VAPT Scans (CLI)
Run network, device, Wi-Fi, Active Directory, OSINT, and cloud posture scans from the Safeguard CLI on your own environment
VAPT Scans (CLI)
Vulnerability Assessment & Penetration Testing (VAPT) scans assess the security posture of infrastructure you own — your networks, devices, wireless, identity directory, public footprint, and cloud accounts. They run from the Safeguard CLI on a machine you control and upload only their results to your Safeguard console, where they appear as projects alongside your other findings.
Available scans
| Scan | What it assesses | Runs from |
|---|---|---|
| Network Scan | Open ports, exposed services, service versions, and known CVEs across a host or network range | A machine inside the target network |
| Device Scan | LAN / IoT device discovery and their exposed services | A machine on the local network |
| Wi-Fi Scan | Wireless posture — open, weak-encryption, and possible rogue networks | A machine with a wireless adapter, on site |
| Active Directory Scan | Read-only Active Directory / LDAP identity posture | A machine with directory access |
| OSINT | Public footprint and data-leak / breach exposure for a domain, email, or username | Anywhere |
| Cloud Scan | Cloud configuration posture (CSPM) for AWS, Azure, or GCP | Anywhere, with read-only cloud credentials |
Before you start
Install the CLI
Every VAPT scan runs from the Safeguard CLI. Install it once:
curl -fsSL https://cli.safeguard.sh/install | bashThen sign in so results upload to your console:
safeguard loginThe CLI provisions the tools each scan needs on first use — you do not install them by hand.
Authorization
VAPT scans actively probe systems, so you must confirm you are authorized to scan the target. Provide authorization in one of two ways:
- Pass
--i-am-authorisedon the command, or - Place an authorizing
scope.yamlin.safeguard/in your working directory that lists the targets you are permitted to scan.
Targets outside your authorized scope are refused. Only scan assets you own or have explicit written permission to test.
Start each scan against a small, known target before running it against a whole network. Active scanning can be slow on large or quiet ranges.
Where results appear
Each scan registers a project in your console and uploads its findings and any discovered assets. Open the project to review results in the usual Findings, Vulnerabilities, Assets, and Checks views.
Running from the Integrations page
On the Integrations → Add Project/Product tab, search for a scan (for example, "Network Scan" or "OSINT"). Each card opens a panel with the exact command to copy and run, with your target filled in.