Safeguard Docs
Enterprise Software Supply Chain Manager (ESSCM)IntegrationsVAPT Scans (CLI)

VAPT Scans (CLI)

Run network, device, Wi-Fi, Active Directory, OSINT, and cloud posture scans from the Safeguard CLI on your own environment

VAPT Scans (CLI)

Vulnerability Assessment & Penetration Testing (VAPT) scans assess the security posture of infrastructure you own — your networks, devices, wireless, identity directory, public footprint, and cloud accounts. They run from the Safeguard CLI on a machine you control and upload only their results to your Safeguard console, where they appear as projects alongside your other findings.

Available scans

ScanWhat it assessesRuns from
Network ScanOpen ports, exposed services, service versions, and known CVEs across a host or network rangeA machine inside the target network
Device ScanLAN / IoT device discovery and their exposed servicesA machine on the local network
Wi-Fi ScanWireless posture — open, weak-encryption, and possible rogue networksA machine with a wireless adapter, on site
Active Directory ScanRead-only Active Directory / LDAP identity postureA machine with directory access
OSINTPublic footprint and data-leak / breach exposure for a domain, email, or usernameAnywhere
Cloud ScanCloud configuration posture (CSPM) for AWS, Azure, or GCPAnywhere, with read-only cloud credentials

Before you start

Install the CLI

Every VAPT scan runs from the Safeguard CLI. Install it once:

curl -fsSL https://cli.safeguard.sh/install | bash

Then sign in so results upload to your console:

safeguard login

The CLI provisions the tools each scan needs on first use — you do not install them by hand.

Authorization

VAPT scans actively probe systems, so you must confirm you are authorized to scan the target. Provide authorization in one of two ways:

  • Pass --i-am-authorised on the command, or
  • Place an authorizing scope.yaml in .safeguard/ in your working directory that lists the targets you are permitted to scan.

Targets outside your authorized scope are refused. Only scan assets you own or have explicit written permission to test.

Start each scan against a small, known target before running it against a whole network. Active scanning can be slow on large or quiet ranges.

Where results appear

Each scan registers a project in your console and uploads its findings and any discovered assets. Open the project to review results in the usual Findings, Vulnerabilities, Assets, and Checks views.

Running from the Integrations page

On the Integrations → Add Project/Product tab, search for a scan (for example, "Network Scan" or "OSINT"). Each card opens a panel with the exact command to copy and run, with your target filled in.

On this page