Skip to content
IT asset management

Agentless discovery: inventory without a software rollout on endpoint devices.

LOGINventory discovers Windows, Linux, macOS, SNMP devices, and cloud resources over protocols that are already active in every corporate environment. No agent on the endpoint devices. Not for the first scan, and not afterward.

loginventory.local / Scanner / Live log cycle: 09:47:12
Asset Protocol Port Status
WS-PROD-042WMI135 / 445OK
SRV-LINUX-08SSH22OK
SW-CORE-ASNMP v3161OK
esxi-prod.localHTTPS443OK
MAC-DESIGN-04SSH22Auth retry
What this changes

Less effort to set up, less maintenance to run.

No rollout

Install the server, done.

No MSI on 600 devices, no staged pilot, no rollout waves. The Inventory Service runs as a Windows service on a standard Windows machine. Installation with no prerequisites on the endpoint devices.

No patch stress

What isn’t installed can’t fail.

No agent on the endpoint device means: no incompatible versions after an OS update, no helpdesk ticket because “the agent stopped working.” The protocols are standards, they’ve stayed stable for 20 years.

Up-to-date picture

Scan cycle: from every minute to daily, set by you.

For every asset, LOGINventory reads out hardware, installed software, configuration, local admin rights, and share permissions. The cadence is up to you; the server keeps the picture current automatically.

Established protocols, one architecture

The ports you already have open anyway.

The Inventory Service uses established standards. Which one applies depends on the device type. Configuration stays in one interface.

WMI · RPC

Windows world

Clients and servers. TCP 135, 445, plus dynamic ports 49152–65535. Local admin and LanmanServer are enough. Standard in domains.

SSH

Linux · Unix · macOS

TCP 22. Perl 5.8+ and an account with sudo. OpenSSH keys and PuTTY PPK are supported.

SNMP

Switches · routers · printers

UDP 161. v1, v2c, v3 with auth and privacy protocol (MD5, SHA, AES). A read-only community string is enough.

HTTPS · API

Virtualization · cloud

TCP 443. vSphere API for ESXi/vCenter, XenServer, Azure, and AWS with modern authentication or an access key.

Discovered platforms
Windows Vista – 11 · Server 2003 – 2025 Linux · Unix · macOS from 10.15 VMware ESXi · Hyper-V · XenServer Azure · AWS · M365 · Entra ID Exchange · SQL Server · Intune Switches · routers · printers
How the scan works technically

Remote query instead of endpoint software.

The server asks. The endpoint answers.

The Inventory Service runs as a Windows service on the inventory server and scans defined network ranges on a schedule. Which protocol applies depends on the device. Configuration runs in a single interface.

For Windows devices, LOGINventory copies a small helper file (LOGINfo.exe) via a remote call, runs it, reads the result, and removes the file again. If RPC isn’t available, the scan falls back to pure remote API discovery. For Linux, Unix, and macOS, the scan runs exclusively over SSH. No file is left behind.

The difference between a remote scan and a local scan is small: a local scan additionally discovers connected network drives and user profile packages.

The Windows Firewall opens the required ports automatically once WMI remoting is enabled via Group Policy. If you want to restrict that access, restrict it via GPO to the IP of the LOGINventory server. No global RPC opening required.

Devices outside the LAN: Offline Agent and logon script

Laptops in the field or in home offices aren’t reachable over the network. There are two ways to handle that.

The Offline Agent runs locally on the device, collects the inventory data, and saves it as an .inv file as soon as the device reconnects to the company network or over VPN. Alternatively, a logon script controls the inventory run at the next sign-in, with no permanently installed service.

Devices without a network interface can be entered manually.

Computer and user accounts, permissions

Besides hardware and software, LOGINventory also discovers accounts and access rights.

Active Directory computer accounts and user accounts are read in with recursive resolution of group membership. LOGINventory also evaluates who has admin rights on which devices and who has access to which shares, folders, or databases.

This data lives in the same interface as the hardware and software inventory. No separate tool required.

Multiple sites or segmented networks

Standalone Remote Scanner. Decentralized scan proxy.

If the central server can’t route into every network segment, or subsidiary sites run their own subnets: a lightweight scanner per site, with file sync to headquarters.

01

Scan locally

One Windows machine per site as a scan proxy. Discovers the segment completely with the same protocols as headquarters.

02

Generate .inv files

Results land locally as inventory files. No permanent contact with headquarters required.

03

Sync to headquarters

Transfer via Robocopy or a scheduled task into the central data directory. One interface, all sites.

Multi-site and MSP architecture in detail →