{"id":610,"date":"2026-08-11T13:11:31","date_gmt":"2026-08-11T13:11:31","guid":{"rendered":"https:\/\/www.osto.one\/resources\/?p=610"},"modified":"2026-08-11T13:11:31","modified_gmt":"2026-08-11T13:11:31","slug":"vulnerability-scanning","status":"publish","type":"post","link":"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-scanning\/","title":{"rendered":"Vulnerability Scanning: How Scanners Really Work"},"content":{"rendered":"\n<!-- =========================================================================\n     OSTO GLOSSARY: VULNERABILITY SCANNING\n     Same design system as the VAPT, MFA, Penetration Testing and ISO 27001 pages.\n     Paste the whole block into one Custom HTML block. No H1 (WP adds it).\n     ========================================================================= -->\n\n<style>\n.og{\n  --navy:#1c267a; --text:#0f1538; --muted:#0f1538; --light:#0f1538;\n  --border:#e7e9f2; --divider:#eceef5; --white:#ffffff;\n\n  --peri-50:#f4f5fd;  --peri-100:#e9ecfa; --peri-200:#cfd5f2; --peri-700:#4a52a8;\n  --sage-50:#f2f8f5;  --sage-100:#e3f0e9; --sage-200:#c3ddce; --sage-700:#3a6f5d;\n  --apri-50:#fdf6f0;  --apri-100:#fbe9dc; --apri-200:#f2cdb2; --apri-700:#a2603a;\n  --plum-50:#f8f3f9;  --plum-100:#f0e6f3; --plum-200:#dcc6e2; --plum-700:#6b4576;\n  --sky-50:#f1f7fb;   --sky-100:#e2eff7;  --sky-200:#bfd9e9;  --sky-700:#2f6a89;\n\n  --shadow:0 6px 22px rgba(15,21,56,.05);\n  --font:'Inter',-apple-system,BlinkMacSystemFont,'Segoe UI',Roboto,sans-serif;\n  font-family:var(--font); font-size:17px; line-height:1.75; color:var(--text);\n}\n.og p{margin:0 0 22px}\n.og h2{font-family:var(--font);font-size:clamp(25px,3vw,31px);font-weight:700;line-height:1.25;letter-spacing:-.5px;color:var(--navy);margin:52px 0 8px;scroll-margin-top:92px}\n.og h2::after{content:\"\";display:block;width:46px;height:5px;border-radius:3px;margin:12px 0 18px;background:var(--peri-200)}\n.og h2.c-sage::after{background:var(--sage-200)}\n.og h2.c-apri::after{background:var(--apri-200)}\n.og h2.c-plum::after{background:var(--plum-200)}\n.og h2.c-sky::after{background:var(--sky-200)}\n.og ul,.og ol{padding-left:22px;margin:0 0 24px}\n.og li{margin-bottom:9px}\n.og strong{font-weight:600}\n\n.og .dek{font-size:20px;line-height:1.6;color:var(--muted);margin:0 0 18px}\n.og .tags{margin:0 0 30px;padding:0;list-style:none;display:flex;flex-wrap:wrap;gap:8px}\n.og .tags li{margin:0}\n.og .tag{display:inline-block;font-size:12px;font-weight:600;letter-spacing:.7px;text-transform:uppercase;padding:6px 13px;border-radius:20px}\n.og .t-peri{background:var(--peri-100);color:var(--peri-700)}\n.og .t-sage{background:var(--sage-100);color:var(--sage-700)}\n\n.og .short{background:linear-gradient(135deg,var(--peri-100) 0%,var(--sage-100) 100%);border-radius:22px;padding:28px 32px;margin:0 0 30px}\n.og .short .k{font-size:13px;font-weight:700;letter-spacing:1.4px;text-transform:uppercase;color:var(--peri-700);margin:0 0 10px}\n.og .short p{font-size:19px;line-height:1.65;margin:0;color:var(--text)}\n\n.og .toc{background:var(--peri-50);border-radius:20px;padding:24px 28px;margin:0 0 34px}\n.og .toc .k{font-size:12px;font-weight:700;letter-spacing:1.3px;text-transform:uppercase;color:var(--peri-700);margin:0 0 12px}\n.og .toc ol{margin:0;padding-left:20px;columns:2;column-gap:34px}\n.og .toc li{margin-bottom:8px;break-inside:avoid;font-size:16px}\n.og .toc a{color:var(--navy);text-decoration:none;border-bottom:1px solid rgba(28,38,122,.22)}\n\n.og .callout{border-radius:4px;padding:24px 28px;margin:0 0 30px;background:var(--white);border:2px solid var(--navy)}\n.og .callout .k{font-weight:700;font-size:17px;margin:0 0 8px;color:var(--navy)}\n.og .callout p:last-child{margin-bottom:0}\n.og .callout.c-plum{background:var(--plum-50);border:none;border-radius:20px}\n.og .callout.c-plum .k{color:var(--plum-700)}\n\n.og figure{margin:0 0 