- [assets](../assets/SKILL.md) - Assets running the services
- [sites](../sites/SKILL.md) - Sites containing the services
- [tasks](../tasks/SKILL.md) - Scans that discover services

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…