// THREAT DETECTION AND DATA PRIVACY TERM

Vulnerability Scanning

Vulnerability scanning is an automated process of identifying security weaknesses or misconfigurations in computer systems, networks, and applications. It helps organizations find potential entry points attackers could exploit.

Vulnerability Scanning — illustration from Wikipedia
Image via Wikipedia

TECHNICAL DEFINITION

Vulnerability scanning is an automated cybersecurity process that uses specialized tools to systematically identify known security weaknesses, misconfigurations, and exploitable flaws across IT infrastructure, including networks, systems, and applications, informing risk assessments and compliance efforts.

BACKGROUND

Computer security is a subdiscipline within the field of information security. It focuses on protecting computer software, systems, and networks from threats that can lead to unauthorized information disclosure, theft, or damage to hardware, software, or data, as well as to the disruption or misdirection of the services they provide.

READ MORE ON WIKIPEDIA

SYNONYMS & ALIASES

  • Security scanning
  • Vulnerability assessment
  • Weakness detection
  • Cyber scanning
  • Flaw identification

USAGE NOTE

It is regularly conducted to maintain an organization's security posture, identify exploitable flaws, and meet regulatory compliance requirements.

DEVELOPERS

Organizations developing technology related to Vulnerability Scanning.

  • Tenable

    A cybersecurity company known for its vulnerability management platform, Tenable.io, and its popular vulnerability scanner, Nessus.

  • Qualys

    Provides a cloud-based platform for vulnerability management, compliance, and web application security, including extensive vulnerability scanning capabilities.

  • Rapid7

    Offers a comprehensive vulnerability management solution, InsightVM, and is also known for Metasploit, a penetration testing framework that includes vulnerability identification.

  • Greenbone Networks

    The main developer behind the open-source Open Vulnerability Assessment System (OpenVAS) and provides commercial vulnerability management solutions based on it.

  • Invicti Security

    The parent company of Acunetix and Netsparker, specializing in web application security solutions that include advanced web vulnerability scanning.

  • Palo Alto Networks

    A global cybersecurity leader that integrates vulnerability assessment and management into its broader security platforms, including cloud security offerings.

  • Fortinet

    Provides a wide range of cybersecurity solutions, including FortiAnalyzer and FortiManager, which offer vulnerability assessment and management as part of their security fabric.

  • CrowdStrike

    Known for its cloud-native endpoint protection, CrowdStrike also offers Falcon Spotlight, providing continuous vulnerability management and IT hygiene from the endpoint.

RELATED TERMS IN DEFENSE & ARCHITECTURE