30px}\n.og .sx{overflow-x:auto;-webkit-overflow-scrolling:touch;border-radius:20px;background:var(--white);box-shadow:var(--shadow)}\n.og .sx svg{display:block;width:100%;height:auto;min-width:600px}\n.og figcaption{font-size:14px;line-height:1.6;color:var(--muted);margin-top:12px}\n.og .swipe{display:none}\n\n.og table{width:100%;border-collapse:collapse;margin:0 0 28px;font-size:15px;background:var(--white);border-radius:18px;overflow:hidden;box-shadow:var(--shadow)}\n.og th{text-align:left;padding:14px 16px;font-weight:700;font-size:12.5px;letter-spacing:.8px;text-transform:uppercase}\n.og td{border-bottom:1px solid var(--divider);padding:13px 16px;vertical-align:top;line-height:1.6}\n.og tr:last-child td{border-bottom:none}\n.og .h-peri th{background:var(--peri-100);color:var(--peri-700)}\n.og .h-sage th{background:var(--sage-100);color:var(--sage-700)}\n.og .h-plum th{background:var(--plum-100);color:var(--plum-700)}\n\n.og .trio{display:grid;grid-template-columns:repeat(3,1fr);gap:14px;margin:0 0 28px}\n.og .tcard{border-radius:18px;padding:20px 22px}\n.og .tcard .n{font-size:16px;font-weight:700;margin:0 0 4px}\n.og .tcard .g{font-size:13px;font-weight:600;margin:0 0 10px;opacity:.8}\n.og .tcard p{font-size:14px;line-height:1.55;margin:0;color:var(--muted)}\n.og .tcard.a{background:var(--sky-50)}   .og .tcard.a .n,.og .tcard.a .g{color:var(--sky-700)}\n.og .tcard.b{background:var(--sage-50)}  .og .tcard.b .n,.og .tcard.b .g{color:var(--sage-700)}\n.og .tcard.c{background:var(--plum-50)}  .og .tcard.c .n,.og .tcard.c .g{color:var(--plum-700)}\n\n.og .pill{display:inline-block;font-size:11px;font-weight:700;letter-spacing:.8px;text-transform:uppercase;padding:5px 11px;border-radius:20px;white-space:nowrap}\n.og .p-req{background:var(--plum-200);color:#4d2f57}\n.og .p-exp{background:var(--sky-100);color:var(--sky-700)}\n.og .p-imp{background:#eef0f4;color:var(--muted)}\n.og .p-ask{background:var(--apri-100);color:var(--apri-700)}\n.og .p-yes{background:var(--sage-100);color:var(--sage-700)}\n.og .p-no{background:#eef0f4;color:var(--muted)}\n\n.og details{background:var(--white);border-radius:14px;margin:0 0 10px;box-shadow:0 2px 10px rgba(15,21,56,.04)}\n.og summary{cursor:pointer;padding:16px 20px;font-weight:600;font-size:17px;color:var(--navy);list-style:none;display:flex;justify-content:space-between;gap:16px;align-items:flex-start}\n.og summary::-webkit-details-marker{display:none}\n.og summary::after{content:\"+\";font-size:22px;line-height:1;color:var(--peri-700);flex:0 0 auto}\n.og details[open] summary::after{content:\"\\2013\"}\n.og details p{padding:0 20px 18px;margin:0;font-size:16px;line-height:1.7}\n\n.og .related{font-size:15px;color:var(--muted);border-top:1px solid var(--divider);padding-top:22px;margin-top:40px}\n\n@media(max-width:700px){\n  .og{font-size:16px}\n  .og .dek{font-size:18px}\n  .og .short p{font-size:17px}\n  .og .short,.og .toc,.og .callout{padding:22px 20px}\n  .og .toc ol{columns:1}\n  .og .trio{grid-template-columns:1fr}\n  .og .swipe{display:inline;font-weight:600;color:var(--peri-700)}\n  .og table{font-size:14px}\n  .og th,.og td{padding:11px 12px}\n}\n<\/style>\n\n<div class=\"og\">\n\n<p class=\"dek\">Vulnerability scanning is the automated process of checking systems against databases of known weaknesses, producing a list of what may be vulnerable and where.<\/p>\n\n<ul class=\"tags\">\n  <li><span class=\"tag t-peri\">Glossary<\/span><\/li>\n  <li><span class=\"tag t-sage\">Testing &amp; scanning<\/span><\/li>\n<\/ul>\n\n<div class=\"short\">\n  <p class=\"k\">The short answer<\/p>\n  <p>A vulnerability scanner inspects hosts, applications, containers and cloud accounts, compares what it finds against published vulnerability databases such as the CVE list, and reports anything that matches. It runs in minutes or hours, repeats on a schedule, and produces raw output that still needs review.