Network scan
Build a TLS certificate inventory by scanning hosts and ports over the network.
Introduction
Network scan discovery uses the Horizon Client agent (horizon-cli) to probe a range of hosts and ports over the network, retrieve the TLS certificates they present, and feed them back to Horizon. It lets you build a certificate inventory across your infrastructure without deploying anything on the target hosts.
This guide walks through configuring a discovery campaign for a network scan, running the scan, viewing the results, and the next steps for working with what you find.
Prerequisites
The agent must be installed and configured on the host that will perform the scanning before you start. Follow Installing the Horizon Client to install the agent and create its configuration (API ID/key and endpoint), then confirm it can reach Horizon:
horizon-cli pingIf ping succeeds, the agent is ready. The scanning host must have network access to the target hosts and ports you intend to scan — check that firewall rules allow outbound connections from it.
Configure the campaign
A discovery campaign is the object in Horizon that scan results are fed into. Create it in the Horizon web interface under the Discovery section before running the agent.
When creating the campaign, set:
- Name — a unique name. It must not contain dots (for example
net-scan-prod, notnet.scan). The agent references the campaign by name. - Description — optional, for your own reference.
- Enabled — leave the campaign enabled so it can receive results.
- Hosts — the IP addresses, CIDR ranges, or hostnames to scan, one per line (for example
10.0.0.0/24orserver.example.com). - Ports — the TCP ports to probe on each host. The default is
443. Add any additional ports your services use (for example8443,8080). - Authorization levels — who is allowed to search the campaign's results and who is allowed to feed it. Each can be set to everyone, authenticated, or authorized. Make sure the account the agent authenticates as is allowed to feed the campaign.
- Grading policies (optional) — attach one or more grading policies so that discovered certificates are graded automatically as they come in.
Service account
The agent authenticates to Horizon using an API ID and key. For production scans, create a dedicated service account in Horizon with the minimum permissions required: feed access on the campaign, and read access to the profiles used for discovery. Avoid using a personal account — if credentials are rotated, the scan will fail.
Run the network scan
On the host where the agent is installed, run the network scan and point it at your campaign:
horizon-cli netscan --campaign=<campaign-name>The agent reads the Hosts and Ports defined on the campaign and probes each combination. Run the command with sufficient network access — on restricted systems, confirm the scanning host can reach the targets before starting a large scan.
To override the hosts and ports from the command line rather than reading them from the campaign:
horizon-cli netscan --campaign=<campaign-name> --hosts=10.0.0.0/24 --ports=443,8443See the results in the dashboard
Once the scan finishes, the agent feeds its findings to Horizon:
- The run is recorded as discovery events (success, warning, or failure), so you can confirm the scan completed and review any warnings.
- The discovered certificates appear in Horizon with their discovery metadata (the host and port they were found on), and in your certificate inventory.
- If you attached grading policies to the campaign, each discovered certificate shows its grade immediately.
To track discovery over time, add a certificate or discovery chart to a dashboard — for example, discovered certificates by grade or by expiry window.
Next steps
After reviewing the discovered certificates, you have two main options for each certificate:
Monitor it. Keep the certificate in the discovery campaign to track its expiry and grade over time. No further action is needed — discovered certificates do not count toward your licence usage.
Migrate it to a managed profile. If you want to take over the lifecycle of a discovered certificate (renew it through Horizon, apply policies, automate deployment), enrol a new certificate against a managed profile using the same subject and SANs, then revoke or let the old one expire. The new certificate will then appear in your managed inventory.
Schedule recurring scans
To keep your inventory up to date automatically, create a periodic task on the scanning host:
horizon-cli netscan --campaign=<campaign-name> --create-periodic-task --period=weeklyThe --period value can be:
- daily — every day between 00:00–04:00 UTC
- weekly — every Sunday between 00:00–04:00 UTC
- monthly — the first day of each month between 00:00–04:00 UTC
To remove a scheduled task:
horizon-cli netscan --campaign=<campaign-name> --remove-periodic-taskGet command help
Every command supports --help for the full list of options:
horizon-cli netscan --help