VM / runZero

runZero

runZero is an agentless discovery and exposure product for information technology, operational technology, and Internet of Things environments. It combines active, passive, and integration inventory with hosted external engines, query-based vulnerability matching, and a 5.0 verified-remediation workflow. A Community Edition exists.

Agentless discovery and exposure workflowResearch reviewed

What you are evaluating

The product still publishes as runZero. An 18 June 2026 agreement for Accenture to acquire runZero and NetRise is distinct from a majority investment in Dragos; completion was not established in reviewed sources. Safe operational-technology scanning remains an evaluation item.

A useful evaluation context

A plausible evaluation context is an estate that needs agentless discovery, including operational technology, and must test scan safety and correlation with authenticated scanners.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Agentless active, passive, and integration inventory across information technology, operational technology, and Internet of Things assets.
  • Hosted external discovery engines and query-based vulnerability matching on discovered services.
  • Version 5.0 verified-remediation workflow, with a Community Edition available beside commercial deployment.

Where it fits in the work

  1. Authorize active and passive collection only on owned lab or production segments, with extra safety review before operational-technology protocols are probed.
  2. Compare runZero inventory and query-based vulnerabilities with credentialed scanner results so fingerprint matches are not mistaken for authenticated package evidence.
  3. Use verified remediation to confirm a change, and record the contracting entity and support path named in the agreement you actually have.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

On a lab segment you own, run authorized agentless discovery against planted IT hosts and a representative non-production operational-technology or Internet of Things device approved for testing.

Evidence to look for

Planted hosts appear in inventory, query-based findings are labeled distinctly from any credentialed scanner evidence, operational-technology collection stays inside the approved window, and documentation still names runZero as the publishing product.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. What scan modes are safe on representative operational-technology devices, and who authorizes them?
  2. How do query-based matches correlate with authenticated scanner evidence on the same host?
  3. Which legal entity, brand, and support path are named in the contract for this deployment?

Names you may encounter: runZero Community Edition. Historical names do not establish current availability or feature equivalence.

Find your next idea.

Tip: press / to open search. Escape closes this window.