Vulnerability assessment · vulnerability management

A vulnerability assessment isn't the same as a pentest —
here's the difference

A vulnerability assessment continuously and automatically scans your infrastructure in breadth and prioritises findings by real risk (CISA KEV), whereas penetration testing goes in depth and tries to exploit a vulnerability like a real attacker.

Continuous, broad coverage Prioritized by CISA KEV Measurable over time
Key difference

Breadth of scanning vs. proof of depth

Both approaches are valuable and complement each other, but they answer different questions. Scanning asks "where might it be weak"; a pentest asks "can it actually be exploited".

CRITERIONVulnerability assessment (scan)Penetration testing
GoalList and prioritize known weaknessesExploit a weakness and prove the impact
MethodAutomated scanningManual + automated, with exploitation
CoverageBroad — many systemsDeep — selected targets
FrequencyContinuous / regularPeriodic (e.g. quarterly, annually)
OutcomeA prioritized list with recommendationsA proven finding with steps and a retest
False positivesPossible — require verificationVerified through exploitation
When to use which: use vulnerability assessment continuously as hygiene and for breadth; Penetration testing periodically, for depth, proof and regulatory requirements. Aegis does both on the same platform.
What Aegis vulnerability assessment does

Priority by risk, not by the alphabet

A list of a thousand vulnerabilities is useless if you don't know which to fix first. Aegis prioritises by whether a vulnerability is actually being exploited in attacks.

Continuous scanning

Regular checking of services, applications and configurations instead of a one-off snapshot.

CVE and CISA KEV

Known vulnerabilities prioritized by whether they are actually being exploited in attacks.

COVERAGE SCORE

A measurable score of 0–100 shows how exposed you are and where you are weakest.

Concrete recommendations

For each finding, a clear next step — what to fix, where and why.

Tracking over time

See whether things are improving and how quickly you close vulnerabilities.

Link with the SIEM

A vulnerability linked to detection — if your exact weak point is under attack, you know immediately.

19.000+
cases processed
13.000+
detection rules
10.000+
pentest findings
280.000+
automatic blocks

Aggregated, anonymized and illustratively rounded production metrics.

Basics

CVE, CVSS, EPSS and KEV — how to read a vulnerability

A vulnerability is a weakness in software or configuration that an attacker can exploit. Known vulnerabilities get a CVE identifier (e.g. CVE-2024-12345) so they can be referred to unambiguously.

How severity is measured

  • CVSS — a technical severity score (0–10). It tells you how dangerous a vulnerability is "on paper".
  • EPSS — an estimate of the probability that a vulnerability will be exploited in the near future.
  • CISA KEV — a list of vulnerabilities confirmed to be actively exploited in attacks.

Aegis combines these signals so you first deal with what is genuinely dangerous today, not just the highest CVSS number. Vulnerabilities found by scanning are linked with SIEM detection and, when needed, prove it through Penetration testing.

Frequently asked questions

Vulnerability assessment — frequently asked questions

What's the difference between vulnerability assessment and a pentest? +
A vulnerability assessment is an automated broad scan that lists and prioritizes known weaknesses; penetration testing goes deep and tries to exploit a weakness to prove real impact. Do the first continuously, the second periodically.
How does Aegis decide what's a priority? +
By combining technical severity (CVSS), the probability of exploitation (EPSS) and confirmation of active exploitation (CISA KEV). This way, what's dangerous today gets fixed first.
Are there false positives? +
With any scan, false positives are possible. That's why Aegis enriches findings with context and confirms critical ones through an extra check or pentest before you spend time on a fix.
Does this replace a pentest? +
No. Scanning provides breadth and continuity, but does not prove exploitability. For proof and regulatory requirements, penetration testing is still needed.
RELATED

Keep exploring the platform

Find out where you're vulnerable — before an attacker does

Let's run a vulnerability assessment on your scope and show you a prioritised list: what's dangerous today and what to fix first.

Odgovaramo isti radni dan · info@aegis.hr