← All Netgraph solutions
Vulnerability & Asset ManagementExposure & Validation

Know every asset. Rank every CVE by what it can reach.

The unified endpoint agent's UEM module inventories everything — hardware, software, patches, kernel, applications, plug-ins, dependencies and licenses — into a rich per-asset profile that syncs into the Asset Register. Vulnerabilities land on the knowledge graph next to runtime, code, identity and data, so prioritization answers the question that matters: from this vulnerable box, what could an attacker actually reach?

UEM full-stack inventory30-min incremental syncBlast-radius prioritizationCVE → technique edgesData-source value insight

What ships in the module

Inventory, register, risk — all on one graph.

01

UEM inventory

The endpoint agent's UEM module captures hardware, software, patch state, kernel, applications, plug-ins, dependencies and licenses — one agent, a full per-asset profile.

02

Asset Register

Incrementally synced from UEM inventory — a 30-minute background loop plus on-demand sync — and enriched from identity sources. Assets carry business owner, environment and criticality.

03

Vulnerability DB

A dedicated console of risk-scored findings, each tied into the knowledge graph — not a flat scanner export you triage by hand.

04

Blast-radius prioritization

Ranked by actual reach across runtime + code + identity + data. A CVE on a box that can reach crown jewels outranks a higher-CVSS CVE on an isolated host.

05

Feeds CTEM

Reachability-aware ranking flows straight into CTEM prioritization — vulnerability management is the discovery-and-ranking substrate of the exposure lifecycle.

06

Linked to detections

CVE → technique edges connect findings to detections — from any alert, it's one hop to “is this host vulnerable to the technique being attempted?”

07

Data-source value

A dashboard that shows which telemetry earns its ingest cost — so inventory and visibility decisions are grounded in what each source actually contributes.

The per-asset profile

One asset, everything known about it — and everything it touches.

Because inventory, vulnerabilities, identities and detections share one graph, an asset profile isn't a spec sheet — it's a risk story. What's installed, what's unpatched, who logs in, what data it holds, what it can reach, and which techniques it's exposed to. That's the context a prioritization decision actually needs.

  • Full UEM inventory — hardware to dependencies to licenses — refreshed incrementally.
  • Business owner, environment and criticality from the Asset Register.
  • Graph edges to identities, data classifications and reachable assets.
  • CVE → technique edges tie the profile to live detections and alerts.

Functionality map

Module functions at a glance

FunctionWhat it doesWhere it lives
Asset RegisterIncremental UEM sync (30-min loop + on-demand) plus identity sources; owner, environment, criticality per assetSOC ▸ Enrich ▸ Asset Register
Vulnerability DBRisk-scored findings tied into the knowledge graphSOC ▸ Enrich ▸ Vulnerability DB
Endpoint inventoryUEM full-stack inventory — hardware, software, patch, kernel, apps, plug-ins, dependencies, licensesEDR ▸ Visibility
PrioritizationReachability-aware ranking across runtime + code + identity + data; feeds CTEMGraph-ranked in Vulnerability DB / CTEM
Detection linkageCVE → technique edges — one hop from an alert to the host's exposure to that techniqueKnowledge graph — surfaced in alerts
Data-source valueShows which telemetry earns its ingest costVisibility ▸ Data Source Value

See it live

Pick your scariest CVE. See what it can actually reach.