Skip to content
Continuous Threat Exposure Management

Proof-driven CTEM.
From discovery to validated fix.

VirtueThreatX runs all five Gartner CTEM stages in one workflow — with adversarial validation and AI/LLM exposure built in. Your team ships proven, prioritized fixes instead of more findings.

Built around the frameworks your team already reports on
MITRE ATT&CK · OWASP Top 10 · CISA KEV · EPSS · NIST CSF · PCI DSS · SOC 2
The validation chain
how every finding earns its label
  1. 01
    Detection
    A candidate finding enters the pipeline.
  2. 02
    Corroboration
    Cross-engine agreement separates signal from noise.
  3. 03
    Adversarial probe
    Production-safe probe proves exploitability.
  4. State assignment
    Validated · Validating · Theoretical · Suppressed.
Only one state pages on-call
Validated
Pages on-call with evidence.
Validating
In active probe.
Theoretical
Real, not reachable.
Suppressed
Audit trail only.
Why VirtueThreatX

Three things make us different.

Exposure management vendors agree on the words. The platforms diverge on what they actually do. Here is what we do that the others don't.

01 · Validated

Proven exploitable, not theoretically vulnerable.

Every critical finding is corroborated across multiple scanners and run through adversarial validation before it reaches your queue. Severity scores are evidence, not estimates.

Raw findings
247
unverified
After validation
12
all exploitable
corroboration · BAS · LLM triage · KEV cross-ref
02 · Surface-aware

Right scanner, right surface, every time.

Scanners are dispatched by surface — Web, API, Cloud, Identity, AI/LLM — not blasted across every asset. You get higher signal, lower cost, and the right tool on the right target.

Web
Active scanning DAST Tech fingerprint
API
Schema probing Auth-flow testing
Cloud
Misconfig audit IAM walk
AI/LLM
Prompt-injection probe RAG context fuzzing
Identity
IAM walks Credential leak monitor
10 surfaces · capability-per-surface dispatch · zero misdirected scans
03 · Continuous + delta

Event-driven, with the diff that matters.

Re-scans trigger on the things that actually change risk: code pushes, KEV entries, certificate transparency, cloud changes. You see what's new and what changed, not the whole report every time.

  1. 09:14
    CISA KEV entry added
    → targeted rescan dispatched across affected surfaces
  2. 09:31
    Affected assets identified
    → entering adversarial validation queue
  3. 09:48
    Finding validated as exploitable
    → ticket auto-opened · owner + SLA assigned
git · KEV · CT log · CloudTrail · k8s admission
What is CTEM

Vulnerability management is a list.
CTEM is a continuous program.

Gartner introduced Continuous Threat Exposure Management (CTEM) as a five-stage, continuous program for reducing real exposure — not a scanner category. The point is the loop: scope what matters, discover everything in it, prioritize by real risk, validate exploitability, and mobilize a fix. Then start again.

Most platforms claim CTEM. Few implement all five stages in one workflow. Fewer still close the loop with adversarial validation. That gap is what VirtueThreatX was built for.

  • 01 · Scope
  • 02 · Discover
  • 03 · Prioritize
  • 04 · Validate
  • 05 · Mobilize
The five stages of CTEM as a continuous loop.
CONTINUOUS CTEM Loop 01 Scope 02 Discover 03 Prioritize 04 Validate 05 Mobilize
Source
Gartner CTEM
First named
2022
Stages
5 · continuous
Modern cybersecurity services

The eight services that actually matter in 2026.

A focused platform, not a directory of thirty. These are the capabilities CISOs shortlist for first this year.

See the full platform
Exposure lifecycle

Five stages. One workflow.

Click through each stage to see what the platform actually does — not what the category brochure says it should.

Stage 04 · Gartner CTEM

Validate. Prove it before you page the on-call.

Corroboration across multiple engines, adversarial probing where safe, and LLM-assisted triage with evidence capture. Every critical that reaches your queue carries the receipts: reproduction steps, response capture, exploitation path.

Four-state outcome model
  • Validated
    Proven exploitable with full evidence chain. Pages on-call.
  • Validating
    Adversarial probe in flight. Held in queue.
  • Theoretical
    Real, but unreachable or unsafe to probe. Tracked, never paged.
  • Suppressed
    Accepted risk with audit trail. Quiet by default.
Attack surface coverage

Ten surfaces. Named scanners.

Every surface attackers actually use — covered with the open-source and commercial engines we name. No "powered by AI" black-box claims.

