Vulnerability Management

Detect, prioritize, and remediate known vulnerabilities continuously across your entire infrastructure to patch them before attackers exploit them.

Powered by HarfangLab’s single lightweight agent, the Vulnerability Management feature transforms each endpoint into a watchdog, providing continuous automatic detection without the hassle, overhead, or network impact of manual scanning.

Improve your IT hygiene with complete visibility over your OSes and applications, while linking your Vulnerability Operations Center (VOC) directly to your SOC to accelerate investigations and reduce Mean Time to Response (MTTR).

Cybersecurity scan
Anticipate potential entry points for attackers
Cybersecurity alert
Prioritize vulnerabilities effectively
Cybersecurity experts
Implement corrective actions
Cybersecurity - Protection Detection Capacities
Track the impact of your actions
Cybersecurity Certification
Patch CVEs

Vulnerability Management is available via both the Cloud and On-Prem versions of HarfangLab. This feature reports vulnerabilities identified on your IT infrastructure using a continuously updated list of public vulnerabilities (CVEs). 
Installation is simple and requires no specific configuration.

CVEs are continuously retrieved by the HarfangLab security platform and compared with the software, OSes and applications deployed on the protected IT environments to report vulnerabilities that need to be corrected. 

The solution enables security teams to stay one step ahead of threats. Immediately prioritize and remediate detected vulnerabilities from a single console, and correlate data with that of the deployed agents if needed.

  • Continuous automatic detection without scanning
  • CVE database constantly updated
  • Daily reporting

What is a CVE?

CVE stands for Common Vulnerabilities and Exposures. It is a public database that lists IT security vulnerabilities – Log4Shell and Spectre are among the most infamous examples. 

The cyber ecosystem relies on these databases to report vulnerabilities to security teams.  

These vulnerabilities are given a standardized score that assesses their criticality, called the Common Vulnerability Scoring System (CVSS). This score ranges from 0 for the least critical to 10 for the most critical.  

This score should be considered in the context of each unique organization. A vulnerability that is not inherently critical may still affect essential devices or solutions critical to the organization. In this case, it must be remediated as quickly as possible, even if the CVSS score is low! 

Vulnerability Assessment is accessible via the HarfangLab console. 

This feature is also available as a standalone feature with the Scout offering, without EDR or EPP. 

Unlike EDR detection rules, for example, the CVEs list comes from NIST and cannot be customized 

For the Cloud and On-Prem versions of HarfangLab, the CVEs list is updated constantly and deployed to the consoles of SaaS solution users.  

For On-Prem or Air-gapped environments, the updated file is stored in a dedicated secure space and can be loaded into the console manually. 

This update frequency allows for optimal responsiveness to correct vulnerabilities wherever and whenever they occur.