Skip to content
Explore platformDefensum
Defensum · Continuous Threat Exposure Management

Know what to fix.
And why it comes first.

Defensum brings assets, identities and exposures into one risk view. It combines the evidence from your connected tools with business importance and available SOC activity, so your team can focus remediation where it matters.

Asset & identity postureExplainable riskConnected casework
Defensum / Exposure workspaceIllustrative workflow
Evidence from your tools
Asset inventoryportal-web · public service
Vulnerability scannerKnown-exploited vulnerability
Control coverageEndpoint protection missing
Asset risk0–100
portal-web
85Critical · Act
Internet-facing + known-exploited vulnerability
A finding you can act on
Critical exposureRestore protection.
Address the vulnerability.

Keep the asset, risk drivers and evidence together.

Casebook follow-upFinding + evidence + priority
Remediation follows permissions and approval rules.

Turn the priority into casework. Threshold-crossing findings can create or update a Casebook case with their risk context.

Synthetic asset and score. This composite adapts Defensum’s dashboards and asset detail; it is not live customer data. The example shows a critical exposure, not a completed fix.
01 - Asset posture

See the gaps behind the score.

Bring inventory from supported endpoint, cloud, identity and security tools into a shared asset record. Defensum resolves matching identifiers, checks control health and exposes the evidence behind each risk score.

portal-web / Control coverageIllustrative asset detail
Endpoint protectionMissing
FirewallHealthy
SIEM loggingStale
BackupUnknown
Patch managementMisconfigured

Separate severity from priority

Combine vulnerability severity and exploit intelligence with exposure, control gaps, criticality and available attack-path and SOC context. Open the explanation to understand what drives the score.

Put business importance in context

Mark crown-jewel assets and group assets into business services. A service’s higher criticality can flow into its members’ scores, keeping remediation focused on what the business relies on.

02 - Identities

Find risky access, including the accounts without a person.

Identity posture connects authentication, privilege and exposure signals. Your team can review who has risky access and which machine identities lack an accountable owner.

User health

Review MFA strength, privilege, risky sign-ins and credential exposure alongside mailbox and OAuth risk.

Non-human identities

Inspect service accounts and other machine identities for excessive permissions, stale activity, credential hygiene and missing owners.

Shadow identities

Surface risky SaaS and OAuth grants from supported identity sources, with the user and application context needed to investigate.

Coverage follows your configured sources and the signals they provide. Unknown data remains distinct from a healthy control.

03 - Exposure

See how weaknesses connect.

The asset graph and attack paths connect exposed entry points to crown-jewel assets. Toxic combinations highlight dangerous conditions that occur together, giving your team a concrete reason to move a finding up the queue.

A toxic combinationSynthetic example
Internet-facing assetKnown-exploited vulnerabilityMissing endpoint protection
Critical exposure on portal-web. The combination keeps the vulnerability and control-gap evidence attached to the same asset.

Find paths to critical assets

Inspect reachable paths, intermediate assets and choke points. Focus on the relationships that could put a crown jewel within reach.

Keep the evidence honest

Graph-derived relationships are labelled as derived. A possible path describes exposure; it does not establish that an attacker traversed it.

04 - External surface

Bring your public footprint into view.

External Attack Surface Management adds domains, IP ranges, services and findings to the exposure picture. Start with declared scope and verified ownership, then use configured discovery and scanning to inspect what is reachable from outside.

  1. 1

    Define and verify the scope

    Accept the rules of engagement, declare the domain or IP range, then verify ownership.

  2. 2

    Discover and inspect

    Use configured passive sources and, for eligible scope, a registered scanning engine. Active scan depth follows the selected intensity and permissions.

  3. 3

    Review the findings

    Inspect exposed services and vulnerability findings alongside external risk and scan status. Carry relevant findings into casework.

05 - SOC context & action

Connect exposure to the work already in your SOC.

SOC Fusion joins asset posture with available alerts, cases and AI-agent activity. It helps your team distinguish a weakness in inventory from one connected to current security work.

Asset contextPosture + exposure
SOC contextAlerts + cases + agent activity

Confident identity matches determine what can be joined. Unmatched assets and unavailable data remain visible; an optional live-attack priority floor requires configuration.

Hand over the evidence

Threshold-crossing posture findings can create or update a Casebook case. Risk drivers and evidence travel with the finding, so the responder can start with context.

Make the work accountable

Group findings into campaigns with owners and SLA targets. Record accepted risk explicitly. Remediation actions follow permissions, connector availability and risk-based approval rules.

Start with a real asset group.

Enable Defensum in the SecOps Platform, configure supported connectors, review collected assets and set business criticality. Add external scanning and action policies as your workflow requires.

A few practical details.

1Do we need to replace our existing tools?

Defensum collects from supported, configured connectors. Inventory and posture collection use those existing sources. Active external scanning additionally needs a registered EASM engine and eligible, authorized scope.

2What does a high risk score mean?

It means the available evidence gives that asset or identity a higher remediation priority. Scores include explainable signals and decision tiers. A score is not a prediction that a breach will occur.

3Can Defensum take action automatically?

Actions depend on the configured workflow and permissions. High- and critical-risk remediation actions require approval; lower-risk actions may run directly. Remediation policies default to approval-required execution. Case creation is distinct from permission to remediate.

4How does Defensum relate to Virtus Sentinel?

Defensum covers asset, identity and exposure posture, including AI security posture findings. Virtus Sentinel provides the dedicated AI-asset discovery and protection experience. Availability follows each module’s entitlement and configuration.

Have a specific environment in mind? Talk to our team

Find the exposure.
Focus the response.

Bring an asset group or an exposure you need to understand. See how Defensum connects the evidence to the work your team needs to do.