Total
49 scanners

Web

Public sites, admin portals, marketing apps.

Active web scanning DAST Tech fingerprint

API

REST, GraphQL, gRPC. Schema-aware probing.

Schema probing OpenAPI drift Auth-flow testing

Network

Edge, internal, TLS posture, port exposure.

Port + service map TLS posture Edge scan

Cloud

AWS · GCP · Azure misconfig and over-permission.

Misconfig audit IAM walk Resource posture

Code

SAST, secrets, dependency posture in your repos.

SAST Secrets detection Dependency posture

Container

Image CVEs, runtime drift, k8s admission posture.

Image CVE scan Runtime drift Admission policy

Identity

Over-permission, leaked creds, non-human identity.

IAM relationship walks Credential leak monitor NHI discovery

Mobile

iOS · Android binary analysis and runtime posture.

Binary analysis Runtime posture
New

AI / LLM

Prompt injection, RAG context, shadow-AI discovery.

Prompt-injection probe RAG context fuzzing Shadow-AI discovery
Limited

OT / ICS

Industrial protocol fingerprint and exposure check.

Protocol fingerprint Exposure check
Continuous monitoring

Triggered by events. Not by the calendar.

Quarterly scans miss what's already in production. VirtueThreatX listens to the events that actually change risk — and runs a targeted re-validation in minutes, not next sprint.

Triggers we listen to
  • Git push

    github · gitlab · bitbucket

    Code change to a watched path triggers SAST, secrets, dependency, and IaC re-validation on the affected service.

  • CISA KEV entry

    cisa.gov · vendor feeds

    A new CVE lands in CISA’s Known Exploited Vulnerabilities catalog. Affected-version sweep fires across every asset in scope.

  • Certificate transparency

    CT log feeds · multi-CA coverage

    A new certificate for your apex appears in a CT log. New subdomain enters the scope and gets a first-pass scan within minutes.

  • CloudTrail / Activity log

    aws · gcp · azure

    A new cloud resource is created or a security group changes. Misconfiguration check runs before the resource sees production traffic.

  • K8s admission

    kube-api · admission webhooks

    Pod, service, or workload spec changes. Policy and image posture re-validated against your scope before rollout completes.

Lifecycle of one event
  1. 01
    Event arrives
    Signal lands on the bus from one of the trigger sources.
  2. 02
    Match against scope
    Affected assets identified within the in-scope graph.
  3. 03
    Targeted dispatch
    Right capability fires against right surface — never blanket re-scan.
  4. 04
    Validate + score
    Findings move through corroboration, probe, and CRPS scoring.
  5. 05
    Update state
    Validated / Validating / Theoretical / Suppressed transitions logged.
  6. 06
    Notify on change
    On-call paged only when state actually changes risk. Quiet otherwise.
Median lifecycle: minutes from event arrival to state change.
Platform intelligence · CRPS

Severity is not priority.

A 9.8 CVSS on a forgotten test box is not the same as a 9.8 on the payments path. Our Composite Risk Priority Score blends published severity, real-world exploit pressure, and your context — so the queue is ordered by what actually matters.

Four inputs. One ordered queue.

CRPS is deterministic and transparent. Every score is broken down so analysts can see exactly which input drove the priority — and can challenge it. No black-box AI, no hidden weights.

CRPS = CVSS × EPSS + KEV bump × context
Score is normalized to a 0–15 scale. Critical > 13, High 9–13, Medium 4–9, Low < 4.
  • CVSS 0–10
    Severity

    The published score. Tells you how bad the vulnerability is in the abstract.

  • EPSS 0.00–1.00
    Exploit probability

    FIRST.org's 30-day exploit probability. Tells you how likely an attacker uses it now.

  • KEV + multiplier
    Known exploited

    CISA's catalog of vulnerabilities being actively exploited in the wild. Binary.

  • Context asset-aware
    Your risk

    Asset tier, reachability, business priority, blast radius. The bit only you know.

Same severity. Different priorities. Visible math.

composition · not a fixed table

Identical published severity can compose to very different priorities once exploit pressure and local context apply. The diagram below shows that composition abstractly — every cell of the math is visible on the finding detail, challengeable by analysts, and reproducible.

Profile A
CVSS high
EPSS high
KEV listed
Context tier 0 · reachable
Outcome Pages on-call
Profile B
CVSS high
EPSS moderate
KEV not listed
Context tier 1 · SSO-gated
Outcome Tickets · normal SLA
Profile C
CVSS high
EPSS low
KEV not listed
Context tier 3 · not reachable
Outcome Theoretical · tracked

Three exposure profiles with comparable published severity. Profile A pages the on-call; Profile C never makes the queue. The difference is exploit pressure and your environment context — captured at scope time, applied at score time, visible to the analyst.

