This is a publishable, anonymized Scantide Auditor PowerShell example report. Real internal IP addresses, hostnames, domains, Wi-Fi names, Bluetooth device names, MAC/BSSID values and organization names have been replaced with generic example values while keeping the report structure, statistics and evidence style useful for evaluation.
Example coverage: internal network inventory, PowerShell network scanner output, open port review, TLS certificate audit, CVE intelligence, DNS coverage, CMDB comparison, ServiceNow-style asset coverage, Wi-Fi discovery and Bluetooth discovery.
| IP Address | Hostname | Discovery | CMDB Asset | CMDB Status | Port | Service | Server / Banner | CVE Alert | CVE Status | Page Title | Web Evidence | Certificate CN | Expiry | Issuer | TLS Versions |
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
10.10.10.85 | srv-071.corp.example.local | ICMP echo | SRV-071 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.84 | srv-070.corp.example.local | ICMP echo | SRV-070 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-070.corp.example.local | 2026-07-31 VALID62 days | srv-070.corp.example.local | TLS 1.3TLS 1.2 | |||
10.10.10.80 | srv-066.corp.example.local | ICMP echo | SRV-066 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-066.corp.example.local | 2026-11-14 VALID168 days | srv-066.corp.example.local | TLS 1.2 | |||
10.10.10.81 | srv-067.corp.example.local | ICMP echo | SRV-067 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-067.corp.example.local | 2026-08-29 VALID91 days | srv-067.corp.example.local | TLS 1.2 | |||
10.10.10.82 | srv-068.corp.example.local | ICMP echo | SRV-068 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-068.corp.example.local | 2026-08-29 VALID91 days | srv-068.corp.example.local | TLS 1.2 | |||
10.10.10.83 | srv-069.corp.example.local | ICMP echo | SRV-069 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | IIS Windows Server | None captured | None | |||||
10.10.10.83 | srv-069.corp.example.local | ICMP echo | SRV-069 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2022 (16.0.1000.6) [3 instances] | [-] Review (INFO) - Microsoft SQL Server 2022 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. Modern SQL Server release detected. Confirm current cumulative update/build before treating as clean. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.83 | srv-069.corp.example.local | ICMP echo | SRV-069 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-069.corp.example.local | 2026-09-30 VALID123 days | srv-069.corp.example.local | TLS 1.2 | |||
10.10.10.81 | srv-067.corp.example.local | ICMP echo | SRV-067 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.82 | srv-068.corp.example.local | ICMP echo | SRV-068 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.79 | srv-065.corp.example.local | ICMP echo | SRV-065 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-065.corp.example.local | 2026-11-14 VALID168 days | srv-065.corp.example.local | TLS 1.2 | |||
10.10.10.80 | srv-066.corp.example.local | ICMP echo | SRV-066 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.76 | srv-062.corp.example.local | ICMP echo | SRV-062 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | IIS Windows Server | None captured | None | |||||
10.10.10.77 | srv-063.corp.example.local | ICMP echo | SRV-063 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-063.corp.example.local | 2026-07-15 VALID46 days | srv-063.corp.example.local | TLS 1.2 | |||
10.10.10.78 | SRV-064 | ICMP echo | SRV-064 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.79 | srv-065.corp.example.local | ICMP echo | SRV-065 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.76 | srv-062.corp.example.local | ICMP echo | SRV-062 | [OK] In CMDB | 443 | HTTPS | Microsoft-IIS/10.0 | ASP.NET | IIS Windows Server | None captured | srv-062.corp.example.local | 2027-09-22 VALID480 days | ExampleCorp Internal Issuing CA 01 G2 | TLS 1.3TLS 1.2 | ||
10.10.10.78 | SRV-064 | ICMP echo | SRV-064 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-064.corp.example.local | 2026-08-09 VALID71 days | srv-064.corp.example.local | TLS 1.2 | |||
10.10.10.71 | srv-057.corp.example.local | ICMP echo | SRV-057 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.74 | srv-060.corp.example.local | ICMP echo | SRV-060 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-060.corp.example.local | 2026-07-10 VALID41 days | srv-060.corp.example.local | TLS 1.2 | |||
10.10.10.75 | srv-061.corp.example.local | ICMP echo | SRV-061 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-061.corp.example.local | 2026-07-11 VALID42 days | srv-061.corp.example.local | TLS 1.2 | |||
10.10.10.77 | srv-063.corp.example.local | ICMP echo | SRV-063 | [OK] In CMDB | 80 | HTTP | Microsoft-HTTPAPI/2.0 | Not Found | None captured | None | |||||
10.10.10.77 | srv-063.corp.example.local | ICMP echo | SRV-063 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.73 | srv-059.corp.example.local | ICMP echo | SRV-059 | [OK] In CMDB | 22 | SSH | SSH-2.0-OpenSSH_9.9 | 2 CVEs (CRITICAL) Highest: CVE-1999-0661 (Score: 10) Latest: CVE-2002-0083 (2002) | [OK] Verified (2/20 applicable) | None captured | None | ||||
10.10.10.76 | srv-062.corp.example.local | ICMP echo | SRV-062 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.69 | srv-055.corp.example.local | ICMP echo | SRV-055 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-055.corp.example.local | 2026-09-30 VALID123 days | srv-055.corp.example.local | TLS 1.2 | |||
10.10.10.73 | srv-059.corp.example.local | ICMP echo | SRV-059 | [OK] In CMDB | 443 | HTTPS | Apache | Test Page for the HTTP Server on Red Hat Enterprise Linux | None captured | srv-077.corp.example.local | 2027-12-01 VALID550 days | ExampleCorp Internal Issuing CA 01 G2 | TLS 1.3TLS 1.2 | ||
10.10.10.74 | srv-060.corp.example.local | ICMP echo | SRV-060 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.76 | srv-062.corp.example.local | ICMP echo | SRV-062 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-062.corp.example.local | 2027-09-22 VALID480 days | ExampleCorp Internal Issuing CA 01 G2 | TLS 1.3TLS 1.2 | |||
10.10.10.69 | srv-055.corp.example.local | ICMP echo | SRV-055 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.70 | srv-056.corp.example.local | ICMP echo | SRV-056 | [OK] In CMDB | 80 | HTTP | NetApp Application Server | Loading... | None captured | None | |||||
10.10.10.71 | srv-057.corp.example.local | ICMP echo | SRV-057 | [OK] In CMDB | 80 | HTTP | HTTP Server (no Server header) | Redirecting.. | None captured | None | |||||
10.10.10.71 | srv-057.corp.example.local | ICMP echo | SRV-057 | [OK] In CMDB | 443 | HTTPS | HTTPS Server (no Server header) | Redirecting.. | None captured | SRV-057 | 2026-07-25 VALID56 days | SRV-057 | TLS 1.3TLS 1.2 | ||
10.10.10.72 | srv-058.corp.example.local | ICMP echo | SRV-058 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-058.corp.example.local | 2026-10-21 VALID144 days | srv-058.corp.example.local | TLS 1.2 | |||
10.10.10.73 | srv-059.corp.example.local | ICMP echo | SRV-059 | [OK] In CMDB | 80 | HTTP | Apache | Test Page for the HTTP Server on Red Hat Enterprise Linux | None captured | None | |||||
10.10.10.75 | srv-061.corp.example.local | ICMP echo | SRV-061 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.70 | srv-056.corp.example.local | ICMP echo | SRV-056 | [OK] In CMDB | 443 | HTTPS | NetApp Application Server | Loading... | None captured | srv-056.corp.example.local | 2025-06-24 EXPIRED339 days ago | srv-056.corp.example.local | TLS 1.3TLS 1.2 | ||
10.10.10.70 | srv-056.corp.example.local | ICMP echo | SRV-056 | [OK] In CMDB | 3306 | MySQL | MySQL jHost '10.10.10.101' is not allowed to connect to this MySQL server | None captured | None | ||||||
10.10.10.71 | srv-057.corp.example.local | ICMP echo | SRV-057 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-057.corp.example.local | 2026-10-22 VALID145 days | srv-057.corp.example.local | TLS 1.2 | |||
