Mobile infrastructure intelligence

See what is really on the network.

Scantide Auditor for Android turns a phone into a practical field-audit tool for authorized environments. Discover devices, identify what they probably are, inspect exposed services and security posture, correlate evidence with Scantide intelligence, and keep the reasoning visible so technicians can verify every conclusion.

Observational Authorized use Agentless Evidence explained
Scantide Auditor Field audit
Device intelligence Identity, exposure, posture and change evidence in one view
LAN & radio discoveryCombined
Device classificationEvidence based
CVE / lifecycle contextCorrelated
Previous scan changesTracked locally
LANHosts & services
RadioWi-Fi / BLE / P2P
IntelCVE & lifecycle
Current capabilities

More than a mobile port scanner

Auditor combines several independent observations into one device view. A port, MAC address or banner is useful; multiple signals agreeing with each other are much more useful.

LAN discovery

Find reachable devices and combine IP, MAC, hostname, service, mDNS, SSDP/UPnP, WSD and other observable evidence.

Device intelligence

Classify servers, routers, switches, printers, NAS, cameras, hypervisors, BMCs and IoT devices with confidence and visible reasoning.

Wi-Fi security

Review nearby wireless networks, security modes, signal/channel context and other Wi-Fi posture indicators Android exposes.

Bluetooth & BLE

Observe BLE advertisements, Bluetooth SIG/company evidence, names, proximity signals and device-type clues without pairing.

Wi-Fi Direct & Aware

Discover Wi-Fi Direct peers and use bounded Wi-Fi Aware/NAN discovery for participating Scantide peers where Android supports it.

TLS & certificates

Collect certificate identity, issuer, validity and naming evidence from HTTPS and other supported TLS-bearing services.

SMB & RDP posture

Review SMB signing/encryption signals and RDP/TLS certificate evidence without attempting credentials or interactive access.

CVE & lifecycle context

Use normalized product/version evidence with Scantide backend intelligence to add vulnerability, exploitation and lifecycle context.

CMDB correlation

Compare discovered devices with configured ServiceNow/CMDB records and distinguish matched, not-found and lookup-error states.

Local Android audit

Review available Android security posture including OS/API level, security patch, lock state, VPN, Private DNS, DNS and network context.

What changed?

Keep local scan baselines and highlight new devices, service changes, identity changes and devices no longer seen on a revisited network.

Reports & evidence

Create persistent local reports, share them when needed, and delete individual, older or all stored reports from the app.

Explainable fingerprinting

Why Scantide thinks this

Device classification is deliberately transparent. Scantide can combine MAC/OUI, service combinations, HTTP titles, TLS identities, mDNS, SSDP/UPnP, WSD, BLE/SIG evidence and backend fingerprints, then show the evidence behind the resulting classification.

Identity with confidence

A device can be presented as a likely server, printer, NAS, router, camera, hypervisor or other class with a confidence level rather than an unexplained label.

Evidence stays visible

Technicians can inspect the signals that produced the classification instead of treating the result as a black-box conclusion.

Local reclassification

If automatic fingerprinting is wrong, locally reclassify the device. The technician override is remembered on the phone and can later be reset to automatic.

Important: local technician corrections remain local. They do not silently become shared Scantide fingerprint intelligence.
Specialized device review

Infrastructure, printers, cameras and IoT

The same discovery evidence is interpreted in context so different device classes get findings that make sense for them.

Printers & MFPs

Recognize IPP/IPPS, LPD, JetDirect/raw printing, web management and related exposure signals, then correlate product intelligence where identity is available.

Cameras & media devices

Use RTSP, web interfaces, UPnP/SSDP and other observed signals to identify likely camera/media roles and highlight exposed management or cleartext protocols.

NAS, hypervisors & BMCs

Combine characteristic services, web/TLS identity and discovery data to provide more useful context around storage, virtualization and management controllers.

Radio & proximity

See beyond the IP subnet

A phone is useful because it can observe radio and local-network evidence at the same time. Auditor keeps these observations separate enough to be trustworthy while making them available together for analysis.

Wi-Fi

Review visible SSIDs, security modes, signal and channel context along with the phone's current network environment.

BLE

Collect advertised names, service and manufacturer/company identifiers, signal strength and other passive Bluetooth evidence.

Wi-Fi Direct / Aware

Run bounded peer discovery where Android permits it. Wi-Fi Aware results are explicitly described as observed matching peers, not a wildcard inventory of every Aware-capable device nearby.

NFC

Inspect tags and safely audit reader behavior

Auditor can inspect supported NFC tags/cards and includes an experimental reader-audit mode built around a synthetic Scantide HCE profile. The reader side is deliberately constrained to observation and controlled test responses.

Tag / card inspection

Review NFC technologies and information Android can legitimately expose from a presented tag or card.

Reader audit

Use the Scantide-only synthetic AID to observe compatible reader interaction. On supported Android versions, polling evidence can distinguish reader activity from a reader actually selecting the Scantide test application.

Safety boundary: no cloning real cards, credential replay, brute force, key guessing, payment/access-card impersonation or authentication bypass.
Security posture

Turn observations into useful review questions

Is this device what we think it is?

Compare automatic identity, evidence, local technician classification and CMDB presence instead of relying on an IP address alone.

Is management exposed safely?

Review cleartext management protocols, HTTPS/TLS evidence, SMB security signals and unexpected administration surfaces.

