Security, Vulnerability Scanning Program, General Information

Overview of Vulnerability Scanning Program including information on tools used and reports generated.

Introduction

This document details the security vulnerability program, common sources, tools, and policies used by Security for vulnerability management at the University of Illinois. 

Technology Services scanning is a supporting service/control and does not replace the responsibility of service owners, support teams, and administrators to identify and manage vulnerabilities, exposure, and associated risks on their systems and services.

As of June 15th, 2026, the Vulnerability Scanning Program has retired Qualys. CrowdStrike network scanning has been selected as the replacement. Due to differences in how CrowdStrike presents data, reporting will look different, and we are actively exploring options for building and delivering these reports.

Going forward, vulnerability discovery will primarily rely on the on-system CrowdStrike sensor rather than network vulnerability scanning. While CrowdStrike does offer network scanning functionality, current limitations mean that self-service scanning features will no longer be generally available.

We are continuing to test CrowdStrike's network vulnerability scanning capabilities as the vendor enhances functionality for devices without an installed sensor. Current testing focuses on scanner load capacity and overall scan times. Please do not be alarmed if you observe port scans from the following IP addresses: 192.17.170.4, 192.17.170.5, 192.17.170.10, 192.17.170.11, 192.17.170.13, 192.17.170.14. These test scans are performing basic open port discovery (similar to Nmap) and should not cause problems or high resource utilization on your devices.

As always, if you have questions or concerns, please contact securitysupport@illinois.edu.

Program Goals


System Vulnerability Scanning

  1. Goal: Continuously probe university systems and networks for vulnerabilities and exposures such that the university has the most accurate and timely information.
  2. Goal: Provide service owners with access to accurate and timely vulnerability information. 
  3. Goal: Perform timely scans of critical infrastructure including data centers.  
  4. Service: Consult with stakeholders, service managers, and interested parties regarding: understanding results, understanding tools available, security scanning practices, planning/prioritizing remediation, validating results.
  5. Limitation: Scanning is currently performed on the University of Illinois Urbana-Champaign and University of Illinois Springfield wired networks.

Application / Web application Vulnerability Scanning

  1. Goal: Continuously probe university web applications for vulnerabilities and exposures such that the university has the most accurate and timely information.
  2. Goal: Provide service owners with access to accurate and timely vulnerability information.
  3. Goal: Perform timely scans of web application infrastructure.
  4. Service: Consult with stakeholders, service managers, and interested parties regarding: understanding results, understanding tools available, security scanning practices, planning/prioritizing remediation, validating results.
  5. Limitation: Application owners must follow and implement secure coding practices for proper remediation of application vulnerabilities. Cybersecurity, Code Risk Discussion Questions

Internal / External Vulnerability Reports

  1. Goal: Provide a source for Internal / External agencies to report vulnerabilities.
  2. Goal: Review, approve, and implement appropriate external reporting and scanning services.
  3. Service: Validate reports and forward appropriate information to service owners and stewards.
  4. Service: Respond to critical vulnerabilities with appropriate action sanctioned by university leadership.
  5. Service: Report overall state of vulnerability detection capabilities and known campus vulnerabilities to campus leadership.
  6. Limitation: Internal scanning may only be conducted on services / systems owned by the unit and must use approved security tools.
  7. Limitation: External reports vary in quality and validation requirements may exceed staffing resources.  

Risk

Urbana campus and the Office of the CIO have approved network, system, and application scanning as a fundamental risk management practice. While scanning inherently carries some risk, efforts are made to limit impact to systems and services, and scanning tools and processes are regularly reviewed for effectiveness.

Vulnerability Scanning Practice and Tools


The below tools or services are commonly utilized as sources of vulnerability data on campus. 

Common sources of vulnerability data.
TOOL
DESCRIPTION
HOW TO GET/USE
CrowdStrike Falcon sensor Agent based threat and vulnerability detection

What is CrowdStrike?

