Category
What the internet already sees, and the ticket you already have. Inventory and queue. Detection lives under Security Operations. SAST lives under Application Security. Open a shortlist for the buy you are making.
We split ASM by listing what the internet already sees. A pentest is a scoped test, not this list.
ShortlistsWe split vuln platforms by queueing the finding you already have. Account misconfig is Cloud.
BAS toolsBreach and attack simulation to prove controls actually fire. UVM toolsRemediation ownership queues that unify findings and name a fixer. CTEM toolsAttack-path prioritization and validation beyond scanner green.More categories
Questions about Vulnerability and exposure
No. A pentest is a scoped test. These lists are what is already visible and how you queue it.
No. A finding is not a detection you hunt.
Account misconfig is Cloud. This pillar is the public name and the ticket.