ReleaseMONITIC 2026.07 — Synapse Control Plane is live: topology, blast radius & AI-driven RCASee what's new
Platform · Vulnerability Management

Find, prioritize, and patch vulnerabilities

The expensive part of vulnerability management is not finding vulnerabilities — it is the handoff: exported from one tool, triaged in another, remediated in a third, verified never. Monitic closes the loop on one platform.

Real-machine mapping

Findings tied to real machines

Every CVE maps to the exact endpoints running the affected software — no guessing which assets a scanner report actually means.

No-export remediation

Detection to fix, zero exports

The remediation is a click away on the same platform, not a CSV emailed to another team.

Verified closure

Re-detection proves it

The inventory updates and the finding clears — detection verifying its own remediation, on the same console.

Workflow

Detect → Prioritize → Remediate → Verify

  1. 01 · DETECT

    Match against live inventory

    NVD CVE data syncs and matches against each endpoint’s live software inventory — packages and versions installed right now, maintained by the agent. No scan window.

  2. 02 · PRIORITIZE

    Context, not a flat list

    Exposure, known-exploited status, and threat context from the Wazuh integration rank what to fix first — a vulnerability list without context is a to-do list sorted wrong.

  3. 03 · REMEDIATE

    Fix on the same agent

    Patchable CVEs route into patch deployment; configuration findings route to a scripted fix — both executed by the same agent that found them.

  4. 04 · VERIFY

    Re-detection confirms closure

    Re-evaluation against the updated inventory confirms the finding cleared. Detect, prioritize, fix, confirm — one data model.

Endpoint CVEs

CVE detection matched to your live inventory

Monitic syncs CVE data from the NVD and matches it against each endpoint’s live software inventory. New CVE published, affected machines identified — that is the whole pipeline, with no scan appliance for endpoint CVEs.

  • NVD sync keeps CVE data current
  • Matching runs against the live inventory, not a stale asset export
  • Every finding names the endpoint, the software, and the version
CVE detection in depth
matched
  • CVE-2025-32463 → app-01, app-02
  • CVE-2025-2857 → build-07
  • CVE-2024-6387 → 0 affected · cleared
Agentless surface

Network vulnerability scanning with Greenbone

Endpoints are not the whole attack surface. Through the Greenbone integration, Monitic runs network vulnerability scans against the devices and services that carry no agent — and brings those findings into the same console as the endpoint CVEs.

Network scanning
greenbone scan
  • 192.168.10.1 · edge-fw · 2 findings
  • 192.168.10.24 · printer · 1 finding
  • 192.168.10.55 · nas · 0 findings
Threat context

Threat context from the Wazuh SIEM integration

The Wazuh integration adds SIEM capability — log collection, file integrity monitoring, security configuration assessment, MITRE ATT&CK mapping, and a SOC dashboard — so teams see what is being probed and exploited next to what is vulnerable.

SIEM & threat detection
wazuh context
  • app-01 · probing on :22 (24h)
  • ATT&CK T1190 · exploit public-facing
  • FIM · /etc/sudoers changed
Closed loop

From finding to fix on the same platform

A CVE with a vendor patch routes into patch management and deploys through the same agent that found it. A finding needing a configuration change routes to a scripted fix through automation. Then the inventory updates and the finding clears.

  • Patchable CVEs flow directly into patch deployment
  • Non-patch findings resolve via scripted remediation on the agent
  • Re-detection against the updated inventory confirms closure
Remediation workflows
remediation
  • patch → dispatched · app-01, app-02
  • script → sudoers hardened · build-07
  • re-detect → 0 open · closed ✓
Capabilities

What ships in vulnerability management

NVD CVE detection

Continuous matching of published CVEs against the agent-maintained live software inventory.

Network scanning (Greenbone)

Agentless network vulnerability scanning, findings unified with endpoint CVEs.

availability depends on plan and deployment

Threat context (Wazuh)

SIEM signals — FIM, SCA, MITRE ATT&CK mapping — attached to findings.

availability depends on plan and deployment

Patch remediation

Patchable CVEs route to OS and third-party patch deployment on the same agent.

Scripted remediation

Non-patch findings resolve through the automation engine and scripted fixes.

Verified closure

Re-detection against updated inventory confirms and records the finding cleared.

Integrations & trust

Open surface, accountable actions

Endpoint CVE detection uses NVD data; agentless coverage uses the Greenbone integration; threat context uses Wazuh. Every remediation runs inside the operator’s permissions and lands in an immutable audit log — see the Trust Center.

Consolidating scanner, SIEM, and remediation into one workflow? See Monitic for security operations.

FAQ

Vulnerability management FAQ

Do I need a separate scanner for endpoint CVEs?

No. Endpoint CVE detection matches NVD data against the live software inventory the agent already maintains — no scan appliance, no scan windows, no credentialed-scan configuration for endpoints.

How does Monitic scan devices without agents?

Through the Greenbone integration, which performs network vulnerability scanning and returns findings into the same console as endpoint CVEs.

Can Monitic actually fix what it finds?

Yes. Patchable CVEs route into patch deployment and other findings into scripted fixes, both executed by the same agent on the same platform, then verified by re-detection.

How does this relate to compliance checks?

Vulnerability management finds flawed software; security compliance finds flawed configuration. They are complementary controls, and Monitic runs both with shared remediation and audit logging.

Ready when you are

Close the loop on vulnerabilities

Every module, full-featured, for 14 days. Your fleet in the console on day one.