When the print dialog opens: choose "Save as PDF", then uncheck "Headers and footers" under More settings.
Internal Network Scanning
Scanning the Network From the Inside
External scanning sees your organisation the way an attacker on the internet sees it. Internal scanning sees it from inside the perimeter — where servers, workstations, printers, NAS units, network gear, IoT and Active Directory actually live. RECON does this with Scout: a single, lightweight, agentless probe that you install with one command and that observes the network to work out what is there. There is nothing to install on individual devices. One probe discovers, identifies, scans for vulnerabilities, reconstructs topology and gathers directory evidence across entire subnets.
Key takeaways
- Agentless by design: a single probe covers multiple subnets, with no software deployed to your endpoints. Deployment is measured in minutes, not weeks.
- A fixed seven-stage pipeline runs the same way every time, under a strict thirty-minute ceiling, so results are repeatable and a scan never hangs.
- Results are uploaded only at the end of a scan as one consistent record — never a partial state to reconcile.
- The probe is driven entirely from the server through a thirty-second heartbeat. There is no inbound SSH and no shell access into your network.
- One agentless probe delivers what competitors sell as several separate products: resolved asset inventory, vulnerabilities, network topology, drift, directory evidence and compliance — correlated and billed per real device.
Agentless by Design
Putting an agent on every endpoint does not scale: it means software to deploy, update and troubleshoot on thousands of machines. Scout takes the opposite approach. It is one lightweight probe placed on a single host inside the network, and it observes the network to deduce what is present — no footprint on the endpoints themselves.
Agentless means no per-host software to manage and a deployment measured in minutes. Scanning from inside the perimeter means you see what is invisible from outside. A single binary means nothing to maintain host by host. And uploading results at the end of each scan means a clean, coherent record rather than a partial state to reconcile.
Deployment & Onboarding
Onboarding is a single copy-and-paste command. The goal is that anyone can bring a probe online in minutes, with no packages to compile and no manual configuration. From that point the probe is driven entirely from the server.
Paste a single command on any Linux host inside the network. No packages to compile, no per-device rollout, no manual editing of configuration files.
The installer registers the probe as an always-on background service that restarts automatically and comes back after a reboot.
The probe authenticates once with a single-use installation token, reports its host details and flips from never-connected to online.
An initial discovery pass seeds the asset inventory, establishes the first baseline and sizes the deployment.
Once the first baseline is in, the probe is ready. From here it is driven entirely from the server through its heartbeat — no inbound SSH, no shell access required.
Because the probe is controlled through its outbound heartbeat, RECON pilots a remote probe without ever opening an inbound connection into your network. Scans, configuration changes and even probe updates all travel as commands in the heartbeat response and apply only when the probe is idle.
The Onboarding Flow
Onboarding runs as a short, fixed sequence: local install steps on the host, two authenticated calls out to RECON, and a first discovery pass that seeds the inventory. A reinstall reuses the existing credential and skips key rotation.
Discovery — Finding What Is Alive
Before anything else, the probe has to discover what is alive on the network. No single method sees everything, so it combines many active and passive techniques and starts with a reachability check, so a dead subnet never sends the whole scan to a halt.
Every subnet is classified before scanning. Live networks are scanned; routed-but-empty networks are recorded as a clean result; dead networks are skipped without failing the scan.
ARP, ICMP, TCP and UDP sweeps find live hosts and open ports across each in-scope subnet, with liveness re-validated to avoid phantom entries.
A passive listener quietly captures broadcast traffic — address assignment, service discovery, name announcements and neighbour discovery — to reveal hosts that stay otherwise silent, with zero added traffic.
A gentle discovery request coaxes privacy-conscious IoT and mobile devices into responding, so randomised-address and low-chatter devices are not missed.
Reverse DNS, NetBIOS, link-local resolution and service discovery run in parallel to attach real hostnames, with fully-qualified names preferred over short ones.
Each signal adds weight to an asset’s identity — vendor, model, open ports, hostname, operating system — producing a transparent confidence score capped at one hundred.
