Subscribe

Pillar

Vulnerability and exposure

The backlog is names and ports you already exposed, plus the ticket a scanner opened. This pillar is inventory and queue. Detection lives under Security Operations.

Questions about Vulnerability and exposure

Is this a pentest pillar?

No. A pentest is a scoped test. This pillar lists what is already visible and how you queue it. Different door.

Does a scanner replace the SIEM?

No. A finding is not a detection you hunt. Link Security Operations for the console job.

Can I scan a vendor from these pages?

No. Only assets you own or have written permission to test.

Where does CSPM sit?

Account misconfig is Cloud. This pillar is the public name and the ticket queue.