Vulnerability Scanning & Assessment
A systematic sweep for known vulnerabilities across your infrastructure and web applications, with results validated by a tester.
What is a vulnerability assessment?
A vulnerability assessment finds the known weaknesses in your environment: missing patches, outdated software, exposed services and common misconfigurations. Scanning tools check your systems against databases of known vulnerabilities. Then a person reviews the results, validates the vulnerabilities, and weeds out the noise. You walk away with a clear baseline and a list your team can actually work through.
How is that different from a penetration test?
Our work on offensive engagements shows that vulnerability scans and assessments turn up a large volume of known issues: outdated software, missing patches and exposed services. They give you a solid baseline for where each asset stands in isolation. They often miss configuration problems in Active Directory and other complex setups, though, and the findings they report usually carry less risk than what a penetration test uncovers. A penetration test finds the weaknesses scanners miss and shows what an attacker can do with them. An assessment finds the open windows. A pentest climbs through them and shows you what's inside. Both have a place, and we cover the difference in more depth in pentest vs vuln scan.
Every Red Raine Labs penetration test includes a vulnerability scan, so if you plan to buy a pentest anyway, you don't need a separate assessment first.
When does an assessment make more sense than a pentest?
- Nobody has ever looked. If you've never had a security review, an assessment shows you the obvious problems for less money. Fix those first, then bring in a pentest to find what's left.
- You know you're behind on patching. Paying a tester to exploit missing patches you already know about wastes budget. Get the baseline, clean it up, then test.
- You need broad coverage. An assessment covers a lot of systems quickly. It works well for large environments and for catching drift between annual pentests.
What do you scan?
Whatever you need covered: your external, internet-facing systems, your internal network, and your web applications. Most clients start with external and internal infrastructure, since that's where missing patches and exposed services pile up.
Our IT provider already runs a scanner. Why pay for this?
Plenty of IT providers run a scanner and forward the output. A raw scan report can run hundreds of pages, rank everything by generic severity score and include findings that don't apply to your environment at all. Your team ends up either ignoring it or burning weeks on the wrong things.
We validate and review the results, remove what doesn't apply, and prioritize based on possible impact to the organization. Scanners also vary in how you set them up, from credentials and scan policies to the networks they reach, so two scans of the same environment can report different results. A fresh scan with a different configuration often finds what your current scanner misses, and comparing the two shows you the gaps between your current setup and what a scan could see.
Is scanning safe for our systems?
Modern scanners rarely cause trouble, but older or fragile systems sometimes react badly. During scoping we'll ask about anything delicate, like legacy equipment or industrial controls, and either exclude it or tune the scan to go easy on it. We also schedule scans for a time that works for you.
How often should we scan?
Quarterly scanning makes a sensible baseline for most organizations, and internet-facing systems deserve more frequent checks. A one-time assessment gives you a starting point, but new vulnerabilities appear every week, and regular scanning catches them before an attacker does.
Related services and reading
- Pentest vs vuln scan: what each one actually tells you, and which one you need.
- Network Penetration Testing: the next step once the obvious issues are cleaned up.
- Free attack surface assessment: a no-cost look at what you expose to the internet.
Want a clear baseline?
Tell us roughly what you'd like covered and when it last got a look. We'll help you decide between an assessment and a pentest.
Let's Talk Through Your Scope