blackbox testing

How to Use NetScan: A Step-by-Step Guide to Black-Box Vulnerability Scanning

Bugnexa team6 min read

Knowing what a security platform is and knowing how to use it are two different things. This guide walks through the practical workflow: signing in, adding assets, running scans, reviewing findings, scheduling continuous assessments, and generating reports. By the end, you should have a clear idea of how to run your first authorized assessment with confidence.

Before You Start: Authorization First

NetScan is designed for legitimate security testing. You should only scan systems you own or systems where you have explicit permission to perform security testing.

Before every scan, make sure:

l  The target is within the approved scope.

l  Stakeholders know that testing may generate traffic, alerts, or temporary disruption.

l  You are following company policy and applicable laws.

Without authorization, do not proceed.

Step 1: Sign In to NetScan

  1. Open the NetScan platform (https://netscan.in or your organization URL).

  2. Go to the Login page.

  3. Enter your email and password.

  4. Accept the Terms and Conditions.

  5. Continue.

Depending on your organization and account settings, NetScan may ask for a one-time password (OTP / 2FA) sent to your email. If OTP is enabled, open your inbox, enter the 6-digit code, and finish signing in.

Tips:

l  Use a strong, unique password.

l  Enable 2FA on your profile when it is available.

l  If your admin requires a password change on first login, complete it before starting any scans.

Step 2: Get Oriented in the Dashboard

After logging in, you will land on the NetScan dashboard. Think of it as your operations center. From there, you can usually access areas such as:

l  Dashboard overview

l  Assets

l  Scans

l  Findings

l  Schedules

l  Reports / Report creation

l  Users / team controls (based on role)

l  Settings / Profile

l  Support

Take a couple of minutes to understand the navigation before creating your first scan. It will save you time later.

Step 3: Add Your Assets (Define Scope)

Good scanning starts with a clear scope. Go to Assets and add the systems you are authorized to assess. These may include domains, websites, IP addresses, applications, services, or other in-scope network targets.

How to add assets effectively:

  1. Open Assets.

  2. Create a new asset entry.

  3. Use accurate names and identifiers.

  4. Keep ownership and environment clear (for example, production vs. staging).

  5. Only include authorized targets.

Why this matters:

l  It helps prevent accidental out-of-scope testing.

l  It makes findings easier to track by system.

l  It improves reporting clarity for stakeholders.

For your first run, start with a small, well-understood asset set instead of scanning your entire inventory on day one.

Step 4: Create a New Scan

Now you are ready to start an assessment.

  1. Go to Scans.

  2. Click to create a New Scan.

  3. Follow the scan wizard.

In the wizard, you will typically select the asset or target, confirm assessment details, accept the required authorization or terms confirmations, and start the scan. NetScan asks you to confirm that you are authorized to test the selected target, so take that confirmation seriously.

Practical advice for your first scan:

l  Choose one important but controlled target.

l  Use a maintenance window if the environment is sensitive.

l  Let the operations or SOC team know that a scan is taking place.

l  Keep a note of why the scan was started (release, audit, regression check, etc.).

Step 5: Monitor Scan Progress

After launching the scan, open the scan detail page to track its status (running, completed, or failed), progress, activity, and related outputs as they become available.

While a scan is running:

l  Do not repeatedly relaunch the same target unless it is actually needed.

l  Watch for the completion status.

l  Prepare your review checklist for the findings.

If a scan fails, check target reachability, confirm that the asset details are correct, verify network/DNS conditions, and retry only after you understand the issue.

Step 6: Review Findings

Once a scan is complete, go to Findings (or open the findings from the scan view). For each finding, look at the title or issue type, severity, affected asset, evidence and context, and the recommended direction for remediation.

How to review efficiently:

  1. Sort or filter by severity first (Critical/High before Low/Informational).

  2. Group findings by asset when multiple systems are involved.

  3. Validate the business impact with system owners.

  4. Mark or track items that need remediation.

  5. Separate real risk from lower-priority noise.

Remember that no scanner is perfect, and some findings may need human validation. Treat scan results as evidence-backed candidates for action rather than automatic proof that every issue is exploitable.

Step 7: Prioritize Remediation

A good NetScan workflow does not stop at detection. After reviewing the findings, create an action plan:

l  Critical/High: assign an owner and deadline immediately.

l  Medium: schedule remediation.

l  Low/Info: add to the backlog or treat as hardening work.

Helpful questions when prioritizing:

l  Is this internet-facing?

l  Does it expose credentials, admin interfaces, or sensitive data?

l  Is there an easy attacker path?

l  Does it affect compliance requirements?

l  Is there already a temporary mitigating control in place?

Then assign owners through your engineering or infrastructure process, such as a ticketing system or sprint board.

Step 8: Schedule Continuous Scanning

One-time scans are useful, but continuous scanning is where NetScan becomes an ongoing security program. Go to Schedules and create recurring assessments for key assets.

Good candidates for scheduled scans include:

l  Public websites

l  External APIs

l  Critical network entry points

l  Assets that change frequently

l  Systems tied to compliance evidence needs

Suggested cadence examples:

l  Weekly: high-value public assets

l  Bi-weekly / monthly: stable infrastructure

l  After major releases: on-demand scanning plus the existing schedule

Step 9: Create and Export Reports

Security work needs to be easy to communicate. Use Reports / Report Creation to generate outputs for engineering remediation, management updates, customer or stakeholder delivery, and audit or compliance discussions.

A useful report will usually include the assessment scope, when the scan took place, key findings by severity, affected assets, and recommended next steps.

Reporting tips:

l  Do not send raw scanner noise to executives—summarize the risk instead.

l  Keep deeper technical detail for engineers.

l  Include context: what was tested, what was found, and what happens next.

l  Re-scan after remediation and show progress over time.

Step 10: Manage Profile, Users, and Settings

Depending on your role, you may also be able to manage the workspace.

Profile: Update your details, change your password when required, and enable or manage 2FA/OTP settings.

Users / Roles (admin): Invite teammates, assign appropriate access, and remove access when people leave projects. Give people only the access they need because scan data is sensitive.

Settings (admin / org): Manage organization preferences, session and security policy-related controls, and branding or workspace configuration where available.

Best Practices for Using NetScan Well

  1. Always confirm authorization before scanning.

  2. Start small, then expand the scope.

  3. Keep the asset inventory accurate.

  4. Prefer recurring schedules for critical public systems.

  5. Triage findings quickly—delayed review reduces the value of the scan.

  6. Re-test after remediation.

  7. Keep executive summaries separate from deep technical detail.

  8. Protect account access with strong passwords and 2FA.

  9. Coordinate with SOC/IT so scans are not mistaken for attacks.

  10. Treat NetScan as part of a broader security program, not a one-click guarantee.

Final Thoughts

Using NetScan well is less about simply clicking “Start Scan” and more about building a repeatable habit:

l  Define scope.

l  Assess continuously.

l  Prioritize with evidence.

l  Remediate with ownership.

l  Verify with re-scans.

l  Communicate with clear reports.

By following these steps, you can move from your first login to a working vulnerability assessment workflow in days rather than months.

Call to Action

Ready to run your first authorized assessment?

Visit: http://187.127.189.62:3000

Need help scoping continuous scanning? Contact:  support@neetscan.com

#bugnexa#uses