CTEM Lifecycle · 01

Continuous Discovery & Detection

Zafran builds a live, runtime-aware inventory of every asset, software component and finding across hybrid cloud, endpoints, servers and containers. The agentless Zafran Detector and your existing scanner and cloud integrations feed one Exposure Graph, so discovery never waits on a scan window.

Capabilities

How Zafran Enables Continuous Discovery & Detection

Agentless, runtime-aware inventory of every asset, component and finding across hybrid cloud.

Cap 1

Exposure Graph: assets to findings

Every asset links to its runtime components, findings and owners in one graph that updates as the environment changes.

Cap 2

Normalized, de-duplicated findings

Overlapping results from every scanner collapse into one record per real exposure.

Cap 3

Agentless Zafran Detector

Discover runtime software presence across cloud, servers, endpoints and containers without rolling out new agents.

Cap 4

Coverage and freshness

Inventory coverage, last-seen times and blind spots as live KPIs instead of a quarterly audit.

Workflow

How it works

  1. 01

    Connect what you already run

    Plug in cloud accounts, vulnerability scanners, EDR, CMDB and ticketing over API. Nothing new to deploy on hosts.

  2. 02

    Detect at runtime

    Zafran Detector adds runtime-aware SBOM data so you know which components are actually loaded, not just installed.

  3. 03

    Normalize into one graph

    Findings are de-duplicated, mapped to assets and owners, and kept current continuously.

Compare

Zafran vs. the alternatives

Zafran runs the whole lifecycle on one Exposure Graph; alternatives cover a slice of it.

CapabilityZafranAgent-based scannersCAASM point tools
Agentless deployment
Runtime-aware SBOM (loaded vs. installed)
De-duplication across scanners
Hybrid cloud, endpoint, server and container coverage
Continuous refresh, no scan windows
Feeds validation, mitigation and remediation downstream
Yes Partial NoIllustrative; final rows per stage TBD with PMM

Proof

What customers see

130
new CVEs published every day
1 graph
for assets, components, findings and owners
0
new agents to deploy

“Zafran is tackling vulnerabilities from a hacker's perspective, adding a true layer of risk mitigation through compensating controls.”

Ricardo Lafosse
CISO, Kraft Heinz

FAQ

Continuous Discovery & Detection: questions buyers ask

What is continuous discovery and detection in CTEM?

It is the first stage of continuous threat exposure management: maintaining an always-current inventory of assets, software components and security findings across the whole environment, instead of relying on periodic scans. Zafran does this by combining agentless runtime detection with data from the scanners and cloud platforms you already use.

Does Zafran require agents to discover assets?

No. The Zafran Detector is agentless. It gathers runtime presence data from hybrid cloud, endpoints, servers and containers through existing access paths and integrations, so there is nothing new to install or maintain on hosts.

What is a runtime-aware SBOM and why does it matter?

A runtime-aware software bill of materials records which libraries and packages are actually loaded and running, not just present on disk. That distinction is what lets Zafran rule out large numbers of vulnerabilities that can never be triggered.

How does Zafran de-duplicate findings from multiple vulnerability scanners?

Zafran normalizes results from every connected scanner into a common model, matches them to the same asset and component in the Exposure Graph, and merges overlapping records into one finding with a single owner.

Which environments does Zafran discover across?

Public and private cloud, on-premises servers, endpoints and containerized workloads, alongside findings from vulnerability scanners, EDR, cloud security and AppSec tools.

How is Zafran discovery different from a CAASM tool?

CAASM products stop at inventory. Zafran discovery feeds the same graph that assesses exploitability, activates compensating controls and routes remediation, so discovery is the start of a workflow rather than another dashboard.

See Zafran in Action

Prioritize and fix what is truly exploitable using risk context from your existing security tools.

WireframeSitemap