EVIDENCE-CONNECTED VULNERABILITY CONTEXT

Connect Vulnerability Intelligence to the Assets That Matter

Bring relevant vulnerability intelligence together with observed asset evidence. GapSwift helps IT and security teams understand vulnerability context for supported assets using available software, version, hotfix and other applicable evidence, alongside Asset Intelligence and Security Gaps.

Evidence-connectedAsset-level contextClaims-safe interpretation
Relevant contextSupported evidence
Asset evidenceConnect supported observed evidence to the applicable asset.
Vulnerability intelligenceConsider available vulnerability information where correlation is supported.
Clear boundariesRelevant context is not a guarantee of applicability or exploitability.
WHAT IS VULNERABILITY INTELLIGENCE?

Understand vulnerability context in relation to managed assets.

GapSwift Vulnerability Intelligence connects relevant vulnerability information with supported asset evidence to help teams understand vulnerability context in relation to the assets they manage.

It is evidence-connected vulnerability context, not traditional network vulnerability scanning and not a claim to detect every vulnerability.

Explore Asset Intelligence →

Supported correlation
Software identityUse observed identity where the supported workflow provides it.
Version informationConsider available version evidence without implying universal matching.
Windows hotfix evidenceUse collected hotfix context where applicable.
Other applicable evidenceConnect supported asset or security context when relevant.
SUPPORTED EVIDENCE CORRELATION

Use available evidence without overstating certainty.

GapSwift correlates supported observed evidence, such as software identity, version information, hotfix evidence and other applicable asset context, with available vulnerability intelligence to determine relevant vulnerability context.

Depending on the supported asset and workflow, evidence may include software identity, software version, Windows hotfix information and other applicable asset or security evidence. This does not imply universal software, version or CVE matching.

Evidence-connected interpretation
OBSERVED

Supported evidence is associated with an authorized asset.

CORRELATED

Available intelligence is considered where the supported evidence permits.

CONTEXTUAL

Related asset and security context supports investigation.

BOUNDED

No conclusion promises complete detection or proven exploitability.

VULNERABILITIES & SECURITY GAPS

Keep different types of security information distinct.

A vulnerability relates to applicable vulnerability intelligence such as a CVE, while a Security Gap represents an observed supported security condition that does not match an implemented expected security state.

Relevant vulnerability information can be considered alongside supported Windows security configuration evidence, without implying that Vulnerability Intelligence performs a complete security posture assessment.

Connected, not collapsed
Vulnerability contextApplicable available intelligence such as a CVE where supported evidence correlates.
Security GapAn observed supported condition that does not match an implemented expected state.
Asset-level pictureAuthorized teams can understand each concept alongside current asset context.
FOCUS, SCORE & HISTORY

Keep broader indicators connected to underlying context.

Use Cyber Score as a broader indicator of observed security posture alongside underlying findings and evidence.

Maintain historical context around supported asset, software and security changes that can help teams understand how the environment has evolved over time.

Supported asset evidence observed
Applicable context correlated
Authorized team reviews information
Meaningful supported changes retained
CONTEXT FOR RESPONSIBLE TEAMS

Support investigation across authorized roles.

01

IT Administrators

Review relevant vulnerability information with supported software, hotfix and asset evidence.

02

IT Managers

Focus operational attention using available asset, configuration and security context.

03

IT Directors

Understand broader posture while retaining access to underlying supported context.

04

Security Teams & Leaders

Investigate applicable vulnerability context alongside distinct Security Gaps and evidence.

05

MSPs & Partners

Work within authorized managed customer organizations while preserving customer-level access boundaries.

VULNERABILITY INTELLIGENCE FAQ

Common questions.

What is Vulnerability Intelligence in GapSwift?

GapSwift Vulnerability Intelligence connects relevant vulnerability information with supported asset evidence to help teams understand vulnerability context in relation to the assets they manage.

How does GapSwift determine relevant vulnerability context?

GapSwift uses supported observed evidence such as software identity, version information, hotfix evidence and other applicable asset context, and correlates it with available vulnerability intelligence.

Does GapSwift perform vulnerability scanning?

GapSwift should not currently be positioned as a traditional network vulnerability scanner. Its current Vulnerability Intelligence capability uses supported collected asset and software evidence to provide relevant vulnerability context.

What evidence is used?

Depending on the supported asset and workflow, relevant evidence may include software identity, software version, Windows hotfix information and other applicable asset or security evidence.

What is the difference between a vulnerability and a Security Gap?

A vulnerability relates to applicable vulnerability intelligence such as a CVE. A Security Gap represents an observed supported security or configuration condition that does not match an implemented expected state. GapSwift keeps the two concepts distinct while allowing their context to be understood together.

Does GapSwift automatically patch vulnerabilities?

No. GapSwift does not currently provide automatic CVE patching or autonomous remediation. It helps teams understand relevant vulnerability context, supporting evidence and related security information so appropriate corrective action can be planned and later verified.

Can vulnerability information be viewed alongside asset/security context?

Yes. GapSwift connects relevant vulnerability context with supported Asset Intelligence, Security Gaps and other available security information to provide a clearer asset-level picture.

SEE GAPSWIFT IN ACTION

See Vulnerability Context Alongside the Assets That Matter.

Explore how supported asset evidence, Security Gaps and relevant vulnerability information can form a clearer asset-level picture.

Questions or want to learn more about GapSwift? Contact us at info@gapswift.com.