How do hackers find vulnerable computers?
The short answer: Hackers do not have to manually search for individual businesses or computers. Automated tools can scan internet connected systems looking for exposed services, open ports, outdated software, default credentials, remote access systems, and known vulnerabilities. Once something interesting is discovered, additional automated tools may determine whether that system can be attacked.
Your business does not need a flashing sign saying:
"We are vulnerable."
An exposed system can effectively advertise that fact on its own.
That is one of the most important concepts for business owners and IT leaders to understand about modern cybersecurity.
Attackers can automate discovery.
They can automate reconnaissance.
They can automate password attempts.
They can automate vulnerability checks.
And in some cases, they can automate portions of the attack itself.
The internet is therefore not simply a network that allows your business to communicate with customers, employees, vendors, cloud applications, and other organizations.
It is also an environment in which publicly accessible technology can potentially be discovered, identified, categorized, and tested.
That raises an important question:
How Do Hackers Actually Find Your Computer or Network?
One of the answers is surprisingly simple.
They look.
But increasingly, software does the looking for them.
What Is Internet Scanning?
Internet scanning is the process of systematically checking internet connected addresses and systems to determine what is accessible.
Scanning itself is not inherently malicious.
Security researchers scan.
Cybersecurity companies scan.
Network administrators scan.
Government cybersecurity programs scan.
Search and discovery platforms scan.
And attackers scan.
CISA, the U.S. Cybersecurity and Infrastructure Security Agency, operates vulnerability scanning services designed to help organizations identify internet accessible vulnerabilities before adversaries exploit them.
The fundamental concept is straightforward:
If a system is reachable from the public internet, someone may be able to discover that it exists.
The important cybersecurity question becomes:
What will they discover when they find it?
What Is an IP Address?
To understand internet scanning, it helps to understand one basic piece of networking.
Devices communicating across the internet use Internet Protocol addresses, commonly called IP addresses.
You can think of an IP address somewhat like a street address for internet communications.
That analogy is not technically perfect, but it is useful.
If someone knows a street address, they know where a building is located.
If a system is publicly reachable through an IP address, other systems may potentially attempt to communicate with it.
Attackers therefore do not necessarily need your company name to begin discovering your infrastructure.
They may start with internet addresses.
Do Hackers Need to Know My IP Address First?
Not necessarily in the way most people imagine.
A common assumption is:
"How would a hacker ever get our IP address?"
That assumes the IP address is a secret.
Publicly accessible internet infrastructure generally should not be treated as secret simply because your employees do not know the address.
Internet discovery platforms and scanning technologies can identify publicly reachable systems.
CISA specifically references tools capable of identifying internet connected assets and recommends organizations assess which of their assets are accessible through the internet.
The security strategy therefore should not depend on:
"Hopefully nobody finds us."
It should depend on:
"If someone finds us, what can they reach?"
What Happens When a Hacker Finds an IP Address?
Finding an address is only the beginning.
The next question is:
What is running there?
A single internet address may expose one or more network services.
An automated scanner can attempt to determine whether particular services respond.
This introduces another important networking concept:
What Is a Port?
A network port helps computers direct network communications to particular services.
A useful analogy is an office building.
The IP address tells you which building you have reached.
The port helps identify which door or department you are trying to communicate with.
Different applications and protocols commonly use different ports.
For example, organizations may operate services associated with:
- Websites
- VPN connectivity
- Remote administration
- File transfer
- Remote Desktop
- Secure Shell, or SSH
- Databases
- Voice systems
- Cameras
- Network appliances
- Cloud services
A port being open is not automatically a security vulnerability.
Businesses need network services to communicate.
The question is whether the service should be publicly accessible and whether it is properly protected.
What Is Port Scanning?
Port scanning is the process of checking a system to determine which network ports appear accessible.
Administrators use port scanning for legitimate security and troubleshooting purposes.
Attackers can use the same general technique for reconnaissance.
Imagine walking around an office building and checking which entrances exist.
One door might lead to reception.