10.10.10.72 | srv-058.corp.example.local | ICMP echo | SRV-058 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.66 | srv-052.corp.example.local | ICMP echo | SRV-052 | [OK] In CMDB | 9001 | HTTPS | HTTPS Server (no Server header) | [-] Review (INFO) - Product recognized, but no confirmed CVE range/exact-version match was found for version 9.0.82. Other versions have 20 documented CVEs, so treat this as a review item rather than clean. | [!] Review | Apache Tomcat/9.0.82 | None captured | srv-044.corp.example.local | 2028-04-07 VALID678 days | ExampleCorp Internal Issuing CA 01 G2 | TLS 1.3TLS 1.2 |
10.10.10.67 | srv-053.corp.example.local | ICMP echo | SRV-053 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.67 | srv-053.corp.example.local | ICMP echo | SRV-053 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-053.corp.example.local | 2026-09-26 VALID119 days | srv-053.corp.example.local | TLS 1.2 | |||
10.10.10.68 | srv-054.corp.example.local | ICMP echo | SRV-054 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.68 | srv-054.corp.example.local | ICMP echo | SRV-054 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-054.corp.example.local | 2026-09-26 VALID119 days | srv-054.corp.example.local | TLS 1.2 | |||
10.10.10.70 | srv-056.corp.example.local | ICMP echo | SRV-056 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.70 | srv-056.corp.example.local | ICMP echo | SRV-056 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-056.corp.example.local | 2026-10-27 VALID150 days | srv-056.corp.example.local | TLS 1.2 | |||
10.10.10.12 | srv-029.corp.example.local | ICMP echo | SRV-029 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.12 | srv-029.corp.example.local | ICMP echo | SRV-029 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-029.corp.example.local | 2026-11-22 VALID176 days | srv-029.corp.example.local | TLS 1.2 | |||
10.10.10.12 | srv-029.corp.example.local | ICMP echo | SRV-029 | [OK] In CMDB | 8080 | HTTP | Payara Server 5.2022.5 #badassfish | 1 CVEs (CRITICAL) Highest: CVE-2023-28462 (Score: 9.8) | [OK] Verified (1/8 applicable) | Payara Server - Server Running | None captured | None | |||
10.10.10.13 | N/A | ICMP echo | SRV-080 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.13 | N/A | ICMP echo | SRV-080 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | SRV-080.examplecorp.local | 2026-08-23 VALID85 days | SRV-080.examplecorp.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.14 | N/A | ICMP echo | SRV-081 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.14 | N/A | ICMP echo | SRV-081 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | SRV-081.examplecorp.local | 2026-08-23 VALID85 days | SRV-081.examplecorp.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.15 | srv-001.corp.example.local | ICMP echo | SRV-001 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.15 | srv-001.corp.example.local | ICMP echo | SRV-001 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-001.corp.example.local | 2026-07-31 VALID62 days | srv-001.corp.example.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.16 | SRV-082 | ICMP echo | SRV-082 | [OK] In CMDB | 22 | SSH | SSH-2.0-OpenSSH_7.2 | 3 CVEs (CRITICAL) Highest: CVE-1999-0661 (Score: 10) Latest: CVE-2002-0083 (2002) | [OK] Verified (3/20 applicable) | None captured | None | ||||
10.10.10.16 | SRV-082 | ICMP echo | SRV-082 | [OK] In CMDB | 25 | SMTP | 220 localhost ESMTP | None captured | None | ||||||
10.10.10.16 | SRV-082 | ICMP echo | SRV-082 | [OK] In CMDB | 80 | HTTP | nginx | Not Found | None captured | None | |||||
10.10.10.16 | SRV-082 | ICMP echo | SRV-082 | [OK] In CMDB | 443 | HTTPS | nginx | Not Found | None captured | legal.examplecorp.local | 2029-10-02 VALID1221 days | ExampleCorp Internal Issuing CA 01 G2 | TLS 1.3TLS 1.2 | ||
10.10.10.16 | SRV-082 | ICMP echo | SRV-082 | [OK] In CMDB | 8080 | HTTP | nginx | 403 Forbidden | None captured | None | |||||
10.10.10.17 | srv-003.corp.example.local | ICMP echo | SRV-003 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | 4.0.30319 | 5.2 | Home Page - SAP Wrapping Service | None captured | None | |||||
10.10.10.17 | srv-003.corp.example.local | ICMP echo | SRV-003 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.17 | srv-003.corp.example.local | ICMP echo | SRV-003 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-003.corp.example.local | 2026-09-20 VALID113 days | srv-003.corp.example.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.17 | srv-003.corp.example.local | ICMP echo | SRV-003 | [OK] In CMDB | 8080 | HTTP | Microsoft-IIS/10.0 | ASP.NET | 4.0.30319 | 5.2 | Home Page - SAP Wrapping Service | None captured | None | |||||
10.10.10.18 | srv-004.corp.example.local | ICMP echo | SRV-004 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | 4.0.30319 | 5.2 | Home Page - SAP Wrapping Service | None captured | None | |||||
10.10.10.18 | srv-004.corp.example.local | ICMP echo | SRV-004 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.18 | srv-004.corp.example.local | ICMP echo | SRV-004 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-004.corp.example.local | 2026-09-09 VALID102 days | srv-004.corp.example.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.18 | srv-004.corp.example.local | ICMP echo | SRV-004 | [OK] In CMDB | 8080 | HTTP | Microsoft-IIS/10.0 | ASP.NET | 4.0.30319 | Runtime Error | None captured | None | |||||
10.10.10.19 | srv-005.corp.example.local | ICMP echo | SRV-005 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.19 | srv-005.corp.example.local | ICMP echo | SRV-005 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2017 (14.0.1000.169) | [-] Review (WARNING) - Microsoft SQL Server 2017 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. This SQL Server generation is older and should be reviewed for support status, cumulative updates and exposure. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.19 | srv-005.corp.example.local | ICMP echo | SRV-005 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-005.corp.example.local | 2026-09-09 VALID102 days | srv-005.corp.example.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.20 | srv-006.corp.example.local | ICMP echo | SRV-006 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | [-] Review (UNKNOWN) - Ignored generic/short product token: "ce" is too ambiguous for reliable CVE lookup by itself. Capture the surrounding product context, for example pfSense CE, GitLab CE, Java SE, or the real server/banner name. | [!] Review | OT Intelligent Capture for SAP Solutions CE 23.4 | None captured | None | |||
10.10.10.20 | srv-006.corp.example.local | ICMP echo | SRV-006 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.20 | srv-006.corp.example.local | ICMP echo | SRV-006 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-006.corp.example.local | 2026-08-09 VALID71 days | srv-006.corp.example.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.21 | srv-035.corp.example.local | ICMP echo | SRV-035 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.21 | srv-035.corp.example.local | ICMP echo | SRV-035 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-035.corp.example.local | 2026-11-22 VALID176 days | srv-035.corp.example.local | TLS 1.2 | |||
10.10.10.22 | srv-007.corp.example.local | ICMP echo | SRV-007 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.22 | srv-007.corp.example.local | ICMP echo | SRV-007 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-007.corp.example.local | 2026-11-09 VALID163 days | srv-007.corp.example.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.23 | srv-008.corp.example.local | ICMP echo | SRV-008 | [OK] In CMDB | 80 | HTTP | HTTP Server (no Server header) | None captured | None | ||||||
10.10.10.23 | srv-008.corp.example.local | ICMP echo | SRV-008 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.23 | srv-008.corp.example.local | ICMP echo | SRV-008 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-008.corp.example.local | 2026-07-26 VALID57 days | srv-008.corp.example.local | TLS 1.2 | |||
