Agent-Based Vulnerability Scanning: The Coverage Gap Your Network-Only Program Doesn't Admit

A network-only vulnerability program is blind to the laptops and field devices that leave the office. Here is when agent-based scanning earns its place, what each method sees, and the 5-class matrix for running both.

Agent-Based Vulnerability Scanning: The Coverage Gap Your Network-Only Program Doesn't Admit

Agent-Based Vulnerability Scanning: The Coverage Gap Your Network-Only Program Doesn't Admit

Agent-based vulnerability scanning installs a small scanner on each endpoint so it reports its patch and configuration state even when off the corporate network. Network-based scanning sees only what it can reach by protocol. They are complementary: agents cover roaming laptops and field devices, network scans cover the rest, and a complete program runs both and reconciles the inventories.

A vulnerability report that looks complete can still be missing the assets most likely to be the initial compromise. For a network-only program, that gap is structural. Agent-based vulnerability scanning exists to close it, because a scanner that only probes the network can never see the laptops, field tablets and home-office machines that spend most of their time off it.

In our assessments, we consistently see the same pattern. The network-based program is current and well run. The endpoints that leave the office are not in the report. No one made a bad decision. The scanner can only report on what it can reach by protocol, and a laptop on hotel Wi-Fi is unreachable by definition. The most common unknown we find in a network-based program is not a hidden server. It is a laptop that has not been on the network since it was issued.

The reachability numbers make the stakes concrete. Zero Networks' 2026 Lateral Movement Exposure Report, based on 54 trillion network activities across 312 enterprise environments, found that 80% of enterprise servers are reachable from anywhere inside the network, and that a single compromised host can reach 85% of internal systems on the first hop [2]. Once an attacker is in, reachability is rarely the problem. The problem is the entry point, and the easiest door is an unpatched machine your scan does not cover.

So the question is not "agents or network scans." It is how you keep every asset in the program and prove that you did. This post is the decision framework we use with clients to answer that.

When Should You Use Agent-Based Vulnerability Scanning?

Deploy agent-based scanning for every asset that regularly leaves the corporate network: company-issued laptops, field-service devices, home-office workstations, and contractor machines. If a machine can be off-network for more than a few days, a network-based scan alone will not reliably see it.

The machine leaves the building

Network scanning needs a path. A scanner placed on an internal segment can probe any host that answers on the wire, but it cannot probe a laptop on a hotel network or a tablet mounted in a service van. An agent flips the direction: the host reports its own state to the console over whatever internet connection it has, so coverage no longer depends on where the machine is plugged in.

You cannot attribute findings to a stable asset

End-user networks assign dynamic IPs. A network-based finding tied to 10.20.4.17 is useful only if you can say whose machine that is today, and the address will be different by next month. An agent binds findings to a named asset, so a finding on FIN-LT-212 is trackable from first sighting to remediation. For reporting to the CISO, attribution is what turns a scan into a metric.

Your patch SLA assumes you know what is installed

NIST SP 800-40 Rev 4 defines enterprise patch management as identifying, prioritizing, acquiring, installing, and verifying patches across the estate [1]. Verification starts with knowing what is on each host. If half your estate is off-network more than half the time, your patch SLA is only as good as the last time those machines were on the network.

CISA's Known Exploited Vulnerabilities catalog now lists 1,728 vulnerabilities with confirmed real-world exploitation, and CISA directs organizations to use the catalog as an input to prioritization [3]. Entries added in late September 2026 for Citrix NetScaler, WordPress, and SharePoint carried federal due dates of three days. A 90-day internal SLA on a laptop that has not been scanned in six weeks is a 120-day SLA in practice.

What Does Agent-Based Scanning See That Network Scans Cannot?

An agent reports from inside the host: installed software, exact patch levels, and configuration state, with no network path required, and it keeps reporting while the machine is off your network. Even a credentialed network scan is limited to what it can probe from its vantage point.

Installed software, not just running services

A network probe sees listening services, versions that banner themselves, and OS fingerprints. An agent can read the full software inventory, including applications that open no port at all: PDF readers, office suites, development tools, and the quiet shadow software that becomes the patch backlog. Clients are often surprised to learn how much of their installed software is only visible from the inside.

Internal state, not inference

Agent checks validate what a network scan can only infer: installed patch identifiers, specific configuration values, and kernel-level state. That cuts false positives from version guessing and gives the remediation team an exact target instead of a probability.

Current state between scan windows

An agent can report the moment the host changes: a new application install, a patch applied, or a configuration drift. The console shows the current state, not a point-in-time snapshot. When the priority is a KEV-listed vulnerability [3], the age of the data matters as much as the finding.

Can Agent-Based Scanning Replace Network-Based Scanning?

No. An agent only covers the hosts it is installed on, and much of the estate has no operating system an agent can run on. Network-based scanning remains the default method for everything with an IP address, and it is the only method that discovers assets your inventory does not yet know exist.

Assets an agent cannot run on

Printers, switches, routers, storage appliances, iLO and iDRAC management interfaces, cameras, and OT endpoints. These have no general-purpose OS, they are usually the easiest targets for a network probe, and they show up in network scans without any credentials.

