> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning Your Network

> How Docusnap365 captures your network automatically – from the gateway to the first scan job.

Docusnap365 captures your IT landscape automatically through scan modules —
one for each kind of source, such as Active Directory, Windows or VMware. For
this you create a **scan job**: the named configuration of gateway, targets,
credentials and schedule. A single pass of a job is called an execution.

## Requirement: a gateway

A job always runs through a **Docusnap Enterprise Gateway** — the Windows
service in your network that connects it to Docusnap365. Without a connected
gateway, no job can start.

<Note>
  You do not have to set up the gateway in advance. Starting a new scan job
  walks you through the setup first if none is connected yet, then continues to
  the module selection.
</Note>

One gateway is enough for one network; for separate sites or networks, set up
one more each. Installation details are in
[Installing and Registering the Gateway](/docs/en/scan/gateway-install).

## Choosing a scan module

*Scan › Scan Modules* shows the catalog of all modules, grouped into
*Favorites*, *Active Modules* and categories such as *System*, *Cloud* or
*Virtualization*.

<Tip>
  For a new tenant with no existing jobs, Docusnap365 suggests *Active
  Directory*, *Windows (AD)* and *SNMP v1 and v2* as a starting point.
</Tip>

## Targets, credentials and schedule

The wizard asks for the targets — depending on the module, IP addresses,
ranges, host names or a domain — and credentials for access. You create
credentials as *Reusable*, so they remain available in the vault for further
jobs, or as *One-time*, for this one job only.

<Note>
  One-time credentials are not saved. A job with one-time credentials therefore
  cannot be run again without entering the credentials once more.
</Note>

In the last step you decide whether the job runs immediately or on a
schedule. The closing button reads *Run Now* or *Schedule Job* accordingly.

## Following the first scan

*Scan › Dashboard* shows how many assets are captured, when the last scan
ran, how many gateways are connected and how many systems are still unknown.
The *Action Required* section flags *Failed Scans*, credentials that have
expired or are expiring, and *Unused Scan Modules*.

<Note>
  A captured system without a recognized type appears under *Unknown Systems*
  with the line *Typing pending*. It can be assigned a type
  afterwards.
</Note>

## What the first scan fills in automatically

Once the first scan is through, several areas fill in automatically: the
inventory under *Assets*, the software found along with its vulnerabilities
under *Analysis*, and — if NTFS was captured — the permission structure
there as well. The commercial data — responsibility, costs, warranties — does
not come from the scan. It comes from ITAM and is entered there.

## Related

[Storing Credentials Locally and Running Your First Scan](/docs/en/scan/tutorial-first-scan)
walks through the gateway, credentials and the first Active Directory and
Windows scan step by step. An overview of all modules is in
[Scan Modules](/docs/en/scan/scan-modules); what scanning means in general is in
[Scanning Fundamentals](/docs/en/scan/understanding-scanning). Once the assets are
there, add their [ITAM data](/docs/en/itam/manage-data) and back your NIS-2
requirements with captured systems instead of manual entries — see
[Assessing NIS-2](/docs/en/getting-started/nis2).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.