Skip to content

Sentry

Internal vulnerability scans with Sentry

A scanner that runs as a VM or Docker container inside your network. It tests servers, clients, OT and Active Directory and reports into the same workflow.

Sentry in the internal networkonline
Servers423 critical
Clients186
OT & IoT172 critical
Network91 critical
Active Directory12 accounts without sign-in for 90 daysMedium

Visuals show sample data.

products in the vulnerability catalogue
175.000+
device classes, server to industrial controller
10
vulnerability tests, updated daily
200,000+
Agent for the entire infrastructure
1

A VM or container, no agent on every device

Sentry runs on VMware, Hyper-V, Proxmox or Docker and connects from the inside out with a one-time token. Nothing is installed on the target systems.

Sentry agents2 of 3 online
sentry-hqVMware, 2 vCPU, 4 GB RAMOnline
sentry-dmzDocker containerOnline
sentry-plantProxmox, 8 vCPU, 16 GB RAMOffline for 18 min
Scan job server networkMondays 02:00
Target
192.0.2.0/24
Profile
Vulnerability
Ports
Default, ~4,500

Visuals show sample data.

  1. 1

    Start the image

    Start the VM image or the Docker container on an existing host.

  2. 2

    Connect with a token

    Enter the one-time token. No inbound firewall rules are needed.

  3. 3

    Choose targets and schedule

    Set networks or hosts, scan profile, port template and schedule.

  4. 4

    Work the findings

    Results land with EPSS and AI explanation in the same workflow.

Active Directory scan with minimal rights

Ransomware groups move through networks via Active Directory. Sentry checks accounts, policies and permissions over SMB with a read-only account.

Active DirectorySMB, port 445
dc01.beispiel-gmbh.atDomain controllerRead-only
Identities214
Privileged9
Stale (90 days)12
Privileged accounts without sign-in2 of 9 accounts inactive for over 90 daysHigh
Stale passwords31 accounts, password older than 90 daysMedium

Visuals show sample data.

  • No domain admin needed

    A setup script creates a least-privilege account you can revoke at any time.

  • Results as findings

    With severity, status and remediation guidance next to every other finding.

  • Identities in the inventory

    AD accounts alongside cloud identities from Entra ID and Google.

IoT, OT and everything nobody else scans

Printers, cameras, IP phones and industrial controllers rarely appear in an inventory. Sentry discovers and classifies them automatically.

Discovered devicesclassified automatically
192.0.2.31Camera, default passwordHigh
192.0.2.45Printer, SNMP v1 publicMedium
198.51.100.12Industrial controllerDiscovery only
192.0.2.60IP phoneNo findings

Visuals show sample data.

  • Automatic classification

    From server and client to camera, storage and industrial controller.

  • Authenticated checks

    The credential profile finds missing patches that are invisible from outside.

  • Gentle on OT

    Discovery profile or quick port template first, the full profile later.

Frequently asked questions

External scans show what is reachable from the internet. Most ransomware incidents, however, proceed through internal systems after initial access: unpatched servers, weak Active Directory configurations, printers or cameras with default passwords. Internal vulnerability scanning tests these systems from inside your own network. With the blacklens.io Sentry agent the results land in the same workflow as external and cloud findings.

Install Sentry today, see the first findings tomorrow.

14 days free with five internal assets. We guide you through set-up and the first Active Directory scan.

  • 14 days free, all features
  • No credit card required
  • We walk you through your first findings