HostedScan

use case

Internal Vulnerability Scanning

Learn how to run internal vulnerability scans with HostedScan

Security team reviewing scan results on their monitors

what it is

What is internal vulnerability scanning?

Internal vulnerability scanning is the process of testing for security vulnerabilities from inside a private network. The scanning software is installed inside the network and sends requests to discover and test all of the devices on the network, even if they are not addressable via the public internet.

External vulnerability scanning is conducted from outside the network over the public internet. The scanner has the same view as an outside attacker. Whereas internal scanning has the view of an attacker who has gained a foothold inside the network - for example: through phishing, malware, or a compromised device.

Both external and internal scans are important components of cybersecurity programs and required by many certification standards. By running regular internal scans, organizations can:

Detect vulnerabilities before they are exploited

Maintain compliance with frameworks such as SOC 2 and ISO 27001

Gain full visibility into the security posture of internal assets across data centers, offices, and cloud environments

Full-stack security

Running internal vulnerability scans with HostedScan

HostedScan provides scalable and secure options to connect vulnerability scanners on internal networks to hostedscan.com for centralized management and reporting. Read the technical documentation to get started!

Diagram of the HostedScan internal vulnerability scanning architecture: the HostedScan cloud platform connects over the public internet to a HostedScan Agent and OpenVAS engine running on a scan server inside a private network behind NAT and a firewall, using outbound-only HTTPS to api.hostedscan.com:443, while the agent scans internal devices such as VoIP phones, workstations, printers, and laptops.

Benefits of using HostedScan

Strengthen your
cybersecurity
resilience

Mitigate security vulnerabilities

Discover CVEs, OWASP Top 10 vulnerabilities, and exploitable weaknesses across your entire infrastructure. Get prioritized remediation guidance with CVSS scoring and actionable risk classifications—fix what matters first.

Learn more

Manage your risk exposure

With regulations such as GDPR and CCPA, failure to maintain reasonable security procedures is grounds for lawsuits and fines.

Get started

Meet compliance requirements

Vulnerability scanning is essential for your compliance with SOC 2, ISO 27001, cyber insurance, and more.

Learn more

Detect misconfigurations

90% of cyber attacks exploit simple misconfigurations, not zero-days. Detect exposed ports, weak credentials, outdated software, and common security gaps before attackers do—automatically, every day.

Get started

Map your attack surface

Your infrastructure changes constantly. Automatically discover and monitor all websites, servers, networks, and APIs—maintaining complete visibility of your attack surface without manual tracking.

Get started

Our Customers

5,000+ MSPs and IT teams who move faster

BbAmericas
Porsche
ExpediaGroup
WeMakeApps
SibylSoft
Luminary
CoinMe
Appetize
WonderProxy
Median
TaxiCaller
Yamaha
UniversityOfOxford

Speed and power,
without the complexity

The world's leading vulnerability scanners, all in one platform.

Loading call to action