How to set up Torva Core
Torva Core is a small agent that runs inside your network and scans only the devices you approve. This guide walks through installing it, choosing what it can see, and confirming it's connected. Core is rolling out now; steps may vary slightly as it launches.
Before you start
- An Edge + Core plan on your Torva account.
- A machine inside the network to host the agent: a small always-on Windows or Linux server, or a VM. It needs outbound internet access but no inbound ports.
- A list of the internal ranges you may want to scan, such as
10.0.1.0/24. You'll pick from these later.
Step 1: Install the agent
From your dashboard, open Core, then Add agent and download the installer for your operating system. Run it on the host machine. During setup it asks for the one-time enrollment code shown in your dashboard, which links the agent to your account.
Step 2: Confirm it connected
The agent makes an outbound connection to Torva, the same way a browser reaches a website, so you don't open any firewall ports. Within a minute the dashboard should show the agent as Connected. If it doesn't, confirm the host can reach the internet on HTTPS.
Step 3: Choose what it can scan
This is the important part, and it's entirely your call. In Core, then Scope, switch on only the devices and address ranges you want checked. Everything is off until you enable it. A typical setup:
Servers 10.0.1.0/28 ON
Staff workstations 10.0.2.0/24 ON
Printers 10.0.3.0/27 ON
Lab equipment 10.0.8.0/27 OFF (leave sensitive gear out)
Guest Wi-Fi 192.168.50.0/24 OFF
Step 4: Run your first internal scan
Click Scan now, or let the monthly schedule handle it. Core checks the approved devices for the weaknesses attackers look for once inside: unpatched software, weak internal services, default credentials, and risky configurations. Results appear alongside your Edge findings, with the same plain-English fixes.
Staying in control
- Pause any time: one switch in the dashboard stops all scanning without removing the agent.
- Change scope freely: add or remove ranges whenever your network changes.
- Remove completely: uninstall the agent and it disconnects immediately; nothing is left scanning.
Why outbound-only matters. Because the agent reaches out to us and never listens for inbound connections, installing Core doesn't add a new way into your network. It gives you visibility without widening your attack surface.
Want this checked for you automatically? Start a free Torva account and we'll scan for this and dozens of other issues every month, with the fixes spelled out.