When the print dialog opens: choose "Save as PDF", then uncheck "Headers and footers" under More settings.
Internal Attack Surface
See Your Network From the Inside
External attack surface mapping shows a company the way the internet sees it. The internal attack surface is everything behind the perimeter — servers, workstations, printers, NAS, network gear, IoT, industrial controllers and Active Directory — and it is where most breaches actually move. RECON Internal extends attack surface management inside the perimeter through a single agentless probe. One probe discovers, identifies and classifies devices, runs security checks, reconstructs topology, tracks drift and gathers Active Directory evidence across entire subnets — without installing anything on the endpoints.
Key takeaways
- Agentless by design: a single lightweight probe observes the network and correlates the signals, instead of an agent on every host. Nothing to roll out, patch or manage device by device.
- One probe spans many subnets from a single point inside the perimeter, so you see what is invisible from the outside without standing up a scanner per segment.
- Every scan runs the same fixed pipeline under a 30-minute ceiling and uploads its results as one coherent record at the end — not a partial state you have to reconcile.
- Findings are resolved into a named, typed asset inventory and mapped to NIS2, ISO 27001, PCI DSS, DORA and GDPR, so the output is audit-ready, not a raw list of IP addresses.
- Billing is per real device on a rolling inventory, never per raw IP — so re-scanning as often as you like never inflates the count.
One Agentless Probe, Many Subnets
A single lightweight probe sits inside the perimeter and is driven entirely by the RECON server. It observes every subnet it can reach, checks in every 30 seconds for its next command, and never accepts an inbound shell — so internal coverage scales by reach, not by rolling out an agent to every host.
Who should read this
- CISOs and security leads who need internal visibility without the cost and friction of an agent on every endpoint.
- IT and infrastructure teams who own networks spanning multiple sites, subnets and OT segments.
- Compliance owners driving NIS2 Article 21, ISO 27001, PCI DSS, DORA and GDPR evidence for internal estate, not just the public-facing surface.
- Organisations that already use RECON External and want to close the loop with inside-the-perimeter coverage.
The Internal Scan Pipeline
Every scan runs the same fixed seven-phase pipeline, in the same order, under a hard 30-minute wall-clock ceiling — and uploads its results only at the end as one coherent record. Passive side-channels listen alongside the active spine, so nothing depends on a single technique.
The 30-minute cap is a real wall-clock limit on every internal scan, enforced by the probe itself. It keeps scans repeatable and safe to schedule as often as you like — a scan always returns, and results are only ever published as one complete record, never a partial state.
What It Discovers & Inventories
A single scan finds what is alive, works out what each device is, and resolves the raw signals into a clean, named inventory. Active and passive techniques run side by side because no single method sees everything — and the result is one consistent record per device.
The Resolved Internal Inventory
Raw discovery signals are resolved server-side into a named, typed inventory — every device anchored to its hardware identity, deduplicated across scans and grouped by asset class. This is the console view a team works from after the very first scan.
Security Checks & Coverage
After discovery, built-in checks run per device — gated to the ports that are actually open, so the cost on the wire stays low. The catalogue spans classic IT, operational-technology and cloud-native services, and grows in waves so coverage extends without re-engineering the probe.
OT / ICS & Cloud-Native Coverage
The same agentless probe that maps IT assets also identifies industrial controllers and runs safe, read-oriented checks against the control network on the core protocols — Modbus, Siemens S7, CODESYS, EtherNet/IP, PROFINET and IEC 61850 — while BACnet, DNP3 and OPC-UA are identified with their checks on the roadmap, so converged IT/OT estates are mapped in one pass, by one probe, under one inventory.
OT / ICS protocols covered
Cloud-native services covered
Compliance, Drift & Topology
Findings do not stop at a list of weaknesses. Each scan maps results to recognised frameworks, compares the network to its own history, and reconstructs how it is wired — the layers that turn a host list into a picture of risk.
The same agentless probe that maps IT assets also identifies industrial controllers and runs safe, read-oriented checks against the control network on the core protocols — Modbus, Siemens S7, CODESYS, EtherNet/IP, PROFINET and IEC 61850 — while BACnet, DNP3 and OPC-UA are identified with their checks on the roadmap, so converged IT/OT estates are mapped in one pass, by one probe, under one inventory.
