Security
Threat intelligence and software risk
Turn package inventory into prioritized risk: know which installed software is vulnerable, which is known-exploited, and where to remediate first.
Match live endpoint software inventory against open and commercial vulnerability feeds—including NVD , CISA KEV , and VulnCheck —to surface high-risk packages with exploit and KEV context next to the devices that run them.
Inventory first, then intelligence
Threat intelligence is only as good as the software truth underneath it. ServiceRadar matches current endpoint package and SBOM coordinates in the control plane after collection—agents do not pull CVE feeds or run matching jobs on every host.
- Uses the endpoint software inventory as the source of installed packages
- Central matching writes device-scoped vulnerability findings
- Shows installed version, fixed version, confidence, and feed provenance
- KEV and exploit flags travel with the advisory when the feed provides them
Open and commercial feeds, one matching surface
Feed producers download, validate, and normalize provider data, then submit a common advisory contract. Operators can enable or disable sources without rewriting core. First-party paths include open sources such as CISA KEV and NVD/NIST, plus commercial VulnCheck KEV and NVD-class mirrors when licensed.
- CISA Known Exploited Vulnerabilities (KEV) for actively abused issues
- NVD and related NIST-style advisory data for broad CVE coverage
- VulnCheck feeds for commercial KEV and NVD-class intelligence
- Third-party producers can add more sources through the same contract
Prioritize what is installed and high risk
The goal is not another CVE dump. It is to identify high-risk software packages that are actually present in your estate—especially those with known exploit or KEV context—so remediation starts where it matters.
- Device Software tab as the remediation view for host packages and matches
- Security findings dashboard for fleet severity and source coverage
- Match explanations tied to package coordinates, not opaque scores alone
- Disable a noisy source without turning off all matching
Beyond host packages
Endpoint package matching sits beside other security signals in the same experience: container image vulnerability findings, detection events, and optional local exposure scanning on developer and workstation agents that reports findings without shipping a full local package inventory by default.
- Container image CVE findings flow into security views for image risk
- Optional endpoint exposure scanning for developer and workstation hosts
- Findings-first posture: store active findings and coverage, not bulk exfiltration of every local package
- Unified triage entry points for security operators
Producers stay at the edge trust boundary
Intelligence producers use gateway-mediated credentials and artifact APIs. They do not receive direct object-store credentials or call the control plane from a freeform agent path. Schedules, credentials, and enablement are operator-controlled in security settings.
- Scheduled feed runs through the existing agent command path
- Scoped credential grants instead of raw secrets on agents
- Snapshot validation and content hashes recorded with each submit
- Open-source core with inspectable matching and display contracts
FAQs
Which vulnerability feeds does ServiceRadar support?
Feed producers normalize advisories into a common contract. Common first-party sources include CISA KEV, NVD/NIST feeds, and VulnCheck KEV and NVD-class mirrors. Additional producers can register without core parser changes.
Do we need paid VulnCheck to get value?
Open feeds such as CISA KEV and NVD provide a strong baseline. VulnCheck adds commercial intelligence where you need deeper or faster coverage. Matching works from whatever sources you enable.
How is this different from only running a scanner on each host?
Collection and matching are separated. Inventory stays on the agent path; feeds and matching stay centralized so you are not distributing large feed snapshots and provider credentials to every endpoint.
Where do operators act on matches?
Start on the device Software tab for package-level remediation, and use security findings views for fleet triage, severity, and source coverage.
Where are the technical docs?
Inventory, feeds, matching, and security views are covered in the Endpoint Software Security docs .