Skip to content

Exploit Hound: Smart Scan and network monitoring

For the technician who runs an Exploit Hound agent on a customer network: how Smart Scan sweeps every 15 minutes and fully scans only genuinely new hardware (by MAC, not IP), how to turn it on for an agent and where its results appear, the three per-agent collectors (NetFlow / IPFIX, Syslog and port mirroring with BPF filters), exporting flows from a router, the seven-day baseline, and troubleshooting missing flows, memory and false positives.

Level
Intermediate
Length
About 50 minutes
Contents
3 lessons · 1 video · final exam
Status
Published · updated 2 Oct 2026
  • Exploit Hound

Skills you'll practise

  • Describe the Smart Scan cycle and predict whether a device change triggers a full scan
  • Enable Smart Scan on an agent with the right settings and interval units
  • Choose and configure the right collector (NetFlow / IPFIX, Syslog or port mirroring) for a monitoring need
  • Write or check router-side flow export and BPF filters for an agent
  • Troubleshoot missing flows, high agent memory and false positives using the documented checks

Course outline

  1. 1.Exploit Hound: Smart Scan and network monitoringVideo · 1 min
  2. 2.Smart Scan: new hardware onlyLesson · 17 min
  3. 3.Three collectors on the agentLesson · 17 min
  4. 4.Baseline, tuning and troubleshootingLesson · 16 min
  5. 5.Exploit Hound: Smart Scan and network monitoring: knowledge checkKnowledge check · 16 questions
  6. 6.Final exam9 questions · passing it completes the course, so people who already know the material can test out

Sources it draws on

The lessons and questions are written from these references, so learners can go back to the original.

See it with your own jobs and topics

Tell us about your team and we'll walk you through setup, from choosing jobs to your first skills check.