Drift Between Scans & Topology
Beyond a snapshot, each scan is compared to the previous one on the same network, and the wiring is reconstructed — so change and segmentation become first-class findings, not something a human has to diff by hand.
Drift between scans
Every scan is compared to the previous one on the same network. Security incidents always leave traces — an unauthorised device, a service that should not be there, a port that opened overnight — and drift surfaces them as discrete, timestamped events:
- New asset — a device that was not present in the previous scan of this network.
- Asset gone — a device that was present before and is now missing.
- New port / port closed — a service opened or closed on a known device since the last scan.
- Configuration change — a meaningful change to a device between scans, with before and after recorded.
Beyond individual devices, the probe reconstructs network topology — gateways, switches and per-asset uplinks — and audits segmentation between subnets, flagging where a flat network exposes more than it should. Intrusion indicators (suspicious ports, unsigned lateral SMB, legacy protocols, end-of-life systems) are tagged to a recognised attacker-tactic framework, and likely decoys or honeypots are detected and excluded from billing.
Deployment in Brief
Onboarding is a single copy-paste command. The goal is that anyone can bring a probe online in minutes, with nothing to compile and no manual configuration. From there the probe is driven entirely by the server.
The console produces a one-line install command scoped to a single probe, with a single-use token that expires within 24 hours.
Run the command on any Linux host inside the network. It installs a single lightweight probe and registers it as an always-on background service that restarts itself automatically.
The probe registers with the platform, flips to online, and a quick asset discovery seeds the inventory and the per-asset estimate.
The probe checks in every 30 seconds; the server tells it what to do — scan on schedule, refresh discovery, reload configuration or update itself — with no inbound shell access ever opened to it.
Each scan uploads its results as one compressed record when it finishes, which the platform ingests, correlates, bills and renders — an atomic, consistent record rather than a partial state.
A single probe can be shared across users with owner-scoped controls, and removing a probe never destroys data — it decommissions and can be deliberately reactivated, history and licence intact.
Data endpoints authenticate with the probe’s own API key; administrative actions require a signed-in user. The probe is a machine, not a browser, and the two layers never blur — the server pilots the entire fleet, including updates, without ever opening a remote shell.
Packaging & Pricing
RECON Internal is licensed per asset, per year — you pay for real devices, not raw IP addresses. The figures below are customer-facing list prices; per-asset rates step down as the estate grows.
Every company gets one 30-day company trial, enough to map the full internal estate before you commit. The licence is bound to the probe and follows it through decommission and reactivation, so a reinstalled probe resumes where it left off.
Why It Matters & What It Replaces
A single agentless probe delivers what competitors sell as several separate products: a resolved asset inventory, vulnerabilities and misconfigurations, network topology, drift, Active Directory evidence and NIS2 / ISO / PCI DSS / DORA / GDPR compliance — all correlated and billed per device, not per raw IP.
How it compares
- Agentless and one probe per site — no agent on every endpoint, no per-endpoint cost, install in minutes.
- Resolved inventory, topology and drift in the same pass — capabilities others split across modules or sell as add-ons.
- OT/ICS and cloud-native checks alongside classic IT — a converged estate mapped by one probe, under one inventory.
- European and sovereign by design — your internal network data stays on EU-sovereign infrastructure.
One attack surface
RECON Internal does not stand alone. It correlates with RECON External (the internet-facing surface) and Active Directory evidence into one continuous attack surface — outside-in and inside-out — so the same platform shows what an attacker sees from the internet, what they would find once inside, and how the two connect.
Next steps
- Install a probe on one Linux host and map your first subnet in minutes with the 30-day company trial.
- Review the resolved internal inventory and the NIS2 / ISO 27001 / PCI DSS / DORA / GDPR mapping for your own estate.
- Pair RECON Internal with RECON External to see your full attack surface, outside-in and inside-out.
Contact: [email protected] · orizon.one/recon · EU sovereign infrastructure.