Agent-based scanning installs software on each device, which then reports its installed software and missing patches back to a central console. Agentless scanning inspects devices from the outside, either over the network or, in the cloud, by reading disk snapshots through the provider's APIs. Agents give the most accurate, up-to-date view of laptops and servers, including ones that are rarely on your network. Agentless methods cover what agents can't, such as routers, firewalls and appliances, and they're quicker to roll out across cloud accounts. Most mature programs use both, matched to each asset type.
What are the main scanning approaches?
"Agentless" covers several quite different techniques, so it helps to separate them before comparing anything.
Unauthenticated network scanning
An unauthenticated scan probes systems over the network without logging in. It finds open ports, identifies services from their responses and flags known issues it can detect from outside, such as outdated service versions, weak TLS settings or default pages.
This is roughly the view an external attacker has. It's valuable for internet-facing systems and for discovering devices you didn't know about. But it can only guess at installed software from what services reveal, so it misses local vulnerabilities and can misreport versions. A common example is a Linux distribution that backports a security fix without changing the version string a service advertises.
Credentialed network scanning
A credentialed (authenticated) scan logs in to each system, typically over SSH or Windows remote management protocols, and reads the installed packages, patch levels and configuration directly. Accuracy improves dramatically, and the scan can see software that never listens on the network, such as browsers, runtimes and libraries.
The costs are operational. You need privileged service accounts on every target, network paths and firewall rules that let the scanner reach them, and a scan window when the systems are powered on and connected.
Endpoint agents
An agent is a small service installed on each host. It collects inventory and vulnerability data locally and sends it to a central platform, usually over an outbound connection to the internet. Because the agent doesn't depend on the scanner reaching the device, it reports from wherever the device is.
Cloud snapshot-based agentless scanning
In cloud environments, a newer agentless approach uses the provider's APIs to take a snapshot of a virtual machine's disk and analyze it separately. The scanner reads the file system to find installed packages, libraries and configuration, without logging in to the workload or touching its network.
This gives broad coverage across cloud accounts quickly, with no performance impact on the running instance. The trade-off is that it's a periodic, point-in-time view of what's on disk, not what's running in memory.
Agent vs. agentless: how do they compare?
| Unauthenticated network scan | Credentialed network scan | Endpoint agent | Cloud snapshot scan | |
|---|---|---|---|---|
| Visibility | Exposed services only | Installed software and config | Installed software and config, often running state | Installed software and config on disk |
| Accuracy | Lower, version guessing | High | High | High for disk contents |
| Load on target | Network probes | Login session during scan | Small, continuous | None on the running instance |
| Roaming laptops | Only when on the network | Only when reachable | Yes, from anywhere with internet | Not applicable |
| Ephemeral cloud workloads | Often missed | Often missed | Only if baked into the image | Good, if the scan interval fits their lifetime |
| Network devices and appliances | Yes, external view | Yes, where supported | No | No |
| Credentials to manage | None | Privileged accounts per target | None per scan | Cloud API permissions |
| Main operational effort | Scheduling, tuning | Credential and firewall management | Deployment, updates, health monitoring | Cloud permissions, snapshot cost |
No column wins every row, which is the whole point. Each method has a blind spot that another method covers.
Where do agents work best?
Remote and roaming endpoints
Laptops are the clearest case for agents. A laptop that spends most of its time on home or hotel networks may never be reachable when a network scan runs. An agent reports whenever the device has internet access, so patch status stays current regardless of location.
Servers where accuracy and frequency matter
Agents also suit long-lived servers, especially critical ones. They report frequently without needing a scan window, and there are no inbound firewall rules or shared privileged credentials to manage. Many can also pick up changes soon after they happen, such as new software being installed.
The costs of agents
Agents aren't free to run. Someone has to deploy them, keep them updated and notice when one stops reporting. An agent that silently failed three months ago produces no findings, which looks exactly like a healthy, fully patched machine.
There's also a small but real performance and stability cost on each host, and an agent is privileged software running everywhere. It becomes part of your vendor risk: if the agent or its update channel were compromised, it would have broad reach. Treat agent software with the same scrutiny as any other privileged component.
