Know every asset. Rank every CVE by what it can reach.
The unified endpoint agent's UEM module inventories everything — hardware, software, patches, kernel, applications, plug-ins, dependencies and licenses — into a rich per-asset profile that syncs into the Asset Register. Vulnerabilities land on the knowledge graph next to runtime, code, identity and data, so prioritization answers the question that matters: from this vulnerable box, what could an attacker actually reach?
What ships in the module
Inventory, register, risk — all on one graph.
The per-asset profile
One asset, everything known about it — and everything it touches.
Because inventory, vulnerabilities, identities and detections share one graph, an asset profile isn't a spec sheet — it's a risk story. What's installed, what's unpatched, who logs in, what data it holds, what it can reach, and which techniques it's exposed to. That's the context a prioritization decision actually needs.
- Full UEM inventory — hardware to dependencies to licenses — refreshed incrementally.
- Business owner, environment and criticality from the Asset Register.
- Graph edges to identities, data classifications and reachable assets.
- CVE → technique edges tie the profile to live detections and alerts.
Functionality map
Module functions at a glance
| Function | What it does | Where it lives |
|---|---|---|
| Asset Register | Incremental UEM sync (30-min loop + on-demand) plus identity sources; owner, environment, criticality per asset | SOC ▸ Enrich ▸ Asset Register |
| Vulnerability DB | Risk-scored findings tied into the knowledge graph | SOC ▸ Enrich ▸ Vulnerability DB |
| Endpoint inventory | UEM full-stack inventory — hardware, software, patch, kernel, apps, plug-ins, dependencies, licenses | EDR ▸ Visibility |
| Prioritization | Reachability-aware ranking across runtime + code + identity + data; feeds CTEM | Graph-ranked in Vulnerability DB / CTEM |
| Detection linkage | CVE → technique edges — one hop from an alert to the host's exposure to that technique | Knowledge graph — surfaced in alerts |
| Data-source value | Shows which telemetry earns its ingest cost | Visibility ▸ Data Source Value |
Works with everything on the graph
EDR / EPP
The unified endpoint agent whose UEM module supplies the inventory — one deployment, detection and asset management both.
Explore→CTEM
Reachability-aware vulnerability ranking is the prioritization stage of the continuous exposure lifecycle.
Explore→NextGen SIEM
Alerts enrich from the same asset and vulnerability context — CVE → technique edges put exposure one hop from every detection.
Explore→