Another might lead to a loading dock.
Another might lead to an employee entrance.
Another might lead to a maintenance room.
Knowing a door exists does not automatically provide access.
But it provides information.
That information can help determine what to investigate next.
What Are Hackers Looking for During a Scan?
An attacker may be interested in several things.
1. Open Ports
An open port can indicate that a network service is available.
The attacker may then try to identify what service is responding.
2. Software Information
Some services provide information that can help identify the software or technology responding.
That information may help determine whether known vulnerabilities exist for that product or version.
3. Remote Access Services
Services providing remote administrative access deserve particular attention because they may provide a path into sensitive systems if they are improperly exposed or inadequately protected.
4. Administrative Interfaces
Routers, firewalls, cameras, servers, applications, and other appliances may contain web based management interfaces.
Those interfaces should not automatically be accessible from everywhere simply because administrators need convenient access.
5. Default Configurations
Factory configurations can sometimes expose unnecessary services or rely on default administrative credentials.
6. Known Vulnerabilities
Once a scanner identifies a particular technology, additional systems may check whether that technology appears vulnerable to known security flaws.
7. Outdated Software
Older software may contain vulnerabilities that have already been documented and patched by the manufacturer.
8. Internet of Things Devices
Cameras, sensors, routers, building systems, and other connected devices can also be discovered when improperly exposed.
CISA specifically warns organizations about internet accessible assets including IoT, industrial IoT, remote access technologies, and other infrastructure.
How Does an Attacker Know What Software I Am Running?
Sometimes network services reveal characteristics about themselves.
This is sometimes referred to as service identification or fingerprinting.
The response from a device can provide clues about:
- The protocol being used
- The application
- The operating system
- The device manufacturer
- The product family
- The software version
- The type of hardware
- The encryption configuration
An attacker can combine multiple clues to make an educated determination about the technology behind an internet accessible service.
That matters because vulnerabilities are frequently associated with particular products or software versions.
The attacker's workflow can become:
Find device
↓
Identify service
↓
Identify software
↓
Determine possible vulnerabilities
↓
Test whether exploitation may be possible
Automation can make portions of this process extremely fast.
How Do Hackers Find Known Vulnerabilities?
Cybersecurity vulnerabilities are documented by vendors, researchers, government organizations, and security databases.
Many publicly disclosed vulnerabilities receive a standardized identifier called a CVE, or Common Vulnerabilities and Exposures identifier.
This standardization is useful for defenders because it allows organizations to identify affected software and prioritize remediation.
But public vulnerability information can also inform attackers.
Once a vulnerability is publicly understood, defenders and attackers may both know about it.
The difference is what each side does with that knowledge.
Defenders ask:
"Do we have this vulnerability?"
Attackers ask:
"Who has not fixed it yet?"
What Is CISA's Known Exploited Vulnerabilities Catalog?
Not every vulnerability carries the same level of practical risk.
CISA maintains a Known Exploited Vulnerabilities Catalog, commonly called the KEV Catalog.
It identifies vulnerabilities for which there is evidence of exploitation in the wild.
For security teams, this provides valuable prioritization information.
A vulnerability that attackers are actively exploiting deserves particular attention.
This illustrates an important principle:
Patch management should consider both severity and actual exploitation activity.
Can Attackers Automatically Search for Vulnerable Software?
Yes.
Once a vulnerability and its identifying characteristics are known, automated systems can potentially search for systems that appear to be affected.
This is why organizations should take internet facing vulnerabilities particularly seriously.
Imagine a manufacturer announces:
"A certain model of electronic door lock has a security flaw."
That announcement helps owners fix their locks.
But criminals can also learn which model to look for.
Cybersecurity operates under a similar dynamic.
The answer is not to hide vulnerability information.
Responsible disclosure allows defenders to fix problems.
The answer is to patch vulnerable systems promptly and reduce unnecessary exposure.
How Quickly Can Attackers Find a Newly Exposed System?
Businesses should operate under the assumption that publicly accessible systems may eventually be discovered.
