Hosts Vulnerability Scanner
Host-level security assessments, including network shares and credential scanning
Comprehensive network and host vulnerability scanning. Detect every device on your network, inventory shares, and assess private and public IPs for exploitable risk.
- Agentless external and internal scanning
- Credentialed scans with vault-backed secrets
- Automatic network topology mapping
What this module does
Our solution provides comprehensive and accurate vulnerability assessments, from pinpointing critical host vulnerabilities to evaluating weaknesses. Achieve unified visibility into IT and host vulnerabilities, boosting operational efficiency.
PentestBX scans all devices on your server and obtains network shares. This process allows you to easily identify every device on your network, manage network shares, and quickly surface any security vulnerability.
We use advanced scanning tools to detect all devices on your network and create an inventory, so you understand which devices are present and what state they are in. Shared folders and files are identified quickly, helping you ensure these shares are correctly configured — crucial for data security and access control.
We also scan your specified private and public IPs. Our tooling identifies potential vulnerabilities in these IPs, helping you address security issues before they become critical.
Hosts in the console
Real screens from the PentestBX platform — swipe or use the arrows to look around.
Scan overview
Estate-wide breakdown of operating systems, exposed services and where the vulnerabilities actually sit.
Everything in Hosts
Each capability is available on its own or combined with the other modules in a single subscription.
Basic Reporting
Converts automatic scan results into readable, configurable reports. Each report includes severity, CVE references, verification status, and remediation recommendations. Reports can be downloaded as PDF/HTML/XLS and accessed via the API.
Notification
Sends real-time alerts via email and webhooks for scan results, critical findings, or scan errors. You can customise notification thresholds (critical/medium/low) and recipients per project or host.
Scheduling Scanning
Scheduled scans can run hourly, daily, weekly, or as custom scheduled jobs. A full history of scans and scheduled tasks is maintained.
Report Compare
Compares different scan results and highlights new, fixed, and regression findings. Filter changes by CVE, severity level, and affected asset. Comparison outputs feed SLA tracking and trend reporting.
External Vulnerability Scanning
Performs external scans for internet-exposed assets, including port/service discovery and banner fingerprinting. Provides safe, scalable, agentless scanning for IP blocks and cloud IP ranges, with WAF/IPS detection and false-positive reduction.
Internal Vulnerability Scanning
Assesses the internal attack surface with segment-based targeting, VLAN-aware scanning, and low-noise profiles. Scan traffic throttling can be applied and discovery results are automatically correlated with network topology.
Deep Scan
In-depth analysis of services — application logic tests, exhaustive SSL/TLS certificate analysis, and detailed configuration checks. An extensive module set performs deeper verification and exploit proof-of-concept attempts at the application, service, and OS levels.
Host Credential Scan
Authenticated scans using supplied credentials (SSH, WinRM, SMB, domain user) detect configuration issues, local exploit vectors, and privilege escalation surfaces. Credentials are stored in a secure vault with access controls and per-scan audit logs.
Network Share Scan
Scans SMB/NFS shares to identify exposed files, incorrect permissions, misconfigured shares, and sensitive data leakage. World-writable shares, admin-share access, and legacy backups are automatically reported.
Network Topology Mapping
Automatically derives and visualises network topology using active discovery, ARP/ICMP/LLDP, and passive traffic analysis. Host–switch–segment relationships, port density, and critical access paths are mapped and stored as a time series.
Weak Credential / Weak Password
Detects weak, default, and reused passwords against corporate password policies using dictionary checks, brute-force, and credential-stuffing attempts — with recommendations and enforced password changes for discovered accounts.
Bring Hosts into your security programme
Size your estate in the configurator and request a tailored quote, or start a trial straight away.




