SCANTIDE AUDITOR
Scantide Auditor Guide

Local Software Inventory vs Network Discovery: Two Different Views

Network discovery tells you what systems and services are visible. Local inventory tells you what software the operating system reports as installed. Neither view replaces the other.

Technical guideUpdated 25 September 2026Scantide Auditor
Short answer: Network discovery tells you what systems and services are visible. Local inventory tells you what software the operating system reports as installed. Neither view replaces the other.

Network visibility answers 'what is reachable?'

A network scan can reveal hosts, open services, web interfaces and devices that may never appear in endpoint inventory.

Local inventory answers 'what is installed here?'

Authorized local or remote inventory can enumerate applications that do not expose network services at all.

Differences are useful

A server may run installed software that is currently stopped, or expose a service provided by a container or appliance not obvious in the normal software list.

Auditor combines multiple evidence sources

Scantide Auditor can be used for LAN discovery and local endpoint/software assessment, allowing the views to reinforce rather than replace each other.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Agentless Network Discovery for Servers and Infrastructure

Scantide Auditor performs authorized agentless network discovery to identify reachable hosts, services and infrastructure evidence for inventory and security review.

Current Scantide source: Scantide Auditor – Agentless Internal Network Discovery and Security Visibility

Scantide Auditor provides authorized internal network discovery, asset inventory, service visibility, CMDB review and readable evidence reports for Windows and Linux environments.

Current Scantide source: Linux Network Auditor and Internal Discovery

Use Scantide Auditor in Linux environments for authorized network discovery, service visibility and infrastructure evidence without a heavyweight endpoint deployment.

Current Scantide source: Windows Network Auditor and Internal Asset Discovery

Discover Windows network assets, exposed services and useful operational evidence with Scantide Auditor, designed for authorized internal visibility and readable reporting.

Current Scantide source: Windows Network Auditor and Internal Asset Discovery

Use Scantide Auditor on Windows to build a practical picture of reachable systems and services without turning an inventory task into an exploitation exercise.

Field experience from the archive

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

Server Inventory: Maintain complete asset inventory of all servers (physical, virtual, cloud). Include IP addresses, purposes, owners, and last patched dates.

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

In many environments, local firewalls are disabled out of pure laziness. "We can't be bothered troubleshooting why SQL traffic doesn't work .." Have local firewalls enabled , enable logging so you can easily find what's going on. If you're in a shared environment you'll also get alerted about noisy neighbors . Local firewalls also enables you to utilize a brute force prevention software and have those attacks mitigated, no matter where they come from. If you want, I'll happily help you out with getting a brute force prevention software in place.

Historical source · JufCorp: Securing Windows Server with a baseline security

11. Disable any unused services and network protocols. They can be a point of entry and for the unused network protocols, you bascially fill your local network with useless chatter that comsume bandwidth. This also goes for workstations and printers and so on.

1. Make sure all of your software is updated with all security patches. This includes the Windows operating system but also Adobe, Java,Office and any software really. This reduces the risk for so called 0day attacks or your server being compromised by software bugs.

7. Have a good monitoring and inventory system in place such as the free SpiceWorks and I also recently discovered Sitemonitoring at Sourceforge that I liked. Unfortunately Sitemonitoring only works for HTTP responses , I'd love to also have it work for pure port monitoring.

Historical source · JufCorp: Securing server environments – part II – Networking

Always have a good monitoring software running and checking your network for new devices. If you start seeing devices with MAC addresses with 00-00-00-BE-50-00-DE-AD .. well. its too late . you’re toast. Personally I favor SpiceWorks but there are lots of monitoring software solutions out there. Take your pick. Basically, you need to have a clue of what’s going on your network and , even mores so. You need to know why. You need to monitor bandwidth usage and also have monitoring points on your network , both from internal point and from external.

Practical review checklist

Frequently asked questions

Which view is more accurate?

They answer different questions, so accuracy depends on what you are trying to establish.

Why combine them?

Because visible services and installed software can reveal different parts of the asset story.

Check the evidence with Scantide Auditor

Agentless internal network discovery and security visibility. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Explore Scantide AuditorMore guidesAll Scantide guides