Network visibility answers 'what is reachable?'
A network scan can reveal hosts, open services, web interfaces and devices that may never appear in endpoint inventory.
Local inventory answers 'what is installed here?'
Authorized local or remote inventory can enumerate applications that do not expose network services at all.
Differences are useful
A server may run installed software that is currently stopped, or expose a service provided by a container or appliance not obvious in the normal software list.
Auditor combines multiple evidence sources
Scantide Auditor can be used for LAN discovery and local endpoint/software assessment, allowing the views to reinforce rather than replace each other.
Practical depth: examples, failure modes and what to verify
Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.
Current Scantide detail
Current Scantide source: Agentless Network Discovery for Servers and InfrastructureScantide Auditor performs authorized agentless network discovery to identify reachable hosts, services and infrastructure evidence for inventory and security review.
Current Scantide source: Scantide Auditor – Agentless Internal Network Discovery and Security VisibilityScantide Auditor provides authorized internal network discovery, asset inventory, service visibility, CMDB review and readable evidence reports for Windows and Linux environments.
Current Scantide source: Linux Network Auditor and Internal DiscoveryUse Scantide Auditor in Linux environments for authorized network discovery, service visibility and infrastructure evidence without a heavyweight endpoint deployment.
Current Scantide source: Windows Network Auditor and Internal Asset DiscoveryDiscover Windows network assets, exposed services and useful operational evidence with Scantide Auditor, designed for authorized internal visibility and readable reporting.
Current Scantide source: Windows Network Auditor and Internal Asset DiscoveryUse Scantide Auditor on Windows to build a practical picture of reachable systems and services without turning an inventory task into an exploitation exercise.
Field experience from the archive
Historical source · JufCorp: Securing your server environment - Part III - Operating systemsIn many environments, local firewalls are disabled out of pure laziness. "We can't be bothered troubleshooting why SQL traffic doesn't work .." Have local firewalls enabled , enable logging so you can easily find what's going on. If you're in a shared environment you'll also get alerted about noisy neighbors . Local firewalls also enables you to utilize a brute force prevention software and have those attacks mitigated, no matter where they come from. If you want, I'll happily help you out with getting a brute force prevention software in place.
Historical source · JufCorp: Securing Windows Server with a baseline security11. Disable any unused services and network protocols. They can be a point of entry and for the unused network protocols, you bascially fill your local network with useless chatter that comsume bandwidth. This also goes for workstations and printers and so on.
1. Make sure all of your software is updated with all security patches. This includes the Windows operating system but also Adobe, Java,Office and any software really. This reduces the risk for so called 0day attacks or your server being compromised by software bugs.
7. Have a good monitoring and inventory system in place such as the free SpiceWorks and I also recently discovered Sitemonitoring at Sourceforge that I liked. Unfortunately Sitemonitoring only works for HTTP responses , I'd love to also have it work for pure port monitoring.
Historical source · JufCorp: Securing server environments – part II – NetworkingAlways have a good monitoring software running and checking your network for new devices. If you start seeing devices with MAC addresses with 00-00-00-BE-50-00-DE-AD .. well. its too late . you’re toast. Personally I favor SpiceWorks but there are lots of monitoring software solutions out there. Take your pick. Basically, you need to have a clue of what’s going on your network and , even mores so. You need to know why. You need to monitor bandwidth usage and also have monitoring points on your network , both from internal point and from external.
Practical review checklist
- Scantide Auditor performs authorized agentless network discovery to identify reachable hosts, services and infrastructure evidence for inventory and security review.
- Scantide Auditor provides authorized internal network discovery, asset inventory, service visibility, CMDB review and readable evidence reports for Windows and Linux environments.
- Use Scantide Auditor in Linux environments for authorized network discovery, service visibility and infrastructure evidence without a heavyweight endpoint deployment.
- Discover Windows network assets, exposed services and useful operational evidence with Scantide Auditor, designed for authorized internal visibility and readable reporting.
- Use Scantide Auditor on Windows to build a practical picture of reachable systems and services without turning an inventory task into an exploitation exercise.
- Server Inventory: Maintain complete asset inventory of all servers (physical, virtual, cloud).
- In many environments, local firewalls are disabled out of pure laziness.