Read a Windows PC's inventory from your Android phone
Prepare a Windows PC, read its hardware, software and defences from NetBlade on Android, schedule it and check its programs for known vulnerabilities.
NetBlade can read a Windows PC’s inventory from your phone without installing anything on it: Windows build, disks, installed programs with their exact versions, local administrators, and, if WinRM is on, hardware, services, updates and the state of antivirus, firewall and BitLocker. This article covers what the PC needs, how to run the inventory, how to schedule it and how to check the programs for known vulnerabilities.
Before you start
- A local administrator account on the PC, with a password. An account without a password cannot log on over the network.
- File and printer sharing enabled on the PC, with the network set as Private in Windows.
- The phone on the same local network as the PC.
- Windows inventory and the vulnerability check are advanced features: unlock them for 24 hours with “Watch a short ad · unlock everything for 24h”, or permanently with “Remove ads” in “Settings”.
1. Prepare the PC
NetBlade reads the basics over file sharing (SMB, port 445). For the extended data it uses WinRM on port 5985. On the PC, open PowerShell as administrator:
- To enable WinRM, run:
winrm quickconfig - Only on PCs in a workgroup (not joined to a domain), run this as well:
New-ItemProperty -Path 'HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System' -Name LocalAccountTokenFilterPolicy -PropertyType DWord -Value 1 -Force
The second command matters because on workgroup PCs Windows strips local accounts of their administrator rights when they log on over the network. Without it, disks and administrators come back missing, unless you use the built-in Administrator account.
Note: NetBlade never runs these commands for you. The app shows them under “How to get more data” so you can copy them.
2. Run the inventory
- Scan the network from the “LAN” tab.
- Open the PC’s details. The “Windows inventory” section appears when the device looks like a Windows PC.
- Tap the key icon and enter “User”, “Password” and “Domain (empty for a workgroup)”.
- Tap “Run inventory”.
Results are grouped into “System”, “Hardware”, “Software”, “Security” and “Accounts”. Program versions are read from inside each executable, so they match what the vendor calls the version, and the exact Windows build comes from the system itself.
Tip: If you manage several PCs with the same account, set the credentials once on the saved network instead: “Saved networks” → edit the network → “Windows PCs on this network”. Each PC can still have its own credentials, which take priority.
3. Read the results that matter
- Security: antivirus and signature status, firewall per profile, BitLocker encryption, TPM and SMB1. Any of these off is worth a question.
- Accounts: local administrators and groups. An unexpected administrator is the first thing to look into.
- System: disks and free space, last boot, signed-in user and clock drift.
- Software: installed programs with exact versions, the input for the vulnerability check.
4. Schedule the inventory
- Tap the router icon in the top bar (“Saved networks”) and edit the network.
- Under “Scheduled inventory” choose every 6, 12 or 24 hours (“Off” disables it).
- Save.
Each pass reads the PCs on the network and writes what changed to the “Network timeline”: inventory refused, new local administrator, disk almost full, security updates due, firewall, antivirus or encryption off, new share, new startup item, account enabled, new listening port. When a defence that was on is now off, you also get a notification.
Warning: Scheduled inventory acts only on the network the phone is connected to at that moment. If you are at home, your office PCs are not read, and they are read again when you are back on the office network. If several saved networks have different intervals, the shortest one applies.
5. Check the programs for known vulnerabilities
After an inventory, NetBlade can ask the National Vulnerability Database (NVD) which published vulnerabilities affect the exact versions of the programs it recognises, about seventy widely used products.
- In the PC’s details, after the inventory, go to “Known vulnerabilities”.
- Tap “Check online”.
- The first time, read the consent and accept it.
- Read the list, worst first, with CVSS score. Tap a CVE to open it on nvd.nist.gov.
What leaves the phone
Only the name and version of the recognised programs. Never the PC’s name, the full list of programs or your credentials. The check is opt-in and does nothing until you accept.
How to read the count
The summary says how many programs were checked, how many were not recognised, and how many could not be checked because the database did not answer. It never rounds this up to “all clear”. A program outside the dictionary simply gets no verdict.
Note: Answers are cached for a week, so a CVE published today may show up a few days later.
Check that it worked
- The PC’s details show “System”, “Hardware”, “Software”, “Security” and “Accounts”. If “Hardware” is thin, WinRM is not reachable yet.
- “Saved networks” shows how many PCs were read or refused, and a vulnerability summary such as “N CVE · M PC”.
- After a scheduled pass, the “Network timeline” (ⓘ “My network” → “Network timeline”) shows inventory events.
If something goes wrong
Tap “Why, and what to do”: it explains the specific reason. The most common ones:
- Port 445 closed. File and printer sharing is off, or the network is set as Public in Windows. Set it to Private.
- Credentials refused. Check user and password. For a local account, leave the domain empty. Accounts without a password cannot log on over the network.
- Disks and administrators missing on a workgroup PC. Run the
LocalAccountTokenFilterPolicycommand above, or use the built-in Administrator. - No hardware, services or defences. WinRM is off or blocked. Run
winrm quickconfig. NetBlade uses port 5985, not 5986. - Credentials gone after a restore. Windows credentials are encrypted on the phone and left out of every backup, on purpose. Enter them again.
Next
- Watch your network in the background
- Check an unknown network before you trust it
- NetBlade for Android guide: Windows inventory
← All how-to guides Feature guide → The product: NetBlade Android →