> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Analysis Fundamentals

> What the vulnerability analysis and the permission analysis evaluate, where their data comes from, and what the results are used for.

An analysis evaluates the entire inventory, not a single asset. It answers
questions that do not show up on one asset alone – which systems a
vulnerability affects, or who has access across multiple folders. Docusnap365
runs two such analyses: the vulnerability analysis against known CVEs, and
the permission analysis for the file system.

## Vulnerability Analysis and Permission Analysis

<CardGroup cols={2}>
  <Card title="Vulnerability Analysis" icon="bug" href="/docs/en/analysis/cve">
    Known vulnerabilities (CVEs) against the software installed on captured
    systems. Menu entry *CVE Analysis*.
  </Card>

  <Card title="Permission Analysis" icon="folder-lock" href="/docs/en/analysis/file-system">
    Who can access which directories, and where the right comes from. Menu
    entry *File System*.
  </Card>
</CardGroup>

*Permission Analysis* is the menu group heading, not a clickable entry;
*File System* is the only entry under it. Permission modules for shares,
databases and SharePoint will join the same group.

## Origin

Scan modules capture systems,
software, directories and permissions; a background match compares captured
software against known vulnerabilities, and an analysis package evaluates
NTFS permissions.

<Note>
  Neither area has a create function. A CVE comes from the background match, a permission analysis result from an
  analysis package – never from an entry made in the interface.
</Note>

## Module surface and the asset tab

The vulnerability analysis shows up in two places with different scope. The
module surface under *Analysis* answers how many CVEs exist overall, which
to treat first, and who is responsible; the *CVEs* tab on a single asset
answers what concerns that one device.

Two related figures rate a CVE: the CVSS score, a number
from 0 to 10, and the severity, with the four
levels *Critical*, *High*, *Medium* and *Low*. Where severity is set, it
takes precedence; where only the score exists, Docusnap365 derives the level
from it.

## The tabs of the permission analysis

The permission analysis answers the same underlying question across several
tabs:

| Tab | Question |
| - | - |
| *Overview* | What's the overall state? |
| *Folder Analysis* | Who can do what on this folder? |
| *Principal Analysis* | What can this user or group access? |
| *Permission Origin* | Why can this principal do that on this folder? |

The first two take stock, the third starts from the user or group, and the
fourth explains a single case.

## From finding to control

The vulnerability analysis exists to prioritize CVEs by severity, assign
them to a responsible person, and carry them into an ISMS control through
the *Controls* tab – the same control, not a copy. The permission analysis
answers who can access which directories and where the right comes from.

## Limits

Both analyses only evaluate what a scan module has captured: software no scan
module captures never appears in a vulnerability analysis; directories no
scan module captures never appear in a permission analysis. CVE data is only
as current as the last background match, not the last scan.

## Related

[CVE Analysis](/docs/en/analysis/cve) covers lists, the detail page and
assessment in depth; the tutorial [From Vulnerability to
Control](/docs/en/analysis/tutorial-vulnerability-to-control) walks the path
through to the ISMS. [File System](/docs/en/analysis/file-system) covers the four
tabs of the permission analysis. Where the underlying data comes from is
described in [Scanning Fundamentals](/docs/en/scan/understanding-scanning) and
[Scanning NTFS Security](/docs/en/scan/ntfs-analysis).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.