Cap 1
Exposure Graph: assets to findings
Every asset links to its runtime components, findings and owners in one graph that updates as the environment changes.
CTEM Lifecycle · 01
Zafran builds a live, runtime-aware inventory of every asset, software component and finding across hybrid cloud, endpoints, servers and containers. The agentless Zafran Detector and your existing scanner and cloud integrations feed one Exposure Graph, so discovery never waits on a scan window.
Capabilities
Agentless, runtime-aware inventory of every asset, component and finding across hybrid cloud.
Cap 1
Every asset links to its runtime components, findings and owners in one graph that updates as the environment changes.
Cap 2
Overlapping results from every scanner collapse into one record per real exposure.
Cap 3
Discover runtime software presence across cloud, servers, endpoints and containers without rolling out new agents.
Cap 4
Inventory coverage, last-seen times and blind spots as live KPIs instead of a quarterly audit.
Workflow
Plug in cloud accounts, vulnerability scanners, EDR, CMDB and ticketing over API. Nothing new to deploy on hosts.
Zafran Detector adds runtime-aware SBOM data so you know which components are actually loaded, not just installed.
Findings are de-duplicated, mapped to assets and owners, and kept current continuously.
Compare
Zafran runs the whole lifecycle on one Exposure Graph; alternatives cover a slice of it.
| Capability | Zafran | Agent-based scanners | CAASM point tools |
|---|---|---|---|
| Agentless deployment | |||
| Runtime-aware SBOM (loaded vs. installed) | |||
| De-duplication across scanners | |||
| Hybrid cloud, endpoint, server and container coverage | |||
| Continuous refresh, no scan windows | |||
| Feeds validation, mitigation and remediation downstream |
Proof
“Zafran is tackling vulnerabilities from a hacker's perspective, adding a true layer of risk mitigation through compensating controls.”
FAQ
It is the first stage of continuous threat exposure management: maintaining an always-current inventory of assets, software components and security findings across the whole environment, instead of relying on periodic scans. Zafran does this by combining agentless runtime detection with data from the scanners and cloud platforms you already use.
No. The Zafran Detector is agentless. It gathers runtime presence data from hybrid cloud, endpoints, servers and containers through existing access paths and integrations, so there is nothing new to install or maintain on hosts.
A runtime-aware software bill of materials records which libraries and packages are actually loaded and running, not just present on disk. That distinction is what lets Zafran rule out large numbers of vulnerabilities that can never be triggered.
Zafran normalizes results from every connected scanner into a common model, matches them to the same asset and component in the Exposure Graph, and merges overlapping records into one finding with a single owner.
Public and private cloud, on-premises servers, endpoints and containerized workloads, alongside findings from vulnerability scanners, EDR, cloud security and AppSec tools.
CAASM products stop at inventory. Zafran discovery feeds the same graph that assesses exploitability, activates compensating controls and routes remediation, so discovery is the start of a workflow rather than another dashboard.
Prioritize and fix what is truly exploitable using risk context from your existing security tools.