Directory

CTEM vendor directory

Every vendor below now markets a CTEM story. This directory records what each product actually covers, in our assessment, so you can assemble a program rather than buy a slogan.

Categories: Application security · Attack path analysis · Attack surface management · Automated penetration testing · Breach and attack simulation · Cloud security · Exposure platform · Validation · Vulnerability management. Listings are editorial and unpaid. See our disclosure.

Coverage of the five CTEM stages, by product
ProductCategoriesOur summary
Tenable One
Tenable
Exposure platformVulnerability managementAttack path analysis Unified exposure platform built on Tenable's vulnerability scanning heritage. Strongest on asset coverage and prioritisation scoring; validation relies on partners.
XM Cyber
XM Cyber
Attack path analysisExposure platform Attack-graph modelling that shows how an attacker chains exposures to reach critical assets. Best fit for organisations that already have discovery covered and need prioritisation.
Cymulate
Cymulate
Breach and attack simulationValidation Breach and attack simulation with a CTEM-branded exposure module. Covers the validation stage well; discovery is lighter than scanner-first platforms.
Pentera
Pentera
Automated penetration testingValidation Automated, safe-by-design penetration testing across internal, external and credential exposure. Validation-first, so pair it with a discovery tool.
Falcon Exposure Management
CrowdStrike
Exposure platformAttack surface management Exposure management inside the Falcon platform. Compelling if you already run Falcon sensors; discovery leans on agent telemetry.
Rapid7 Exposure Command
Rapid7
Exposure platformVulnerability managementCloud security Combines InsightVM, external ASM and cloud posture into one exposure view. Broad coverage for mid-market teams with mixed on-prem and cloud.
Qualys Enterprise TruRisk
Qualys
Exposure platformVulnerability management Risk-scored vulnerability management with remediation workflow. Mature scanning; validation is the weakest of the five CTEM stages here.
Intruder
Intruder
Attack surface managementVulnerability management Lightweight external and internal scanning aimed at small and mid-size teams. Good entry point to CTEM without an enterprise budget.
Detectify
Detectify
Attack surface managementApplication security External attack surface monitoring for web applications, powered by crowdsourced research. Narrow scope, strong on internet-facing apps.
Picus Security
Picus
Breach and attack simulationValidation Security validation platform that tests controls against current attack techniques and maps results to exposure. Validation and mobilisation focus.

How to read this

Missing or wrong? Vendors and users can send corrections. We publish corrections, not press releases.

Get vendor updates monthly

One email a month: what changed in exposure management, which vendors moved, and one thing worth doing. No spam, unsubscribe any time.