ProjectDiscovery has launched Internal Network Scanning, a feature that deploys a lightweight agent (pd-agent) inside your network to discover and scan reachable hosts the way an unauthenticated attacker would. Unlike traditional credentialed scanners (Tenable, Qualys, Rapid7) that match banners against CVE lists and generate noisy unvalidated findings, this tool runs unauthenticated scans using the Nuclei detection engine and returns only confirmed, exploitable exposures with the request/response proof. The agent connects outbound only, requires no credentials or domain account, supports Linux/macOS/Windows via Docker/Kubernetes/systemd, and integrates with Kubernetes pod/service CIDRs. It complements existing scanners by covering unmanaged devices and forgotten servers, and pairs with Neo, ProjectDiscovery's AI security engineer, for deeper reasoning about authorization flaws and lateral movement paths.

8m read timeFrom projectdiscovery.io
Post cover image
Table of contents
Where it fitsWhat it solvesHow it worksPairing it with NeoWhere this leaves internal security
178 Impressions