Safeguard Docs
Enterprise Software Supply Chain Manager (ESSCM)IntegrationsVAPT Scans (CLI)

Network Scan

Assess a host or network range for open ports, exposed services, and known CVEs

Network Scan

The network scan assesses the attack surface of a host or network range you own: it discovers open ports, identifies the services and versions listening on them, and checks the live services against known CVEs and a set of named high-profile vulnerability checks.

Run it from the Safeguard CLI on a machine inside the target network.

Prerequisites

  • The Safeguard CLI installed and signed in.
  • Authorization to scan the target (--i-am-authorised or an authorizing scope.yaml).

Usage

Scan a single host or a CIDR range:

safeguard network-scan --targets scanme.example.com --i-am-authorised
safeguard network-scan --targets 10.0.0.0/24 --i-am-authorised

Discover and scan everything reachable on the machine's local network(s):

safeguard network-scan --all --i-am-authorised

--all is a whole-network sweep. It still requires authorization and can be slow on large or quiet subnets. Scope exclusions are respected.

What you get

  • Assets — each open service becomes an asset with its port, protocol, and detected version.
  • Vulnerabilities — CVEs and misconfigurations found on the live services.
  • Checks — the named high-profile checks that were evaluated, with their pass / fail outcome.

Results upload to a project in your console when the scan completes.

Common options

OptionDescription
--targetsOne or more hosts and/or CIDR ranges to scan
--allAuto-discover and scan the local network(s) instead of --targets
--i-am-authorisedConfirm you are authorized to scan the target

Notes

  • Only scan hosts and networks you own or have explicit written permission to test.
  • For the fullest results, run the scan from a machine with unfiltered network access to the target.

On this page