The exposure lifecycle as a working loop, not a slide.
Netgraph runs the full Gartner five-stage exposure lifecycle end to end — scope your crown jewels, discover what you actually have, rank exposures by real attack-path reachability on the knowledge graph, prove exploitability with breach & attack simulation, and mobilize fixes with deploy receipts that close the loop. Every stage reads and writes the same graph the rest of the platform lives on.
What is CTEM (Continuous Threat Exposure Management)?
CTEM is the discipline of continuously scoping, discovering, prioritizing, validating, and mobilizing against the exposures an attacker could actually use — rather than patching by CVSS score alone. Netgraph implements the full five-stage lifecycle on the security knowledge graph: exposures are ranked by real reachability and blast radius (can an attacker actually get from the internet to this asset, and what falls if they do), validated with BAS, and mobilized through the same case and playbook machinery the SOC already runs.
What ships in the module
Five stages, one graph, no gaps between them.
Prioritization, done honestly
Rank by paths to crown jewels — not by CVSS alone.
Most exposure tools re-sort a CVE list. Netgraph walks the knowledge graph: which exposures sit on real paths — through runtime, code, identity and data edges — to the assets you scoped as crown jewels? Those go to the top. Then BAS validation tells you whether the path is exploitable and whether your detections would fire along it.
- Reachability computed across runtime + code + identity + data edges — one graph, four dimensions.
- A medium-severity CVE with live paths to a crown jewel outranks a critical CVE on an isolated host.
- Validation runs prove exploitability and detectability with real telemetry read-back.
- Mobilized fixes come back as deploy receipts — the exposure closes when the evidence says so.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Scoping | Crown-jewel and business-context scoping per tenant | CTEM ▸ Scoping |
| Discovery | Assets, identities, vulns, misconfigs, data locations — from UEM, cloud posture, vuln DB, DSPM | CTEM ▸ Discovery |
| Prioritization | Exposure ranking by attack-path reachability to crown jewels on the graph | CTEM ▸ Prioritization |
| Validation | BAS runs prove exploitability and detectability with real telemetry read-back | CTEM ▸ Validation |
| Mobilization | Findings route to owners via cases, playbooks, ticketing — deploy receipts close the loop | CTEM ▸ Mobilization |
| Blast radius | K-hop traversal from any node scopes adversary reach | Analytics ▸ Blast Radius |
| Digital twin | Live kill-chain simulation over the AGE property graph projects attack paths | CTEM ▸ Digital Twin |
| Exposure trends | Posture over time for leadership and risk reporting | Dashboards ▸ Risk Metrics / CISO Dashboard |
Common questions
CTEM — asked and answered
How does CTEM differ from vulnerability management?+
Vulnerability management enumerates and patches CVEs. CTEM asks the attacker's question: which exposures are reachable, exploitable, and consequential in *this* environment — including misconfigurations, identity weaknesses, and exposed data, not just CVEs — and validates the answer with simulation before spending remediation effort.
Why does CTEM need a knowledge graph?+
Because exposure priority is a path question: internet → asset → identity → data. Ranking by attack paths requires runtime, code, identity, and data context in one queryable structure. On the Netgraph graph that traversal is native; with separate tools it's a spreadsheet exercise. Our research piece 'CTEM as an emerging discipline' covers how this ends the multi-vendor tool tax.
Does CTEM include dark web and external exposure?+
Yes — Dark Web Monitoring is a licensed CTEM add-on, and external attack-surface discovery feeds the same exposure lifecycle as internal findings.
See it live
Scope one crown jewel. Watch the loop find the paths to it.
Works with everything on the graph
Dark Web Monitoring
The licensed add-on under CTEM — external exposure from leaked credentials and brand mentions feeds the same lifecycle.
Explore→Vulnerability & Asset Management
The discovery substrate — UEM inventory, Asset Register and the risk-scored vulnerability DB CTEM ranks from.
Explore→Attack Simulation
The validation stage in depth — BAS scenarios against real endpoints with real telemetry read-back.
Explore→