Why 65535 portsbeats 1000

HostedScan wraps solid open-source tools at a fair price. But it scans ~1000 ports, has no AI verification, and no compliance evidence mapping. NoxScan fills every gap - starting at €10/mo.

More ports scanned65x
Verified findingsAI
Per-control mappingSOC 2
Starting price /mo€10
Full matrix

The short version above. The detail view below.

Use this matrix when you need the exact tradeoffs instead of the quick buying view.

Feature
NoxScanStarter · upgrades noted
HostedScanBasic · upgrades noted
Advantage
Scanning Engine
Port Range
All 65535 TCP ports
All 65535 TCP ports
Tie
Port Discovery Engine
masscan
Nmap
Depends
Service Fingerprinting
Nmap + ZGrab2 with custom plugins
Nmap
Depends
Custom Protocol Detection
Custom ZGrab2 plugins for non-standard protocols
Custom plugins not documented for Basic
Depends
Vulnerability Scanner
Nuclei (custom templates)
OpenVAS + Nuclei
Depends
SSL/TLS Analysis
Available
Available + SSLyze (dedicated engine)
Competitor Edge
Number of Scan Engines
4 (masscan, Nmap, ZGrab2, Nuclei)
5 (OpenVAS, Nmap, ZAP, Nuclei, SSLyze)
Depends
AI & Intelligence
AI False-Positive Filtering
Built-in, all plans
Automatic AI verification not documented for Basic
Depends
AI Severity Classification
Contextual analysis
AI classification not documented for Basic
Depends
Cyber Hygiene Score
Aggregate health metric
Target and account health scores
Tie
Asset Discovery
Auto-Discovery
Port scan -> creates domain assets within quota
Attack surface mapping included
Depends
HTTP Service Detection
On any port -> triggers web scanning
Automatic web-scan handoff not documented
Depends
Canonicalized Variants
www/non-www, HTTP/HTTPS
-
NoxScan Edge
Scanning Frequency
Scheduled Scans
Weekly; daily on Business+
Automated scheduling (paid plans)
Tie
Free Plan Scan Limits
30-day Starter trial; card required, then €10/month
3 targets, 100 ports
Depends
On-Demand Scans
2 credits/month on Starter; 1 per selected asset
Unlimited re-scans (paid plans)
Competitor Edge
Findings & Remediation
Finding Lifecycle
Auto-update + auto-close on rescan
Accept / remediate / track
NoxScan Edge
Detection Timeline
Visual history per finding
-
NoxScan Edge
Risk Scoring
AI-enhanced severity
CVSS-based
Depends
Compliance & Reporting
SOC 2 Evidence Mapping
Per-control: CC7.1, CC3.2, CC4.1, CC7.2
Basic compliance page, summary reports
NoxScan Edge
ISO 27001 Mapping
A.8.8
Mentioned, not per-control
NoxScan Edge
Compliance-Ready PDF Reports
Per-control evidence mapping
Summary reports only
NoxScan Edge
PDF Reports
Available
Custom reports; white-label on Professional
Depends
Advanced Scanning
Internal Network Scanning
Not available
Not on Basic; Premium+
Tie
Authenticated Web App Scans
-
Not on Basic; Premium+
Tie
Integrations
Slack
Available
Available
Depends
Telegram
Available
-
NoxScan Edge
Linear
Available
-
NoxScan Edge
CI/CD (GitHub Actions, CircleCI)
-
API automation requires Premium+
Tie
Webhooks
Not on Starter; Business+
Not on Basic; Premium+
Tie
API Access
Not on Starter; Business+
Not on Basic; Premium+
Tie
AWS / Azure / Vanta
-
Available
Competitor Edge
User Experience
Global Search (Cmd+K)
Available
-
NoxScan Edge
Dark Mode UI
Default
-
NoxScan Edge
MSP / White-Label
Not on Starter; Scale / Enterprise
Not on Basic; Professional
Tie
Scanner Depth Across Tiers
Same core scanner on every paid plan
Five core engines on Basic; Nessus on Professional
Depends

Where HostedScan Wins

We believe in honest comparisons. Here's where HostedScan has a genuine advantage.

01
Competitor Edge

Free Plan

HostedScan offers a forever-free plan, while NoxScan starts with a free trial. If you need a no-cost entry point, HostedScan has that option, but the free tier only scans 100 ports.

02
Competitor Edge

Internal Network Scanning

HostedScan supports internal scanning with SSH and SMB authenticated scans on Premium+. NoxScan focuses on external attack surface only. If you need to scan internal infrastructure, HostedScan covers this.

03
Competitor Edge

Authenticated Web App Scanning

HostedScan uses Selenium-based login replay for authenticated web app scans via OWASP ZAP. This means it can scan behind login pages - a capability NoxScan doesn't currently offer.

04
Competitor Edge

CI/CD Integrations

HostedScan integrates with GitHub Actions, CircleCI, Azure, and AWS for DevSecOps workflows. If you need scans triggered by deployments in your CI/CD pipeline, HostedScan has pre-built integrations.

05
Competitor Edge

MSP / White-Label

HostedScan's MSP plan includes white-label reports and multi-tenant workspaces - designed for managed service providers serving multiple clients. NoxScan offers white-label reports on higher plans, but not the same MSP-first workspace model.

