Start with authorization and purpose
Define the network ranges, owners and goal before scanning. A CMDB reconciliation exercise may need different coverage than a focused server assessment.
Use the least intrusive method that answers the question
If service visibility is enough, do not add deeper authenticated checks automatically. Evidence-oriented scanning should expand only when the use case requires it.
Segment large environments
Scanning in logical ranges or profiles makes reports easier to review and limits the effect of unexpected network behavior.
Treat findings as observations
A reachable port or unknown host is a reason to investigate, not proof of compromise. Scantide Auditor is designed to turn observations into follow-up rather than exploitation.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Scantide Auditor – Agentless Internal Network Discovery and Security VisibilityScantide Auditor provides authorized internal network discovery, asset inventory, service visibility, CMDB review and readable evidence reports for Windows and Linux environments.
Current Scantide source: Agentless Network Discovery for Servers and InfrastructureScantide Auditor performs authorized agentless network discovery to identify reachable hosts, services and infrastructure evidence for inventory and security review.
Current Scantide source: Linux Network Auditor and Internal DiscoveryUse Scantide Auditor in Linux environments for authorized network discovery, service visibility and infrastructure evidence without a heavyweight endpoint deployment.
Current Scantide source: Windows Network Auditor and Internal Asset DiscoveryDiscover Windows network assets, exposed services and useful operational evidence with Scantide Auditor, designed for authorized internal visibility and readable reporting.
Current Scantide source: Network Asset Inventory and Service DiscoveryCreate a practical internal network asset inventory with discovered hosts, visible services and evidence that helps administrators validate ownership and exposure.
Field experience from the archive
Historical source · JufCorp: Securing server environments - part II - NetworkingDon't have computers in the reception connected to the corporate network such as guest access systems. There is absolutely no need for external visitors to be able to browse your internal network.
For external guests you should also have a separate guest network that has no connection with your server networks or the workstations network . Remember, even if the salesperson or consultant seems reliable , you have absolutely no way of know if their computers has been infected with a virus or if they are up to no good.
Historical source · JufCorp: Securing server environments – part II – NetworkingAlways have a good monitoring software running and checking your network for new devices. If you start seeing devices with MAC addresses with 00-00-00-BE-50-00-DE-AD .. well. its too late . you’re toast. Personally I favor SpiceWorks but there are lots of monitoring software solutions out there. Take your pick. Basically, you need to have a clue of what’s going on your network and , even mores so. You need to know why. You need to monitor bandwidth usage and also have monitoring points on your network , both from internal point and from external.
Historical source · JufCorp: Securing your server environment - Part III - Operating systemsAlthough not a service but if you're not using IPv6, you might as well go ahead and disable it and also have a look at the various network settings for packet size, TCP chimney offload etc. Verify your routes are ok and that you're using the DNS servers you need. Avoid WINS if possible. It's old, slow and can have terrible impact on a network.
Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're SafeA developer spins up a test server, forgets about it after project ends. Server runs outdated software with default passwords. Attackers find it, use it as entry point to internal network. This happens more often than you think.
Server Inventory: Maintain complete asset inventory of all servers (physical, virtual, cloud). Include IP addresses, purposes, owners, and last patched dates.
Practical review checklist
- Scantide Auditor provides authorized internal network discovery, asset inventory, service visibility, CMDB review and readable evidence reports for Windows and Linux environments.
- Scantide Auditor performs authorized agentless network discovery to identify reachable hosts, services and infrastructure evidence for inventory and security review.
- Use Scantide Auditor in Linux environments for authorized network discovery, service visibility and infrastructure evidence without a heavyweight endpoint deployment.
- Discover Windows network assets, exposed services and useful operational evidence with Scantide Auditor, designed for authorized internal visibility and readable reporting.
- Create a practical internal network asset inventory with discovered hosts, visible services and evidence that helps administrators validate ownership and exposure.
- Don't have computers in the reception connected to the corporate network such as guest access systems.
- Always have a good monitoring software running and checking your network for new devices.