Continuous coverage from a lightweight agent.

Deploy a small CloneGuard agent to every laptop, server, cloud VM, and container host you care about. Get authenticated-quality vulnerability, patch, and configuration data streamed continuously, on-network or off.

Continuous
Streaming telemetry, not scan windows
Works Off-VPN
Remote endpoints stay covered
Cross-Platform
Windows · macOS · Linux · ARM
Self-managed
Support team on hand to troubleshoot
Agent-Based Scanning Capabilities

What a modern endpoint vulnerability program actually needs.

Deep host visibility, continuous telemetry, credentialed-quality findings without credentials, and reporting mapped to your auditors' frameworks, all through the CloneGuard platform.

Lightweight, Always-On Agent

A small, resource-friendly agent lives on each host and streams telemetry continuously, so findings appear the moment they exist.

Works Off-Network

Remote laptops, field devices, and road warriors stay covered without VPN. The agent reports directly to CloneGuard over TLS.

Deep Software Inventory

Every OS package, third-party application, browser extension, and runtime is inventoried for accurate CVE matching and SBOM export.

Authenticated by Design

The agent runs locally with the visibility it needs, so you get credentialed-quality results without managing scan credentials per host.

Configuration & Patch Posture

Detect missing patches, insecure configurations, end-of-life software, and hardening gaps against CIS and vendor baselines.

Unified Reporting

Agent findings live alongside network, PCI ASV, and pentest results in one CloneGuard console, with remediation reports and framework-mapped exports.

One Portal, Every Agent

Every agent, every finding, in the same CloneGuard console.

Agent-based scanning is one module inside CloneGuard. Its telemetry lives alongside network, PCI ASV, and pentest results, so one console tells the whole story of your exposure.

Clone Systems
7
CL
Security Overview

Your posture, what changed, and what to do next.

Security Posture
B+
342 open findings
High8
Medium47
Compliance
Passing
PCI DSS 4.0.1 ready
Passed 90d128
Failed 90d6
What's New
+23
since last scan
New KEVs 7d3
Scans 30d42
Next Scan
Tomorrow
weekly · 02:00 UTC
Running2
IPs1,284
Risk Over Time
-38% · 90 days
90450
JFMAMJJASOND
Clone Guard® Security Scanning  |  © 1998–2026 Clone Systems, Inc. All rights reserved

Where Agent-Based Scanning Wins

When an asset moves, changes constantly, or sits outside the network you control, an agent on the host is the fastest path to accurate, continuous vulnerability data.

  • Remote and roaming laptops
  • Cloud VMs, containers, and auto-scaling groups
  • Hardened servers where credential-based scanning is painful
  • Environments where scan windows are hard to coordinate

Where Network Scanning Still Belongs

Agents cover what you can install on; network scanning fills the rest. The two are complementary and both live in the same CloneGuard portal.

  • PCI ASV external scanning obligations
  • Unmanaged and BYO devices on your network
  • Network appliances, printers, IoT, and OT
  • Perimeter and public-facing infrastructure
How Agent-Based Scanning Works

From first install to verified fix, in five steps.

A predictable model your team runs independently, with support a message away for deployment or tuning help.

01

Deploy

Push the agent through Intune, Jamf, Group Policy, RMM, or a one-line install script. Bake it into cloud images for auto-scaling fleets.

02

Inventory

Each agent enumerates installed software, running services, patch state, and configuration posture from inside the host, no credentials required.

03

Detect

Findings flow to the CloneGuard platform continuously and are correlated against current CVE, exploit, and misconfiguration intelligence.

04

Prioritize

Every issue is scored on severity, exploitability, asset criticality, and framework impact so remediation effort starts where risk is highest.

05

Verify

Rescan on demand or wait for the next telemetry cycle. Closed findings drop off automatically, and trend views show progress over time.

Deploy Where Your Assets Live

One agent, everywhere your workloads run.

Ship the agent through the tools you already use: MDM for laptops, Group Policy or RMM for servers, golden image or Terraform for cloud. Nothing about your deployment stack has to change.

Linux one-liner
curl -sSL https://install.cloneguard.io/agent | \
  sudo TOKEN=<your-tenant-token> bash
Windows & macOS Laptops
Intune · Jamf · Kandji · Workspace ONE
Windows, macOS & Linux Servers
GPO · SCCM · Ansible · RMM
Cloud VMs
AWS EC2 · Azure VM · GCP Compute
Container Hosts
Docker · Kubernetes nodes
Compliance Coverage

Continuous evidence for the frameworks that matter.

