GeoTrust Vulnerability Manager continuously scans your IP-based assets for security weaknesses, both externally and internally. So, you can quickly identify, prioritize, and fix vulnerabilities. This article gives you all the information you need to quickly start scanning your asset.
Before You Begin Using GeoTrust Vulnerability Manager
Make sure you have the following details ready to help your purchase and setup go smoothly:
- IPv4 Address
- The IP address of the asset you’d like to scan.
- Root access to the asset – if you want to install the internal agent.
- You’ll need admin or root permission to install our lightweight agent.
- Internet Connection
- Ensure the asset is connected to the internet for external scans, and that the internal agent (if installed) can communicate externally with our scanning platform to share its findings.
How to Set Up Vulnerability Manager
Follow these simple steps to begin securing your asset:
- Purchase GeoTrust Vulnerability Manager. (This is part of the GeoTrust Horizon platform.)
- Enter the IPv4 address of the asset you want to scan
- Choose your scan type: External, Internal, or Internal & External (recommended).
- Install the Internal Scanning Agent on your asset for deeper visibility (only required for internal scans).
Once your GeoTrust Vulnerability Manager account setup process is complete, your scans will begin automatically; external scans begin shortly after the subscription has been set up, and internal scans once your agent is installed and connected.
Your scan results will soon appear in your dashboard. You can then view, sort, and filter vulnerabilities, and access remediation advice to help you resolve them.
Choose Your Vulnerability Scan Type
You have three ways to scan your assets: External only, internal only, or the full combined coverage of internal & external.
| Scan Type | Description | Internal Agent |
| External | Scan your asset from outside your network to detect publicly exposed vulnerabilities. | Not Required |
| Internal | Scans from within your network to uncover configuration and system-level issues. Useful for scanning assets on a private network. | Required |
| Internal & External (Recommended) | Combines both scans for full coverage and the most accurate results. | Required |
Tip: If you do not have root or admin access to your asset, you can still scan for vulnerabilities by selecting External Only. This might be the case if you are on a shared hosting platform, like ionos, GoDaddy, or Fasthosts. Please check your web host’s policy on vulnerability scanning before beginning.
We do recommend installing the internal agent, if you can, as it will give you a more complete picture of any vulnerabilities your asset might have.
View and Resolve Vulnerabilities
When your scan completes:
- You’ll see a detailed list of vulnerabilities, grouped by severity — Critical, High, Medium, Low, and Very Low — in the Vulnerability Manager’s full report.
- Each finding includes remediation recommendations to help you fix the issue. For more tailored support, you can generate AI remediation guidance, which provides step-by-step advice based on the specific asset being scanned.
- After applying fixes, you can manually trigger a new external scan to confirm the vulnerabilities have been resolved.
- Internal scans are configured to run automatically every two hours, but the exact timing may vary depending on the asset’s capacity and current workload.
- For example, if a server is experiencing high levels of traffic, the agent may delay the scan to help maintain performance when it is needed the most.
Tip: Scans will return a mixture of “confirmed” and “potential” vulnerabilities. “Potential” vulnerabilities are those where one or more required conditions for confirmation are not met, so the tool detects a possible weakness but can’t fully verify exploitability.