Enterprise Software Supply Chain Manager (ESSCM)IntegrationsVAPT Scans (CLI)
Network Scan
Assess a host or network range for open ports, exposed services, and known CVEs
Network Scan
The network scan assesses the attack surface of a host or network range you own: it discovers open ports, identifies the services and versions listening on them, and checks the live services against known CVEs and a set of named high-profile vulnerability checks.
Run it from the Safeguard CLI on a machine inside the target network.
Prerequisites
- The Safeguard CLI installed and signed in.
- Authorization to scan the target (
--i-am-authorisedor an authorizingscope.yaml).
Usage
Scan a single host or a CIDR range:
safeguard network-scan --targets scanme.example.com --i-am-authorised
safeguard network-scan --targets 10.0.0.0/24 --i-am-authorisedDiscover and scan everything reachable on the machine's local network(s):
safeguard network-scan --all --i-am-authorised--all is a whole-network sweep. It still requires authorization and can be
slow on large or quiet subnets. Scope exclusions are respected.
What you get
- Assets — each open service becomes an asset with its port, protocol, and detected version.
- Vulnerabilities — CVEs and misconfigurations found on the live services.
- Checks — the named high-profile checks that were evaluated, with their pass / fail outcome.
Results upload to a project in your console when the scan completes.
Common options
| Option | Description |
|---|---|
--targets | One or more hosts and/or CIDR ranges to scan |
--all | Auto-discover and scan the local network(s) instead of --targets |
--i-am-authorised | Confirm you are authorized to scan the target |
Notes
- Only scan hosts and networks you own or have explicit written permission to test.
- For the fullest results, run the scan from a machine with unfiltered network access to the target.