06
Competitor Edge

More Scan Engines

HostedScan wraps 5 open-source engines (OpenVAS, Nmap, ZAP, Nuclei, SSLyze). Having dedicated ZAP and SSLyze engines means deeper web app and SSL analysis out of the box.

Where NoxScan Wins

The capabilities that make NoxScan a fundamentally different kind of scanner.

01
NoxScan Edge

65535 Ports vs ~1000 Ports

This is the single biggest difference. HostedScan uses Nmap to scan approximately 1000 common ports. NoxScan scans every single TCP port using masscan and XDP Scanner for rapid discovery, then Nmap and ZGrab2 for deep fingerprinting. That's 64,535 more ports per asset - catching services on non-standard ports (dev servers on 3000, admin panels on 8443, databases on 27017) that HostedScan's scans miss entirely. You can't fix vulnerabilities on ports you never scan.

02
NoxScan Edge

AI False-Positive Filtering

HostedScan presents raw output from OpenVAS, ZAP, and Nuclei without verification. That can mean false positives that waste your team's time. NoxScan uses AI to verify every finding - analyzing context, checking exploitability, and filtering noise automatically. Your team sees only verified, actionable findings.

03
NoxScan Edge

SOC 2 Evidence Database with Per-Control Mapping

HostedScan has a SOC 2 compliance page and generates summary reports, but doesn't map findings to specific controls. NoxScan maps every result to SOC 2 controls (CC7.1, CC3.2, CC4.1, CC7.2) and ISO 27001 control (A.8.8) - giving auditors exactly what they need without manual mapping work.

04
NoxScan Edge

PDF Reports Stay Tied to the Scan

NoxScan turns completed runs into PDF reports without creating a second reporting trail. The report stays connected to the scan and the finding that produced it, which makes handoff cleaner. HostedScan offers broader reporting, but not the same scan-first evidence path.

05
NoxScan Edge

Auto-Discovery

When an IP scan discovers HTTP services, NoxScan can create separate domain assets and queue web scanning if the asset quota has enough space. Those records count toward the plan allowance. Starter’s one IP can fill its quota, so adding discovered web targets may require an upgrade.

06
NoxScan Edge

Core Scanner Stays Intact

HostedScan gates API access, webhooks, and authenticated scans behind the Premium plan ($109/mo). NoxScan still unlocks workflow extras like API access, webhooks, and white-label reporting on higher plans, but the full 65535-port scanner stays available from the Starter tier upward.

07
NoxScan Edge

Modern UX

NoxScan was built in 2024 with a modern dark-mode interface, global Cmd+K search, detection timelines, and clean data visualization. HostedScan's interface is functional, but the overall workflow is less polished. If your team lives in the dashboard, the UX difference matters.

Switching from HostedScan?

Migrating is simple and takes minutes, not days.

01

Start a free NoxScan trial

Spin up the account you will use for the side-by-side check.

02

Import the same IPs and domains

Bring over the exact surface you already monitor in HostedScan.

03

Run one full baseline scan

NoxScan scans all 65535 TCP ports. Discovered web services can be added for scanning when your asset quota has room.

04

Review the gap and decide

See what you've been missing, then decide whether the extra depth is worth the switch.

Frequently Asked Questions

NoxScan scans all 65535 TCP ports on every asset using masscan and XDP Scanner for discovery, then Nmap and ZGrab2 for service fingerprinting. HostedScan uses Nmap to scan approximately 1000 common ports. That means NoxScan covers 64,535 more ports per scan - catching services on non-standard ports that HostedScan misses entirely.

NoxScan Starter is €10/month for one asset. Growth is €49/month for 10 assets. HostedScan Basic starts at US$39/month equivalent, billed US$468 annually, with five targets. Compare the same currency, asset count and billing term before estimating savings.

Eligible organizations receive 30 days on NoxScan Starter for one asset, with a payment method required; renewal is €10/month. The trial includes full TCP-port discovery, AI filtering, reports and two manual scan credits per calendar month. HostedScan also offers a free tier with its own limits.

No. HostedScan presents raw results from OpenVAS, Nmap, ZAP, Nuclei, and SSLyze without AI verification. NoxScan uses AI to verify every finding, filtering false positives and classifying severity with contextual analysis before results reach your dashboard.

HostedScan has a SOC 2 compliance page and generates summary reports, but does not offer per-control evidence mapping. NoxScan maps findings to specific SOC 2 controls (CC7.1, CC3.2, CC4.1, CC7.2) and ISO 27001 control (A.8.8) with detailed evidence for each finding - exactly what auditors need.

Yes. HostedScan offers a forever-free tier, internal network scanning with SSH/SMB authentication (Premium+), web app authenticated scanning via Selenium, CI/CD integrations (GitHub Actions, CircleCI, Azure, AWS), MSP white-label reporting, and 5 scanning engines vs NoxScan's 4. HostedScan also offers a 25% annual billing discount.

If internal scanning and CI/CD are hard requirements today, HostedScan has the edge there. However, many teams use NoxScan for external attack surface monitoring (with far more thorough coverage at lower cost) alongside other tools for internal scanning. NoxScan's CI/CD and internal scanning capabilities are on the roadmap.

See what 64,535 more ports looks like

Start a free trial and compare your results side-by-side with HostedScan.