Cap 1
Exploitability score, not CVSS
Every finding carries a live score built from what is running, what is reachable, what is being exploited and what a control already blocks.
Business initiative
RBVM is supposed to tell you which of the 130 new CVEs a day actually matter, and legacy tools answer by re-ranking CVSS with threat intel. Zafran answers with evidence from your environment: runtime presence, reachability, exploitation activity, asset criticality and the controls you already own.
Definition
Risk-Based Vulnerability Management (RBVM) is the practice of prioritizing vulnerabilities by the real risk they pose to the business rather than by CVSS score alone. A mature RBVM program combines threat intelligence, asset context and exploitability evidence so teams fix the small set of findings attackers can actually use, and can show why the rest can wait.
Mapping
Replacing Kenna or another legacy RBVM platform? This is the same mapping we use in those migrations: your requirements column, Zafran's capability, and where it sits in the lifecycle.
| Program requirement | Zafran capability | Lifecycle stage |
|---|---|---|
| Ingest findings from all existing scanners | Agentless connectors normalize and de-duplicate infrastructure, cloud, AppSec and container findings on one exposure graph | 01Continuous Discovery & Detection |
| Score risk beyond CVSS | Exploitability scoring built from runtime presence, reachability, exploitation intelligence, asset criticality and control coverage | 02Assess & Validate |
| Reduce the exploitable backlog fast | Mitigation through controls you already own (EDR, WAF, firewall, cloud policy) while patches are scheduled | 03Risk Mitigation |
| Route fixes to owners with SLAs | RemOps groups findings by root cause, assigns owners and tracks SLAs in ServiceNow or Jira | 04Remediation Workflows |
| Report risk reduction to leadership | Board-ready exposure reporting with validation evidence and trend analytics per business unit | 05Reporting & Analytics |
Capabilities
Stylized dashboard callouts; each tile becomes a short micro-animation in production.
Cap 1
Every finding carries a live score built from what is running, what is reachable, what is being exploited and what a control already blocks.
Cap 2
All findings, runtime-present, reachable, exploited in the wild, unmitigated. Watch the backlog collapse.
Cap 3
A single de-duplicated table across scanners with owner, SLA and mitigation status.
Cap 4
Exploitable exposure over time, sliced the way your board slices the business.
RFP checklist
Download
Requirement language, scoring criteria and proof-of-value tests you can paste into an RFP.
Outcomes
Illustrative figures for the wireframe; replace with validated customer outcomes.
“Zafran is tackling vulnerabilities from a hacker's perspective, adding a true layer of risk mitigation through compensating controls.”
“Zafran lets us evaluate the effectiveness and ROI of our security stack against what is actually exploitable.”
FAQ
Risk-Based Vulnerability Management prioritizes vulnerabilities by the real risk they pose, using threat intelligence, asset context and exploitability evidence instead of CVSS alone.
RBVM is the prioritization discipline inside vulnerability management. CTEM is the broader, continuous lifecycle of discovering, validating, mitigating, remediating and reporting on exposure. Zafran delivers RBVM as one stage of that full lifecycle.
No. Zafran ingests findings from the scanners you already run and adds the runtime, reachability, exploitation and control context they lack.
Yes. Customers migrate from legacy RBVM platforms to Zafran to get validated exploitability and mitigation through existing controls, rather than a re-ranked list of the same findings.
Each finding is scored on runtime presence, network reachability, active exploitation, asset criticality and whether an existing security control already blocks the attack path.
See how the platform maps to your requirements, on your data, in a 30-minute walkthrough.