Agent findings are pre-mapped to the controls auditors ask about, replacing the point-in-time scan PDF you used to assemble the week of the audit with continuous, timestamped host-level evidence.

Not sure which frameworks apply to your environment? A senior specialist can walk you through it.

PCI DSS 4.0.1
Req 6.3.3 · 11.3
HIPAA
Security Rule §164.308
SOC 2
CC7.1 · Vulnerability Mgmt
NIST 800-53
RA-5 · SI-2 · CM-8
NIST CSF
ID.AM · PR.IP · DE.CM
ISO 27001
A.8.8 · A.8.9
CIS Controls
Control 2 · 7 · CVM
CMMC
Level 2 · RA / CM
FedRAMP
RA-5 Continuous
GLBA
Safeguards Rule
GDPR
Art. 32 · Security
State privacy laws
CCPA · CPRA · more
Why Agent-Based Scanning

Continuous coverage, deeper visibility, cleaner audits.

Real-Time Visibility

New CVEs are matched against your live inventory as soon as they land, so you learn about exposure in hours, not at the next scan window.

No Scan Windows to Coordinate

There is no traffic to schedule, no maintenance window to negotiate, and no firewall rules to open. The agent just reports.

Low Overhead, No End-User Impact

Sub-100 MB idle memory, minimal CPU outside collection cycles, and compressed telemetry keep the agent invisible on laptops and busy servers alike.

Evidence Auditors Accept

Continuous, timestamped host-level evidence with framework mappings replaces point-in-time scan PDFs pulled together the week of an audit.

Who Runs Agent-Based Scanning

Built for teams whose assets do not sit still.

IT & Security Teams with Remote Workforces

Cover laptops that rarely touch the corporate network without shipping them home over a VPN.

Financial & Payment Environments

Continuous, authenticated coverage of workstations and servers to satisfy PCI DSS 4.0.1 vulnerability management expectations.

Healthcare & HIPAA-Regulated Businesses

Inventory and monitor clinical workstations, back-office servers, and cloud workloads without disrupting patient-facing systems.

Cloud-Native & DevOps Teams

Bake the agent into golden images so every auto-scaled instance and container host reports the moment it boots.

New · AI Add-On

An AI assistant that turns agent telemetry into a remediation plan.

Add the Clone Systems AI assistant to your agent fleet and stop scrolling through host-by-host findings. It clusters vulnerabilities, ranks what to fix first, and hands your team a ready-to-work remediation plan.

  • Fleet-wide clustering. Related findings across thousands of hosts collapse into a handful of work items you can actually assign.
  • Plain-English findings. Every vulnerability is rewritten in language engineers and non-engineers can act on together.
  • Risk-ranked priority. Exploitability, asset value, and framework impact combine into a single, defensible priority order.
  • Auditor-ready summaries. Draft executive and compliance-mapped narratives you can edit and export from the portal.
CloneGuard AI Assistanton shift
What is the highest-impact thing to fix across our agent fleet this week?
1,842 findings across 612 agents collapsed into 34 work items. Top priority is an outdated Chromium build on 289 laptops, actively exploited in the wild and in-scope for SOC 2 CC7.1.
Severity: 9.1Hosts: 289SOC 2 CC7.1
Recommended Plan
Push the Chromium update through Intune to the 289 affected laptops, then let the agents confirm the fix on next check-in. Want me to draft the change ticket and stage the deployment ring?
READY WHEN YOU ARE

Continuous agent coverage, live in days, not months.

Scope your fleet with a senior specialist, see the CloneGuard platform reporting from live agents, and get a plan for standing up continuous vulnerability coverage across every host you care about.

  • Windows, macOS, and Linux coverage from day one
  • Deploy through Intune, Jamf, GPO, RMM, or cloud images
  • Continuous telemetry, on-network and off-VPN
  • Support team available to help you troubleshoot
TALK TO OUR SCANNING TEAM

Scope your agent-based scanning rollout

Tell us about your fleet and how you deploy software today. A senior specialist will get back to you. All fields required.

No spam, ever.

Agent-Based Scanning FAQ

Agent-based scanning questions, answered.

Everything you need to know about running agent-based vulnerability scanning with Clone Systems. Still stuck? Talk to us.