VultSight Scope · Vulnerability assessment

Know what's exposed.
Fix what actually matters.

Continuous assessment across your network, web applications and external attack surface — multiple scanning engines, merged into one set of findings, ranked by what an attacker would really reach for.

  • Cut duplicate triage — one finding per flaw, not one per engine
  • Rank by real risk — exploit probability and active exploitation, not severity alone
  • Prove the fix landed — nothing closes without a passing retest
How it works

Scan → unify → prioritise → prove it's fixed

A closed assessment loop. Nothing is marked done until a rescan says so.

🎯

1 · Scope

Define what's in play — IP ranges, domains, applications and cloud assets. Add credentials where you want authenticated depth rather than a surface look.

🔍

2 · Scan

Multiple engines run in parallel across infrastructure, web applications and template-driven checks — on a schedule or on demand.

🧩

3 · Unify

Findings from every engine are correlated by CVE and asset fingerprint into a single record — merged, with each engine's evidence kept.

4 · Prioritise

Each finding is scored on severity, real-world exploit probability, known-exploited status and how much the asset matters to you.

🔧

5 · Remediate

Owner, due date and fix guidance per finding — tracked like any other ticket, not exported to a spreadsheet and forgotten.

6 · Verify

Retest closes the loop. A finding stays open until a rescan proves the fix actually landed in your environment.

Risk-based prioritisation

10,000 findings
is not a report

Severity on its own tells you how bad something would be — not whether anyone is actually exploiting it, or whether the affected box matters. Scope scores every finding on four signals, so the top of the list is genuinely the top of the list.

  • CVSS severity — how damaging it is if exploited
  • EPSS — the measured probability it will be exploited
  • CISA KEV — confirmed exploitation happening in the wild
  • Asset criticality — what the target is worth to your business
  • Exposure — internet-facing or reachable only from inside
SignalThe question it answers
CVSSHow severe is it?
EPSSHow likely is exploitation?
CISA KEVExploited in the wild today?
Asset criticalityDoes this asset matter?
ExposureCan it be reached externally?
Coverage

One platform across the whole estate

🌐

Network & infrastructure

Servers, endpoints, network devices and services — misconfigurations, missing patches, weak protocols and exposed services.

🕸

Web application testing

Dynamic testing against running applications and APIs — injection, broken access control, misconfiguration and exposed components.

🔭

External attack surface

See your estate the way an outsider does — internet-facing hosts, forgotten subdomains, stale services and shadow assets.

🔐

Authenticated scanning

Credentialed scans see installed packages and true patch state, cutting the false positives that unauthenticated scans invent.

🔄

Scheduled & continuous

Assessment as a routine, not an annual event. Recurring scans surface drift and newly disclosed CVEs against assets you already own.

📑

Evidence & audit trail

Every scan, finding, change and retest is recorded — the paper trail auditors and clients ask for, without reconstructing it later.

Unified findings

Many engines. One finding.

No single scanner sees everything, so Scope runs several. The problem that creates — the same vulnerability reported three times, in three formats, with three names — is the part Scope actually solves.

🔗

Correlated, not concatenated

Results are matched on CVE and asset fingerprint, so three engines reporting one flaw become one finding — not three tickets for one fix.

🗃

Union, never drop

Merging keeps every engine's evidence rather than picking a winner. You lose the duplicate, never the proof behind it.

🎫

One owner, one fix

A merged finding carries a single owner, due date and retest — so remediation effort matches the number of real problems.

Reporting

Reports people
actually read

An assessment is only worth what gets acted on. Scope produces the executive view and the technical detail from the same data — so the summary and the appendix never disagree.

  • Executive summary — posture, trend and the handful that matter
  • Technical detail — evidence, affected assets and fix guidance
  • White-label — your branding when you assess on behalf of clients
  • Trend over time — remediation velocity and ageing, not a single snapshot
AudienceWhat they get
Board / execPosture & trend
EngineeringFix guidance per asset
AuditorsEvidence & retest history
Your clientsWhite-label assessment
Better together

Exposure informs detection

Scope tells you what's weak. XDR watches what's happening. Together they answer the question that matters during an incident: was the thing being attacked actually vulnerable?

🛡

Prioritise exposed assets

Scan results feed asset risk, so detections on a known-vulnerable, internet-facing host are treated with the urgency they deserve.

🚨

Context during triage

An analyst sees the target's open vulnerabilities inside the investigation, instead of opening a second tool to find out.

🕵

Close the loop on zero-days

When a new CVE lands, find every affected asset immediately — see zero-day defence for how detection covers the gap until you patch.

Find it before they do

Run Scope yourself, or let our assessment team run it for you and hand you the remediation plan.