Is it still supported?

Use visible product/version evidence with Scantide CVE, exploitation and lifecycle intelligence to prioritize follow-up.

Is it documented?

CMDB correlation can show whether discovered infrastructure has a corresponding asset record and whether lookups succeeded.

Did anything change?

Compare with the previous local baseline to highlight devices and service exposure that appeared, disappeared or changed.

Why was it flagged?

Keep the underlying evidence available so findings can be reviewed by the technician rather than accepted blindly.

Field workflow

How to use it

Use Auditor only on networks and equipment you own, manage or are explicitly authorized to assess. Android permissions and OEM restrictions affect which radio and local-device signals are available.

Typical assessment

  • Install the signed APK from the trusted Scantide source or your managed app distribution.
  • Grant only the Android permissions needed for the checks you intend to run.
  • Connect to the approved local network and run Discover with the appropriate scan profile.
  • Review Devices for identity, services, evidence, security posture and changes.
  • Run Bluetooth, Wi-Fi Direct/Aware or NFC checks when they are relevant to the site.
  • Use Local Audit for the Android device itself and CMDB correlation when configured.
  • Generate a report for handover, then retain or delete stored reports from the Reports view.

Installation note

1. Download ScantideAuditor.apk 2. Open the APK on the Android device 3. Allow installation from this source if your policy permits it 4. Grant the permissions required for the intended checks 5. Use only on authorized networks and devices

For managed company devices, MDM/private app distribution is generally preferable to ad-hoc sideloading because it gives cleaner control over versions and trust.

Permissions & Android limits

What Android allows matters

Auditor reports what it can actually observe. Hardware, Android version, OEM policy, runtime permissions and network controls can all change what is visible.

Radio permissions

Wi-Fi, Bluetooth, Wi-Fi Direct and related discovery require Android permissions that vary by OS version. Missing permission should be treated differently from “nothing found.”

Feature support

Wi-Fi Aware, NFC HCE/Observe Mode and other capabilities depend on both Android version and device hardware.

Local posture restrictions

Some Android security settings are restricted by OEM or platform policy. Local Audit degrades per observation rather than declaring the entire audit unavailable.

Scantide intelligence

CVE, exploitation and lifecycle context

When enough product/version evidence is available, Auditor can use Scantide backend intelligence to turn a raw device fingerprint into useful vulnerability and lifecycle context.

Vulnerability intelligence

Product and version clues can be correlated with CVEs and associated intelligence. Results remain evidence for review: backports, proxies, hidden versions and configuration differences can affect applicability.

Lifecycle intelligence

Where product identity is sufficiently strong, lifecycle information can help identify equipment or software that may be approaching or beyond vendor support.

Safety & scope

Built for defensive visibility

Scantide Auditor is intended to help technicians understand systems, identify weaknesses or risky configurations and decide where security should be tightened. It is not an exploitation framework.

Authorized environments

Run network and radio checks only where you have permission to perform the assessment.

Observational by design

Collect identity, protocol and security evidence without turning ordinary audit workflows into exploitation or credential attacks.

Actionable follow-up

Use findings for asset ownership, patching, lifecycle review, firewall cleanup, protocol hardening and documentation.

FAQ

Common questions

Is Scantide Auditor for Android a hacking tool?

No. It is an authorized visibility, inventory and defensive auditing tool. It does not include exploitation, password guessing, brute forcing or access-control bypass functionality.

Does a device classification prove the exact model?

No. Classification is based on observable evidence and confidence. Use the “Why Scantide thinks this” evidence to verify the conclusion, and locally reclassify a device when the technician knows better.

Why can RDP or certificate evidence be intermittent?

Some devices, services, network paths and Android/OEM implementations respond differently to lightweight probing. Missing evidence should not automatically be interpreted as proof that a capability is absent.

Does Wi-Fi Aware list every Aware device nearby?

No. Android Wi-Fi Aware discovery is service based. Auditor can discover participating matching Scantide peers, but it cannot perform wildcard enumeration of unrelated Aware services.

Are local device corrections uploaded?

No. Technician reclassification overrides are stored locally on the Android device unless a separate sharing mechanism is explicitly introduced in the future.

Why would I use this instead of only the Windows or Linux Auditor?

Android is strongest for mobile field work and combined LAN/radio visibility. The Windows and Linux editions are better suited to deeper repeatable host and network assessment from administrative systems. They complement each other.

Scantide product map

Use the right Scantide view for the job

The Scantide tools share the same goal—clear, actionable evidence—but are optimized for different environments.

Scantide Online

Public-domain and external infrastructure review for TLS, DNS, headers, exposure, provider and related evidence.

Run Online scanner

Software Analyzer

Search software, packages, products and vulnerability identifiers against Scantide's correlated intelligence.

Open Software Analyzer

Observe

Browser-visible website privacy, trackers, cookies, scripts, headers, infrastructure and security context while browsing.

Open Observe guide

Observe Mobile

Android website/privacy analysis for URLs shared from browsers and other apps.

Open Observe Mobile

Auditor Windows

Deeper authorized internal-network and Windows assessment with inventory, service, posture and reporting workflows.

Open Windows Auditor

Auditor Linux

Linux local server inventory, service, hardening, CVE and lifecycle assessment.

Open Linux Auditor
Need help choosing or setting this up? Use the main manual or contact Scantide.