Scanner profiles
A scanner profile is a reusable set of scanning settings. Define one, apply it wherever it fits, and change it in one place.
Three parts:
| Part | Decides |
|---|---|
| Host discovery | How scanners determine a host exists |
| Service discovery | How they determine what it runs |
| Credentials | Whether they can log in and look properly |
Host discovery
How a scanner decides something is there. The trade is coverage against noise and speed:
- Hosts that do not respond to ping are missed by discovery that only pings, and plenty of hardened hosts do not.
- More thorough discovery finds them, takes longer, and is more visible to anything watching the network.
If an asset you know exists never appears, host discovery settings are the first thing to look at.
Service discovery
Once a host is known, what it runs. More thorough probing identifies services more accurately and takes longer.
Accuracy here matters more than it looks: vulnerability findings depend on correctly identifying versions, and a service identified only by port number produces weaker results than one properly fingerprinted.
Credentials
This is the part that changes results most, and the part most often skipped.
An uncredentialed scan sees a host from outside: open ports, service banners, whatever is inferable from the network. A credentialed scan logs in and reads the actual installed package versions, configuration, and patch state.
The difference is not incremental:
| Uncredentialed | Credentialed | |
|---|---|---|
| Finds | What is exposed | What is installed |
| Version accuracy | Inferred from banners | Read from the system |
| False positives | Higher | Much lower |
| Missing patches | Largely invisible | Enumerated |
If your vulnerability results feel thin or full of maybes, missing credentials is the most likely reason.
A credentialed scan needs an account on the target. Give it the least privilege that lets it read package and configuration state - it does not need administrative rights for most checks, and a scanning account with domain administrator is a significant piece of your estate's security resting on the scanner.
Credentials are stored encrypted, but scope them as though they were not.
Using profiles well
Build a small number of profiles that describe situations rather than individual targets:
- Standard - thorough discovery and credentialed scanning, for everything that can take it.
- Gentle - light discovery, no aggressive probing, for fragile networks and equipment that reacts badly to being scanned.
- External - what you use where you have no credentials and no network position.
A profile per zone is usually wrong. Profiles describe how to scan, zones describe what; keeping them separate is what stops you maintaining forty near-identical profiles.
Anything too fragile to scan even gently belongs in a zone's excluded hosts rather than in a gentler profile.
API
The endpoints behind this section are in the API reference.
Next
- Zones, subnets, URLs, and tags - what gets scanned
- Scanners - deploying the scanners that use these