10.10.10.24 | srv-009.corp.example.local | ICMP echo | SRV-009 | [OK] In CMDB | 80 | HTTP | Microsoft-HTTPAPI/2.0 | None captured | None | ||||||
10.10.10.24 | srv-009.corp.example.local | ICMP echo | SRV-009 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.24 | srv-009.corp.example.local | ICMP echo | SRV-009 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-009.corp.example.local | 2026-07-28 VALID59 days | srv-009.corp.example.local | TLS 1.2 | |||
10.10.10.25 | srv-011.corp.example.local | ICMP echo | SRV-011 | [OK] In CMDB | 80 | HTTP | Microsoft-HTTPAPI/2.0 | Not Found | None captured | None | |||||
10.10.10.25 | srv-011.corp.example.local | ICMP echo | SRV-011 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.25 | srv-011.corp.example.local | ICMP echo | SRV-011 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-011.corp.example.local | 2026-07-20 VALID51 days | srv-011.corp.example.local | TLS 1.2 | |||
10.10.10.26 | srv-013.corp.example.local | ICMP echo | SRV-013 | [OK] In CMDB | 80 | HTTP | Microsoft-HTTPAPI/2.0 | Not Found | None captured | None | |||||
10.10.10.26 | srv-013.corp.example.local | ICMP echo | SRV-013 | [OK] In CMDB | 443 | HTTPS | Microsoft-IIS/10.0 | ASP.NET | 403 - Forbidden: Access is denied. | None captured | srv-013.corp.example.local | 2021-03-20 EXPIRED1896 days ago | srv-013.corp.example.local | TLS 1.3TLS 1.2TLS 1.1TLS 1.0 | ||
10.10.10.26 | srv-013.corp.example.local | ICMP echo | SRV-013 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.26 | srv-013.corp.example.local | ICMP echo | SRV-013 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-013.corp.example.local | 2026-09-14 VALID107 days | srv-013.corp.example.local | TLS 1.3TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.26 | srv-013.corp.example.local | ICMP echo | SRV-013 | [OK] In CMDB | 8080 | HTTP | Microsoft-IIS/10.0 | ASP.NET | 403 - Forbidden: Access is denied. | None captured | None | |||||
10.10.10.27 | srv-014.corp.example.local | ICMP echo | SRV-014 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | 401 - Unauthorized: Access is denied due to invalid credentials. | None captured | None | |||||
10.10.10.27 | srv-014.corp.example.local | ICMP echo | SRV-014 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.27 | srv-014.corp.example.local | ICMP echo | SRV-014 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-014.corp.example.local | 2026-08-16 VALID78 days | srv-014.corp.example.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.28 | srv-015.corp.example.local | ICMP echo | SRV-015 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | IIS Windows Server | None captured | None | |||||
10.10.10.28 | srv-015.corp.example.local | ICMP echo | SRV-015 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.28 | srv-015.corp.example.local | ICMP echo | SRV-015 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-015.corp.example.local | 2026-08-30 VALID92 days | srv-015.corp.example.local | TLS 1.2 | |||
10.10.10.29 | srv-017.corp.example.local | ICMP echo | SRV-017 | [OK] In CMDB | 80 | HTTP | HTTP Server (no Server header) | Login - CXO Software | None captured | None | |||||
10.10.10.29 | srv-017.corp.example.local | ICMP echo | SRV-017 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.29 | srv-017.corp.example.local | ICMP echo | SRV-017 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-017.corp.example.local | 2026-09-08 VALID101 days | srv-017.corp.example.local | TLS 1.2 | |||
10.10.10.30 | srv-019.corp.example.local | ICMP echo | SRV-019 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.30 | srv-019.corp.example.local | ICMP echo | SRV-019 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-019.corp.example.local | 2026-09-09 VALID102 days | srv-019.corp.example.local | TLS 1.2 | |||
10.10.10.30 | srv-019.corp.example.local | ICMP echo | SRV-019 | [OK] In CMDB | 8080 | HTTP | HTTP Server (no Server header) | Header issues: 8Headers checked Show scripts, beacons, cookies, inline code, and header evaluationCaptured HTTP security-relevant response headers
HTTP security header / browser policy evaluation
| None | ||||||
10.10.10.30 | srv-019.corp.example.local | ICMP echo | SRV-019 | [OK] In CMDB | 8443 | HTTPS | HTTPS Server (no Server header) | Header issues: 9Headers checked Show scripts, beacons, cookies, inline code, and header evaluationCaptured HTTP security-relevant response headers
HTTP security header / browser policy evaluation
| SRV-019 | 2030-11-01 VALID1616 days | SRV-019 | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.31 | srv-020.corp.example.local | ICMP echo | SRV-020 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.31 | srv-020.corp.example.local | ICMP echo | SRV-020 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-020.corp.example.local | 2026-09-20 VALID113 days | srv-020.corp.example.local | TLS 1.2 | |||
10.10.10.31 | srv-020.corp.example.local | ICMP echo | SRV-020 | [OK] In CMDB | 8080 | HTTP | HTTP Server (no Server header) | Header issues: 8Headers checked Show scripts, beacons, cookies, inline code, and header evaluationCaptured HTTP security-relevant response headers
HTTP security header / browser policy evaluation
| None | ||||||
10.10.10.31 | srv-020.corp.example.local | ICMP echo | SRV-020 | [OK] In CMDB | 8443 | HTTPS | HTTPS Server (no Server header) | Header issues: 9Headers checked Show scripts, beacons, cookies, inline code, and header evaluationCaptured HTTP security-relevant response headers
HTTP security header / browser policy evaluation
| SRV-020 | 2030-11-07 VALID1622 days | SRV-020 | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.32 | srv-022.corp.example.local | ICMP echo | SRV-022 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.32 | srv-022.corp.example.local | ICMP echo | SRV-022 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-022.corp.example.local | 2026-09-28 VALID121 days | srv-022.corp.example.local | TLS 1.2 | |||
10.10.10.33 | srv-023.corp.example.local | ICMP echo | SRV-023 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.33 | srv-023.corp.example.local | ICMP echo | SRV-023 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-023.corp.example.local | 2026-10-25 VALID148 days | srv-023.corp.example.local | TLS 1.2 | |||
10.10.10.33 | srv-023.corp.example.local | ICMP echo | SRV-023 | [OK] In CMDB | 8080 | HTTP | HTTP Server (no Server header) | Header issues: 8Headers checked Show scripts, beacons, cookies, inline code, and header evaluationCaptured HTTP security-relevant response headers
HTTP security header / browser policy evaluation
| None | ||||||
10.10.10.34 | srv-024.corp.example.local | ICMP echo | SRV-024 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.34 | srv-024.corp.example.local | ICMP echo | SRV-024 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2022 (16.0.1000.6) | [-] Review (INFO) - Microsoft SQL Server 2022 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. Modern SQL Server release detected. Confirm current cumulative update/build before treating as clean. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.34 | srv-024.corp.example.local | ICMP echo | SRV-024 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-024.corp.example.local | 2026-11-22 VALID176 days | srv-024.corp.example.local | TLS 1.2 | |||
