Use case · Exposure
Exposure and vulnerability
Scanners are good at producing findings and poor at telling you which ones can actually hurt you. The missing work is joining a finding to an asset, an owner, an exposure and an exploit, and most of that context lives outside the scanner.
Runs on
Tenable · Qualys · Wiz · CMDB · ITSM
Autonomy
levels 1 to 3
The problem today
A severity score is not a priority
A critical on an isolated test box and a high on an internet facing gateway carry the same colour in most tools. Working out which is which means knowing what the asset does, who owns it, whether it is reachable and whether anyone is exploiting the flaw in the wild.
That work is manual, so it happens for a handful of findings a month, and the rest are prioritised by number rather than by risk.
What CloudPeek does
Fixed, not just flagged.
What you get
Outcomes, not activity.
Related use cases
Triage
Incident triage
Detection volume outruns the rota, so the queue decides what gets looked at rather than the risk. CloudPeek works each one and either escalates it with evidence or closes it with a written reason.
Investigation
Investigations
When triage escalates, the real work starts: reconstructing a timeline across sources, establishing scope, reaching a root cause and writing it up so somebody else can act on it.
Identity
Identity compromise
Impossible travel, token reuse, consent grants and privilege escalation, investigated against sign in history, device posture and known travel patterns.