← Go to login

Feature scope

Everything ArgusGuardian makes visible today for IT service providers and MSPs.

ArgusGuardian captures external attack surfaces and internal customer networks as a repeatable security service. Results are prepared as prioritized findings, a management PDF, and a technical PDF.

Detection only in external scans: no exploitation, no DoS, no brute-force tests.

Scope

Which assets are checked

Domains Web, DNS, mail security, subdomains, certificates
IP addresses Ports, services, TLS, reputation, and exposed services
Email addresses Breach monitoring for verified domains and affected accounts
Internal networks On-prem appliance for hosts, services, vendors, package/update inventory, and internal CVEs
Microsoft 365 Entra ID accounts, administrators, policies, apps and mailboxes of the customer's tenant (optional module)

On-prem scanner

Internal visibility in the customer network

LOCAL

Data stays in the customer network

Matching against CVE, Windows update and distribution data runs against mirrors on the platform itself. The appliance never contacts vendors - build and patch levels of internal hosts never leave the environment.

DIFF

Changes between two runs

Newly opened ports and newly appeared services are reported separately instead of getting lost in a full list.

LAN

Internal on-prem scanner

Appliance in the customer network for network inventory, internal services, host overview, and internal CVE findings - without inbound ports from outside.

AUTH

Authenticated deep scan

Opt-in for Linux and Windows: package/software inventory, Windows update metadata, and more precise CVE mapping based on authorized credentials.

CVE

Self-hosted CVE mirror

CVE matching runs platform-side against an in-house mirror. Inventory and package data do not have to be sent to external CVE services.

DNS

Internal DNS threat detection

DNS query matches from Pi-hole, Windows AD DNS, or Unbound are checked locally against self-hosted blocklists; only confirmed matches leave the customer network.

FLOW

NetFlow egress check

The appliance detects outbound connections to known malware, C2, or botnet destinations via NetFlow/IPFIX - matched locally, without payload export.

ARM

Appliance on Raspberry Pi

ARM/Raspberry Pi support enables affordable, signed appliances for small customer networks and branch offices.

OVAL

Backport false-positive reduction

Distro OVAL refinement reduces false positives for distributions with backports, starting with Debian packages and traceable suppression.

OUI

MAC vendor detection

Self-hosted OUI data helps classify internal devices faster and makes inventory lists easier to understand in customer conversations.

RMM

RMM integration (Server-Eye, Atera)

Optional modules per IT service provider: manufacturer, model, operating system and MAC address from Server-Eye or Atera supplement device detection; Windows devices without an agent become visible.

WSUS

Windows updates and end of support

Per Windows host the patch level against our own Microsoft mirror as a traffic light, plus the end of support of the version - without any device contacting Microsoft.

NIS2

NIS2 asset inventory

Criticality, owner, location, serial number and lifecycle per host, maintained in the portal, with a monthly snapshot and export as CSV or JSON.

ID

Device knowledge instead of IP guessing

Devices are recognized by MAC address and hostname, not by changing IP addresses; whatever RMM, deep scan or manual entries teach applies to all customers.

SIGN

Signed appliance & auto-update

Signed delivery and opt-in auto-update create a cleaner operational basis for recurring scanner deployments at customer sites.

Features

Scan modules at a glance

NET

Network & services

Port scanning for IPv4/IPv6, service and version detection, plus risky services such as databases, remote access, or container interfaces.

ASM

Asset discovery

Subdomains via certificate transparency, cloud/SaaS indicators, subdomain takeover risks, and typo-like registered domains.

WEB

Web technologies

Fingerprinting of web servers, frameworks, CMS systems, and publicly reachable web services.

HDR

Security headers & cookies

CSP, HSTS, X-Frame-Options, X-Content-Type-Options, referrer/permissions policy, cookie flags, and CORS wildcards.

WP

WordPress inventory

WordPress core, plugins, themes, detected versions, and CVE matching as a basis for maintenance and updates.

NUC

Nuclei detection

Template-based detection without intrusive tests, OOB, or dangerous tags. Findings for CVEs, exposures, misconfigurations, and panels.

PATH

Exposed paths

Sensitive paths and files such as Git directories, environment files, backups, or debug endpoints.

SEC

Secret leak search

Indicators of published secrets on verified web assets so critical leaks can be prioritized quickly.

HIBP

Breach monitoring

Paid add-on for verified domains: known data breaches and affected email addresses directly in the customer context.

TLS

TLS & certificates

Outdated protocols, weak ciphers, missing forward secrecy, expired or soon-expiring certificates.

DNS

DNS and mail hygiene

SPF, DMARC, DKIM, DNSSEC, DANE, MTA-STS, and open zone transfers as customer-friendly findings.

REP

Reputation & blacklists

DNSBL and reputation checks for IPs and mail server IPs to reveal deliverability and abuse indicators.

LEAK

Leak & exposure search

Email breach indicators, GitHub code search signals, and cloud storage exposure for S3, GCS, and Azure.

CVE

CVE matching

Detected services and web technologies are matched against known vulnerabilities and consolidated into findings.

KEV

Exploit prioritization

CISA KEV and EPSS enrich CVEs, highlight actively exploited vulnerabilities, and move urgent items to the top.

PDF

Management & technical reports

Management overview, scope, recommendations, and technical evidence as customer-ready PDF reports.

API

REST API v1

Read-only access to assets, scans, findings, and report downloads via API key for integrations and automation.

SCORE

Security score with history

A traffic-light rating per customer, including its development over time - so that improvement can be demonstrated.

SHOT

Screenshot evidence

Automatic captures of reachable web interfaces as evidence in the report - what was found can also be seen.

VERIFY

Scope verification and attestation

Only what demonstrably belongs to the customer is scanned: domains and IP addresses are approved via DNS, file or attestation by the IT service provider.

AUTO

Scans on a fixed schedule

External and internal runs automatically every N months or weekly, with the next date visible - or as a one-off scan at the click of a button.

M365

Microsoft 365 / Entra ID

Optional module per customer: MFA coverage, privileged roles, legacy authentication, external forwarding, inactive accounts, unused mailboxes, guest and SharePoint sharing, app permissions and expiring app secrets, consent policy and Microsoft Secure Score - read-only via Microsoft Graph, with history and per-account exceptions.

Operations and IT service provider

What the platform brings beyond that

MSP

Multi-tenant and white-label

An IT service provider manages its customers separately from one another and appears under its own name – logo, colors and sender address belong to it, not to the operator.

COMP

Compliance report

Open findings mapped to common requirement catalogs - a basis for discussions in audits and certifications.

TICK

Ticket system integration

Findings arrive as tickets in the IT service provider's existing system instead of sitting in yet another interface.

LOG

Audit log

A traceable record of who changed, approved or suppressed what and when - for customer queries and your own evidence.

GDPR

GDPR access and erasure

Access to and erasure of personal data are designed into the product and implemented, not bolted on afterwards.

I18N

German and English

The interface is fully available in both languages and can be switched per user - for customers with international sites.

INV

Electronic invoicing

Invoices in the structured format required by public authorities and increasingly expected by mid-sized businesses.

END

End-customer login

An IT service provider's customer sees their own area read-only: score, reports and findings, without access to other customers.

LIST

Open filter lists

ArgusGuardian maintains its own allow and block lists and publishes them free of charge under CC0 - anyone may use them, anyone may report addresses.

PAY

Subscription or one-off scan

Selectable per customer: an ongoing subscription with a fixed schedule or individual scans on demand, appliance paid once, add-ons transparent.