Kenzer runs the full CTEM cycle — scoping, discovery, prioritization, validation, and mobilization.
Its triage queue is ranked by real exploit maturity data (EPSS, VEDAS, CISA KEV), not just CVSS severity.
Define the organizations, domains, and sub-organizations in scope, with hierarchy and rollup.
Enumerate assets, services, and exposures across the full attack surface.
Rank findings by severity and real-world exploit likelihood, not raw CVSS alone.
Scheduled rescans confirm whether a finding is still live or has been remediated.
Scoped access lets the owning team fix findings directly and see the score respond.
A 9.8 CVSS finding nobody is exploiting and a 7.2 finding under active mass-exploitation are not the same problem.
Kenzer's findings pipeline cross-references EPSS (exploit prediction), VEDAS (ARPSyndicate's own exploit-maturity score), and the CISA Known Exploited Vulnerabilities catalog.
| Signal | What it tells you |
|---|---|
| CVSS | Theoretical severity if exploited — doesn't reflect real-world likelihood |
| EPSS | Probability a vulnerability will be exploited in the next 30 days |
| VEDAS | ARPSyndicate's own exploit-maturity score, derived from its exploit database |
| CISA KEV | Confirmed — this vulnerability is already being exploited in the wild |
Every in-scope organization is rescanned on a recurring cadence.
Exposure is tracked as it changes, not audited once.
Built on ARPSyndicate's Exploit Observer — one of the largest exploit intelligence databases — for real exploit-maturity scoring.
Track whether an organization's posture is improving or worsening over time, portfolio-wide.
Surface critical and high findings that have stayed open past a threshold.
Nothing ages silently.
A shared-provider incident automatically re-flags every organization with a detected dependency on it.
Scoped access routes remediation to the team that actually owns the affected organization.
A scanner produces a list.
CTEM is the full cycle around that list — continuous rescoping, exploit-aware prioritization, validation, and routing remediation to an owner.
Yes — discovery covers subdomains, web apps, cloud storage, and code-leak exposure alongside traditional port/service scanning.
Yes — higher-risk organizations can be scheduled more frequently than lower-risk ones.
Via scoped accounts — see remediation access on the Third-Party Risk Management page.
Exploit-aware, continuously validated, and routed to the right owner automatically.