Scan Level

The default depth applied to every asset: passive enumeration, active enumeration, or vulnerability discovery.

Scan Level

Scan Level is the default depth Guard applies to all assets on this account. It is not a per-asset toggle (individual assets can still be frozen or deleted elsewhere).

The three levels

Label in the UI

What it does

Passive Asset Enumeration

Discovers assets from public sources only. Does not send packets to your infrastructure.

Active Asset Enumeration

Talks to assets on the network to discover services and configurations.

Vulnerability Discovery

Full vulnerability scanning (Nuclei). This is the default if no level has been saved.

The card shows the current label. Edit opens a radio list; Apply writes the scan-level setting.

Who can edit

Super-admin only. Customer Admins see Edit locked: Contact your Praetorian account team to update this setting. Scan depth is treated as a cost-control setting, same as the scan schedule.