Asset Filters

Prev Next

Overview

Asset Filters allow you to focus Nucleus on a specific portion of your environment without changing or removing the underlying data.

When an asset filter is applied, supported dashboards, findings views, trends, and other analysis pages display data associated only with assets that match the filter. This allows you to move from an enterprise-wide view to a specific business unit, application, team, environment, or risk category.

Use Asset Filters to answer questions such as:

  • What are the highest-risk vulnerabilities affecting production?

  • Which exploitable vulnerabilities exist on internet-facing assets?

  • How is a particular business unit performing against its SLAs?

  • Which findings belong to assets owned by the Cloud team?

  • How does risk differ between critical and non-critical assets?

  • Which vulnerabilities affect assets within a particular compliance scope?

Asset Filters are available from the global header, next to the project selector, so you can maintain the same scope as you navigate between supported areas of Nucleus.

Asset Filters and Project Scope

Asset Filters operate within the currently selected Nucleus project.

The project determines the complete collection of assets and findings available for analysis. An asset filter narrows that project data to the assets relevant to your current task.

For example, a project may contain all assets across your organization. You can then use Asset Filters to view only:

  • Assets belonging to the Finance business unit

  • Production applications owned by a specific team

  • Internet-facing assets with high business criticality

  • Assets included in a regulatory or compliance program

  • Cloud resources associated with a particular provider or account

Asset Filters do not move assets, modify asset properties, or change asset group membership. They only control which assets—and their associated findings—are included in the current view.

For more information about how projects and asset groups organize data, see Projects and Asset Group Structure.

Accessing Asset Filters

The Asset Filters control is located in the global header, immediately to the right of the project selector.

To create a filter:

  1. Select the project you want to analyze.

  2. Select Asset Filters in the global header.

  3. Choose one or more asset criteria.

  4. Select the values you want to include.

  5. Configure whether assets must match all or any of the selected criteria.

  6. Apply the filter.

After the filter is applied, Nucleus updates supported pages to include only assets matching the selected criteria.

Available Filter Criteria

The criteria available to you depend on the asset data, metadata, ownership information, and risk attributes present in your project.

Common criteria include:

Filter category

Example uses

Asset Type

Limit the view to hosts, applications, container images, cloud resources, or other asset types

Asset Group

Focus on an application, business unit, environment, location, or other organizational grouping

Business Owner Team

Review assets associated with a particular business owner

Support Team

Scope remediation work to the team responsible for maintaining the assets

Asset Name or Identifier

Locate a specific system or a collection of similarly named assets

Tags and Metadata

Filter using information imported from scanners, cloud platforms, CMDBs, or other connected systems

Business Criticality

Focus on assets with a particular level of importance to the organization

Public-Facing

Identify assets that may be exposed to the internet

Data Sensitivity

Limit the view based on the sensitivity of data handled by the asset

Compliance Scope

Review assets associated with a compliance or regulatory program

The usefulness of Asset Filters increases as you add accurate ownership, business context, and metadata to your assets.

Matching All or Any Criteria

When a filter contains multiple criteria, you can control how Nucleus determines whether an asset should be included.

Match All Criteria

With Match All selected, an asset must meet every configured criterion.

For example:

  • Asset Type is Host

  • Business Criticality is High

  • Public-Facing is Yes

Only assets satisfying all three conditions are included.

Use Match All when you want to progressively narrow the scope to a precise population of assets.

Match Any Criteria

With Match Any selected, an asset is included when it meets at least one of the configured criteria.

For example:

  • Business Owner Team is Cloud

  • Support Team is Infrastructure

  • Asset Group is Customer-Facing Applications

An asset matching any one of these conditions is included.

Use Match Any when several different criteria can independently qualify an asset for inclusion.

Multiple Values Within One Criterion

When you select multiple values within the same criterion, those values generally use Any logic.

For example, if you select the asset types Host, Application, and Cloud Resource, an asset can match any one of those asset types.

This differs from selecting separate criteria with Match All enabled. Separate criteria must all be satisfied, while multiple selected values within an individual criterion represent acceptable alternatives.

Example:
Asset Type = Host OR Cloud Resource
AND
Business Criticality = High

This filter includes high-criticality assets that are either hosts or cloud resources.

How Filters Affect Nucleus

Once applied, an asset filter scopes the information displayed across supported Nucleus pages.

This can include:

  • Operations Overview

  • Dashboards

  • Trends

  • Metrics

  • Active findings

  • Resolved findings

  • Top Risks

  • Findings assigned to you

  • Findings assigned to your team

  • Reports and other supported analysis views

Because the filter follows you between supported pages, you can investigate the same population of assets without rebuilding the scope for each view.

For example, you can:

  1. Apply a filter for internet-facing production assets.

  2. Review their risk posture on the Operations Overview.

  3. Open Top Risks to identify the most urgent vulnerability instances.

  4. Review Trends to evaluate remediation performance.

  5. Continue into detailed findings views to assign or remediate the work.

This creates a consistent analytical scope across the vulnerability management workflow.

Some pages may not support the global asset filter or may provide their own page-specific filtering. Always confirm the active scope before exporting data or using it for reporting.

Saving an Asset Filter

Save filters that you expect to use repeatedly. Saved Asset Filters eliminate the need to recreate common scopes for recurring reviews, investigations, or reports.

To save an asset filter:

  1. Open Asset Filters.

  2. Configure the desired criteria.

  3. Apply the filter and confirm that it returns the intended scope.

  4. Open the Asset Filters menu.

  5. Select Save As.

  6. Enter a descriptive name.

  7. Save the filter.

Use names that communicate the purpose of the filter to other users.

