Cortex Network Scanner - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-11
Category
Administrator Guide

The Cortex Network Scanner is a powerful application designed to identify and analyze devices, services, and vulnerabilities in your internal network.

What is Cortex Network Scanner?

The Cortex Network Scanner, a key component of the Exposure Management portfolio, is a robust tool for internal network vulnerability assessment. The scanner efficiently identifies live hosts and vulnerabilities using various methods, including remote and authenticated local checks. Distributed as a Broker VM applet, it integrates seamlessly into your existing infrastructure.

Cortex Network Scanner provides the following key capabilities:

  • Asset discovery

    Cortex Network Scanner identifies responsive hosts within a specified IP range, covering both on-premises and cloud-hosted assets.

  • Vulnerability scanning

    Cortex Network Scanner supports authenticated and non-authenticated scanning:

    • Non-authenticated scans use various vulnerability tests to detect vulnerabilities in the target system based on system responses without requiring credentials, including sending tailored packets to target hosts.

    • Authenticated scans use the supplied credentials to authenticate into a target host and identify vulnerabilities by performing deeper tests, including detailed software enumeration and service detection.

  • Customizable and targeted scanning options

    • Select from different scan profiles for quick turnaround or deeper assessments.

    • Specify different network configurations to adapt to different environments, such as alive test methods, ports to scan, schedules, and performance settings.

    • Scan for specific vulnerabilities quickly across your asset inventory.

  • Multi-scanner support to distribute scan loads across multiple scanners

    Reduce the amount of time it takes to complete large network scans by assigning multiple scanners to the task.

  • Integration with the Cortex XDR inventory and vulnerability management

    Scan results are seamlessly integrated into the inventory and vulnerability management views in Cortex XDR, providing a centralized view of all discovered assets, vulnerabilities, and issues.

  • Credential test scans

    Check the credentials for service accounts before launching full-scale authenticated scan.