<\/p>\n<\/div>\n\n<p>Scanning is the engine underneath most security testing. A <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-assessment\/\">vulnerability assessment<\/a> uses a scan and then interprets it. A managed vulnerability programme runs scans continuously. On its own, a scan tells you what might be wrong, not what matters.<\/p>\n\n<div class=\"toc\">\n  <p class=\"k\">On this page<\/p>\n  <ol>\n    <li><a href=\"#how\">How a scanner works<\/a><\/li>\n    <li><a href=\"#auth\">Authenticated and unauthenticated scans<\/a><\/li>\n    <li><a href=\"#types\">Types of scan<\/a><\/li>\n    <li><a href=\"#limits\">What scanning is best at<\/a><\/li>\n    <li><a href=\"#osto\">How Osto scans<\/a><\/li>\n    <li><a href=\"#faq\">FAQ<\/a><\/li>\n  <\/ol>\n<\/div>\n\n<h2 id=\"how\">How a scanner works<\/h2>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 160\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"A scanner discovers what is reachable, fingerprints software and version, then matches against vulnerability databases.\">\n  <defs><marker id=\"vsA\" markerWidth=\"8\" markerHeight=\"8\" refX=\"6\" refY=\"4\" orient=\"auto\"><path d=\"M0,0 L8,4 L0,8 z\" fill=\"#b9c0d4\"\/><\/marker><\/defs>\n  <rect x=\"8\" y=\"34\" width=\"226\" height=\"80\" rx=\"14\" fill=\"#e9ecfa\"\/>\n  <text x=\"121\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#4a52a8\">1. Discover<\/text>\n  <text x=\"121\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Find what is reachable:<\/text>\n  <text x=\"121\" y=\"105\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">hosts, ports, endpoints<\/text>\n  <line x1=\"240\" y1=\"74\" x2=\"258\" y2=\"74\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#vsA)\"\/>\n\n  <rect x=\"266\" y=\"34\" width=\"226\" height=\"80\" rx=\"14\" fill=\"#c2d9ec\"\/>\n  <text x=\"379\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#25547a\">2. Fingerprint<\/text>\n  <text x=\"379\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Identify the software<\/text>\n  <text x=\"379\" y=\"105\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">and its version<\/text>\n  <line x1=\"498\" y1=\"74\" x2=\"516\" y2=\"74\" stroke=\"#b9c0d4\" stroke-width=\"2\" marker-end=\"url(#vsA)\"\/>\n\n  <rect x=\"524\" y=\"34\" width=\"226\" height=\"80\" rx=\"14\" fill=\"#1c267a\"\/>\n  <text x=\"637\" y=\"66\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"14\" font-weight=\"700\" fill=\"#ffffff\">3. Match<\/text>\n  <text x=\"637\" y=\"88\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#b9c1e6\">Compare against published<\/text>\n  <text x=\"637\" y=\"105\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#b9c1e6\">records such as the CVE list<\/text>\n\n  <text x=\"380\" y=\"146\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12\" fill=\"#0f1538\">Everything reported is already published. A scanner does not discover new weaknesses.<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Step 2 is where false positives originate: a version number can match a record even when the vulnerable component is unused or the patch was backported.<\/figcaption>\n<\/figure>\n\n<h2 id=\"auth\" class=\"c-sage\">Authenticated and unauthenticated scans<\/h2>\n\n<p>The single biggest factor in scan quality is whether the scanner has credentials. Without them it sees only what an outsider sees. With them it can read installed package versions and configuration directly.<\/p>\n\n<figure>\n<div class=\"sx\">\n<svg viewBox=\"0 0 760 300\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" role=\"img\" aria-label=\"An unauthenticated scan sees only exposed surface, while an authenticated scan also sees packages, patch level and configuration.