Examples include:

  • Production – Internet-Facing

  • Cloud Team – Critical Assets

  • PCI Scope

  • Customer-Facing Applications

  • Executive SLA Scope

  • Critical Infrastructure

  • Business Unit – Finance

Saved filters are associated with the project in which they were created. The assets returned by a saved filter may change over time as asset properties, ownership, tags, and group membership change.

This means a saved filter represents reusable criteria—not a static list of assets.

Applying a Saved Asset Filter

To reuse a saved filter:

  1. Confirm that you are in the correct project.

  2. Open the Asset Filters menu in the global header.

  3. Select the saved filter.

  4. Confirm that the expected scope is applied.

Nucleus updates supported views using the saved filter’s criteria.

Before using a saved filter for an important report or operational review, confirm that its criteria still represent the intended asset population.

Clearing an Asset Filter

When you have finished working within a filtered scope, clear the filter to return to the full project view.

To clear a filter:

  1. Open the Asset Filters menu.

  2. Select Clear.

The supported pages will return to displaying all assets available to you within the selected project.

Clearing a filter does not delete a saved filter. It only removes the filter from your current view.

Common Workflows

Review Risk for a Business Unit

Filter by the asset group, business owner, or metadata associated with the business unit. Then use the Operations Overview and Trends pages to evaluate:

  • Overall risk

  • High-risk findings

  • Vulnerability age

  • Remediation velocity

  • SLA compliance

Find Urgent Exposure

Create an asset filter for critical, internet-facing, or production assets. Then use findings filters to identify vulnerabilities with signals such as:

  • Confirmed exploitation

  • Malware or ransomware association

  • CISA KEV inclusion

  • Existential or Critical Nucleus Threat Rating

  • High Nucleus or Custom Risk Score

Asset Filters determine where to look. Findings filters determine what vulnerability conditions to look for within that scope.

Prepare a Team Review

Filter by Business Owner Team, Support Team, application, or asset group. Use the filtered results to review:

  • The team’s highest-risk findings

  • Overdue vulnerabilities

  • SLA performance

  • Riskiest assets

  • Remediation progress over time

Save the filter so the same scope can be reused during future team reviews.

Evaluate Scanner or Asset Coverage

Filter by asset type, environment, cloud account, business unit, or source-related metadata. Review asset totals and scan dates to identify:

  • Expected assets that may be missing

  • Assets with stale scan information

  • Business units with incomplete coverage

  • Unexpected differences between environments

Build Scoped Reporting

Apply a filter before reviewing dashboards, trends, or supported reports. This allows you to create reporting views for a specific application, team, compliance program, or executive stakeholder.

Always confirm the active project and asset filter before exporting or distributing results.

Asset Filters vs. Asset Groups

Asset Filters and Asset Groups are related but serve different purposes.

Capability

Asset Filters

Asset Groups

Primary purpose

Temporarily scope analysis and reporting

Organize assets within the project

Changes asset organization

No

Yes

Can be reused

Yes, by saving the filter

Yes

Can represent organizational hierarchy

Can filter by hierarchy and metadata

Yes, including nested groups

Can support access control

No

Yes

Can drive automation

Not directly

Yes

Best used for

Investigation, dashboards, trends, and reporting

Ownership, organization, access, automation, and long-term structure

Use Asset Groups to model the durable structure of your vulnerability management program. Use Asset Filters to create the analytical scope needed for a particular question or workflow.

For more information, see Asset Groups.

Access and Permissions

Asset Filters do not provide access to additional assets.

Users can only filter and view assets they are already authorized to access. If Asset Group Access Control restricts a user to certain groups, the filter results remain limited to those permitted assets.

As a result, two users applying the same saved filter may see different results if they have different project or asset group permissions.

Troubleshooting

The Filter Returns No Assets

Confirm that:

  • You are in the correct project.

  • The selected criteria and values exist on assets in that project.

  • Match All is not making the filter too restrictive.

  • You have permission to view the expected assets.

  • The asset metadata or group membership has not changed.

Try removing one criterion at a time to identify which condition is excluding the assets.

The Asset Count Changed Since the Last Review

Saved filters evaluate the current asset data each time they are applied. The results can change when:

  • New assets are ingested

  • Assets are deactivated or removed

  • Ownership changes

  • Asset metadata is updated

  • Assets move into or out of groups

  • Automated asset processing rules update asset properties

This behavior keeps saved filters aligned with the current environment.

A Filter Does Not Affect the Current Page

Not every page uses the global Asset Filters control. Some pages operate at an organization-wide level, use a different dataset, or provide their own page-specific filters.

Confirm that the page supports global asset filtering and review any filters available directly within the page.

Another User Sees Different Results

Users may have different access to projects or asset groups. Asset Filters respect those access restrictions, so identical filter criteria can produce different results for different users.

Best Practices

  • Save filters used for recurring operational and executive reviews.

  • Use clear names that identify the environment, team, application, or purpose.

  • Prefer asset metadata and dynamic asset groups over manually maintained lists.

  • Combine asset filters with findings filters for precise vulnerability analysis.

  • Confirm the active filter before exporting or sharing data.

  • Periodically review saved filters to ensure their criteria still match the intended scope.

  • Clear filters when switching to an unrelated analysis to avoid unintentionally carrying forward a narrow scope.

Asset Filters are most effective when asset ownership, grouping, criticality, and metadata are accurate. A well-maintained asset model allows teams to move quickly from an enterprise-wide risk picture to the exact population requiring investigation or remediation.