The silent-failure mode

An agent that stops running is indistinguishable from a machine that left the network. A host can drop out of your report for months, and nothing will alert you. That is why network scans must keep sweeping every segment on schedule: the sweep finds both dead agents and unknown devices. In our reconciliations, a missing agent is almost always an asset that was decommissioned, reimaged, or reassigned without a record.

Discovery is a network-scanning job

You cannot install an agent on a machine you do not know exists. Network discovery finds the unknown asset first, and the inventory question is what to do with it. The first verb in NIST SP 800-40 Rev 4's definition of patch management is "identifying" [1]. You cannot prioritize, patch, or verify what you have not found.

How to Run Both: the Clone Systems 5-Class Asset Coverage Decision Matrix

Treat coverage as a property of the asset, not of the tool. Assign every asset class a primary method and a cross-check method, then reconcile the two inventories on a fixed schedule. That is the whole framework, and it is the Clone Systems 5-Class Asset Coverage Decision Matrix:

Asset classPrimary methodCross-checkWhy
Roaming laptops and field devicesAgent-based scanQuarterly network sweep when on siteThe primary method must work off network
Fixed desktops and serversCredentialed network scanAgent where feasibleBoth are cheap; the diff catches drift
Network, OT, IoT, and printUncredentialed network scanNone (no agent OS)Reachability is the whole point
Virtual and cloud hostsAgent or credentialed scanReconcile against the cloud inventoryProvisioning changes faster than the scan schedule
Unknown assetsNetwork discoveryManual triage and ownership assignmentYou do not know yet, by definition

The reconciliation is what makes it a program rather than a collection of tools:

  1. Weekly: diff the agent inventory against the network-discovery inventory. New agents, new hosts, and any agent silent for more than 7 days each get a ticket.
  2. Monthly: produce a coverage report: the percentage of the estate scanned in the last 30 days, by asset class.
  3. Quarterly: verify that the primary method still matches the asset class. A "field" laptop that has sat in a dock for two quarters is a fixed desktop now, and the network scan becomes primary.

Test your own environment in 30 minutes:

  1. Export last month's network-scan host list.
  2. Export the list of assets that were off the corporate network for more than 3 days last month (VPN logs or your MDM tool).
  3. Count the overlap. The difference is your blind spot, and it is the size of the problem you are about to solve.

If you want a second pair of eyes on whether your current program actually covers your estate, our agent-based scanning service adds agent coverage to your existing network scans and reconciles the two inventories for you.

How Clone Systems Can Help

Clone Systems runs all three methods as one managed vulnerability program. Network vulnerability assessment covers the estate from the right vantage points, credentialed scanning deepens internal coverage, and agent-based scanning keeps off-network endpoints in the report. The reconciliation cadence above is built in, so the coverage gap is measured, not assumed. Contact us to scope a program for your environment.

Frequently Asked Questions

What is agent-based vulnerability scanning? A small piece of scanner software is installed on each host, and it reports its own software inventory, patch level, and configuration to a central console. It works whether or not the machine is on your network.

When should you use agent-based vulnerability scanning? Use it for assets that regularly leave the corporate network, such as company-issued laptops, field devices, and home-office machines. If a machine can be off-network for more than a few days, a network-based scan alone will miss it.

Can agent-based scanning replace network-based scanning? No. Agents cannot run on many of the assets on your network, such as printers, switches, and management interfaces, and a stopped agent fails silently. Network-based scanning still covers those assets and discovers anything your inventory has missed.

Do I need both agent-based and network-based vulnerability scanning? Yes. Network-based scanning covers the estate on the network and discovers unknown assets, while agents cover endpoints that roam. The strongest programs run both and reconcile the two inventories weekly.

What are the disadvantages of agent-based vulnerability scanning? The main costs are deployment, maintenance, and a silent failure mode: if the agent stops running, the host quietly drops out of your report. Treat any agent down for more than 7 days as a coverage finding and track it like any other vulnerability.

Conclusion

Your vulnerability program is only as complete as the assets it can see. A network-only program sees the building. The laptops that leave it are where the compromise starts, and closing that gap is a coverage decision, not a technology decision: agents where the asset roams, network scans everywhere else, and a reconciliation that proves the two together cover the estate. If you are not sure which of your assets are invisible today, talk to the Clone Systems team about a coverage review of your current program.

References

[1] NIST SP 800-40 Rev. 4, Guide to Enterprise Patch Management Planning: Preventive Maintenance for Technology, NIST CSRC, 2022. https://csrc.nist.gov/pubs/sp/800/40/r4/final [2] Zero Networks, 2026 Lateral Movement Exposure Report, 2026. https://zeronetworks.com/resource-center/reports/2026-lateral-movement-exposure-report [3] CISA, Known Exploited Vulnerabilities (KEV) Catalog, 2026. https://www.cisa.gov/known-exploited-vulnerabilities-catalog [4] Clone Systems, Agent-Based Scanning service page. www.clone-systems.com/agent-based-scanning/ [5] Clone Systems, Credentialed Scanning service page. www.clone-systems.com/credentialed-scanning/ [6] Clone Systems, Network Vulnerability Assessment Services. www.clone-systems.com/network-vulnerability-assessment-services/

Ready when you are

Have a scoping question this post didn't answer?

A senior specialist will walk you through it. No junior sales handoffs, no scripted qualifying rounds.