Find every device on your network

VECTOR is Kovira's agentless network scanner. Point it at your network and it discovers what is connected, identifies each device, and maps how everything links together. Included in every plan. See how it supports a current configuration record in our continuous discovery guide.

Finds everything, agents or not

Managed, unmanaged, or forgotten. VECTOR surfaces it.

Nothing needs to be installed on the machines being scanned. VECTOR works across whatever mix of vendors, operating systems, and ages you happen to have deployed, from a new server rack to the switch nobody remembers plugging in.

Run it on demand or on a schedule. Active probes are deliberately paced and do not write device configuration; every pass refreshes existing evidence rather than piling up duplicates.

When a scan reports its results, the observations flow directly through Kovira's correlation boundary and into the tenant-scoped CMDB. There is no separate CSV import or delayed synchronisation stage.

Key capabilities

  • No agent on the scanned devices
  • Works across managed and unmanaged networks
  • On-demand or scheduled
  • Paced discovery with no device-configuration writes
  • Direct, correlated CMDB ingestion after each scan

More than a device list

Devices, the links between them, and physical network topology.

Every responding device shows up in your CMDB (routers, switches, firewalls, servers, workstations, printers, IoT), each with enough detail to tell it apart from everything else.

The VECTOR collector is part of that model too. Registration publishes it as a device CI, and active collectors in the same tenant and customer scope can discover its CI identity, observed endpoint, and public keys for authenticated peering.

VECTOR also maps the shape of the network itself: LLDP and CDP neighbours, local and remote ports, VLAN membership, access and trunk roles, LAG bundles, link speed and state, spanning-tree root and port state, subnets, and the WAN links that tie sites together. The graph can isolate L2 or L3, colour links by VLAN, and lay the same evidence out as force, radial, tree, or STP. From managed switches, device-to-port presence answers both directions: what is connected to this port, and where was this device last observed?

With optional read-only SNMP access, VECTOR collects standards-backed chassis and software inventory, ENTITY-SENSOR health, POWER-ETHERNET PoE state, IEEE 802.1X sessions, and IEEE 802.3 LACP actor, partner, and aggregator state. Each observation is resolved through the same tenant-scoped device and port identities before persistence, so enrichment cannot create an orphaned topology object.

Subnet and VLAN inventory comes through alongside the topology, and WAN-link circuits get detected so the cross-site picture is part of the same map.

Key capabilities

  • Routers, switches, firewalls, servers, workstations, printers, IoT
  • Port-level connectivity from your managed switches
  • LLDP/CDP, VLAN, trunk, LAG, and STP evidence
  • SNMP chassis, software, sensor, PoE, 802.1X, and LACP evidence
  • Interactive L2, L3, VLAN-colour, and STP views
  • Device-to-port presence intelligence
  • Find any device on the network instantly
  • Subnet and VLAN discovery, WAN circuit detection
  • Collector-as-CI identity with authenticated WAN peering

Straight into your CMDB

No CSV exports. No sync step. No duplicates.

When a scan finishes, the results become part of your CMDB. Strong identities are normalised and resolved inside the tenant and customer boundary before a new record is accepted. A database claim prevents simultaneous writers from assigning the same active serial, asset tag, globally administered unicast MAC, or SSH host key to two device CIs.

If a unique match already exists, VECTOR attaches its source observation to that canonical record and preserves field provenance. If old data makes a match ambiguous, Kovira surfaces it for review instead of guessing. Topology data becomes validated relationships whose endpoints must exist in the same tenant, so the graph cannot silently accumulate dangling objects.

Key capabilities

  • Devices land in the CMDB automatically
  • Plays nicely with ATLAS and Microsoft 365
  • One record per device, even across sources
  • Concurrent duplicate claims rejected at the database boundary
  • Ambiguous matches surfaced instead of guessed
  • Topology becomes a working dependency map

VECTOR network scanner: frequently asked questions

The questions IT teams ask most often before pointing VECTOR at their first subnet.

Is VECTOR really agentless?
Yes. VECTOR is a collector you run on a machine inside the network you want to scan; it does not install software on discovered devices. Discovery sends deliberately paced network probes but does not change device configuration. Basic discovery needs no device credentials. Optional read-only SNMP access adds standards-backed chassis and software inventory, environmental sensors, PoE state, 802.1X session state, and LACP actor, partner, and aggregator evidence on devices that expose it.
Does VECTOR need credentials to scan my network?
No, not for basic discovery. VECTOR identifies devices through standard discovery protocols and paced active scanning. On managed devices, optional read-only SNMP credentials add the inventory and Layer 2 evidence the device actually publishes. Kovira keeps supplied credentials in its encrypted secrets vault; VECTOR does not write device configuration.
How does VECTOR map physical network connections?
VECTOR captures port-level connectivity from your managed switches and builds a device-to-port presence index. The result: for any device on the network you can ask which switch port it has been seen on, and for any switch you can see exactly what is plugged into each port. Both views are surfaced as cards on the device's CI page, so the topology you see in Kovira is what is actually wired into the rack.
Can I run VECTOR across multiple sites or networks?
Yes. You can run as many VECTOR collectors as you need in a single workspace, each scoped to its own subnets. A typical multi-site deployment has one collector per office or data centre, each scanning the local network and reporting back to the same CMDB. Results from every collector flow into the same configuration database and are deduplicated against existing records, so a device that responds in two places becomes one CI with both observations attached.
How do VECTOR collectors identify and peer with each other?
A registered VECTOR collector publishes itself as a device CI and advertises server-observed reachability plus its Ed25519 and X25519 public keys. Kovira returns only active peers in the same tenant and customer scope, excludes the requesting collector, and binds peer discovery to the collector's identity proof. Collectors can then establish an authenticated, forward-secret channel and report measured WAN paths back to the shared topology.
Will VECTOR slow down my network or trigger security alerts?
VECTOR is throttled and read-only by design. Active scans are paced to avoid saturating links or appearing as a port scan to your security tooling, and we recommend tagging the collector's source IP in your IDS or EDR so it does not generate false positives on initial deployment. For environments where active scanning is sensitive, VECTOR can run primarily in passive observation mode with active probes restricted to specific subnets or windows.

Be ready to scan on launch day

VECTOR will be in every plan at launch, including the free tier. Register your interest and be ready to point it at your first subnet the moment Kovira goes live.