Skip to main content

Scanner profiles

A scanner profile is a reusable set of scanning settings. Define one, apply it wherever it fits, and change it in one place.

Three parts:

PartDecides
Host discoveryHow scanners determine a host exists
Service discoveryHow they determine what it runs
CredentialsWhether they can log in and look properly

Host discovery​

How a scanner decides something is there. The trade is coverage against noise and speed:

  • Hosts that do not respond to ping are missed by discovery that only pings, and plenty of hardened hosts do not.
  • More thorough discovery finds them, takes longer, and is more visible to anything watching the network.

If an asset you know exists never appears, host discovery settings are the first thing to look at.

Service discovery​

Once a host is known, what it runs. More thorough probing identifies services more accurately and takes longer.

Accuracy here matters more than it looks: vulnerability findings depend on correctly identifying versions, and a service identified only by port number produces weaker results than one properly fingerprinted.

Credentials​

This is the part that changes results most, and the part most often skipped.

An uncredentialed scan sees a host from outside: open ports, service banners, whatever is inferable from the network. A credentialed scan logs in and reads the actual installed package versions, configuration, and patch state.

The difference is not incremental:

UncredentialedCredentialed
FindsWhat is exposedWhat is installed
Version accuracyInferred from bannersRead from the system
False positivesHigherMuch lower
Missing patchesLargely invisibleEnumerated

If your vulnerability results feel thin or full of maybes, missing credentials is the most likely reason.

Scanning credentials are real credentials

A credentialed scan needs an account on the target. Give it the least privilege that lets it read package and configuration state - it does not need administrative rights for most checks, and a scanning account with domain administrator is a significant piece of your estate's security resting on the scanner.

Credentials are stored encrypted, but scope them as though they were not.

Using profiles well​

Build a small number of profiles that describe situations rather than individual targets:

  • Standard - thorough discovery and credentialed scanning, for everything that can take it.
  • Gentle - light discovery, no aggressive probing, for fragile networks and equipment that reacts badly to being scanned.
  • External - what you use where you have no credentials and no network position.

A profile per zone is usually wrong. Profiles describe how to scan, zones describe what; keeping them separate is what stops you maintaining forty near-identical profiles.

Anything too fragile to scan even gently belongs in a zone's excluded hosts rather than in a gentler profile.

API​

The endpoints behind this section are in the API reference.

Next​