{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/",
        "slug": "dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/"
        },
        "title": "Keep agentless inventory separate from software first-seen chronology",
        "summary": "Does a missing First seen at value mean Defender for Cloud has no software evidence?",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:31+00:00",
        "modified_at": "2026-09-10T00:52:39+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 245,
        "potentially_affected": "Defender for Cloud installed-application inventory combining agent-based and agentless software observations.",
        "dse_recommendation": "Record the collection method before using First seen at to compare software discovery timelines.",
        "primary_source": {
            "name": "Cloud asset inventory - Microsoft Defender for Cloud | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/defender-for-cloud/asset-inventory",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender for Cloud&#8217;s installed-application inventory defines First seen at as when software was first observed on the asset. That field is populated only for agent-based scanning, not agentless scanning. The inventory separately exposes detected version and, when available, file or registry paths as evidence. <a href=\"https://learn.microsoft.com/en-us/azure/defender-for-cloud/asset-inventory\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this interpretation when a report combines observations from both collection methods. The first-observation field should not be presented as an installation timestamp, and an empty value should not by itself settle whether software evidence exists.</p>\n<h2>DSE recommendation</h2>\n<p>Record the collection method before using First seen at to compare software discovery timelines. Keep the software identity, version and available evidence alongside the date field rather than ranking records solely by whether that date is present. For an investigation requiring installation chronology, identify the additional authorized evidence needed to establish it. Do not substitute the time of report generation for an unavailable first-observation value.</p>\n<h2>Verification</h2>\n<p>Compare representative agent-based and agentless records for the same reporting purpose. Confirm that an empty date remains explicitly unavailable and does not cause the software row to be discarded or described as newly installed. Inspect any downstream sorting, age calculations or exception logic that consumes the field. Preserve the collection-method distinction with the exported evidence so a later reviewer can understand why similar software records have different chronological detail. No installation or discovery event is inferred beyond the recorded observations.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/defender-for-cloud/asset-inventory\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Defender for Cloud asset inventory</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nDefender for Cloud’s installed-application inventory defines First seen at as when software was first observed on the asset. That field is populated only for agent-based scanning, not agentless scanning. The inventory separately exposes detected version and, when available, file or registry paths as evidence. Microsoft Learn.\nApplicability\nUse this interpretation when a report combines observations from both collection methods. The first-observation field should not be presented as an installation timestamp, and an empty value should not by itself settle whether software evidence exists.\nDSE recommendation\nRecord the collection method before using First seen at to compare software discovery timelines. Keep the software identity, version and available evidence alongside the date field rather than ranking records solely by whether that date is present. For an investigation requiring installation chronology, identify the additional authorized evidence needed to establish it. Do not substitute the time of report generation for an unavailable first-observation value.\nVerification\nCompare representative agent-based and agentless records for the same reporting purpose. Confirm that an empty date remains explicitly unavailable and does not cause the software row to be discarded or described as newly installed. Inspect any downstream sorting, age calculations or exception logic that consumes the field. Preserve the collection-method distinction with the exported evidence so a later reviewer can understand why similar software records have different chronological detail. No installation or discovery event is inferred beyond the recorded observations.\nOfficial references\nMicrosoft Learn: Defender for Cloud asset inventory. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nDefender for Cloud’s installed-application inventory defines First seen at as when software was first observed on the asset. That field is populated only for agent-based scanning, not agentless scanning. The inventory separately exposes detected version and, when available, file or registry paths as evidence. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/asset-inventory).\n\n## Applicability\n\nUse this interpretation when a report combines observations from both collection methods. The first-observation field should not be presented as an installation timestamp, and an empty value should not by itself settle whether software evidence exists.\n\n## DSE recommendation\n\nRecord the collection method before using First seen at to compare software discovery timelines. Keep the software identity, version and available evidence alongside the date field rather than ranking records solely by whether that date is present. For an investigation requiring installation chronology, identify the additional authorized evidence needed to establish it. Do not substitute the time of report generation for an unavailable first-observation value.\n\n## Verification\n\nCompare representative agent-based and agentless records for the same reporting purpose. Confirm that an empty date remains explicitly unavailable and does not cause the software row to be discarded or described as newly installed. Inspect any downstream sorting, age calculations or exception logic that consumes the field. Preserve the collection-method distinction with the exported evidence so a later reviewer can understand why similar software records have different chronological detail. No installation or discovery event is inferred beyond the recorded observations.\n\n## Official references\n\n[Microsoft Learn: Defender for Cloud asset inventory](https://learn.microsoft.com/en-us/azure/defender-for-cloud/asset-inventory). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Keep agentless inventory separate from software first-seen chronology",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/",
                "headline": "Keep agentless inventory separate from software first-seen chronology",
                "description": "Does a missing First seen at value mean Defender for Cloud has no software evidence?",
                "abstract": "Does a missing First seen at value mean Defender for Cloud has no software evidence?",
                "articleBody": "Source facts\nDefender for Cloud’s installed-application inventory defines First seen at as when software was first observed on the asset. That field is populated only for agent-based scanning, not agentless scanning. The inventory separately exposes detected version and, when available, file or registry paths as evidence. Microsoft Learn.\nApplicability\nUse this interpretation when a report combines observations from both collection methods. The first-observation field should not be presented as an installation timestamp, and an empty value should not by itself settle whether software evidence exists.\nDSE recommendation\nRecord the collection method before using First seen at to compare software discovery timelines. Keep the software identity, version and available evidence alongside the date field rather than ranking records solely by whether that date is present. For an investigation requiring installation chronology, identify the additional authorized evidence needed to establish it. Do not substitute the time of report generation for an unavailable first-observation value.\nVerification\nCompare representative agent-based and agentless records for the same reporting purpose. Confirm that an empty date remains explicitly unavailable and does not cause the software row to be discarded or described as newly installed. Inspect any downstream sorting, age calculations or exception logic that consumes the field. Preserve the collection-method distinction with the exported evidence so a later reviewer can understand why similar software records have different chronological detail. No installation or discovery event is inferred beyond the recorded observations.\nOfficial references\nMicrosoft Learn: Defender for Cloud asset inventory. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:29:31+00:00",
                "dateModified": "2026-09-10T00:52:39+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Keep agentless inventory separate from software first-seen chronology"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Explainer",
                    "Information priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 245,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Cloud asset inventory - Microsoft Defender for Cloud | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/defender-for-cloud/asset-inventory"
                }
            }
        ]
    }
}