Skip to content

ServiceRadar

Open navigation

Security

Threat intelligence and software risk

Turn package inventory into prioritized risk: know which installed software is vulnerable, which is known-exploited, and where to remediate first.

Match live endpoint software inventory against open and commercial vulnerability feeds—including NVD , CISA KEV , and VulnCheck —to surface high-risk packages with exploit and KEV context next to the devices that run them.

Inventory first, then intelligence

Threat intelligence is only as good as the software truth underneath it. ServiceRadar matches current endpoint package and SBOM coordinates in the control plane after collection—agents do not pull CVE feeds or run matching jobs on every host.

  • Uses the endpoint software inventory as the source of installed packages
  • Central matching writes device-scoped vulnerability findings
  • Shows installed version, fixed version, confidence, and feed provenance
  • KEV and exploit flags travel with the advisory when the feed provides them

Open and commercial feeds, one matching surface

Feed producers download, validate, and normalize provider data, then submit a common advisory contract. Operators can enable or disable sources without rewriting core. First-party paths include open sources such as CISA KEV and NVD/NIST, plus commercial VulnCheck KEV and NVD-class mirrors when licensed.

Prioritize what is installed and high risk

The goal is not another CVE dump. It is to identify high-risk software packages that are actually present in your estate—especially those with known exploit or KEV context—so remediation starts where it matters.

  • Device Software tab as the remediation view for host packages and matches
  • Security findings dashboard for fleet severity and source coverage
  • Match explanations tied to package coordinates, not opaque scores alone
  • Disable a noisy source without turning off all matching

Beyond host packages

Endpoint package matching sits beside other security signals in the same experience: container image vulnerability findings, detection events, and optional local exposure scanning on developer and workstation agents that reports findings without shipping a full local package inventory by default.

  • Container image CVE findings flow into security views for image risk
  • Optional endpoint exposure scanning for developer and workstation hosts
  • Findings-first posture: store active findings and coverage, not bulk exfiltration of every local package
  • Unified triage entry points for security operators

Producers stay at the edge trust boundary

Intelligence producers use gateway-mediated credentials and artifact APIs. They do not receive direct object-store credentials or call the control plane from a freeform agent path. Schedules, credentials, and enablement are operator-controlled in security settings.

  • Scheduled feed runs through the existing agent command path
  • Scoped credential grants instead of raw secrets on agents
  • Snapshot validation and content hashes recorded with each submit
  • Open-source core with inspectable matching and display contracts

FAQs

Which vulnerability feeds does ServiceRadar support?

Feed producers normalize advisories into a common contract. Common first-party sources include CISA KEV, NVD/NIST feeds, and VulnCheck KEV and NVD-class mirrors. Additional producers can register without core parser changes.

Do we need paid VulnCheck to get value?

Open feeds such as CISA KEV and NVD provide a strong baseline. VulnCheck adds commercial intelligence where you need deeper or faster coverage. Matching works from whatever sources you enable.

How is this different from only running a scanner on each host?

Collection and matching are separated. Inventory stays on the agent path; feeds and matching stay centralized so you are not distributing large feed snapshots and provider credentials to every endpoint.

Where do operators act on matches?

Start on the device Software tab for package-level remediation, and use security findings views for fleet triage, severity, and source coverage.

Where are the technical docs?

Inventory, feeds, matching, and security views are covered in the Endpoint Software Security docs .