Safeguard Docs
Enterprise Software Supply Chain Manager (ESSCM)IntegrationsVAPT Scans (CLI)

Device Scan

Discover LAN and IoT devices on your local network and assess their exposure

Device Scan

The device scan discovers the devices on your local network and assesses their exposure. It performs a safe connect sweep, passively identifies devices, and best-effort classifies each device's vendor, so weak-default or exposed services surface as findings.

Run it from the Safeguard CLI on a machine on the local network you want to inventory.

Prerequisites

  • The Safeguard CLI installed and signed in.
  • Authorization to scan the network (--i-am-authorised or an authorizing scope.yaml).

Usage

Sweep the auto-detected local network:

safeguard device-scan --i-am-authorised

Scan a specific range:

safeguard device-scan --targets 192.168.1.0/24 --i-am-authorised

What you get

  • Assets — each discovered device, with its address, open ports, and detected vendor where available.
  • Findings — weak-default or exposed services on those devices.

Results upload to a project in your console when the scan completes.

Notes

  • The scan is a safe connect sweep — it does not send exploit payloads.
  • Only scan networks you own or have explicit written permission to test.

On this page