Skip to main content

Risk Management

VULN

Vulnerability Discovery and Ranking

Where a scan export becomes a ranked list of what to fix first.

The discovery stage of the pipeline. Findings from the scanners you already run come in, ATIP enrichment is joined to every CVE, AREA ranks the result, and four scoped views show it: vulnerabilities, misconfigurations, hardware and software.

ARLCVEKEVEPSSHostsSystem
1CVE-2025-31324Yes0.9441Example A
1CVE-2024-21762Yes0.9127Example B
2CVE-2025-24813Yes0.7819Example A
3CVE-2025-22457No0.4212Example C
5CVE-2024-3400No0.118Example B

Scoped to 3 systems. ARL 1 is most urgent. Illustrative values.

Where it sits

01

Discover

This page: scan data in, enriched, ranked, scoped

You are here

02

Prioritize

AREA scores, tiers and plans

Open

03

Remediate

Grouped fixes, sprints, lanes, Jira, scanner verified

Open

04

Monitor

The ATO workflow's continuous monitoring reads the same findings

Open

How the order is decided

Exploitation first, then severity

AREA weighs whether a vulnerability is known to be exploited in the wild, what actors and ransomware families use it, its daily exploit probability and its severity, and produces the AREA Risk Level seen on every finding. ARL 1 is the most urgent, and the 1 to 5 band is what the platform works first.

See the AREA pipeline
  • Known exploited

    CISA KEV membership and public exploit availability from ATIP

  • Who uses it

    Threat actors, malware and ransomware families tied to the CVE

  • Exploit probability

    The daily EPSS score and percentile

  • Severity

    CVSS, kept as one signal among several rather than the sort key

Four views, one scope

Findings, misconfigurations, hardware, software

Vulnerabilities

Every open finding across your systems, ranked by ARL and filterable by asset, status, exploitation and age. Send one straight to remediation.

Misconfigurations

Compliance checks per asset, already mapped to the NIST control they put at risk, so a failed check rolls up to the control the ATO workflow reports on.

Hardware assets

Inventory by system, with the findings each device carries.

Software assets

Installed software and components across your systems. Check whether a package exists anywhere before the advisory finishes making the rounds.

Every view is restricted to the systems you are cleared for, applied by the server before a row is returned. A system with no assets returns nothing rather than everything.

Where it comes from

  • Tenable and Qualys

    Scan data ingested from both, side by side, through the Dataset Builder

  • ATIP

    The enriched record for every CVE, refreshed daily

  • Any other scanner

    Describe its export once in the Dataset Builder and it appears here without a release

Straight answers

What makes a finding urgent?

AlloyGRC weighs whether a vulnerability is known to be exploited in the wild, not just its raw severity score. That weighting is what AREA does.

What is ARL?

AREA Risk Level, the score AREA assigns each finding. ARL 1 is the most urgent, and the 1 to 5 band is what the platform works first.

Are the rows limited to my systems?

Yes. Results are restricted to the systems you are scoped to, and the restriction is applied by the server rather than by the page.

An asset belongs to three systems. Is it counted three times?

Yes, on purpose. A shared asset carries risk for every system that depends on it, so each system's view shows it.

See your findings in the order they should be worked.

Ask for a demo and we will show a ranked view built from synthetic scan data, then send the top row to remediation.