Network Scanning
What it is
Network Scanning discovers hosts, services, and software across the network without requiring an agent on every device. Scanner agents perform network scans and feed discovered assets into the same vulnerability pipeline used by endpoint agents.
Highlights
- Host discovery — identifies IP addresses, hostnames, MAC addresses, and operating system guesses.
- Service detection — maps open ports, protocols, and running services with version information.
- Software fingerprinting — detected services are linked to the central software inventory for CVE matching.
- Security findings — network-level issues are classified and reported.
Finding types
| Type | Examples |
|---|---|
| Vulnerability | CVEs detected via scanner scripts (e.g., EternalBlue) |
| TLS Issue | Weak ciphers, expired certificates, compromised SSL keys |
| Suspicious Port | Unexpected or high-risk open ports |
| Misconfiguration | Missing security headers, insecure HTTP configurations |
Why it matters
Not every asset can run an endpoint agent. Network scanning extends scani5 's coverage to printers, IoT devices, shadow IT, and unmanaged infrastructure.
In the application
The Network Scanner view shows scan activity and outcomes. Use it to monitor scanning operations, review scan results, and investigate network-focused security checks.
Discovered assets flow into the same Vulnerability Management and Threat Exposure pipeline as endpoint agents.