For CTEM teams
Review asset posture alongside user and non-human identity risk. Missing protection, excessive privilege and risky credentials become specific work to investigate, rather than disconnected lists.
Imperum helps exposure teams turn scattered findings into focused remediation work. Defensum connects assets, identities and vulnerabilities with business and SOC context; Casebook carries the evidence into follow-up.
Customer portal · production
Creating the case does not authorize the change.
An operator creates a case with the asset’s risk explanation and evidence. Remediation is a separate decision, with approval required for high-risk actions.
Your scanner, directory and cloud platform can describe the same machine differently. Defensum matches supported identifiers and keeps source observations with the asset, so the team can review the exposure in context.
Review asset posture alongside user and non-human identity risk. Missing protection, excessive privilege and risky credentials become specific work to investigate, rather than disconnected lists.
Use findings from configured scanners such as Tenable or Qualys. Imperum adds asset and control context to the scanner’s findings, helping you explain why a particular system needs attention.
Matching depends on the identifiers available. Unknown or stale control evidence needs follow-up; it is not proof that a control is working.
Explore asset and identity posture in DefensumExposure-prioritization teams need a defensible decision. Defensum combines vulnerability severity and known-exploited vulnerabilities with internet exposure, control gaps, business criticality and available SOC context in its asset-risk assessment.
Business-service criticality can feed the asset score. Derived attack paths and blast-radius views help your team examine how exposure could affect critical assets.
Available alerts and cases add investigation context when they can be matched to the asset. A potential attack path describes a relationship to investigate, not proof that an attacker followed it.
Asset, identity and exposure signals are reviewed across their relevant views. This is not a single universal queue that ranks every kind of exposure.
Attack-surface teams need to understand both public-facing systems and the AI tools used across the business. These require different sources and controls.
Defensum’s external attack-surface workflow assesses declared targets. Accept the rules of engagement, verify ownership and meet scan-eligibility requirements before scanning with a configured engine.
Keep external assessment within the scope your organization owns and authorizes.
See external-surface managementVirtus Sentinel brings AI-asset observations from deployed endpoint, browser, gateway and platform sources into its inventory, including MCP servers and AI agents.
Identify AI use that needs review. Coverage depends on deployed sources and the Sentinel entitlement.
Explore AI discovery in Virtus SentinelAn exposure decision becomes useful when someone can act on it. Create or open a Casebook case from a finding, with its risk explanation, recommended actions and evidence references. Use remediation assignments and campaigns to give the follow-up an owner and a deadline.
The case links back to the exposure. An existing matching open case can be updated instead of creating another record for the same work.
High-risk and critical remediation actions require approval. Lower-risk actions may execute with the required permissions and configured tools; opening a case alone does not authorize remediation.
Return to the asset’s reported control health as new observations arrive. A closed ticket alone does not establish that a control is healthy or that a vulnerability is gone.
The affected asset, why it matters and what needs review stay with the work. Your team spends less effort rebuilding the context for each handoff.
Yes. This workflow consumes findings from supported, configured scanners such as Tenable or Qualys. Defensum adds asset, control and risk context. Its separately configured external attack-surface scanning workflow has its own scope, ownership and authorization requirements.
Yes. Asset posture, scanner findings and identity risk can support exposure work without a matched alert. Available SOC evidence adds context; missing or unmatched evidence should not be read as proof that the asset is safe.
No. The asset’s risk score and a proposed action’s risk classification are separate. High-risk or critical remediation actions require approval. Lower-risk actions can execute when the necessary permissions and tools are in place.
Choose one asset group and the tools that already report on it. Check source coverage and identity matches, review the risk explanation, then take one finding into a case. Add external-surface or AI discovery where it fits your scope and enabled capabilities.
Have another question? Talk to our team
See how asset context, exposure evidence and an accountable handoff could change the next decision your team makes.