CrowdStrike Network Scanning Active network scans run continuously  Currently for Technology Services Security team use only
Nmap Scriptable port scanner Free tool; Can be downloaded, installed and used by responsible IT pros on any Linux or Windows computer
CrowdStrike EASM Passive web application scanner run by CrowdStrike which continually scans for Illinois external assets Privacy and Security will monitor vulnerability reports and communicate confirmed vulnerabilities to unit
OWASP Zed Attack Proxy (ZAP) Web application vulnerability testing tool.
Can be used with the Desktop Graphical User Interface or Docker.
Free tool; Can be downloaded, installed and used by responsible IT pros.

Documentation, including their Getting Started Guide, is available .
  • Scan reports are considered confidential and should not be shared with non-stakeholders unless authorized by the campus Chief Information Security and Privacy Officer.
  • Vulnerability scans will be stored in the Security Office's logging environment for correlation with network based attacks.

Scanning Engine Source List

Technology Services maintains multiple vulnerability assessment technologies each targeting specific layer in the service delivery stack, though some degree of overlap exists in each.

Authorized scanning resources are listed below for general reference. This is a non-inclusive list as the vulnerability program needs it may use additional resources not listed here. External agencies both approved and not approved continuously scan our network for vulnerabilities.  If you have questions about scanning activity from the any source, feel free to contact securitysupport@illinois.edu

Authorized scanning resources
ENGINE TYPE(S)
FQDN
IP/NET
NOTES
Nmap, application scanning tools, etc. scanner.opia.illinois.edu

192.17.82.165

2620:0:e00:4008::5

Multipurpose security scanner, other tools used as needed
Crowdstrike Network Scanners

CRWDSTRKSCAN[01-06].ad.uillinois.edu

CRWDSTRKSCAN-UI (UIS scanner)

192.17.170.4

192.17.170.5

192.17.170.10

192.17.170.11

192.17.170.13

192.17.170.14

10.64.1.90

Scanning servers
CrowdStrike EASM --- 52.8.221.60 13.52.148.107 52.52.20.134

Passive web application scanner run by CrowdStrike which continually scans for Illinois external assets

Shodan census[1-12].shodan.io † †There are many shodan scanners, but they all should resolve to shodan.io addresses. Use the shodan web console to enumerate info found by Shodan.

IT Security Standards and Controls Information


CrowdStrike network scans meet the controls regarding unauthenticated vulnerability scanning: Network Security - IT 03.10.1, Client Computer Security - IT 10.10.1, Server Security - IT 04.10.1

Installing the CrowdStrike Falcon agent is required for High Risk systems.

Detailed information about security controls can be found at: https://go.illinois.edu/securitycontrols 

Recurring Scan Practices


Regular vulnerability scans are conducted to maintain accurate and timely vulnerability information for campus assets.  These scans are conducted with the CrowdStrike network scanning platform. Administrators and stewards are responsible for reviewing critical scan results and are expected to remedy or mitigate exposures in a timely fashion.

Continuous Wired Network Scan
  1. Every wired device on the network is to be scanned at least monthly.
    1. Current scanning covers 3,200 CDB asset groups and around 70,000 hosts.
  2. Scanning is scheduled based on asset groups in CDB and notification is sent based on primary contacts.
    1. You can update your primary contacts in CDB by following the guide:

      Networking, Contacts Database, How do I add remove or change info in CDB?

  3. The scan template has been determined to be the minimum required to get basic vulnerability information.
    1. Devices disrupted by this type of scan are considered vulnerable by default as this indicates susceptibility to DoS or other style attacks.
  4. Exceptions to scanning can be requested by completing this form: Scanning Exception Form
  5. Devices not excluded or scanned manually with this profile will be considered compliant with IT04.10.1 IT03.10.1 and IT10.10.1 vulnerability controls.
  6. If an IT Pro needs to cancel a currently running scan or the next scheduled scan, please reach out to SecuritySupport@illinois.edu 

Contacts


For any questions please email securitysupport@illinois.edu.



Keywords:
cybersecurity, vulnerable, scan, scanning, Nmap, EASM, CrowdStrike 
Doc ID:
89291
Owned by:
Security G. in University of Illinois Technology Services
Created:
2019-01-25
Updated:
2026-10-01
Sites:
University of Illinois Technology Services