All use cases
    Use case

    Vulnerability management

    Find, prioritise and fix CVEs across your estate.

    Why this fits, Vulnerability management and prioritisation platforms.

    97 vendors for this

    Binarly logo
    Binarly
    Supply Chain Security
    5 products

    Binarly is a software and firmware supply chain security vendor focused on binary-level analysis of compiled artifacts, including UEFI, BMC, embedded Linux, and other firmware components. In this category, it is used to generate and validate SBOMs and CBOMs, assess third-party software before deployment, and surface vulnerabilities, secrets, and crypto issues without source code. Its position is strongest for hardware vendors, OEMs, embedded product teams, and enterprise security groups that need defensible evidence about what is actually inside shipped binaries. The company also offers adjacent firmware security and risk intelligence capabilities, but its supply-chain value centers on binary transparency and post-build verification.

    Binary-level supply chain analysis+11
    Claroty logo
    Claroty
    OT & ICS Security
    9 products

    Claroty positions its platform for cyber-physical systems and IoT/IIoT security, with deployment options in the cloud as xDome or on-premises as Continuous Threat Detection (CTD). In the IoT Security scope, it focuses on discovering connected devices, profiling their communications and firmware, detecting anomalies, and supporting exposure analysis for industrial and other mission-critical environments. It is best suited for organizations that need passive visibility into unmanaged or fragile devices on operational networks, including manufacturing, utilities, healthcare, and other infrastructure operators. Adjacent modules such as secure remote access exist, but the core IoT Security value is asset discovery, monitoring, and threat detection.

    Discover and profile connected devicesCentralized asset inventory+10
    Cybereason logo
    Cybereason
    Endpoint Detection & Response (EDR)
    10 products

    Cybereason provides Endpoint Detection and Response (EDR) that correlates endpoint telemetry across machines into MalOp™ narratives, revealing full attack chains from initial compromise to lateral movement. It uses behavioral analysis, machine learning on threat feeds ranked by historical accuracy, and cross-machine correlation for real-time detection of sophisticated threats. The platform supports instant remediation like process termination, file quarantine, persistence removal, and machine isolation. Best for enterprises needing high analyst efficiency (1:200,000 endpoint ratio) and advanced threat hunting without alert fatigue, as validated by top Forrester Wave and MITRE ATT&CK scores.

    Behavioral detection of malicious activity+10
    Furl logo
    Furl
    Vulnerability Management
    1 product

    Furl is an autonomous remediation platform that closes security findings such as vulnerabilities, misconfigurations, and endpoint hardening gaps after they are identified by existing vulnerability scanners. It is built for security and IT operations teams responsible for reducing vulnerability backlogs across endpoints and servers. The platform integrates with tools such as Qualys, Tenable, and Rapid7 for findings, and with CrowdStrike, SentinelOne, AWS, Okta, and Google for execution, rather than replacing existing infrastructure. It investigates each issue, builds an environment specific fix, and validates closure within guardrails and approval thresholds the customer defines. Furl is deployed as a SaaS solution and was founded by veterans of Rapid7, Automox, and Censys.

    Autonomous vulnerability remediationContext-aware asset mapping+4
    Phoenix Security logo
    Phoenix Security
    Application Security Posture Management (ASPM)
    5 products

    Phoenix Security is an application security platform focused on finding and triaging code-level and runtime vulnerabilities across the software delivery lifecycle. In the DAST/SAST scope, it normalizes findings from source-code analysis, dynamic testing, and related appsec scanners into a single model, then uses runtime context to help prioritize remediation. Public materials also indicate support for air-gapped deployments and broader AppSec workflows, but the core value for buyers in this category is combining static and dynamic findings with remediation guidance. It is best suited for security teams and developers that need one place to correlate application vulnerability signals from multiple testing methods.

    Static application security testing for source code and compiled artifacts to identify issues such as injection flaws, unsafe input handling, and other OWASP Top 10-style defects before deployment.
    Plainsea logo
    Plainsea
    Vulnerability Management
    1 product

    Plainsea is a cybersecurity service-delivery platform whose vulnerability management scope centers on mapping assets, identifying weaknesses, and prioritizing remediation for pentest and security teams. It combines manual asset mapping with automated discovery, integrates vulnerability data sources for risk scoring, and produces structured reports and remediation guidance. The product appears aimed at MSSPs, internal security teams, and enterprises that run recurring vulnerability assessments and penetration testing workflows. Outside vulnerability management, Plainsea also mentions collaboration and reporting features, but its core buyer value in this category is coordinating discovery, scoring, and remediation planning around exposed systems and findings.

    Automated infrastructure mapping+4
    Qualys logo
    Qualys
    Vulnerability Management
    6 products

    Qualys provides Vulnerability Management, Detection and Response (VMDR), a cloud-based platform that automatically discovers assets across on-premises, cloud, and mobile environments, including unmanaged devices. It scans for vulnerabilities using over 20,000 checks from its Vulnerability KnowledgeBase, correlates findings with threat intelligence and machine learning to prioritize risks on critical assets, and detects indicators of compromise. VMDR supports hybrid IT scanning from a single console, generates role-based reports for compliance, and integrates with ticketing systems for automated remediation workflows. Best for enterprises needing continuous visibility and prioritization in complex, distributed networks.

    Continuous vulnerability scanning+10
    Raven logo
    Raven
    Application Security Posture Management (ASPM)
    6 products

    Raven.io provides a runtime application security platform that runs inside cloud-deployed applications to detect and block malicious code execution as it happens, independent of whether a CVE exists. The platform includes application detection and response for forensic visibility down to libraries, functions and call paths, a runtime software composition analysis capability that uses reachability data to de-prioritize vulnerabilities, and a module for discovering and controlling AI agents operating inside application environments. It is aimed at enterprises running internet-facing applications on Kubernetes, containers and compute instances across AWS, GCP and Azure, supporting languages including Java, Python, JavaScript, Go, Ruby, PHP, C++ and .NET. Customers include organizations in regulated industries such as insurance and financial services.

    Runtime exploit prevention+5
    Swimlane logo
    Swimlane
    SOAR
    6 products

    Swimlane provides Swimlane Turbine, an agentic AI automation platform for AI SOCs, integrating AI agents, low-code playbooks, case management, dashboards, and reporting with infinite integrations. It automates triage, investigation, and response through governed workflows, delivering 60,000 SOC analyst equivalents daily across customers. The Investigation Agent synthesizes threat intelligence, past investigations, and knowledge bases to generate NIST-aligned, four-phase response plans (containment, eradication, recovery, hardening) with actionable steps. Best for enterprise SOCs and MSSPs seeking transparent, auditable AI execution to reduce context switching and MTTR by up to 75%. Leader in GenAI SOC platforms, #1 on Gartner Peer Insights.

    Autonomous AI investigation agents+7