You can use an authenticated scan to test vulnerabilities on devices by checking the operating system, installed software, and operating system patches. Authenticated scans will also lower the percentage of false positives since it allows the scanner direct access using SSH or RDP. To see which operating system patches are missing, and which third-party applications are installed, you must provide access to the registry by way of the Remote Registry Service in Windows. 


To add authentication to an existing or new scan, do the following:

  1. Log in to beSECURE.
  2. In the upper-left corner of the Home page, select DevOps.
  3. Select Scans > Scan List.
  4. Select an existing scan or select the Newbutton to create a new scan.
  5.  Under the Settings tab, select the Authentication tab.
  6. In the Stored Credentials box, select the credentials to use with the scan, or add new credentials by populating the Windows Username, Windows Password, Windows Domain, and SSH Authentication parameters. Note: When adding a new SSH Host, leave the Port box empty to use port 22.
  7. Select Modify to save your changes.


For information on troubleshooting authenticated scans, see Troubleshooting Problems with Authenticated Scans.


For information on storing credentials, see What credential storage options are available?