Nerva: Service Fingerprinting
Nerva is Guard's network fingerprinting engine — identifying services, extracting versions, and correlating CVEs across your attack surface.

Every open port tells a story — and now Praetorian Guard reads it better than ever.
We've upgraded the service fingerprinting engine inside the Praetorian Guard Platform with Nerva, a ground-up rebuild of how Guard identifies what's running on every port across your attack surface.
This matters because knowing a port is open is only half the picture. The real question is: what service is behind it, what version is it running, and is it vulnerable? Nerva answers all three. It launches with over 120 protocol detections — from the usual suspects like SSH, HTTP, and PostgreSQL to industrial control systems, telecom infrastructure, and modern cloud services like Kubernetes and Kafka — and extracts rich metadata including version numbers and configuration details. That information flows directly into Guard's risk engine, enabling automatic CVE correlation and vulnerable service detection across your entire attack surface.
Nerva uses intelligent port-aware prioritization to test the most likely protocols first, so your attack surface inventory stays current without introducing scanning bottlenecks, even at scale.
But 120 protocols is just the starting line. Nerva's detection system is fully modular — each protocol is an independent plugin, making it straightforward to add new detections as the landscape evolves. And because Nerva is open-source, the security community can contribute new detections directly, with every submission going through a rigorous audit process before inclusion. This isn't a static capability that ships and stagnates. It's an evergreen detection engine that grows continuously, driven by both our team and the broader community.
For security teams, the impact is immediate: assets that previously showed up as "port 8443 open" now resolve to "Jenkins 2.387.3" or "Kubernetes API v1.28" — with associated CVEs and risk scores already attached. Vulnerable services surface faster, blind spots shrink, and your team spends less time investigating and more time remediating.
Nerva is open-source under Apache 2.0 and available on GitHub. Read the full technical deep-dive on the Praetorian blog.
Scan depth control
Nerva exposes a --scan-depth flag that lets you balance scan thoroughness against runtime.
Usage:
nerva --scan-depth fast
nerva --scan-depth thorough
Note: The legacy
--fastflag is deprecated. Use--scan-depth fastinstead.
Fingerprinter coverage
Nerva's plugin library is continuously expanded. The sections below describe the technologies currently detected.
AI inference servers
GitOps and Kubernetes tooling
Database administration
Oracle infrastructure
Backup and data protection platforms (CISA KEV)
IT management and help desk (CISA KEV)
CMS and web platforms (CISA KEV)
Network management
More in The Caesars
Augustus: LLM Vulnerability ScannerAurelian: Multi-Cloud Security ReconnaissanceBrutus: Modern Credential Attack TestingConstantine: Locates Fatal Security Bugs in Software & Code Repository Security AnalysisStill need help? Ask the team