Asset discovery is the automated scanning of a network, cloud and endpoints to find and identify connected devices and installed software for an inventory.
Asset discovery is the automated scanning of a network, and increasingly the cloud and individual endpoints, to find and identify the devices that are present and, in most implementations, the software installed on them. The output is a list of what is actually out there - hostnames, device types, operating systems, applications - which feeds an asset inventory or a CMDB, where each found component can become a record or a configuration item. Discovery answers “what is on our estate right now”; it deliberately says nothing about what you own, what it cost, or who is accountable for it.
What you will learn
- How asset discovery works
- Active vs passive scanning
- The asset discovery process step by step
- What discovery finds
- Why asset discovery matters
- How often should you run asset discovery?
- Cloud, SaaS and shadow IT discovery
- Common asset discovery challenges
- Discovery vs inventory
- When discovery is worth it
- FAQ
How asset discovery works
There are two broad ways to collect data, often combined:
- Agentless discovery scans from the outside. A scanner sweeps IP ranges and interrogates whatever responds, using protocols such as SNMP for network gear, WMI for Windows machines, and SSH for Linux. Nothing is installed on the endpoints, which makes it quick to roll out - but a device is only visible while it is switched on and connected to the network being scanned.
- Agent-based discovery installs a small program on each device that reports its details back over the internet. Remote and travelling laptops stay visible wherever they are, and the data is richer - but every machine needs the agent deployed, updated, and working.
Agent versus agentless is only one axis, though. The other is whether the scanner probes the network or merely listens to it - the active-versus-passive distinction covered next. Most tools schedule scans or run continuously, flagging new devices as they appear and marking devices that have gone quiet.
Active vs passive scanning
The second method axis is how aggressively the scanner reaches into the network.
- Active discovery proactively probes devices - ICMP ping sweeps, SNMP, WMI and SSH queries, port scans - to pull detailed, real-time data and catch machines that are idle or dormant but still reachable. The trade-off is that it adds traffic and, on sensitive or operational-technology (OT) environments, the extra probing can disturb fragile systems.
- Passive discovery simply watches the traffic already flowing on the network and infers what is there from it. It adds no extra load, which makes it safe for fragile environments, and over time it catches devices that ignore active probes. Its limit is the mirror image of active scanning: anything silent or powered down never shows up because it never sends traffic.
The key point is that agent/agentless and active/passive are two separate axes, not one choice. You can run an agentless scan actively or passively, and most mature setups combine active and passive collection because neither alone sees the whole estate. Note that AMPthilly does not perform any network, active or passive scanning - the sections here are general market education; AMPthilly is the register those findings are recorded in.
The asset discovery process step by step
Behind the methods sits a repeatable lifecycle. The labels vary between tools, but the stages are consistent:
- Discover - run the network, cloud and endpoint scans that generate raw signals about what is present.
- Normalise and de-duplicate - turn those raw signals into consistent records, merging the multiple readings that often represent the same physical device (a laptop seen by IP, by MAC and by agent should resolve to one item, not three).
- Classify and enrich - identify device type, operating system, owner and business criticality so a bare network reading becomes a meaningful record.
- Reconcile - feed the normalised records into the inventory or CMDB, flagging what is new, what has changed and what has gone missing. This is where a discovered component becomes a managed configuration item.
- Repeat continuously - because the estate keeps changing, the loop runs on a schedule or continuously rather than once.
This lifecycle is exactly why discovery and inventory are partners rather than rivals: discovery generates the signals, and the inventory or CMDB is where they are reconciled into a trustworthy record.
What discovery finds
A typical scan identifies the device type and model where it can, the operating system and version, hostname, IP and MAC addresses, and - with credentials or an agent - the installed software and sometimes hardware specifications. The software half is what makes discovery useful for licence work: comparing what is installed against the software entitlements the company actually purchased shows both compliance gaps and wasted seats under per-user licensing.
Why asset discovery matters
The case for discovery starts with a security maxim: you cannot protect what you do not know exists. Every unmanaged device is a potential blind spot, and discovery is what surfaces the things nobody put in the record - shadow IT, unauthorised or rogue devices, the forgotten test server, the personal laptop someone plugged in. An attacker only needs one of those; defenders need to see all of them.
