Get started with Cortex Network Scanner - Set up Cortex Network Scanner for the first time. - Administrator Guide - Cortex XDR - Cortex - Security Operations

Cortex XDR 5.x Documentation

Product
Cortex XDR
License
XDR + Cloud
Creation date
2025-07-13
Last date published
2026-06-04
Category
Administrator Guide
Abstract

Set up Cortex Network Scanner for the first time.

To set up and configure Cortex Network Scanner for the first time, perform the following tasks.

  1. Review the Deployment recommendations and complete any prerequisites.

  2. Deploy a Broker VM

  3. Activate Cortex Network Scanner

    Cortex Network Scanner is distributed as an applet on a Cortex Broker VM. Follow the instructions at this link to activate the Broker VM, and install Cortex Network Scanner on that Broker VM.

  4. Add a network (Optional)

  5. Define target groups (Optional)

  6. Add credentials for authenticated scans (Optional)

  7. Create a new scanCreate a new scan old

After completing these set-up and configuration tasks, you can and view issues and findings from scans and manage scans.

Deployment recommendations
Activate Cortex Network Scanner

The Cortex Network Scanner identifies and analyzes devices, services, and vulnerabilities in your internal network. It discovers responsive hosts within specified IP ranges, including on-premises and cloud environments. The scanner supports both non-authenticated and authenticated vulnerability scanning, with authenticated scans providing deeper insights through credential-based access. Scan results are seamlessly integrated into the inventory and vulnerability management views in Cortex XSIAM, providing a centralized view of all discovered assets, vulnerabilities, and issues.

Cortex Network Scanner is installed as an applet on a Broker VM.

Notice

Requires the Exposure Management add-on.

Important

The Cortex Network Scanner applet is not supported for FedRAMP customers.

Cortex Network Scanner does not support high availability (HA) Broker VM configuration.

Prerequisites

How to activate Cortex Network Scanner
  1. Navigate to SettingsConfigurationsData BrokerBroker VMs.

  2. Right click the Broker VM, and select Add AppNetwork Scanner.

  3. After the applet has installed, the scanner should automatically connect to the tenant. If the connection is successful, you’ll see a green dot next to Network Scanner in the Apps column of the Broker VMs table.

    A red dot indicates that an error occurred and the scanner is not connected.

    broker-vms-list.png
  4. (Optional) Click on the network scanner in the table to display details about the scanner or to deactivate it.

  5. Validate the installation. Navigate to ModulesVulnerability & Exposure ManagementNetwork ScannersNetwork Scanners and find your new scanner in the list.

    The Network Scanners page displays all your deployed and configured scanners, along with additional details about each of them.

    network-scanners.png

After setting up a Broker VM and activating Cortex Network Scanner, refer to Get started with Cortex Network Scanner for information about adding networks, adding credentials for authenticated scans, and configuring scans.