Skip to main content

Network Scanning

What it is

Network Scanning discovers hosts, services, and software across the network without requiring an agent on every device. Scanner agents perform network scans and feed discovered assets into the same vulnerability pipeline used by endpoint agents.

Highlights

  • Host discovery — identifies IP addresses, hostnames, MAC addresses, and operating system guesses.
  • Service detection — maps open ports, protocols, and running services with version information.
  • Software fingerprinting — detected services are linked to the central software inventory for CVE matching.
  • Security findings — network-level issues are classified and reported.

Finding types

TypeExamples
VulnerabilityCVEs detected via scanner scripts (e.g., EternalBlue)
TLS IssueWeak ciphers, expired certificates, compromised SSL keys
Suspicious PortUnexpected or high-risk open ports
MisconfigurationMissing security headers, insecure HTTP configurations

Why it matters

Not every asset can run an endpoint agent. Network scanning extends scani5 's coverage to printers, IoT devices, shadow IT, and unmanaged infrastructure.

In the application

The Network Scanner view shows scan activity and outcomes. Use it to monitor scanning operations, review scan results, and investigate network-focused security checks.

Discovered assets flow into the same Vulnerability Management and Threat Exposure pipeline as endpoint agents.