It is unsafe to assume:
"We'll expose this temporarily. Nobody will notice."
or:
"Nobody knows this server exists."
or:
"This is only a test system."
or:
"We'll secure it later."
Automated discovery changes the risk calculation.
The longer unnecessary exposure exists, the more opportunity there is for someone or something to discover it.
What Is a Honeypot?
A honeypot is a system intentionally designed to attract and observe potentially malicious activity.
It may resemble a real server, application, device, or service, but its primary purpose is monitoring and research.
Cybersecurity researchers can use honeypots to study questions such as:
- What services are attackers searching for?
- What usernames are being attempted?
- What passwords are being tested?
- Which vulnerabilities are attackers trying to exploit?
- Where is suspicious traffic originating?
- What commands are executed after access?
- What malware is being delivered?
- How quickly is an exposed system discovered?
Honeypots provide an important cybersecurity lesson:
A system does not necessarily need valuable information on it to attract malicious activity.
Sometimes being accessible is enough to attract attention.
What Is a Brute Force Attack?
A brute force attack involves repeatedly attempting credentials until access is obtained.
Attackers may try combinations involving:
- Common usernames
- Default administrative accounts
- Common passwords
- Previously compromised credentials
- Predictable password patterns
This is another activity that automation makes scalable.
A person manually entering passwords is slow.
Software can perform repetitive authentication attempts much more efficiently.
That is why businesses should not rely exclusively on a password to protect critical remote access systems.
What Is Password Spraying?
Password spraying is related to brute force activity but uses a somewhat different strategy.
Instead of trying thousands of passwords against one account, an attacker may try a small number of commonly used passwords against many accounts.
The objective can be to avoid triggering protections designed to detect repeated failures against one account.
Strong identity security therefore includes more than simply telling employees:
"Choose a complicated password."
Organizations should consider:
- Multifactor authentication
- Unique passwords
- Password managers
- Account lockout and detection controls
- Removal of unnecessary accounts
- Protection of administrative accounts
- Monitoring of authentication activity
The FTC recommends multifactor authentication and strong password practices as part of small business cybersecurity.
Can Hackers Find My Router?
Potentially, yes, if an interface or service associated with that router is reachable from the public internet.
The same applies to:
- Firewalls
- VPN appliances
- Wireless controllers
- Cameras
- Network storage
- Remote access gateways
- Voice systems
- Other network appliances
This is one reason internet facing network equipment deserves aggressive patching and configuration management.
A company's network security device is still a computer running software.
And software can contain vulnerabilities.
Can Hackers Find My Security Cameras?
Internet connected cameras can potentially be discoverable if services associated with them are publicly exposed.
Security cameras frequently fall into the broader category of Internet of Things devices.
The irony is important:
A device purchased to improve physical security can introduce cybersecurity risk if it is improperly configured.
Businesses should know:
- What cameras are installed
- Who manages them
- Whether default credentials were changed
- Whether firmware is current
- Whether they require direct internet exposure
- Who has administrative access
- Whether remote access is appropriately protected
- Whether the camera network is appropriately segmented
The same principle applies to many IoT devices.
Can a Firewall Prevent Internet Scanning?
A firewall can significantly control what outside systems are allowed to reach.
But a firewall cannot make your public presence disappear entirely.
Businesses intentionally expose certain services.
A public website needs to be reachable.
A VPN gateway needs to communicate with authorized remote users.
Cloud services must communicate.
Email systems communicate.
The objective is therefore not necessarily:
"Make everything invisible."
It is:
"Expose only what is necessary, restrict access appropriately, and protect what must remain exposed."
CISA's Internet Exposure Reduction Guidance follows this same general philosophy: identify exposed assets, determine whether the exposure is necessary, and mitigate risk for systems that must remain accessible.
Why Firewall Configuration Matters
Simply owning a firewall does not guarantee that the firewall is configured correctly.
Firewall environments change over time.
A rule may be created for:
- A temporary project
- A vendor
- A new application
- A remote employee
- A troubleshooting session
- A camera installation
- A phone system
- A software migration
Months later, nobody remembers why the rule exists.