Platform architecture

Five layers. One continuous loop.

Each layer is necessary for the next. The loop closes when validated findings ship to a fix and re-validation confirms the regression has not returned.

01

Discovery

Seedless attack-surface enumeration

Apex-rooted asset graph across web, API, cloud, identity, code, and AI surfaces. Continuous certificate transparency, DNS, and cloud-provider listeners surface new assets as they appear.

Asset graph Delta + drift Shadow inventory
02

Surface-aware orchestration

Right capability, right surface, right time

Capabilities are dispatched by surface — never blasted uniformly. Event-driven triggers fire targeted re-validation on git pushes, KEV entries, certificate-transparency events, and cloud changes.

Per-surface dispatch Event-driven scans Tenant isolation
03

Intelligence

Score real risk, not raw severity

CRPS composes published severity (CVSS), real-world exploit pressure (EPSS, CISA KEV), and your local context (asset tier, reachability) into a deterministic, challengeable priority.

CRPS scoring Attack-path correlation Risk decay
04

Validation

Prove exploitability before paging on-call

Multi-engine corroboration plus adversarial probing produces an evidence chain — replication, response trace, exploitation path. Findings land in one of four states: Validated, Validating, Theoretical, Suppressed.

Adversarial probe Evidence chain 4-state machine
05

Mobilization

Route the right fix to the right owner

Validated findings reach the team's existing tools with owner, SLA, evidence, and reproduction pre-filled. Re-validation fires automatically when the fix ships; regressions reopen the ticket.

Workflow integrations Auto-routed tickets Re-validation on close
Re-validation closes the loop · the program runs continuously
Validation & risk prioritization

Four states. One reaches your queue.

Every finding the platform produces lives in one of four states. Only Validated findings page on-call. Theoretical and Suppressed are quiet by default — audited, not screaming.

Validated

Proven exploitable. Pages the on-call.

Multi-engine corroboration plus adversarial validation captured the receipts: replication script, request/response trace, exploitation path. This is what reaches the queue.

Trigger
BAS confirms · 3+ engines agree · evidence captured
Action
P0 pages on-call. P1+ opens ticket with owner, SLA, evidence pre-filled.
Validating

In active probing. Held until proven.

Initial detection cleared corroboration but BAS or analyst confirmation is still running. Visible to analysts in the queue, never paged from this state.

Trigger
Corroboration passed · validation running
Action
Held in queue. Analyst can claim or wait for the automated result.
Theoretical

Real, but not exploitable from here.

The finding exists, but the asset is unreachable from the internet or BAS is not safe to run against the target. Tracked for context, never paged on its own.

Trigger
Reachability blocked · BAS unsafe · isolated network
Action
Visible on dashboard. Status flips automatically if reachability changes.
Suppressed

Accepted, scoped-out, or known pattern.

Analyst-suppressed with a reason, or auto-suppressed for known acceptable patterns (e.g. tier-3 marketing missing a header). Full audit trail kept; hidden from defaults.

Trigger
Analyst decision · rule-based auto-suppress
Action
Quiet by default. Suppression auto-expires; reviewed on rule change.

The lifecycle of one finding.

end-to-end loop
  1. 01
    Discovered
    49-engine scan or event-triggered probe
  2. 02
    Corroborated
    multi-engine agreement · LLM triage
  3. 03
    Validated
    adversarial probe · evidence captured
  4. 04
    Routed
    jira · slack · servicenow · pagerduty
  5. 05
    Closed
    fix shipped · owner attests
  6. 06
    Re-validated
    automatic · loop closed when fix holds
Median time to validation
minutes, not days · varies by surface and BAS scope
Re-validation cadence
on close · then continuous · auto-reopen if regression
Suppression governance
reason required · expiry default 90d · audit-logged
MSSP & enterprise

Built for the way enterprise security teams actually run.

Multi-tenant from day one. Granular RBAC across five named roles. MSSP-ready white-labeling. The control surface is the product, not an enterprise upsell.

