Passive scanning is a method of vulnerability detection that relies on information gleaned from network data that is captured from a target computer without direct interaction.
What is passive vulnerability?
Passive vulnerability assessment takes a unique approach: In monitoring network traffic, it attempts to classify a node’s operating system, ports and services, and to discover vulnerabilities an active scanner like Nessus or Qualys might not find because ports are blocked or a new host has come online.
What is passive security testing?
Definition(s): Security testing that does not involve any direct interaction with the targets, such as sending packets to a target. Source(s): NIST SP 800-115.