Vulnerability intelligence
Product and version clues can be correlated with CVEs and associated intelligence. Results remain evidence for review: backports, proxies, hidden versions and configuration differences can affect applicability.
Scantide Auditor for Android turns a phone into a practical field-audit tool for authorized environments. Discover devices, identify what they probably are, inspect exposed services and security posture, correlate evidence with Scantide intelligence, and keep the reasoning visible so technicians can verify every conclusion.
Auditor combines several independent observations into one device view. A port, MAC address or banner is useful; multiple signals agreeing with each other are much more useful.
Find reachable devices and combine IP, MAC, hostname, service, mDNS, SSDP/UPnP, WSD and other observable evidence.
Classify servers, routers, switches, printers, NAS, cameras, hypervisors, BMCs and IoT devices with confidence and visible reasoning.
Review nearby wireless networks, security modes, signal/channel context and other Wi-Fi posture indicators Android exposes.
Observe BLE advertisements, Bluetooth SIG/company evidence, names, proximity signals and device-type clues without pairing.
Discover Wi-Fi Direct peers and use bounded Wi-Fi Aware/NAN discovery for participating Scantide peers where Android supports it.
Collect certificate identity, issuer, validity and naming evidence from HTTPS and other supported TLS-bearing services.
Review SMB signing/encryption signals and RDP/TLS certificate evidence without attempting credentials or interactive access.
Use normalized product/version evidence with Scantide backend intelligence to add vulnerability, exploitation and lifecycle context.
Compare discovered devices with configured ServiceNow/CMDB records and distinguish matched, not-found and lookup-error states.
Review available Android security posture including OS/API level, security patch, lock state, VPN, Private DNS, DNS and network context.
Keep local scan baselines and highlight new devices, service changes, identity changes and devices no longer seen on a revisited network.
Create persistent local reports, share them when needed, and delete individual, older or all stored reports from the app.
Device classification is deliberately transparent. Scantide can combine MAC/OUI, service combinations, HTTP titles, TLS identities, mDNS, SSDP/UPnP, WSD, BLE/SIG evidence and backend fingerprints, then show the evidence behind the resulting classification.
A device can be presented as a likely server, printer, NAS, router, camera, hypervisor or other class with a confidence level rather than an unexplained label.
Technicians can inspect the signals that produced the classification instead of treating the result as a black-box conclusion.
If automatic fingerprinting is wrong, locally reclassify the device. The technician override is remembered on the phone and can later be reset to automatic.
The same discovery evidence is interpreted in context so different device classes get findings that make sense for them.
Recognize IPP/IPPS, LPD, JetDirect/raw printing, web management and related exposure signals, then correlate product intelligence where identity is available.
Use RTSP, web interfaces, UPnP/SSDP and other observed signals to identify likely camera/media roles and highlight exposed management or cleartext protocols.
Combine characteristic services, web/TLS identity and discovery data to provide more useful context around storage, virtualization and management controllers.
A phone is useful because it can observe radio and local-network evidence at the same time. Auditor keeps these observations separate enough to be trustworthy while making them available together for analysis.
Review visible SSIDs, security modes, signal and channel context along with the phone's current network environment.
Collect advertised names, service and manufacturer/company identifiers, signal strength and other passive Bluetooth evidence.
Run bounded peer discovery where Android permits it. Wi-Fi Aware results are explicitly described as observed matching peers, not a wildcard inventory of every Aware-capable device nearby.
Auditor can inspect supported NFC tags/cards and includes an experimental reader-audit mode built around a synthetic Scantide HCE profile. The reader side is deliberately constrained to observation and controlled test responses.
Review NFC technologies and information Android can legitimately expose from a presented tag or card.
Use the Scantide-only synthetic AID to observe compatible reader interaction. On supported Android versions, polling evidence can distinguish reader activity from a reader actually selecting the Scantide test application.
Compare automatic identity, evidence, local technician classification and CMDB presence instead of relying on an IP address alone.