Where does agentless scanning work best?
Network devices and appliances
Routers, switches, firewalls, VPN gateways, storage arrays, printers and many security appliances can't run third-party agents. Credentialed network scans, often using SSH or device APIs, and unauthenticated scans are the only options. These devices are often internet-facing, and an unpatched edge appliance is one of the more serious findings a program can have, so this coverage matters.
Ephemeral cloud workloads
Auto-scaling instances may live for hours. Network scans on a weekly schedule will usually miss them, and agents only help if they're built into the image and register quickly. Snapshot-based scanning covers these workloads well, since it discovers instances through cloud APIs rather than IP ranges.
The better fix for short-lived workloads is to scan the machine image or container image they're launched from. If the image is clean and nobody patches instances in place, scanning the image effectively covers every instance launched from it.
The external view
Even with full agent coverage, keep running unauthenticated scans against your internet-facing address ranges. They show what an outsider can reach, including exposed management interfaces and services someone opened without telling anyone. Agents can't tell you that a database port is open to the internet because of a firewall misconfiguration.
The costs of agentless scanning
Credentialed network scanning concentrates risk in a small number of highly privileged accounts. Stolen scanning credentials would give an attacker access to much of the estate, so store them in a vault, rotate them, and restrict where they can be used from. Scans also generate network traffic and can occasionally upset fragile devices, so test before scanning operational technology or older equipment.
Snapshot scanning needs broad read permissions in each cloud account and carries some storage and compute cost. It may also need extra configuration for encrypted disks.
Why do most programs use a mix?
Because no single method covers every asset type, the practical question is which method to use for which assets. A reasonable starting point:
- Laptops and desktops: agents
- On-premises servers: agents, with credentialed scans as a cross-check
- Cloud virtual machines: snapshot scanning for breadth, agents on long-lived or critical instances
- Machine and container images: scanning in the build pipeline and the registry
- Network devices and appliances: credentialed network scans and configuration reviews
- Internet-facing ranges: regular unauthenticated external scans
- Unknown assets: discovery scans across all your address space
That last item is easy to skip. Compare discovered assets against the devices reporting through agents. Anything on the network without an agent is either a device that can't run one, which should be covered by network scans, or a coverage gap to fix.
Federal guidance takes the same mixed view. CISA's Binding Operational Directive 23-01, issued in October 2022, requires federal civilian agencies to run automated asset discovery every 7 days and vulnerability enumeration on all discovered assets every 14 days, including roaming devices such as laptops. It treats both credentialed network scans and agent-based detection as meeting its privileged-credentials requirement. The directive doesn't bind private organizations, but it's a useful benchmark for cadence.
Mixing methods creates one new problem: the same host shows up several times. Make sure your tooling or process deduplicates findings by asset, so a server seen by an agent and a network scan isn't counted and ticketed twice.
Frequently asked questions
Is agent-based scanning more accurate than agentless?
Agents and credentialed network scans are similarly accurate for installed software, because both read the system directly. Unauthenticated scans are much less accurate. The bigger difference between agents and credentialed scans is coverage of devices that are offline or off-network during the scan window.
Does cloud snapshot scanning replace agents?
For many cloud workloads it provides enough coverage on its own. Agents still add value on critical, long-lived instances where you want continuous reporting or runtime detail that a disk snapshot can't show.
How often should we scan?
Match the cadence to how quickly you can act and how exposed the asset is. Internet-facing systems deserve the most frequent checks. Agents report without needing a scan window, so the limit there is usually how often someone reviews the results.
Key takeaways
- "Agentless" covers three different methods: unauthenticated scans, credentialed scans and cloud snapshot scans.
- Agents win for roaming endpoints and long-lived servers; agentless methods win for network devices, appliances and broad cloud coverage.
- Keep running external unauthenticated scans, since they show what outsiders can see.
- Protect scanning credentials and treat agent software as privileged, high-trust software.
- Reconcile discovered assets against agent coverage to find the gaps.
- Assign each asset class a primary method, and deduplicate findings across methods.