\">\n  <text x=\"18\" y=\"28\" font-family=\"Inter,sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#4a52a8\">Unauthenticated<\/text>\n  <text x=\"18\" y=\"49\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">No credentials, outside view only<\/text>\n  <rect x=\"8\" y=\"62\" width=\"356\" height=\"218\" rx=\"18\" fill=\"#f4f5fd\"\/>\n\n  <rect x=\"36\" y=\"86\" width=\"300\" height=\"34\" rx=\"9\" fill=\"#c3c9f0\"\/>\n  <text x=\"52\" y=\"108\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#2f3673\">Open ports and services<\/text>\n  <rect x=\"36\" y=\"128\" width=\"300\" height=\"34\" rx=\"9\" fill=\"#c3c9f0\"\/>\n  <text x=\"52\" y=\"150\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#2f3673\">Banner and version fingerprints<\/text>\n  <rect x=\"36\" y=\"170\" width=\"300\" height=\"34\" rx=\"9\" fill=\"#eff0f6\"\/>\n  <text x=\"52\" y=\"192\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">Installed packages<\/text>\n  <rect x=\"36\" y=\"212\" width=\"300\" height=\"34\" rx=\"9\" fill=\"#eff0f6\"\/>\n  <text x=\"52\" y=\"234\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">Local configuration and patch level<\/text>\n  <text x=\"186\" y=\"268\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">More guesswork, more false positives<\/text>\n\n  <text x=\"406\" y=\"28\" font-family=\"Inter,sans-serif\" font-size=\"16\" font-weight=\"700\" fill=\"#1c267a\">Authenticated<\/text>\n  <text x=\"406\" y=\"49\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#0f1538\">Credentials supplied, inside view<\/text>\n  <rect x=\"396\" y=\"62\" width=\"356\" height=\"218\" rx=\"18\" fill=\"#f1f7fb\"\/>\n\n  <rect x=\"424\" y=\"86\" width=\"300\" height=\"34\" rx=\"9\" fill=\"#c2d9ec\"\/>\n  <text x=\"440\" y=\"108\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#25547a\">Open ports and services<\/text>\n  <rect x=\"424\" y=\"128\" width=\"300\" height=\"34\" rx=\"9\" fill=\"#c2d9ec\"\/>\n  <text x=\"440\" y=\"150\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#25547a\">Banner and version fingerprints<\/text>\n  <rect x=\"424\" y=\"170\" width=\"300\" height=\"34\" rx=\"9\" fill=\"#7b9dc9\"\/>\n  <text x=\"440\" y=\"192\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#ffffff\">Installed packages<\/text>\n  <rect x=\"424\" y=\"212\" width=\"300\" height=\"34\" rx=\"9\" fill=\"#1c267a\"\/>\n  <text x=\"440\" y=\"234\" font-family=\"Inter,sans-serif\" font-size=\"13\" fill=\"#ffffff\">Local configuration and patch level<\/text>\n  <text x=\"574\" y=\"268\" text-anchor=\"middle\" font-family=\"Inter,sans-serif\" font-size=\"12.5\" fill=\"#0f1538\">Fuller picture, far fewer false positives<\/text>\n<\/svg>\n<\/div>\n<figcaption><span class=\"swipe\">Swipe to see the full diagram. <\/span>Greyed rows are invisible to an unauthenticated scan. Most patch-level findings live in those two rows.<\/figcaption>\n<\/figure>\n\n<h2 id=\"types\" class=\"c-apri\">Types of scan<\/h2>\n\n<table class=\"h-sage\">\n  <thead>\n    <tr><th>Scan<\/th><th>What it inspects<\/th><th>Typical cadence<\/th><\/tr>\n  <\/thead>\n  <tbody>\n    <tr><td><strong>External network<\/strong><\/td><td>Internet-facing hosts, exposed services, TLS configuration<\/td><td>Weekly<\/td><\/tr>\n    <tr><td><strong>Internal network<\/strong><\/td><td>Hosts inside the perimeter, patch level, service configuration<\/td><td>Monthly<\/td><\/tr>\n    <tr><td><strong>Web application (DAST)<\/strong><\/td><td>A running application, tested through its interface as a user would reach it<\/td><td>Per release<\/td><\/tr>\n    <tr><td><strong>Container image<\/strong><\/td><td>Base image and packaged libraries, before the image ships<\/td><td>Every build<\/td><\/tr>\n    <tr><td><strong>Cloud configuration<\/strong><\/td><td>IAM, storage exposure, security groups, encryption and logging settings<\/td><td>Continuous<\/td><\/tr>\n    <tr><td><strong>Dependency (<a href=\"https:\/\/www.osto.one\/resources\/glossary\/sca\/\">SCA<\/a>)<\/strong><\/td><td>Open-source libraries declared in the codebase<\/td><td>Every commit<\/td><\/tr>\n  <\/tbody>\n<\/table>\n\n<h2 id=\"limits\" class=\"c-plum\">What scanning is best at<\/h2>\n\n<p>Scanning does one thing extremely well, and it is the thing manual testing cannot do.