The value runs straight into IT asset management and finance, too. An accurate, current picture of what is installed gives licensing a real base to reconcile against - the foundation for matching usage to software entitlements and spotting unused seats rather than over-buying. And it underpins compliance: a complete, up-to-date record of what exists is precisely what auditors and security reviews expect to see. Without discovery, both the security posture and the asset record are built on assumptions.
How often should you run asset discovery?
One-off or monthly scans are now considered outdated for any dynamic or hybrid estate, where assets are added, removed and reconfigured daily. A scan that is a month old describes a network that no longer exists. For that reason, continuous or frequently scheduled discovery - daily or weekly - has become the norm, so the record keeps pace with reality.
The practical choice is between two patterns. Continuous monitoring watches constantly and reflects changes almost as they happen, which suits fast-moving, security-sensitive environments. Periodic scheduled scans run at set intervals and are lighter to operate, which can be enough for steadier estates. For a small, stable estate, neither may be necessary at all - a disciplined labelled register kept current by hand can cover the need, as the section on when discovery is worth it explains.
Cloud, SaaS and shadow IT discovery
Traditional IP-range scanning was built for the on-premise world, and it has a blind spot that has only grown: it does not see cloud instances, SaaS subscriptions, or assets that live entirely off the corporate network. A spun-up cloud server, a department’s self-bought SaaS tool, and a remote contractor’s machine can all be invisible to a network sweep.
Modern discovery closes that gap by pulling from more sources - cloud-provider APIs that list running instances, SaaS and identity signals that reveal which applications people are actually signed in to, and log data that shows activity the network scan misses. This is how teams surface shadow IT (technology used without IT’s knowledge or approval) and unmanaged SaaS spend.
Worth stating plainly: AMPthilly does not perform network, cloud or API scanning. This section is general guide prose about how the discipline works in the wider market. Where AMPthilly fits is downstream - it is the register and inventory those findings are recorded into, so what discovery surfaces does not just get noticed once and forgotten.
Common asset discovery challenges
Discovery is powerful but not effortless, and the same problems recur across real deployments:
- Incomplete or outdated data and duplicate records. Raw scans throw up the same device under different identifiers, and yesterday’s snapshot drifts out of date quickly - which is why normalisation and continuous scanning matter.
- Intermittent devices. Anything that is only occasionally connected, or powered down during a scan, can slip through entirely.
- Coverage gaps. Cloud, remote, OT and BYOD assets often sit outside the reach of a standard network scan, leaving whole categories under-counted.
- Credential management. Authenticated scans see far more than unauthenticated ones, but they require credentials to be stored and rotated securely across many systems.
- The noise and privacy trade-off. Active scanning adds traffic and can feel intrusive; passive monitoring is gentler but slower and less detailed.
None of these is a reason to skip discovery - they are reasons it is a feeding mechanism rather than the whole answer. The business context (owner, cost, accountability) lives in the inventory, not in the scan.
Discovery vs inventory
Discovery and inventory are routinely conflated, and the difference matters. Discovery reports a snapshot of what is connected; an inventory is the maintained record of what the organisation owns and where it stands in the IT asset lifecycle. A network scan will never find the spare headsets in the cupboard, the projector in the boot of a car, or the laptop powered down in a drawer - and it cannot tell you a device’s purchase price, warranty status, or owner. Conversely, an inventory built only from purchase records will miss the unauthorised kit a scan finds in seconds. Mature setups use discovery to verify and enrich the inventory, and the inventory to give discovered devices business context.
When discovery is worth it
Discovery earns its keep when the network is too large or too fluid to know by hand: hundreds of connected devices, multiple sites, heavy remote work, or a compliance requirement to detect unknown machines. For a small team with a few dozen devices, a disciplined register with labels usually covers the need - the estate is small enough to know, and most of its value may sit in things a scanner cannot see anyway, from peripherals to software licences and physical kit with no network presence at all.
FAQ
What is the difference between agent-based and agentless discovery? Agentless discovery scans the network from outside - sweeping IP ranges and querying devices over protocols like SNMP, WMI, or SSH - so nothing is installed on the endpoints, but it only sees devices while they are connected to the scanned network. Agent-based discovery installs a small program on each device that reports in over the internet, so remote laptops stay visible wherever they are, at the cost of deploying and maintaining the agent on every machine.
