Vulnerability Scanning
One platform- Vuln scanning, Risk and Simulation
- Vuln scanners from code to cloud- Replace your existing scanners
- Ingests 3rd party data from Tenable, Rapid7, CrowdStrike, SentinelOne ingestion
- Breach & Attack Simulation is included in Base license
Benefits
One single platform and unified view of exposure from code to cloud, Lower licensing cost Multiple Platforms
- Doesn’t have native scanning capabilities
- Only ingests 3rd Party data
Drawback
Additional cost, added complexity and learning curveRisk Score and Threat Exposure
Real Risk Score (1-100)
- Considers vulnerability severity, age, access, attack complexity, threat intel, asset criticality, business impact, security controls and attack feasibility
- Global, Industry and Regional Threat Intel
- Provide IOCs to detect Vulnerability Exploitation
Benefits
Practical Risk Score, Targetted exposure reduction and remediation, high ROI Inaccurate Risk Score (1-1000)
- Multiple scores (RF, Risk)- more confusion rather than clarity
- Scores Ignore security controls in place and doesn’t evaluate attack feasibility
- Generic Threat Intelligence
- No IOCs to detect vulnerability exploitation
Drawback
Misleading and inactionable risk score. High efforts and uncertain exposure reductionCyber Asset Attack Surface Management (CAASM)
Comprehensive and Easy
- Visibiity of Security Controls and their Effectiveness
- EDR, Network Security, etc
Benefits
Single view of Cyber Asset Inventory and Cybersecurity Incomplete and unuseful
- Raw application inventory- no security controls category
- No visibility into security controls effectiveness
Drawback
Incomplete view of assets