10.10.10.35 | srv-026.corp.example.local | ICMP echo | SRV-026 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.35 | srv-026.corp.example.local | ICMP echo | SRV-026 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2017 (14.0.1000.169) | [-] Review (WARNING) - Microsoft SQL Server 2017 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. This SQL Server generation is older and should be reviewed for support status, cumulative updates and exposure. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.35 | srv-026.corp.example.local | ICMP echo | SRV-026 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-026.corp.example.local | 2026-11-22 VALID176 days | srv-026.corp.example.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.36 | srv-027.corp.example.local | ICMP echo | SRV-027 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.36 | srv-027.corp.example.local | ICMP echo | SRV-027 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-027.corp.example.local | 2026-10-25 VALID148 days | srv-027.corp.example.local | TLS 1.3TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.36 | srv-027.corp.example.local | ICMP echo | SRV-027 | [OK] In CMDB | 8080 | HTTP | WildFly (title evidence; Server header not captured) | Welcome to WildFly | Header issues: 8Headers checked Show scripts, beacons, cookies, inline code, and header evaluationCaptured HTTP security-relevant response headers
HTTP security header / browser policy evaluation
| None | |||||
10.10.10.36 | srv-027.corp.example.local | ICMP echo | SRV-027 | [OK] In CMDB | 8443 | HTTPS | HTTPS Server (no Server header) | Welcome to WildFly | Header issues: 9Headers checked Show scripts, beacons, cookies, inline code, and header evaluationCaptured HTTP security-relevant response headers
HTTP security header / browser policy evaluation
| localhost | 2036-01-21 VALID3523 days | localhost | TLS 1.2 | ||
10.10.10.37 | N/A | ICMP echo | SRV-083 | [OK] In CMDB | 80 | HTTP | HTTP Server (no Server header) | Header issues: 8Headers checked Show scripts, beacons, cookies, inline code, and header evaluationCaptured HTTP security-relevant response headers
HTTP security header / browser policy evaluation
| None | ||||||
10.10.10.37 | N/A | ICMP echo | SRV-083 | [OK] In CMDB | 443 | HTTPS | HTTPS Server (no Server header) | Header issues: 9Headers checked Show scripts, beacons, cookies, inline code, and header evaluationCaptured HTTP security-relevant response headers
HTTP security header / browser policy evaluation
| localhost | 2036-01-20 VALID3522 days | localhost | TLS 1.2 | |||
10.10.10.37 | N/A | ICMP echo | SRV-083 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.37 | N/A | ICMP echo | SRV-083 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2017 (14.0.1000.169) | [-] Review (WARNING) - Microsoft SQL Server 2017 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. This SQL Server generation is older and should be reviewed for support status, cumulative updates and exposure. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.37 | N/A | ICMP echo | SRV-083 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | SRV-083.examplecorpexternal.com | 2026-10-26 VALID149 days | SRV-083.examplecorpexternal.com | TLS 1.3TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.38 | srv-030.corp.example.local | ICMP echo | SRV-030 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.38 | srv-030.corp.example.local | ICMP echo | SRV-030 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-030.corp.example.local | 2026-08-28 VALID90 days | srv-030.corp.example.local | TLS 1.2 | |||
10.10.10.38 | srv-030.corp.example.local | ICMP echo | SRV-030 | [OK] In CMDB | 8000 | HTTP | Kestrel | BPS Visualization web | None captured | None | |||||
10.10.10.38 | srv-030.corp.example.local | ICMP echo | SRV-030 | [OK] In CMDB | 8080 | HTTP | DelphiMVCFramework | DMVCFramework 3.2.1 (carbon) | [?] Review (UNKNOWN) - Unmapped product: no reliable CVE product mapping was found for this banner. It may be proprietary, renamed, embedded, or device-specific. | [!] Review | DMVCFramework Exception | None captured | None | |||
10.10.10.39 | srv-032.corp.example.local | ICMP echo | SRV-032 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.39 | srv-032.corp.example.local | ICMP echo | SRV-032 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-032.corp.example.local | 2026-09-03 VALID96 days | srv-032.corp.example.local | TLS 1.2 | |||
10.10.10.40 | srv-033.corp.example.local | ICMP echo | SRV-033 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.40 | srv-033.corp.example.local | ICMP echo | SRV-033 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-033.corp.example.local | 2026-09-03 VALID96 days | srv-033.corp.example.local | TLS 1.2 | |||
10.10.10.40 | srv-033.corp.example.local | ICMP echo | SRV-033 | [OK] In CMDB | 8080 | HTTP | HTTP Server (no Server header) | Header issues: 8Headers checked Show scripts, beacons, cookies, inline code, and header evaluationCaptured HTTP security-relevant response headers
HTTP security header / browser policy evaluation
| None | ||||||
10.10.10.41 | srv-031.corp.example.local | ICMP echo | DEFR-SRV-174 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.41 | srv-031.corp.example.local | ICMP echo | DEFR-SRV-174 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2019 (15.0.2000.5) | 4 CVEs (CRITICAL) Highest: CVE-2021-38159 (Score: 9.8) Latest: CVE-2023-34362 (2023) | [OK] Verified (4/6 applicable) | None captured | None | ||||
10.10.10.41 | srv-031.corp.example.local | ICMP echo | DEFR-SRV-174 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-031.corp.example.local | 2026-09-02 VALID95 days | srv-031.corp.example.local | TLS 1.2 | |||
10.10.10.42 | srv-034.corp.example.local | ICMP echo | SRV-034 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.42 | srv-034.corp.example.local | ICMP echo | SRV-034 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-034.corp.example.local | 2026-10-01 VALID124 days | srv-034.corp.example.local | TLS 1.2 | |||
10.10.10.43 | srv-040.corp.example.local | ICMP echo | SRV-040 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | IIS Windows Server | None captured | None | |||||
10.10.10.43 | srv-040.corp.example.local | ICMP echo | SRV-040 | [OK] In CMDB | 443 | HTTPS | Microsoft-IIS/10.0 | ASP.NET | IIS Windows Server | None captured | srv-040.corp.example.local | 2029-10-06 VALID1225 days | ExampleCorp Internal Issuing CA 01 G2 | TLS 1.2 | ||
10.10.10.43 | srv-040.corp.example.local | ICMP echo | SRV-040 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.43 | srv-040.corp.example.local | ICMP echo | SRV-040 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-040.corp.example.local | 2026-07-16 VALID47 days | srv-040.corp.example.local | TLS 1.2 | |||
10.10.10.44 | srv-072.corp.example.local | ICMP echo | SRV-072 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.44 | srv-072.corp.example.local | ICMP echo | SRV-072 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-072.corp.example.local | 2026-09-12 VALID105 days | srv-072.corp.example.local | TLS 1.2 | |||
10.10.10.45 | srv-037.corp.example.local | ICMP echo | SRV-037 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | IIS Windows Server | None captured | None | |||||
10.10.10.45 | srv-037.corp.example.local | ICMP echo | SRV-037 | [OK] In CMDB | 443 | HTTPS | Microsoft-IIS/10.0 | ASP.NET | IIS Windows Server | None captured | srv-037.corp.example.local | 2026-09-14 VALID107 days | ExampleCorp Internal Issuing CA 01 G2 | TLS 1.2 | ||
10.10.10.45 | srv-037.corp.example.local | ICMP echo | SRV-037 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.45 | srv-037.corp.example.local | ICMP echo | SRV-037 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-037.corp.example.local | 2026-07-14 VALID45 days | srv-037.corp.example.local | TLS 1.2 | |||
10.10.10.46 | srv-038.corp.example.local | ICMP echo | SRV-038 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | IIS Windows Server | None captured | None | |||||
10.10.10.46 | srv-038.corp.example.local | ICMP echo | SRV-038 | [OK] In CMDB | 443 | HTTPS | Microsoft-IIS/10.0 | ASP.NET | IIS Windows Server | None captured | srv-038.corp.example.local | 2026-09-14 VALID107 days | ExampleCorp Internal Issuing CA 01 G2 | TLS 1.2 | ||
10.10.10.46 | srv-038.corp.example.local | ICMP echo | SRV-038 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.46 | srv-038.corp.example.local | ICMP echo | SRV-038 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-038.corp.example.local | 2026-07-14 VALID45 days | srv-038.corp.example.local | TLS 1.2 | |||