<\/p>\n\n<div class=\"trio\">\n  <div class=\"tcard a\">\n    <p class=\"n\">Complete coverage<\/p>\n    <p>Every host, image and cloud account checked, including the ones nobody would think to test by hand.<\/p>\n  <\/div>\n  <div class=\"tcard b\">\n    <p class=\"n\">Repeatable on a schedule<\/p>\n    <p>The same checks run daily or weekly, so new exposure surfaces within days rather than at the next audit.<\/p>\n  <\/div>\n  <div class=\"tcard c\">\n    <p class=\"n\">Fast, early warning<\/p>\n    <p>A newly published vulnerability can be matched against your estate the day it lands.<\/p>\n  <\/div>\n<\/div>\n\n<div class=\"callout\">\n  <p class=\"k\">Where it hands over to a human<\/p>\n  <p>Scanning matches against published records, so it will not find business logic flaws and it does not prove exploitability. That is the job of a <a href=\"https:\/\/www.osto.one\/resources\/glossary\/penetration-testing\/\">penetration test<\/a>. Used together, scanning holds the coverage between tests and testing supplies the proof.<\/p>\n<\/div>\n\n<h2 id=\"osto\">How Osto scans<\/h2>\n\n<p>Osto scans web applications, mobile applications, code dependencies and cloud accounts from one platform, on a schedule rather than on request. Findings are rated by severity and mapped to affected endpoints, and because the same platform holds the WAF and cloud posture data, a finding can be reviewed alongside whether anything is already blocking it.<\/p>\n\n<p class=\"related\"><strong>Product documentation:<\/strong> Setup guides and technical reference are available in the <a href=\"https:\/\/docs.osto.one\/\" target=\"_blank\" rel=\"noopener\">Osto documentation<\/a>.<\/p>\n\n<!-- ============ CTA ============ -->\n<div style=\"background:linear-gradient(135deg,#1c267a 0%,#3f4796 48%,#6b4576 100%);border-radius:22px;padding:38px 34px;margin:40px 0 12px;box-shadow:0 10px 26px rgba(28,38,122,.2);text-align:center;\">\n  <p style=\"display:inline-block;background:rgba(255,255,255,.16);color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:11px;font-weight:700;letter-spacing:1.2px;text-transform:uppercase;padding:6px 14px;border-radius:20px;margin:0 0 16px;\">Free security assessment<\/p>\n  <p style=\"color:#ffffff;font-family:'Inter',-apple-system,sans-serif;font-size:26px;line-height:1.3;font-weight:700;letter-spacing:-.4px;margin:0 0 12px;\">Scanning that runs without being asked<\/p>\n  <p style=\"color:#cfd3ea;font-family:'Inter',-apple-system,sans-serif;font-size:16px;line-height:1.65;margin:0 auto 26px;max-width:520px;\">Applications, APIs, dependencies and cloud accounts scanned on a schedule, with findings ranked and mapped to the endpoints they affect.<\/p>\n  <a href=\"https:\/\/osto.one\/contact\/\" style=\"display:inline-block;background:#ffffff;color:#1c267a;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:700;font-size:16px;text-decoration:none;border-bottom:none;padding:14px 30px;border-radius:12px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#1c267a;\">Get a free security assessment<\/span><\/a>\n  <a href=\"https:\/\/osto.one\/book-demo\/\" style=\"display:inline-block;background:transparent;color:#ffffff;font-family:&#039;Inter&#039;,-apple-system,sans-serif;font-weight:600;font-size:16px;text-decoration:none;border:1.5px solid rgba(255,255,255,.5);border-radius:12px;padding:13px 28px;margin:0 6px 10px;\" target=\"_blank\" rel=\"noopener\"><span style=\"color:#ffffff;\">Book a platform walkthrough<\/span><\/a>\n  <p style=\"color:#b3b8d8;font-family:'Inter',-apple-system,sans-serif;font-size:13px;margin:14px 0 0;\">Scheduled scanning &middot; Web, mobile, code and cloud &middot; One platform, everything<\/p>\n<\/div>\n\n<h2 id=\"faq\">Frequently asked questions<\/h2>\n\n<details>\n  <summary>What is vulnerability scanning?