What is the difference between active and passive asset discovery? Active discovery probes the network on purpose - ping sweeps, port scans and authenticated queries - to pull detailed, real-time data and catch idle or dormant machines, but it adds traffic and can disturb fragile or operational-technology environments. Passive discovery simply watches the traffic already flowing on the network, so it adds no load and is safe for sensitive systems, but it cannot see anything that is silent or powered down. Agent-vs-agentless and active-vs-passive are two separate axes, and mature setups usually combine active and passive because neither alone sees everything.
How often should you run asset discovery? In dynamic, hybrid environments where assets change daily, continuous or frequently scheduled discovery - daily or weekly - is now the norm, so the record reflects additions, removals and changes as they happen rather than drifting between rare scans. One-off or monthly scans are considered outdated for fast-moving estates. For a small, stable estate a disciplined labelled register kept current by hand can still be enough.
Why is asset discovery important? The short version is that you cannot protect, license or budget for what you do not know exists. Discovery surfaces shadow IT, rogue or unauthorised devices and forgotten systems that create security blind spots; it gives software licensing and finance an accurate base to reconcile against; and it underpins the complete, current record auditors expect. Without it, both the security picture and the asset record are built on guesswork.
Can asset discovery find cloud and SaaS assets? Not through traditional IP-range scanning alone, which only sees devices on the networks you scan. To cover cloud instances, SaaS subscriptions and remote assets, discovery has to extend through cloud-provider APIs, SaaS and identity signals, and log data. Combining those sources is how teams surface unmanaged SaaS spend and shadow IT that on-premise network scanning would never see.
What is shadow IT and how does asset discovery help find it? Shadow IT is hardware, software or cloud services used inside an organisation without IT’s knowledge or approval - the personal laptop plugged into the network, the team that bought its own SaaS tool on a credit card. Discovery helps by comparing what is actually present on the network, in the cloud and across identity and log signals against the sanctioned inventory, so anything unaccounted for stands out for review.
Is asset discovery the same as an asset inventory? No. Discovery finds what is connected to the network right now; an inventory is the curated record of what the organisation owns. Discovery cannot see offline equipment, spares in cupboards, or anything that never touches the network, and it knows nothing about purchase price, warranty, or who is accountable for an item. In practice discovery is one input that feeds and verifies the inventory, not a replacement for it.
What can asset discovery not find? Anything off the network: powered-down machines, spare equipment in storage, peripherals with no network interface, and devices on networks you did not scan - home networks, guest Wi-Fi, a branch office outside the range. It also records technical facts rather than business ones: a scan can report a device’s hostname and installed software, but not what it cost, when its warranty ends, or who is responsible for returning it.
Tools that make this easier
Discovery surfaces what is on the network; something still has to hold the record that scan results feed into - with owners, locations, purchase details and service history attached. That is where AMPthilly fits. It is one register for IT and physical assets where each item carries its serial number, supplier, purchase date and price, warranty dates, current owner and location, condition notes, and attached documents, all backed by a full audit history of checkouts, returns and changes. CSV import and export make it straightforward to bring discovered devices in and reconcile them against what you own, and QR labels scanned with a phone camera - no app to install - open each asset’s profile in the browser to check it in or out or report an issue. There is a free plan (3 users, 25 assets, no card required), so a small team can start building the record straight away.
The takeaway
Asset discovery is how you find what is connected to your estate - across network, cloud and endpoints, using agent or agentless collection and active or passive scanning - and it has become continuous rather than occasional because estates change daily. It matters because you cannot protect, license or budget for what you cannot see, and it is the front line against shadow IT. But discovery produces signals, not the full picture: it cannot see offline kit, business context, or who is accountable. Pair it with a maintained inventory and you get both halves - the scan that finds the unknown, and the record that makes it manageable.
Related terms
- Configuration Item - what a discovered component becomes in a CMDB
- Software Entitlement - the purchased rights discovery results are reconciled against
- Perpetual vs Subscription License - the licence models behind installed software
- Per-User Licensing - seat-based licensing where discovery exposes unused seats
- IT Asset Lifecycle - the stages an asset record tracks that a scan cannot see