Read services across the network#

One row per service, ordered by how many machines expose it, turns a scan of many addresses into a picture of what the network actually serves.

The host table answers 'what is on this machine'. The Services pivot answers 'what is on this network'. That is usually the more useful question once a scan covers more than a handful of addresses.

Select Services beside Hosts above the results. The same scan data regroups: one row per distinct service instead of one row per address.

The Services pivot listing two open services with port, service name, product, version and a count of hosts exposing each

Read the service rows#

Each row is a port and service combination. Product and Version come from service detection, and Hosts counts how many machines expose it.

The table orders rows by that count, most widespread first, then by port number. The order is the point: it puts whatever is most prevalent on the network at the top.

This view aggregates only the ports the scan found open, or open and filtered. Closed and filtered ports do not appear, so the list shows what the network actually serves.

Why the count matters#

A service on one host is a machine to look at. The same service on thirty hosts is a standard build, and a version that is out of date there is out of date thirty times over.

The reverse is equally informative. When one host runs a version that differs from every other host running the same service, it is usually the machine that missed a patch round or was set up by hand.

Select a row to list the hosts that expose that service underneath, with a count in the header. Select one of those hosts to return to the Hosts pivot with that host selected. You can therefore go from a service you are concerned about straight to the machine that runs it, and read its full port list.

Until you select a row, the pane below reads Select a service to see the hosts exposing it.

When no services are listed#

The table reads No open services discovered when the scan found nothing open. If hosts came back up but no services are listed, the ports you scanned were closed or filtered on all of them. The next step is a wider port preset, because the default covers only the most common hundred ports.