TrustMeter
TrustMeter collects information from your network via active throttled scanning and pulls identity information from Active Directory, cloud computing services (AWS, Azure, GCP) and other identity providers. Using this information, TrustMeter discovers the managed and unmanaged assets in your network, classifying them as clients, servers or cloud hosts. A TrustMeter report gives details overall exposure level while providing detailed insights into network topology. Scan a network from the data center to identify problematic network paths. Scan the network from an internal host to give you complete visibility into assets accessible from a single machine inside the network.
Learn more
Wiz
Wiz is a new approach to cloud security that finds the most critical risks and infiltration vectors with complete coverage across the full stack of multi-cloud environments. Find all lateral movement risks such as private keys used to access both development and production environments. Scan for vulnerable and unpatched operating systems, installed software, and code libraries in your workloads prioritized by risk. Get a complete and up-to-date inventory of all services and software in your cloud environments including the version and package. Identify all keys located on your workloads cross referenced with the privileges they have in your cloud environment. See which resources are publicly exposed to the internet based on a full analysis of your cloud network, even those behind multiple hops. Assess the configuration of cloud infrastructure, Kubernetes, and VM operating systems against your baselines and industry best practices.
Learn more
Evidence Platform
Evidence Platform is an evidence-based vulnerability management platform that helps organizations discover their external attack surface, identify the vulnerabilities tied to real financial loss, prove the value of remediation, and back the results with financial protection. Evidence Platform uses the Evidence Graph, a live model of the internet, to map an organization’s public-facing assets before configuration, including infrastructure missed by seed-based discovery tools. It shows why each asset belongs to the organization, tracks new assets from certificate logs and passive DNS, and supports search by technology, ports, certificates, geography, and risk. Evidence Scan checks every asset every 24 hours against the FIRE list, KEVs, and custom CVE lists through external, non-intrusive scanning. FIREs are externally reachable CVEs connected to documented losses in insurance claims, forensic records, reinsurer data, or public disclosures.
Learn more
SecHard
SecHard is a multi-module software for implementing zero-trust architecture. SecHard provides automated security hardening auditing, scoring, and remediation for servers, clients, network devices, applications, databases, and more. A powerful identity and access management software to get compliant with zero trust and to prevent attacks like privilege abuse, ransomware, and more. SecHard solves the risk awareness problem in asset management. Automated discovery, access, identification, and remediation features provide ultra-wide visibility for all regulations. With the passive scanning method, SecHard operates the vulnerability detection and management processes for all IT assets without creating any risks. SecHard auto-discovers the certificates in the company’s environment report the expiration dates of these certificates, and it can automatically renew some of these certificates through well-known certificate authorities.
Learn more