OTserver Discovery in Isolated and Critical Infrastructure
Collection and transfer procedure
Keep the scanner inside the isolated environment and write validated scan.otserver.json files locally. Use a controlled gateway or approved file share when policy allows. For a disconnected site, transfer the file on approved removable media after malware scanning and review. Do not store API keys or SNMP credentials in the transfer file.
Linux collection
Run without direct upload:
| |
Validate at the collection point, transfer only the expected JSON through the approved boundary, validate again, and import it through Imports → Create New at the central manager. Leave the file local when the manager is unavailable; do not weaken the network boundary to make one upload succeed.
Windows collection
| |
The Windows GUI can run the same offline collection with the target, interface, output, protocol, and authorization controls. Copy only the validated JSON through the approved transfer boundary.
Verify the result
Record collection time, scanner identity, target scope, validation result, transfer owner, and destination site. Compare warnings and asset counts with the previous quarterly collection before accepting the import.
Deploy scanners per production line or review import provenance.