SCANTIDE AUDITOR
Scantide Auditor Guide

How to Scope an Internal Network Discovery Safely

Internal discovery should be deliberate: know which networks you are authorized to review, choose the evidence you need, and avoid turning a visibility exercise into unnecessary load.

Technical guideUpdated 25 September 2026Scantide Auditor
Short answer: Internal discovery should be deliberate: know which networks you are authorized to review, choose the evidence you need, and avoid turning a visibility exercise into unnecessary load.

Start with authorization and purpose

Define the network ranges, owners and goal before scanning. A CMDB reconciliation exercise may need different coverage than a focused server assessment.

Use the least intrusive method that answers the question

If service visibility is enough, do not add deeper authenticated checks automatically. Evidence-oriented scanning should expand only when the use case requires it.

Segment large environments

Scanning in logical ranges or profiles makes reports easier to review and limits the effect of unexpected network behavior.

Treat findings as observations

A reachable port or unknown host is a reason to investigate, not proof of compromise. Scantide Auditor is designed to turn observations into follow-up rather than exploitation.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Scantide Auditor – Agentless Internal Network Discovery and Security Visibility

Scantide Auditor provides authorized internal network discovery, asset inventory, service visibility, CMDB review and readable evidence reports for Windows and Linux environments.

Current Scantide source: Agentless Network Discovery for Servers and Infrastructure

Scantide Auditor performs authorized agentless network discovery to identify reachable hosts, services and infrastructure evidence for inventory and security review.

Current Scantide source: Linux Network Auditor and Internal Discovery

Use Scantide Auditor in Linux environments for authorized network discovery, service visibility and infrastructure evidence without a heavyweight endpoint deployment.

Current Scantide source: Windows Network Auditor and Internal Asset Discovery

Discover Windows network assets, exposed services and useful operational evidence with Scantide Auditor, designed for authorized internal visibility and readable reporting.

Current Scantide source: Network Asset Inventory and Service Discovery

Create a practical internal network asset inventory with discovered hosts, visible services and evidence that helps administrators validate ownership and exposure.

Field experience from the archive

Historical source · JufCorp: Securing server environments - part II - Networking

Don't have computers in the reception connected to the corporate network such as guest access systems. There is absolutely no need for external visitors to be able to browse your internal network.

For external guests you should also have a separate guest network that has no connection with your server networks or the workstations network . Remember, even if the salesperson or consultant seems reliable , you have absolutely no way of know if their computers has been infected with a virus or if they are up to no good.

Historical source · JufCorp: Securing server environments – part II – Networking

Always have a good monitoring software running and checking your network for new devices. If you start seeing devices with MAC addresses with 00-00-00-BE-50-00-DE-AD .. well. its too late . you’re toast. Personally I favor SpiceWorks but there are lots of monitoring software solutions out there. Take your pick. Basically, you need to have a clue of what’s going on your network and , even mores so. You need to know why. You need to monitor bandwidth usage and also have monitoring points on your network , both from internal point and from external.

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

Although not a service but if you're not using IPv6, you might as well go ahead and disable it and also have a look at the various network settings for packet size, TCP chimney offload etc. Verify your routes are ok and that you're using the DNS servers you need. Avoid WINS if possible. It's old, slow and can have terrible impact on a network.

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

A developer spins up a test server, forgets about it after project ends. Server runs outdated software with default passwords. Attackers find it, use it as entry point to internal network. This happens more often than you think.

Server Inventory: Maintain complete asset inventory of all servers (physical, virtual, cloud). Include IP addresses, purposes, owners, and last patched dates.

Practical review checklist

Frequently asked questions

Do I need permission to scan an internal network?

Yes. Run discovery only on networks you are authorized to review.

Can a discovery scan affect fragile devices?

Any network interaction can affect poorly designed equipment, so scope and profiles should be chosen carefully.

Check the evidence with Scantide Auditor

Agentless internal network discovery and security visibility. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Explore Scantide AuditorMore guidesAll Scantide guides