10.10.10.47 | SRV-084.examplecorp.local | ICMP echo | SRV-084 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.47 | SRV-084.examplecorp.local | ICMP echo | SRV-084 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | SRV-084.examplecorp.local | 2026-08-04 VALID66 days | SRV-084.examplecorp.local | TLS 1.2 | |||
10.10.10.48 | N/A | ICMP echo | DEFRADXR001 | [OK] In CMDB | 139 | NetBIOS | NetBIOS (SMB1) | None captured | None | ||||||
10.10.10.48 | N/A | ICMP echo | DEFRADXR001 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.48 | N/A | ICMP echo | DEFRADXR001 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | DEFRADXR001.examplecorpexternal.com | 2026-08-12 VALID74 days | DEFRADXR001.examplecorpexternal.com | TLS 1.2 | |||
10.10.10.49 | srv-075.corp.example.local | ICMP echo | SRV-074 | [OK] In CMDB | 21 | FTP | 220 Microsoft FTP Service | None captured | None | ||||||
10.10.10.49 | srv-075.corp.example.local | ICMP echo | SRV-074 | [OK] In CMDB | 22 | SSH | SSH-2.0-9.39 FlowSsh: Bitvise SSH Server (WinSSHD) 9.39 | 1 CVEs (MEDIUM) Highest: CVE-2002-0460 (Score: 5) | [OK] Verified | None captured | None | ||||
10.10.10.49 | srv-075.corp.example.local | ICMP echo | SRV-074 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.49 | srv-075.corp.example.local | ICMP echo | SRV-074 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-074.corp.example.local | 2026-08-19 VALID81 days | srv-074.corp.example.local | TLS 1.2 | |||
10.10.10.50 | srv-073.corp.example.local | ICMP echo | SRV-073 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.50 | srv-073.corp.example.local | ICMP echo | SRV-073 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-073.corp.example.local | 2026-08-07 VALID69 days | srv-073.corp.example.local | TLS 1.2 | |||
10.10.10.51 | SRV-085 | ICMP echo | SRV-085 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.51 | SRV-085 | ICMP echo | SRV-085 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | SRV-085 | 2026-08-12 VALID74 days | SRV-085 | TLS 1.2 | |||
10.10.10.52 | srv-076.corp.example.local | ICMP echo | SRV-086 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | ASP.NET | None captured | None | ||||||
10.10.10.52 | srv-076.corp.example.local | ICMP echo | SRV-086 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.52 | srv-076.corp.example.local | ICMP echo | SRV-086 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server (version detection failed) | None captured | None | ||||||
10.10.10.52 | srv-076.corp.example.local | ICMP echo | SRV-086 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | SRV-086.examplecorpexternal.com | 2026-09-13 VALID106 days | SRV-086.examplecorpexternal.com | TLS 1.2 | |||
10.10.10.53 | N/A | ICMP echo | SRV-087 | [OK] In CMDB | 80 | HTTP | Microsoft-HTTPAPI/2.0 | Not Found | None captured | None | |||||
10.10.10.53 | N/A | ICMP echo | SRV-087 | [OK] In CMDB | 443 | HTTPS | Microsoft-HTTPAPI/2.0 | Not Found | None captured | Dealerweb2016.example.local | 2024-09-04 EXPIRED632 days ago | Dealerweb2016.example.local | TLS 1.2 | ||
10.10.10.53 | N/A | ICMP echo | SRV-087 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.53 | N/A | ICMP echo | SRV-087 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | SRV-087.examplecorpexternal.com | 2026-07-27 VALID58 days | SRV-087.examplecorpexternal.com | TLS 1.2 | |||
10.10.10.54 | N/A | ICMP echo | SRV-088 | [OK] In CMDB | 80 | HTTP | Microsoft-HTTPAPI/2.0 | Not Found | None captured | None | |||||
10.10.10.54 | N/A | ICMP echo | SRV-088 | [OK] In CMDB | 443 | HTTPS | Microsoft-HTTPAPI/2.0 | Not Found | None captured | dealerweb2016.example.local | 2024-09-15 EXPIRED621 days ago | dealerweb2016.example.local | TLS 1.2 | ||
10.10.10.54 | N/A | ICMP echo | SRV-088 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.54 | N/A | ICMP echo | SRV-088 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | SRV-088.examplecorpexternal.com | 2026-08-26 VALID88 days | SRV-088.examplecorpexternal.com | TLS 1.2 | |||
10.10.10.55 | N/A | ICMP echo | SRV-090 | [OK] In CMDB | 80 | HTTP | Microsoft-HTTPAPI/2.0 | Not Found | None captured | None | |||||
10.10.10.55 | N/A | ICMP echo | SRV-090 | [OK] In CMDB | 443 | HTTPS | Microsoft-HTTPAPI/2.0 | Not Found | None captured | dealerweb.example.local | 2025-10-15 EXPIRED226 days ago | ExampleCorp Internal Issuing CA 01 G2 | TLS 1.2 | ||
10.10.10.55 | N/A | ICMP echo | SRV-090 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.55 | N/A | ICMP echo | SRV-090 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | SRV-090.examplecorpexternal.com | 2026-08-26 VALID88 days | SRV-090.examplecorpexternal.com | TLS 1.2 | |||
10.10.10.56 | srv-042.corp.example.local | ICMP echo | SRV-042 | [OK] In CMDB | 80 | HTTP | Microsoft-IIS/10.0 | 1 CVEs (CRITICAL) Highest: CVE-1999-0561 (Score: 10) | [OK] Verified (1/20 applicable) | srv-042.corp.example.local - / | None captured | None | |||
10.10.10.56 | srv-042.corp.example.local | ICMP echo | SRV-042 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.56 | srv-042.corp.example.local | ICMP echo | SRV-042 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-042.corp.example.local | 2026-11-22 VALID176 days | srv-042.corp.example.local | TLS 1.2 | |||
10.10.10.57 | srv-078.corp.example.local | ICMP echo | SRV-079 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.57 | srv-078.corp.example.local | ICMP echo | SRV-079 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-079.corp.example.local | 2026-08-04 VALID66 days | srv-079.corp.example.local | TLS 1.2 | |||
10.10.10.58 | srv-044.corp.example.local | ICMP echo | SRV-044 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.58 | srv-044.corp.example.local | ICMP echo | SRV-044 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-044.corp.example.local | 2026-09-25 VALID118 days | srv-044.corp.example.local | TLS 1.2 | |||
10.10.10.58 | srv-044.corp.example.local | ICMP echo | SRV-044 | [OK] In CMDB | 9001 | HTTPS | HTTPS Server (no Server header) | [-] Review (INFO) - Product recognized, but no confirmed CVE range/exact-version match was found for version 9.0.82. Other versions have 20 documented CVEs, so treat this as a review item rather than clean. | [!] Review | Apache Tomcat/9.0.82 | None captured | srv-044.corp.example.local | 2028-04-07 VALID678 days | ExampleCorp Internal Issuing CA 01 G2 | TLS 1.3TLS 1.2 |
10.10.10.59 | srv-045.corp.example.local | ICMP echo | SRV-045 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.59 | srv-045.corp.example.local | ICMP echo | SRV-045 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-045.corp.example.local | 2026-09-26 VALID119 days | srv-045.corp.example.local | TLS 1.2 | |||
10.10.10.60 | srv-046.corp.example.local | ICMP echo | SRV-046 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.60 | srv-046.corp.example.local | ICMP echo | SRV-046 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-046.corp.example.local | 2026-09-26 VALID119 days | srv-046.corp.example.local | TLS 1.2 | |||
10.10.10.61 | srv-047.corp.example.local | ICMP echo | SRV-047 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.61 | srv-047.corp.example.local | ICMP echo | SRV-047 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-047.corp.example.local | 2026-09-28 VALID121 days | srv-047.corp.example.local | TLS 1.2 | |||
10.10.10.62 | srv-048.corp.example.local | ICMP echo | SRV-048 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.62 | srv-048.corp.example.local | ICMP echo | SRV-048 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-048.corp.example.local | 2026-09-25 VALID118 days | srv-048.corp.example.local | TLS 1.2 | |||
10.10.10.63 | srv-049.corp.example.local | ICMP echo | SRV-049 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.63 | srv-049.corp.example.local | ICMP echo | SRV-049 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-049.corp.example.local | 2026-09-26 VALID119 days | srv-049.corp.example.local | TLS 1.2 | |||
