SCANTIDE AUDITOR
Scantide Auditor Guide

From Installed Software Inventory to Useful CVE Review

Finding installed software is the easy part. Useful vulnerability review also needs reliable product matching, version context and a way to distinguish evidence from uncertain associations.

Technical guideUpdated 25 September 2026Scantide Auditor
Short answer: Finding installed software is the easy part. Useful vulnerability review also needs reliable product matching, version context and a way to distinguish evidence from uncertain associations.

Inventory starts with what the operating system reports

Package managers, installed-program registries and application metadata provide names and versions, but naming is inconsistent across vendors and editions.

CVE matching is not always exact

A product family name may map to several versions or components. Good tooling should avoid claiming vulnerability when the version evidence does not support it.

Lifecycle context changes priority

Software that is no longer maintained can be important even when there is no immediately matching CVE. Version and lifecycle intelligence provide a broader maintenance signal.

Auditor combines the views

Scantide Auditor can include software inventory, CVE review and lifecycle/latest-version intelligence in the same assessment so administrators can investigate rather than juggle unrelated reports.

Practical depth: examples, failure modes and what to verify

Source note: current Scantide material describes the present platform. Older JufCorp/Red Cloud material is retained as field experience and historical context. Old product names, versions and configuration examples are not presented as current requirements.

Current Scantide detail

Current Scantide source: Scantide Auditor – Agentless Internal Network Discovery and Security Visibility

Scantide Auditor provides authorized internal network discovery, asset inventory, service visibility, CMDB review and readable evidence reports for Windows and Linux environments.

Current Scantide source: Agentless Network Discovery for Servers and Infrastructure

Scantide Auditor performs authorized agentless network discovery to identify reachable hosts, services and infrastructure evidence for inventory and security review.

Current Scantide source: Network Asset Inventory and Service Discovery

An inventory becomes more useful when each asset has evidence: address, reachability, visible services and other context that can be reviewed.

Current Scantide source: Windows Network Auditor and Internal Asset Discovery

Discover Windows network assets, exposed services and useful operational evidence with Scantide Auditor, designed for authorized internal visibility and readable reporting.

Current Scantide source: Linux Network Auditor and Internal Discovery

Use Scantide Auditor in Linux environments for authorized network discovery, service visibility and infrastructure evidence without a heavyweight endpoint deployment.

Field experience from the archive

Historical source · JufCorp: Security Reality Check: Why a Perfect Score Doesn't Mean You're Safe

Server Inventory: Maintain complete asset inventory of all servers (physical, virtual, cloud). Include IP addresses, purposes, owners, and last patched dates.

Historical source · JufCorp: Securing your server environment - Part III - Operating systems

In many environments, local firewalls are disabled out of pure laziness. "We can't be bothered troubleshooting why SQL traffic doesn't work .." Have local firewalls enabled , enable logging so you can easily find what's going on. If you're in a shared environment you'll also get alerted about noisy neighbors . Local firewalls also enables you to utilize a brute force prevention software and have those attacks mitigated, no matter where they come from. If you want, I'll happily help you out with getting a brute force prevention software in place.

Historical source · JufCorp: Using HTTP redirects for mitigating vulnerability scans and bruteforce attacks

This way , a vulnerability scan will render the attacking client to be redirected to where-ever I want so my idea is to simply get rid of the attecker, saving bandwidth and preventing them from finding something I've missed. It's NOT a foolproof method but a fun experiment and it might be useful in some scenarios.

Historical source · JufCorp: Securing server environments – part II – Networking

Always have a good monitoring software running and checking your network for new devices. If you start seeing devices with MAC addresses with 00-00-00-BE-50-00-DE-AD .. well. its too late . you’re toast. Personally I favor SpiceWorks but there are lots of monitoring software solutions out there. Take your pick. Basically, you need to have a clue of what’s going on your network and , even mores so. You need to know why. You need to monitor bandwidth usage and also have monitoring points on your network , both from internal point and from external.

Practical review checklist

Frequently asked questions

Does a product-name match prove a CVE applies?

No. Version, edition and component context matter.

Why include lifecycle information?

Unsupported or aging software can represent operational risk even without a specific current CVE.

Check the evidence with Scantide Auditor

Agentless internal network discovery and security visibility. Scantide is designed to show observable evidence and readable context rather than turn every observation into a vulnerability claim.

Explore Scantide AuditorMore guidesAll Scantide guides