<\/summary>\n  <p>Vulnerability scanning is the automated process of inspecting hosts, applications, containers and cloud accounts, then comparing what is found against databases of published vulnerabilities such as the CVE list. It reports potential weaknesses along with a severity rating.<\/p>\n<\/details>\n\n<details>\n  <summary>What is the difference between an authenticated and an unauthenticated scan?<\/summary>\n  <p>An unauthenticated scan runs without credentials and sees only what is externally reachable, which produces more guesswork and more false positives. An authenticated scan uses credentials to read installed package versions and local configuration directly, producing a fuller and more accurate result.<\/p>\n<\/details>\n\n<details>\n  <summary>How often should scanning run?<\/summary>\n  <p>Continuously where possible. External scans weekly, internal scans monthly, container images on every build and dependencies on every commit is a workable pattern. Cloud configuration should be monitored continuously rather than scanned periodically.<\/p>\n<\/details>\n\n<details>\n  <summary>Is a vulnerability scan the same as a penetration test?<\/summary>\n  <p>No. A scan is automated and reports potential issues matched against a database. A penetration test is performed by a person who exploits findings to prove what an attacker could achieve. An <a href=\"https:\/\/www.osto.one\/resources\/blog\/soc-2-evidence-collection\/\">auditor<\/a> asking for a penetration test will not accept scanner output.<\/p>\n<\/details>\n\n<details>\n  <summary>Why do scanners report false positives?<\/summary>\n  <p>A scanner often infers a vulnerability from a version number rather than confirming the vulnerable code path is reachable. Backported patches, unused components and compensating controls all produce findings that are technically matched but not exploitable in practice.<\/p>\n<\/details>\n\n<p class=\"related\"><strong>Related glossary terms:<\/strong> <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-assessment\/\">Vulnerability Assessment<\/a> &middot; <a href=\"https:\/\/www.osto.one\/resources\/glossary\/vulnerability-management\/\">Vulnerability Management<\/a> &middot; CVE &middot; CVSS &middot; DAST &middot; SCA<\/p>\n\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Vulnerability scanning is the automated process of checking systems against databases of known weaknesses, producing a list of what may\u2026<\/p>\n","protected":false},"author":8,"featured_media":611,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[180],"tags":[195,196,194,197],"class_list":["post-610","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-glossary","tag-authenticated-scan","tag-unauthenticated-scan","tag-vulnerability-scanner","tag-vulnerability-scanning"],"_links":{"self":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/610","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/users\/8"}],"replies":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/comments?post=610"}],"version-history":[{"count":1,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/610\/revisions"}],"predecessor-version":[{"id":612,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/posts\/610\/revisions\/612"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media\/611"}],"wp:attachment":[{"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/media?parent=610"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/categories?post=610"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.osto.one\/resources\/wp-json\/wp\/v2\/tags?post=610"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}