Help center
Network targets
Daily port scans of public IP addresses and small ranges you own or are authorised to test, filed under a client, with results per scan.
Updated · 1 article
A domain is not the only thing with an outside. An office firewall, a VPN appliance, a mail server on a static IP: network targets put those under the same daily port scan the domain scanner runs, with the same attestation and guardrails.
Articles
- IP and CIDR targets - adding a target, the attestation, the /24 limit, auto-verification from inside the range, the daily scan and the manual scan cooldown.
Where
- Web: Security, Network targets.
- iOS: under a domain's Vulnerabilities module, Add a network target, with "Use this connection".
- API/MCP:
GET/POST /api/ip-targets,PATCH/DELETE /api/ip-targets/:id,GET /api/ip-targets/:id/scans,POST /api/ip-targets/:id/scan; toolslist_ip_targets,add_ip_target,update_ip_target,delete_ip_target,list_ip_target_scans,scan_ip_target.
What it is for
Most small businesses have two or three public addresses that are not a website: the static IP the firewall sits on, the address the phone system uses, the box a vendor installed for remote access. Nobody scans them, and the port that was opened for a contractor three years ago is still open. A network target puts each of those under the same 128-port probe the domain scanner runs, once a day, with a history so a newly opened port shows as a change.
What it is not
It is not a vulnerability scanner for a network. The probe is a TCP connect test that names the service behind each open port and flags the ones that should not face the internet (databases, remote desktop, management consoles). It does not exploit, fingerprint deeply, or scan inside the network.
Plans
Network targets are available on every plan. The daily sweep and the manual scan follow the same rules for everyone; the one-hour cooldown on Scan now applies per target.
Common questions
Can I add a hostname? No. Add the domain instead; its hosts are discovered and scanned as part of the domain's exposure scan.
Is IPv6 supported? Not yet. Targets are IPv4 addresses and IPv4 CIDR ranges.
Who can see the results? Only your account. A target filed under a client shows in that client's view on the web and in the read-only Organisation screen in the app.
Still stuck?
Ask the people who run the scanner.
Send the domain and what you expected to see. We look at the same scan you are looking at and write back with what it means and what to change.