This is how unnecessary exposure can accumulate.
Good firewall management should include periodic review.
Questions should include:
Is this rule still required?
Who requested it?
What system does it expose?
Who should be allowed to connect?
Can access be restricted further?
Is the underlying system still supported and patched?
What Is an Attack Surface?
Your organization's attack surface is broadly the collection of potential points through which an attacker could attempt to interact with your technology environment.
That can include more than the traditional office network.
Modern attack surfaces may include:
- Corporate offices
- Branch locations
- Remote workers
- Cloud infrastructure
- Websites
- SaaS applications
- VPNs
- Firewalls
- Routers
- Servers
- Employee devices
- Mobile devices
- IoT equipment
- Cameras
- Third party connections
- Vendor access
- APIs
- Remote support tools
This is one reason modern cybersecurity begins with visibility and inventory.
You cannot evaluate exposure if you do not know what exists.
What Is External Attack Surface Management?
External attack surface management is the process of identifying and evaluating technology associated with an organization that is visible or accessible from outside its internal environment.
It attempts to answer questions such as:
What can the internet see?
Which systems belong to us?
Which services are exposed?
Do we recognize all of them?
Are any unnecessary?
Are any vulnerable?
Did something new appear?
That last question is particularly important.
Cybersecurity is not simply about taking an inventory once.
Environments change.
The Forgotten Server Problem
Consider a business that launches a temporary server for a project.
The project ends.
Employees move on.
The application is forgotten.
But the server remains online.
It may stop receiving:
- Updates
- Security reviews
- Password changes
- Monitoring
- Ownership
- Maintenance
The business may have forgotten the server.
The internet has not.
If that system remains reachable, automated scanners can continue finding it.
This is sometimes referred to as an orphaned asset or part of shadow IT, depending upon the circumstances.
These forgotten systems are one reason asset discovery matters.
How Do I Know What My Business Is Exposing to the Internet?
This is a question every organization should be able to answer.
Start with an inventory.
Identify:
- Public IP addresses
- Domains
- Internet facing servers
- Firewalls
- VPN gateways
- Remote access systems
- Cloud infrastructure
- Websites
- Cameras and IoT devices
- Vendor managed equipment
- Public administrative interfaces
Then ask:
Does this need to be accessible from the internet?
If the answer is no, reduce or remove the exposure.
If the answer is yes, determine how it is protected.
CISA specifically recommends that organizations assess their current exposure and determine which assets genuinely need to remain internet accessible.
How Do I Know if Someone Is Scanning My Network?
Depending on the environment and available security tools, scanning activity may appear in:
- Firewall logs
- Intrusion detection systems
- Intrusion prevention systems
- Server logs
- Authentication logs
- Security information and event management platforms
- Cloud security systems
- Endpoint security tools
- Network monitoring platforms
However, seeing a connection attempt does not automatically mean a sophisticated hacker has specifically selected your business.
Context matters.
The activity could originate from:
- Legitimate security scanning
- Search engines
- Research organizations
- Monitoring platforms
- Vendors
- Misconfigured systems
- Bots
- Malware
- Criminal infrastructure
The goal is not to panic every time an unfamiliar address appears.
The goal is to have enough visibility to distinguish normal activity from activity requiring investigation.
Should I Block Every IP Address That Scans My Network?
Not necessarily.
Blocking clearly malicious sources can be useful, but individual IP blocking should not become the entire security strategy.
Attackers can operate through:
- Multiple addresses
- Compromised computers
- Cloud infrastructure
- Proxy services
- Botnets
- Changing infrastructure
Blocking one address does not fix an exposed service or unpatched vulnerability.
Think of it this way:
If someone keeps trying the lock on your front door, identifying that person is useful.
But if the lock itself is broken, fixing the lock is more important than maintaining an endless list of people who tried it.
What Should Businesses Do About Internet Scanning?
Businesses cannot realistically prevent every system on the internet from attempting to communicate with their public infrastructure.