Review cleartext management protocols, HTTPS/TLS evidence, SMB security signals and unexpected administration surfaces.
Use visible product/version evidence with Scantide CVE, exploitation and lifecycle intelligence to prioritize follow-up.
CMDB correlation can show whether discovered infrastructure has a corresponding asset record and whether lookups succeeded.
Compare with the previous local baseline to highlight devices and service exposure that appeared, disappeared or changed.
Keep the underlying evidence available so findings can be reviewed by the technician rather than accepted blindly.
Use Auditor only on networks and equipment you own, manage or are explicitly authorized to assess. Android permissions and OEM restrictions affect which radio and local-device signals are available.
1. Download ScantideAuditor.apk
2. Open the APK on the Android device
3. Allow installation from this source if your policy permits it
4. Grant the permissions required for the intended checks
5. Use only on authorized networks and devicesFor managed company devices, MDM/private app distribution is generally preferable to ad-hoc sideloading because it gives cleaner control over versions and trust.
Auditor reports what it can actually observe. Hardware, Android version, OEM policy, runtime permissions and network controls can all change what is visible.
Wi-Fi, Bluetooth, Wi-Fi Direct and related discovery require Android permissions that vary by OS version. Missing permission should be treated differently from “nothing found.”
Wi-Fi Aware, NFC HCE/Observe Mode and other capabilities depend on both Android version and device hardware.
Some Android security settings are restricted by OEM or platform policy. Local Audit degrades per observation rather than declaring the entire audit unavailable.
When enough product/version evidence is available, Auditor can use Scantide backend intelligence to turn a raw device fingerprint into useful vulnerability and lifecycle context.
Product and version clues can be correlated with CVEs and associated intelligence. Results remain evidence for review: backports, proxies, hidden versions and configuration differences can affect applicability.
Where product identity is sufficiently strong, lifecycle information can help identify equipment or software that may be approaching or beyond vendor support.
Scantide Auditor is intended to help technicians understand systems, identify weaknesses or risky configurations and decide where security should be tightened. It is not an exploitation framework.
Run network and radio checks only where you have permission to perform the assessment.
Collect identity, protocol and security evidence without turning ordinary audit workflows into exploitation or credential attacks.
Use findings for asset ownership, patching, lifecycle review, firewall cleanup, protocol hardening and documentation.
No. It is an authorized visibility, inventory and defensive auditing tool. It does not include exploitation, password guessing, brute forcing or access-control bypass functionality.
No. Classification is based on observable evidence and confidence. Use the “Why Scantide thinks this” evidence to verify the conclusion, and locally reclassify a device when the technician knows better.
Some devices, services, network paths and Android/OEM implementations respond differently to lightweight probing. Missing evidence should not automatically be interpreted as proof that a capability is absent.
No. Android Wi-Fi Aware discovery is service based. Auditor can discover participating matching Scantide peers, but it cannot perform wildcard enumeration of unrelated Aware services.
No. Technician reclassification overrides are stored locally on the Android device unless a separate sharing mechanism is explicitly introduced in the future.
Android is strongest for mobile field work and combined LAN/radio visibility. The Windows and Linux editions are better suited to deeper repeatable host and network assessment from administrative systems. They complement each other.
The Scantide tools share the same goal—clear, actionable evidence—but are optimized for different environments.
Public-domain and external infrastructure review for TLS, DNS, headers, exposure, provider and related evidence.
Run Online scannerSearch software, packages, products and vulnerability identifiers against Scantide's correlated intelligence.
Open Software AnalyzerBrowser-visible website privacy, trackers, cookies, scripts, headers, infrastructure and security context while browsing.
Open Observe guideAndroid website/privacy analysis for URLs shared from browsers and other apps.
Open Observe MobileDeeper authorized internal-network and Windows assessment with inventory, service, posture and reporting workflows.
Open Windows AuditorLinux local server inventory, service, hardening, CVE and lifecycle assessment.
Open Linux Auditor