Query-Based and IP Address-Based Scanning
The following active scanning adapters support query-based and IP address-based scanning:
- BACnet Scanner
- CIP Scanner
- Modbus Scanner
Using Query-Based Scanning
Instead of manually specifying IP address ranges with IP Address-based scanning, you can configure these adapters to scan devices that match a saved query in Axonius. This enables dynamic, automated scanning of assets based on any query criteria (location, department, risk level, etc.).
To use query-driven scanning:
- Create a saved query in Axonius that identifies the devices you want to scan (e.g., "All devices in Building 3" or "All OT devices with outdated firmware"). Make sure the query includes devices that communicate over the relevant protocols, for example: "All Modbus devices in Building 3" or "ALL OT CIP devices with outdated firmware"
- When creating a Device Scan job, select a saved query to define which devices to scan.
- The adapter automatically resolves the query to extract IPv4 addresses from the devices that match the query.
- The adapter scans those IPv4 addresses using the appropriate protocol (BACnet, CIP/EtherNet-IP, or Modbus TCP).
Benefits:
- Dynamic targeting - The list of devices to scan updates automatically as devices move in/out of your query criteria.
- Context-aware scanning - Target specific devices based on business context (location, compliance status, risk level).
- Reduced manual configuration - No need to maintain static IP range lists.
- Integration with workflows - Combine with Enforcement Center actions for automated response.
Example Use Cases
- Location-based scanning: Scan all OT devices discovered in a specific facility or network segment.
- Risk-based scanning: Regularly scan devices identified as high-risk by other security tools.
- Compliance validation: Scan devices that need validation against specific compliance requirements.
- Follow-up scanning: After discovering devices with network discovery adapters, use active scanners to gather detailed protocol-specific information.
Notes
If a query is configured, the manually-specified IP range is ignored.
If a query is configured but matches no devices or has no usable IPv4 addresses, no scan will occur.
If no query is configured, the adapter falls back to the manually-configured IP range (existing behavior).
Duplicate IP addresses are automatically deduplicated across multiple devices.
Using IP Address-based Scanning
Use IP address-based scanning to scan all devices on a specific network segment.
- When creating a Device Scan Job, select IP Address/Subnet and enter the values in the text field.
The adapter will only scan devices in this network segment.
Updated about 2 hours ago