10.10.10.64 | srv-050.corp.example.local | ICMP echo | SRV-050 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.64 | srv-050.corp.example.local | ICMP echo | SRV-050 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-050.corp.example.local | 2026-09-25 VALID118 days | srv-050.corp.example.local | TLS 1.2 | |||
10.10.10.65 | srv-051.corp.example.local | ICMP echo | SRV-051 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.65 | srv-051.corp.example.local | ICMP echo | SRV-051 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-051.corp.example.local | 2026-09-25 VALID118 days | srv-051.corp.example.local | TLS 1.2 | |||
10.10.10.66 | srv-052.corp.example.local | ICMP echo | SRV-052 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.66 | srv-052.corp.example.local | ICMP echo | SRV-052 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-052.corp.example.local | 2026-09-25 VALID118 days | srv-052.corp.example.local | TLS 1.2 | |||
10.10.10.83 | srv-069.corp.example.local | ICMP echo | SRV-069 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.84 | srv-070.corp.example.local | ICMP echo | SRV-070 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.85 | srv-071.corp.example.local | ICMP echo | SRV-071 | [OK] In CMDB | 80 | HTTP | Microsoft-HTTPAPI/2.0 | None captured | None | ||||||
10.10.10.86 | N/A | ICMP echo | SRV-091 | [OK] In CMDB | 22 | SSH | SSH-2.0-OpenSSH_8.7 | 1 CVEs (MEDIUM) Highest: CVE-2016-20012 (Score: 5.3) | [OK] Verified | None captured | None | ||||
10.10.10.85 | srv-071.corp.example.local | ICMP echo | SRV-071 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-071.corp.example.local | 2026-07-27 VALID58 days | srv-071.corp.example.local | TLS 1.3TLS 1.2 | |||
10.10.10.85 | srv-071.corp.example.local | ICMP echo | SRV-071 | [OK] In CMDB | 443 | HTTPS | Microsoft-HTTPAPI/2.0 | None captured | srv-071.corp.example.local | 2027-03-02 VALID276 days | Sectigo Public Server Authentication CA DV R36 | TLS 1.3TLS 1.2 | |||
10.10.10.11 | N/A | ICMP echo | [!] Not in CMDB | Discovered Host | Discovered host No checked TCP service answered. | None captured | None | ||||||||
10.10.10.88 | srv-002.corp.example.local | ICMP echo | SRV-002 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.89 | srv-010.corp.example.local | ICMP echo | SRV-010 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.90 | srv-012.corp.example.local | ICMP echo | SRV-012 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.90 | srv-012.corp.example.local | ICMP echo | SRV-012 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2016 (13.0.7080.1) [2 instances] | [-] Review (WARNING) - Microsoft SQL Server 2016 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. This SQL Server generation is older and should be reviewed for support status, cumulative updates and exposure. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.90 | srv-012.corp.example.local | ICMP echo | SRV-012 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-012.corp.example.local | 2026-08-16 VALID78 days | srv-012.corp.example.local | TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.91 | srv-016.corp.example.local | ICMP echo | SRV-016 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.91 | srv-016.corp.example.local | ICMP echo | SRV-016 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2016 (13.0.7080.1) | [-] Review (WARNING) - Microsoft SQL Server 2016 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. This SQL Server generation is older and should be reviewed for support status, cumulative updates and exposure. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.91 | srv-016.corp.example.local | ICMP echo | SRV-016 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-016.corp.example.local | 2026-08-28 VALID90 days | srv-016.corp.example.local | TLS 1.2 | |||
10.10.10.92 | srv-018.corp.example.local | ICMP echo | SRV-018 | [OK] In CMDB | 80 | HTTP | Microsoft-HTTPAPI/2.0 | Not Found | None captured | None | |||||
10.10.10.92 | srv-018.corp.example.local | ICMP echo | SRV-018 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.92 | srv-018.corp.example.local | ICMP echo | SRV-018 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2022 (16.0.1000.6) | [-] Review (INFO) - Microsoft SQL Server 2022 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. Modern SQL Server release detected. Confirm current cumulative update/build before treating as clean. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.92 | srv-018.corp.example.local | ICMP echo | SRV-018 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-018.corp.example.local | 2026-10-12 VALID135 days | srv-018.corp.example.local | TLS 1.3TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.93 | srv-021.corp.example.local | ICMP echo | SRV-021 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.93 | srv-021.corp.example.local | ICMP echo | SRV-021 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2017 (14.0.1000.169) | [-] Review (WARNING) - Microsoft SQL Server 2017 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. This SQL Server generation is older and should be reviewed for support status, cumulative updates and exposure. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.93 | srv-021.corp.example.local | ICMP echo | SRV-021 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-021.corp.example.local | 2026-09-21 VALID114 days | srv-021.corp.example.local | TLS 1.2 | |||
10.10.10.94 | srv-025.corp.example.local | ICMP echo | SRV-025 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.94 | srv-025.corp.example.local | ICMP echo | SRV-025 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2017 (14.0.1000.169) | [-] Review (WARNING) - Microsoft SQL Server 2017 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. This SQL Server generation is older and should be reviewed for support status, cumulative updates and exposure. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.94 | srv-025.corp.example.local | ICMP echo | SRV-025 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-025.corp.example.local | 2026-07-15 VALID46 days | srv-025.corp.example.local | TLS 1.2 | |||
10.10.10.95 | srv-028.corp.example.local | ICMP echo | SRV-028 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.95 | srv-028.corp.example.local | ICMP echo | SRV-028 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2022 (16.0.1000.6) | [-] Review (INFO) - Microsoft SQL Server 2022 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. Modern SQL Server release detected. Confirm current cumulative update/build before treating as clean. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.95 | srv-028.corp.example.local | ICMP echo | SRV-028 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-028.corp.example.local | 2026-10-25 VALID148 days | srv-028.corp.example.local | TLS 1.3TLS 1.2TLS 1.1TLS 1.0 | |||
10.10.10.96 | srv-039.corp.example.local | ICMP echo | SRV-039 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.96 | srv-039.corp.example.local | ICMP echo | SRV-039 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2017 (14.0.1000.169) | [-] Review (WARNING) - Microsoft SQL Server 2017 was recognized, but the banner/year alone is not enough to prove exact CVE applicability. This SQL Server generation is older and should be reviewed for support status, cumulative updates and exposure. Other SQL Server versions have 20 documented CVEs in the current lookup result. Treat this as a tracked review item, not as unmapped and not as clean. | [!] Review | None captured | None | ||||
10.10.10.96 | srv-039.corp.example.local | ICMP echo | SRV-039 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-039.corp.example.local | 2026-07-14 VALID45 days | srv-039.corp.example.local | TLS 1.2 | |||
10.10.10.97 | srv-036.corp.example.local | ICMP echo | SRV-036 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.97 | srv-036.corp.example.local | ICMP echo | SRV-036 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2019 (15.0.2000.5) | 4 CVEs (CRITICAL) Highest: CVE-2021-38159 (Score: 9.8) Latest: CVE-2023-34362 (2023) | [OK] Verified (4/6 applicable) | None captured | None | ||||
