Network scanning
Register an IP address or range you own, scan it for open ports and exposed services, and ask Vulnara's security experts about a finding.
Besides code, Vulnara scans networks. You register an IP address or range that you own, start a scan, and Vulnara reports every open port it finds with the service, product and version behind it.
What it is for
An open port running an old service is one of the easiest ways into a network. A network scan shows you what the outside world can see on your hosts, so you can close what should not be open and update what is out of date.
How it works
- Vulnara scans the hosts in the range one at a time, so progress is reported host by host and one unreachable host does not stop the scan.
- On each host it checks the 100 most common TCP ports and identifies the service running on each open one.
- Every open port becomes a finding carrying the host, hostname, protocol, port, service name, state, product, version, extra information, the reason it was reported, a confidence value and the CPE identifier where one is known. Ports that give no response or no useful service information are not reported.
- The network's security score is worked out from its findings. Open ports weigh more than filtered ones, and closed ports add nothing. Services that are commonly attacked, such as HTTP, FTP, Telnet and SSH, add more risk, as does a service on its standard port and any disclosed product, version or CPE. Low-confidence findings count for less.

What you can set
- Name: a label for the network.
- Network: an IPv4 or IPv6 address, or a CIDR range such as
192.168.1.0/24or2001:db8::/112. A range can cover at most 65,536 addresses. - Network Type: Public, Private, VPN, Internal, External, DMZ or Unknown. Vulnara suggests a type from the range; choose Unknown if you are not sure.
- Ownership confirmation: you must confirm that you own the network or have permission from its owner to scan it.
Do it
Add the network
Open Networks in the web app and choose Add Network. Enter a name, the address or range, and the network type, tick the ownership confirmation and save.
Start the scan
Select the network and choose Scan Network, then confirm. You can also choose New Scan in the sidebar and pick Network. The scan appears in the tasks bar with the hosts scanned out of the total.
Read the results
Open Network Scans to see each scan and its findings. On a finding, choose Request Consultation to ask Vulnara's security experts to help you understand and resolve it.

The same operations exist in the API:
- GraphQL: createNetwork, startNetworkScan, networkScanResults, networkScanFindings, requestNSFConsultation and deleteNetwork.
createNetworkrequiresownershipConsent: true. - CLI: start_network_scan, networks, network_scan_results and network_scan_findings.
- MCP (read only): networks, network_scan_results and network_scan_findings.
vulnara start_network_scan --networkId <network-id>Good to know
- A range larger than 65,536 addresses, such as an IPv6
/64, is refused and the scan is marked failed. - Your plan sets how many networks you can hold and limits network scans. At the network limit you cannot add another network, and the web app offers an upgrade. If a plan change leaves you holding more networks than the plan allows, scans are refused until you are back within it.
- You can cancel a running network scan from the tasks bar. It stops before the next host.
- Vulnara notifies you when a network scan finishes or fails. See Notifications.
- Deleting a network cancels any scan still pending for it. You can also transfer a network to another account.