The reachability gate at the head of discovery is what keeps internal scanning robust at scale. Cross-subnet ranges that turn out to be empty are recorded as a security win rather than an error, and dead networks appear clearly flagged rather than silently dragging down the scan.
Fingerprinting & Asset Inventory
Once a device is found, the probe works out what it is — operating system, vendor, model, device type and the services it runs. The more signals it can cross-reference, the more reliable the answer, and this resolved identity feeds both the inventory and the correlation of vulnerabilities.
The Resolved Asset Inventory
Discovery and fingerprinting resolve into a single inventory: device categories, counts and a live feed of what the probe finds as it works.
The Scan Pipeline, End to End
Every scan runs the same spine of seven stages under a strict thirty-minute ceiling. Passive side-channels listen alongside the first stage and feed discovery, and only the final consolidated record is uploaded — never a partial state.
The Seven Scan Stages
Every scan runs the same seven stages in the same order, under a thirty-minute ceiling. The fixed order makes results repeatable, and the results are uploaded only at the end — as a single, consistent record rather than a stream of partial updates.
Finds what is alive across every in-scope subnet, fusing active probing with passive listening on the side.
Resolves operating system, version, vendor, model and services for each live host with open ports.
Runs control modules against the ports that are actually open and identifies the applications and services running on each host.
Checks whether network segments are properly isolated and flags lateral exposure and signs of intrusion.
Compares the network against the previous baseline to surface what has changed since the last scan.
Maps results to control frameworks — NIS2, ISO 27001, PCI DSS, DORA and GDPR — turning findings into compliance evidence.
Builds the topology, resolves geolocation and routing, then uploads one consolidated record to RECON.
A thirty-minute wall-clock ceiling guarantees that every scan returns — the probe never hangs in a scanning state. Progress is reported live, and the consolidated record is uploaded at the end so RECON ingests one coherent snapshot, correlates it and presents it.
Live Scan, Stage by Stage
While a scan runs, RECON reports progress live — each stage lighting up as the probe advances and results accumulating alongside.
Control Coverage
Security checks run only against the ports that are actually open, so the cost on the wire stays low and the network stays quiet. The catalogue grows in waves — a base set, then industrial protocols, then cloud-native services — so coverage extends without re-engineering the core.
Frameworks & protocols covered
RECON inspects programmable controllers, automation systems and industrial protocols alongside the IT estate, using safe, read-only protocol probes designed not to disturb sensitive operational equipment — with security checks on the core protocols today, and BACnet, DNP3 and OPC-UA identified with their checks on the roadmap — so the same probe gives you one inventory across IT, OT and cloud-native services.
The Server-Driven Control Loop
Every thirty seconds the probe checks in, and the heartbeat response tells it what to do next. Each spoke is an independent state machine — scan dispatch, configuration reload, self-update, remote uninstall, discovery refresh and stale-scan recovery — so RECON pilots the fleet without ever opening an inbound connection.
Topology, Drift, Geolocation & Decoy Detection
Beyond individual machines, the probe reconstructs how the network is wired, what has changed since last time, where the probe physically sits, and whether any of what it sees is deliberately fake. These are the layers that turn a list of hosts into a picture of risk.
Security Model & Unified Attack Surface
Every endpoint has its own authentication, chosen by who is calling. The probe’s own data travels with its credential; administrative actions require an authenticated user session. The two layers never blur into one another, and the probe is never reachable from outside your network.
One unified attack surface
Internal scan data does not live in isolation. RECON brings internal, external and Active Directory findings together in one console, so a device seen inside the perimeter can be viewed alongside its external exposure and identity posture — rather than living in three separate tools — and it is billed per real device on a rolling inventory, not per raw IP address.
How It Compares
A single agentless probe does the work that competitors sell as several separate products. RECON collapses three categories — vulnerability management, asset discovery and directory security posture — into one probe with a unified interface and a single per-device bill.
Next steps
- Request a scoping call to map your internal networks and size a probe deployment.
- Get a sample internal scan report to see resolved inventory, topology and compliance mapping side by side.
- Deploy a probe in minutes with a single command and see your internal attack surface in your browser.
Contact: [email protected] · orizon.one/services/recon · EU sovereign infrastructure.