Directory
CTEM vendor directory
Every vendor below now markets a CTEM story. This directory records what each product actually covers, in our assessment, so you can assemble a program rather than buy a slogan.
| Product | Categories | Our summary |
|---|---|---|
| Tenable One | Exposure platformVulnerability managementAttack path analysis | Unified exposure platform built on Tenable's vulnerability scanning heritage. Strongest on asset coverage and prioritisation scoring; validation relies on partners. |
| XM Cyber | Attack path analysisExposure platform | Attack-graph modelling that shows how an attacker chains exposures to reach critical assets. Best fit for organisations that already have discovery covered and need prioritisation. |
| Cymulate | Breach and attack simulationValidation | Breach and attack simulation with a CTEM-branded exposure module. Covers the validation stage well; discovery is lighter than scanner-first platforms. |
| Pentera | Automated penetration testingValidation | Automated, safe-by-design penetration testing across internal, external and credential exposure. Validation-first, so pair it with a discovery tool. |
| Falcon Exposure Management | Exposure platformAttack surface management | Exposure management inside the Falcon platform. Compelling if you already run Falcon sensors; discovery leans on agent telemetry. |
| Rapid7 Exposure Command | Exposure platformVulnerability managementCloud security | Combines InsightVM, external ASM and cloud posture into one exposure view. Broad coverage for mid-market teams with mixed on-prem and cloud. |
| Qualys Enterprise TruRisk | Exposure platformVulnerability management | Risk-scored vulnerability management with remediation workflow. Mature scanning; validation is the weakest of the five CTEM stages here. |
| Intruder | Attack surface managementVulnerability management | Lightweight external and internal scanning aimed at small and mid-size teams. Good entry point to CTEM without an enterprise budget. |
| Detectify | Attack surface managementApplication security | External attack surface monitoring for web applications, powered by crowdsourced research. Narrow scope, strong on internet-facing apps. |
| Picus Security | Breach and attack simulationValidation | Security validation platform that tests controls against current attack techniques and maps results to exposure. Validation and mobilisation focus. |
How to read this
- Exposure platform: aims at discovery and prioritisation across multiple sources. Usually the system of record.
- Attack path analysis: models how exposures chain to critical assets. Prioritisation specialists.
- Breach and attack simulation, automated penetration testing: validation. Prove the exposure is real and the controls miss it.
- Attack surface management: external discovery. Fast to deploy, narrow by design.
Missing or wrong? Vendors and users can send corrections. We publish corrections, not press releases.