Vulnerability Scanner & Patch Management

Vulnerability scanner and compliance management for your servers, workstations, and virtual machines (VMs). Agent-based or agentless scanning, compliance assessment based on CIS Benchmarks, and integrated patch management. On-premise or SaaS deployment.

The challenge: managing heterogeneity

Infrastructure heterogeneity

Hundreds of technologies to inventory and secure: Windows and Linux servers, workstations, network equipment, hypervisors, databases, middleware...

Technological silos

Disparate tools (SIEM, EDR, configuration management) without cross-functional visibility. No correlation between vulnerabilities and actual configuration.

Wasted time

Manual data collection, reconciling fragmented information, and tedious audits. Risks are evolving faster than your ability to respond.

attack surface

Attack Surface Management

Automatically discover all your IT assets using over 50 specialized connectors.

Endpoint Platform Attack Surface Management

Agent mode

Deployment on every workstation for complete visibility and real-time data

  • Item 1
  • Item 2
  • Item 3

Agentless mode

Authenticated scanning via WinRM/SSH/SNMP for sensitive, network, or ephemeral devices

  • Item 1
  • Item 2
  • Item 3

Offline mode

Import via CSV/JSON files for isolated or air-gapped assets
Import via CycloneDX/SPDX SBOM files

  • Item 1
  • Item 2
  • Item 3

Comprehensive coverage

Servers, workstations, hypervisors, databases, middleware, network equipment

  • Item 1
  • Item 2
  • Item 3

A solid foundation for all your downstream security processes.

Vulnerabilities

Vulnerability Management

Continuous CVE detection, vulnerability prioritization based on risk level, and real-time alerts for critical flaws.

Endpoint Platform Vulnerability Management

CVE Updates

Hourly feed of new vulnerabilities, MTTD < 1 hour

  • Item 1
  • Item 2
  • Item 3

CVSS-BTE + EPSS Prioritization

Beyond CVSS scores: integrate operational context and exploit probabilities

  • Item 1
  • Item 2
  • Item 3

CERT Alerts

Immediate notifications for critical vulnerabilities (CISA KEV, CERT-FR)

  • Item 1
  • Item 2
  • Item 3

Contextual correlation

Link every CVE to your exposed assets and configurations

  • Item 1
  • Item 2
  • Item 3

Cut through the noise: patch only what matters.

Compliance

Configuration Management

Continuously assess your compliance with security and hardening benchmarks, internal policies, and industry-specific standards.

Endpoint Platform Configuration Management

CIS Benchmarks

CIS controls for Windows, Linux, and cloud services

  • Item 1
  • Item 2
  • Item 3

ANSSI/CERT-FR Guides

French applicability: sector-specific recommendations and geopolitical risks

  • Item 1
  • Item 2
  • Item 3

Custom rules

Integration of your internal standards and industry regulations (PCI-DSS, HIPAA, etc.)

  • Item 1
  • Item 2
  • Item 3

Continuous compliance scoring

Real-time dashboard with automatic detection of deviations from the validated baseline

  • Item 1
  • Item 2
  • Item 3

Configuration is your passive defense: keep it tight.

microsoft 365

Microsoft 365 / Entra ID

Audit identities, access, and data sharing at the heart of your Microsoft ecosystem.

Conditional access

Policy analysis and identity spoofing risk

MFA & guest management

MFA coverage, external access audit, and bypass risks

SharePoint/Teams/OneDrive sharing

Detect accidental public sharing and faulty access controls

Exchange anti-phishing

Anti-phishing policies, transport rules, and log compliance

Endpoint Platform Microsoft 365

Full visibility into risks associated with your Microsoft identities.

patch management

Patch Management

Orchestrate patches natively and integrate your existing tools: ServiceNow, Jira, GLPI, WAPT, Ivanti.

Native Windows + Linux patching

Direct deployment via Windows Update, YUM, and APT with granular scheduling

  • Item 1
  • Item 2
  • Item 3

Patch tool connectors

Bidirectional synchronization with WAPT, CoreUpdate, Ivanti, and more

  • Item 1
  • Item 2
  • Item 3
Endpoint Platform Patch Management

ITSM integration

ServiceNow, Jira, and GLPI connectors for change traceability and approvals

  • Item 1
  • Item 2
  • Item 3

Business context adaptation

Windows Patch Tuesday, business calendars, and freeze periods during sensitive times

  • Item 1
  • Item 2
  • Item 3

From detection to deployment, without switching tools.

Testimonials

The platform centralizes both our PCI compliance for online billing operations and our broader IT vulnerability management, which simplifies our security oversight.

CISO, energy

CISO

Quarterly ASV scans and the supplementary pentest provide us with a comprehensive view of our PCI DSS compliance, with reports that are directly actionable for our QSA auditors.

Payment Security Manager, Finance

Payment Security Manager

Hardening our configurations according to CIS Benchmarks allowed us to close entry points we hadn't even considered, all without interrupting our production.

