Find the exposure.
Prove the response.
NetworkPilot turns authorized external scanning, continuous posture monitoring, CVE evidence, and remediation history into one defensible record—built for client conversations, cyber-insurance documentation, and the work between assessments.
One target. Clear answers.
Choose a diagnostic, enter a public domain, and get a readable result without the terminal archaeology.
DNS Lookup
Inspect A, AAAA, MX, TXT, NS, CNAME, CAA, and SOA records.
From authorization to verified remediation.
The useful part of a security assessment is not a single scan. It is the chain of custody around what was allowed, what was tested, what changed, and what the organization did next.
Authorize the asset
Prove a domain with DNS or record an accountable authorization attestation for a public IP.
Choose the right depth
Launch a focused scanner, a repeatable assessment pack, or isolated worker coverage.
Follow real execution
Watch authorization, resolution, collection, discoveries, and evidence sealing as they happen.
Prove the follow-through
Assign remediation, set a due date, retest the finding, and export the retained evidence.
Focused profiles. Honest confidence.
Start with fast public-surface checks, move into isolated network discovery when the scope calls for it, and retain exactly what was performed or skipped. Ambiguous service evidence is reported as limited—not promoted into a guessed vulnerability.
Baseline posture
A broad, non-invasive review of DNS, HTTPS, response headers, and public hardening controls.
Domain recon
Capture recursive DNS answers, mail routing, SPF/DMARC posture, certificate policy, and public address inventory.
SSL/TLS scanner
Validate certificate identity and lifetime, record negotiated TLS, and probe legacy TLS support on up to four public endpoints.
Web surface
Review HTTPS redirects, browser protections, robots.txt, and RFC 9116 security-contact publication.
Port scanner
Map TCP exposure with Quick, System Range, custom, or isolated full-range coverage on an authorized asset.
Network Assurance
Full TCP discovery with safe TLS and HTTP protocol pivots, certificate-chain analysis, service evidence, and exact NVD correlation.
Critical CVE scanner
Correlate exact versioned CPE identifiers to high and critical NVD CVEs, with CISA known-exploited findings prioritized.
UDP Exposure
Probe the 100 most frequently exposed UDP services from a separately isolated, rate-limited worker and preserve open versus open-or-filtered evidence.
Safe Vulnerability Validation
Run a pinned, reviewed Nuclei template bundle against confirmed web services with redirects, OAST, fuzzing, code, headless, and credentialed checks disabled.
Repeatable scope without repetitive setup.
Launch coordinated profiles against the same authorized domain and follow one unified activity timeline.
Build a broad external baseline across DNS, mail policy, TLS, web controls, and the quick TCP exposure map.
5 PROFILES · ONE LAUNCH · UNIFIED TIMELINERecheck transport, certificate health, response protections, disclosure, and public policy files.
3 PROFILES · WEB POSTURE · REMEDIATIONBuilt for the work that follows.
NetworkPilot keeps exposure history, customer boundaries, and remediation accountability in the same workspace as the technical evidence.
Monitoring that sees more than ports.
Track DNS, mail policy, HTTPS availability, certificate health, browser protections, and TCP exposure. NetworkPilot records meaningful drift without turning ordinary timing noise into an incident.
Every client stays in the right lane.
Separate client workspaces preserve role-scoped assets, scans, monitors, reports, and evidence. Invite administrators, analysts, and viewers without mixing customer data.
Findings become accountable work.
Move findings from open to in progress, document accepted risk, assign ownership and due dates, then use a later scan to prove whether the condition is gone.
A report that shows
what actually happened.
Every completed assessment can preserve the authorized target, scope, scanner version, methodology, observed addresses, findings, remediation guidance, and a canonical SHA-256 integrity fingerprint.
- ✓Insurer-ready PDF and machine-readable JSONClear evidence for renewals, client reviews, and retained technical records.
- ✓NIST CSF and CIS contribution mappingUseful framework context with explicit boundaries—never a blanket compliance claim.
- ✓Role-scoped and brandable deliveryMSP workspaces retain the correct client boundary and can carry provider branding.
8f1c…4d97verified at exportDefensive intelligence.
Deliberately constrained.
NetworkPilot helps owners understand their public attack surface while reducing the chance that the platform itself becomes an abuse tool.
- ✓Pinned public resolutionPrivate and reserved destinations are rejected, and scans connect to the validated public address.
- ✓Signed, bounded worker scopeDeeper jobs use short-lived signed manifests, rate limits, cancellation, and one pinned public address.
- ✓Safe validation policyCurated templates disable OAST, fuzzing, code, headless, credentials, and exploits. Credentialed and exploit activity is not offered.
Ready when the renewal questionnaire arrives