Role-based access · five named roles

enforced at API + UI + queue
Action SuperOrg adminAnalystAuditorViewer
View findings
Validate / re-run scans
Suppress / accept risk
Manage team + SSO
Manage API keys
View audit log
Cross-org administration
5 roles · 7 actions shown · 30+ enforced server-side custom roles available on enterprise plans

Multi-tenant isolation

Per-tenant data, scanners, and configuration. Hard isolation at the database and queue layer — never just a UI scoping convention.

row-level · queue-isolated · key-segregated

SSO · SAML · OIDC

Bring Okta, Entra, Google, or any OIDC IdP. SCIM provisioning for hands-off lifecycle. JWT TTL is 15 minutes by default; refresh tokens rotate.

okta · entra · google · oidc · scim

White-label · partner branding

MSSPs get full visual ownership: logo, palette, sub-domain, customer-facing reports. Persistent, not template overlays.

logo · domain · report PDF

Audit log · SIEM export

Every privileged action recorded with actor, target, and reason. Stream to Splunk, Datadog, Sumo, or an S3 bucket — your SIEM, not ours.

every action · stream-ready
Also shipped · API + webhooks for every entity · Data residency · EU / US · Sub-processor registry · Customer-facing PDF reports
Compliance & governance

Mapped to every framework your team reports against — and attested ourselves.

Compliance evidence is captured continuously, not assembled the week before an audit. The platform we ship attests to its own posture too.

Framework mappings VTX produces for every finding

12 frameworks · auto-attached
MITRE ATT&CK

Every validated finding mapped to technique + tactic.

OWASP Top 10

Web findings categorized to current OWASP categories.

CISA KEV

Daily catalog sync. KEV-listed findings escalated automatically.

EPSS

FIRST.org EPSS score attached to every CVE.

NIST CSF 2.0

Findings tied to Identify · Protect · Detect · Respond functions.

CIS Controls v8

Asset and config findings mapped to CIS safeguards.

PCI DSS 4.0

In-scope assets reported against requirement 6 + 11 controls.

ISO 27001:2022

Findings mapped to Annex A controls for evidence collection.

HIPAA Security Rule

PHI-handling assets segmented; technical safeguard mapping.

SOC 2 TSC

Continuous evidence for Security and Availability criteria.

ISO 42001

AI/LLM findings mapped to the new AI management standard.

CSA CCM

Cloud findings cross-walked to Cloud Controls Matrix domains.

Our own security posture — current state

Trust center
  • SOC 2 Type II In progress
  • ISO 27001:2022 Roadmap
  • ISO 42001 (AI mgmt) Roadmap
  • GDPR · UK GDPR Compliant
  • HIPAA-eligible processing In progress
  • Data residency EU · US
  • Sub-processor registry Published
  • Vendor security review On request
Updated as audits complete and certifications land. DPAs · MSAs · SIG questionnaires on request
Industry use cases

The same platform — your sector's frame.

CTEM looks the same in the framework diagram. It does not look the same when the regulator walks in. Here's how the platform lands in four enterprise verticals.

Workflow integrations

Lands in the tools your team already opens.

A validated finding leaves the platform with owner, SLA, evidence, and reproduction steps pre-filled. Nothing for the analyst to copy-paste; nothing for the on-call to re-derive at 2am.

Native integrations
  • Jira Ticketing
  • ServiceNow Ticketing
  • Linear Ticketing
  • Slack Comms
  • Microsoft Teams Comms
  • PagerDuty On-call
  • Opsgenie On-call
  • GitHub Source
  • GitLab Source
  • Bitbucket Source
  • Splunk SIEM
  • Datadog SIEM
  • Okta Identity
  • Entra ID Identity
  • Webhook · API Custom
What ships to your existing tools

Every validated finding lands with the work pre-done.

The structure below is the contract: every routed finding carries the same fields, regardless of destination tool. Engineers spend their time remediating — not re-deriving what was already proved.

Jira ServiceNow Slack Microsoft Teams PagerDuty Opsgenie Webhook · API
Anatomy of a routed finding
Priority
P-band + SLA window
State
Validated
Surface
Web · API · Cloud · Identity · AI/LLM · …
CRPS
Owner
Auto-assigned by surface + scope tags
Evidence
replication request capture response trace exploitation path
Loop
Re-validation on close · auto-reopen on regression
Threat trends · 2026

What's actually changing —
and what we built first.

Three trends shaping CTEM buying decisions this year. We built each into the product before it was an analyst category, not after.

AI / LLM exposure

Prompt injection is no longer a research demo.

Zero-click prompt-injection exploits against agent and RAG systems have moved from conference talks to wild-caught samples in 2025–26. Shadow-AI services proliferate inside enterprises faster than security teams can inventory them, and most CTEM platforms still treat them as out-of-scope.

