NetBlade
iPhone · iPad Step 5 of 5 ~20 min Advanced

Inventory Windows and Linux PCs from your iPhone

Prepare Windows and Linux machines, read their inventory with NetBlade Pro on iPhone or iPad, and check Windows programs for known vulnerabilities.

NetBlade Pro can read what is inside the PCs on your network without installing anything on them: hardware, installed software, services, updates, accounts and the state of their defences. Windows machines are read over WinRM, Linux machines over SSH. This article shows how to prepare each kind of machine, run the inventory, check Windows programs for known vulnerabilities and follow changes over time.

Before you start

  • NetBlade Pro. Windows inventory, Linux inventory and the vulnerability check are Pro features.
  • The iPhone or iPad on the same local network as the PCs.
  • For Windows: an account allowed to log on over the network, usually a local administrator, with a password.
  • For Linux: an SSH server and a regular user account. No sudo needed.

Note: NetBlade changes nothing on your PCs. It only reads, and any command that prepares a machine is yours to run.

1. Prepare a Windows PC

iOS has no SMB client, so everything NetBlade reads from Windows comes over WinRM, on port 5985. Windows ships with WinRM switched off. On the PC, open PowerShell as administrator:

  1. Turn on WinRM: Enable-PSRemoting -Force
  2. Only on PCs in a workgroup, not joined to a domain, when you use a local account other than the built-in Administrator: New-ItemProperty -Path HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System -Name LocalAccountTokenFilterPolicy -Value 1 -PropertyType DWord -Force

The second command is needed because Windows hands local accounts a filtered token over the network, so a workgroup PC refuses them even with the right password.

You do not have to copy these from here: in the app, «How to get more data» shows both, each with a copy button.

Tip: Enable-PSRemoting refuses to run while the PC’s network is set to Public. In Windows settings, set the network profile to Private first.

2. Prepare a Linux machine

There is usually nothing to do: if you can SSH into it with a normal user, NetBlade can read it. The commands it runs are read-only and do not use sudo, so anything that requires root stays empty.

3. Save the credentials once (optional)

If many machines share an account, store it on the network instead of on each device:

  1. Open Saved › your network › «Credentials».
  2. Fill in the Windows (WinRM) and Linux (SSH) accounts.

A single machine can override them from its own page with «Credentials (this device)». Passwords are kept in the iOS Keychain, on this device only, and never go into the backup file.

4. Run the inventory

  1. Scan the network from the LAN tab and tap the PC.
  2. Tap «Remote inventory (Windows / Linux)» and choose the system.
  3. Enter the user and password. For Windows add the domain, or leave «Domain (optional)» empty for a local account. For Linux, check the port.
  4. Tap «Read this PC».

If it fails, NetBlade explains why and, where there is one, shows the command that fixes it.

What you get from Windows

System and uptime, hardware (processor, memory, BIOS serial), services, updates, local accounts, startup items, network adapters, disks, installed software, and «Defenses»: antivirus, firewall per profile, BitLocker per volume and TPM.

Program versions come from the Windows registry. They are complete, but less exact than versions read from the program file, which iOS cannot do without SMB. For the same reason there are no shared folders or user profiles.

What you get from Linux

Distribution and kernel, CPU and memory, disks, services and listening ports, users, containers, packages and pending updates, firewall, SELinux and AppArmor.

5. Check Windows programs for known vulnerabilities

The check asks the National Vulnerability Database (NVD) which published vulnerabilities (CVEs) affect the exact version of each program NetBlade recognises.

  1. Go to Settings › «Vulnerability check».
  2. Turn on «Check software for known vulnerabilities».
  3. Optionally, paste a free «NVD API key (optional)». Without a key NVD allows 5 requests every 30 seconds; with one, 50. On a PC with many programs the key makes the check much faster.
  4. Read, or read again, a Windows PC’s inventory.

Findings are listed worst first, with CVSS score and a link. The summary also appears in the device’s «Posture» and on the saved network.

What leaves your iPhone

Only the name and version of the programs NetBlade can match with certainty, sent to nvd.nist.gov. Never the machine’s name, its address or who is signed in. Nothing is sent until you turn the setting on.

Note: Only programs NetBlade can match exactly to the right database entry are checked. A program it does not recognise gets no verdict, which is not the same as “no vulnerabilities”. Answers are kept for a week. The check covers Windows inventories only.

6. Follow changes over time

Every inventory of a PC on a saved network feeds its «Network timeline»: antivirus, firewall or encryption turned off, reduced protections, enabled accounts, new startup programs, new administrators, new ports, disks nearly full and pending updates.

iOS does not let NetBlade run inventories in the background, so the timeline moves when you read the PCs. Make it a habit: read your key machines each time you are on site.

Check that it worked

  • The PC’s page shows the inventory with the date it was read.
  • For Windows, «Defenses» lists antivirus, firewall, BitLocker and TPM.
  • With the vulnerability check on, «Posture» shows findings, or says that nothing is known against the recognised programs.
  • Saved › your network lists the inventoried PCs.

If something goes wrong

  • Windows does not answer. WinRM is off or blocked. Run Enable-PSRemoting -Force on the PC; remember that a machine that only shares files will not answer, because iOS reads over WinRM only.
  • The account is refused on a workgroup PC. Run the LocalAccountTokenFilterPolicy command, or use the built-in Administrator.
  • The password is right but still refused. Accounts without a password cannot log on over the network. Check the domain field too: empty for local accounts.
  • Linux returns little. The data that requires root stays empty by design. A restricted shell may return nothing at all.
  • The vulnerability check is slow. Add an NVD API key in Settings.

Next

← All how-to guides Feature guide → The product: NetBlade iPhone · iPad →