The better strategy is to reduce what those systems can discover and exploit.
1. Inventory Your Assets
Know what technology your business operates.
2. Identify Internet Facing Systems
Determine what is externally accessible.
3. Remove Unnecessary Exposure
If a service does not need to be publicly accessible, restrict it.
4. Patch Internet Facing Systems
Prioritize vulnerabilities affecting exposed infrastructure.
5. Change Default Credentials
Never rely on manufacturer default usernames and passwords.
6. Implement Multifactor Authentication
Especially for administrative and remote access systems.
7. Review Firewall Rules
Remove outdated and unnecessary rules.
8. Protect Remote Access
VPN, SSH, Remote Desktop, and remote support tools deserve careful configuration.
9. Monitor Infrastructure
Watch for changes, outages, authentication anomalies, unexpected exposure, and other indicators requiring investigation.
10. Repeat the Process
Your network today will not be identical to your network six months from now.
Why Continuous Discovery Matters
This brings us to an important distinction.
An inventory tells you:
What did we know about?
Continuous discovery attempts to answer:
What exists now?
That distinction matters because environments constantly change.
Someone installs equipment.
Someone creates a firewall rule.
Someone launches a cloud server.
Someone enables remote access.
Someone forgets to disable a test environment.
Someone connects a camera.
Someone changes an application.
Someone leaves the company.
Someone replaces a firewall.
Security needs to account for that change.
NIST's Cybersecurity Framework 2.0 organizes cybersecurity risk management around six functions:
Govern
Identify
Protect
Detect
Respond
Recover
Discovery and visibility contribute directly to that lifecycle.
Attackers Automate Discovery. Businesses Should Automate Awareness.
Attackers have a significant advantage when defenders depend entirely upon manual processes.
Computers do not need:
- Sleep
- Weekends
- Vacations
- Lunch breaks
- Office hours
Automation can continuously search for opportunities.
Defenders therefore need technology that helps continuously identify changes and conditions that require attention.
That does not mean artificial intelligence or automation should independently make every cybersecurity decision.
It means automation should help people see what matters.
A useful operating philosophy is:
Discover.
Validate.
Alert.
Investigate.
Escalate.
Remediate.
Document.
And then continue monitoring.
Where USA Telecom and ADAM Fit
USA Telecom's approach to network and infrastructure monitoring is based on visibility.
The goal is not simply to generate more alerts.
Organizations already receive enormous amounts of technical information.
The objective is to help answer more useful operational questions:
Is the location reachable?
Is the network behaving normally?
Did something change?
Is a service unavailable?
Does this condition require investigation?
Who needs to know?
What should happen next?
ADAM products and services are designed to support that visibility and escalation philosophy.
Cybersecurity tools, firewalls, endpoint protection, identity systems, vulnerability management, and network monitoring each provide different pieces of the picture.
The strongest environments bring those pieces together with people and processes capable of interpreting what they mean.
Because detecting something unusual is only the beginning.
Someone still needs to care enough to investigate it.
The Most Important Question Is Not "Can They Find Us?"
Assume that anything intentionally connected to the public internet may eventually be discovered.
Then ask better questions.
What will someone discover?
What services are visible?
Should those services be visible?
Are they patched?
Are they properly configured?
Are administrative accounts protected?
Are default credentials gone?
Would we notice if something changed?
Would we know if someone successfully gained access?
Who would respond?
That is a much stronger cybersecurity posture than relying on obscurity.
Key Takeaway
Hackers do not necessarily search Google for your company, decide they dislike you, and begin attacking your network.
Increasingly, software does the searching.
Automated systems can discover internet connected infrastructure, identify exposed services, gather information about technologies, search for known weaknesses, and identify potential opportunities.
Your company may simply be one address among millions being examined.
That sounds intimidating.
But it also tells us what to do.
Know what you have.
Know what you expose.
Reduce unnecessary exposure.
Patch what remains.
Protect access.
Monitor continuously.
Investigate what matters.