Industry · EchoLeak class · Microsoft Copilot agent risk
How we answer it

VTX treats AI/LLM as a first-class surface: shadow-AI discovery, prompt-injection probing, RAG context fuzzing, model exposure scanning.

Supply chain

SBOMs alone are not stopping software supply-chain attacks.

Dependency confusion, OAuth-token theft, and CI/CD compromise produced a steady drip of disclosed incidents through 2026. SBOM-as-artifact is widely judged to be falling short — the gap is continuous validation that the dependency in production is the one you reviewed.

Industry · ReversingLabs SSCS 2026 · Vercel OAuth incident
How we answer it

Continuous dependency validation tied to your live deploys, not just the SBOM at commit time. Cross-org token usage flagged on first appearance.

Identity exposure

Non-human identities now outnumber humans 45-to-1.

Service accounts, OAuth grants, GitHub PATs, AWS roles, signed JWTs — non-human identity sprawl is the largest unmapped attack surface in most enterprises. CISO buying criteria for 2026 explicitly call out NHI discovery and over-permission analysis.

Industry · CISO priorities 2026 · multiple vendor reports
How we answer it

IAM relationship walks across AWS · GCP · Azure plus credential leak monitoring across paste sites, public repos, and CT logs.

Business outcomes

What changes about the way your program actually runs.

We don't publish vanity percentages because the changes that matter aren't single numbers — they're the rhythm of how your team operates. Here is what teams notice in the first quarter on the platform.

  • Before

    Quarterly scan-and-report cycles. Findings age between runs.

    With VTX

    Continuous, event-driven assurance. Re-validation fires on KEV entries, code pushes, cloud changes.

  • Before

    Alerts page the on-call whenever severity is high — exploitable or not.

    With VTX

    Only Validated findings page. Theoretical and Suppressed live on the dashboard for analysts.

  • Before

    Compliance evidence assembled the week before the audit.

    With VTX

    Every finding mapped to MITRE · OWASP · KEV · NIST · PCI · ISO 27001 at write time.

  • Before

    Tickets require the analyst to re-derive reproduction and evidence.

    With VTX

    Tickets land in Jira / ServiceNow / Slack with owner, SLA, reproduction, and evidence pre-filled.

  • Before

    "What is our exposure right now?" is a project.

    With VTX

    "What is our exposure right now?" is a dashboard question — answered honestly.

Outcome statements describe the change in how the program operates. We publish customer-specific metrics with attribution as customers approve them.
Confidence

What you can verify today.

Customer logos appear here as agreements complete and references go on the record. Until then — and as a principle, regardless — these are the facts that are verifiable about the platform and the team behind it.

Built by VirtuesTech

The platform expression of an offensive-security practice.

VirtuesTech is the cybersecurity engineering firm behind VirtueThreatX. The product was built by the same team that runs validation engagements at enterprise scale — which is why the platform behaves the way operators expect, not the way a marketing org imagines.

49
Open-source + commercial scanners
all named on /platform
10
Attack surfaces covered
web · api · cloud · ai/llm · identity · …
5
Gartner CTEM stages implemented
scope · discover · prioritize · validate · mobilize
12
Compliance frameworks mapped
mitre · owasp · kev · nist · pci · iso 27001 · …

We don't display unnamed logo grids or unattributed testimonials. As customers go on the record, their logos and quotes will appear here — with permission, with names, and with context.

Become a reference customer
Talk to us

See your real surface —
validated, in 30 minutes.

Not a slide deck. Not a recorded walkthrough. A live assessment against a target you own, run with the team that built the platform.

What happens after you click
  1. 01

    You pick a time

    30 minutes, live, with the team that built the platform — not a sales SDR running through a deck.

  2. 02

    You bring a target you own

    A domain, an API, a cloud account, or an LLM endpoint. We scan it during the call, with you.

  3. 03

    You leave with the artefact

    A live, validated exposure report against your target. Yours to keep, with or without us next.

The 30 minutes includes
live · 1-on-1
  • Live discovery on a target you control
  • Sample CRPS scoring on your real findings
  • A walkthrough of validation states · suppression governance
  • Integration into your Jira · Slack · SIEM
  • Q&A with the team that built the engine
  • Pricing scoped to your environment, on the call
Prefer to grab a time directly? Calendar booking lands here.
cal.com · chili piper · hubspot meetings

Ready when you are.

One business day, hand-on-keyboard reply — not a CRM auto-responder. Or email info@virtuethreatx.com.