Find, prioritize, and patch vulnerabilities
The expensive part of vulnerability management is not finding vulnerabilities — it is the handoff: exported from one tool, triaged in another, remediated in a third, verified never. Monitic closes the loop on one platform.
- app-01 sudo 1.9.14
- app-02 sudo 1.9.14
- build-07 sudo 1.9.15
Findings tied to real machines
Every CVE maps to the exact endpoints running the affected software — no guessing which assets a scanner report actually means.
Detection to fix, zero exports
The remediation is a click away on the same platform, not a CSV emailed to another team.
Re-detection proves it
The inventory updates and the finding clears — detection verifying its own remediation, on the same console.
Detect → Prioritize → Remediate → Verify
- 01 · DETECT
Match against live inventory
NVD CVE data syncs and matches against each endpoint’s live software inventory — packages and versions installed right now, maintained by the agent. No scan window.
- 02 · PRIORITIZE
Context, not a flat list
Exposure, known-exploited status, and threat context from the Wazuh integration rank what to fix first — a vulnerability list without context is a to-do list sorted wrong.
- 03 · REMEDIATE
Fix on the same agent
Patchable CVEs route into patch deployment; configuration findings route to a scripted fix — both executed by the same agent that found them.
- 04 · VERIFY
Re-detection confirms closure
Re-evaluation against the updated inventory confirms the finding cleared. Detect, prioritize, fix, confirm — one data model.
CVE detection matched to your live inventory
Monitic syncs CVE data from the NVD and matches it against each endpoint’s live software inventory. New CVE published, affected machines identified — that is the whole pipeline, with no scan appliance for endpoint CVEs.
- NVD sync keeps CVE data current
- Matching runs against the live inventory, not a stale asset export
- Every finding names the endpoint, the software, and the version
- CVE-2025-32463 → app-01, app-02
- CVE-2025-2857 → build-07
- CVE-2024-6387 → 0 affected · cleared
Network vulnerability scanning with Greenbone
Endpoints are not the whole attack surface. Through the Greenbone integration, Monitic runs network vulnerability scans against the devices and services that carry no agent — and brings those findings into the same console as the endpoint CVEs.
Network scanning →- 192.168.10.1 · edge-fw · 2 findings
- 192.168.10.24 · printer · 1 finding
- 192.168.10.55 · nas · 0 findings
Threat context from the Wazuh SIEM integration
The Wazuh integration adds SIEM capability — log collection, file integrity monitoring, security configuration assessment, MITRE ATT&CK mapping, and a SOC dashboard — so teams see what is being probed and exploited next to what is vulnerable.
SIEM & threat detection →- app-01 · probing on :22 (24h)
- ATT&CK T1190 · exploit public-facing
- FIM · /etc/sudoers changed
From finding to fix on the same platform
A CVE with a vendor patch routes into patch management and deploys through the same agent that found it. A finding needing a configuration change routes to a scripted fix through automation. Then the inventory updates and the finding clears.
- Patchable CVEs flow directly into patch deployment
- Non-patch findings resolve via scripted remediation on the agent
- Re-detection against the updated inventory confirms closure
- patch → dispatched · app-01, app-02
- script → sudoers hardened · build-07
- re-detect → 0 open · closed ✓
What ships in vulnerability management
NVD CVE detection
Continuous matching of published CVEs against the agent-maintained live software inventory.
Network scanning (Greenbone)
Agentless network vulnerability scanning, findings unified with endpoint CVEs.
Threat context (Wazuh)
SIEM signals — FIM, SCA, MITRE ATT&CK mapping — attached to findings.
Patch remediation
Patchable CVEs route to OS and third-party patch deployment on the same agent.
Scripted remediation
Non-patch findings resolve through the automation engine and scripted fixes.
Verified closure
Re-detection against updated inventory confirms and records the finding cleared.
Open surface, accountable actions
Endpoint CVE detection uses NVD data; agentless coverage uses the Greenbone integration; threat context uses Wazuh. Every remediation runs inside the operator’s permissions and lands in an immutable audit log — see the Trust Center.
Consolidating scanner, SIEM, and remediation into one workflow? See Monitic for security operations.
Vulnerability management FAQ
Do I need a separate scanner for endpoint CVEs?
No. Endpoint CVE detection matches NVD data against the live software inventory the agent already maintains — no scan appliance, no scan windows, no credentialed-scan configuration for endpoints.
How does Monitic scan devices without agents?
Through the Greenbone integration, which performs network vulnerability scanning and returns findings into the same console as endpoint CVEs.
Can Monitic actually fix what it finds?
Yes. Patchable CVEs route into patch deployment and other findings into scripted fixes, both executed by the same agent on the same platform, then verified by re-detection.
How does this relate to compliance checks?
Vulnerability management finds flawed software; security compliance finds flawed configuration. They are complementary controls, and Monitic runs both with shared remediation and audit logging.
Close the loop on vulnerabilities
Every module, full-featured, for 14 days. Your fleet in the console on day one.