Asset availability indicates whether Patrowl can identify an externally accessible service on an asset.
Our approach is designed from an attacker’s perspective: if a service is exposed and reachable from the Internet, it may be part of your attack surface and can therefore be assessed by Patrowl.
How does Patrowl determine whether an asset is Up or Down?
Patrowl continuously checks a set of commonly exposed services by scanning for open ports. The list of ports scanned depends on the protection mode applied to each asset:
Unprotected domains are checked against the most common ports (Top 100). This discovery confirms exposure and gives you the visibility needed to select the protection mode best suited to each asset.
Protected assets are scanned with precision across a list of 294 TCP ports, including service detection (version identification, banner grabbing, etc.) to accurately fingerprint the exposed technologies.
The top 6 ports are also scanned every 5 days on all domains, regardless of protection mode. This shorter interval keeps your exposure data current on the ports most commonly left open on the internet.
These ports include web services, remote administration services, databases, email services and other commonly exposed technologies. The list is derived from continuous analysis of the ports most frequently encountered across internet-facing assets, and is regularly updated to reflect evolving technologies and threats, ensuring the broadest possible coverage of your exposed attack surface.
Asset availability is derived from these observations:
An asset is considered
🟢 Upwhen at least one service has been observed responding on one of the monitored ports during the last 14 days.An asset is considered
🔴 Downwhen no responding service has been observed on any monitored port during the last 14 days.
The 14-day observation window provides a highly reliable availability assessment and reduces the risk of temporary network issues or isolated scan failures affecting the displayed status.
How does Patrowl detect banned scans?
In some situations, security controls such as IP filtering mechanisms may prevent Patrowl from accessing an asset.
When no responding service is detected from a probe, Patrowl performs additional verification checks to determine whether the asset is genuinely unavailable or whether our scanning probe is being blocked. If Patrowl can confirm that the asset remains accessible from an independent verification source (a clean IP) while one of our scanning probes is denied access, the asset status is displayed as 🟡 Banned.
This status is determined based on the latest probe result received for the asset. If multiple scans are running simultaneously, an asset may temporarily appear as 🟡 Banned when several probes are blocked. However, as soon as a subsequent probe successfully reaches an open port, the asset status is updated back to 🟢 Up.
It is also worth noting that the purpose of our scans is not to assess the resilience of the filtering layer itself, but to analyze the services and applications it protects. We therefore recommend allowlisting all of our scanning IP ranges, so that our testing covers your actual attack surface rather than the filtering layer in front of it.
Availability Checks by Protection Level
Patrowl performs availability checks on all assets, regardless of their protection status.
Protected Assets
Protected assets are checked weekly using the full set of covered ports (294)
Unprotected Assets
Unprotected assets are checked weekly on the most commonly exposed ports (top 100) and periodically validated against the full covered port list.
Availability Statuses
🟢 Up At least one responding service has been observed during the current observation window.
🔴 Down No responding service has been observed during the current observation window.
🟡 Banned The asset appears to be online, but Patrowl's scanners are currently being blocked by a security control.
⚪️ Unknown The asset has not yet been scanned by Patrowl.
