Protect your console login with an authenticator app (Google Authenticator, Authy, 1Password…).
Prefer to run the scanner on your own hardware? Download and install it, then click Enroll a node below and connect it from its Settings → Cloud console. On-prem nodes are still activated and licence-limited from here.
On-prem nodes that run network assessments & scans inside your environment.
| Node | Version | Status | Last seen |
|---|
Scans run on your on-prem node — never in the cloud. Start a scan from the node; it appears here to track and, once complete, to download as a PDF report.
| Node | Target | Status | When | Progress | Findings |
|---|
All scanning runs on your own node. The console only queues work and shows results — targets, credentials and raw evidence never leave your network. Everything you need to set up a node, run scans, and act on findings is below.
Cyentrix Scan has two parts. The node is a single program you run on a machine inside your network — it does all the scanning. The console (this site) is where you create scans and read results from anywhere. The node only ever makes an outbound HTTPS connection to the console, so there are no inbound ports to open and your data never leaves your network.
The node is one self-contained binary — no dependencies. Put it on a machine that can reach the systems you want to scan.
The complete engine, including the Metasploit exploit-validation tier. This is the recommended platform for a scanning node.
chmod +x cyentrix ./cyentrix -addr 0.0.0.0:8834Run the installer (or the binary) on a Windows host, for example:
C:\Program Files\Cyentrix\cyentrix.exe -addr 0.0.0.0:8834| Name | Status | Version | Last seen |
|---|---|---|---|
| HQ-scanner | online | 1.0.3 | just now |
| branch-01 | online | 1.0.3 | 2 min ago |
10.0.0.0/24). Deduplicated and CIDR-safe.Every scan runs in one of three modes — pick the depth that matches your authorisation and risk tolerance.
| Mode | What it does | Use when |
|---|---|---|
| Safe | Passive / non-invasive only — discovery, service & version detection, and CVE / KEV / EPSS matching. No default-credential attempts, exploit validation, or active web templates. | Production hours, sensitive or fragile systems, a first look. |
| Standard | Everything in Safe, plus safe active probes: web-exposure checks, non-destructive templates, and safe validation checks. Recommended default. | Most routine assessments. |
| Aggressive | Full depth: default-credential attempts and active exploit validation. Requires explicit written authorisation. | Authorised penetration tests only. |
| Targets | One or many: IP, hostname, range, or CIDR (e.g. 10.0.0.0/24). |
| Policy | The set of checks to run — which plugin families and benchmarks. Use a broad policy or a focused one (web, TLS, a specific framework). Some policies include default-credential / exploit checks that only run in Aggressive mode. |
| Credentials | Optional. Attach stored SSH (Linux) or WinRM (Windows) credentials for authenticated checks — installed packages, missing patches, local config — for far fewer false positives. Credentials are stored and used on the node only. |
| Timing | How fast and loud the scan is: 1 Sneaky · 2 Polite · 3 Normal (default) · 4 Aggressive. Lower is slower and quieter — less likely to trip IDS or overload fragile hosts. |
| Compliance | Run benchmark / hardening checks (e.g. CIS-style) alongside the vulnerability scan and see control drift in the same report. |
When a scan finishes, open it to see findings ranked by real risk — exploited-in-the-wild (CISA KEV) first, then high EPSS, then the rest.
| Host | 10.0.14.22 |
| Exploit | CISA KEV · EPSS 97 |
| First seen | today |
From a completed scan, choose Report to generate a clean PDF — an executive summary plus the full findings with remediation. The PDF is produced on the node, so nothing leaves your network unless you choose to share it.
Protect your login: open the Security · Two-factor authentication card, choose Enable 2FA, scan the QR/secret with an authenticator app (Google Authenticator, Authy, 1Password…), and confirm with a code. After that, sign-in asks for a 6-digit code.
Prefer a walkthrough, or stuck on setup? Request a demo or email hello@cyentrix.com.