Skip to content
PentestBX — Security is a continuous process
Module

Hosts Vulnerability Scanner

Host-level security assessments, including network shares and credential scanning

Comprehensive network and host vulnerability scanning. Detect every device on your network, inventory shares, and assess private and public IPs for exploitable risk.

  • Agentless external and internal scanning
  • Credentialed scans with vault-backed secrets
  • Automatic network topology mapping

What this module does

Our solution provides comprehensive and accurate vulnerability assessments, from pinpointing critical host vulnerabilities to evaluating weaknesses. Achieve unified visibility into IT and host vulnerabilities, boosting operational efficiency.

PentestBX scans all devices on your server and obtains network shares. This process allows you to easily identify every device on your network, manage network shares, and quickly surface any security vulnerability.

We use advanced scanning tools to detect all devices on your network and create an inventory, so you understand which devices are present and what state they are in. Shared folders and files are identified quickly, helping you ensure these shares are correctly configured — crucial for data security and access control.

We also scan your specified private and public IPs. Our tooling identifies potential vulnerabilities in these IPs, helping you address security issues before they become critical.

Inside the platform

Hosts in the console

Real screens from the PentestBX platform — swipe or use the arrows to look around.

Product screenshots
platform.pentestbx.com
  • Estate-wide breakdown of operating systems, exposed services and where the vulnerabilities actually sit.
  • Findings grouped by platform with severity, CVE reference and an exploitable / not exploitable filter.
  • Every discovered host with its online state and the number of shares it exposes.
  • Vulnerability trends over time, severity mix and a letter-grade security score per scan.
  • Interactive topology map — 64 subnets and 5,409 hosts, coloured by the severity found on each node.

Scan overview

Estate-wide breakdown of operating systems, exposed services and where the vulnerabilities actually sit.

Capabilities

Everything in Hosts

Each capability is available on its own or combined with the other modules in a single subscription.

  • Basic Reporting

    Converts automatic scan results into readable, configurable reports. Each report includes severity, CVE references, verification status, and remediation recommendations. Reports can be downloaded as PDF/HTML/XLS and accessed via the API.

  • Notification

    Sends real-time alerts via email and webhooks for scan results, critical findings, or scan errors. You can customise notification thresholds (critical/medium/low) and recipients per project or host.

  • Scheduling Scanning

    Scheduled scans can run hourly, daily, weekly, or as custom scheduled jobs. A full history of scans and scheduled tasks is maintained.

  • Report Compare

    Compares different scan results and highlights new, fixed, and regression findings. Filter changes by CVE, severity level, and affected asset. Comparison outputs feed SLA tracking and trend reporting.

  • External Vulnerability Scanning

    Performs external scans for internet-exposed assets, including port/service discovery and banner fingerprinting. Provides safe, scalable, agentless scanning for IP blocks and cloud IP ranges, with WAF/IPS detection and false-positive reduction.

  • Internal Vulnerability Scanning

    Assesses the internal attack surface with segment-based targeting, VLAN-aware scanning, and low-noise profiles. Scan traffic throttling can be applied and discovery results are automatically correlated with network topology.

  • Deep Scan

    In-depth analysis of services — application logic tests, exhaustive SSL/TLS certificate analysis, and detailed configuration checks. An extensive module set performs deeper verification and exploit proof-of-concept attempts at the application, service, and OS levels.

  • Host Credential Scan

    Authenticated scans using supplied credentials (SSH, WinRM, SMB, domain user) detect configuration issues, local exploit vectors, and privilege escalation surfaces. Credentials are stored in a secure vault with access controls and per-scan audit logs.

  • Network Share Scan

    Scans SMB/NFS shares to identify exposed files, incorrect permissions, misconfigured shares, and sensitive data leakage. World-writable shares, admin-share access, and legacy backups are automatically reported.

  • Network Topology Mapping

    Automatically derives and visualises network topology using active discovery, ARP/ICMP/LLDP, and passive traffic analysis. Host–switch–segment relationships, port density, and critical access paths are mapped and stored as a time series.

  • Weak Credential / Weak Password

    Detects weak, default, and reused passwords against corporate password policies using dictionary checks, brute-force, and credential-stuffing attempts — with recommendations and enforced password changes for discovered accounts.

Bring Hosts into your security programme

Size your estate in the configurator and request a tailored quote, or start a trial straight away.