Watch entry 04 · tool log
LizardSystems Network Scanner: the share detector
Ping sweeps stop at the door. This one opens it: computers, printers and shared folders enumerated over SMB, with the permissions each share actually enforces when an ordinary account knocks.
The evening it earned its keep
Seventeen devices on the sweep; fourteen answered SMB. Under those fourteen sat a printer nobody remembered sharing, and next to it a folder set to Everyone → Full Control sometime during a Windows upgrade two years prior. No drama, no breach — just a door standing open in a hallway nobody walks. Closed in ten seconds once seen.
Running it usefully
- Run as a standard user, not admin. The report then shows what any colleague could reach, which is the question that matters.
- Let it finish. Share enumeration is slower than pinging; interrupting it leaves the tree half-built and the report misleading.
- Export the HTML report before closing. It opens anywhere and reads better than a screenshot ever will.
Reading the permission column
For each share the scanner records whether your account could read and whether it could write. A share you can write to as a regular user is either intentional or forgotten, and on small networks it is forgotten far more often than anyone admits. That column is the reason to run this tool even when the sweep already told you the device count.
Free edition and the cap
The free build limits how many computers a scan returns. A flat with a laptop, a NAS and a printer may never meet the limit; a small office will, usually during the first serious audit — which is also the moment the licence becomes obviously worth it. The vendor's page carries the current numbers and a time-limited trial of the full product.
Vendor page: lizardsystems.com/network-scanner.