Network asset discovery tools: what a scan of the address ranges finds, what it misses, and how the result is reconciled against a small organisation's register

Network asset discovery tools scan an organisation's address ranges and list every device that answers: by ARP on the local segment, by ping and port probes across routed ranges, and by reading the tables in switches and the DHCP server. They are the agentless half of asset discovery, and for a small organisation they are usually a free scanner run by the IT manager before the quarterly close. This page sets out what a network scan finds and what it structurally misses, how the result is reconciled against the register to produce the unknown-device count, and where an agent is needed as well. The free discovery coverage worksheet on this site works the reconciliation from a scan's figures.

What a network scan finds: everything that answers on the ranges you pointed it at

A scan lists the addresses that answered, with a hardware address, often a manufacturer from it, sometimes a hostname and the open ports. On a small network that is the laptops and desktops in the building, the printers, the phones on the wireless, the switches and access points, the server, and the things nobody filed: the smart television in the meeting room, the badge reader, a contractor's laptop, a personal phone on the staff wireless. The scan finds them because they answered, not because anyone knew they were there, which is its whole value.

What a network scan misses: anything off the network, and any range you forgot

A scan cannot see a laptop at home, a phone in a pocket outside the building, a spare in a drawer, or a device on a range it was not pointed at, including the guest wireless and the site the scan forgot. It also cannot tell a device's holder or its warranty date, which live on the register. The coverage worksheet on this site asks for the off-network devices for exactly this reason: the estate is what answered plus what could not, and a scan that reports high coverage against a partial estate is reporting on the wrong denominator.

The reconciliation: three lists from one scan

Matched against the register by hardware address or hostname, the scan produces three lists. Devices found that the register does not know about: the unknown devices, to be identified and filed, blocked or closed. Register devices that should have answered and did not: lost, moved, or off the network without being recorded. And the matched devices, which confirm the register. CISA's directive to federal agencies sets discovery at every 7 days across the whole address space; a small organisation reconciling before each close, with all three lists recorded, is running the same control at its own scale.

Where an agent is needed as well

An agent installed on each device reports it wherever it is, so the laptop at home and the phone on the road are covered, and it reports the installed software, which a network scan cannot see. It cannot be installed on printers, badge readers or televisions. Most small organisations end up with both: the agent for the devices people carry, the network scan for everything else, and the register as the place both are reconciled. NIST's Cybersecurity Framework puts the inventory of hardware and software under its Identify function for the same reason: everything after it depends on the list being true.

Questions people ask about network asset discovery tools

What is the difference between network asset discovery tools and IT asset discovery tools?

Network discovery is the agentless half: scanning the ranges for what answers. IT asset discovery covers that and the agent-based half, where software on each device reports in. Most small organisations use both.

Can free network scanners do asset discovery?

Yes, for the scan. The reconciliation against the register, the unknown-device list and the history of each pass are the register's job, and the worksheet on this site works one pass's figures.

How often should a small organisation run a network scan?

Before each monthly or quarterly close is a good habit. CISA directs federal agencies to discover every 7 days, which shows what the control looks like when taken seriously.

A device on the scan has no register match. What should I do?

Identify it from the hardware address and the switch port, then either file it on the register with a holder, block it if it does not belong, or record it as a visitor's device. Leaving it unexplained is the one wrong answer.

Sources

Related answers

Start Depreo ProKeep the register, not the spreadsheet