Checking behind the wall

Although it is good to have a properly setup firewall, I was wondering what else I could do to check that the machines behind it haven't been compromised (by an email trojan or the like)?

I was thinking of setting up a scanner (strobe/nmap/...?) to automatically do a scan from a cron and mail the results to me. However, is there any existing framework like this that I could leverage?


