Skip to main content

Cyentrix Scan · the on-prem engine

The engine behind every assessment, running inside your network.

Cyentrix Scan is the scanner we built to run our assessments. It does the heavy lifting — discovery, CVE matching enriched with CISA KEV and EPSS, credentialed and compliance checks — on a node inside your network. Then a person verifies every finding before it reaches your report. You don’t buy it or run it yourself: it comes with the engagement.

How it works

Machine-scale coverage. Human judgement on every finding.

01Principle

Runs inside your network.

For internal scopes, the engine is a single binary on a box inside your network — Windows or Linux, no dependencies. Scanning, credentials and raw evidence stay on-premise. The node dials out over HTTPS: no inbound ports, no VPN. For an external review you don’t need it at all — we look from the outside, with no access to your network.

Deployone binary
Connectionoutbound-only HTTPS
02Depth

Real coverage, not a port list.

Nmap discovery and version detection, matched to CVE, enriched with CISA KEV and EPSS, and probed with Nuclei plus TLS and misconfiguration checks. With SSH / WinRM credentials it adds authenticated results and compliance benchmarks. Checks are non-destructive by default.

EngineNmap · Nuclei
ScoringCVE · CISA KEV · EPSS
03Judgement

The engine finds candidates. A person decides.

A scanner — ours included — produces candidates. Every one is checked by an assessor and graded on the strength of its evidence, then ranked by what’s actually exploitable and being exploited. Only what survives that review goes in your report, with the fix in plain language.

Evidence gradesActionable · Potential · Validated-safe
People doverify · rank · explain · re-test
04Boundary

The console can’t scan.

Our cloud console only queues work and shows results. It can never run a tool itself — that boundary is enforced in the software, not just hidden in the UI. Control plane in the cloud; execution strictly on the node in your network.

Console doesqueue · monitor · report
Console neverruns a scan

Compare

Why not just run Nessus or Qualys? You can — here’s the difference.

They’re capable scanners, and running one is better than running nothing. But any scanner produces a list of possibilities. What an assessment adds is the work of turning that list into the few things you should actually fix.

A scanner report

Every match it can find, ranked by CVSS. Many are false positives, already fixed, or not reachable in your setup — and the triage is left to you.

A Cyentrix assessment

The engine’s output, verified by a person and ranked by real exploitability. A short list with the fix, a walkthrough with your team, and a re-test.

Where the evidence lives

For internal scopes the engine runs on a node inside your network. Your targets, credentials and raw evidence stay on-premise.

What you pay for

Judgement, not licences. There’s no scanner subscription to buy or seats to manage — the engine comes with the engagement.

Start from the outside

See what’s exposed. Then fix it.

Start with a free external exposure review — no agent to install, no credentials shared, no commitment. If it’s worth going further, we’ll scope an assessment.

Get my free exposure review →

NO AGENT · NO CREDENTIALS SHARED · PRACTITIONER-REVIEWED