10.10.10.97 | srv-036.corp.example.local | ICMP echo | SRV-036 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-036.corp.example.local | 2026-11-22 VALID176 days | srv-036.corp.example.local | TLS 1.2 | |||
10.10.10.98 | srv-041.corp.example.local | ICMP echo | SRV-041 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.98 | srv-041.corp.example.local | ICMP echo | SRV-041 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server (version detection failed) | None captured | None | ||||||
10.10.10.98 | srv-041.corp.example.local | ICMP echo | SRV-041 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-041.corp.example.local | 2026-07-16 VALID47 days | srv-041.corp.example.local | TLS 1.2 | |||
10.10.10.99 | N/A | ICMP echo | SRV-089 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.99 | N/A | ICMP echo | SRV-089 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | SRV-089.examplecorpexternal.com | 2026-08-26 VALID88 days | SRV-089.examplecorpexternal.com | TLS 1.2 | |||
10.10.10.100 | srv-043.corp.example.local | ICMP echo | SRV-043 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server 2019 (15.0.2000.5) | 4 CVEs (CRITICAL) Highest: CVE-2021-38159 (Score: 9.8) Latest: CVE-2023-34362 (2023) | [OK] Verified (4/6 applicable) | None captured | None | ||||
10.10.10.100 | srv-043.corp.example.local | ICMP echo | SRV-043 | [OK] In CMDB | 445 | SMB | SMB2/3 | None captured | None | ||||||
10.10.10.89 | srv-010.corp.example.local | ICMP echo | SRV-010 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-010.corp.example.local | 2026-07-27 VALID58 days | srv-010.corp.example.local | TLS 1.2 | |||
10.10.10.100 | srv-043.corp.example.local | ICMP echo | SRV-043 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-043.corp.example.local | 2026-09-25 VALID118 days | srv-043.corp.example.local | TLS 1.2 | |||
10.10.10.88 | srv-002.corp.example.local | ICMP echo | SRV-002 | [OK] In CMDB | 3389 | RDP-TLS | RDP with TLS encryption | None captured | srv-002.corp.example.local | 2026-08-03 VALID65 days | srv-002.corp.example.local | TLS 1.2 | |||
10.10.10.89 | srv-010.corp.example.local | ICMP echo | SRV-010 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server (version detection failed) | None captured | None | ||||||
10.10.10.88 | srv-002.corp.example.local | ICMP echo | SRV-002 | [OK] In CMDB | 1433 | MS-SQL | Microsoft SQL Server (version detection failed) | None captured | None | ||||||
10.10.10.87 | N/A | ICMP echo | [!] Not in CMDB | Discovered Host | Discovered host No checked TCP service answered. | None captured | None |
The summary cards at the top are clickable. A clicked card applies a matching table filter, for example Critical CVEs shows the affected rows, Not in DNS shows live hosts without a useful reverse DNS/PTR name, and Open Ports shows rows where a checked TCP service answered. Use Clear card filter to return to the full table.
ping -a IP_Address, but the report stores it as PTR/reverse DNS evidence.Why it matters: good names make assets easier to identify, assign, monitor and investigate.Suggestion: compare the hostname with CMDB, DHCP reservations and naming standards. Rename stale or misleading records.This local network report shows what answered during the subnet scan. The other Scantide tools are useful when the next question is: what is exposed on public domains, what happens inside the browser, or what does a mobile device/application reveal?
CVE matching is banner-based and version-aware where possible. A green or grey status does not mean the service is automatically safe; it means the scanner did not find a confirmed CVE match for the detected version. Use the confidence label to decide what needs manual review.
Nearby Wi-Fi, Wi-Fi Direct candidate networks/devices and Bluetooth observations collected from the scanning workstation. The evidence table comes first; the interpretation guide is below it.
| Type | Name / SSID | Address / BSSID | Vendor | Signal | Channel | Authentication | Encryption | Risk | Findings | Security evaluation | Evidence |
|---|---|---|---|---|---|---|---|---|---|---|---|
| WiFiNetwork | ExampleCorp | 02:00:00:00:00:0A | Locally administered / randomized | 24% | 100 | WPA3-Enterprise | CCMP | Medium | WPA3 advertised; Enterprise authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA3 is advertised; still verify configuration, client compatibility and management frame protection policy. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp | 02:00:00:00:00:0B | Locally administered / randomized | 70% | 60 | WPA3-Enterprise | CCMP | Medium | WPA3 advertised; Enterprise authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA3 is advertised; still verify configuration, client compatibility and management frame protection policy. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp | 02:00:00:00:00:0C | Locally administered / randomized | 82% | 36 | WPA3-Enterprise | CCMP | Medium | WPA3 advertised; Enterprise authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA3 is advertised; still verify configuration, client compatibility and management frame protection policy. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp | 02:00:00:00:00:07 | Locally administered / randomized | 72% | 11 | WPA3-Enterprise | CCMP | Medium | WPA3 advertised; Enterprise authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA3 is advertised; still verify configuration, client compatibility and management frame protection policy. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp | 02:00:00:00:00:08 | Locally administered / randomized | 80% | 6 | WPA3-Enterprise | CCMP | Medium | WPA3 advertised; Enterprise authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA3 is advertised; still verify configuration, client compatibility and management frame protection policy. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Corporate-SSID | 02:00:00:00:00:14 | Locally administered / randomized | 26% | 100 | WPA2-Enterprise | CCMP | Medium | WPA2 with AES/CCMP advertised; Enterprise authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Corporate-SSID | 02:00:00:00:00:16 | Locally administered / randomized | 70% | 60 | WPA2-Enterprise | CCMP | Medium | WPA2 with AES/CCMP advertised; Enterprise authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Corporate-SSID | 02:00:00:00:00:15 | Locally administered / randomized | 24% | 100 | WPA2-Enterprise | CCMP | Medium | WPA2 with AES/CCMP advertised; Enterprise authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Corporate-SSID | 02:00:00:00:00:12 | Cisco Meraki | 72% | 11 | WPA2-Enterprise | CCMP | Medium | WPA2 with AES/CCMP advertised; Enterprise authentication; Vendor matched from BSSID OUI: Cisco Meraki; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Corporate-SSID | 02:00:00:00:00:17 | Locally administered / randomized | 82% | 36 | WPA2-Enterprise | CCMP | Medium | WPA2 with AES/CCMP advertised; Enterprise authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Corporate-SSID | 02:00:00:00:00:13 | Cisco Meraki | 80% | 6 | WPA2-Enterprise | CCMP | Medium | WPA2 with AES/CCMP advertised; Enterprise authentication; Vendor matched from BSSID OUI: Cisco Meraki; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp-IoT | 02:00:00:00:00:04 | Locally administered / randomized | 26% | 100 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp-IoT | 02:00:00:00:00:05 | Locally administered / randomized | 70% | 60 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp-IoT | 02:00:00:00:00:06 | Locally administered / randomized | 82% | 36 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp-IoT | 02:00:00:00:00:01 | Locally administered / randomized | 72% | 11 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp-IoT | 02:00:00:00:00:02 | Locally administered / randomized | 80% | 6 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp_Guest | 02:00:00:00:00:10 | Locally administered / randomized | 70% | 60 | Open | None | High | Open Wi-Fi network; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | No link-layer encryption is advertised. Treat as unsafe unless this is an intentionally isolated guest/onboarding network. