Cap 1
Compensating controls, ready to switch on
See which existing EDR, firewall, WAF, IPS and identity policies would neutralize a validated exposure, then enable them.
CTEM Lifecycle · 03
Zafran closes the exposure window before a patch exists or is scheduled by activating the compensating controls you already own: EDR, firewall, WAF, IPS and identity. Step-by-step guidance shows exactly which rule or policy to enable, on which tool, for which exposure.
Capabilities
Close the exposure window now with the security controls you already own, without waiting on patch cycles.
Cap 1
See which existing EDR, firewall, WAF, IPS and identity policies would neutralize a validated exposure, then enable them.
Cap 2
Each mitigation ships as ordered steps for the owning team with the exact configuration to apply.
Cap 3
Time-to-mitigate tracked against time-to-patch, plus the residual risk left once controls are applied.
Cap 4
A per-exposure view of which controls already cover it, which could, and which gaps remain.
Workflow
Zafran ingests policy state from your security stack and links each control to the exposures it can block.
For every validated exposure, Zafran proposes the specific rule, signature or policy change that closes it now.
Owners apply the change (or approve an agent to), Zafran verifies coverage, and patching proceeds on a normal cadence.
Compare
Zafran runs the whole lifecycle on one Exposure Graph; alternatives cover a slice of it.
| Capability | Zafran | Patch-only programs | Virtual patching (IPS/WAF alone) |
|---|---|---|---|
| Mitigation before a patch is available | |||
| Uses existing EDR, firewall, WAF, IPS and identity controls | |||
| Step-by-step guidance per tool and owner | |||
| Mitigation tied to validated exploitability | |||
| Residual-risk tracking after mitigation | |||
| Covers hybrid cloud, endpoints, servers and containers |
Proof
“Zafran is like bubble wrap around our vulnerabilities while we work through remediation.”
Case study · Healthcare
Read how the team ran this stage of the lifecycle with Zafran.
FAQ
Mitigation reduces the exploitability of a validated exposure without changing the vulnerable software, typically by activating a compensating control. In Zafran it sits between validation and remediation so the exposure window closes in minutes while the patch is scheduled.
A security control that blocks the attack path to a vulnerability rather than fixing the vulnerability itself: an EDR prevention rule, a firewall or WAF policy, an IPS signature, or an identity restriction. Zafran identifies which of your existing controls can act as a compensating control for each exposure.
Endpoint detection and response, network and cloud firewalls, web application firewalls, intrusion prevention systems and identity providers, connected through API. The exact integration list is maintained on the Platform page.
No. Mitigation buys time. Zafran tracks the residual risk after a control is applied and keeps the patch in the remediation queue at a lower urgency, so teams patch on a sustainable schedule instead of in emergency mode.
When a zero-day is disclosed, Zafran identifies affected assets that are loaded and reachable, then recommends the specific controls that block the known exploitation technique, giving teams protection before a vendor patch ships.
Mitigations can be applied by the owning team following the guided steps, or prepared by a Zafran agent and executed after a human approves the change. Fully unattended execution is a per-customer policy decision.
Prioritize and fix what is truly exploitable using risk context from your existing security tools.