Platform · Exposure & Risk

Fix what is exploitable, first.

WireTrace matches each device's identified operating system, software, firmware and OT product to the NVD and OT vendor advisories, prioritised with CISA KEV and FIRST EPSS. Every finding states how it was matched, how confident the match is, and whether the vulnerable version is confirmed on that device.

ASSET RISK SCORE · 0-100ExposureKnown-exploited vulnerabilitiesThreat activityCriticality / role68likelihood × impactconfidence shown separatelyILLUSTRATIVE VALUES
Asset Risk Score

One score per device, with its factors.

Each device receives a 0-100 Asset Risk Score (likelihood × impact) with a separate confidence indicator and a factor breakdown. The Risk Register ranks devices and supports time-limited risk acceptance.

Exposure

Risks & Exposures, in one view.

Clear-text credentials

Accounts and secrets exposed by legacy and clear-text authentication.

Weak cryptography

Expired or weak certificates and outdated protocol versions.

Exposed services

Management and engineering interfaces reachable where they should not be.

OT exposure

Unauthenticated industrial protocols and unexpected paths into control networks.

End-of-life technology

Operating systems and products past vendor end of life, using lifecycle data that also works offline.

Network integrity

Adversary-in-the-middle findings and ransomware activity alongside exposure.

Remediation

From finding to verified fix.

Now / Next / Later remediation lanes with owners, SLAs, change windows, time-limited risk acceptance, verified-fix tracking and a containment view for unpatchable devices.

Version-precise matches need version evidence: from the device itself, from credentialed collection or from switch polling. Findings without it are labelled as such.

See it on your network.

A WireTrace evaluation runs on a mirror port, on your infrastructure, and shows your own devices, communications and risks.