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp_Guest | 02:00:00:00:00:0F | Locally administered / randomized | 24% | 100 | Open | None | High | Open Wi-Fi network; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | No link-layer encryption is advertised. Treat as unsafe unless this is an intentionally isolated guest/onboarding network. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp_Guest | 02:00:00:00:00:0D | Locally administered / randomized | 72% | 11 | Open | None | High | Open Wi-Fi network; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | No link-layer encryption is advertised. Treat as unsafe unless this is an intentionally isolated guest/onboarding network. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp_Guest | 02:00:00:00:00:0E | Locally administered / randomized | 80% | 6 | Open | None | High | Open Wi-Fi network; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | No link-layer encryption is advertised. Treat as unsafe unless this is an intentionally isolated guest/onboarding network. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp_Guest | 02:00:00:00:00:11 | Locally administered / randomized | 82% | 36 | Open | None | High | Open Wi-Fi network; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | No link-layer encryption is advertised. Treat as unsafe unless this is an intentionally isolated guest/onboarding network. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Warehouse-WiFi | 02:00:00:00:00:18 | Locally administered / randomized | 72% | 11 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Warehouse-WiFi | 02:00:00:00:00:1C | Locally administered / randomized | 82% | 36 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Warehouse-WiFi | 02:00:00:00:00:19 | Locally administered / randomized | 80% | 6 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Warehouse-WiFi | 02:00:00:00:00:1B | Locally administered / randomized | 70% | 60 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp | 02:00:00:00:00:09 | Locally administered / randomized | 26% | 100 | WPA3-Enterprise | CCMP | Medium | WPA3 advertised; Enterprise authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA3 is advertised; still verify configuration, client compatibility and management frame protection policy. Enterprise/802.1X authentication is advertised; verify certificate validation and EAP settings on clients. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | ExampleCorp-IoT | 02:00:00:00:00:03 | Locally administered / randomized | 26% | 100 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| WiFiNetwork | Warehouse-WiFi | 02:00:00:00:00:1A | Locally administered / randomized | 24% | 100 | WPA2-Personal | CCMP | Medium | WPA2 with AES/CCMP advertised; Personal/PSK authentication; Randomized/locally administered BSSID; Possible rogue AP indicator: randomized/locally administered BSSID present for this SSID | WPA2 with AES/CCMP is a reasonable baseline when configured with strong credentials or 802.1X. PSK networks depend heavily on passphrase quality and rotation. Corporate networks should normally prefer 802.1X/Enterprise. BSSID uses a locally administered/randomized prefix, so vendor attribution is weaker and manual validation is recommended. WPS/PIN status was not exposed by Windows netsh for this observation; verify on the AP/controller if WPS/PIN is disabled. At least one BSSID for this SSID uses a locally administered/randomized prefix, which weakens vendor attribution and deserves manual validation. | Native WlanScan refresh + netsh wlan show networks mode=bssid |
| Bluetooth | Mobile Device AVRCP Transport | Info | Known/paired/installed Bluetooth device | BTHENUM\{0000110E-0000-1000-8000-00805F9B34FB}_VID&00010075_PID&0100\7&923F0F0&1&CC2119A7C775_C00000000 | |||||||
| Bluetooth | Mobile Device | Info | Known/paired/installed Bluetooth device | BTHENUM\DEV_CC2119A7C775\7&923F0F0&1&BLUETOOTHDEVICE_CC2119A7C775 | |||||||
| Bluetooth | Personal Area Network Service | Info | Known/paired/installed Bluetooth device | BTHENUM\{00001115-0000-1000-8000-00805F9B34FB}_VID&00010075_PID&0100\7&923F0F0&1&CC2119A7C775_C00000000 | |||||||
| Bluetooth | Bluetooth LE Generic Attribute Service | Info | Known/paired/installed Bluetooth device | BTHLEDEVICE\{0000180F-0000-1000-8000-00805F9B34FB}_DEV_VID&02413C_PID&3026_REV&0001_C80C062075FA\8&2A5CB5FC&0&0012 | |||||||
| Bluetooth | Generic Access Profile | Info | Known/paired/installed Bluetooth device | BTHLEDEVICE\{00001800-0000-1000-8000-00805F9B34FB}_DEV_VID&02413C_PID&3026_REV&0001_C80C062075FA\8&2A5CB5FC&0&0001 | |||||||
| Bluetooth | Device Information Service | Info | Known/paired/installed Bluetooth device | BTHLEDEVICE\{0000180A-0000-1000-8000-00805F9B34FB}_DEV_VID&02413C_PID&2511_REV&0001_C90D89369F17\8&2F7FD925&0&000B | |||||||
| Bluetooth | Microsoft Bluetooth Enumerator | Info | Known/paired/installed Bluetooth device | BTH\MS_BTHBRB\6&C17656B&0&1 | |||||||
| Bluetooth | Microsoft Bluetooth LE Enumerator | Info | Known/paired/installed Bluetooth device | BTH\MS_BTHLE\6&C17656B&0&3 | |||||||
| Bluetooth | Sim Access Service | Info | Known/paired/installed Bluetooth device | BTHENUM\{0000112D-0000-1000-8000-00805F9B34FB}_VID&00010075_PID&0100\7&923F0F0&1&CC2119A7C775_C00000000 | |||||||
| Bluetooth | Intel(R) Wireless Bluetooth(R) | Info | Known/paired/installed Bluetooth device | USB\VID_8087&PID_0032\5&1A90396&0&10 | |||||||
| Bluetooth | Generic Attribute Profile | Info | Known/paired/installed Bluetooth device | BTHLEDEVICE\{00001801-0000-1000-8000-00805F9B34FB}_DEV_VID&02413C_PID&3026_REV&0001_C80C062075FA\8&2A5CB5FC&0&000A | |||||||
| Bluetooth | Object Push Service | Info | Known/paired/installed Bluetooth device | BTHENUM\{00001105-0000-1000-8000-00805F9B34FB}_VID&00010075_PID&0100\7&923F0F0&1&CC2119A7C775_C00000000 | |||||||
| Bluetooth | Bluetooth Device (RFCOMM Protocol TDI) | Info | Known/paired/installed Bluetooth device | BTH\MS_RFCOMM\6&C17656B&0&0 | |||||||
| Bluetooth | Headset Audio Gateway Service | Info | Known/paired/installed Bluetooth device | BTHENUM\{00001112-0000-1000-8000-00805F9B34FB}_VID&00010075_PID&0100\7&923F0F0&1&CC2119A7C775_C00000000 | |||||||
| Bluetooth | Personal Area Network NAP Service | Info | Known/paired/installed Bluetooth device | BTHENUM\{00001116-0000-1000-8000-00805F9B34FB}_VID&00010075_PID&0100\7&923F0F0&1&CC2119A7C775_C00000000 | |||||||
| Bluetooth | Wireless Keyboard | Info | Known/paired/installed Bluetooth device | BTHLE\DEV_C90D89369F17\7&38A468DE&1&C90D89369F17 | |||||||
| Bluetooth | Phonebook Access Pse Service | Info | Known/paired/installed Bluetooth device | BTHENUM\{0000112F-0000-1000-8000-00805F9B34FB}_VID&00010075_PID&0100\7&923F0F0&1&CC2119A7C775_C00000000 | |||||||
| Bluetooth | Wireless Mouse | Low | Known/paired/installed Bluetooth device; Bluetooth HID/input device | BTHLE\DEV_C80C062075FA\7&38A468DE&1&C80C062075FA | |||||||
| BluetoothLE | BLE live advertisement scan unavailable in Windows PowerShell | Info | Windows PowerShell cannot subscribe to Windows Runtime Bluetooth LE events; Known/paired Bluetooth inventory is still collected | Register-ObjectEvent does not support WinRT events in Windows PowerShell 5.1 |
Radio findings are evidence-based and local to the scanner position. Treat open/weak encryption, duplicate SSIDs with different security, vendor mismatches and randomized BSSIDs as review indicators, not automatic proof of compromise. Confirm suspected rogue/evil-twin rows against your approved AP inventory/controller before taking action.
Wi-Fi Aware is intentionally reported by the Android Auditor where the platform exposes the required discovery APIs. On Windows, this helper reports Wi-Fi Direct candidates and Bluetooth/BLE observations on a best-effort basis.