b2KIT

Security Asset Inventory Tracker

Track IT assets with security metadata: OS versions, patch levels, ownership, and classification. Export inventory reports.

Tested tool guide Tested browser tools Checked August 16, 2026

What Security Asset Inventory Tracker does and how it behaves

A register of the machines and devices an organization runs, kept with the security facts that matter about each one: operating system version, current patch level, the person or team responsible for it, and its data classification. You add records, keep them updated, and export the inventory as a report. The thing people most often get wrong: this is a ledger, not a scanner. It records what someone enters. It does not discover devices on the network or fetch patch status from vendors, and an exported report is only as fresh as the records behind it.

How the result is produced

1

One record per asset

Each asset is a record that pairs identity information with the four security fields this tracker centers on: OS version, patch level, owner, and classification. Records are kept locally in the browser, so the inventory accumulates as you add devices and the data never leaves the machine; nothing is uploaded.

2

Reports from current records

The export builds an inventory report from the records stored at that moment, so it is a snapshot, not a live view. An asset whose patch level was never updated after enrollment exports with the old value, and a device that was never entered does not appear at all. Keep records current and the report follows; skip updates and it shows the gap.

Good uses

  • A new workstation, server, or VM arrives: record its OS version, patch level, owner, and classification so the organization has a defensible answer to what it is and who runs it.
  • Ahead of a security review or an incident response, go through the inventory to see which assets still carry older patch levels, then export the report for the people deciding next steps.
  • Handover or audit: when a new administrator, an auditor, or a compliance review asks for the asset picture, export the inventory report instead of reconstructing a spreadsheet from memory and old emails.

Limits and checks

  • Entered, not discovered: the tool stores what someone types. OS versions and patch levels are not detected from the machines themselves, so a record's freshness equals the last time someone updated it.
  • Absence proves nothing: devices nobody recorded (shadow IT, contractor laptops) are simply missing from the inventory. An empty spot in the report means not tracked, not does not exist.
  • Labels are only as consistent as the people typing them. If two groups classify similar data differently or write patch levels in different formats, the report treats them as different things. Agree on conventions before filling records in.

Common questions

Does the export give my security team a live report?

It gives a snapshot. The export is generated from the records in the inventory at that moment, so it is as current as the last update made. Refresh patch levels and ownership before exporting and the report reflects them; forget to, and it silently carries old values. Re-export when things change.

Will it tell me which machines are out of date?

Only in the sense that the records can. If someone entered an older patch level for an asset, that shows up in the inventory and in exports. What it cannot do is check the machines themselves: no scanning, no vendor patch feeds. Up to date in this tracker means the record says so, so decide who owns the updates.

References and verification

The behavioral notes were checked against the browser implementation. Standards and primary references below define the relevant format, formula, or platform behavior.

Related Tools