Scan Level

The default depth applied to every asset: passive enumeration, active enumeration, or vulnerability discovery.

Scan Level is the default depth Guard applies to all assets on this account. It is not a per-asset toggle.

The three levels

Label in the UI

What it does

Passive Asset Enumeration

Discovers assets from public sources only. Does not send packets to your infrastructure.

Active Asset Enumeration

Interacts directly with assets on the network to discover services and configurations.

Vulnerability Discovery

Full vulnerability scanning with Nuclei. This is the default if no level has been saved.

The card shows the current level. Click Edit, choose a level in the Scan Levels dialog, and click Apply.

Who can edit

Only super-admins can change the scan level. For other users, Edit is locked with the tooltip Contact your Praetorian account team to update this setting.