Systems Administrator, industry

Systems and Network Administrator

Continuous auditing of our Active Directory revealed several poorly managed privileged accounts, which we were able to remediate quickly.

CISO, healthcare

CISO

Pouvoir déployer une console complète isolée d'Internet, avec mise à jour manuelle de la base de vulnérabilités, était un prérequis pour certains de nos environnements les plus critiques.

Exemple à remplacer — Responsable sécurité, secteur public

Responsable sécurité des systèmes d'information

Le mode air-gap totalement déconnecté correspond exactement à nos exigences de sécurité pour les systèmes les plus sensibles, sans compromis sur la qualité de la détection.

Exemple à remplacer — Responsable SSI, défense

Responsable de la sécurité des systèmes d'information

Le suivi de notre conformité NIS2 est désormais centralisé et actualisé en continu, ce qui simplifie considérablement nos rapports aux autorités compétentes.

Exemple à remplacer — RSSI, énergie

RSSI

La génération automatisée de preuves d'audit nous fait gagner un temps précieux lors de nos revues de conformité DORA et de nos échanges avec nos auditeurs.

Exemple à remplacer — Responsable conformité, finance

Responsable conformité

La formation Cyberwatch Certified Professional a permis à nos équipes de monter en compétence rapidement et d'exploiter pleinement les fonctionnalités de remédiation de la plateforme.

Exemple à remplacer — Responsable IT, industrie

Responsable infrastructure IT

Le patch management intégré et les tickets générés automatiquement dans notre outil ITSM ont nettement réduit nos délais de correction.

Exemple à remplacer — DSI, secteur public

DSI

Avec des centaines de dispositifs médicaux à surveiller, la priorisation par criticité métier nous permet de ne pas nous disperser tout en respectant la continuité des soins.

Exemple à remplacer — RSSI, santé

RSSI

Le scoring contextuel nous aide à concentrer nos équipes sur les vulnérabilités qui présentent un risque réel pour nos installations, plutôt que de traiter des milliers de CVE sans distinction.

Exemple à remplacer — Responsable cybersécurité, énergie

Responsable cybersécurité

Pouvoir cartographier nos environnements sensibles sans connexion réseau permanente était une exigence non négociable. Cyberwatch répond à cette contrainte tout en gardant un inventaire à jour.

Exemple à remplacer — Officier sécurité, défense

Officier de sécurité des systèmes d'information

La cartographie automatique de nos actifs nous a permis de découvrir des serveurs oubliés que nos audits précédents n'avaient jamais identifiés. C'est un vrai gain de visibilité sur notre Shadow IT.

Exemple à remplacer — Responsable sécurité, finance

Responsable sécurité IT

L'accompagnement de l'équipe Cyberwatch a été déterminant pour déployer la plateforme sur nos sites de production sans perturber nos lignes. Le support dédié répond vite et comprend nos contraintes industrielles.

Exemple à remplacer — DSI, industrie

DSI

Avec Cyberwatch, nous avons enfin une vue exhaustive de notre parc informatique et pouvons prioriser nos actions de remédiation selon un risque réel plutôt qu'une simple liste de CVE. La plateforme s'intègre bien à nos contraintes de souveraineté.

Exemple à remplacer — RSSI, secteur public

RSSI

FAQ

From asset mapping to automated remediation.

What is an agent-based or agentless vulnerability scanner?

An agent-based vulnerability scanner installs lightweight software on every server, application, or workstation to be scanned, even when offline. An agentless scanner queries machines remotely without requiring any installation. Cyberwatch Endpoint offers both modes to adapt to your heterogeneous environment and operational constraints.

hidden category

How does patch management work at Cyberwatch?

Patch management natively orchestrates the deployment of patches identified by the vulnerability scanner, without disrupting your processes. Cyberwatch also integrates with your existing tools (ServiceNow, Jira, GLPI, WAPT, Ivanti) to automate the entire cycle, from vulnerability detection to deployment validation, reducing exposure time.

hidden category

What are CIS Benchmarks and why should you check them?

CIS Benchmarks are recognized secure configuration standards covering operating systems, databases, and middleware. Cyberwatch continuously assesses your servers, workstations, and VMs for compliance with these hardening standards to detect misconfigurations, which are often just as critical an entry point as an unpatched software vulnerability.

hidden category

Can Cyberwatch Endpoint audit Microsoft 365 and Entra ID?

Yes, Cyberwatch audits identities, permissions, and data sharing within your Microsoft 365 and Entra ID ecosystem. This comprehensive visibility into identity-related risks complements the technical analysis of servers and workstations, covering both software vulnerabilities and cloud access or configuration weaknesses.

hidden category

Does Cyberwatch Endpoint also cover the cloud and the external surface?

Cyberwatch Endpoint focuses on servers, workstations, and VMs, but integrates natively with the other modules of the Cyberwatch platform: CSPM and container security for the cloud, EASM and DAST for the external surface, and SCA and SBOM for DevSecOps. A single platform thus centralizes your entire cyber exposure.

hidden category