The objective is not to make your company impossible to find.
The objective is to make sure that being found does not mean being vulnerable.
Frequently asked questions
How do hackers find vulnerable computers?
Attackers can use automated internet scanning and discovery tools to identify publicly reachable systems, open services, technologies, and potential vulnerabilities. They do not necessarily need to know the business operating the system beforehand.
How do hackers find my IP address?
Public internet infrastructure can be discovered through scanning and internet search technologies. Businesses should not rely on their public IP address remaining unknown as a security measure.
Do hackers scan every IP address?
Large scale automated scanning occurs continuously across the internet, although not every scanner is malicious and not every address is necessarily scanned by every system. Organizations should assume publicly exposed services may eventually be discovered.
What is port scanning?
Port scanning checks a computer or network device to determine which network services appear accessible. Administrators use scanning legitimately, while attackers may use it for reconnaissance.
Is port scanning a cyberattack?
Not necessarily. Port scanning is a technique with both legitimate and malicious uses. Context, intent, frequency, source, and subsequent activity help determine whether scanning represents a security concern.
Can hackers tell what software I use?
Sometimes. Network services can provide characteristics that allow software, devices, operating systems, or versions to be identified or estimated.
Can hackers find my firewall?
Potentially. If a firewall or associated service is internet accessible, aspects of that infrastructure may be discoverable.
Can hackers find my security cameras?
Internet connected cameras can potentially be discovered if services associated with them are exposed publicly. Cameras should therefore use secure credentials, current firmware, appropriate network segmentation, and controlled remote access.
Does a firewall stop port scanning?
A firewall can control which traffic and services are reachable, but organizations often intentionally expose certain services. The goal is to minimize unnecessary exposure and properly secure services that must remain available.
How do hackers know whether software is vulnerable?
Attackers can combine information about exposed services and software with publicly available vulnerability information. Automated tools can help identify systems that may be affected by known vulnerabilities.
What is an attack surface?
An attack surface is the collection of systems, services, applications, accounts, interfaces, devices, and other potential points through which an attacker could attempt to interact with an organization's environment.
How can I reduce my internet attack surface?
Start by identifying internet accessible assets, removing unnecessary exposure, patching vulnerabilities, securing remote access, changing default credentials, enabling MFA, reviewing firewall rules, and continuously monitoring for changes.
Sources
- CISA — Internet Exposure Reduction Guidance. Evaluating necessity of exposure, and removing or restricting access to assets that do not need to be internet accessible.
- CISA — Known Exploited Vulnerabilities (KEV) Catalog. Only vulnerabilities with reliable evidence of active exploitation in the wild; scanning activity and public proof-of-concept releases do not qualify.
- CISA — Cyber Hygiene Services. Free vulnerability and web application scanning for enrolled federal, SLTT and critical-infrastructure organizations.
- CISA — BOD 23-02: Mitigating the Risk from Internet-Exposed Management Interfaces. Binding on federal civilian agencies; a useful benchmark for everyone else.
- NIST — The NIST Cybersecurity Framework (CSF) 2.0 (NIST CSWP 29, February 26, 2024).
- NIST — NIST Cybersecurity Framework 2.0: Small Business Quick-Start Guide (NIST SP 1300, February 2024).
- FTC — Cybersecurity for Small Business, including the Understanding the NIST Cybersecurity Framework fact sheet.
Cybersecurity risk and the controls appropriate to it vary by organization. Evaluate these recommendations against your own technology environment, business requirements, regulatory obligations, threat profile and risk tolerance.
USA Telecom Consulting LLC is a Service-Disabled Veteran-Owned Small Business running a 24/7 NOC. We monitor networks, circuits and firewalls for regulated and defense-supply-chain organizations.
How do I know if someone is hacking my network? · Why would hackers target my small business? · Does a firewall stop hackers? · Microsoft is retiring SMS and voice MFA · Is Remote Desktop or SSH safe to expose to the internet? · Why do old vulnerabilities still matter? · Patch management vs vulnerability management