Feature scope
Everything ArgusGuardian makes visible today for IT service providers and MSPs.
ArgusGuardian captures external attack surfaces and internal customer networks as a repeatable security service. Results are prepared as prioritized findings, a management PDF, and a technical PDF.
Scope
Which assets are checked
On-prem scanner
Internal visibility in the customer network
Data stays in the customer network
Matching against CVE, Windows update and distribution data runs against mirrors on the platform itself. The appliance never contacts vendors - build and patch levels of internal hosts never leave the environment.
Changes between two runs
Newly opened ports and newly appeared services are reported separately instead of getting lost in a full list.
Internal on-prem scanner
Appliance in the customer network for network inventory, internal services, host overview, and internal CVE findings - without inbound ports from outside.
Authenticated deep scan
Opt-in for Linux and Windows: package/software inventory, Windows update metadata, and more precise CVE mapping based on authorized credentials.
Self-hosted CVE mirror
CVE matching runs platform-side against an in-house mirror. Inventory and package data do not have to be sent to external CVE services.
Internal DNS threat detection
DNS query matches from Pi-hole, Windows AD DNS, or Unbound are checked locally against self-hosted blocklists; only confirmed matches leave the customer network.
NetFlow egress check
The appliance detects outbound connections to known malware, C2, or botnet destinations via NetFlow/IPFIX - matched locally, without payload export.
Appliance on Raspberry Pi
ARM/Raspberry Pi support enables affordable, signed appliances for small customer networks and branch offices.
Backport false-positive reduction
Distro OVAL refinement reduces false positives for distributions with backports, starting with Debian packages and traceable suppression.
MAC vendor detection
Self-hosted OUI data helps classify internal devices faster and makes inventory lists easier to understand in customer conversations.
RMM integration (Server-Eye, Atera)
Optional modules per IT service provider: manufacturer, model, operating system and MAC address from Server-Eye or Atera supplement device detection; Windows devices without an agent become visible.
Windows updates and end of support
Per Windows host the patch level against our own Microsoft mirror as a traffic light, plus the end of support of the version - without any device contacting Microsoft.
NIS2 asset inventory
Criticality, owner, location, serial number and lifecycle per host, maintained in the portal, with a monthly snapshot and export as CSV or JSON.
Device knowledge instead of IP guessing
Devices are recognized by MAC address and hostname, not by changing IP addresses; whatever RMM, deep scan or manual entries teach applies to all customers.
Signed appliance & auto-update
Signed delivery and opt-in auto-update create a cleaner operational basis for recurring scanner deployments at customer sites.
Features
Scan modules at a glance
Network & services
Port scanning for IPv4/IPv6, service and version detection, plus risky services such as databases, remote access, or container interfaces.
Asset discovery
Subdomains via certificate transparency, cloud/SaaS indicators, subdomain takeover risks, and typo-like registered domains.
Web technologies
Fingerprinting of web servers, frameworks, CMS systems, and publicly reachable web services.
Security headers & cookies
CSP, HSTS, X-Frame-Options, X-Content-Type-Options, referrer/permissions policy, cookie flags, and CORS wildcards.
WordPress inventory
WordPress core, plugins, themes, detected versions, and CVE matching as a basis for maintenance and updates.
Nuclei detection
Template-based detection without intrusive tests, OOB, or dangerous tags. Findings for CVEs, exposures, misconfigurations, and panels.
Exposed paths
Sensitive paths and files such as Git directories, environment files, backups, or debug endpoints.
Secret leak search
Indicators of published secrets on verified web assets so critical leaks can be prioritized quickly.
Breach monitoring
Paid add-on for verified domains: known data breaches and affected email addresses directly in the customer context.
TLS & certificates
Outdated protocols, weak ciphers, missing forward secrecy, expired or soon-expiring certificates.
DNS and mail hygiene
SPF, DMARC, DKIM, DNSSEC, DANE, MTA-STS, and open zone transfers as customer-friendly findings.
Reputation & blacklists
DNSBL and reputation checks for IPs and mail server IPs to reveal deliverability and abuse indicators.
Leak & exposure search
Email breach indicators, GitHub code search signals, and cloud storage exposure for S3, GCS, and Azure.
CVE matching
Detected services and web technologies are matched against known vulnerabilities and consolidated into findings.
Exploit prioritization
CISA KEV and EPSS enrich CVEs, highlight actively exploited vulnerabilities, and move urgent items to the top.
Management & technical reports
Management overview, scope, recommendations, and technical evidence as customer-ready PDF reports.
REST API v1
Read-only access to assets, scans, findings, and report downloads via API key for integrations and automation.
Security score with history
A traffic-light rating per customer, including its development over time - so that improvement can be demonstrated.
Screenshot evidence
Automatic captures of reachable web interfaces as evidence in the report - what was found can also be seen.
Scope verification and attestation
Only what demonstrably belongs to the customer is scanned: domains and IP addresses are approved via DNS, file or attestation by the IT service provider.
Scans on a fixed schedule
External and internal runs automatically every N months or weekly, with the next date visible - or as a one-off scan at the click of a button.
Microsoft 365 / Entra ID
Optional module per customer: MFA coverage, privileged roles, legacy authentication, external forwarding, inactive accounts, unused mailboxes, guest and SharePoint sharing, app permissions and expiring app secrets, consent policy and Microsoft Secure Score - read-only via Microsoft Graph, with history and per-account exceptions.
Operations and IT service provider
What the platform brings beyond that
Multi-tenant and white-label
An IT service provider manages its customers separately from one another and appears under its own name – logo, colors and sender address belong to it, not to the operator.
Compliance report
Open findings mapped to common requirement catalogs - a basis for discussions in audits and certifications.
Ticket system integration
Findings arrive as tickets in the IT service provider's existing system instead of sitting in yet another interface.
Audit log
A traceable record of who changed, approved or suppressed what and when - for customer queries and your own evidence.
GDPR access and erasure
Access to and erasure of personal data are designed into the product and implemented, not bolted on afterwards.
German and English
The interface is fully available in both languages and can be switched per user - for customers with international sites.
Electronic invoicing
Invoices in the structured format required by public authorities and increasingly expected by mid-sized businesses.
End-customer login
An IT service provider's customer sees their own area read-only: score, reports and findings, without access to other customers.
Open filter lists
ArgusGuardian maintains its own allow and block lists and publishes them free of charge under CC0 - anyone may use them, anyone may report addresses.
Subscription or one-off scan
Selectable per customer: an ongoing subscription with a fixed schedule or individual scans on demand, appliance paid once, add-ons transparent.