Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The two free tools reported in November 2016 checked different warning signs, not malware infection itself. Imperva’s Mirai scanner tested the public-facing gateway of the network you were using for remote-access ports that Mirai could exploit. Rapid7’s IoTSeeker searched the local network for common IoT devices still using factory-set credentials. A finding meant “investigate this exposure or weakness,” not “this device is infected.”
What the 2016 scanners actually checked
The tools were described in Dark Reading’s November 8, 2016 report, during the period when Mirai was targeting internet-accessible routers, cameras and DVRs protected by common default credentials. Their checks operated at different points in a network.
| Tool | Where it looked | Reported check | What a result meant |
|---|---|---|---|
| Imperva Mirai scanner | From outside, against the public IP and gateway of the connected network | Remote-access ports described as vulnerable to Mirai | An internet-exposed path to investigate; not proof of malware |
| Rapid7 IoTSeeker | On the local network where the Linux or macOS host was connected | Common IoT devices still using factory-set credentials | A device or credential weakness to investigate; not proof of malware |
Imperva’s external gateway check
According to the report, the Imperva scanner discovered the network’s public IP address and checked its gateway from outside for remote-access ports vulnerable to Mirai. It was described as restricted to the network to which the user was connected. A result could identify an IP address hosting an IoT device vulnerable to Mirai injection attacks.
Imperva also cautioned that changing a device password might not necessarily prevent attacks. Closing unnecessary exposure, patching, replacing unsupported equipment and checking for compromise can still be necessary.
#1 Best Overall
- Large format scanner - Helps improve access to and management of all your large files
- Has a color depth of 32-bit
Rapid7’s local credential check
IoTSeeker was described as searching for common IoT devices that retained factory-set credentials, with the aim of helping users identify whether those credentials had been changed. The report said it could scan thousands of IoT devices at once and ran on Linux or macOS at that time. Those are historical descriptions; present-day compatibility, downloads and maintenance were not established.
Vulnerable, exposed and infected are different conditions
A scanner can reveal an attack opportunity without establishing that malware is present. For example, an open remote-access port may expose a camera or DVR, while a factory password may allow an attacker to try logging in. Neither fact alone demonstrates that Mirai—or any other malware—has already executed.
Rank #2
- Exposed: An internet-reachable service or device can be contacted from outside the network.
- Vulnerable: The service, software or credentials create a known or plausible path to unauthorized access.
- Infected: Malicious code has actually compromised the device and is operating on it.
A negative result is not a guarantee either. The described tools focused on particular ports, device patterns and credentials; they did not constitute a complete forensic examination or a universal test for every Mirai variant.
What to do if a scan finds a problem
1. Identify the device and decide whether it needs internet access
Map the result to a specific router, camera, DVR or other IoT device. Ask whether remote access is required. If it is not, disable internet-facing administration and remove port forwards or other unnecessary exposure.
Rank #3
- Standalone network scanner with scanning speeds of 25 ppm/50 ipm (A4 portrait, 200/300 dpi), ADF capacity of 50 sheets
- PC-less scanning with large touch screen and on-screen keyboard
- Supports scanning from thin paper to thick paper, and plastic cards
- Security measures include Login Authentication with custom job menus, Encryption, Data Transmission Security, and more
- USB port to connect devices like a mouse or contactless IC card reader
2. Change every default credential
Set a unique, strong administrator password on the device and on the router that controls it. Change credentials anywhere the same password was reused. Treat this as one mitigation, not proof that existing malware has been removed.
3. Patch—or replace—unsupported equipment
Install firmware and software updates from the manufacturer. If security updates are no longer provided, replace the device rather than leaving a permanently exposed system in service. CISA’s Internet Exposure Reduction Guidance, published June 4, 2025, specifically recommends replacing software and devices that no longer receive security support.
Rank #4
4. Use safer administrative access
For systems that must remain reachable, CISA recommends controls such as a jump host for secure, monitored access, multifactor authentication where possible, and traffic monitoring. Restrict management interfaces instead of publishing them broadly to the internet.
Free tools Windows power users keep installed
One-click scans. No signup required.
5. Look for signs of compromise
Review router and device logs, unexpected configuration changes, unexplained outbound traffic and unusual reboots. Disconnect a suspected device from the network while investigating. If you cannot restore trustworthy firmware or otherwise verify the device, replacement is the safer recovery path.
Best Value
- FAST BUSINESS PRINTING AND COPYING: The Brother MFC-L5915DW business monochrome laser all-in-one printer delivers high-quality output and print and copy speeds of up to 50ppm(1) to help boost productivity and ensure fast, professional quality documents for busy offices.
- LOW-COST OUTPUT: Help reduce operating costs by using the Brother Genuine TN920UXXL ultra high-yield 18,000-page replacement toner cartridge. Includes a Brother Genuine 3,000-page toner cartridge(2).
- FAST, HIGH-VOLUME SCANNING: The 70-page capacity(3) auto document feeder offers single-pass, two-sided scanning up to 56ipm(4). Features a large document glass for up to legal-sized documents.
- FLEXIBLE CONNECTIVITY OPTIONS: Features built‐in Gigabit Ethernet and dual band wireless networking to seamlessly set up and share on your wired.
6. Reassess regularly
Keep an inventory of internet-accessible assets and repeat exposure checks after router, firmware or network changes. CISA’s guidance treats discovery and recurring assessment as ongoing processes rather than a one-time scan.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How current CISA services fit in
CISA’s Internet Exposure Reduction Guidance lists discovery platforms including Shodan, Censys, Thingful and Shadowserver. CISA explicitly says that listing them does not constitute U.S. government or CISA endorsement.
CISA Cyber Hygiene Services is a separate organizational service. Its vulnerability scanning monitors internet-accessible network assets with public static IPv4 addresses and is offered to eligible U.S.-based federal, state, local, tribal and territorial governments and public or private critical-infrastructure organizations. It is not described as a Mirai-specific household scanner, nor as a service for scanning every private home network.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minuteAre the 2016 tools still available?
The report documented the tools as free in 2016, but their current availability, safety, compatibility and maintenance were not verified. Do not download an old copy from an unknown mirror simply because it carries the Imperva or Rapid7 name. Prefer current vendor documentation and reputable security controls, and avoid exposing a device while experimenting with an untrusted scanner.
Bottom line for a Mirai concern
The Imperva tool’s signal was external gateway exposure; IoTSeeker’s signal was local discovery of devices using factory credentials. Either result justified immediate hardening, but neither scanner result proved infection or ruled it out. Today, the durable response is to inventory exposed assets, remove unnecessary internet access, change defaults, patch or replace unsupported devices, monitor for compromise and repeat the assessment.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

